Audit and Compliance
Who did what in whose estate, how much of a framework the book covers, and the export that reconciles what you delivered.
On this page (4)
Audit and Compliance Documentation
Compliance in the portal covers three separate questions, each answered from its own source rather than from a summary the firm keeps about itself.
Who did what, in whose estate
Audit is the record of actions taken inside a customer's estate, and it is read from that customer's own record on the plane. The customer sees the same entries you do, which is what makes the record worth anything: it is not a report about the firm, written by the firm.
For an entry to name a person rather than the firm, that person has to be an operator, a technician the control plane can name individually. Your team and roles covers who is one, and join a firm is how the authority lands on their key.
How much of a framework is covered
Compliance reports control coverage per framework, for one customer or across the book.
Coverage answers the detection half of the same question. It is an ATT&CK matrix for the book that separates what the graph saw from what an on-host sensor saw, and marks which tactics were actually recorded rather than which are theoretically in range. A tactic nothing recorded is shown as unrecorded, because a matrix that shades in what the product could see in principle is a matrix that tells you nothing about this book.
What you delivered
The portal generates a reconciliation export: a CSV file listing each customer's usage over the period you choose, which you feed into whatever system keeps your service records.
It is a file you fetch rather than a connection you configure, so nothing has to be granted on the other side and nothing is pushed anywhere on your behalf. Case records and DNS records export separately in OCSF, for a customer who wants the raw events in their own tooling.
Reading the three together
An artifact is defensible when the three agree: the action appears in the audit record of the estate it touched, the control it satisfies appears in the framework report, and the endpoint it acted on appears in the export.
Prove and report is where that gets packaged for a customer, and the response verbs are what wrote the audit lines in the first place.