Compliance Dashboard
The Compliance page gives you an automated, framework-mapped view of how your Microsoft 365 environment measures up against common regulatory standards. Instead of manually gathering evidence before an audit, Tenaxis checks your configuration and access data continuously and presents findings per control clause.
Supported Frameworks
| Framework | Description |
|---|---|
| ISO 27001 | Information security management - access control, asset management, supplier relationships |
| GDPR / AVG | Data protection requirements - data minimization, access limitation, breach preparedness |
| NIS2 | Network and information systems directive - access control, incident handling, supply chain |
How It Works
When you open the Compliance page and select a framework, Tenaxis runs a set of automated control checks against your live data. Each control maps to a specific clause in the framework and returns one of three statuses:
| Status | Meaning |
|---|---|
| Pass | The Tenaxis-observable check passed; this does not establish that the entire framework control is satisfied |
| Warning | Attention is required, or evidence is missing because the check is outside Tenaxis visibility |
| Fail | The observed check failed - review the finding; this is not a legal compliance determination |
Visitor-based checks remain warnings even when guest lifecycle settings are enabled. They stay in the scoring denominator and do not count as passed checks. Review visitor access directly in SharePoint; changing Tenaxis settings alone cannot close this evidence gap.
Each result includes:
- The clause ID (e.g.
A.5.18for ISO/IEC 27001:2022 - access rights; the Tenaxis check provides relevant evidence, not satisfaction of the entire control) - A plain-language finding explaining what was checked and what was found
- A Fix link that takes you directly to the relevant page in Tenaxis to resolve the issue (where applicable)
Example Controls Checked
The following are examples of what the compliance engine evaluates. The exact control set depends on the selected framework.
- Recorded group-role review coverage - checks recent authenticated decisions and verified removals per governed site; see the coverage criteria below
- Offboarding removal evidence - checks for successful historical M365 group-role removal events with explicit Microsoft readback. Disabled-account group roles are separately reported as cached observations, not complete current access.
- SharePoint visitor access and expiry - reports an evidence gap because this access inventory is unsupported. Empty or historical visitor records cannot establish a pass; M365 group membership expiry is a separate, narrower capability
- Review coverage includes governed sites at every risk level - a completed review on one site cannot establish coverage of other sites
- Lifecycle management is active - checks whether stale site detection is enabled
- Sharing is restricted on sensitive sites - checks whether sites classified as sensitive have appropriate sharing settings
Reviewing Findings
- Go to Compliance in the left sidebar
- Select a framework from the dropdown
- Review the list of controls - failing and warning controls are shown first
- Click Fix → on any control to jump to the relevant Tenaxis page
- After resolving an issue, you can re-run the check by refreshing the page
Evidence Export
For auditors who need a downloadable evidence package, click Export Evidence Bundle. This generates a ZIP archive containing:
- A summary report (CSV) of all control statuses for the selected framework
- A site access report (CSV) listing all sites, members, and roles
- The audit log export (CSV) for the period you select
The ZIP file is named tenaxis-evidence-<framework>-<date>.zip and is ready to hand to an auditor or attach to your compliance management system.
What the Compliance Dashboard Does Not Replace
The compliance checks are based on the data Tenaxis has - site metadata, membership lists, access review records, and audit logs. They do not:
- Scan your Microsoft 365 tenant for security settings outside of what Tenaxis manages (e.g. Conditional Access policies, MFA enforcement, DLP rules)
- Replace a formal audit performed by a qualified assessor
- Guarantee regulatory compliance - findings are informational signals, not legal opinions
Use the dashboard as a continuous monitoring tool and as a starting point for preparing audit evidence.
Tips
- Run the check before your audit window to identify gaps early and give yourself time to fix them
- Complete access reviews across governed sites - enabling the schedule alone does not establish review coverage
- Enable lifecycle management - stale site controls fail when this is turned off
- Address sole-owner sites - several controls flag sites with no active owner as a risk
Visitor evidence in exports
The evidence package retains legacy visitor records in legacy-visitor-observations.csv, labelled HISTORICAL_UNVERIFIED. Recorded expiry and renewal dates do not establish current Microsoft access. The access matrix labels group roles as CACHED_OBSERVATION and visitors as LEGACY_VISITOR; neither is a complete effective-access calculation.
Offboarding evidence: what a pass means
The offboarding removal checks pass only when Tenaxis has a successful
OFFBOARDING_MEMBER_REMOVED event with the explicit
MICROSOFT_ROLE_READBACK verification marker. The finding counts historical
verification events for individual M365 group roles, not employees fully
removed, unique departures completed or all SharePoint access paths covered.
It does not prove current access state or timely removal.
