Tenaxis
/Docs
Sign in

Automation & Compliance

Compliance Dashboard

The Compliance page gives you an automated, framework-mapped view of how your Microsoft 365 environment measures up against common regulatory standards. Instead of manually gathering evidence before an audit, Tenaxis checks your configuration and access data continuously and presents findings per control clause.


Supported Frameworks

FrameworkDescription
ISO 27001Information security management - access control, asset management, supplier relationships
GDPR / AVGData protection requirements - data minimization, access limitation, breach preparedness
NIS2Network and information systems directive - access control, incident handling, supply chain

How It Works

When you open the Compliance page and select a framework, Tenaxis runs a set of automated control checks against your live data. Each control maps to a specific clause in the framework and returns one of three statuses:

StatusMeaning
PassThe Tenaxis-observable check passed; this does not establish that the entire framework control is satisfied
WarningAttention is required, or evidence is missing because the check is outside Tenaxis visibility
FailThe observed check failed - review the finding; this is not a legal compliance determination

Visitor-based checks remain warnings even when guest lifecycle settings are enabled. They stay in the scoring denominator and do not count as passed checks. Review visitor access directly in SharePoint; changing Tenaxis settings alone cannot close this evidence gap.

Each result includes:

  • The clause ID (e.g. A.5.18 for ISO/IEC 27001:2022 - access rights; the Tenaxis check provides relevant evidence, not satisfaction of the entire control)
  • A plain-language finding explaining what was checked and what was found
  • A Fix link that takes you directly to the relevant page in Tenaxis to resolve the issue (where applicable)

Example Controls Checked

The following are examples of what the compliance engine evaluates. The exact control set depends on the selected framework.

  • Recorded group-role review coverage - checks recent authenticated decisions and verified removals per governed site; see the coverage criteria below
  • Offboarding removal evidence - checks for successful historical M365 group-role removal events with explicit Microsoft readback. Disabled-account group roles are separately reported as cached observations, not complete current access.
  • SharePoint visitor access and expiry - reports an evidence gap because this access inventory is unsupported. Empty or historical visitor records cannot establish a pass; M365 group membership expiry is a separate, narrower capability
  • Review coverage includes governed sites at every risk level - a completed review on one site cannot establish coverage of other sites
  • Lifecycle management is active - checks whether stale site detection is enabled
  • Sharing is restricted on sensitive sites - checks whether sites classified as sensitive have appropriate sharing settings

Reviewing Findings

  1. Go to Compliance in the left sidebar
  2. Select a framework from the dropdown
  3. Review the list of controls - failing and warning controls are shown first
  4. Click Fix → on any control to jump to the relevant Tenaxis page
  5. After resolving an issue, you can re-run the check by refreshing the page

Evidence Export

For auditors who need a downloadable evidence package, click Export Evidence Bundle. This generates a ZIP archive containing:

  • A summary report (CSV) of all control statuses for the selected framework
  • A site access report (CSV) listing all sites, members, and roles
  • The audit log export (CSV) for the period you select

The ZIP file is named tenaxis-evidence-<framework>-<date>.zip and is ready to hand to an auditor or attach to your compliance management system.


What the Compliance Dashboard Does Not Replace

The compliance checks are based on the data Tenaxis has - site metadata, membership lists, access review records, and audit logs. They do not:

  • Scan your Microsoft 365 tenant for security settings outside of what Tenaxis manages (e.g. Conditional Access policies, MFA enforcement, DLP rules)
  • Replace a formal audit performed by a qualified assessor
  • Guarantee regulatory compliance - findings are informational signals, not legal opinions

Use the dashboard as a continuous monitoring tool and as a starting point for preparing audit evidence.


Tips

  • Run the check before your audit window to identify gaps early and give yourself time to fix them
  • Complete access reviews across governed sites - enabling the schedule alone does not establish review coverage
  • Enable lifecycle management - stale site controls fail when this is turned off
  • Address sole-owner sites - several controls flag sites with no active owner as a risk

Visitor evidence in exports

The evidence package retains legacy visitor records in legacy-visitor-observations.csv, labelled HISTORICAL_UNVERIFIED. Recorded expiry and renewal dates do not establish current Microsoft access. The access matrix labels group roles as CACHED_OBSERVATION and visitors as LEGACY_VISITOR; neither is a complete effective-access calculation.

Offboarding evidence: what a pass means

The offboarding removal checks pass only when Tenaxis has a successful OFFBOARDING_MEMBER_REMOVED event with the explicit MICROSOFT_ROLE_READBACK verification marker. The finding counts historical verification events for individual M365 group roles, not employees fully removed, unique departures completed or all SharePoint access paths covered. It does not prove current access state or timely removal.

