Creately Compass
Creately Compass · Compliance intelligence SOC 2 · ISO 27001 · HIPAA

Compliance evidence review that shows what is ready — and exactly why.

Compass brings controls, process evidence, infrastructure facts, and reviewer decisions into one connected view. AI helps reconcile what belongs together; every claim stays visible, source-backed, and under human review.

The relevant contextControls, process evidence, infrastructure, and review history
AI-assisted reconciliationConnections proposed with their sources attached
Visible human controlReview what counts, what is blocked, and what changes
LIVE PRODUCTCompass · Compliance AuditAuditRun f873dd25 · SOC 2 Type II
app.creately.com / compass / soc-2-type-ii
2 drifts · 4 evidence stale Audit · Q4 '26
FRAMEWORKS
  • SOC 2 II 47/56
  • ISO 27001 81/114
  • HIPAA 38/45
  • NIST 800-53 —
  • PCI DSS —
  • GDPR 29/34
TSC FAMILY
  • Common Criteria (CC)
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy
SOC 2 · Common Criteria · 32 controls
FilterGroupSort: severity ↓
CC1.1 Code of conduct
Met
CC1.2 Board oversight
Met
CC2.2 Comms of objectives
Met
CC3.1 Risk identification
Met
CC3.4 Risk mitigation tracking
Drift
CC5.1 Control activities
Met
CC5.3 Policy deployment
Met
CC6.1 Logical access — agent diff
Drift
CC6.6 Boundary protection
At risk
CC7.2 Anomaly detection
Met
CC7.3 Incident response
Met
CC8.1 Change management
Met
CC6.1 Drift
Logical access controls

The entity implements logical access security measures to protect against threats from sources outside its system boundaries.

JOINED CHAIN
P Access Control Policy v4.2 ●
P Joiner / leaver process ●
P Privilege review · quarterly ●
Evidence
aws.iam · roles snapshot 2h
okta · privileged groups drift
github · branch protection 1d
✦ compass-agent · just now
Re-scanning Okta privileged groups for CC6.1 drift…
Found: 2 new admin grants, 1 stale.
→ Draft remediation task for J. Wei
Linked sources · AWS · Okta · GitHub · Workday · 4 more Last sync · 2 min ago
The full picture behind every control

Your tools already hold pieces of the answer. Compass connects them.

Policies explain intent. Processes show how the work should happen. Infrastructure and identity systems show what is actually running. Compass keeps those pieces connected so your team — and its AI — can reason from the same context.

Bring the evidence together

Start with the systems you have. Build the connected view you need.

01 · Creately ProcessWhat you sayYour policies become editable process flows — every step, field, owner and mapping traceable to its source.Explore Process →
03 · Creately CompassWhat is readySee which requirements have credible support, where the gaps are, and what still needs a person.Inspect the connected view →
Connected context you can inspect

Turn scattered evidence into an answer you can see and question.

Compass resolves the same system, owner, control, and activity across sources. The graph is the mechanism, not the pitch: it gives people and agents one inspectable context instead of a pile of disconnected files.

P

ProcessWhat you say · 42 flows

B

BlueprintInfrastructure and dependencies

A

AtlasIdentity · Entra + Okta

Compass federates them on shared entities — a system, an owner, a control
Framework requirementWhat you sayWhat you runCompass

CC6.1Access reviewed on a cadence

SOP: every 90 days

IAM: last review 134d agoBlueprint · cloud

△ Gap

CC6.2MFA enforced for all users

Policy: MFA required

Entra / Okta: 3 admins exemptAtlas · identity

△ Gap

CC6.6Data encrypted at rest

Policy: encryption required

S3 / RDS: KMS enabledBlueprint · cloud

✓ Aligned

CC7.2Audit logging enabled

SOP: multi-region logging

CloudTrail: multi-region onBlueprint · cloud

✓ Aligned

23

Readiness, scored liveEvery clause, against every source — recomputed on change

Audit pack — gated ↗Sealed until blockers clear

Entity resolution

“Warehouse” and “Warehouse Team” collapse to one canonical node.

Provenance on every link

Each join cites a verbatim process step, identity record, or cloud resource.

Federates your GRC too

Vanta or Drata evidence joins the graph — no rip-and-replace.

A direct answer, with the evidence behind it

Know what is ready, what is blocked, and what needs a person.

