Check control status
1
Open Compliance
Open Security and click the Compliance tab.
2
Refresh the estate evidence
A banner shows when the AWS scan and the GitHub scan last completed, and that they run daily.
Click Run posture scans now to start both. Results appear on the page as they finish. If a
scan is already running, the page tells you instead of queueing another.
3
Pick a framework
The tabs are ISO 27001:2022, SOC 2, CIS AWS Foundations and NIST CSF 2.0.
Controls are grouped by category, for example Organizational and Technological for ISO, or
Identify, Protect, Detect, Respond and Recover for NIST.
4
Read each control
Every control shows a reference, a title, a status and a one-sentence summary. Open Evidence
to see the records behind it, each linked to the page in the app where it lives.
Only controls the platform can evidence from live records appear. Controls that live in documents, such as policy sets or supplier registers, stay in your own governance tool.
Act on a control
- Attention. Click Create card with this evidence to put a high-priority card on the board, labelled
compliance, carrying the summary and evidence links. - No data. Open What would light this up: a read-only grant, review the permission statement, and click Request this grant as a card to hand it to whoever owns your AWS account. Full permission set opens Settings, Infrastructure. Every action in the statement is a read.
- Copy for GRC. Click it on any control to copy its status, counts and evidence links to your clipboard for a GRC tool, an auditor email or a spreadsheet. The links are absolute, so they work when pasted.
Run the access review
The Access review card generates this month’s review as a card on the board. It lists every member, every collected AWS principal and the Identity Center estate, and asks the reviewer you pick for a sign-off. The decided approval becomes the evidence.1
Pick a reviewer
Choose a member from Pick a reviewer.
2
Generate the card
Click Generate review card. The card appears on the board, and the flash message names it.
Export evidence for an audit period
An audit period is the window an export speaks for. The page evaluates a rolling 90 days, while an export evaluates the period’s own dates.1
Create a period
Under Audit periods, enter a Name such as
SOC 2 FY26, choose the Framework, set
Starts and Ends, and click Create period.2
Export the bundle
Click Export bundle on the period’s row. You download a zip.
3
Keep the hash
The period row shows the first characters of the bundle’s top hash. It identifies the manifest,
so you can match a bundle someone presents later to the period that claims it.
What happens next
Statuses move as your estate does. Resolve the cards you created, run the scans again, and the control returns to supported when the records agree.Related
- Control data privacy and retention: export your retention policy as evidence.
- Manage people and roles: the member list the access review covers.
- Track work on the ops board: where evidence cards land.

