Processes

Every procedure run,
every run on record.

A process is a procedure your people carry out: a checklist worked through on a cadence, or a report form filed when something happens. Each run is stored as a dated submission with its own frozen copy of the structure. Your people run them in the employee portal, and the auditor gets the submissions, not the blank template.

Start for freeBook a conversation
++++
app.devguard.ch / processes / vehicle-readiness-check
Checklist · monthly
Cadence
11
of 12 runs submitted
This year92%
Submitted11
In progress01
Reports open02
Next due 30 Sep · re-anchors on completion
Vehicle readiness check
CL 3.1.1owner · Fleet Manager
BuilderTextSubmissions
Template · ISO 9001 internal audit
Structure
#Cab and documents
Vehicle registration document1
Warning triangle1
#Lights and signals
Headlights—
Defibrillator battery>80%
Portal preview
Vehicle registration documentAK06:41
Warning triangleAK06:42
HeadlightsMR07:05
Defibrillator battery
A. Klein started 06:41 · M. Rossi continues
Every submission freezes its own copy of these rows, so editing the template never rewrites March.
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO 9001
  • Swiss nFADP
How it works

Written once, run where the work is.

You write the procedure down and build its rows, your people run it in the portal, and every run comes back as a submission you can handle, cite and export.

01

Write the procedure down once.

A process carries a name, the identifier your organization already uses, a description, an owner role and the business roles that may run it, plus a cadence, a version and labels. Leaving the audience empty means everyone in the portal can run it. The rows are built afterwards on the Structure tab, in a visual builder or a text view for bulk entry, with a live preview of exactly what your people will see.

Templates built on ISO 9001:2015 give you a starting point for internal audits, management reviews, nonconformities, customer complaints, supplier evaluations, job release, measuring equipment and change requests. Picking one replaces the current structure after you confirm, and nothing is saved until you press Save.

Two kinds, one model.

A checklist is worked through and submitted, a pre-shift vehicle check or a monthly server-room walkthrough. A report form is filled in and filed when something happens, a damage report or a near-miss. The kind is fixed once the process exists, because every submission is shaped by it.

02

Your people run it in the portal.

A checklist is started, worked through and submitted. Progress saves automatically, so a tablet on a loading bay that loses its connection does not lose the last twenty ticks. A checklist left open appears to the whole audience as something to continue, the late shift finishes what the early shift began, and each row records who ticked it and when.

A report form is filed in one go. The person who filed it can read it back afterwards, and nobody else in the portal can, because a damage report names people and places.

03

Handle the report, keep the submission.

Filed reports land in Submissions, opened on what still needs somebody. The owner role moves a report from submitted to being handled to resolved and records the measures taken, the parts and material used, the cost and any remarks. A resolved report is locked until someone explicitly unlocks it, so reopening a closed record is a decision rather than a side effect of clicking into it.

The owner role hears about every submission and filing, the filer hears when their report is taken over, resolved or reopened, and the audience hears when a recurring checklist is due or overdue. Portal-only people have no in-app inbox, so for them the email is the whole of what comes back.

Why it’s built this way

Built for the person holding the tablet.

Four choices behind how processes work here — each one something you can check, not an adjective.

01

The submission freezes its own structure.

Every submission keeps its own copy of the rows it was started with, so a checklist somebody submitted in March still shows exactly what they were asked in March, however often you edit the template afterwards. A run started before an edit finishes against the old rows instead of jumping to the new ones, and the PDF export renders from that frozen copy rather than from today’s template.

02

Sixty rows should not take sixty clicks.

A ward checklist is sixty rows, and typing them one button at a time is why checklists stay on paper. The Text view takes one section per heading line and one row per line, label, target and remark separated by pipes, while the Builder handles reordering, duplicating and deleting. The live preview beside the editor shows exactly what your people will be handed in the portal.

03

A filed report is private to the person who filed it.

A damage report names people and places, so the reporter is the only employee who can read it back in the portal. The handling happens in Submissions, where the owner role moves it from submitted to being handled to resolved and records what was done, the parts and material used and the cost. Whoever filed it hears about each step by email.

04

Late does not mean late forever.

A checklist with a cadence re-anchors from the day the work was actually done, not from when it was supposed to happen, so one late run does not compress every following cycle and leave the deadline list nagging for good. Report forms take no cadence at all: they are filed when something happens, and a due date for one would ask for something nobody can supply.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where processes connect.

A process takes its audience from business roles, puts its recurring runs on the deadline calendar, and files each execution as evidence for the controls it serves.

policyv1.3
access_control {
require mfa = true
}

Policies

A document people read and acknowledge, not a procedure they run.

JUN
ISO review
in 3 days

Deadlines

Recurring checklists on the calendar, re-anchored when the work is done.

342
artifacts captured
linked to controls

Evidence

One signed checklist cited as proof for one execution.

86%
Shared with
JDAKMR+3

Reports

A submission as a PDF, every row with who ticked it and when.

FAQ

The questions evaluators ask.

How is a process different from a policy, a training or a task?

A policy is a document people read and acknowledge, a training is material people work through and attest to, and a task is one piece of work for one person. A process is a procedure people carry out again and again, and every time they do, a dated submission is stored. An auditor asking you to show that the ambulance is checked every month wants those submissions, and that is what this module produces.

Can I change a checklist after people have submitted it?

Yes, and nothing that already exists changes with it. Every submission freezes its own copy of the structure the moment it starts, so earlier runs keep showing the rows people were actually asked about, and a run in progress finishes against the rows it began with. Only the kind, checklist or report form, is fixed after creation, because existing submissions are shaped by it.

How does a filed report get handled?

Filed reports land in Submissions, which opens on what still needs somebody. Opening one shows the answers exactly as filed plus a handling panel: a status that moves from submitted to being handled to resolved, the measures taken, the parts and material used, the cost as free text and remarks. A resolved report is locked, and editing it again takes an explicit unlock. The person who filed it is notified at each step.

Who can run a process, and where?

People run processes in the employee portal, not in the admin app, so a member with the Employee role can work through a checklist on a tablet without ever seeing the registers. Naming business roles under who can run it narrows the audience to their members; leaving it empty means everyone in the portal. A checklist left open can be continued by a colleague, and each row records who ticked it and when.

Do you ship templates?

Yes, a set of starting points built on ISO 9001:2015: internal audit, management review, nonconformity and corrective action, customer complaint, supplier evaluation, job release, measuring equipment and change request. Picking one replaces the structure you have and asks you to confirm first. Nothing is saved until you press Save, so a template you dislike costs a page reload.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Export the process list to CSV, or any single submission as a PDF with every row, who checked it and when, and the full timeline. Archiving a process takes it out of every audience and deadline while keeping its submissions intact. Your data is yours and exportable in full at any time, with no lock-in.

Show the auditor the run, not the blank form.

Write the checklist down once, hand it to the people who carry it out, and let every submission build the record while the template stays yours to improve.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free