Skip to content

Feature Walkthrough

This guide explains the main Studio features from the user interface and how to use each one in day-to-day compliance, audit, and security work.

After signing in, Studio opens into the authenticated app area. The available screens depend on your role, but most users work from these sections:

Area Route Use it for
Dashboard /dashboard Daily status, alerts, project progress, and role-specific work queues
Projects /dashboard/projects Compliance project setup, framework tracking, assignments, and review
Evidence /evidence Uploading, organizing, analyzing, and linking audit evidence
Evidence Vault /evidence/vault Reusable customer evidence that can be linked across projects
AI Chat /ai-chat Asking compliance questions and using AI-assisted platform workflows
Policy Generator /policy-generator Creating or refining policy documents from templates
Reports /reports Audit-ready reports, exports, and evidence-backed summaries
Risk /risk Customer-level risk scoring and security posture overview
Threats /threats Threat intelligence and threat tracking
Vulnerabilities /vulnerabilities Vulnerability management and remediation status
Findings /findings Security and audit findings, comments, and resolution workflow
Endpoints /endpoints Endpoint inventory, agent download, scans, and control mapping
CASB /casb Cloud application integrations and SaaS posture visibility
Documents /documents Document library and document AI workflows
Learning /learning Policy review assignments and training resources
Users /users User administration where permitted
Settings /settings Profile, preferences, security settings, and integrations

Roles and Dashboards

Studio uses role-based dashboards so each user sees the workflows they are responsible for.

Role Main screens Typical workflow
Admin /dashboard/admin, /users, /dashboard/admin/frameworks, /dashboard/admin/ai-compliance Configure users, frameworks, AI document types, limits, and system-wide settings
Manager /dashboard/manager, /dashboard/manager/projects Approve projects, assign auditors, monitor team performance, and manage customer work
Auditor /dashboard/auditor/projects, /dashboard/project/{id} Review controls, request evidence, add observations, analyze gaps, and prepare reports
Customer /dashboard/customer/projects, /evidence, /endpoints Create project requests, upload evidence, respond to auditor requests, and monitor compliance progress
Reviewer Auditor project views Review assigned evidence and control work when included in a project workflow

Projects

Projects are the main container for audits and compliance work.

How to use projects

  1. Open Projects from the dashboard or sidebar.
  2. Create a project request or open an existing project.
  3. Select the compliance framework and project scope.
  4. Assign or confirm responsible users.
  5. Work through the framework controls.
  6. Upload or link evidence for each control.
  7. Track status, reviewer notes, and progress until completion.

What projects track

  • Framework, customer, auditor, reviewer, and manager ownership.
  • Control status, observations, analysis, progress, and review state.
  • Evidence linked to each control.
  • Project activity and audit workflow history.
  • Chunking and document processing status for AI-assisted analysis.

Evidence Management

Evidence is where users upload, review, annotate, analyze, and reuse compliance documents.

Upload and manage evidence

  1. Open Evidence.
  2. Upload a file or create an evidence record.
  3. Add a title, description, project, customer, tags, and relevant metadata.
  4. Link the evidence to a project or framework control.
  5. Use Analyze when AI review is needed.
  6. Open the evidence viewer to inspect details, comments, and annotations.

Evidence vault

Use Evidence Vault for reusable customer evidence that may apply across more than one project. Vault evidence can be created once and linked to projects later, which helps avoid duplicate uploads.

Evidence viewer

The evidence viewer supports secure file viewing and collaborative review. Users can inspect evidence details, create annotations, trigger AI analysis, and follow review notes without directly exposing raw storage paths.

Compliance Tracking

Compliance tracking combines project controls, evidence links, review progress, and risk signals.

How to monitor compliance

  1. Open a project dashboard.
  2. Review overall completion and control-level progress.
  3. Open controls with missing or weak evidence.
  4. Upload, link, or refresh evidence.
  5. Ask the AI assistant for gap analysis if more context is needed.
  6. Generate reports once the evidence set is ready.

Framework administration

Admins can manage frameworks from /dashboard/admin/frameworks. They can create frameworks, import controls, import questionnaires, edit framework metadata, and update control SQL mappings used by automation and reporting.

AI Assistant

The AI assistant provides compliance guidance, policy help, document analysis, semantic search, and platform-aware answers.

How to use AI chat

  1. Open AI Chat.
  2. Ask a specific question with project, framework, or control context.
  3. Review the answer and any referenced evidence.
  4. Use follow-up prompts to narrow the result.
  5. Save useful outputs as evidence or tasks when the UI offers that action.

Good prompts:

What evidence is missing for this SOC 2 access control?
Summarize the main gaps in the uploaded incident response policy.
Draft remediation tasks for high-risk endpoint findings.

Policy generator

Use Policy Generator when you need a formal policy or standard.

  1. Open /policy-generator.
  2. Choose or describe the policy type.
  3. Add company, industry, framework, and requirement context.
  4. Generate the policy.
  5. Refine the output with follow-up instructions.
  6. Save the generated policy as evidence when it is ready for review.

AI Compliance Administration

Admins can configure AI document review behavior from /dashboard/admin/ai-compliance.

Use this area to:

  • Manage document types such as policies, plans, or standards.
  • Define checklist tasks for each document type.
  • Configure tags that trigger specific AI review workflows.
  • Trigger background memory consolidation and AI compliance maintenance workflows.

