Skip to content

Workflows & Configuration

Your administrators change it. Not your vendor.

Configure how work moves, what people see and who can do what, in the browser, with every change logged.

Review chains

Work moves to a person, and stops there until they act.

A review chain is a reusable sequence of stages, assigned per module, with an SLA escalation behind each one. The chain routes the work; the decision at every stage is a person's.

Sastrum routes the work and records who acted. It does not approve anything on your behalf.

Reusable
One chain, assigned to the modules that need it.
Presets
The Review Chains page ships presets to start from.
SLA escalation
Each stage carries its own escalation.

Presets are offered in the Review Chains page; none had been created in the tenant we reviewed.

PreviewThe Approval Inbox, the screen a reviewer opens, is a preview running on sample data.

Recorded in the product

Control Mapping · Approval Workflow

The drafted policy is mapped to the controls it governs and to the framework clauses each provision satisfies, then routed through maker, checker, head of department and director.Sample organisation

Configured in the browser

Six surfaces, and every change on the audit trail.

These are the things an administrator changes without raising a ticket with us.

  1. Review chainsReusable chains with presets and SLA escalations, assigned per module.
  2. Task managementAll tasks, workflow actions, status and extensions in one place.
  3. TemplatesWorkflows, dashboards, reports, notifications, events, forms and modules.
  4. SurveysTemplates and instances, versioned and bilingual where needed.
  5. Taxonomies & SoDConfigurable entities, computed fields and conflict rules.
  6. Roles & permissionsSystem and custom roles with a permission matrix across nine areas.
Also configured hereOnboarding HubGRC CalendarAudit Trail

Access model

Permissions, area by area.

Permissions available per area in the role matrix, as read from the application. Select an area to see what it governs.

Permissions available per area

Audit100

The audit universe, engagements, committees and corrective actions.

Where it applies

Roles in the reviewed tenant

System admin
625permissions held
Risk Manager (custom)
150permissions held

Per-area availability and the size of a role are different measures; they are not two views of one total.

Read from the application, 18 Sep 2026.

Configuration is a record too.

Security & Trust

  • Every change loggedConfiguration changes land on the same audit trail as everything else, filterable by module, event, actor and date.
  • Conflicts enforcedSeparation-of-duties rules are configured here and enforced on the records they govern.
  • Decisions stay with peopleChains route work and record who acted. No stage completes itself.

Change it yourself, on a Tuesday.

The demo covers the review-chain presets, the roles matrix and what an administrator can change without involving us.