Complete capability reference Evidence-led assurance API-first

Citadel — Complete Platform Capability Reference

An assessment-driven integrated risk management platform that derives risk from the real-world performance of controls — giving organisations an evidence-based, continuously updated view of operational and strategic risk across sites, assets, people and activities. This page sets out the platform's full documented capability set.

Citadel by arx Partners

Citadel at a Glance

Evidence-driven risk — risk is derived from assessments and control performance, not manually maintained registers.
Flexible model — groups, sites, assets and controls mirror your organisation, from a single site to a global multi-domain estate.
Adaptive assessments — a central Bank of Questions, a Question Set builder and AI-assisted question set generation.
Configurable scoring — weighted models, reply scores 0–6, and Threat Vector multipliers for site and asset criticality.
Decision-ready dashboards — Events Map, risk heat maps, trends and comparative reporting at every level.
Open by design — API-first integration, Microsoft Power BI, and export to PDF, Excel and CSV.
Defence-grade security — granular RBAC, SSO/MFA, comprehensive audit logging.
Classification-ready — supports customer-managed deployments at different classifications, including physically separated and fully air-gapped environments.
Complete traceability — every executive report drills back to the original evidence.
Browser-based — no local installation; desktop, tablet and mobile. Continuous assurance that evolves as conditions change.

1Introduction

Citadel dashboard showing active emergency response, assessment activity and strategic risk distribution
The Citadel dashboard — a common operational picture spanning assessments, emergencies, risk and reporting.

Citadel provides organisations with a clear, evidence-based understanding of operational and strategic risk across sites, assets, people and activities. Unlike traditional risk registers that rely on periodic reviews and manual updates, Citadel derives risk directly from the performance of controls in the real world. Assessments, inspections, audits and operational activity continuously update the organisation's view of risk, so decision makers see current operational conditions rather than historic assumptions.

By linking evidence, control performance, operational findings and risk within a single platform, Citadel provides a common operational picture supporting informed decision making at operational, tactical and strategic levels.

It is designed for complex, highly regulated and security-sensitive environments including critical national infrastructure, defence, transportation, security operations, facilities management and corporate assurance programmes.

Configuration, not custom code
Citadel is entirely configuration driven. Organisations can configure their own assessment frameworks, scoring models, workflows, permissions, reporting, notifications and dashboards without bespoke software development.

2Platform Principles

Diagram of Citadel platform principles showing how risk is derived from evidence and control performance
Citadel derives a live, evidence-based view of risk from control performance.

Seven practical principles reflecting how assurance and risk management operate in modern organisations:

  • Risk reflects operational reality — assessments, inspections, audits and control performance maintain an up-to-date understanding of exposure based on current evidence, not historic assumptions or infrequently reviewed registers.
  • Define controls once, reuse everywhere — controls link to multiple sites, assets, risks and assessment types, improving consistency, reducing duplication, and propagating changes wherever the control is used.
  • Capture evidence at the point of activity — photographs, documents, observations and supporting information are recorded during assessment, improving accuracy and creating a defensible audit trail to source.
  • Collect data once, reuse many times — information from routine assurance activity supports operational management, compliance reporting, trend analysis, executive dashboards and BI without re-entry into different systems.
  • Continuous assurance, not periodic — assessments and operational activity continuously contribute to understanding of performance and exposure as risk changes over time.
  • Reporting becomes decision support — dashboards and reports highlight what changed, where attention is required and which actions to prioritise.
  • Scale without losing clarity or control — supports a single site, a national estate or a globally distributed organisation with consistent governance, reporting and oversight at every level.

Together these create a living view of organisational risk and assurance — an evidence-based picture that evolves as conditions change and new information becomes available.

3Core Platform Components

Diagram of Citadel core components: groups, sites, assets, controls, assessments, users and risks
The core building blocks: groups, sites, assets, controls, assessments, users and risks.

A small number of composable core components mirror how organisations actually manage assurance, compliance and risk — supporting anything from a single site to a globally distributed operation spanning multiple business units, contracts and security domains. Citadel can use AI to identify sites, assets, users, groups and organisational structures from existing data sources and prepare that information for direct import, significantly reducing initial deployment and ongoing administration effort.

3.1 Groups

Groups give Citadel its flexible organisational model, representing regions, business units, operational commands, contracts, programmes, customers or any meaningful boundary — without rigid imposed hierarchies. Examples: corporate divisions, geographic regions, operational commands, business units, contracts, programmes, customer portfolios.

Corporate GroupRegionBusiness UnitSiteAsset
CommandFormationStationBuildingAsset

Groups support complex visibility and ownership models — access driven by responsibilities and relationships, not hierarchy alone. Group-based governance, permissions, notifications and reporting are provided as standard, allowing delegation while maintaining enterprise-wide visibility. The group model evolves as organisations grow or restructure, without changing the underlying data model.

3.2 Sites

Assurance information is collected, managed and reported at site level. Sites may be physical locations, operational areas or logical entities — offices, airports, military establishments, stadiums, data centres, warehouses, offshore facilities, ports and marinas. Sites belong to one or more groups and may be organised geographically, operationally or contractually. Each site carries a complete operational picture — assurance history, vulnerabilities, trends, compliance performance and risk exposure — while contributing to regional and enterprise reporting.

3.3 Assets

Both fixed and mobile assets are supported — buildings, control rooms, vehicles, boats and vessels, aircraft, communications equipment, critical infrastructure, IT systems. Assets inherit context from their parent site while maintaining their own assurance history, operational records and risk profile, so organisations understand both site health and the individual components driving it.

3.4 Controls

Controls are defined once and applied wherever required through a reusable framework. They may be physical, procedural or technical — access control systems, CCTV coverage, security guarding, maintenance regimes, training programmes, policies and procedures, emergency plans, technical security controls. A single control can mitigate multiple risks across multiple sites, assets and activities simultaneously. As assessments complete and evidence is collected, Citadel automatically updates control effectiveness, keeping dashboards, reporting and risk exposure current.

