The Action Center

One prioritized list of what to fix, assembled automatically from gaps, drift, access findings and expiring evidence.

Core concepts · 2 min read

The Action Center is the answer to "what do I do next". It's assembled from four sources, and tasks close themselves when the underlying condition goes away.

Where tasks come from

  • Gaps — a control in an active framework that no evidence covers.
  • Drift — a monitored setting that moved out of compliance.
  • Access — a person your directory marks inactive who still holds live access in a connected system.
  • Expiring evidence — evidence past, or close to, its validity date.

You can also create tasks by hand. Manual tasks are never touched by the automatic sync.

Tasks that close themselves

Fix the underlying condition and the task completes on the next sync, with a timestamp. Upload evidence for a missing control and its gap task closes. Re-enable MFA and the drift task closes.

Access tasks work differently, on purpose

An access task closes only on positive evidence that the access is gone — a later sync observing the entitlement absent — or because the person is active again. It will not close merely because we stopped being able to look, which is what happens if the provider is disconnected. If a revoked entitlement reappears, the task reopens.

More in Core concepts

Evidence and control mappingHow a document becomes control coverage — confidence scores, the human-confirm gate, and reuse across frameworks.Integrations and continuous monitoringConnect your stack so evidence collects itself, and drift is caught the day it happens.
← All documentation