How can we help?
Search for the articles here or browse the categories below.
Browse by topic
Find guides, tutorials, and answers organised by category.
Getting Started with Humadroid
Humadroid Feature Walkthrough
Admin Guide Compliance Module
Manage compliance policies, documents, and audits. Track acknowledgments, set alerts, and automate regulatory processes with Humadroid’s Compliance module.
Integrations
Popular articles
What other people are reading right now.
Vercel Integration User Guide
Overview Humadroid's Vercel integration automatically collects compliance evidence from your Vercel deployment platform. Once connected, it continuously monitors your Vercel team configuration, project settings, and security controls to gather evidence that satisfies controls for SOC 2 and ISO 27001 compliance frameworks. Key Benefits - Automated evidence collection - No more manual screenshots or exports - Compliance-focused collection - Evidence collected on schedule (monthly) - Auto-verification - Many evidence sources are automatically checked against compliance rules - Multi-framework support - Single integration satisfies controls across SOC 2 and ISO 27001 - Plan-aware - Automatically adapts to your Vercel plan (Hobby/Pro/Enterprise) Security Model - Read-only access - Humadroid cannot modify your Vercel settings or deployments - Dual authentication options - OAuth integration (recommended) or API Token - Team-scoped access - Access limited to selected team only - Encrypted credential storage - Credentials encrypted at rest - Easily revocable - Disconnect anytime from Humadroid or revoke from Vercel Evidence Sources The Vercel integration collects 9 distinct evidence types across three categories: Access Control Team Members & Roles - Description: Collects team membership and role assignments for access control evidence - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans RBAC Configuration - Description: Documents role-based access control configuration and custom roles - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans Project Access Settings - Description: Collects project-level access restrictions and team assignments - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans SSO/SAML Configuration - Description: Collects SSO enforcement status and SAML configuration - Frequency: Monthly - Auto-Verify: Yes - Plan Required: Enterprise only Deployment Security Deployment Protection - Description: Collects deployment protection settings including authentication requirements - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans (limited on Hobby) Network Security Firewall Status - Description: Collects firewall enablement and managed rulesets (Bot Protection, AI Bots) across projects - Frequency: Monthly - Auto-Verify: Yes - Plan Required: Pro+ WAF Rules - Description: Collects custom WAF rules and managed rule configurations - Frequency: Monthly - Auto-Verify: No (manual review recommended) - Plan Required: Pro+ IP Blocking Rules - Description: Collects IP blocking and allowlist configurations - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans (limits vary by plan) Audit & Monitoring Audit Logs - Description: Team activity audit logs for security monitoring - Frequency: Monthly - Auto-Verify: No (manual review required) - Plan Required: Enterprise only SOC 2 Control Coverage The Vercel integration provides evidence for the following SOC 2 (2017) Trust Services Criteria: CC6 - Logical and Physical Access Controls CC6.1 - Logical Access Security The entity implements logical access security software, infrastructure, and architectures to protect information assets - Team Members & Roles - Access policies enforce least-privilege principles - RBAC Configuration - Role-based access controls are properly configured - Project Access Settings - Project-level access is restricted appropriately - SSO/SAML Configuration - Enterprise SSO enforces strong authentication CC6.2 - User Registration and Authorization Prior to issuing system credentials and granting access, the entity registers and authorizes new users - Team Members & Roles - Complete inventory of users with access and role assignments - Audit Logs - User registration and authorization events are logged (Enterprise) CC6.3 - Removal of Access Rights The entity removes credentials and disables system access when no longer required - RBAC Configuration - Role changes and access modifications documented - Audit Logs - Access revocation events are logged (Enterprise) CC6.6 - Logical Access Security Measures The entity implements controls to prevent or detect and act upon unauthorized logical access - Project Access Settings - Project-level access restrictions prevent unauthorized access - Deployment Protection - Deployments are protected from unauthorized access - Firewall Status - Firewall and managed rulesets protect against attacks (Pro+) - WAF Rules - Custom WAF rules provide application-level protection (Pro+) - IP Blocking Rules - Network-level access restrictions are configured CC7 - System Operations CC7.2 - Security Event Logging The entity identifies and logs security events - Audit Logs - Security events are recorded (Enterprise) CC8 - Change Management CC8.1 - Change Management The entity authorizes, documents, and controls infrastructure changes - Deployment Protection - Deployment changes require appropriate authorization - Audit Logs - Infrastructure changes are logged (Enterprise) ISO 27001:2022 Control Coverage The Vercel integration provides evidence for the following ISO 27001:2022 Annex A controls: A.5 - Organizational Controls A.5.15 - Access Control Rules to control physical and logical access to information and other associated assets shall be established and implemented - Team Members & Roles - Access policies enforce security requirements - RBAC Configuration - Role-based access control is implemented - Project Access Settings - Project-level access is controlled - SSO/SAML Configuration - Strong authentication is enforced (Enterprise) A.5.16 - Identity Management The full life cycle of identities shall be managed - Team Members & Roles - Complete inventory of identities - Audit Logs - Identity lifecycle events are tracked (Enterprise) A.5.17 - Authentication Information Allocation and management of authentication information shall be controlled - SSO/SAML Configuration - Authentication is properly configured (Enterprise) - Deployment Protection - Deployment authentication requirements A.5.18 - Access Rights Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed - RBAC Configuration - Access rights are managed through roles - Audit Logs - Access changes are logged (Enterprise) A.5.23 - Information Security for Use of Cloud Services Processes for acquisition, use, management and exit from cloud services shall be established - Firewall Status - Cloud security controls are configured (Pro+) - Deployment Protection - Cloud deployments are protected - Audit Logs - Cloud service usage is logged (Enterprise) A.8 - Technological Controls A.8.3 - Information Access Restriction Access to information and other associated assets shall be restricted - Project Access Settings - Project data access is restricted - Deployment Protection - Deployment access is controlled - IP Blocking Rules - Network access is restricted A.8.9 - Configuration Management Configurations, including security configurations, shall be established, documented, implemented, monitored and reviewed - Firewall Status - Security configurations are documented (Pro+) - WAF Rules - Custom security rules are configured (Pro+) A.8.12 - Data Leakage Prevention Data leakage prevention measures shall be applied - Deployment Protection - Unauthorized access to deployments is prevented A.8.15 - Logging Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed - Audit Logs - Activity logs are maintained (Enterprise) A.8.16 - Monitoring Activities Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken - Firewall Status - Security monitoring via firewall (Pro+) A.8.20 - Networks Security Networks and network devices shall be secured, managed and controlled - Firewall Status - Firewall provides network protection (Pro+) - WAF Rules - Network security rules are configured (Pro+) - IP Blocking Rules - Network access is controlled A.8.21 - Security of Network Services Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored - Firewall Status - Network service security is monitored (Pro+) - IP Blocking Rules - Network service access is controlled Verification Rules Auto-verified evidence sources are checked against the following compliance thresholds: Team Members & Roles - All team members have assigned roles: Required - No orphaned or inactive members: Flagged - Admin role usage: Documented and reviewed RBAC Configuration - Custom roles follow least-privilege: Recommended - Role assignments documented: Required - Sensitive permissions (billing, team management): Flagged for review Project Access Settings - Project access restricted to authorized teams: Required - No overly permissive project settings: Flagged - Production project restrictions: Recommended Deployment Protection - Production environments protected: Required - Authentication required for preview deployments: Recommended - Password protection configured: Optional SSO/SAML Configuration (Enterprise) - SSO enforcement enabled: Required - SAML configuration valid: Required - Identity provider properly configured: Required Firewall Status (Pro+) - Firewall enabled on production projects: Required - Bot Protection managed ruleset enabled: Recommended - All public-facing projects protected: Required WAF Rules (Pro+) - OWASP Core Rule Set enabled: Recommended - Custom rules reviewed: Manual verification - Rule exceptions