Feature Walkthrough¶
This guide explains the main Studio features from the user interface and how to use each one in day-to-day compliance, audit, and security work.
Navigation Basics¶
After signing in, Studio opens into the authenticated app area. The available screens depend on your role, but most users work from these sections:
| Area | Route | Use it for |
|---|---|---|
| Dashboard | /dashboard | Daily status, alerts, project progress, and role-specific work queues |
| Projects | /dashboard/projects | Compliance project setup, framework tracking, assignments, and review |
| Evidence | /evidence | Uploading, organizing, analyzing, and linking audit evidence |
| Evidence Vault | /evidence/vault | Reusable customer evidence that can be linked across projects |
| AI Chat | /ai-chat | Asking compliance questions and using AI-assisted platform workflows |
| Policy Generator | /policy-generator | Creating or refining policy documents from templates |
| Reports | /reports | Audit-ready reports, exports, and evidence-backed summaries |
| Risk | /risk | Customer-level risk scoring and security posture overview |
| Threats | /threats | Threat intelligence and threat tracking |
| Vulnerabilities | /vulnerabilities | Vulnerability management and remediation status |
| Findings | /findings | Security and audit findings, comments, and resolution workflow |
| Endpoints | /endpoints | Endpoint inventory, agent download, scans, and control mapping |
| CASB | /casb | Cloud application integrations and SaaS posture visibility |
| Documents | /documents | Document library and document AI workflows |
| Learning | /learning | Policy review assignments and training resources |
| Users | /users | User administration where permitted |
| Settings | /settings | Profile, preferences, security settings, and integrations |
Roles and Dashboards¶
Studio uses role-based dashboards so each user sees the workflows they are responsible for.
| Role | Main screens | Typical workflow |
|---|---|---|
| Admin | /dashboard/admin, /users, /dashboard/admin/frameworks, /dashboard/admin/ai-compliance | Configure users, frameworks, AI document types, limits, and system-wide settings |
| Manager | /dashboard/manager, /dashboard/manager/projects | Approve projects, assign auditors, monitor team performance, and manage customer work |
| Auditor | /dashboard/auditor/projects, /dashboard/project/{id} | Review controls, request evidence, add observations, analyze gaps, and prepare reports |
| Customer | /dashboard/customer/projects, /evidence, /endpoints | Create project requests, upload evidence, respond to auditor requests, and monitor compliance progress |
| Reviewer | Auditor project views | Review assigned evidence and control work when included in a project workflow |
Projects¶
Projects are the main container for audits and compliance work.
How to use projects¶
- Open Projects from the dashboard or sidebar.
- Create a project request or open an existing project.
- Select the compliance framework and project scope.
- Assign or confirm responsible users.
- Work through the framework controls.
- Upload or link evidence for each control.
- Track status, reviewer notes, and progress until completion.
What projects track¶
- Framework, customer, auditor, reviewer, and manager ownership.
- Control status, observations, analysis, progress, and review state.
- Evidence linked to each control.
- Project activity and audit workflow history.
- Chunking and document processing status for AI-assisted analysis.
Evidence Management¶
Evidence is where users upload, review, annotate, analyze, and reuse compliance documents.
Upload and manage evidence¶
- Open Evidence.
- Upload a file or create an evidence record.
- Add a title, description, project, customer, tags, and relevant metadata.
- Link the evidence to a project or framework control.
- Use Analyze when AI review is needed.
- Open the evidence viewer to inspect details, comments, and annotations.
Evidence vault¶
Use Evidence Vault for reusable customer evidence that may apply across more than one project. Vault evidence can be created once and linked to projects later, which helps avoid duplicate uploads.
Evidence viewer¶
The evidence viewer supports secure file viewing and collaborative review. Users can inspect evidence details, create annotations, trigger AI analysis, and follow review notes without directly exposing raw storage paths.
Compliance Tracking¶
Compliance tracking combines project controls, evidence links, review progress, and risk signals.
How to monitor compliance¶
- Open a project dashboard.
- Review overall completion and control-level progress.
- Open controls with missing or weak evidence.
- Upload, link, or refresh evidence.
- Ask the AI assistant for gap analysis if more context is needed.
- Generate reports once the evidence set is ready.
Framework administration¶
Admins can manage frameworks from /dashboard/admin/frameworks. They can create frameworks, import controls, import questionnaires, edit framework metadata, and update control SQL mappings used by automation and reporting.
AI Assistant¶
The AI assistant provides compliance guidance, policy help, document analysis, semantic search, and platform-aware answers.
How to use AI chat¶
- Open AI Chat.
- Ask a specific question with project, framework, or control context.
- Review the answer and any referenced evidence.
- Use follow-up prompts to narrow the result.
- Save useful outputs as evidence or tasks when the UI offers that action.
Good prompts:
Policy generator¶
Use Policy Generator when you need a formal policy or standard.
- Open
/policy-generator. - Choose or describe the policy type.
- Add company, industry, framework, and requirement context.
- Generate the policy.
- Refine the output with follow-up instructions.
- Save the generated policy as evidence when it is ready for review.
AI Compliance Administration¶
Admins can configure AI document review behavior from /dashboard/admin/ai-compliance.
Use this area to:
- Manage document types such as policies, plans, or standards.