3.5 Assessments and Surveys

A single framework supports inspections, surveys, audits, reviews and routine operational checks — compliance audits, security inspections, facilities checks, fire safety assessments, supplier assurance reviews, operational readiness inspections, training validation, accreditation exercises. Assessments may be scheduled, recurring, manually initiated, event-driven or generated automatically through workflows and business rules — supporting routine compliance, strategic assurance and incident-driven investigations without separate systems.

3.6 Users

One environment supports operational users, specialist teams, analysts, administrators and executive stakeholders — completing assessments, reviewing findings, managing actions, analysing trends or administering structures and workflows. Access is governed through role-based permissions, organisational structures and contextual visibility rules, supporting complex operating models across multiple business units, customers, contracts, programmes, operational commands and external suppliers while maintaining governance and information separation.

3.7 Risks

An evidence-driven approach: risk is derived directly from findings, evidence and control effectiveness in the real world rather than manually maintained scores or periodic reviews. Operational findings contribute to site risk, asset risk, business unit risk, programme risk, strategic risk, and executive/board reporting. As control performance changes and new evidence arrives, emerging risks become visible automatically, allowing intervention before issues become significant events.

4Question Sets

Screenshot-style view of the Citadel Question Set builder and Bank of Questions
Building assessments from the central Bank of Questions.

At the heart of the platform is a powerful assessment engine. Question sets are assembled from a central Bank of Questions using the Question Set builder, so standards are defined once and reused across the organisation — standardising inspections, audits, surveys and operational checks while retaining flexibility across environments, asset types, operating models and risk profiles.

AI-assisted question set generation

A built-in AI-assisted generator analyses existing procedures, policies, standards, audit reports, spreadsheets, checklists and operational documentation to identify questions, answer options, scoring methodologies, evidence requirements and decision logic, then automatically generates draft question sets. This accelerates onboarding new assurance activities and migrating existing inspections, audits and compliance processes into Citadel while maintaining alignment with established procedures and regulatory requirements. Generated sets can be reviewed, refined and enhanced by subject matter experts; output quality depends on source material quality, and models can be refined or trained to customer-specific terminology, standards and requirements.

Supported question types

Yes / NoSingle choiceMultiple choice Numeric entryFree textDate & time Image capture & uploadFile attachmentsLocation capture Electronic signatures

Questions can be mandatory or optional and may include guidance notes, scoring rules, validation criteria and evidence requirements to improve consistency and data quality.

Intelligent, context-aware questionnaires

Questions can be displayed, hidden or triggered automatically based on previous responses, so assessors only see what is relevant. Confirming a control operates correctly may need no further action, whereas a negative response can automatically trigger additional questions, mandatory comments, photographic evidence requirements, corrective actions or escalation workflows. Citadel can also present information already held — site details, asset details, historical findings and previous responses — including prior answers, comments, photographs and evidence for the same site, asset or control, helping assessors identify recurring issues, confirm previous corrective actions remain effective, and reduce duplication. Historical responses can be displayed alongside current assessments to support trend analysis and consistency.

The same adaptive framework supports simple routine inspections and highly complex assurance activities. Question sets can be updated and extended without affecting historical records — new questions, workflows and scoring methodologies can be introduced while preserving historical continuity and comparability.

The assessment experience

Save & resume — assessments can be started, saved and continued later, so long or multi-visit inspections don't have to be completed in one sitting.
Review before submission — assessors review their responses, and completed assessments can be subject to approval or additional QA before they are finalised.
Amendment & versioning — completed assessments can be reopened for correction or amendment, with the original submission and every revision preserved in a full audit history.
Compare with previous assessments — prior answers, comments, photographs and evidence for the same site, asset or control can be shown alongside the current assessment.
Historical answer history — a complete history of responses supports trend analysis, consistency between assessors and confirmation that corrective actions remain effective.
Non-scorable answers (N/A) — replies can be marked Not Applicable / non-scorable so they don't distort the score where a question doesn't apply.

5Scoring and Assurance

Diagram of Citadel configurable scoring flow from reply scores and weighting to section and report scores
Configurable scoring — reply scores, weighting and Threat Vector multipliers roll up to section and report scores.

Scoring is flexible and configurable. In the current implementation, individual replies are scored 0 to 6 in increments of 0.1 (or marked non-scorable), and Threat Vector multipliers in the range 0 to 10 (default 1) adjust outcomes for site and asset criticality.

Configurable scoring models

Scoring is not fixed — organisations select and configure the model that matches their assurance activity, and can weight questions by operational significance:

Compliance scoringMaturity scoringControl effectiveness scoring Risk-based scoringWeighted scoring models Threat Vector criticality multipliersNon-scorable (N/A) answers

Individual questions can contribute differently based on operational significance, regulatory importance or business impact — e.g. failure of a life safety system, perimeter control or critical security measure carries far greater weight than an administrative or housekeeping observation. Contextual and environmental scoring lets site criticality, asset importance, operational dependency and business impact influence how findings are interpreted and prioritised, so a minor issue at a critical national infrastructure site is treated differently from the same issue in a low-risk administrative environment.

Worked example
A failed perimeter CCTV question at a Tier 1 site scores 0 of a possible 6. Weighted as a critical control and multiplied by the site's Threat Vector rating, the finding immediately lowers the section and report scores, raises a corrective action, notifies the site security manager and appears on the regional dashboard — before the assessor has left the gate.

Scoring methodologies can be refined over time without impacting historical assessments or previously collected data. Citadel can also use AI to assist analysis of reports, findings, evidence and supporting documentation — identifying recurring themes, summarising large volumes of information, spotting emerging trends and supporting interpretation of outcomes. AI models may require training, tuning and validation against customer-specific data, terminology and procedures.

