PLATFORM STRUCTURE EXPLAINED
What the Zebsoft Assurance Platform Comprises
One Connected Structure for Governance, Operation and Evidence
The Zebsoft Assurance Platform comprises a shared operating structure, configurable domains, reusable capabilities, controlled portals and ZAP validation workflows. Together they connect what an organisation expects with what people do, the evidence produced and the assurance decisions that follow.

THE SHORT ANSWER
A Platform—not a Stack of Separate Compliance Tools
Zebsoft brings governance information, operational activity, validation and evidence into one connected assurance environment. The platform provides the common structure. Domains apply that structure to a subject. Capabilities perform reusable functions. Portals involve the right people. ZAP workflows make activity and exceptions visible.
This distinction matters because buyers frequently compare platforms by counting modules. A long list of functions does not show whether they share context or influence one another. Zebsoft is organised so a risk can affect controls, workflows, audits, training or supplier reviews; a failed check can create an exception and corrective action; and a management view can lead back to the evidence and judgement supporting it.
THE FOUR STRUCTURAL LAYERS
From Organisational Intent to Evidence-backed Oversight
The platform can be understood as four connected layers. Each has a different purpose; assurance depends on retaining the links between them.

BUILT AROUND OPERATIONAL REALITY
Each Layer Answers a Different Question
A policy can define an expectation, but it cannot prove that the expected activity occurred. A completed task can show activity, but it may not prove that the control was effective. A dashboard can summarise status, but it is useful only when the user can trace it to the underlying workflow, evidence and human judgement.
Zebsoft preserves these distinctions while keeping the information connected. That prevents “everything in one place” from becoming a larger repository with the same assurance gaps.
THE OPERATING MODEL
Define, Communicate, Operate and Assure
The structural layers describe what the platform contains. Define, Communicate, Operate and Assure explains how information should move through it.
Requirement → context and risk → owned control → workflow operation → evidence → human verification → exception or assurance
STATIC GOVERNANCE. DYNAMIC ASSURANCE.
Defined Information Provides Direction. Activity Tests Reality.
A useful management system requires both. Static information establishes the approved position; dynamic information reveals whether that position is being operated and where it has failed.
CONNECTED BY DESIGN
Relationships Make the Information Operational
Connection means more than placing records in the same interface. The relationship should help determine what happens next.
Connected records explain relationships. Governed workflows make those relationships operate.

DOMAINS PROVIDE OPERATIONAL CONTEXT
Different Subjects. One Shared Assurance Structure.
A domain organises relevant capabilities around a real operational subject. It provides the terminology, relationships, risk context, workflow and management views needed by the people responsible for that area.
Domains do not need separate copies of the same audit, risk or document function. They use the shared capabilities of the platform while preserving their specialist context and competent judgement.
CAPABILITIES ARE THE REUSABLE ENGINES
Functions That Work Across the Platform
Capabilities perform recurring operational functions. Their shared use is what allows one activity or evidence source to contribute to several connected purposes.

ZAP OPERATIONAL VALIDATION
Use Workflow to Test Whether Expectations Are Being Met
ZAP validation is not a separate repository. It is the configured activity through which the platform requests, observes and verifies operation.
Automation moves the approved process forward. It does not invent evidence or replace accountable human judgement.
CONTROLLED PARTICIPATION
Bring the Right People Into the Right Part of the Process
Assurance depends on information and action from people beyond the core management team. Portals provide an appropriate route without exposing the complete internal platform.
OVERSIGHT WITH TRACEABILITY
See the Position—and the Basis for It
Management views bring together risk, control performance, overdue activity, findings, actions and exceptions. The value lies in being able to move from the summary to the source workflow, evidence and human judgement.
AI may help users interrogate and summarise approved information. It has no authority to invent controls, evidence, approvals or assurance conclusions.