Enabled automatic removal, recent scan timestamps and DEPARTED/RESOLVED
tracking records do not prove removal. Failed events, events without that marker
(including legacy automatic-removal records), and other tenants' events cannot
satisfy this check. Missing evidence produces a warning, not an assertion that
access remains. Tenaxis does not retroactively mark old events verified.
An empty disabled-account membership cache also produces an evidence gap. A positive count identifies cached group-role records requiring investigation; confirm current Microsoft state before remediation. A departure-tracking check only establishes that tracking records exist, not pre-departure action or removal.
Offboarding CSV evidence types
offboarding-log.csv distinguishes four types of evidence:
| Type | Meaning |
|---|---|
CACHED_DISABLED_ACCOUNT_ROLE | Stored group role for an account observed as disabled; not a fresh access check. |
REMOVAL_RECORDED_UNVERIFIED | A removal event without qualifying readback evidence, including legacy automatic-removal events. |
REMOVAL_FAILED | A failed removal event; see Error and the original AuditDetails. |
REMOVAL_VERIFIED | A successful OFFBOARDING_MEMBER_REMOVED event with the explicit MICROSOFT_ROLE_READBACK marker. |
VerificationStatus is MICROSOFT_ROLE_READBACK only for the last type; otherwise
it is NOT_VERIFIED. All rows concern M365 group roles. Historical verification
does not prove current access or complete offboarding across all SharePoint
access paths. A failure does not by itself establish the resulting Microsoft state.
AuditEventId, AuditAction, AuditActor, timestamps and original AuditDetails
allow investigation. SiteId and UPN are separate columns. Missing historical
identity fields remain blank rather than being inferred from a site identifier.
AccountCheckedAt describes the stored account observation, not removal time.
CSV consumers must use these headers; the old DISABLED_ACTIVE/REMOVED labels
and column layout have been replaced.
Discovery coverage and inventory freshness
The inventory check compares recorded discovery with governed sites, not just the number of sites managed by Tenaxis. Findings show discovered, governed, unmanaged and intentionally excluded counts, the coverage percentage and the last completed discovery timestamp. Excluded sites stay in the denominator. Archived sites with governance records remain governed.
A pass requires a nonempty, fully governed discovery snapshot completed within 26 hours, with no recorded discovery failure and all inventory records belonging to that snapshot. Missing, stale, failed, empty or mixed-snapshot discovery gives a warning, as do unmanaged or excluded sites. Retained records from an older scan or partially updated records from a newer scan do not establish completeness. A percentage rounded to 100% cannot produce a pass while any site is unmanaged.
Use Estate to investigate and refresh discovery. Counts are recorded observations, not a guarantee of the current estate. Even a pass only describes coverage of that recent snapshot; it does not establish effective access, policy enforcement or framework compliance. OneDrive personal sites are outside scope. Compliance results may be cached for up to five minutes; evidence-package creation evaluates the check again.
Sharing policy evidence
The sensitive-site sharing checks use Tenaxis governance classifications CONFIDENTIAL and RESTRICTED, not Microsoft Purview labels. Their criterion is external sharing set to Disabled; this is a Tenaxis check, not a rule imposed by the referenced framework. Policy-template existence establishes configuration only, not approved organisational policy or successful enforcement.
A cached sharing value or policy-application timestamp alone cannot pass the check. For each governed site in these classifications, Tenaxis considers the latest recorded policy mutation. Qualifying evidence requires a successful verified event with an operation identifier and matching intended, observed and cached sharing values, with no recorded policy-application failure. A later pending or failed mutation invalidates an older success for this check. Missing sharing intent, unknown values and contradictory evidence produce an evidence gap.
All relevant sites need qualifying Disabled readback for a pass. Verified external sharing produces a failed check even if 90% of sites have Disabled readback. ExistingExternalUserSharingOnly still permits external sharing and counts as an exception. No relevant sites means not applicable, not estate-wide assurance. Missing verification means attention required.
These findings describe historical Microsoft readback, not current Microsoft state, item-level permissions or whole-policy enforcement. Changes outside Tenaxis may not be reflected. Summary, detail and evidence exports use the same check; normal compliance results can be cached for five minutes.
Access-review evidence coverage
The GDPR, NIS2, ISO and Copilot review-coverage checks count governed sites with qualifying evidence from their latest created review. One completed review cannot cover another site. Archived governed sites remain included; sites without an M365 group are reported as unsupported and prevent a full-coverage pass. Unmanaged and excluded estate sites are outside this denominator: consult Estate coverage separately. An empty governed inventory gives an evidence warning.
A qualifying review must be completed within the last 90 days, have recorded Microsoft Entra authentication and a completing user ID, and contain decided M365 owner/member role items. Every Remove decision needs successful remediation and a recorded verification timestamp. Missing or future completion dates, undecided items, empty reviews and unverified removals cannot qualify. A newer unfinished cycle prevents an older completion from qualifying. Ninety days is this check's explicit evidence window, not a framework requirement or a change to the configured review schedule; annual reviews may therefore show a gap.
