Regixo docs
For the compliance team·Step 3 of 6 — Claim & review·see the whole journey ↗

Claim & review

An engineer has forwarded you a draft record built from their real systems — the structure, never the rows. This page is how you open it, sign in, and get your bearings — what the record shows, which calls are already made, and which are waiting for you. Reviewing needs no account; signing does.

Optional · EU compliance module You need this only if your company must keep a GDPR Article 30 RoPA or a DORA register — it is an optional module on top of the free data catalog. If that is not you, you can skip this section.

Walk one claim all the way through (the worked example)

Before the detail, do one claim end to end so the loop is concrete. An engineer at Aurelia Payments Oy forwarded a draft built from their systems. Here is each of the six steps for it:

StepWhat you doWhat you see / decide
1 · OpenClick the forwarded claim link on your laptop.The live record loads — no login needed to read. (If the link looks like localhost, see the branch below — the one you were sent is the hosted address.)
2 · Sign inEnter your work email, press Email me a sign-in link, open the email, click through Confirm it’s you.You’re signed in — no password set. The first verified sign-in becomes the record’s admin. (Signed in but see “no role on this record”? That’s the branch below — the draft was addressed to a specific person.)
3 · Commit?Nothing yet.Reading and filling commit you to nothing. The record stays DRAFT; signing is a separate, later act.
4 · ReadRead the intro block, the coverage banner and the activities.Three activities — Manage customer accounts, Customer due diligence (KYC/AML), Take and record payments — on 2 of 4 systems reached. The “Where this stands” panel counts what’s still blank: some calls are yours, the rest your engineering team’s.
5 · Three checksActivities right? · open legal calls? · sensitive data?KYC/AML is present and correctly named. Purpose, basis and retention are still suggestions. “0 Art. 9” is flagged — sanity-check it, since KYC rarely looks sensitive by column name.
6 · What’s missingNote the coverage banner.snowflake-dwh and stripe were unreachable — email the engineer to re-scan. You’ll know it worked when the banner clears.

Every claim is that same six-step pass. The rest of this page is each step in full — including the three branches a real reviewer hits: the link that looks like phishing, a system that is missing, and a record that is not yours to sign yet.

What the engineer forwards

The engineer either runs regixo invite on their machine, or presses Make the invitation on their own portal — the same thing, either way. That produces two things they send you, and nothing else leaves their machine but metadata:

Both point at the same record. The PDF is for forwarding and reading offline; the link is for filling and, later, signing. The engineer never had to create an account to send them.

The engineer’s own Record page carries the same hand-off: ↓ Download the draft PDF is a one-click download there (with the DORA register as an HTML file, for financial firms), beside a See what they’ll get preview of exactly the page you will open. And before anything is sent, regixo serve-claim serves that record page locally — the engineer reads exactly what you will read.

The exact payload that arrived

What reached you is metadata only — the same list the engineer saw and approved on their own invite screen before anything was sent. It is:

And never: a row or a value, column names, column types, credentials, or table owners. Everything else is a count, not a name. The list you can read on the claim is identical to the one the engineer confirmed at the regixo invite gate — the same preview, on both sides of the hand-off, so nothing reaches you that they did not watch leave.

1 · Open the link on your own laptop

The claim link points at whichever portal your engineer forwarded it to — app.regixo.com is the default once that host is switched on, and it is not yet, so today the link names the portal they ran. Either way you install nothing and set no password. Opening it lands you straight on the record; reading needs no account. The token in the link is the credential, so treat the link as you would a shared secret: whoever holds it can open the record.

Branch — the link looks like phishing A plain http:// or a localhost link is the shape a security-minded person is trained to distrust — so here is why the one you were sent is safe, and how to open it. A localhost link only ever works on the machine that made it: that is the engineer’s local address. Once the hosted portal is switched on, the link you are sent points there and opens anywhere; until then it names the portal your engineer is running. You never create a password and never install anything — you prove who you are with a one-time link sent to your email, so there is no account to be phished. The fix, if a link ever looks wrong, is the ordinary one: confirm with the colleague who sent it before you open it. The full vendor due diligence is Is it safe to sign?

2 · Sign in with the one-time email link

Opening the claim link lands you straight on the record — no login to look. When you are ready to change or confirm anything, you sign in with a one-time email link (a “magic link”). Here is the exact flow, and the one branch where the record turns you away:

what you'll see — the Sign in to fill card, in the rail beside the record (a static picture, not a live app)
Regixo compliance portal · EU-hosted Have edits to make? Sign in
▤ In the portal

Reading the draft needs no account — the claim link is enough. To change or confirm anything, press Email me a sign-in link: Regixo sends a one-time link, good for 15 minutes. Corporate mail scanners often open links first, so it lands on a Confirm it’s you page — press Continue to sign in → and you are in, with no password to set. The first person to sign in on a claim becomes the record’s admin. A tour: the compliance portal tour.

— not here

Signing in is a portal act — no terminal command signs a person in. The engineer’s side is regixo invite to send the claim, and later regixo seal pull to bring the sealed copy home.

— not here

An agent can read the draft over the read-only API, but it never signs in and never signs — signing names a verified person.

