Skip to main content
This guide walks you through the first-time setup of Kliper — from creating your organization to opening the Assessment Workbench on your first engagement.

Prerequisites

Before you begin, ensure you have:
  • A Kliper account (sign up at app.kliper.io using email, Google, GitHub, or Microsoft)
  • Your QSA firm details (company name, address, website)
  • At least one client’s basic information (company name, primary contact)

Step 1 — Create Your Organization

Your Organization is the top-level workspace for your QSA firm. All clients, engagements, assessments, team members, and files live within it.
1

Navigate to Onboarding

After signing in for the first time, you are directed to the onboarding screen. If you already have an account, navigate to Settings > Organization to view your workspace.
2

Enter Organization Details

Fill in the following fields:
FieldDescriptionExample
Organization NameYour QSA firm or team nameAcme Security Assessors
Workspace SlugURL-friendly identifier (auto-generated from name, editable)acme-security
FrameworkPre-selected to PCI DSS 4.0 (locked)PCI DSS 4.0
The slug must be lowercase, alphanumeric with hyphens only, and at least 3 characters.
3

Create the Workspace

Click Create Organization. The platform provisions your workspace, pre-loads the PCI DSS 4.0.1 template library, and assigns you the Admin role automatically.
Screenshot of Organization Creation
Each user can belong to one active organization. If your firm has multiple divisions, each operates as a separate organization with its own data isolation.

Step 2 — Add Your First Client

A Client represents the merchant or entity you are assessing. Client records carry PCI-relevant context through every engagement.
1

Open the Engagement Hub

From the left sidebar, navigate to Engagement Hub. This is your central dashboard for managing clients and engagements.
2

Click New Client

Click the + New Client button in the top-right corner. The Create Client dialog opens.
3

Enter Client Details

At minimum, enter the Client Name. For a more complete setup, fill in:
FieldPurpose
Company NameLegal entity name (appears in the ROC)
IndustryClassification (e.g., Retail, Financial Services, Healthcare)
Primary ContactName, email, and phone of your main point of contact
AddressMailing address for the assessed entity
PCI-specific fields (Merchant Level, Annual Transaction Volume, Acquirer Name) can be filled now or later from the client profile.
4

Save the Client

Click Create. The client appears in your Engagement Hub with a profile ready for engagements.
Screenshot of New Client Dialog

Step 3 — Create a Letter of Engagement (LOE)

The LOE defines the contractual scope, timeline, and financial terms for the assessment engagement. Every assessment must belong to an LOE.
1

Open the Client Profile

In the Engagement Hub, click on your client’s name to open their profile page.
2

Click Add LOE

Click the + Add LOE button. You are taken to the LOE creation form.
3

Fill in Core Fields

The essential fields to get started are:
FieldRequiredDescription
TitleYesDescriptive name (e.g., “2026 Annual PCI DSS ROC”)
Start DateYesEngagement start date
End DateYesEngagement end date
Contract ValueNoTotal engagement fee
The platform auto-generates a unique LOE Number (e.g., LOE-2026-001).
4

Set Milestone Dates (Optional)

Expand the Timeline section to define key project milestones:
  • Kickoff Date
  • Onsite Start / End Dates
  • Draft Report Date
  • Remediation Window (Start / End)
  • QA Review Window (Start / End)
  • Final Report Date
These milestones drive the engagement phases and progress tracking.
5

Save the LOE

Click Create LOE. The LOE is now linked to your client and ready for assessments.
Screenshot of LOE Creation Form
You can return to the LOE at any time to fill in scope details, financial terms, legal clauses, and QSA signer information. None of these block assessment creation.

Step 4 — Launch an Assessment

The Assessment is where the actual PCI DSS evaluation happens. Creating one loads the full set of 200+ testing procedures into the workbench.
1

Open the LOE

From the client profile, click on the LOE you just created.
2

Click Create Assessment

Click the + Create Assessment button. The Assessment Creation Wizard opens.
3

Complete the Wizard

The wizard walks you through 5 steps:
  1. Assessment Type & Framework — Select the assessment type. The framework is pre-set to PCI DSS 4.0.1.
  2. Basic Info — Enter a name and optional description.
  3. Due Date & Owner — Set the target completion date and assign a lead assessor.
  4. Collaborators — Search and add team members who will work on the assessment.
  5. Review & Create — Confirm all details and click Create.
4

Open the Assessment Workbench

After creation, click Open Assessment to enter the Assessment Workbench — the primary interface where you will conduct the evaluation.
Screenshot of Assessment Creation Wizard

Step 5 — Navigate the Assessment Workbench

The workbench opens with a three-panel layout:
PanelLocationWhat You See
Section TreeLeftAll 12 PCI DSS principal requirements in a collapsible hierarchy
Question PanelCenterTesting procedures, reporting instructions, and answer fields for the selected requirement
Context PanelsRightCortex AI, Attachments, Comments, Collaborators, Gap Assessment, Audit Trail
1

Select a Requirement

In the Section Tree, expand a requirement group (e.g., Requirement 1 — Network Security Controls) and click a sub-requirement to load it in the center panel.
2

Answer Testing Procedures

Each requirement presents its testing procedures. Type your assessor response in the structured fields provided.
3

Set the Finding Status

Select the assessment finding for each requirement:
  • In Place — requirement is fully met
  • Not Applicable — does not apply to the assessed environment
  • Not Tested — requirement was not evaluated
  • Not in Place — requirement is not met
4

Upload Evidence

Open the Attachments panel on the right side. Drag and drop evidence files (PDFs, screenshots, configuration exports) directly into the upload area. Files are automatically scanned for malware and hashed for integrity.
5

Use Cortex AI

Open the Cortex AI panel to ask questions about the current requirement, validate uploaded evidence against PCI DSS criteria, or auto-generate a draft findings description.
Screenshot of Assessment Workbench

What’s Next

With your first assessment open, you are ready to begin the evaluation. Here are the recommended next steps: