Generate a Compliance Report
Close the most common compliance gaps, then export a coverage report for security reviews, vendor assessments, or regulatory submissions.
Close common gaps
Each missing or partial control on the Compliance page includes a recommendation. To resolve the most common gaps:
No human oversight policy — Add a ValidatingPolicy with
mode: approvalfor high-risk tool categories (production writes, credential access).No content safety scanning — Enable the Prompt Scanner in Settings → Security.
Anomaly detection disabled — Enable detection thresholds in Settings → Anomaly Detection (alerts-only mode is sufficient for this control).
No audit retention policy — Configure an S3-compatible export target in Settings → Integrations to retain events beyond the 90-day default.
No identity-level access control — Add a budget rule or deny policy scoped to a specific team or user.
Enabling a capability in audit mode (rather than enforce mode) still counts as coverage for monitoring-class controls, but not for enforcement-class controls. The detail panel distinguishes between the two.
Export a report
Navigate to Security → Compliance.
Click Export report to generate a PDF or CSV summary of your current coverage state — control by control, with status, evidence (which policy or setting provides coverage), and any open gaps.
Use the exported report for:
- Internal security reviews and board-level AI risk reporting
- Customer trust questionnaires and vendor assessments
- SOC 2 or ISO 27001 supplementary evidence (AI controls annex)
- Regulatory submissions where NIST AI RMF alignment is requested
The report timestamps each control's evidence so reviewers can see that coverage was active at the time of the assessment, not just at export time.