Enabled automatic removal, recent scan timestamps and DEPARTED/RESOLVED tracking records do not prove removal. Failed events, events without that marker (including legacy automatic-removal records), and other tenants' events cannot satisfy this check. Missing evidence produces a warning, not an assertion that access remains. Tenaxis does not retroactively mark old events verified.

An empty disabled-account membership cache also produces an evidence gap. A positive count identifies cached group-role records requiring investigation; confirm current Microsoft state before remediation. A departure-tracking check only establishes that tracking records exist, not pre-departure action or removal.

Offboarding CSV evidence types

offboarding-log.csv distinguishes four types of evidence:

TypeMeaning
CACHED_DISABLED_ACCOUNT_ROLEStored group role for an account observed as disabled; not a fresh access check.
REMOVAL_RECORDED_UNVERIFIEDA removal event without qualifying readback evidence, including legacy automatic-removal events.
REMOVAL_FAILEDA failed removal event; see Error and the original AuditDetails.
REMOVAL_VERIFIEDA successful OFFBOARDING_MEMBER_REMOVED event with the explicit MICROSOFT_ROLE_READBACK marker.

VerificationStatus is MICROSOFT_ROLE_READBACK only for the last type; otherwise it is NOT_VERIFIED. All rows concern M365 group roles. Historical verification does not prove current access or complete offboarding across all SharePoint access paths. A failure does not by itself establish the resulting Microsoft state.

AuditEventId, AuditAction, AuditActor, timestamps and original AuditDetails allow investigation. SiteId and UPN are separate columns. Missing historical identity fields remain blank rather than being inferred from a site identifier. AccountCheckedAt describes the stored account observation, not removal time. CSV consumers must use these headers; the old DISABLED_ACTIVE/REMOVED labels and column layout have been replaced.

Discovery coverage and inventory freshness

The inventory check compares recorded discovery with governed sites, not just the number of sites managed by Tenaxis. Findings show discovered, governed, unmanaged and intentionally excluded counts, the coverage percentage and the last completed discovery timestamp. Excluded sites stay in the denominator. Archived sites with governance records remain governed.

A pass requires a nonempty, fully governed discovery snapshot completed within 26 hours, with no recorded discovery failure and all inventory records belonging to that snapshot. Missing, stale, failed, empty or mixed-snapshot discovery gives a warning, as do unmanaged or excluded sites. Retained records from an older scan or partially updated records from a newer scan do not establish completeness. A percentage rounded to 100% cannot produce a pass while any site is unmanaged.

Use Estate to investigate and refresh discovery. Counts are recorded observations, not a guarantee of the current estate. Even a pass only describes coverage of that recent snapshot; it does not establish effective access, policy enforcement or framework compliance. OneDrive personal sites are outside scope. Compliance results may be cached for up to five minutes; evidence-package creation evaluates the check again.

Sharing policy evidence

The sensitive-site sharing checks use Tenaxis governance classifications CONFIDENTIAL and RESTRICTED, not Microsoft Purview labels. Their criterion is external sharing set to Disabled; this is a Tenaxis check, not a rule imposed by the referenced framework. Policy-template existence establishes configuration only, not approved organisational policy or successful enforcement.

A cached sharing value or policy-application timestamp alone cannot pass the check. For each governed site in these classifications, Tenaxis considers the latest recorded policy mutation. Qualifying evidence requires a successful verified event with an operation identifier and matching intended, observed and cached sharing values, with no recorded policy-application failure. A later pending or failed mutation invalidates an older success for this check. Missing sharing intent, unknown values and contradictory evidence produce an evidence gap.

All relevant sites need qualifying Disabled readback for a pass. Verified external sharing produces a failed check even if 90% of sites have Disabled readback. ExistingExternalUserSharingOnly still permits external sharing and counts as an exception. No relevant sites means not applicable, not estate-wide assurance. Missing verification means attention required.

These findings describe historical Microsoft readback, not current Microsoft state, item-level permissions or whole-policy enforcement. Changes outside Tenaxis may not be reflected. Summary, detail and evidence exports use the same check; normal compliance results can be cached for five minutes.

Access-review evidence coverage

The GDPR, NIS2, ISO and Copilot review-coverage checks count governed sites with qualifying evidence from their latest created review. One completed review cannot cover another site. Archived governed sites remain included; sites without an M365 group are reported as unsupported and prevent a full-coverage pass. Unmanaged and excluded estate sites are outside this denominator: consult Estate coverage separately. An empty governed inventory gives an evidence warning.