Risk Management

The risk area summarizes customer risk using findings, endpoint posture, device signals, and cloud security sources.

How to use risk views

  1. Open Risk.
  2. Review the overall risk score and severity distribution.
  3. Drill into devices, findings, and affected areas.
  4. Prioritize critical and high findings.
  5. Assign remediation work through findings, tasks, or external integrations.
  6. Re-check risk after evidence, endpoint, or cloud scan updates.

Findings

Findings capture audit and security issues that require review or remediation.

Finding workflow

  1. Open Findings.
  2. Filter by severity, source, status, customer, or project.
  3. Open a finding for details and linked evidence.
  4. Add comments or update ownership and status.
  5. Resolve the finding when remediation is complete.

Findings may come from manual creation, endpoint scans, Prowler cloud scans, AI analysis, or audit review.

Threats and Vulnerabilities

Studio separates broader threat tracking from vulnerability remediation.

Use Threats for:

  • Threat intelligence review.
  • Threat records and categorization.
  • Linking threats to risks, controls, or remediation work.

Use Vulnerabilities for:

  • Vulnerability lists and severity review.
  • Remediation tracking.
  • Security posture reporting.
  • Follow-up on scanner or endpoint findings.

Endpoint Management

Endpoint management supports manual asset inventory and agent-based security monitoring.

How to use endpoints

  1. Open Endpoints.
  2. Review the asset list and device status.
  3. Add a manual asset when needed.
  4. Download an agent or install script for supported platforms.
  5. Open an asset to view details and framework assignments.
  6. Trigger scans, pings, or framework scans when available.
  7. Review generated findings and linked control evidence.

CASB and Cloud Posture

CASB provides cloud application and SaaS integration management.

How to use CASB

  1. Open CASB.
  2. Create an integration for the target cloud or SaaS source.
  3. Enter the required credentials or connection details.
  4. Save and trigger a sync.
  5. Open the integration details page to review synchronized data.
  6. Use resulting findings in risk, compliance, and report workflows.

Prowler Cloud Scans

Prowler is used for cloud security posture findings.

Typical flow:

  1. Configure Prowler credentials and scan targets.
  2. Run or import scans through the Prowler service.
  3. Review cloud findings in risk and findings views.
  4. Link relevant findings to compliance controls.
  5. Track remediation and re-run scans to confirm closure.

Reports

Reports turn project, evidence, risk, and compliance data into audit-ready output.

How to use reports

  1. Open Reports.
  2. Choose the project, customer, or report type.
  3. Review included evidence and compliance status.
  4. Check AI-generated summaries against source evidence.
  5. Export or share the report using the available actions.

The reports area includes reliability indicators so users can distinguish hard evidence, Studio AI analysis, external AI output, and human review.

Questionnaires and Security Questions

Questionnaires help collect structured control answers.

Use them to:

  • Import or manage framework questionnaires.
  • Answer security questions for customer assessments.
  • Convert questionnaire responses into project evidence.
  • Support auditor review with structured answers.

Learning and Policy Review

Learning supports policy acknowledgement and training workflows.

How to use learning

  1. Open Learning.
  2. Review assigned policies and training videos.
  3. Mark policies as reviewed after reading.
  4. Admins or managers can assign policies by department.
  5. Track completion as part of compliance readiness.

Collaboration

Studio includes role-scoped communication and workflow collaboration.

Use collaboration features to:

  • Chat with assigned customers, auditors, managers, and admins.
  • Send project or evidence questions without leaving the platform.
  • Receive in-app notifications for project updates.
  • Track audit requests, meetings, and comments.

Audit Log

The audit log records important platform activity for accountability.

Use it to review:

  • User actions.
  • Evidence changes.
  • Project workflow changes.
  • Administrative updates.
  • Security-relevant events.

Documents

The documents area supports document library and retrieval workflows.

Use documents to:

  • Manage document collections.
  • Support AI search and retrieval.
  • Feed policy, evidence, and compliance analysis.
  • Keep reusable documentation separate from project-specific evidence.

Employee Information

Employee information supports compliance workflows that require workforce context.

Use it to manage:

  • Employee records used in compliance checks.
  • Department context for policy assignments.
  • Training or acknowledgement scope.
  • Personnel evidence needed for audits.

Standards and Secure Coding

Studio includes security standards and secure coding guidance areas.

Use Standards for policy and control reference material.

Use Secure Coding for application security practices, secure development guidance, and engineering-focused compliance support.

Settings

Settings are used for profile, preferences, security, and integration configuration.

Common settings tasks:

  • Update profile information.
  • Review notification preferences.
  • Manage session or security options.
  • Configure integration details when permitted.
  • Adjust role-specific account settings.
  1. Start on the dashboard and review alerts.
  2. Open active projects and check blocked controls.
  3. Upload or link evidence for missing controls.
  4. Review findings and prioritize high-severity remediation.
  5. Use AI chat for gap analysis or document review.
  6. Update project status and comments.
  7. Generate or refresh reports when evidence changes.
  1. Review system health and audit logs.
  2. Manage users and role assignments.
  3. Keep frameworks and questionnaires current.
  4. Configure AI compliance document types and tasks.
  5. Review integration health for CASB, Prowler, FleetDM, and notifications.
  6. Monitor usage limits, background workers, and alerts.