  1. Enter your work email and press Email me a sign-in link. Regixo sends a single-use link, good for 15 minutes.
  2. Open the email and click the link. Corporate mail scanners often open links first, so it lands on a Confirm it’s you page — press Continue to sign in → and you are in, with no password to set or remember.
  3. The first verified sign-in becomes the record’s admin, so the record you later sign carries a verified identity — the signature can name who you are. The admin can then add the rest of the team.
Viewing vs signing Reading the draft needs no account — the link is enough. Signing does: it is the act that turns a suggestion into a confirmed, defensible fact, so it must be tied to a verified person. The first person to sign in on a claim becomes its admin and can manage the rest of the team.
Branch — “this record isn’t yours to sign yet” Access is per record, never portal-wide. When the draft was addressed to a specific person, only that address can be the first to sign in and claim it. Sign in with a different address and the record says so plainly — “This record doesn’t know you yet … you have no role on this record.” It is not an error and you are not locked out; the record is waiting for the right person. Two fixes: if your team has already claimed it, ask its admin to add you; if nobody has claimed it and it was addressed to a colleague, have that colleague do the first sign-in, or ask the engineer to re-send the invitation to your address.

3 · Reviewing commits you to nothing

This is worth stating plainly, because your name may one day go on this record. Opening the link, reading every activity, even filling in the legal calls — none of it signs anything. The record stays a DRAFT until a named person deliberately signs it, and the DRAFT is free forever. Nothing on the claim asks for a card to read or to fill. Signing is a separate step, covered on Unlock, sign & maintain — you reach it only when your team decides the record is ready.

4 · Read what the record shows

The record opens as a finished-looking document built from the engineer’s real tables — not a blank form. Three things orient you:

A “Read this first” block sits at the top of the claimed record, under the letterhead: what it is, where it came from, what is done and what is still blank — with a provenance line stating exactly what left the engineer’s machine, a coverage banner when a source could not be reached, and a “Where this stands” card in the rail carrying the counts:

what you'll see — the top of the claimed record, not signed in · the coverage banner, the letterhead, “Read this first” with its provenance line, and the counts in the rail (a static picture, not a live app)
Regixo compliance portal · EU-hosted Have edits to make? Sign in

GDPR · Art. 30 · Record of Processing — drafted from your own systems

Record of Processing Activities

DRAFT

A plain list of every way your company uses people’s personal data — drafted from the sources you configure. EU law (GDPR Art. 30) makes most companies keep one. Each entry is an activity: your datasets, grouped by the job they serve. Not yet defensible — it becomes official when the legal fields are confirmed and a named person signs.

3 records · 3 named · 3 with open calls

Your engineering team answered their part on 2026-07-10. 3 fields came from them — security measures, recipients, data subjects. They are facts about the systems, not legal decisions: yours to review and confirm below.

Read this first

  • What this is — the list of how your company uses people’s personal data — the “Record of Processing” most EU organisations must keep.
  • Where it came from — your engineering team mapped the sources they configure with Regixo, which drafted this from their schemas.
  • What’s done — the data inventory is mapped for you.
  • What needs you — 10 legal calls are still blank — purpose, your lawful basis, retention and transfers. Your team fills them below; then you sign.
  • Your privacy — what reached this page is metadata only: the drafted record, the names of the 4 tables behind it, and counts. No column names, no column types, no row values — they never left your team’s machine.
  • What’s not coveredsnowflake-dwh, stripe (unreachable at the last scan).

Forwarded draft — received 2026-07-10 · what left their machine: metadata only — the names of the 4 tables these activities are built from, the drafted record, and counts (4 datasets · 9 personal-data flags). No column names or row values, ever. No account needed to review. · what changed → · who is Regixo? →

The same summary, as plain text:

example — the summary line on a claimed record
Record of Processing Activities — DRAFT
GDPR Article 30 · not defensible until your team confirms the legal calls and signs

  Coverage           18 of 22 datasets · 5 of 6 sources reached
  Auto-filled        23 mechanical fields
  Needs you          14 legal fields across 6 activities
  Special category   2 activities carry Art. 9 data

One more state to know: staleness. If the engineer’s catalog changes after they send the invitation, their own Record page says so plainly — “Your catalog has changed since you made this … The record behind this link no longer matches what Regixo sees today.” The fix is theirs, not yours: they re-scan and make a fresh invitation. The new link replaces the old one, and everything your team filled in carries over — answers, licence and team members all move to the fresh record.

And if their machine is paired, the record can move while you are reading it. You do not have to watch for that: a small bar appears at the bottom of the page saying “This record was updated <when>”, with See what changed and Reload. It never reloads by itself, and if you have typed an answer that is not yet saved it asks a second time before throwing it away. On a record you have already signed it adds “What you signed is unchanged” — a new copy of the draft arriving never touches the sealed snapshot.

5 · The three first-read checks

You do not need to read every field to know where you stand. On a first pass, check three things:

6 · Decide what’s missing — and get a re-scan

The coverage meter and the banner name any source the last scan could not reach, so a missing system is visible, not silent. Closing that gap is the engineer’s job, not yours — a scanner runs on their machine, against their credentials. What you do is ask, and name the system.

You never re-do filled fields to gain coverage: a re-scan adds what was missing and leaves your confirmed legal calls untouched.

How you know you’re done

You are ready to move on to the legal calls when all of these are true:

Nothing here signs anything. The record stays a DRAFT until a named person deliberately signs it, which is two stations further on.

What works today The forwardable DRAFT PDF plus the claim link is the hand-off that works now — no server for you to stand up, no software to install. The fully hosted, multi-tenant portal (with per-tenant isolation and SSO) is not live yet; the pages here describe the claim experience, they do not stand in for it.
Your engineer and you (from both sides)

The engineer’s side is done: they scanned your real systems, answered their three facts (security measures, recipients, data subjects), and forwarded the draft — only structure ever left their machine. Your side starts now: claim the link, review, and fill the legal calls. The one thing you may still need from them is a re-scan if a system is missing (above); everything else on the record is yours to complete.

REGIXO — documentation · viewing needs no account; signing names a verified person · Glossary