6Site Assurance

The site is where strategic policy becomes operational reality. Site assurance brings together information traditionally spread across multiple systems, spreadsheets and reports into a single, continuously updated operational picture. As standard, Citadel provides visibility of:

Current compliance statusOutstanding actionsOpen vulnerabilities Risk concentrationsDirection of travelControl effectiveness Historical trendsEmerging issues

Site performance can be visualised geographically through colour-coded maps and location-based reporting. Citadel highlights relationships between data points — a strong compliance score with rising overdue actions may need intervention; a concentration of low-level findings across controls may signal a systemic issue before a critical failure. The platform focuses on trajectory (improving, stabilising or deteriorating) as well as current status, with historical trends, comparative reporting and benchmarking. Sites can be compared against organisational averages, peer groups, contracts, regions or other units. Site-level dashboards give operational managers immediate visibility while contributing to group, regional, organisational and executive reporting — local ownership with enterprise oversight.

7Asset Assurance

Asset-level assurance reveals the condition, assurance status and operational impact of the individual assets supporting a site. An asset may be a building, control room, communications system, vehicle, vessel, aircraft, piece of critical infrastructure, information system or any item requiring protection, maintenance or assurance. Citadel provides a comprehensive assurance record for every asset:

Assessment historyControl performanceDefects & observations VulnerabilitiesMaintenance findingsEvidence records Improvement actionsIncident historyAssociated risks & mitigations

Assets inherit context from their parent site while maintaining their own operational history, assurance profile and risk exposure — so a site that looks healthy at headline level but has a few deteriorating critical assets is visible, as are recurring issues across similar assets at multiple sites indicating a systemic problem. Both fixed and non-fixed assets are supported within a common framework. A complete assurance history is maintained throughout an asset's operational life — assessments, maintenance, vulnerabilities, incidents and corrective actions remain linked, creating a permanent, defensible audit trail. Assets continue to contribute to site, group and enterprise reporting while preserving full traceability to source evidence.

8Dashboards and Visualisation

Citadel risk heat map screenshot: assets plotted geographically across the UK with a breakdown of risk by category
Risk heat map (Events Map) — assets plotted geographically, with risk concentrations broken down by category across the estate.

Dashboards transform operational data into insight — showing users at every level what is happening, where attention is required and why. Standard capabilities:

Executive dashboardsOperational dashboardsGroup health views Site health viewsAsset assurance viewsRisk heat maps Geographic mapping (Events Map)Compliance reportingTrend analysis Comparative benchmarking

Citadel focuses on relationships, trends and emerging patterns rather than isolated metrics, with colour-coded indicators, health scores and performance metrics for rapid identification of deteriorating conditions. Geospatial visualisation reveals assurance performance, vulnerabilities and risk concentrations across regional, national and global operations, letting teams identify vulnerability clusters and compare locations. Historical trend analysis measures improvement and intervention effectiveness. Dashboards can be viewed at enterprise, group, site, asset or assessment level with full traceability to source evidence. For enterprise BI, Citadel integrates with Microsoft Power BI and other analytics platforms.

Benchmarking & peer comparison

Comparative benchmarking compares sites, regions, contracts, programmes and business units against organisational averages or peer groups using filtered assessment statistics. This lets teams see who is performing well, identify outliers and share good practice — with dedicated benchmarking views configured to customer requirements during deployment.

9Reporting and Analytics

Enterprise Analytics and Business Intelligence

Citadel can provide data to Microsoft Power BI and other enterprise analytics platforms through APIs, data feeds or deployment-specific integrations, combining assurance, compliance and operational risk information with wider organisational data from:

Incident & security event platformsMaintenance & engineering systems Facilities management systemsWorkforce & staffing platforms Training & competency recordsFinancial systems Supply chain informationExternal threat intelligence Environmental & operational monitoring

Combining these surfaces relationships that would otherwise remain hidden — e.g. rising vulnerabilities correlating with reduced staffing, equipment failures aligning with deferred maintenance, or deteriorating compliance coinciding with contractor changes or increased operational tempo. Citadel can generate notifications, alerts and workflow actions automatically when changes in assurance performance or risk posture are detected, becoming a primary source of operational assurance data feeding enterprise reporting, predictive analytics and strategic decision making.

Native Reporting Capabilities

Executive reportsAudit reportsCompliance reports Risk reportsException reportsTrend reports Benchmark reportsSite assurance reportsAsset assurance reports

Reports can be generated automatically, scheduled for regular distribution or produced on demand, and tailored to individual users, teams or stakeholders. Export formats: PDF, Microsoft Excel, CSV, and API data feeds.

From Reporting to Risk Intelligence

As organisations mature, Citadel evolves from a source of assessment information into a key contributor to enterprise-wide risk intelligence. Operational evidence from routine inspections, audits and assurance activities continues to deliver value long after the assessment — supporting trend analysis, predictive modelling and informed decision making.

10Assurance Traceability

Complete traceability is preserved throughout the assurance lifecycle, linking operational activity, evidence, controls and strategic reporting so users can move from a high-level dashboard, report or risk register entry back to the original evidence — photographs, documents, assessor observations and supporting information captured during assessment.

EvidenceControl PerformanceOperational FindingsOperational RiskStrategic RiskExecutive Reporting

Operational teams can see how local findings contribute to wider organisational exposure and strategic decision making. Citadel provides this chain of evidence as standard, creating a defensible audit trail across the entire assurance process and significantly reducing effort for investigations, external audits, regulatory reviews and governance — a single source of truth linking operational activity directly to strategic oversight and executive reporting.

11Security and Access Control

Built on the principle of least privilege — users are granted access only to the information and functionality required for their responsibilities. Access controls align with the organisation's operating model, structure and information assurance requirements. Permissions may be applied at multiple levels:

GroupSiteAssetAssessment ReportWorkflowInformation classificationAdministrative function

Permission levels — worked example

Access can be scoped at every level of the organisational hierarchy, so a user sees exactly the slice of the estate their role requires:

LevelExample scope
EnterpriseBoard / group risk team — visibility of every organisation, region and site, with trends rolled up to strategic risk.
OrganisationA business unit, contract or customer — sees only its own sites, assessments and reports, isolated from other organisations.
SiteA site manager — full assurance picture for their site(s), contributing upward without seeing peer sites.
AssetA specialist team — granted specific asset types (e.g. control rooms, vehicles) across sites without exposing unrelated assets.
AssessmentA field assessor — only the inspections and surveys assigned to them, with contextual visibility rules.
ReportAn executive stakeholder — read-only access to defined reports and dashboards without operational edit rights.

Access is governed through role-based permissions, organisational structures and contextual visibility rules — e.g. a regional manager sees all sites in their area while local assessors see only assigned assets and assessments; specialist teams can be granted specific asset types, contracts or programmes without exposing unrelated information. Granular control is provided over:

Data visibilityAssessment permissionsReporting permissions Administrative permissionsApproval workflowsGeographic boundaries Organisational boundariesClassification boundaries

Authentication & identity

Integration with enterprise identity and authentication services — corporate directory services, federated identity providers and enterprise single sign-on — leverages existing authentication and user lifecycle management. Supported mechanisms:

Username & passwordSingle Sign-On (SSO)Multi-Factor Authentication (MFA) Network access restrictionsIP allow listing

Comprehensive audit logging is provided as standard — user activity, configuration changes and administrative actions remain fully traceable, supporting internal governance, investigations and external assurance.

Certifications & security posture

Cyber Essentials Plus certifiedIndependently penetration tested Role-based access controlSSO & MFA Encryption in transit (TLS)Immutable audit trail Air-gapped deployment capableLeast-privilege by design

Citadel is built and operated to recognised security good practice: arx Partners holds Cyber Essentials Plus, and the platform is subject to independent penetration testing. The architecture supports customer-managed deployment at higher information classifications — including physically separated, logically separated and fully air-gapped environments — subject to the accreditation, operating procedures and security controls implemented by the customer. Certificate details, the most recent penetration-test summary and supporting security evidence are available to evaluators on request.

Citadel is developed and tested against the OWASP Top 10 web application security risks. arx Partners holds Cyber Essentials Plus; the platform does not currently hold ISO 27001 certification, with organisational security controls maintained in line with recognised good practice. Citadel does not currently hold formal accreditation for operation within OFFICIAL, OFFICIAL-SENSITIVE or SECRET environments; however, the architecture is designed to support customer-managed deployment at these classifications — including physically separated, logically separated and fully air-gapped deployments — subject to the accreditation, operating procedures and security controls implemented by the customer.

12Information Classification

Diagram of Citadel information classification and domain separation
Information classification and domain separation across the platform.

A flexible information management framework for complex, regulated and security-sensitive environments where information must be protected, compartmentalised and shared appropriately. Citadel supports organisational, contractual and information classification boundaries, allowing multiple information domains to operate within a consistent assurance and risk management framework. Access is governed through RBAC, organisational structures and contextual visibility rules, maintaining separation between organisations, contracts, programmes and operational activities. Deployment options are suitable for government, defence and critical national infrastructure environments, operating across multiple information classifications through physically or logically separated deployments.

Accreditation status
Citadel does not currently hold accreditation for operation within OFFICIAL, OFFICIAL-SENSITIVE or SECRET environments. However, the architecture is designed to support deployment within customer-managed environments operating at these classifications — including physically separated, logically separated and fully air-gapped deployments — subject to the accreditation, operating procedures and security controls implemented by the customer.

Reporting, dashboards and analytics operate within the same security boundaries as the underlying operational data. The platform is intentionally deployment-agnostic and can operate alongside manual transfer processes, approved cross-domain solutions, controlled data exchange mechanisms or fully segregated environments. It supports deployment within private, classified and fully air-gapped environments without dependency on external networks, cloud services or internet connectivity — authentication, storage, reporting, analytics and supporting services can all operate entirely within the protected environment.

13Integration

Diagram of the Citadel integration ecosystem and API-first architecture
An API-first ecosystem: Citadel integrates with incident, FM, HR, BI and other enterprise systems.

An API-first architecture connects the platform to existing enterprise systems, operational workflows and external data sources. Citadel supports tightly integrated and hybrid deployment models — operating as a standalone platform, a headless assurance engine, or part of a broader ecosystem. As standard, Citadel integrates with:

Incident management systemsFacilities management platformsSecurity management systems HR & workforce systemsLearning & competency platformsBusiness intelligence environments Corporate data warehousesAsset management systemsMaintenance & engineering systems External threat intelligence services

Both inbound and outbound integration patterns are supported — consuming information from external systems while contributing assurance, compliance and operational risk data back to the enterprise ecosystem. Citadel leverages existing organisational data (site information, asset inventories, personnel records, organisational structures, operational metadata) via import or synchronisation from authoritative systems, reducing duplication and manual entry. Incident management is a common pattern: external incidents/events can automatically generate assessments, inspections or assurance activities in Citadel, while Citadel findings and vulnerabilities can create incidents, investigations or corrective actions in external platforms — bidirectional exchange keeping assurance and operational response aligned. Examples: incident information triggering assessments, training records influencing assurance activity, maintenance systems providing context for recurring defects, external threat intelligence influencing local risk profiles. Extensive BI/analytics integration (e.g. Microsoft Power BI) allows assurance information to be analysed alongside incident trends, maintenance activity, staffing levels, financial indicators and operational metrics.

13.1 Document Management Philosophy

Citadel allows documents, photographs, certificates and supporting evidence to be attached to assessments, findings, controls and assets, but is not intended to replace dedicated enterprise document management or EDRMS systems. It stores information required to support assurance and maintain evidential traceability while organisations continue to use established repositories (SharePoint, document management and records management systems) as the authoritative source for controlled documentation. Where required, Citadel can integrate with external repositories or store references and links to externally managed documents, avoiding duplication and parallel document management processes.

14Operational Workflow

Diagram of the Citadel assessment and operational workflow
From assignment and capture through review, approval and continuous update of control effectiveness.

A flexible operational workflow transforms day-to-day activity into meaningful assurance, compliance and risk information, supporting both planned and reactive activities within a common framework. Assessments can be generated automatically through schedules, triggered by business rules or initiated manually. Flexible assignment allocates assessments to individuals, teams, specialist functions or external suppliers based on structures, responsibilities, locations, asset ownership or operational requirements.

