> For the complete documentation index, see [llms.txt](https://intuitem.gitbook.io/ciso-assistant/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://intuitem.gitbook.io/ciso-assistant/configuration/settings/feature-flags.md).

# Feature flags

Feature flags turn whole product areas on or off. They're how you tailor the navigation and the surface area to what your team actually uses, and how you keep experimental or specialised features out of sight until you want them.

Flags affect what's visible in the sidebar, what appears in CRUD pages, and which permissions are even relevant. They do **not** delete any underlying data — turning a flag off hides the feature; turning it back on restores the UI as it was.

## Operations

* **xrays** — the X-rays inconsistency-detection page.
* **incidents** — incident management.
* **tasks** — the task-management module (one-off and recurring tasks).
* **control\_plan** — the consolidated control-plan view across applied controls.
* **workflows** — the [workflow builder](/ciso-assistant/features/workflows.md): automation on a schedule, an event or a webhook. *Default off.*

## Governance

* **risk\_acceptances** — the risk-acceptance workflow.
* **exceptions** — security-exception tracking.
* **follow\_up** — [findings binders](/ciso-assistant/concepts/governance/findings-assessments.md) and the standalone **Findings** list.
* **findings\_from\_requirements** — adds a **Findings** tab on a requirement assessment, so a finding can be raised straight from an audit. The audit's findings are collected in a binder created on first use. *Default off.*
* **commitment\_management** — [commitments](/ciso-assistant/concepts/operations/commitments.md): the delivery date an owner promises on an applied control or a one-off task, and its renegotiation. *Default off.*
* **validation\_flows** — configurable approval workflows that mirror internal review or management-approval processes, attached to objects whose state changes warrant sign-off. *Default off.*
* **organisation\_issues** — context register: issues affecting the organisation.
* **organisation\_objectives** — context register: organisational objectives.
* **policy\_documents** — the dedicated Policies surface (a filtered view of applied controls).
* **quick\_forms** — labelled **Forms and Requests**: [quick forms and the requests they raise](/ciso-assistant/concepts/governance/quick-forms.md). Turns on **Published forms**, **My requests** and the **Requests** queue. *Default off.*
* **document\_management** — the standalone [Documents](/ciso-assistant/concepts/governance/documents.md) module: the reading catalogue, document list, and templates. Author or upload documents through a draft → published lifecycle, independent of policies.

## Risk

* **ebiosrm** — the EBIOS RM module.
* **scoring\_assistant** — the OWASP-based scoring assistant.
* **vulnerabilities** — vulnerability tracking.
* **quantitative\_risk\_studies** — Monte-Carlo quantitative risk.
* **inherent\_risk** — surface inherent-risk columns alongside residual risk on assessments. *Default off.*
* **threat\_modeling** — the threat-modeling surface. *Default off.*

## Compliance

* **compliance** — compliance assessments (audits). Effectively master switch for the entire compliance pillar.
* **auditee\_mode** — the auditee surface external respondents land in.
* **campaigns** — [campaigns](/ciso-assistant/features/campaigns.md): bulk-orchestration of assessments, either across your own perimeters or across a set of third parties. *PRO.*
* **audit\_tree\_inheritance** — combine an audit's results with parent-domain audits on the same framework. Reveals the **Domain inheritance strategy** [general setting](/ciso-assistant/configuration/settings/general.md#domain-tree-audit-inheritance) and the **Combined view** on the [Framework report](/ciso-assistant/features/framework-report.md#combined-view-domain-tree-inheritance). *Default off.*
* **posture\_assessments** — [technical postures](/ciso-assistant/concepts/compliance/technical-postures.md): continuous measurement of assets against technical baselines (CIS Benchmarks, hardening guides) with recurring scan results. *Default off.*

## Resilience

* **bia** — business impact analyses.

