Compliance operations / ISO 27001 readiness

The compliance operating system for SMBs.

For growing software teams facing enterprise security reviews, ISO pressure, and customer due diligence without a dedicated compliance department.

In development. The sales and evaluation journey below is planned; live orders are not open.

ISO-OPS / EXECUTION

Readiness system
Active
CTRL-047 Controls 4d
EV-219 Evidence Linked
SCHEDULER Cadence Armed
RISK-014 Risk Medium
Scope Controls Evidence Audit pack

The IAMSpock execution path

An operating system
for IT security.

Turn security decisions into action, and action into proof. IAMSpock connects the whole journey, from the first risk you identify to the evidence you present for audit or due diligence.

From risk to readiness

Select a step to explore the guidance

Intelligence at every step

Clear options.
Your decision.

Relevant suggestions help your team decide what to do next, why it matters, and how to move forward.

Example guidance · Managing access risk

01 / Identify risk

Where should you focus first?

  • Assess supplier access

    Understand which third parties can reach your systems and data.

  • Check leaver access

    Look for accounts that should have been removed when people left.

Every step builds on the last. Every decision has a path to proof.

Pressure compounds

The work starts long before the auditor arrives.

Enterprise customers ask for proof. Teams search across folders, tickets, policies, owners, and old answers. IAMSpock brings that scattered work into a guided operating rhythm.

Enterprise security questionnaires

Every deal brings new proof requests and another deadline.

Spreadsheet chaos

Readiness gets buried in tabs, comments, and stale status colours.

Consultant dependency

Advice helps, but daily ownership still has to live inside the business.

Scattered evidence

Policies, tickets, logs, and approvals drift away from the controls they prove.

Audit panic

A year of governance work gets compressed into a few stressful weeks.

No internal GRC team

Security, product, ops, and leadership share the load without a clear rhythm.

What changes

The system tells the team what to do next.

Next action Recommended work appears Owner Responsibility is assigned Due date The cadence is set Evidence path Proof stays connected

Operating system

A guided compliance operating system — not a generic GRC toolkit.

Modular governance

Modules grouped by how compliance work actually gets done.

01

Plan the system

Decide what matters and who owns it.

Start Here Know the next best move. Compliance Lead High priority
Risk Register Prioritise risk with evidence. Security High priority
Control Register Turn requirements into ownership. Control Owners Core
02

Run the work

Turn compliance into recurring operations.

Tasks & Calendar Keep compliance moving weekly. Operations Live
Supplier Governance Review supplier risk before it becomes urgent. Procurement Cadence: Quarterly
Management Reviews Make governance decisions visible. Leadership Cadence: Scheduled
03

Prove readiness

Answer customers and auditors with confidence.

Evidence Answer with proof already linked. Evidence Owners Linked
Audit Readiness Prepare by reviewing, not collecting. Audit Lead Ready
Due Diligence Packs Move customer reviews faster. Sales / Security Reusable

Opinionated by design

The system has a point of view, so your team does not start from a blank page.

IAMSpock doctrine Opinionated where compliance usually gets vague.
01

It tells you what matters first.

Controls, risks, evidence, and due diligence work are sequenced instead of left as an open framework.

02

It turns advice into ownership.

Every action has a responsible owner, status, due date, and evidence path before work drifts.

03

It keeps the operating rhythm alive.

Reviews, approvals, suppliers, and proof collection return on schedule, not when panic starts.

Deployment models

Choose the boundary that keeps your compliance data under your control.

IAMSpock is designed for vendor-hosted, customer-hosted, and on-premises deployment. Availability and responsibilities are confirmed in the applicable agreement; vendor-hosted production remains subject to release and operational gates.

IAMSpock Core Policy, risk, controls, evidence, and audit readiness. One operating system. Multiple deployment boundaries.
01

Vendor Hosted

Single-customer managed operation after the applicable production gates are verified.

Clickly operated
02

Customer Hosted

Run inside your approved cloud estate.

Your cloud
03

On Premises

Run the same core application inside your own infrastructure.

Customer operated

Operational rhythm

Compliance becomes recurring operational work — not annual panic.

WEEKLY Scheduled tasks Owners, due dates, and proof requests stay visible.
MONTHLY Evidence collection Refresh cycles surface gaps before customers ask.
QUARTERLY Risk and supplier reviews Approvals, treatments, and governance notes repeat.
ANNUAL Audit preparation Internal-audit records and readiness packs stay connected.

Built for scrutiny

For teams who have to prove trust before the deal can move.

Buying and first use

Arrange your licence with Clickly before you install.

Clickly's planned commercial site will handle enquiries, reviewed orders and customer downloads. You can discuss a purchase or evaluation before creating an IAMSpock environment.

Development preview. The destinations below are planned for launch. Live enquiries, orders and customer access are not yet open.

  1. Tell Clickly what you need

    Share your company details, expected covered users and deployment preference. Clickly reviews the request and verifies the customer relationship before inviting an account owner to the portal.

  2. Review the complete offer

    The quote shows requested users, purchased capacity and any commercial rounding, plus agreed support, updates and packs. Clickly issues quotes and invoices through QuickBooks and confirms cleared payment. A deposit alone does not release a production licence.

  3. Receive your signed files

    After full cleared payment and review, Clickly issues and releases the licence to authorised customer downloads, alongside any purchased pack receipts and eligible software or guides. An approved evaluation follows its separate approval process.

  4. Import the licence you received

    Your administrator signs in with the deployment's own account and imports a valid production or evaluation licence before ordinary use. Setup displays the signed rights; the purchasing decision has already been made.

Evaluation: Clickly reviews each request for the 30-day, 25-user evaluation and any optional demo-pack receipts. Downloading a file again does not restart its evaluation period.

After activation: established core work and data access continue independently of the portal. Administrators can carry signed files to disconnected environments. Changes, renewals and exact-file recovery use reviewed portal requests; portal accounts are separate from IAMSpock installation accounts.

Launch scope: South African direct sales in ZAR. International enquiries are handled outside the portal order workflow. Support, software updates and pack rights retain their separately agreed terms.

For a product discussion while the commercial site is in development, contact info@clickly.co.za. Please do not send ISMS evidence, staff lists, payment-card details or signing material with an enquiry.