For the complete documentation index, see llms.txt. This page is also available as Markdown.

Compliance overview

Understand how BalkanID measures compliance posture across frameworks.

This feature is currently in Early Access. Contact us if you'd like to have this enabled for your tenant(s).

Compliance helps you measure how your environment aligns with supported frameworks such as SOC 2, ISO 27001, and NIST.

It evaluates connected integrations against framework criteria and surfaces violations, exceptions, and suppressions in one place.

This gives admins and risk managers a shared view of current posture, while keeping configuration controls separate from day-to-day monitoring.

Use Compliance controls to configure the model, and use Compliance posture to review live results.


What you can do

  • Monitor compliance posture across active frameworks.

  • Suppress noise when a criterion does not apply.

  • Accept risk with scoped exceptions.

  • Recompute violations after sync or configuration changes.


Two work areas

Compliance Controls

Use Compliance controls in Settings → Compliance to manage how compliance is evaluated.

This area is available to admins. From here, you can:

  • browse frameworks and criteria,

  • add suppressions and create exception rules,

  • review framework mappings and status,

  • and queue a compliance recompute after configuration changes.

Compliance Posture

Use Compliance posture in Dashboard → Compliance Posture to monitor current results.

This area is available to admins and risk managers. From here, you can:

  • review framework and criteria health,

  • drill into framework summaries and severity trends,

  • browse violations with filtering by entity, integration, and status,

  • and add inline exceptions while reviewing live violations.

Separating controls from posture keeps configuration work with admins, while still letting risk managers manage accepted risk during review.


How compliance violations work

Compliance violations are computed in the background.

The compute job evaluates identities, resources, connections, and credentials (i.e., entities) across your connected integrations.

Each framework criterion maps to one or more controls. When an entity fails a mapped control, BalkanID records a compliance violation with the relevant framework, criterion, severity, entity, integration, and source context.

You do not need to manage the underlying control types differently in everyday use (these are seeded by us). What matters in the UI is that a criterion is backed by one or more controls, and a failed control can produce one or more framework violations.

When computation runs

Compliance recomputes automatically when an integration sync introduces changes that can affect posture. For more on connected systems and their sync context, see Viewing your application integrations and Application Integrations.

Admins can also queue a manual recompute from Compliance controls.

Manual recompute supports either:

  • a single integration, or

  • all integrations.

This is useful after changing suppressions, exceptions, control configuration, or after enabling new framework coverage.

Out-of-date posture warning

If control configuration changed after the last scan, BalkanID shows a warning on the posture summary.

This warning means the displayed statistics may no longer reflect the latest configuration.

Run a recompute from Compliance controls to refresh posture data.


Severity levels

Criteria and violations use five severity levels:

  1. Critical

  2. High

  3. Medium

  4. Low

  5. Informational

These levels appear throughout the experience as colored risk chips. They help teams prioritize review and remediation.


Criteria health states

  • Passing — No active violations exist for the criterion.

  • Failing — Active violations still need attention.

  • Passing with Exceptions — All violations are excepted.

  • Fully Suppressed — A blanket suppression covers the criterion.

These health states appear in framework summaries and criteria tables. They help distinguish real control gaps from accepted risk and intentionally hidden noise. For the behavioral difference between hidden and visible risk, see Suppressions and exceptions.


Learn more

Last updated

Was this helpful?