Skip to main content
Help

Using Baseline Telemetry Advisory

Last updated 1 September 2026

This page answers common questions from clients and delivery leads using the workspace. If you cannot find what you need, email support@btadvisory.io with the tenant name, the route you were on, and a short description. For known platform issues, check the status page before writing in. If our site will not load at all, our independent status page at status.btadvisory.io stays online.

Getting into your workspace

  • Sign in. Use the email and password your advisor or workspace owner set up for you. If you are unsure of the URL, check the invitation email.
  • Multi-factor authentication is mandatory. The first time you sign in you are asked to enrol an authenticator app. Save the recovery codes in a safe place.
  • Lost your device or codes? Email support@btadvisory.io from your registered address. We verify your identity before resetting MFA.
  • Forgotten password. Use the Forgot password link on the sign-in page. Reset links expire after 30 minutes.
  • New device notifications. You may receive a security email when you sign in from a new browser or location.

Finding your way around

Your navigation shows only the sections your role can see. Clients have read access to everything in their tenant; advisors can add, edit, and publish.

  • Overview. The dashboard shows open risks, upcoming tasks, controls that need attention, and recent activity.
  • Risks. View and comment on the risk register. Clients can propose changes; advisors own acceptance and treatment decisions.
  • Controls. Read policies and evidence requirements. Status tells you which controls are passing, in progress, or overdue for review.
  • Policies. Published policies live here. Older drafts stay visible only to advisors.
  • Vendors. Third-party and vendor risk records, including review dates and outstanding questionnaires.
  • Incidents. Open and closed incidents, linked controls, and lessons learned.
  • Framework readiness. Your progress against SOC 2, ISO 27001, CIS Controls, or whichever frameworks your engagement is tracking.
  • Deliverables. Where your advisor publishes buyer evidence packs, reports, and the handover bundle.
  • Vault. Secure uploads for evidence, audit files, and anything too sensitive for email.
  • Inbox and activity. Notifications about proposals, comments, invitations, and published items. Activity is the full audit trail.

Asking for a change

Live records stay read-only for clients so the audit trail stays clean. To change a value, open the record, choose Suggest a change or Propose edit, fill in the new values, and add a note explaining why. Your advisor sees the diff in their review queue.

Propose-approve workflow
1
Client
Open a record
Risk, policy, control, vendor, task, or incident.
2
Client
Suggest a change
Add a note and the proposed new values.
3
Advisor
Review queue
Side-by-side diff in /portal/reviews.
4
Advisor
Decide
Approve, reject, or request changes.
5
Client
See outcome
Inbox and activity log update.
Client action
Advisor action

Getting your evidence out

  • Register exports. Every register has an export menu that produces PDF, XLSX, or DOCX files.
  • Published deliverables. The Deliverables tab holds buyer evidence packs, reports, and named releases your advisor has published.
  • Buyer evidence pack. A buyer-safe summary for a customer, partner, or auditor: framework coverage, control library and test state, approved policies, third-party oversight, resilience testing, and an evidence index. Your advisor can publish it as a single dated ZIP, or you can export the underlying modules yourself.
  • Handover bundle. At engagement closure your advisor can package every register into a single ZIP.
  • Snapshots, not live files. Both packs are assembled from your workspace modules on the day they are produced. The live record is always the workspace; ask for a fresh pack when you need current figures.
  • Client-owned. Any file you download or receive is yours to keep, even if the engagement ends.

Your people and access

Advisors and workspace owners

  • Invite colleagues from the Membership page and assign a role: Workspace owner, Workspace member, or Advisor.
  • Owners and advisors can deactivate people who leave. Deactivation keeps the audit trail intact and removes future access.
  • Advisors control which workspaces they are active in through the workspace switcher. Client sessions are scoped to their tenant only.

Your data

  • Isolation. Row-level security keeps your tenant separate from every other tenant in the system.
  • Retention. Engagement data is kept for engagement duration plus 24 months by default. The audit trail is kept for 24 months.
  • Legal holds. Deletion requests are honoured except where law, accountability, or a litigation or regulatory hold requires us to keep specific records. See the Privacy Policy, DPA, and Trust Centre for the full detail.

Frequently asked questions

I lost my authenticator app. How do I get back in?
Email support@btadvisory.io from the address associated with your account. We will verify your identity and reset your MFA enrolment. For security, we do not reset MFA in response to messages sent from an unrecognised email address.
Can I edit a risk, control, or policy myself?
Client accounts are read-only on live records. Open the item and choose Suggest a change or Propose edit, add a short note, and submit. Your advisor reviews the side-by-side diff and approves, rejects, or asks for more information. Nothing changes until they approve.
How do I add a colleague?
Workspace owners and advisors can invite people from /portal/membership. If you do not see that option, ask your advisor to add the person and to set the right role.
Where do I find published deliverables?
Your advisor publishes deliverables to the Deliverables tab. You can also export any register at any time. Everything published or exported is yours to keep, even if the engagement ends.
How is my data isolated from other clients?
Every record is scoped to your tenant and protected by row-level security. A user in one workspace cannot see records in another.
How long is my data kept?
Engagement data is retained for engagement duration plus 24 months by default, then deleted. The audit trail is kept for 24 months. Handover exports follow the same retention window as engagement data; once you've downloaded a copy, it's yours to keep regardless. Deletion requests may be limited where the law, a litigation hold, or a regulatory obligation requires us to retain certain records.
Do you use AI to do the work?
Some workspace features use managed AI services when enabled for an engagement and process only content submitted to that feature. Baseline Telemetry Advisory may also use managed AI and coding assistants for limited internal research, drafting, coding, and analysis. They are not a routine route for client workspace content, and we do not intentionally submit client secrets, credentials, raw evidence, sensitive personal data, or confidential engagement material. AI-assisted outputs are reviewed by Baseline Telemetry Advisory before delivery. Clients may request that AI-assisted processing be excluded from their engagement. Baseline Telemetry Advisory uses a managed business productivity suite for email, bookings, documents, and administration. A managed transactional email provider sends authentication messages, invitations, booking confirmations, reminders, and operational notifications.
The workspace looks slow or offline. What should I check?
Check the status page first for any known incident. If the site itself will not load, go to status.btadvisory.io, which is hosted separately from our platform and stays online during an outage. If nothing is reported, email support@btadvisory.io with the route you were on, the time it happened, and a short description.

Still stuck

Email support@btadvisory.io with your tenant name, the page you were on, what you expected to happen, and the time it happened. Include a screenshot only if it does not contain sensitive data. For platform incidents, check the status page first, or status.btadvisory.io if our site is unreachable.