Skip to content

Client & Engagement Management

How to create and manage client profiles, set up Letters of Engagement, and track engagement milestones and financials.

Updated View as Markdown

The Engagement Hub is the central dashboard for managing your portfolio of clients and engagements. It provides a hierarchical view: each Client contains one or more Letters of Engagement (LOEs), and each LOE contains one or more Assessments.

Screenshot of Engagement Hub Dashboard

Client Management

Creating a Client

Screenshot of Client Creation Dialog

Open the Engagement Hub

Navigate to Engagement Hub from the left sidebar.

Click New Client

Click + New Client in the top-right corner to open the creation dialog.

Fill in Required and Optional Fields

The only required field is the Company Name. Fill in as much detail as available:

Primary Contact:

Field Description
Contact Name Main point of contact at the client organization
Contact Email Primary email for correspondence
Contact Phone Direct phone number

Business Information:

Field Description
Industry Business classification (e.g., Retail, Financial Services, Healthcare, E-Commerce)
Website Company URL
Company Size Employee count bracket (1–50, 51–200, 201–1000, 1001–5000, 5001+)
Address Full mailing address
Tax ID EIN, VAT number, or company registration number

PCI DSS Context:

Field Values / Description
Merchant ID The client’s Merchant Identification Number (MID)
Acquirer Name The acquiring bank or payment processor (e.g., Chase Paymentech)
Merchant Level Level 1 (>6M transactions), Level 2 (1–6M), Level 3 (20K–1M e-commerce), Level 4 (<20K e-commerce or up to 1M other)
Annual Transaction Volume Estimated annual card transaction count
PCI Compliance Status Current standing: Compliant, Non-Compliant, In Progress, Not Assessed
Last Compliance Date Date of most recent successful PCI compliance validation

Additional Contacts:

Contact Type Fields
Technical Contact Name, Role (e.g., IT Security Manager), Email, Phone
Billing Contact Name, Email, Phone

Save the Client

Click Create. The client is added to your Engagement Hub and is ready for LOE creation.

Client Profile Page

Screenshot of Client Profile Page

After creation, clicking a client’s name opens their profile page. The profile contains:

  • Header — client name, industry badge, active/inactive status
  • Stats Cards — Active LOEs, Total Assessments, Total Contract Value
  • LOEs Tab — a table of all Letters of Engagement with LOE number, title, status, date range, contract value, and assessment count
  • Info Tab — full client details organized by category (contacts, business info, PCI context, notes)

Editing a Client

From the client profile, click the Edit button in the header. The edit dialog opens with all current values pre-populated. Make changes and click Save.

Removing a Client

From the client profile, click the trash icon button in the header. A dialog presents two options:

Option What Happens
Set as Inactive The client is marked as inactive and hidden from default views, but all data (LOEs, assessments, files) is preserved. You can reactivate the client later by editing their status back to Active
Delete Permanently The client record is permanently removed from the database. This action cannot be undone

Letter of Engagement (LOE) Management

The LOE is the contractual container that sits between a client and one or more assessments. It captures scope, timeline, financial terms, and QSA signer details.

Creating an LOE

Screenshot of LOE Creation Form

Creating an LOE opens a full-width, 7-step tabbed wizardDetails → Engagement → Scope → Timeline → Payment → Terms → Signatures — with a pinned Back / Next / Save action bar. Editing an LOE reuses the same wizard, pre-filled with the current values.

Open the Client Profile

Navigate to the Engagement Hub and click on the client name.

Click Add LOE

Click + Add LOE from the client profile page. The LOE creation form opens.

Fill in Core Details

Field Required Description
Title Yes Descriptive engagement name (e.g., “2026 Annual PCI DSS ROC Assessment”)
Description No Detailed engagement summary
Start Date Yes Engagement start date
End Date Yes Engagement end date
Contract Value No Total engagement fee in selected currency
Currency No Defaults to USD
Assessment Type No Type of assessment (e.g., Full ROC, Targeted, Gap Analysis)

The platform auto-generates a unique LOE Number in the format LOE-YYYY-NNN (e.g., LOE-2026-001).

Define the Scope

Field Purpose
In-scope summary Systems, processes, and locations included in the assessment
Out-of-scope summary Explicitly excluded items
Methodology Assessment methodology description

Add Assessment Locations

Click + Add Location to define each physical or virtual location where assessment activities will occur:

Field Description
Name Location name (e.g., “Main Data Center”)
Type Headquarters, Data Center, Office, Retail, Cloud, Colocation
Address, City, State, Country Physical address details

Multiple locations can be added. Each appears as a row in the locations table.