Compass can summarize readiness because every result stays connected to its sources. Open the number, inspect the blocker, challenge the connection, and decide what happens next.

Gated for exportA blocker keeps the pack non-shareable.
One run, every sourceAn immutable, period-specific baseline.
Eight readiness gatesSources, health, review and export all tracked.

Audit runSOC 2 Type II · FY2026

RUNNING · 2 SOURCES

Readiness23%1 blocker · 6 findings

✓ Framework✓ Sources✓ Source health4 Period5 Review6 Export

BLOCKER · CC6.1Access review cadence is not supported by live evidence.Policy says 90 days · IAM shows 134 days since review

AI you can work with, not just ask

AI can trace the connection. Your team can inspect and correct it.

Creately’s visual surfaces make the agent’s reasoning tangible. Review the process step, cloud dependency, control, or finding in context — then accept, edit, or reject the proposed change.

Human control is part of the workflow

Every AI-assisted step stays visible and reviewable.

AI can read, structure, match, and suggest. Provenance, confidence, and human sign-off decide what becomes accepted evidence.

  1. 01SourceDid we read the document?
  2. 02OutlineRight processes and parents?
  3. 03EvidenceSupported by the source?
  4. 04DiagramsFaithful to the records?
  5. 05PublishReady for the repository?
CLAUSE · SOC 2 TYPE IICC5.3 · Control activities3 claims · 2 accepted · 1 needs review

95%Security review follows every material release.Verbatim source: Release Management SOP · §4.2Accepted

87%Emergency changes receive retrospective approval.Suggested match · human sign-off requiredReview

01

Every claim is traceableA real process step or control with a verbatim quote and source link.

02

A confidence score on eachReviewers spend their time only where the model is unsure.

03

AI waits for human sign-offNothing counts as evidence until a person accepts it.

04

Addressed, and provably soThe clause clears only when its evidence clears.

Trust is part of the connection

Bring the context together without handing over control.

Connect the evidence you already run, retain ownership of the underlying data, and make every agent-assisted conclusion inspectable.

Source-backed evidence

Processes, infrastructure, identity, and review decisions keep their origin.

Credentials stay controlled

Source connections use scoped access designed around the system being inspected.

No black-box conclusion

Open the finding and inspect the facts and relationships behind it.

Open format · no lock-in

Processes and evidence are RDM — export, round-trip, and own them.

Stands alone — or connects

Bring existing GRC evidence into the same review context.

People approve the answer

Agents can suggest; reviewers decide what counts and what changes.

Common questions from security and compliance teams

What teams ask before connecting their evidence.

What is Creately Compass?
Creately Compass connects controls, process evidence, infrastructure facts, and reviewer decisions in one assurance model. Compliance and security teams use it to assess coverage, investigate gaps, and prepare evidence for audit review.
What is the difference between Creately Compass and compliance management software?
Compass focuses on the relationships between controls, documented work, and infrastructure evidence. It complements compliance management systems by bringing Creately Process and Creately Blueprint into the same review context. Reviewers still decide whether the evidence is sufficient.
Can Compass connect process evidence, controls, and infrastructure facts for audit review?
Creately Compass connects process records and source citations with controls and AWS infrastructure facts. An audit run captures a review snapshot, including decisions and source-health warnings, so reviewers can see what supports a conclusion and what still needs attention.
What evidence sources can Compass use?
Compass can read authorized Process and Blueprint folders, control catalogs, manual evidence uploads, and scanner reports. Vanta and Drata connectors are available in beta. Source permissions determine which records are available for a review.
How is Creately Compass priced?
Compass pricing depends on your Creately subscription and the review, evidence, and audit export capabilities required. Check Creately plans and request a Compass quote for your frameworks, connected sources, and review scope.
What security and compliance controls does Compass provide for audit evidence?
Compass uses explicit grants to read source folders and retains reviewer decisions alongside the evidence. Creately’s platform security controls protect hosted data, while Compass helps your team assess its own compliance readiness. See the security overview for Creately’s assurance documentation.
How does Compass keep evidence source-backed, reviewable, and exportable?
Compass retains links between evidence, its source records, and review decisions. Source-health warnings expose missing or stale inputs, and audit runs preserve the review context. Audit-pack exports support handoff; underlying diagram data can also use the RDM format.
The full picture for compliance

Give your team — and your AI — the context behind every review.

Bring the relevant facts together, let AI help trace the connections, and keep the final judgment visible and in human hands.