What it's for
Tracking implementation state for each control that applies to the selected agent. This is the source of truth that questionnaire answers, citations, and your trust page all read from.
When you use it
Whenever you finish a piece of security work — and before answering a questionnaire, so your answers reflect reality.
What's on the screen
Controls grouped by pillar. Each row shows the control ID (e.g. SEC-01), name, a mandatory badge where applicable, current status, an evidence badge if tests map to it, and a description. A dropdown on the right sets status.
How it works
Four statuses: not started (0), in progress (0.4), implemented (1.0), N/A (excluded from the denominator).
Evidence badges are separate from status. They come from your latest test run mapped by category — you don't set them, and a passing test doesn't automatically mark a control implemented. Status is your assertion; evidence either supports or contradicts it.
When those two disagree — implemented status, failing tests — the control becomes contested and scores 0.2, below an honest "in progress."
Gotchas
- Controls are per-agent. Switching agents in the sidebar changes this list entirely.
- N/A is not a shortcut. It's for structurally inapplicable controls. A reviewer seeing half your Security pillar marked N/A will ask why.
- Changes are saved instantly — no save button.
Related
Work through your control checklist · AIUC-1 and the six pillars