A qualifying review must be completed within the last 90 days, have recorded Microsoft Entra authentication and a completing user ID, and contain decided M365 owner/member role items. Every Remove decision needs successful remediation and a recorded verification timestamp. Missing or future completion dates, undecided items, empty reviews and unverified removals cannot qualify. A newer unfinished cycle prevents an older completion from qualifying. Ninety days is this check's explicit evidence window, not a framework requirement or a change to the configured review schedule; annual reviews may therefore show a gap.

A pass describes historical group-role review evidence across the governed-site denominator. It does not establish current membership, direct SharePoint access, item permissions, complete effective access or framework compliance. The separate workflow completion rate counts stored statuses across review cycles; it does not measure site coverage or establish authenticated, verified evidence.

Identity and ownership observations

The ISO identity and ownership checks concern recorded M365 group roles on governed sites, including archived sites. Deleted governance records are excluded. Sites without a supported group, empty inventories and missing, future-dated or older-than-26-hour membership sync timestamps give evidence gaps, not an all-clear. The 26-hour window is a Tenaxis observation criterion, not a framework requirement.

The identifier check requires a nonempty stored Entra object identifier on every role record at every site with qualifying inventory. Missing identifiers fail this data-quality check; a 90% threshold no longer hides exceptions. An identifier is not proof of a person's identity or complete identity lifecycle management.

The ownership check requires at least one identified owner per site whose account was observed as enabled within the same 26-hour window. Unknown or stale account state gives a gap. Recent nonempty inventories with no owner role, or only owners recently observed as disabled, fail the recorded-observation check. Investigate these cached exceptions before concluding that the Microsoft site is orphaned.

A pass describes stored observations, not guaranteed current Microsoft state, SharePoint Owners groups, direct or item-level permissions, all privileged access, or framework compliance. Unmanaged and excluded estate sites are outside this denominator and must be assessed using Estate coverage. Findings expose counts of supported evidence, exceptions and gaps. Unsupported-site counts are part of the gap count, not an additional mutually exclusive category.

Classification presence and risk distribution

The classification check recognises PUBLIC, INTERNAL, CONFIDENTIAL and RESTRICTED as Tenaxis governance classifications. It passes only for a nonempty governed inventory where every site has a recognised value. Unknown or missing values produce a warning even if most sites are classified. INTERNAL is also the database default: this check proves configuration presence, not a deliberate human decision, content inspection, Purview labelling or successful policy enforcement.

The risk check uses individual scores, not an estate average. It reports low (below 40), moderate (40–69), high (70–100) and missing-evidence counts. Any qualifying high score fails the check; moderate scores or gaps warn. A pass requires a nonempty inventory with all scores low and supported by matching latest calculation records from within 26 hours. Default zero without history, invalid scores, mismatches, stale history and future timestamps cannot pass. A recorded zero with matching recent history can qualify.

These thresholds and the observation window are Tenaxis triage criteria, not framework requirements or AI-safety guarantees. Recent calculation does not prove its source observations are current or complete. Inspect the site's risk contributors before acting; a low score does not prove well-governed permissions or Copilot readiness. Both checks include archived governed sites, exclude deleted governance records and leave unmanaged/excluded estate sites to the separate Estate coverage check. The same results feed dashboard, detail and evidence exports.

Access-review CSV evidence

access-reviews.csv exports the latest 10,000 reviews by creation time, with one row per decision item and a blank-item row for empty reviews. It is a bounded export, not a guarantee of all historical reviews. Existing columns are retained; consumers should read columns by header name.

  • ReviewerUpn is the assigned reviewer. CompletedByUserId, CompletedByUpn and AuthenticationMethod describe the recorded submitting identity, which can differ from the assignment. They do not describe the administrator who subsequently approved remediation. Missing fields remain blank.
  • IdentityEvidence is RECORDED_ENTRA_AUTHENTICATION only when the record has both the MICROSOFT_ENTRA method and a completing user ID; otherwise it is NOT_ESTABLISHED. An assigned email or legacy completion is not identity proof.
  • SiteId and ReviewItemId link the decision to its records. AccessScope is M365_GROUP_ROLES for OWNER/MEMBER items, UNSUPPORTED_ROLE for other roles, and NO_REVIEW_ITEMS for an empty review.
  • RemediationStatus, RemediationError and VerifiedAt preserve stored outcome evidence. VerificationStatus is MICROSOFT_ROLE_READBACK only for a supported REMOVE item with SUCCEEDED status and a verification timestamp. Otherwise it is NOT_VERIFIED. KEEP needs no removal; NOT_VERIFIED alone does not mean failure.

CompletedAt is workflow completion, DecidedAt is the item decision, and VerifiedAt is recorded removal verification. Review status alone establishes neither identity nor verified removal. Raw historical fields remain visible even when contradictory; use the status and evidence fields together. Verification describes historical group role removal, not current effective SharePoint access. CSV output does not include review tokens, delegation tokens or OTP secrets.