Set Milestone Dates

Define the engagement timeline by filling in key milestone dates:

Milestone Description
Kickoff Date Project start meeting
Onsite Start / End On-location assessment window
Draft Report Date Target date for draft ROC delivery
Remediation Start / End Window for the client to address findings
QA Review Start / End Internal QA review period
Final Report Date Final ROC delivery target

These milestones power the progress tracking and phase indicators on the LOE detail page.

Configure Financial Terms

Field Description
Billing Type Fixed Price, Hourly, Monthly Retainer, or Milestone-based
Payment Terms (Net Days) Payment due within N days (0–365)
Late Interest Rate Percentage charged on overdue invoices (0–100%)
Travel Expenses Budget Allocated budget for on-site travel

Payment Schedule — define milestone-based payments:

Milestone Percentage Due Condition
Kickoff 30% Upon project start
Draft Report 40% On draft ROC delivery
Final Report 30% On final ROC delivery

Click + Add Milestone to add rows. Each milestone requires a name and a percentage of the total contract value.

Add Legal Terms and QSA Signer

Legal Terms:

Field Description
Roles & Responsibilities Defined responsibilities for QSA firm and client
Limitation of Liability Liability cap and exclusions
Confidentiality Terms NDA and data handling provisions
Liability Cap Amount Maximum monetary liability
Stop-Work Evidence Days Days allowed for evidence collection if work is halted
Reactivation Fee Fee to restart a paused engagement

QSA Signer:

Field Description
QSA Name Lead assessor’s full name
QSA Title Professional title
QSA Certifications Certificate number and qualifications
QSA Signed Date Date the QSA signed the LOE

Client Signer:

Field Description
Client Signer Name Authorized signatory name
Client Designation Signatory’s title or role

Save the LOE

Click Create LOE. The LOE is created with the auto-generated LOE number and linked to the client.

LOE Detail Page

The LOE detail page provides a comprehensive view organized into tabs:

Tab Contents
Overview Key metrics — contract value, timeline progress, owner, assessment count
Scope & Terms Scope summary, inclusions/exclusions, assessment locations, in-scope components, and legal terms
Timeline Milestone dates with visual progress tracking and days remaining
Assessments Table of linked assessments with status and compliance score
Documents Uploaded LOE document and related files

Payment and signature details are rendered inside these tabs (Overview / Scope & Terms), not as standalone tabs.

Screenshot of LOE Detail Page

Editing an LOE

From the LOE detail page, click Edit. You are taken to the edit form pre-populated with all current values. All fields can be modified after creation.

In-Scope Components

Define the categories of systems and technologies that fall within the assessment scope:

Category Example Items
Applications Payment gateway, e-commerce platform, CRM
Databases PostgreSQL, Oracle, MongoDB
Network Firewalls, switches, routers, VPN concentrators
POS Hardware Card readers, POS terminals, PIN pads
Processes Change management, incident response, access provisioning
Cloud Services AWS VPC, Azure AD, GCP Cloud SQL

Each category supports multiple items. Click + Add Item within a category to list specific components.

Required Documentation

Pre-define the documents the client must provide during the assessment:

Document Required Description
System Architecture Diagram Yes Current network and system topology
Data Flow Diagram Yes Cardholder data flow documentation
Firewall Rulesets Yes Current firewall configurations
Access Control Policy No Written access management procedures

Click + Add Document to add rows. Each entry includes a name, optional description, and a required/optional flag.


Engagement Phases

The LOE detail page shows a read-only phase ribbon derived from the milestone dates — a quick view of where the engagement stands. Each phase is marked done, active, or queued.

Default Phase Sequence

Phase Driven By
Scoping Kickoff Date
Evidence Collection Onsite Start → Onsite End
Testing & Drafting Draft Report Date
Remediation Remediation Start → Remediation End
QA Review QA Review Start → QA Review End
Final Report Final Report Date
Screenshot of Engagement Phases Timeline

Engagement Hub Dashboard

The Engagement Hub landing page provides an at-a-glance view of your entire portfolio:

Metric Description
Total Clients All clients in the organization
Active Clients Clients with at least one active LOE
Total LOEs All Letters of Engagement
Active LOEs LOEs with status “Active”
Total Assessments Sum of assessments across all LOEs
Total Contract Value Sum of all active LOE contract values

The dashboard includes:

  • Search — filter clients by name or industry
  • Recent LOEs — quick access to recently active engagements with progress indicators (days remaining, percentage complete)
  • Client Cards — each client shows their active LOE count, assessment count, and total contract value

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close