← c0c0 / wf1 - Policy Governance: Action-First / Overview

overview

Compliance Overview

Policy compliance posture — passive monitoring, no enforcement

Scan Health: Healthy — last scan 12 min ago

Needs Attention

2 open Critical/High exceptions require triage
Triage now →
3 new vendors detected this window — not yet reviewed
Review vendors →
1 draft policy not yet monitoring
Activate →

Cadence

Per-policy compliance — worst movers first

Policy NameStatusFlowsCompliance %Δ CompExceptionsΔ ExcLast Exception
Data Residency — US OnlyActive4,81296.1%↓ 0.8% Investigate → 7↑ 11d ago
Vendor Allow ListActive3,49097.8%↑ 0.3%5↓ 12h ago
PII Access ControlsActive2,10799.1%↑ 0.2%25d ago
Cross-Region TransferActive1,84399.5%112d ago
Internal Service AccessDraft
Legacy PII ControlsDeprecated851100%0
41 data flows have no policy coverage — these represent compliance gaps.
Review unmanaged flows →

Recent Exceptions

View all exceptions →
ExceptionPolicyStatusDetected
Blocked vendor data transfer to CloudAnalytics IncVendor Allow ListOpen2h ago
Unregistered service accessing PII endpoint /api/usersPII Access ControlsAcknowledged6h ago
Data flow through EU-West region for US-only policyData Residency — US OnlyResolved1d ago
Deprecated vendor still receiving health check pingsVendor Allow ListDismissed2d ago
Cross-region replication to non-approved zone ap-south-1Data Residency — US OnlyOpen3d ago