Security and compliance evidence
This path is for the person who has to show their work to somebody else: a security engineer answering a customer questionnaire, a compliance owner assembling a file for a NIS2 or ISO 27001 review, or an MSP proving to a client what happened inside their account and when.
By the end of it you can state three things precisely. What Sencai records with no configuration at all. What only exists once you turn it on, and who can turn it on. And which files you can actually export and attach to an audit package, as opposed to screens you can only point at.
It assumes you already have an organization with resources in it. Most of the compliance area is a read over your inventory, so if nothing is connected yet, every screen on this path will be truthfully empty.
Before you start
Section titled “Before you start”Three things should be true before the reading order pays off.
You know the role model. Owner, Admin, Member, Auditor, Viewer, in that order, highest first. Auditor is read-oriented and sits below Admin - it is the role to hand an internal compliance lead or an external reviewer, not a promotion. See Roles and permissions.
Sencai has something to record. Connect a cloud provider account, or enroll the fleet agent on your servers, or both. Discovery and agent reporting are what fill the inventory that every compliance view reads from.
You are an Owner or Admin. Setting an IP allowlist, connecting an identity provider, generating a provisioning token, running an identity scan, and opening an access review all require it. Reading the results does not.
Several steps on this path are also gated by plan. Single sign-on and SCIM provisioning start at Business; so do the policy engine, the compliance score, and the NIS2 evidence timeline. Just-in-time elevation starts at Professional, and the GDPR Article 30 processing register is Enterprise only. See Plans for what each tier includes and sencai.space/pricing for the numbers.
The path
Section titled “The path”The order runs from what is already true, through what you have to switch on, to what you can hand over. Start by sorting the security screens into the ones that present findings and the ones that configure something, then read the audit trail underneath them - it is the substrate the rest of this section reports on, and it needs no setup from you at all. Then the two controls you configure yourself - network restriction, then identity. Then the compliance views, which are almost entirely reads over the inventory and that same log, which is why the inventory step comes before them rather than after. Approvals come last: it is the only mechanism here that stops an action instead of describing one.
What to watch out for
Section titled “What to watch out for”Sencai produces evidence, it does not certify you. The compliance area gives you an immutable activity record, guardrail findings, and exportable packs. It does not make a determination that your organization satisfies NIS2, GDPR, or anything else. That is a legal conclusion your own advisors draw, using these outputs as a source. Write it that way in your documentation, and you will not have to walk anything back in front of an assessor.
There is no in-app search over the raw audit log, and no verify button. The
working surface is Settings → Audit Export (/gravity/settings/audit-export),
which produces a filtered CSV or JSON file. Entries are kept permanently and
cannot be edited or deleted by anyone, but a generated export file expires after
seven days - so treat an export as a snapshot you archive yourself, not as a link
you can send an auditor next quarter. Hash chaining makes tampering detectable,
but demonstrating that independently is an account-team request, not a button.
NIS2 evidence is not a second source. The NIS2 evidence timeline is a read-only, filtered window over the same log as Audit log - scoped to discovery, ownership, tagging, and drift activity. Presenting the two as independent corroboration would be wrong, and an assessor who understands the product will notice. It also does not map rows to specific article or control numbers; that mapping is still your compliance team’s work.
Deprovisioning in your identity provider is sharper than it looks. Deleting the group that fronts your Sencai organization does not just unlink people - it archives the entire organization. Never let that happen as part of routine group cleanup in your IdP. See SCIM provisioning.
SSO enforcement has no emergency password fallback. Before you switch it on, confirm the Owner account and at least one Admin can genuinely sign in through the connected provider. Note also that a pending, unaccepted invitation is not membership, so enforcement does not apply to it.
The IP allowlist follows you across every organization you belong to, not just the one you are currently working in, and it restricts you exactly as much as it restricts everyone else. Saving a list that excludes your own network locks out your whole organization at once, and by definition nobody inside it can undo that - recovery goes through Sencai support.
Approvals have no role floor and no delegation. Any member of the owning organization can approve or reject a pending request, and a request expires four hours after it is raised. If your control narrative says “high-impact changes are approved by the security team”, that is a process you enforce socially today, not something the queue enforces for you. Use the dry-run preview and blast-radius breakdown before approving, and remember that a rejection requires a written reason that is stored with the record.
A recorded decision is not an executed action. In an access review, marking someone Revoke or Downgrade captures the decision for the audit file - it does not change their access. Follow through from the members list, or your evidence will show a certification you never actually carried out. The same distinction applies to drift: Sencai records that something changed outside the platform, it does not revert it.
Inventory gaps become evidence gaps. A resource nobody adopted stays Unmanaged, and a missing tag only becomes visible if a policy checks for it - tag governance runs through the policy engine, which is a Business-tier feature, not a separate screen. If your estate is half-tagged when the review starts, the export will faithfully show that.
Give reviewers Auditor, not Admin. It is the role built for oversight without change rights. Pick it in the Invite member dialog like any other role; if it is not among the options in your organization, ask your account team to assign it rather than reaching for Admin as a workaround.
What’s next
Section titled “What’s next”- Cloud policies - the guardrail rules behind the compliance score, and the difference between a rule that warns and one that blocks a provisioning request
- Access management - identity scans inside your connected cloud accounts, recurring access reviews, and time-boxed elevation
- Identity watchdog - directory security events, such as MFA being turned off, once a directory is connected
- Agreements - signing the Data Processing Agreement and Master Service Agreement your reviewers will ask for
- Privacy and data - data export, right to erasure, and the Article 30 register on Enterprise