The same truth,
told six ways
A board member, a sysadmin, a developer, an implementer, an auditor and an investigator all need different things from the same management system. Writing six documents by hand is how they drift apart. Xee generates all six from one dataset.
Board report
Plain language, no acronyms, one page. The question it answers is "are we exposed, and is it getting better?"
- Readiness and trend
- Top business risks in English
- Framework coverage
- Assurance status
- Prints into the board pack
IT report
The A.8 technical control surface, grouped the way an infrastructure team actually thinks about it.
- Identity, logging, backup
- Vulnerability and malware
- Network and segregation
- Verified evidence per domain
- Open technical actions
Software report
Only the secure-SDLC controls development owns — so nobody hands a developer a 93-row spreadsheet again.
- A.8.25–A.8.29 secure development
- Dev-facing questionnaire answers
- Engineering findings
- Fixes tied to controls
Implementer queue
Not a report — a work list. What to do next, in the order that moves readiness furthest.
- Not-started and in-progress controls
- Reviews falling due
- Open findings by due date
- Risks still needing treatment
Auditor pack
A read-only assessor view, shareable with an external auditor who gets this and nothing else.
- Scope and readiness
- Evidence sample with SHA-256 hashes
- Audit programme
- Nonconformities and corrective actions
- Management reviews · prints as a pack
Forensics
The view you'll want on the worst day — built before you need it, not during the incident.
- Searchable activity timeline
- Chain-of-custody evidence register
- Integrity hash per artefact
- Incident-response and logging controls
Why this matters more than it sounds. Six hand-written documents means six versions of the truth, five of them out of date. Because every lens reads the same registers, closing a finding updates the board report, the IT report and the auditor pack at the same moment — and the audit trail shows exactly when it happened.
Generated, not maintained
Nothing here is a template you fill in. Each view is a query over the control register, the risk register, findings, evidence, audits and the activity log — rendered server-side, on demand, for whoever opened it.
- No export-to-spreadsheet step in the middle
- Evidence integrity hashes carried into the auditor and forensics views
- Read-only external auditor role — the pack, nothing else
- Print-to-PDF for the artefacts that leave the building
- Score history behind the trend line, month by month