GRC Guide
Compliance frameworks, policies, and the risk register, sold together as one GRC add-on.
Compliance: frameworks & controls
Enable a framework from the Compliance page. Only frameworks your account manager has allowlisted for you show up as available, out of the full 12-framework catalog (ISO 27001, SOC 2, PCI DSS, NIST CSF, HIPAA, GDPR, CCPA/CPRA, NIST 800-53, CIS Controls, COBIT, FedRAMP, CMMC). Once enabled, track each control's status, owner, and notes. Controls mapped to a continuous test also show how many of those tests are passing and how many are failing. The result comes from open findings on production domains. It does not change the manual status. Controls with no automated test stay on status, owner, and notes. Open Monitoring from Compliance to see each test's latest result, finding count, and whether it is enabled. Open a test to see the findings from its latest run and the earlier runs.
Policies
Draft a policy, edit it freely while it's a draft, then publish it. Editing a published policy creates a new version automatically and resets every member's acknowledgment, so a change to a live policy always requires the team to re-acknowledge it, not silently update under them. Link a policy to one or more controls in the Compliance catalog to show which requirement it satisfies.
Risk Register
Log a risk with a likelihood × impact score (banded low/medium/high/critical), an internal or external source (an external risk can link to a vendor; see the Vendor Security guide), and a treatment plan: accept, mitigate, transfer, or avoid, each with its own owner and due date. Link the controls that mitigate it, and attach supporting documents (stored privately, only visible to your organization).
Who can do what
Owners, admins, and security managers can enable frameworks, edit control status, and manage policies/risks. Any member can view the Compliance catalog and acknowledge a policy for themselves.