## Third-party and privacy

* **tprm** — third-party risk management.
* **contracts** — contracts surface inside TPRM. *Default off.*
* **dora** — the DORA-specific fields on entities, solutions, assets and contracts, plus the [DORA reporting](/ciso-assistant/features/framework-specific/dora.md) capabilities.
* **external\_ratings** — [external ratings](/ciso-assistant/concepts/specialised-modules/third-party-risk.md#external-ratings): record scores published by rating services (SecurityScorecard, Bitsight, CyberVadis, …) against your third parties. *Default off.*
* **privacy** — the privacy register pillar (master switch).
* **personal\_data** — personal-data inventory inside the privacy register.
* **purposes** — purposes register.
* **right\_requests** — data-subject right requests.
* **data\_breaches** — data-breach tracking.

## Catalog

* **security\_advisories** — the security advisories catalogue.
* **cwes** — the CWE catalogue.
* **ttps** — the TTP catalogues (MITRE ATT\&CK, ATLAS): tactics and techniques. *Default off.*

## Metrology and reporting

* **metrology** — metric definitions, instances, and dashboards.
* **reports** — the reports surface. *Default off.*
* **advanced\_analytics** — Per-audit [Advanced Analytics](/ciso-assistant/features/audit-analytics.md) dashboard (compliance by section, controls coverage, timeline, evidence coverage, threats, exceptions).

## Integrations and automation

* **outgoing\_webhooks** — outgoing webhooks. *Default off.*
* **audit\_log\_forwarding** — [forward the audit log](/ciso-assistant/ai-and-integrations/audit-log-forwarding.md) to an external SIEM over HTTP or Kafka. *PRO. Default off.*
* **jit\_provisioning** — [SSO auto-provisioning](/ciso-assistant/configuration/sso.md#auto-provisioning-jit): auto-create an account on a user's first SSO login. Also unlocks the **IdP groups** menu and the **IdP groups** column on the users table (see `idp_groups` below), so auto-provisioned users can inherit roles through IdP group mapping.
* **idp\_groups** — [SCIM 2.0 provisioning and IdP group mapping](/ciso-assistant/configuration/sso/scim.md): the SCIM settings tab, and — same as `jit_provisioning` above — the IdP groups menu and the IdP groups column on the users table. *PRO.*
* **service\_accounts** — [service accounts](/ciso-assistant/ai-and-integrations/service-accounts.md) for machine-to-machine API access via OAuth2 client credentials. *PRO.*
* **chat\_mode** — the in-product chat assistant. *Default off; only visible when `ENABLE_CHAT` is set on the instance.*
* **infra\_config\_management** — the [allowed-IP whitelist](/ciso-assistant/configuration/settings/infra-config-allowed-ip.md) settings tab. *Only visible when `ENABLE_INFRA_CONFIG_MANAGEMENT` is set on the instance.*
* **terminologies** — organisation-specific label overrides.
* **custom\_fields** — org-defined typed fields on objects (Projects, Assets, Applied controls); see [Custom fields](/ciso-assistant/features/custom-fields.md). *PRO. Default off.*

## Project management

* **project\_management** — projects, accreditations, responsibility matrices. *Default off.*

## Workflow

* **journeys** — preset journeys for bootstrapping new organisations or domains.
* **comments** — comments on objects.
* **object\_audit\_trail** — per-object [audit trail](/ciso-assistant/features/audit-log.md#per-object-audit-trail) button on detail pages, gated by the **Can view object audit trails** permission. *PRO.*
* **focus\_mode** — UI mode that filters the entire workspace to a single domain. *PRO. Default off.*

## Publishing

* **custom\_portals** — [portals and trust center](/ciso-assistant/features/portals.md): the **Manage portals** admin surface and the public pages it publishes. *Default off.*

## Experimental

* **experimental** — feature-gate for the experimental area. Use with caution.

> Defaults marked *Default off* are off in fresh installs. Everything else defaults to on. Restart isn't required when a flag is toggled, but a hard refresh in the browser is.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://intuitem.gitbook.io/ciso-assistant/configuration/settings/feature-flags.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