A pass describes historical group-role review evidence across the governed-site denominator. It does not establish current membership, direct SharePoint access, item permissions, complete effective access or framework compliance. The separate workflow completion rate counts stored statuses across review cycles; it does not measure site coverage or establish authenticated, verified evidence.
Identity and ownership observations
The ISO identity and ownership checks concern recorded M365 group roles on governed sites, including archived sites. Deleted governance records are excluded. Sites without a supported group, empty inventories and missing, future-dated or older-than-26-hour membership sync timestamps give evidence gaps, not an all-clear. The 26-hour window is a Tenaxis observation criterion, not a framework requirement.
The identifier check requires a nonempty stored Entra object identifier on every role record at every site with qualifying inventory. Missing identifiers fail this data-quality check; a 90% threshold no longer hides exceptions. An identifier is not proof of a person's identity or complete identity lifecycle management.
The ownership check requires at least one identified owner per site whose account was observed as enabled within the same 26-hour window. Unknown or stale account state gives a gap. Recent nonempty inventories with no owner role, or only owners recently observed as disabled, fail the recorded-observation check. Investigate these cached exceptions before concluding that the Microsoft site is orphaned.
A pass describes stored observations, not guaranteed current Microsoft state, SharePoint Owners groups, direct or item-level permissions, all privileged access, or framework compliance. Unmanaged and excluded estate sites are outside this denominator and must be assessed using Estate coverage. Findings expose counts of supported evidence, exceptions and gaps. Unsupported-site counts are part of the gap count, not an additional mutually exclusive category.
Classification presence and risk distribution
The classification check recognises PUBLIC, INTERNAL, CONFIDENTIAL and RESTRICTED as Tenaxis governance classifications. It passes only for a nonempty governed inventory where every site has a recognised value. Unknown or missing values produce a warning even if most sites are classified. INTERNAL is also the database default: this check proves configuration presence, not a deliberate human decision, content inspection, Purview labelling or successful policy enforcement.
The risk check uses individual scores, not an estate average. It reports low (below 40), moderate (40–69), high (70–100) and missing-evidence counts. Any qualifying high score fails the check; moderate scores or gaps warn. A pass requires a nonempty inventory with all scores low and supported by matching latest calculation records from within 26 hours. Default zero without history, invalid scores, mismatches, stale history and future timestamps cannot pass. A recorded zero with matching recent history can qualify.
These thresholds and the observation window are Tenaxis triage criteria, not framework requirements or AI-safety guarantees. Recent calculation does not prove its source observations are current or complete. Inspect the site's risk contributors before acting; a low score does not prove well-governed permissions or Copilot readiness. Both checks include archived governed sites, exclude deleted governance records and leave unmanaged/excluded estate sites to the separate Estate coverage check. The same results feed dashboard, detail and evidence exports.
Access-review CSV evidence
access-reviews.csv exports the latest 10,000 reviews by creation time, with one
row per decision item and a blank-item row for empty reviews. It is a bounded
export, not a guarantee of all historical reviews. Existing columns are retained;
consumers should read columns by header name.
ReviewerUpnis the assigned reviewer.CompletedByUserId,CompletedByUpnandAuthenticationMethoddescribe the recorded submitting identity, which can differ from the assignment. They do not describe the administrator who subsequently approved remediation. Missing fields remain blank.IdentityEvidenceisRECORDED_ENTRA_AUTHENTICATIONonly when the record has both the MICROSOFT_ENTRA method and a completing user ID; otherwise it isNOT_ESTABLISHED. An assigned email or legacy completion is not identity proof.SiteIdandReviewItemIdlink the decision to its records.AccessScopeisM365_GROUP_ROLESfor OWNER/MEMBER items,UNSUPPORTED_ROLEfor other roles, andNO_REVIEW_ITEMSfor an empty review.RemediationStatus,RemediationErrorandVerifiedAtpreserve stored outcome evidence.VerificationStatusisMICROSOFT_ROLE_READBACKonly for a supported REMOVE item with SUCCEEDED status and a verification timestamp. Otherwise it isNOT_VERIFIED. KEEP needs no removal; NOT_VERIFIED alone does not mean failure.
CompletedAt is workflow completion, DecidedAt is the item decision, and VerifiedAt is recorded removal verification. Review status alone establishes neither identity nor verified removal. Raw historical fields remain visible even when contradictory; use the status and evidence fields together. Verification describes historical group role removal, not current effective SharePoint access. CSV output does not include review tokens, delegation tokens or OTP secrets.