Evaluate controls, investigate drift, and export evidence
Operate the Compliance Control Center without treating product evidence as automatic certification.
Before you begin
Use an authorized administrator/operator identity, define the audit scope, and prepare a protected destination for evidence archives.
- Review posture and monitoring recency.
- Investigate failing controls and drift.
- Inspect evidence integrity.
- Preview and export only the required scope.
Open the feature
Open Settings -> Security & Compliance.
Configure and evaluate current posture
Open Settings -> Security & Compliance. On Overview, record the runtime revision, monitoring recency, failing/unknown controls, open drift, and evidence integrity warnings. Open Controls, select a control, and inspect its observed state, evaluation time, supporting evidence, and framework mappings. A mapping means the evidence is relevant; it does not satisfy an entire external standard.
Trigger a monitoring sweep only when authorized. Wait for the queued run to finish, then compare its new evaluations to the earlier baseline. Do not report a stale passing observation as current state.
Investigate drift
Open Control Drift, select the episode, and compare baseline and current evaluations, evidence, and mapped requirements. Assign remediation outside the control center where appropriate. Acknowledge drift only to record that it was seen; acknowledgment does not make the control compliant. Verify remediation with a later passing evaluation and reviewable evidence.
Inspect evidence integrity
Open Evidence Ledger. Search and filter by control, evidence type, and integrity result. Review collection time, source, payload summary, and digest. An integrity mismatch is an investigation condition: preserve the record, restrict export, and inspect storage/key/runtime history rather than deleting it.
How evaluation works
Evaluations capture observed technical state; evidence supports the observation, and framework mappings relate it to requirements without granting certification.
Export a package
Select Export Evidence Package. Choose all controls, selected controls, or a framework; then choose a current snapshot or a historical date range. Preview the counts and scope before export. The downloaded archive includes observed technical state, mappings, supporting evidence, and SHA-256 integrity manifests.
Store the archive as sensitive audit material. Record the product revision, export time, scope, retention owner, and external evidence that OpsKnight cannot collect. Recalculate/verify digests in the review process; never interpret a valid digest as proof that the underlying control passed.
Verify the result
Confirm archive counts match the preview and that manifest, digests, revision, scope, and evaluation window are present.
Remove or undo
An export cannot be recalled. Quarantine an incorrectly scoped archive under your evidence-handling policy and generate a corrected package.
Troubleshooting
- No controls/evidence: verify authorization, runtime evaluation health, and monitoring completion.
- Export unavailable: the signed-in role lacks export capability.
- Historical export is empty: confirm time range and control/framework scope.
- Integrity mismatch: preserve evidence and investigate; do not regenerate an archive merely to hide the mismatch.
- Drift remains after acknowledgment: expected; only a later evaluation can demonstrate remediated state.
Next steps
Last updated for v2.0.0
Edit this page on GitHub