SoxDesk Quick Start
From zip file to a working audit in about 10 minutes. No installation, no admin rights, no database server.
What you need
- A Windows PC (64-bit) and a modern browser.
- The SoxDesk portable zip (
SoxDesk-portable-win64.zip). - Optional, for team use: a network-share folder everyone can read and write.
1. Unzip and start (2 minutes)
- Unzip
SoxDesk-portable-win64.zipanywhere — your desktop,C:\Apps, wherever. - Open the
SoxDeskfolder and double-clickSoxDesk.cmd. - A minimized "SoxDesk Server" window starts (that's the app — close it to stop SoxDesk).
- Open your browser at http://localhost:5179.
Everything the app stores — database, evidence files, automatic backups — goes in a DataStore folder next to the app. Nothing is written anywhere else.
2. Create the admin account (1 minute)
The first run shows a one-time setup screen. Enter your name and email to create the initial admin account. This screen only appears while no admin exists — after that, all user management happens on the Admin page.
3. Sign in (1 minute)
SoxDesk supports three sign-in modes, selectable on the Admin page (Login method):
- Password — local username + password, fully offline, no mail server needed. You can set a password for the admin account right on the first-run setup screen.
- One-time email codes (the default) — 6-digit codes sent to the user's email. Until you configure your company's SMTP server (see the Admin Guide), codes are shown directly in the server window log and on the Admin page → Pending login codes table (visible to admins). Codes expire after 10 minutes.
- Corporate directory (LDAP / Active Directory) — users sign in with their existing AD credentials. Configure and test it under Admin → Directory, then switch the login method (see the Admin Guide for the fields).
For a quick evaluation, password or email codes are simplest — set a password at first run for the smoothest start.
4. Load the sample audit (1 minute)
On the audit-selection screen, click Load sample SOX audit. You get a realistic audit — areas, controls, tests, walkthroughs, IT dependencies, applications, and workpapers — which is the fastest way to see how everything connects. Recommended stops:
- Dashboard — status tiles, progress by area, open findings, current checkouts.
- Controls — the tester/reviewer workflow (Start → Submit for review → Complete), leverage markers, and the "Import / bulk update from CSV (RCM)" panel.
- IT Linkage — walkthroughs → IT dependencies → applications → ITGC scoping, with uncovered in-scope applications flagged.
- Report — the connected area → control → test → finding view, with CSV, Excel, and archive-zip export.
Or click Create audit and start clean — the fastest way to populate a real audit is the RCM CSV import on the Controls page (there's a downloadable template).
5. Share one audit file with your team (3 minutes)
This is the whole "deployment":
- Create a folder on a network share your team can read/write, e.g.
\\fileserver\audit\SoxDesk-Store. - On the Admin page → Data store card, enter that path and click Save.
- Restart SoxDesk (close the "SoxDesk Server" window, double-click
SoxDesk.cmdagain). Your local data is not moved automatically — for a fresh start just point at the empty folder; to carry your evaluation data over, copy the contents of your localDataStorefolder into the share before restarting. - Each team member unzips their own copy of SoxDesk and points their Data store at the same folder.
Everyone now works in one shared audit file. Item-level checkout locking prevents two people from editing the same workpaper at once, and sign-in sessions roam — a user signed in on one install stays signed in on another install pointing at the same store.
Working offline? Check a workpaper out, click Offline copy to download a self-contained editor (a single HTML file that needs no connection), edit it anywhere, then use Check in from file on the Workpapers page when you're back online. Your checkout is held the whole time.
6. Add your team (2 minutes)
On the Admin page:
- Users card — add each person with name, email, and role (
member, oradminfor people who manage users/settings). - Team card — add users to the audit as
lead,tester, orreviewer.
Assign a tester and reviewer on each test (Controls page) and the enforced workflow takes it from there: not started → in progress → ready for review → complete, with the reviewer required to be a different person than the preparer.
Trial and licensing
SoxDesk is full-featured for 60 days from first run. After that it becomes read-only — sign-in, viewing, and exports keep working, so your data is never locked away. To license, paste your key on the Admin page → License card. Validation is an offline signature check; SoxDesk never contacts the internet.
Next steps
- Admin Guide — SMTP setup, backups and restore, data store details, host/port overrides.
- Deployment Guide — for IT: per-user installs with a shared store, or a central server on a VM.
- Security Overview — the one-pager to hand your IT department.
Questions: support@soxdesk.com (async email support, 48-hour response).