Compliance Controls
Governance in Biztraak is represented as controls and evidence records that can be connected to supported project and deployment workflows.
This helps teams keep review context closer to the work itself, while the exact evidence available depends on the workflow and integration in use.
What are controls?
Controls are the requirements a team chooses to track and evidence as part of a governance, security, or customer review process.
Examples:
- Encryption requirements for data at rest and in transit
- Access logging and monitoring requirements
- Change-management and approval requirements
Biztraak can associate those controls with evidence and operational context from supported infrastructure and code workflows.
How Biztraak automates controls
- Reusable templates: teams can start with pre-structured control mappings and adapt them to their own needs.
- Evidence context: Supported deployments expose operational records that teams can use when assessing relevant controls.
- Dependency context: Component outputs can be used in downstream workflows. they do not by themselves prove that a control is satisfied.
- Dashboards: Show which controls are satisfied, partially satisfied, or still open.
Hub & spoke governance model
Biztraak includes a hub-and-spoke governance model for control management and documentation where the relevant compliance services are enabled.
- Hub: Central Biztraak hub defines frameworks, controls, and automation flows.
- Spokes: Every client can keep an isolated governance workspace for their own evidence and review context.
- Connected evidence: Supported events and records can be made available to a client’s spoke.
- Flows: A configured compliance integration can update spoke control and policy context.
This helps each client keep governance evidence aligned with the latest deployment context, with less lag and less manual chasing.
Example Workflow
- A team deploys a new PostgreSQL database in Biztraak.
- Biztraak provisions the database using the options exposed by the configured compliance integration.
- Available deployment records can be reviewed as evidence context.
- If a governance spoke is configured, supported records can be shared with that workspace.
- The team evaluates the related controls using the available evidence and supporting deployment context.
- Reviewers can inspect the evidence trail in context, without relying on manual screenshots.
Benefits
- Operational visibility: review control context alongside supported project and deployment records.
- Less manual collection: reduce duplicate evidence gathering where integrations expose the required records.
- Hub & spoke isolation: configured client workspaces can keep governance data separated.
- Cross-program reuse: one evidence stream can support multiple review paths.
- Reviewer access: share read-only context instead of building binders.
Roadmap
- Policy Gates: block deployments that would leave mapped controls unsatisfied.
- Multi-program mapping: one deployment can support several internal or external review workflows.
- Control Marketplace: share and import community or industry-specific control sets.
- Expanded GRC integrations: optional connectors for broader governance workflows as needed later.
Next steps
- Framework Support → see how control structures can be organized and connected
- Audit Logs → see the raw evidence stream behind control coverage
- Compliance Overview → big picture of compliance in Biztraak
Controls in Biztraak can stay connected to the work that changes them, giving teams a clearer path to evidence collection, review, and ongoing governance.