For the complete documentation index, see llms.txt. This page is also available as Markdown.

Compliance overview

Understand how BalkanID measures compliance posture across frameworks.

This feature is currently in Early Access. Contact us if you'd like to have this enabled for your tenant(s).

Compliance helps you measure how your environment aligns with supported frameworks such as SOC 2, ISO 27001, and NIST.

It evaluates connected integrations against framework criteria and surfaces violations, exceptions, and suppressions in one place.

This gives admins and risk managers a shared view of current posture, while keeping configuration controls separate from day-to-day monitoring.

Use Compliance controls to configure the model, and use Compliance posture to review live results.


What you can do

  • Monitor compliance posture across active frameworks.

  • Suppress noise when a criterion does not apply.

  • Accept risk with scoped exceptions.

  • Recompute violations after sync or configuration changes.


Two work areas

Compliance Controls

Use Compliance controls in Settings → Compliance to manage how compliance is evaluated.

This area is available to admins. From here, you can:

  • browse frameworks and criteria,

  • add suppressions and create exception rules,

  • review framework mappings and status,

  • and queue a compliance recompute after configuration changes.

Compliance Posture

Use Compliance posture in Dashboard → Compliance Posture to monitor current results.

This area is available to admins and risk managers. From here, you can:

  • review framework and criteria health,

  • drill into framework summaries and severity trends,

  • browse violations with filtering by entity, integration, and status,

  • and add inline exceptions while reviewing live violations.

Separating controls from posture keeps configuration work with admins, while still letting risk managers manage accepted risk during review.


How compliance violations work

Compliance violations are computed in the background.

The compute job evaluates identities, resources, connections, and credentials (i.e., entities) across your connected integrations.

Each framework criterion maps to one or more controls. When an entity fails a mapped control, BalkanID records a compliance violation with the relevant framework, criterion, severity, entity, integration, and source context.

You do not need to manage the underlying control types differently in everyday use (these are seeded by us). What matters in the UI is that a criterion is backed by one or more controls, and a failed control can produce one or more framework violations.

When computation runs

Compliance recomputes automatically when an integration sync introduces changes that can affect posture. For more on connected systems and their sync context, see Viewing your application integrations and Application Integrations.

Admins can also queue a manual recompute from Compliance controls.

Manual recompute supports either:

  • a single integration, or

  • all integrations.

This is useful after changing suppressions, exceptions, control configuration, or after enabling new framework coverage.

Out-of-date posture warning

If control configuration changed after the last scan, BalkanID shows a warning on the posture summary.

This warning means the displayed statistics may no longer reflect the latest configuration.

Run a recompute from Compliance controls to refresh posture data.


Severity levels

Criteria and violations use five severity levels:

  1. Critical

  2. High

  3. Medium

  4. Low

  5. Informational

These levels appear throughout the experience as colored risk chips. They help teams prioritize review and remediation.


Criteria health states

  • Passing — No active violations exist for the criterion.

  • Failing — Active violations still need attention.

  • Passing with Exceptions — All violations are excepted.

  • Fully Suppressed — A blanket suppression covers the criterion.

These health states appear in framework summaries and criteria tables. They help distinguish real control gaps from accepted risk and intentionally hidden noise. For the behavioral difference between hidden and visible risk, see Suppressions and exceptions.


Compliance in access governance

Compliance signals are available in access reviews and campaign policies.

Access reviews

The Compliance Violations column shows active, non-excepted violations affecting an access relationship. It shows the highest severity, the number of violations, and Direct when the violation applies to the exact access under review.

Open the column to inspect violations. They are grouped by severity, then control.

This compliance context always uses the current compliance state. Remediated or excepted violations do not appear.

Campaign policies

Campaign policies can use Active Compliance Violation as a condition for auto-actioning or auto-reassigning reviews. This opens up avenues such as auto-denying access to connections which may cause a high severity Separation of Duties (SoD) violation, or re-assigning all SOC 2 violations to the reviewer handling your compliance certifications.

Match any active violation, or narrow it by severity, framework, criterion, or control. You can also choose whether it applies to the reviewed entity, target entity, or access relationship.


Learn more

Last updated

Was this helpful?