Luftic User Manual
Welcome to Luftic, a governance, risk, and compliance (GRC) platform built for organizations in the GCC. Luftic brings your risk register, compliance frameworks, controls, policies, audits, incidents, and third-party vendors into one bilingual workspace that works fully in Arabic and English.
This manual is for everyone who works in your organization's Luftic workspace — from team members who complete tasks and approvals, to risk and compliance managers, auditors, and the administrators who set up users, roles, and settings. It describes what you see on screen and how to get things done, step by step.
What You Can Do in Luftic
| Area | What it helps you do |
|---|---|
| Risk management | Identify, assess, treat, and monitor risks, and link them to the assets and controls they affect. |
| Incidents | Report, investigate, and resolve security and operational incidents, including regulatory notification deadlines. |
| Assets | Keep an inventory of the systems, data, and facilities you need to protect. |
| Compliance | Activate frameworks such as NCA ECC, PDPL, NESA, and SAMA, run compliance assessments, and track readiness. |
| Controls | Maintain your control catalogue and internal controls, assign them to owners, and monitor them continuously. |
| Policies | Draft, approve, publish, and collect attestations for organizational policies, and manage exceptions. |
| Audit & assurance | Plan and run internal audits, record findings, and collect evidence through evidence requests. |
| Third-party risk | Assess vendors and send them questionnaires. |
| Access & identity | Manage users, departments, roles, and access reviews such as Separation of Duties checks. |
| Automation & analytics | Route work through approval workflows, track SLAs, save reusable views, and produce reports. |
What you see in the sidebar depends on the permissions your role grants, so some areas may not appear for you.
Where to Start
Pick the path that matches your job:
- Everyone — read Getting Started to sign in and learn your way around, set up your profile, then check the Workflow Inbox (My Work) and Tasks for anything waiting on you. Your Dashboard gives you a personal overview.
- Risk managers — start with Risks, then Incidents.
- Compliance managers — start with Compliance, Frameworks, Controls, and Policies.
- Auditors — start with Internal Audit and Evidence Requests.
- Vendor risk managers — start with Vendors.
- Organization administrators — set up Departments, invite people from Users, shape access with Roles and Access Reviews, then configure Settings and Workflows.
Getting Help
- Field help icons — many form fields show a small ? icon next to their label. Click it for a short explanation of what to enter and why it matters. Where available, the explanation includes a Read full documentation link that opens the matching section of this manual.
- AI Advisor — click the sparkle icon in the top bar (or choose Ask AI Advisor in search) to ask questions in English or Arabic, such as "how do I assign a control?" or "which of my risks are overdue?". See AI Advisor.
- Guided tour — open your user menu (your name in the top-right corner) and choose Take the tour for a short walkthrough of the main areas.
- Your administrator — if a menu item or button you expect is missing, you probably don't have the permission for it. Ask your organization's administrator to review your role.