Skip to content
Sentinel Unity

Governance, risk & compliance

Map a control once.
Satisfy every framework.

One control library behind risk, compliance, policy, assets, third parties, and audit. Assess it once and report against every standard that references it.

Runs on your own infrastructure or hosted. Isolation is row-level either way.

Mapped out of the box · extensible to any authority

Control library

Frameworks are views, not silos

One control carries a graded mapping to every standard that references it, with one standard marked primary and your own internal standard sitting alongside the published ones.

Frameworks and controls

Control

Privileged access is reviewed each quarter by the system owner

PeopleProcessTechnologyDataFacility

PPTDF applicability

One owner · one procedure · one evidence trail

Architecture

Three decisions that shape everything else

Jurisdictions and authorities are data

Model the regulator that supervises you, then map controls to it. Nothing about the engine is hard-coded to one rulebook.

Framework coverage

Runs on-premise or as SaaS

Single-tenant on your own infrastructure, or multi-tenant hosted. Isolation is row-level by company either way.

Platform architecture

Immutable audit log

Every change is recorded in an append-only log, alongside per-module evidence review and approval trails.

Security and trust

Assess

Scored against written descriptors, not opinion

Every question in the library defines what each maturity level actually means, so two assessors reach the same number.

Level 3: Well Defined

A standard process is defined and followed across the organisation.

Every question in the control library carries its own written descriptor at each level.

Govern

Ten asset states, each separately permissioned

A coordinator moves an asset to review. Only an approver can approve it. The split is enforced by the permission model, not by convention.

Draft·asset-coordinator creates

Monitor

Indicators that know what they are attached to

Thresholds resolve to within, warning, or critical, and each indicator links to the controls and findings it bears on.

Privileged accounts without review

KRI · monthly · owner: Security Operations

Within threshold
Critical 65Warning 45Linked to 2 controls and 1 finding

Control

Segregation of duties you can actually evidence

Permission bundles operate at the level of individual lifecycle transitions, with declared conflict rules and logged exceptions.

Asset module permission bundles by lifecycle action
Actionasset-viewerasset-coordinatorasset-approverasset-admin
ViewAllowedAllowedAllowedAllowed
Create and editNot allowedAllowedNot allowedAllowed
Submit for intakeNot allowedAllowedNot allowedAllowed
Send to reviewNot allowedAllowedNot allowedAllowed
Send backNot allowedAllowedAllowedAllowed
ApproveNot allowedNot allowedAllowedAllowed
ActivateNot allowedNot allowedAllowedAllowed
Module settingsNot allowedNot allowedNot allowedAllowed

Every module ships bundles at this granularity. Segregation-of-duties conflicts are declared as rules, with logged exceptions.

In the platform

What each module actually does

Frameworks & Controls

One library, every framework as a view

A control carries graded mappings to each standard that references it, with one marked primary.

Explore the module

Control

Privileged access is reviewed each quarter by the system owner

PeopleProcessTechnologyDataFacility

PPTDF applicability

One owner · one procedure · one evidence trail

1 of 6
An empty boardroom with a long table and floor-to-ceiling windows

Reporting

The pack the board reads comes from the same record

Reporting draws directly from the register, so the number in the board pack and the number in the platform cannot drift apart between quarters.

  • Board rollup snapshots generated from the live register, not re-keyed
  • Hierarchy aggregates so a group view and an entity view agree
  • Report jobs, schedules, and saved presets for recurring packs
  • Share links, webhooks, and BI export where the pack has to leave the platform
How the platform fits together

Frameworks

Every standard in one model

International baselines, national regulations, and your own internal standards live in the same control model, mapped to each other rather than maintained in parallel.

  • Control library imported and mapped
  • Assessment templates and questionnaires
  • Maturity scoring per framework
  • Evidence reuse across mapped controls
All frameworks
Supported compliance frameworks
FrameworkType
NCA ECCNational
SAMA CSFFinancial
PDPLPrivacy
ISO/IEC 27001Global
NIST CSFGlobal
Your regulatorConfigurable

See it running against your frameworks

Bring the standards you are held to and the way your entities are structured. We will walk the risk, compliance, and audit workflows end to end against them.