Users complete assessments through a standard web browser on desktop, tablet or mobile, capturing evidence at the point of activity — photographs, documents, certificates, observations and supporting information create a defensible audit trail. Assessments can be reviewed, approved or subjected to additional QA prior to final submission. Completed assessments can be reopened for review, correction or amendment by authorised users while maintaining a complete audit history — errors can be corrected without compromising evidential integrity, and all amendments remain fully attributable, preserving both original submission and subsequent revisions.

As assessments complete, control effectiveness is automatically updated across relevant sites, assets and operational areas, making risks, vulnerabilities and emerging issues visible as conditions evolve. Configurable workflows, escalation rules and automated notifications inform the right personnel immediately when predefined thresholds, risk levels or business rules are exceeded. Dashboards, reports and analytics update continuously. Historical findings, evidence, actions and outcomes remain linked to the original assessment to support future assurance, trend analysis, lessons learned, regulatory investigations and compliance.

15Information Retention and Assurance History

Citadel preserves a complete assurance history — assessments, findings, evidence, actions and decisions — throughout the operational life of a site, asset, contract or programme, ensuring operational knowledge is not lost as personnel, structures and responsibilities change. Historical information supports:

Trend analysisCompliance evidenceRegulatory investigations Lessons learned exercisesAudit requirementsAssurance reviews Historical benchmarkingContinuous improvement programmes

Relationships between assessments, evidence, controls, actions and risks are preserved — organisations understand not only what happened but why decisions were taken and what informed them. Retention periods align with organisational policies, contractual obligations, regulatory requirements and information assurance frameworks; automated archival and disposal schedules are implemented per deployment. Citadel supports archival, disposal and long-term preservation policies as part of wider information lifecycle management.

16Scalability and Growth

The architecture scales from a small initial deployment to enterprise-wide operation while maintaining a consistent operating model, governance framework and assurance methodology. Support is provided for:

Large user communitiesExtensive site portfoliosHigh assessment volumes Concurrent operational activityMulti-region deployments Multiple business units & contractsMultiple operating models & structures

The platform supports multiple concurrent users across different sites, regions and operational domains, with parallel assessment activity, dashboard access and enterprise reporting; performance and capacity are validated against the proposed deployment architecture and anticipated usage profile. The same core capabilities, reporting structures and assurance principles apply whether deployed for a single facility, a national estate or a globally distributed organisation. The flexible group/site/asset model allows geographic, operational and organisational expansion without restructuring the platform or losing historical continuity. For international organisations, multiple regions, deployment models, operating environments and information classifications are supported with a consistent user experience. Growth does not require redesign — the same architecture supporting a single site can support thousands of users, millions of assessment records and globally distributed operations without migration or re-engineering of the data model.

17Continuous Development and Future Growth

Citadel is a flexible, extensible platform that adapts to changing requirements without requiring organisations to replace processes, redesign data models or lose historical continuity. It evolves through ongoing development, regular feature enhancements and new capabilities driven by customer requirements, emerging technologies and the wider assurance landscape. Current areas of development:

Additional assurance & risk domainsNew regulatory frameworks & standards Enhanced reporting & analyticsAI-assisted analysis & decision support Predictive & trend-based analyticsExpanded workflow & automation New enterprise & specialist integrations

Particular emphasis is placed on interoperability and integration — new methods of exchanging information with operational systems, BI platforms and external data sources.

Operational Resilience and Dependency Mapping (in development)

Citadel is developing enhanced operational resilience capabilities to model and visualise dependencies between sites, assets, people, suppliers, services and critical business functions. Using information from existing assessments and question sets, the platform will build relationship maps showing how components contribute to wider capability and resilience, visualised through interactive dependency maps to understand critical paths, single points of failure and the potential impact of disruption. The same capability will support modelling of failure scenarios and assessment of operational impacts if key assets, locations, suppliers or services become unavailable — building on data already collected, so investment in assurance data today continues to deliver value in the future.

18Technical Architecture

Platform Architecture

Citadel is a modern, API-first, configuration-driven enterprise platform designed to support organisations ranging from single-site operations to large, multi-organisation deployments. The platform follows a multi-tier architecture consisting of a browser-based client, application services, a relational database and secure object storage, allowing each component to be deployed independently to meet customer performance, resilience and security requirements.

Browser Based Client API-First Services Configuration Driven Multi-Tier Architecture Cloud or On-Premise Air-Gapped Deployment

Configuration-Driven Platform

Citadel is designed to be configured rather than customised. Assessment frameworks, workflows, permissions, dashboards, scoring models, notifications and reporting can all be configured to meet organisational requirements without modifying the underlying application. This enables organisations to adapt the platform as operational requirements evolve while maintaining a common, supportable codebase.

Deployment Options

Citadel can be deployed within secure cloud environments, customer-managed infrastructure or fully isolated networks. The same application architecture supports hosted, on-premise and air-gapped deployments, allowing organisations to align implementation with their operational, regulatory and security requirements.

Cloud Hosted Customer Hosted Virtual Infrastructure Dedicated Servers High Availability Air-Gapped Environments

Database Platform

Citadel uses PostgreSQL as its enterprise relational database platform. Database services are deployed independently from the application layer, allowing customers to integrate Citadel with existing infrastructure, backup strategies, monitoring tools and security policies. PostgreSQL provides the transactional integrity, resilience and scalability required to support enterprise and mission-critical environments.

Scalability & Resilience

Citadel has been designed to support large numbers of concurrent users, automated processes and system integrations. Enterprise transaction management ensures consistent data integrity while supporting backup, replication, disaster recovery and high-availability deployments. Application services can be scaled independently to meet changing operational demand.

  • Supports large-scale concurrent access across users, services and integrations.
  • Enterprise-grade transactional integrity and data consistency.
  • High-availability deployment and disaster recovery support.
  • Independent scaling of application and database services.
  • Compatible with customer monitoring, backup and security frameworks.

