Skip to content

Controls

A control is one security practice in your compliance program, such as “Penetration testing performed”. Each control maps to one or more requirements in your active frameworks, and its status counts toward the progress of those requirements and frameworks. You bring a control to Passing by getting its checks to pass, attaching the evidence it asks for, and submitting it for review by the Oneleet team.

Controls live under Compliance > Program, on the Controls tab, which appears once your workspace has at least one active framework. Workspace members can do everything described on this page unless a section says otherwise. Auditors can see a control’s status, checks, and evidence, but not its Implementation notes or Activity, and they can’t attach evidence, comment, or submit for review. Oneleet adds controls to your program when a framework is activated, and you can’t create or delete controls in the app.

Every control has one status, worked out from its checks, its review outcome, and any open evidence requests.

A control’s checks are derived from the monitors, policies, and integrations its control type depends on. Each check is one of these kinds:

  • Monitor: passes when the monitor passes and fails when the monitor is alerting or breaching its SLA. Monitors are the only kind of check that can make a control Failing.
  • Policy: passes when a policy of that type has a published version, and reads in progress when the policy exists but isn’t published yet. The check shows who has signed the policy, but signatures don’t change its status.
  • Integration: passes when an integration in that category is connected, and reads in progress when one has been added but isn’t finished connecting.
  • Evidence attached: appears only when the control has no other active checks or has an active evidence request. It passes once any evidence is linked to the control.

Inactive checks don’t count toward the status. A check is inactive when its monitor is snoozed or disabled, its policy type has no policy yet, or its integration category has nothing added.

The statuses, in the order the Controls tab groups them:

  • Failing: at least one check is failing. If the control is in review or the Oneleet team has requested changes, it shows that status instead.
  • Needs changes: the Oneleet team reviewed the control and requested changes.
  • In review: you’ve submitted the control for review.
  • In progress: a check is still in progress, or some checks are passing and others are pending. A control also stays here when every check passes but the Oneleet team hasn’t approved it yet, and when it’s approved but has an open evidence request.
  • Not started: every check is still pending.
  • Passing: the Oneleet team approved the control and no evidence requests are open.

A requirement counts as met only when every one of its controls is Passing.

The Controls tab groups controls by status, with a count for each status at the top. The framework filter includes a control if any of its requirements belongs to a selected framework. Your filters are kept in the page URL, so you can share a filtered view or come back to it later. Export downloads the filtered list as a CSV with each control’s ID, title, status, check counts, owner, evidence count, description, and instructions.

Each control can have one owner, a workspace member responsible for getting it to pass. Pick one from the Owner column, or from the owner field on the control’s page. To assign several controls at once, select their rows and use Assign owner or Unassign owner in the bar that appears at the bottom of the table.

The same bar offers Unlink evidence, which removes every uploaded file and image from the selected controls so they can collect fresh evidence for your next audit. Links, notes, in-app documents, and documents generated by Oneleet stay attached. The unlinked files remain in your evidence library and can be linked again.

Open a control to see its Checks section. Each check shows its status, what it depends on, and a link to the monitor, policy, or integration behind it. Most monitor checks link with View monitor, an integration check with Add integration, Finish connecting, or View integration, and a policy check with Add policy or Publish policy. A check turns green when the underlying monitor, policy, or integration is in order; there’s nothing to change on the control itself. Inactive checks are collapsed behind Show N inactive checks.

Below the checks, Available templates lists in-app document templates for the control type. Create opens the document editor, and Link attaches an existing document made from that template as evidence. Workspace admins also see Supported integrations, which lists integrations relevant to this control that you haven’t connected. If you dismiss either section, it stays hidden in this browser.

In the Evidence section of the control’s page, drop files into the upload area, use Add note or Add link, or use Link evidence to reuse an item already in your evidence library. Files can be up to 40 MB each. For what to attach, see What makes good evidence.

Evidence linked to more than one control shows an “N controls” badge. From a row’s menu, Unlink from this control removes the item from this control only. Delete removes it from your library and from every control it’s attached to, and reads Delete for N controls on a shared item. Every member sees the delete option, but only workspace admins and the member who added an item can delete it, and only workspace admins can delete an in-app document.

The Oneleet team can ask for specific additional evidence on a control. Requests appear in the Control review section with a title, status, and a description of what’s needed. An active request has its own upload area, and anything you add there is linked to that request. A request that isn’t active yet shows the date when you can start submitting evidence for it.

If you upload a single file to the control’s main Evidence section while a request is pending, Oneleet asks whether to link the upload to that request. You can also link an existing item later with Link to pending request from its row menu.

The Control review section lists what has to be true before you can submit:

  • All active checks are passing or within your SLAs.
  • Evidence has been provided for every active evidence request.

Until then, Submit for review is disabled, and hovering over it shows which condition is unmet. A monitor that’s alerting but hasn’t breached its SLA doesn’t block submission. You can’t submit a control that has no checks at all.

While the control is In review, the Oneleet team checks that the evidence is complete, reviews the implementation quality, and may request additional evidence. You can withdraw the submission with Cancel review.

If the reviewer approves the control but adds evidence requests, the Control review section asks you to submit evidence for the remaining requests. If the reviewer requests changes, their notes appear in the timeline; make the changes and click Resubmit for review. You can also resubmit an approved control, for example after attaching new evidence.

The Activity section at the bottom of the control’s page holds comments and a history of changes to the control. Mentioning @oneleet in a comment opens a support conversation with the Oneleet team, and a workspace member you @mention gets an email notification. You can edit or delete your own comments, and each comment can be up to about 10,000 characters.

  • Controls can’t be disabled or marked out of scope, and requirements can’t be marked not applicable. To silence a check, snooze or disable its monitor.
  • To remove a framework, contact the Oneleet team. Removing a framework deletes a control only if Oneleet added it for that framework, no other framework uses it, and your team hasn’t worked on it yet (no owner, linked evidence, comments, or review history, for example).
  • Checks update as soon as you add, link, unlink, or delete evidence on a control. Oneleet also rechecks every control once an hour, and evidence Oneleet attaches automatically, such as a generated Statement of Work, only shows up in the checks after that recheck. Until then, the control may read Not started with Submit for review disabled. The order of checks can also change between rechecks.
  • Auditors see submissions in the review timeline as coming from your workspace team rather than a named person.