Continuous Control Monitoring
Evidence that refreshes itself.
Works with
What it does
Point-in-time compliance is a screenshot taken the week of the audit. Continuous control monitoring replaces it by pulling live posture from the security tools you already own, on a schedule.
A connector collects, a rule turns what it returned into a pass or fail against a specific control, and the result lands on that control with full provenance: which run, which connector, what time.
Connectors run inside the platform wherever it is deployed, and each connection can reach only the hosts allowed for it. That is what makes monitoring work on-premises and in air-gapped deployments too.
Connections
A guided wizard per connector kind covering credentials, scope and schedule. Secrets are stored per tenant and encrypted.
The reason CCM projects stall is credential management. Per-tenant encrypted secrets and a wizard per connector is what gets past the first week.
Collection runs
Scheduled pulls with cursors, rate budgets, retry handling and a full run history you can inspect.
When a control result looks wrong, the first question is always whether the collection ran. Run history answers it without opening a ticket.
Last collected 2026-08-29 04:12 UTC
Rules
Rules map what a connector returns to a pass or fail control result. They are authorable and versioned.
Your definition of "MFA is enforced" is not the vendor default. Authorable, versioned rules mean the definition is yours and its history is visible.
Control results
Live posture per control, with drill-down to the individual observations behind the verdict.
A red control that cannot be drilled into gets ignored. Seeing the eleven endpoints that failed is what makes someone fix them.
Control posture
Run collectionLast collected 2026-08-29 04:12 UTC · run #2841
Evidence provenance
Every automated evidence item records where it came from, when, and from which collection run. An auditor can trace it end to end.
Automated evidence with no provenance is worse than a screenshot, because nobody can say where it came from. Provenance is what makes it admissible.
Exceptions
Time-boxed, approved exceptions so a known and accepted deviation does not sit red forever.
A dashboard that stays amber for months loses attention. Exceptions with an expiry date keep the signal accurate and prompt a fresh decision.
Posture snapshots
Point-in-time posture retained for trend analysis and for audit.
An auditor may ask what your posture was in March, not only what it is today. Snapshots are how you answer that from the record.
Outbound delivery
Push results to subscribed downstream systems, and accept inbound webhooks from tools that push rather than wait to be polled.
Some of your stack cannot be polled. Accepting a push keeps those tools inside the same control result model as everything else.
Air-gapped by design
On-premises and in air-gapped deployments, connectors run on your network inside the platform, and each connection can reach only the hosts on its allowlist. No separate collection service sits between your tools and the platform.
For a regulated Gulf institution this is often the first question. The answer here rests on the platform architecture, not on contractual commitments.
How a day looks
Overnight, the Entra ID connector collects conditional-access policy state and the Tenable connector collects scan results. Two rules fire. The MFA-enforcement control stays green. The patch-currency control drops to fail because eleven servers in the payments perimeter are past their remediation window. The control result appears on the CBO assessment with a provenance line pointing at the 04:12 run, where the compliance officer sees it the same morning.
Roles that live here
- Security Operations
- Control Owner
- Compliance Manager
- Tenant Administrator
- CISO
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See monitoring on the stack you already own.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.