Security & Information Protection

All communication between application services, database services and integrated systems is secured using industry-standard encryption. Citadel supports role-based access control, information classification, comprehensive audit logging and secure deployment within customer-managed environments, including fully isolated networks where required.

Integration Architecture

All platform functionality is exposed through Citadel's REST API, allowing integration with business systems, reporting platforms, identity providers and third-party applications. The API-first architecture ensures that browser interfaces, mobile applications and external integrations all interact with the same core business services, providing consistent behaviour across the platform.

Deployment Diagram

CUSTOMER ENVIRONMENT — air-gapped capable (no external network dependency) Client tier (no install) Web browser Desktop Tablet Mobile Citadel application services API-first · REST Configuration-driven RBAC · Audit · Workflow PostgreSQL Separate DB tier MVCC · WAL Server / VM / HA cluster HTTPS secure network Optional (non air-gapped): REST API ↔ enterprise systems & Microsoft Power BI

Infrastructure Requirements

Citadel aligns with standard enterprise hosting practice rather than imposing a fixed technical solution:

  • Application host — a Linux server, virtual machine or customer container platform to run the Citadel application services.
  • Database — PostgreSQL (a currently supported major release) as a separate service, on a dedicated server, VM, existing enterprise database infrastructure or a high-availability cluster.
  • Network — secure internal connectivity between the application and database tiers; HTTPS/TLS for client access. No inbound internet dependency is required for air-gapped operation.
  • Clients — a modern web browser on desktop, tablet or mobile; no client-side installation.
  • Resilience — supports backup, replication, point-in-time recovery and disaster-recovery strategies; compatible with customer security monitoring and auditing.

Precise sizing (CPU, memory, storage) and the exact service packaging are confirmed per deployment and validated against the proposed architecture and anticipated usage profile.

19Record Identification, Timestamping & Data Portability

Record Identification

All records — issues, findings, assessments, escalations, sites, users and associated supporting objects — are assigned a unique, stable identifier at creation. Citadel uses globally unique identifiers (GUIDs/UUIDs) rather than sequential or auto-incrementing numeric identifiers, e.g. 29c8248b-cd41-4d5e-a169-1ec47e8bb518. Identifiers remain stable throughout a record's lifetime and are preserved during export, import, backup, restoration and migration, keeping references between related records intact and audit trails maintained. Identifiers are included in export files and API responses to support synchronisation, deduplication and reconciliation. Being globally unique across all instances and deployments, they prevent identifier collisions when data is exchanged between separate environments, organisations or security domains — including transfers between isolated or air-gapped deployments — enabling safe federation, migration and consolidation while preserving data integrity, referential consistency and auditability.

Record Timestamping

Server-generated timestamps are assigned to all primary data records at creation and modification — generated by the platform rather than client devices, ensuring consistency and protection against client-side clock discrepancies or manipulation. All timestamps are recorded in Coordinated Universal Time (UTC). Creation and modification timestamps are maintained for records including (but not limited to): issues, findings, assessments, survey responses, escalations, sites, assets, users, and supporting evidence & attachments. Where exposed through the API or included in export files, timestamps are included to support auditability, synchronisation, reconciliation and downstream processing, and are preserved during export, import, backup, restoration and migration. This forms part of Citadel's wider audit and assurance framework.

20Workflow Governance and State Management

Citadel provides a configurable workflow engine that enforces defined state machines for issue, finding, escalation and approval workflows. Workflow states and permitted transitions are defined during solution design by the implementation team in collaboration with the customer — supporting both simple status models and complex state-machine-based workflows aligned to the customer's procedures. Citadel enforces strict workflow sequencing, ensuring records progress only through approved transitions and preventing users from bypassing mandatory stages. Backward transitions can be permitted, restricted or prohibited, and where permitted can be limited to authorised roles or subject to explicit approval.

Central enforcement
Workflow transition validation is enforced centrally by the platform and applies consistently across all access methods — web UI, mobile interfaces, APIs and system integrations. Workflow governance controls cannot be bypassed through direct API access or alternative integration mechanisms. All transitions and status changes are recorded within Citadel's audit framework.

What the workflow engine provides

Configurable workflows — state machines for issues, findings, escalations and approvals, defined to the customer's operating procedures.
Approvals — review, sign-off and QA stages before a record is finalised; backward transitions can require authorised roles or explicit approval.
Escalations — tiered escalation paths (e.g. Site → Department → Enterprise) with tier-restricted outcomes.
Mandatory fields — required comments, justifications, photographic evidence or attachments enforced on defined transitions.
Automation — schedules, business rules and negative responses can auto-generate assessments, actions or escalations.
Notifications — configurable alerts to the right people when thresholds, risk levels or business rules are exceeded.
State transitions — strict sequencing with terminal-state protection, so records progress only through approved paths.
Full attribution — every transition, outcome and status change is recorded with actor and UTC timestamp.

Multi-tier escalation

Where an approval or funding decision needs to move up an organisation, Citadel supports ordered, multi-tier escalation (for example Site → Department → Enterprise) with the governance rules enforced centrally at the workflow layer — not just in the user interface:

  • Tier preconditions — escalation to the next tier only becomes available once the current tier has formally declined; the platform enforces the sequence and prevents out-of-order escalation.
  • Single pending escalation per tier — a second escalation cannot be raised at a tier while one is already pending for the same item; the action is not offered in the UI and is rejected via the API.
  • Outcome permissions by tier — specific outcomes can be restricted to specific roles; for example formal risk acceptance can be limited to the highest (Enterprise) tier, with lower tiers unable to see or select it.
  • Mandatory justification — outcomes such as risk acceptance require a mandatory justification, validated before submission so the record cannot be completed with the field empty.
  • Automatic downstream actions — recording a terminal outcome can automatically transition the parent item (for example auto-closing an issue on risk acceptance), with the change recorded in the audit trail.
  • Terminal-state protection — once an escalation reaches a terminal state (e.g. Funded, Declined, Risk Accepted) no further response can be recorded against it.
  • Status guards — escalation is blocked on items already in a Resolved or Closed state; the action is not offered and API attempts are rejected.

