One product. Nine surfaces.
Built around how security actually happens — a question, a ticket, a review, a renewal. The pages below are the order you'd meet them.
The conversational layer.
A single bar on every screen. Bramm knows your policies, your suppliers, your access matrix and your tickets — and refuses to invent. He cites the source, answers in your team's language, and replies in seconds.
- →Grounded in your tenant — never the open web
- →Citations on by default, source chips on every answer
- →Visibility tiers per data area, set by the ISO

Talk to your handbook.
Today policies are read — rarely. With Bramm they're asked, constantly. The path from "I have a question" to "I have an answer" collapses from twenty minutes of scrolling to eight seconds of typing.
- →Per-policy ownership, change proposals, AI-summarised diffs
- →Acknowledgements per user, per version, with one-click ack
- →Per-department and per-entity visibility, out of the box

Every agent. Owned, reviewed, and audit-ready.
AI agents act autonomously — but they still need an owner, documented access rights, and a periodic review. Bramm tracks every agent your organisation has deployed: what it can do, what it can access, and whether that still makes sense.
- →Risk-tiered review cadence — Critical agents reviewed every 3 months, with access verification built into every review
- →Each agent's access rights appear in the Authorisation Matrix alongside your people — one view, two kinds of identity
- →Add, edit, and remove agents through configurable approval workflows — every change is a ticket, every ticket has an audit trail

A third-party register that runs itself.
Reviewed on cadence by risk. Certifications tracked with expiry reminders. Edits stage a diff for approval. Offboarding revokes access in the matrix and archives the file.
- →Six-question default review, fully editable with conditional logic
- →Certification reminders 30 / 7 / 0 days out
- →Setup mode for bulk-add with a single approval at the end

An asset register that knows what needs attention.
Most asset registers are spreadsheets that age badly. Bramm's is a live record — every asset classified, every review scheduled, every change tracked. The ISO sees what's overdue before the auditor does.
- →Classification tiers — Public, Internal, Confidential, Restricted — with review cadence set per tier (24 / 12 / 6 / 3 months)
- →Every asset gets a unique prefix-based number (LPT, DSK, MNT, SRV...) and an assigned owner — unassigned assets surface immediately on the dashboard
- →Reviews trigger automatically as tickets (ARV prefix), route to the right reviewer, and close with a full audit trail — one click to see the evidence

Your ISMS calendar with teeth.
Bramm ships with 31+ ISO 27001-aligned recurring tasks on day one. Each task spawns an occurrence, gets a nudge, captures evidence, routes to a reviewer, closes with an audit trail.
- →12-month grid view — the whole year in one screen
- →Configurable nudges per recipient and channel
- →Every occurrence gets its own ticket number

Scheduled, tracked, and closed with evidence.
Most compliance tools leave reviews to spreadsheets and good intentions. Bramm runs them — across access, suppliers, and assets.
Access reviews
A yearly calendar sets which months each risk tier gets reviewed. When a period opens, Bramm creates one ticket per supplier with the matrix state frozen as a snapshot — mismatches resolved inline.
Yearly calendar view with TARGET / PROGRESS tracking per risk tier. Snapshot frozen at review start.
Supplier reviews
Frequency per risk level, fully editable. Each period produces one parent ticket — so when an auditor asks for Q3, you hand them one document.
One ticket per period. Questionnaire with conditional logic. Reminders at 30, 7, and 0 days.
Asset reviews
Cadence driven by classification tier, every value editable. The reviewer confirms location, owner, and condition — you control who gets assigned.
Frequency by classification. Custom categories and prefixes. Configurable reviewer and assignee roles.
- →All frequencies are editable — set them once to match your organisation's risk appetite, adjust any time
- →Every review closes with a parent ticket that serves as the auditor's evidence package for that period
- →Reminders are fully configurable per review type — who gets notified, when, and through which channel
- →Mismatches, rescheduled reviews, and exceptions are captured inline — nothing lives outside the system
Workflows & agentic tickets
Jira's work, without Jira.
Eleven shipped workflows — onboarding, offboarding, supplier reviews, access requests, policy changes — all follow the same five steps. The output looks like a champion built it. The work was zero.

You start it.
One short form. Who, what, when. No ticket boilerplate, no choosing approvers, no field hell.
Bramm builds the ticket.
Title, description, audit trail, links to policies, suppliers and the matrix — populated. The best Jira ticket your org has ever seen.
Bramm assigns approvals.
Reads the matrix and your role config. Enforces separation of duties — the requester cannot also approve, cannot also provision.
Bramm fans out provisioning.
Provisioning tasks land with all system admins on the matrix for that system. Any of them can complete it. One click each.
Bramm closes it cleanly.
When the last task is done, it moves to Done with the full trail attached. Ready for an auditor to read in one sitting.
Average mid-market org runs ~50 access requests a quarter. From three hours of human time to roughly twenty minutes — about €8,000 saved per quarter on access alone, before onboarding and supplier reviews.
Bramm Insights
What your team doesn't yet know.
Every question Bramm receives is a quiet signal. Insights surfaces the topics employees keep guessing about, the policies that aren't landing, and the gaps that haven't become incidents yet — with a one-click action attached to each one.
24 people in Sales asked about WhatsApp this month.
Your Data Sharing & Messaging policy doesn't mention it. Bramm suggests an update.
Engineering asked about MFA 17 times.
A reminder might land better than another policy revision.
3 suppliers have no owner.
Open the assign workflow — Bramm has the right candidates ready.

