It’s one fabric, not separate jobs
A single control links to the policy that defines it, the risk it mitigates, the evidence that proves it, the vendor it touches, and every framework that asks for it. Change one and the rest move.
Who it’s for
Security, risk, compliance, privacy, audit, and governance all answer one question for a business: can we be trusted, and can we prove it? Their work isn't a list of separate tasks. It's a single web of controls, policies, risks, evidence, vendors, and frameworks that all point at each other. That's what Compass is built for.
A single control links to the policy that defines it, the risk it mitigates, the evidence that proves it, the vendor it touches, and every framework that asks for it. Change one and the rest move.
Most of the effort isn't writing. It's re-stitching that web by hand each cycle: chasing the source behind a claim, re-explaining a control to the next questionnaire, reconciling the same risk across four spreadsheets.
Compass stitches that larger context together so every phase of the loop draws on the same connected record instead of starting from a fresh blank page.
Use cases
Most trust work runs on a loop. The Compass core reads your workspace and runs the same Plan → Do → Check → Act cycle. Whether it's a single policy draft or a sixty-framework programme, it assembles context, drafts the artifact, and leaves the human in control. Tap or hover a node to see how the one agent carries each job.
Plan
Do
Check
Act
Point Compass at your framework and last cycle's evidence; it drafts the scope, in-scope systems, and control list — cited to what already exists.
scope traced to evidence
objectives & processes
implementation & execution
monitor, measure, evaluate
improve & report
One workspace. Each phase reads the same evidence base so nothing gets re-entered or re-explained as work moves through the cycle.