These behaviours are delivered through workflow configuration and the role-based permission model, and enforced consistently across the web UI, mobile, API and integrations.

Audit & Governance

Diagram of Citadel end-to-end audit and traceability from evidence to executive reporting
End-to-end traceability — every executive report drills back to the original evidence.

Citadel maintains a comprehensive, immutable, tamper-evident audit trail as standard. Audit records are generated automatically by the platform as part of each operation, so user activity, configuration changes and administrative actions are captured, fully attributable and cannot be omitted, altered or bypassed — including via direct API access. Records carry server-generated UTC timestamps that are preserved through export, import, backup, restoration and migration, providing an evidential history suitable for regulated and mission-critical environments.

User actions — who did what and when, across the web UI, mobile and API — recorded identically regardless of access method.
Configuration changes — field-level change records with before/after values (e.g. a site classification change captures previous and new value, actor and timestamp).
Workflow & status changes — every transition and outcome is logged and cannot be bypassed via direct API access.
Evidence history — photographs, documents and observations stay linked to the finding, preserving a defensible chain from report back to source.
Data operations — export, import and cleardown operations are logged with actor, record count and outcome; cleardown audit records are retained permanently.
Approvals & governance — review, sign-off and escalation decisions are recorded against the record, evidencing who authorised what and when.
Traceability — a complete chain from executive report and risk register entry back to the original evidence that informed it.
Compliance evidence & reporting — audit, change and transfer activity can be surfaced to authorised roles through governance views and exported for regulators and external auditors.

This gives compliance, risk and audit teams a defensible, end-to-end record — reducing the effort of investigations, regulatory reviews and external audits, and removing reliance on manually assembled evidence.

21Developer Centre & API

Citadel is built on an API-first architecture: all native platform functionality is exposed through the same APIs available to third-party integrations. It provides a comprehensive REST API with published documentation covering endpoints, request parameters, authentication mechanisms and response schemas, available to customers, implementation partners and authorised integrators. arx Partners can also provide supplementary API examples, sample response payloads and Postman collections.

Developer Centre

REST — resource-oriented endpoints over HTTPS for issues, findings, assessments, sites, assets, users and more.
JSON — JSON request and response payloads, including stable UUID identifiers and UTC timestamps on every record.
Authentication — authenticated, permission-aware access; API calls are subject to the same RBAC and workflow governance as the UI.
OpenAPI / Swagger — published, interactive API documentation (endpoints, parameters, schemas).
Postman & examples — sample collections, example requests and response payloads to accelerate integration.
Sample integrations — reference patterns for incident systems, Power BI and enterprise data sources.
Outbound integration — findings and risk changes can drive downstream systems through the API and established integration patterns. Configurable webhooks / event push are on the roadmap.

Interactive API documentation: https://arx-api.citadel.site/api-docs/index.html

Example — joined issue record (illustrative JSON):

GET /api/v1/issues/29c8248b-cd41-4d5e-a169-1ec47e8bb518

{
  "id": "29c8248b-cd41-4d5e-a169-1ec47e8bb518",
  "created_utc": "2026-08-04T09:14:22Z",
  "status": "Open",
  "site":  { "id": "b1e...", "name": "Tier 1 Data Centre" },
  "asset": { "id": "77a...", "name": "Perimeter CCTV" },
  "control": { "code": "PS-04", "title": "CCTV coverage" },
  "score": 0, "max_score": 6,
  "workflow": { "state": "Open", "escalation": null }
}

Illustrative only — exact endpoints, fields and payloads are defined in the published API documentation and per-deployment integration design.

Hierarchy Context and Joined Data

The API supports retrieval of issue, finding and assessment records together with their associated contextual hierarchy in a single response — the full operational context of a record without multiple lookup requests. Related information returned alongside issue records includes:

Site name & identifierOrganisation name & identifier Enterprise / corporate group informationAsset information Risk & control identifiersControl codes & titles Assessment metadataWorkflow & escalation status

Fields returned are configurable per endpoint to match the customer's data model, reducing API round-trips and improving performance for reporting, dashboarding and integration. API documentation: https://arx-api.citadel.site/api-docs/index.html.

Workflow & escalation context

The same joined-data pattern exposes workflow and escalation context alongside operational records, so a consuming application can retrieve an issue together with its related workflow information in a single call rather than making multiple lookups. Where escalation is used, the returned context can include the escalation tier or level, status, responding role, outcome or decision, justification, assigned responder, creation and response timestamps, and associated audit and workflow history. Exact endpoints and response schemas are configured to the customer's data model and documented as part of the integration design.

Import & Export

Diagram of the Citadel import pipeline: prepare, upload, validate, deduplicate and commit
The import pipeline — prepare, upload, validate, deduplicate and commit, with full auditability.

Citadel is designed to move data in and out cleanly, so it fits alongside existing enterprise systems rather than becoming an island. Structured, machine-readable formats are supported in both directions, with all operations governed by role-based permissions and recorded in the audit trail.

Import

Bulk-load the building blocks of the platform from spreadsheets, CSV or JSON — so a large estate can be stood up quickly and kept in step with authoritative source systems. Supported record types include:

UsersGroupsSitesAssets ControlsQuestion setsOrganisational structuresOperational metadata

Excel & CSV import — load users, groups, sites, assets, question sets and metadata directly from spreadsheets and CSV files.
JSON import — native import of structured JSON, including previously exported Citadel datasets carrying stable UUID identifiers.
Bulk / AI-assisted import — identify sites, assets, users, groups and structures from existing data sources and prepare them for bulk import, reducing deployment and administration effort.
API import — programmatic record creation and update via the REST API for scripted or middleware-driven loads.
Bulk administration — create and update large numbers of records at once, keeping a large estate maintainable without manual, record-by-record entry.

Export

Excel & CSV export — structured exports of assessments, findings and reporting data for analysis and downstream processing.
JSON export — machine-readable export via the export function or the API, with UUIDs and UTC timestamps preserved.
PDF export — formatted report output for distribution and record-keeping.
Scheduled export — reports and data feeds can be generated automatically and scheduled for regular distribution.
API export & feeds — API data feeds into Microsoft Power BI and enterprise analytics platforms.
Configurable scope — filter exports by date range, record type, workflow status, site or grouping — supporting incremental "since last export" transfers.

