Skip to main content
The Compliance tab turns the records SRE Agent already keeps into control-by-control evidence. You see which controls your own history and your connected AWS account and GitHub repositories can speak to, raise cards for the ones that need attention, and export a bundle your auditor can verify. Compliance is a tab of the Security page and is visible to org admins. It shows records, not verdicts: statuses describe evidence, and your auditor decides what it satisfies.

Check control status

1

Open Compliance

Open Security and click the Compliance tab.
2

Refresh the estate evidence

A banner shows when the AWS scan and the GitHub scan last completed, and that they run daily. Click Run posture scans now to start both. Results appear on the page as they finish. If a scan is already running, the page tells you instead of queueing another.
3

Pick a framework

The tabs are ISO 27001:2022, SOC 2, CIS AWS Foundations and NIST CSF 2.0. Controls are grouped by category, for example Organizational and Technological for ISO, or Identify, Protect, Detect, Respond and Recover for NIST.
4

Read each control

Every control shows a reference, a title, a status and a one-sentence summary. Open Evidence to see the records behind it, each linked to the page in the app where it lives.
Only controls the platform can evidence from live records appear. Controls that live in documents, such as policy sets or supplier registers, stay in your own governance tool.

Act on a control

  • Attention. Click Create card with this evidence to put a high-priority card on the board, labelled compliance, carrying the summary and evidence links.
  • No data. Open What would light this up: a read-only grant, review the permission statement, and click Request this grant as a card to hand it to whoever owns your AWS account. Full permission set opens Settings, Infrastructure. Every action in the statement is a read.
  • Copy for GRC. Click it on any control to copy its status, counts and evidence links to your clipboard for a GRC tool, an auditor email or a spreadsheet. The links are absolute, so they work when pasted.

Run the access review

The Access review card generates this month’s review as a card on the board. It lists every member, every collected AWS principal and the Identity Center estate, and asks the reviewer you pick for a sign-off. The decided approval becomes the evidence.
1

Pick a reviewer

Choose a member from Pick a reviewer.
2

Generate the card

Click Generate review card. The card appears on the board, and the flash message names it.

Export evidence for an audit period

An audit period is the window an export speaks for. The page evaluates a rolling 90 days, while an export evaluates the period’s own dates.
1

Create a period

Under Audit periods, enter a Name such as SOC 2 FY26, choose the Framework, set Starts and Ends, and click Create period.
2

Export the bundle

Click Export bundle on the period’s row. You download a zip.
3

Keep the hash

The period row shows the first characters of the bundle’s top hash. It identifies the manifest, so you can match a bundle someone presents later to the period that claims it.
The zip contains a summary of every control, one evidence file per control, and a manifest with a checksum for each file. A checksum detects alteration. It does not prove who produced the bundle, and the manifest says so.
Create the period first and export it after the window has passed, so the bundle covers the whole window.

What happens next

Statuses move as your estate does. Resolve the cards you created, run the scans again, and the control returns to supported when the records agree.