- Define checklist tasks for each document type.
- Configure tags that trigger specific AI review workflows.
- Trigger background memory consolidation and AI compliance maintenance workflows.
Risk Management¶
The risk area summarizes customer risk using findings, endpoint posture, device signals, and cloud security sources.
How to use risk views¶
- Open Risk.
- Review the overall risk score and severity distribution.
- Drill into devices, findings, and affected areas.
- Prioritize critical and high findings.
- Assign remediation work through findings, tasks, or external integrations.
- Re-check risk after evidence, endpoint, or cloud scan updates.
Findings¶
Findings capture audit and security issues that require review or remediation.
Finding workflow¶
- Open Findings.
- Filter by severity, source, status, customer, or project.
- Open a finding for details and linked evidence.
- Add comments or update ownership and status.
- Resolve the finding when remediation is complete.
Findings may come from manual creation, endpoint scans, Prowler cloud scans, AI analysis, or audit review.
Threats and Vulnerabilities¶
Studio separates broader threat tracking from vulnerability remediation.
Use Threats for:
- Threat intelligence review.
- Threat records and categorization.
- Linking threats to risks, controls, or remediation work.
Use Vulnerabilities for:
- Vulnerability lists and severity review.
- Remediation tracking.
- Security posture reporting.
- Follow-up on scanner or endpoint findings.
Endpoint Management¶
Endpoint management supports manual asset inventory and agent-based security monitoring.
How to use endpoints¶
- Open Endpoints.
- Review the asset list and device status.
- Add a manual asset when needed.
- Download an agent or install script for supported platforms.
- Open an asset to view details and framework assignments.
- Trigger scans, pings, or framework scans when available.
- Review generated findings and linked control evidence.
CASB and Cloud Posture¶
CASB provides cloud application and SaaS integration management.
How to use CASB¶
- Open CASB.
- Create an integration for the target cloud or SaaS source.
- Enter the required credentials or connection details.
- Save and trigger a sync.
- Open the integration details page to review synchronized data.
- Use resulting findings in risk, compliance, and report workflows.
Prowler Cloud Scans¶
Prowler is used for cloud security posture findings.
Typical flow:
- Configure Prowler credentials and scan targets.
- Run or import scans through the Prowler service.
- Review cloud findings in risk and findings views.
- Link relevant findings to compliance controls.
- Track remediation and re-run scans to confirm closure.
Reports¶
Reports turn project, evidence, risk, and compliance data into audit-ready output.
How to use reports¶
- Open Reports.
- Choose the project, customer, or report type.
- Review included evidence and compliance status.
- Check AI-generated summaries against source evidence.
- Export or share the report using the available actions.
The reports area includes reliability indicators so users can distinguish hard evidence, Studio AI analysis, external AI output, and human review.
Questionnaires and Security Questions¶
Questionnaires help collect structured control answers.
Use them to:
- Import or manage framework questionnaires.
- Answer security questions for customer assessments.
- Convert questionnaire responses into project evidence.
- Support auditor review with structured answers.
Learning and Policy Review¶
Learning supports policy acknowledgement and training workflows.
How to use learning¶
- Open Learning.
- Review assigned policies and training videos.
- Mark policies as reviewed after reading.
- Admins or managers can assign policies by department.
- Track completion as part of compliance readiness.
Collaboration¶
Studio includes role-scoped communication and workflow collaboration.
Use collaboration features to:
- Chat with assigned customers, auditors, managers, and admins.
- Send project or evidence questions without leaving the platform.
- Receive in-app notifications for project updates.
- Track audit requests, meetings, and comments.
Audit Log¶
The audit log records important platform activity for accountability.
Use it to review:
- User actions.
- Evidence changes.
- Project workflow changes.
- Administrative updates.
- Security-relevant events.
Documents¶
The documents area supports document library and retrieval workflows.
Use documents to:
- Manage document collections.
- Support AI search and retrieval.
- Feed policy, evidence, and compliance analysis.
- Keep reusable documentation separate from project-specific evidence.
Employee Information¶
Employee information supports compliance workflows that require workforce context.
Use it to manage:
- Employee records used in compliance checks.
- Department context for policy assignments.
- Training or acknowledgement scope.
- Personnel evidence needed for audits.
Standards and Secure Coding¶
Studio includes security standards and secure coding guidance areas.
Use Standards for policy and control reference material.
Use Secure Coding for application security practices, secure development guidance, and engineering-focused compliance support.
Settings¶
Settings are used for profile, preferences, security, and integration configuration.
Common settings tasks:
- Update profile information.
- Review notification preferences.
- Manage session or security options.
- Configure integration details when permitted.
- Adjust role-specific account settings.
Recommended Daily Workflow¶
- Start on the dashboard and review alerts.
- Open active projects and check blocked controls.
- Upload or link evidence for missing controls.
- Review findings and prioritize high-severity remediation.
- Use AI chat for gap analysis or document review.
- Update project status and comments.
- Generate or refresh reports when evidence changes.
Recommended Admin Workflow¶
- Review system health and audit logs.
- Manage users and role assignments.
- Keep frameworks and questionnaires current.
- Configure AI compliance document types and tasks.
- Review integration health for CASB, Prowler, FleetDM, and notifications.
- Monitor usage limits, background workers, and alerts.