Stable UUID identifiers and UTC timestamps travel with exported records, enabling reliable synchronisation, deduplication and reconciliation when data moves between environments — including isolated or air-gapped deployments.

22Workflow & Automation

Citadel includes a powerful, configuration-driven workflow engine that enables organisations to automate governance, approvals, notifications, escalations and operational processes. Rather than enforcing a fixed methodology, workflows are configured to reflect each organisation's policies, management structure and assurance model.

Configuration Driven
Workflow behaviour is configured rather than hard coded. Approval stages, notifications, mandatory information, validation rules, role-specific actions and automated transitions can all be tailored to support individual operational and governance requirements without modifying the core platform.

Workflow rules are enforced consistently across the web application, mobile devices, APIs and system integrations, ensuring the same governance rules apply regardless of how information is entered or updated. Every workflow event, approval, notification, status change and escalation is automatically recorded within Citadel's audit framework, providing complete traceability and accountability.

23Flexible Deployment & Information Management

Citadel supports deployment across cloud, customer-hosted and isolated environments. Each deployment can be independently configured to meet organisational, operational and information governance requirements while maintaining a consistent administration model and user experience.

Information Classification

Information classification is managed through configurable metadata, organisational structures, permissions and governance policies. Classification attributes can be applied to sites, assets, assessments or other business objects, allowing organisations to implement their own information management model without requiring bespoke software development.

Role-Based Access Control

Citadel combines hierarchical organisational structures with granular role-based permissions to ensure users only have access to the information and functionality appropriate to their responsibilities. Access controls are enforced consistently across the platform, including the user interface, APIs and system integrations.

Environment Configuration

Individual deployment environments can be configured independently, allowing organisations to enable or disable specific modules, workflows, reporting capabilities and operational functions to support differing business requirements without altering the underlying application.

Classification-aware access & submission

Where sites, assets or assessments carry a classification attribute, Citadel can filter what each user sees and can act on according to that classification — including restricting which sites are available for survey or assessment submission. These controls are enforced centrally at the platform and data-access layer, not only in the user interface, so they hold consistently across the web UI, the API and system integrations and cannot be bypassed through direct API access. In separated deployments this is reinforced by the environment boundary itself, so records outside a given classification are not present in that environment at all.

24Data Exchange & Lifecycle Management

Citadel provides flexible facilities for importing, exporting and integrating operational data throughout its lifecycle. Open standards, configurable data validation and comprehensive APIs enable organisations to exchange information efficiently while maintaining governance and data integrity.

Import & Export

Authorised users can import and export structured information using industry-standard formats including CSV, JSON and Microsoft Excel. Export operations can be filtered by date, organisational structure, workflow status, record type or other business criteria, allowing organisations to exchange only the information required.

Systems Integration

The platform exposes a comprehensive REST API, allowing seamless integration with corporate systems, reporting platforms, business intelligence tools and third-party applications. Integration processes can support both manual and automated data exchange.

Audit & Governance

All import, export and integration activities are automatically recorded within the audit framework, including the user, operation, execution time, outcome and records processed. This provides complete visibility of data movement while supporting governance, compliance and assurance requirements.

Data Lifecycle Management

Citadel supports configurable data retention and lifecycle policies, allowing organisations to manage operational information in accordance with their own governance, regulatory and business requirements. Administrative functions support controlled archival and removal of operational data while preserving appropriate audit records and master information.

Atomic export-and-cleardown

For workflows that move data out of an environment and then clear it down, export and cleardown operate as a single, governed operation rather than two independent buttons:

  • Export-gated — records only become eligible for removal once the corresponding export has completed successfully and been confirmed; a failed or interrupted export never triggers a cleardown, so data cannot be lost.
  • Selective — only transactional records (such as survey responses and findings) are removed; master and reference data (sites, users, controls, templates, schedules and configuration) is preserved.
  • Confirmed & controlled — an operator confirmation step can be required before execution, and access is restricted to a nominated role through role-based access control.
  • Fully audited — a cleardown audit record is written before deletion (actor, timestamp, record count, categories and date range/batch) and is permanently retained, excluded from any future cleardown.

25Notifications & Communications

Citadel includes a flexible notification framework that automatically distributes information in response to configurable workflow events, ensuring that the right people receive the right information at the appropriate point in an operational process.

Assessment Completion Workflow Approvals Escalations Actions & Findings Risk Updates Management Notifications Customer Defined Events

Recipients can include individual users, operational teams, distribution groups or customer-defined contacts. Notification behaviour, message content and recipients are fully configurable, enabling organisations to align communications with their own operational procedures and governance policies.

Submission notifications

On submission of a survey or assessment, Citadel can automatically send an email containing the full submitted record in the body — every control with its Pass / Fail / Not Applicable response, notes, submitter, site and timestamp — so recipients hold a complete, permanent reference copy independent of the platform. The email is generated at the point of submission and processed in near real time, ahead of any later transfer or cleardown. Notifications are configured per deployment environment, so they can be enabled in one environment and switched off in another, and recipient lists (for example the site lead and the submitting user) are fully configurable.

26Summary

Citadel transforms operational activity into meaningful assurance and risk intelligence. By connecting assessments, evidence, controls, workflows, reporting and analytics within a single configuration-driven platform, organisations gain a continuously evolving understanding of operational performance, resilience and enterprise risk.

  • Evidence-led assurance and compliance.
  • Dynamic operational and strategic risk management.
  • Improved visibility across organisations, sites and assets.
  • Reduced administrative effort through automation.
  • Better informed operational and executive decision making.
  • Complete traceability from executive dashboards to source evidence.
  • A scalable platform that adapts as organisational requirements evolve.

Designed to support organisations of all sizes, Citadel provides a common operational picture across teams, management and executive leadership while maintaining appropriate governance, security and information controls.