For the complete documentation index, see llms.txt. This page is also available as Markdown.

Compliance posture

Monitor framework health, review violations, and add inline exceptions.

Use Dashboard → Compliance Posture to monitor compliance results.

Admins and risk managers can access this area.

This is the operational view of Compliance. Use it to understand current framework health, investigate violations, and manage accepted risk during review.

For the configuration workflows behind posture, see Compliance controls. For the rule behavior behind hidden versus visible risk, see Suppressions and exceptions. For a broader tenant-wide discovery view, see the BalkanID Summary Dashboard.

The compliance posture summary dashboard — showing a bird's eye view of violations and posture health across frameworks.

Summary dashboard

The summary view starts with stat tiles which highlight your current compliance posture.

  • Active Violations

  • Violations Marked as Exception

  • Total Exception Rules

  • Blanket Suppression Rules

  • Scoped Suppression Rules

  • Total Suppression Rules

Below the tiles, we show one card per active framework showing compliance percentage and violation counts.

Select a framework card to open its detail view.

The tile counts and framework states use the same criteria health states described in the overview.


Framework detail view

Each framework has a dedicated summary view, showing a general overview of the framework from a compliance posture perspective, with information on the:

  • overall compliance percentage,

  • criteria health

  • and violation counts.

This also includes a chart showing:

  • severity levels at a glance,

  • a per-integration display of violation and criteria status,

  • an employee-level view to see violations-per-employee,

  • and a detailed table for criteria health (which also show details on the controls mapped to each criteria).

You click through into the tables and charts to be taken to a filtered and granular view of the underlying violations.

This view is designed for investigation. You can move from framework-wide trends down to a single criterion or a filtered set of violations in a few clicks.


Violations table

The Violations tab lists every compliance violation in a granular and easily-filterable manner.

Each row can show:

  • Framework

  • Criterion

  • Severity

  • The affected identity, resource, connection or user

  • Integration

  • Control which was violated (and mitigation details)

  • The date on which the violation was last detected

  • Exception status

You can inspect who is affected, what control triggered the finding, and whether the issue should remain active or be excepted.

You can also view further details on the control that flagged a particular violation, as well as any mitigation recommendations, by clicking on the control cell in the table.


Add an inline exception

If a violation is not excepted, the row shows Add Exception.

Use it to create a scoped exception from the violation itself.

1

Open the quick exception panel

Click Add Exception in the violation row.

2

Review the violation context

The panel shows framework, criterion, severity, and entity details.

Add a reason if needed.

3

Save the exception

Submit the exception.

BalkanID refreshes the table after success.

After success, BalkanID confirms:

Exception added. Matching violations will be marked as excepted.

If a violation is already excepted, the row shows an Excepted badge.

The badge tooltip shows the exception reason.

Admins can use the badge to jump to the matching exception rule in Compliance controls.

Inline exceptions let risk managers participate in posture review without giving them full configuration access to the Compliance controls area.


Out-of-date posture warning

A yellow banner appears if control configuration changed since the last scan, or if it detects new frameworks. It warns that summary statistics may be stale. You can then view the global and per-integration posture recency by clicking on the button.

Queue a recompute from Compliance controls to refresh the dashboard.

Last updated

Was this helpful?