Skip to Content
Policy and AuthorityPolicy ControlsEnforcement

Enforcement

Policy & Authority

Enforcement provides compliance monitoring for published policies. Once a policy reaches Published status, the Enforcement module tracks compliance posture through KPI and KRI definitions, monitors compliance incidents, and provides a consolidated view of policy effectiveness across the organization.

Enforcement applies to policies that have reached Published status in the Policy Library. Implementation progress for individual controls is tracked through Control Mapping.


Enforcement view

Navigate to Policy Lifecycle > Enforcement to see all published policies with their compliance status. This view provides an at-a-glance overview of enforcement posture across the organization. An enforcement stats bar at the top summarizes key metrics including total published policies, compliance rates, and open incidents.


Compliance tracking

Each published policy tracks three dimensions of compliance:

  • Compliance Status — the overall compliance posture for the policy, reflecting control implementation and incident history
  • KPI Definitions — Key Performance Indicators that measure policy effectiveness, stored as JSON and configurable per policy
  • KRI Definitions — Key Risk Indicators that flag emerging compliance risks, stored as JSON and configurable per policy

KPIs and KRIs are defined at the individual policy level, allowing each policy to have metrics tailored to its specific compliance requirements.


Compliance incidents

When a policy violation or compliance gap is identified, it is tracked as a compliance incident linked to the relevant policy.

Incident severity

SeverityDescription
LOWMinor deviation with limited impact
MEDIUMNotable compliance gap requiring attention
HIGHSignificant violation with potential business impact
CRITICALSevere breach requiring immediate remediation

Incident status

StatusDescription
OPENIncident identified and awaiting response
IN_REMEDIATIONCorrective actions are underway
RESOLVEDRemediation completed and verified
CLOSEDIncident fully resolved and documented

Permissions

PermissionAccess
policy:manageCreate and manage compliance incidents, configure KPI/KRI definitions, update compliance status
policy:readView enforcement status, compliance metrics, and incident history
Last updated on