AN ASSURANCE LAYER ABOVE SPECIALIST SYSTEMS
Connect the Context Without Replacing Every Tool
Organisations already use specialist systems for finance, HR, security, maintenance, production and other operational work. Zebsoft does not need to duplicate those functions to govern the assurance surrounding them.
The platform is the organisational assurance layer: it connects what specialist tools do to the governance, people and decisions surrounding their use.
THE STRUCTURE AT A GLANCE
Platform, Domain, Capability, Portal and ZAP
These terms describe different parts of the same connected system. This table provides the simplest working distinction.
| Term | What it means in Zebsoft | Typical examples | Why it matters |
|---|---|---|---|
| Platform | The shared assurance architecture, information model, access, workflow, evidence and oversight environment. | Zebsoft Assurance Platform | Keeps domains and capabilities connected rather than creating separate systems. |
| Domain | A structured operational context that combines relevant capabilities around a subject. | Quality, safety, environmental, information security, suppliers and assets | Gives the shared functions the terminology, relationships and workflows needed for real use. |
| Capability | A reusable functional engine available across domains. | Audit, risk, documents, incidents, actions, training, equipment and workflows | Avoids rebuilding the same operational function separately for every subject. |
| Portal | A controlled participation route for people who should not enter the complete internal system. | Employee, supplier, contractor and customer participation | Brings communication, tasks and evidence to the people expected to act. |
| ZAP validation | Configured workflows, checks, schedules, evidence and escalation that test whether expectations are being operated. | Approvals, recurring checks, inspections, evidence requests and effectiveness reviews | Turns defined governance into visible operational assurance. |
Consider an organisation operating quality, health and safety and supplier assurance. Each domain may need audits, risk assessments, controlled documents, actions and competence records. A disconnected approach creates three versions of those functions and forces management to reconcile them later. Within Zebsoft, the domains can use the same capability engines and shared organisational information while retaining different requirements, evidence standards, responsible specialists and assurance outputs.
A supplier incident, for example, may affect product quality, worker safety and continuity. The platform preserves one source event and connects it to the risks, controls and workflows affected in each domain. The quality manager, safety professional and supplier owner can make separate competent judgements without recreating the incident or losing the wider context. Management can then see the combined organisational significance while still tracing each conclusion to its relevant evidence and responsible person.
This is the practical purpose of the hierarchy: shared structure where duplication adds no value, and preserved context wherever scope, expertise or accountability differs. It also makes phased adoption easier because new domains reuse proven platform capabilities rather than starting again.

ADOPT THE STRUCTURE IN STAGES
Start With the Assurance Need—not Every Possible Function
Organisations can establish the platform around a focused requirement and expand as the shared structure proves useful. The objective is controlled adoption, not switching on every domain and capability at once.
Configuration and migration scope depend on organisational priorities, current information quality, required history, permissions and the workflows selected.
CHOOSE THE RIGHT NEXT PAGE
Move From Structure to the Detail You Need
This page explains the architecture. The following routes provide the commercial proposition or deeper detail.
PRACTICAL QUESTIONS
Zebsoft Assurance Platform Structure FAQs
The exact configuration depends on the organisation, domains, responsibilities and assurance outcomes required.
What is the Zebsoft Assurance Platform?
The Zebsoft Assurance Platform is the shared environment connecting governance, domains, capabilities, workflows, participants, evidence and management oversight. It is intended to help organisations operate and interrogate assurance rather than maintain a collection of disconnected records.
Is a domain the same as a module?
No. A domain is the operational context, such as quality, health and safety or information security. A capability is a reusable function, such as audit, risk or document control, that can support several domains.
What is ZAP?
ZAP is the operational validation approach within the platform. Configured workflows, schedules, checks, evidence requests, reviews and escalation help show whether defined controls and responsibilities are being operated.
Does Zebsoft replace every specialist business system?
No. Specialist finance, HR, technical, security, maintenance or operational systems should continue to perform work for which they are designed. Zebsoft provides a connected assurance layer around requirements, responsibility, workflow, evidence and decisions.
Can one capability support several domains?
Yes. Audit, risk, document control, incidents, actions, training and other capabilities can be used across several domains. Shared operation reduces duplication while each domain retains its own context and competent judgement.
Can employees and external parties participate?
Yes, where portals and permissions are configured. Employees, suppliers, contractors or customers can receive relevant communication, complete assigned activity and provide evidence without being given unrestricted access to the internal platform.
Does the platform guarantee compliance?
No software can guarantee compliance, certification or control effectiveness. Zebsoft supports approved workflows and traceable evidence. Competent and authorised people remain responsible for interpretation, risk, control design, verification and formal conclusions.
Where should I go next?
Use the platform page for the overall proposition, Domains Explained to explore operational subjects, Modules to review reusable capabilities, and the relevant standards page where your main interest is a specific ISO or regulatory framework.
ONE PLATFORM. CONNECTED ASSURANCE.
See How the Structure Fits Your Organisation
Explore the platform independently or ask Zebsoft to demonstrate how your domains, capabilities, participants and evidence could work through one connected assurance model.

