Update company context and frameworks
Change heyGRC company profile and frameworks after first setup. GET current config, merge, PUT only what changed. Store the API key like a password.
First-time setup: Set up with your agent. This page is later: you already have an org, and you want to change the company profile, add or drop a framework, or both.
There is no heyGRC MCP. The same REST API does the update. Paste this page (or the setup prompt) at your coding agent.
You need the API key in the environment
Updates use GET and PUT on https://api.heygrc.com/v1/config with a per-org hgrc_… key (config:read and config:write).
Store that key like a password, anywhere the next agent can read it without putting it in chat or in git:
- a shell environment variable (
export HEYGRC_API_KEY=…) - a password manager
- the OS keychain
Keychain is optional. An env var is what the docs tell agents to check.
The key is shown once at creation. If you lost it, create a new key in the console (API keys). Do not paste the new token into chat. Set it in the environment, then tell the agent it is set. Old keys keep working until you revoke them. One org may have several keys.
Send the key only as a header, never in a URL:
printf 'header = "Authorization: Bearer %s"\n' "$HEYGRC_API_KEY" \
| curl -sS -K - https://api.heygrc.com/v1/configHow to change it
A present field replaces that field. An omitted field stays. So:
- Sending
"frameworks": ["AIUC_1"]drops every other framework. - Sending a new
profileobject replaces the whole profile. - Omitting
profileleaves the company context alone.
Do this:
GET https://api.heygrc.com/v1/config- Merge. For frameworks, start from the list you just read, then add or remove IDs. Confirm IDs on
GET https://api.heygrc.com/v1/frameworks(no auth). - Show the human the JSON you will send (key redacted) and wait for yes.
PUTonly the fields you change.GETagain and show what is stored.
Contract: API reference. US-only walkthrough (same GET-then-PUT): Configure US frameworks.
Add one framework (keep the rest)
Example: the org already has ISO 27001, SOC 2, and GDPR. You want to add AIUC-1 (AIUC_1).
# 1. Read current state
printf 'header = "Authorization: Bearer %s"\n' "$HEYGRC_API_KEY" \
| curl -sS -K - https://api.heygrc.com/v1/config
# 2. PUT only frameworks: current IDs plus the new one
cat > /tmp/heygrc-config.json <<'EOF'
{
"frameworks": ["ISO_27001", "SOC_2", "GDPR", "AIUC_1"]
}
EOF
printf 'header = "Authorization: Bearer %s"\n' "$HEYGRC_API_KEY" \
| curl -sS -K - -X PUT -H "Content-Type: application/json" \
--data @/tmp/heygrc-config.json \
https://api.heygrc.com/v1/config
rm -f /tmp/heygrc-config.json
# 3. Read back
printf 'header = "Authorization: Bearer %s"\n' "$HEYGRC_API_KEY" \
| curl -sS -K - https://api.heygrc.com/v1/configUse the IDs from your GET, not this sample list.
Change company context (keep frameworks)
profile is free-form JSON. Present = the whole object is replaced, so include every field you still want.
cat > /tmp/heygrc-config.json <<'EOF'
{
"profile": {
"company": "Acme Inc",
"product": "B2B SaaS for invoice automation",
"data_handled": "customer PII, payment metadata, uploaded documents",
"hosting": "EU, AWS eu-central-1",
"compliance_posture": "pursuing ISO 27001 and SOC 2; ships an AI feature"
}
}
EOFSame PUT as above. Omit frameworks so the selected list does not change.
Console
You can also change profile and frameworks in the console: app.heygrc.com → company context / frameworks. The API and the console write the same org config.
Review cadence (auto, auto_once, mention_only) stays in the console.