documented: Required IP Blocking Rules - Blocking rules configured: Optional - Allowlist properly scoped: Recommended - Geographic restrictions (if applicable): Documented Audit Logs (Enterprise) - Audit logging enabled: Required - Log retention appropriate: Recommended - Regular log review: Manual verification Summary: Control Coverage Matrix SOC 2 Controls by Evidence Source Team Members & Roles - CC6.1: Yes - CC6.2: Yes RBAC Configuration - CC6.1: Yes - CC6.3: Yes Project Access Settings - CC6.1: Yes - CC6.6: Yes Deployment Protection - CC6.6: Yes - CC8.1: Yes SSO/SAML Configuration (Enterprise) - CC6.1: Yes Firewall Status (Pro+) - CC6.6: Yes WAF Rules (Pro+) - CC6.6: Yes IP Blocking Rules - CC6.6: Yes Audit Logs (Enterprise) - CC6.2: Yes - CC6.3: Yes - CC7.2: Yes - CC8.1: Yes ISO 27001 Controls by Evidence Source Team Members & Roles - A.5.15: Yes - A.5.16: Yes RBAC Configuration - A.5.15: Yes - A.5.18: Yes Project Access Settings - A.5.15: Yes - A.8.3: Yes Deployment Protection - A.5.17: Yes - A.5.23: Yes - A.8.3: Yes - A.8.12: Yes SSO/SAML Configuration (Enterprise) - A.5.15: Yes - A.5.17: Yes Firewall Status (Pro+) - A.5.23: Yes - A.8.9: Yes - A.8.16: Yes - A.8.20: Yes - A.8.21: Yes WAF Rules (Pro+) - A.8.9: Yes - A.8.20: Yes IP Blocking Rules - A.8.3: Yes - A.8.20: Yes - A.8.21: Yes Audit Logs (Enterprise) - A.5.16: Yes - A.5.18: Yes - A.5.23: Yes - A.8.15: Yes Additional ISO 27001 Control Coverage A.5.23 - Cloud Services Security - Firewall Status (Pro+): Yes - Deployment Protection: Yes - Audit Logs (Enterprise): Yes A.8.16 - Monitoring Activities - Firewall Status (Pro+): Yes A.8.21 - Security of Network Services - Firewall Status (Pro+): Yes - IP Blocking Rules: Yes Getting Started To set up the Vercel integration: 1. Navigate to Settings > Integrations > Vercel 2. Click Connect Vercel Account 3. Choose your authentication method: - OAuth (Recommended): Click "Connect with Vercel" for one-click authorization - API Token: Manually create and enter a Vercel API token 4. Select the team to monitor (if your account has multiple teams) 5. Validate the connection 6. Enable evidence sources for your compliance controls Option 1: OAuth Connection (Recommended) 1. Click Connect with Vercel button 2. You'll be redirected to Vercel to authorize Humadroid 3. Grant read-only access to your Vercel account 4. You'll be automatically redirected back to Humadroid 5. Select a team if you have multiple teams This method provides automatic token management and scoped permissions. Option 2: API Token (Manual) 1. Log into your Vercel Dashboard 2. Go to Account Settings > Tokens 3. Click Create to create a new token 4. Name: "Humadroid Compliance Read-Only" 5. Scope: Select Full Account for team access 6. Expiration: "No Expiration" recommended for automated collection 7. Click Create Token 8. Copy the token immediately (it won't be shown again) Vercel Permissions Required The integration requires read-only permissions via OAuth or an API Token with Full Account scope: Required Scopes - Team:Read - Access team membership and settings - Projects:Read - Access project configurations - Deployments:Read - Access deployment settings - Firewall:Read - Access WAF and IP blocking rules (Pro+) API Endpoints Used GET /v2/teams - List teams GET /v2/teams/{teamId}/members - List team members GET /v9/projects - List projects GET /v9/projects/{projectId} - Get project details (includes security settings) GET /v6/deployments - List deployments (for protection settings) GET /v1/security/firewall/config - WAF configuration (Enterprise) GET /v2/integrations/sso - SSO configuration (Enterprise) Vercel Plan Feature Matrix Hobby Plan Available Features: - Team Members & Roles - RBAC Configuration (basic roles) - Project Access Settings - Deployment Protection (limited) - IP Blocking Rules (10 IPs max) Not Available: - Firewall Status - WAF Rules - SSO/SAML Configuration - Audit Logs Pro Plan Available Features: - Team Members & Roles - RBAC Configuration - Project Access Settings - Deployment Protection (full features) - IP Blocking Rules (100 IPs max) - Firewall Status - WAF Rules (40 rules max) Not Available: - SSO/SAML Configuration - Audit Logs Enterprise Plan All Features Available: - Team Members & Roles - RBAC Configuration (custom roles) - Project Access Settings - Deployment Protection (full features) - IP Blocking Rules (custom limits) - Firewall Status - WAF Rules (1000 rules max) - SSO/SAML Configuration - Audit Logs - SIEM Streaming - Trusted IPs Troubleshooting Common Issues "Invalid API Token" - Verify the token was copied correctly (no extra spaces) - Check if the token has expired - Ensure the token has Full Account scope "No teams found" - The API token may be personal-only; create a team-scoped token - Verify you have access to at least one team "Firewall data not available" - Firewall features require Pro plan or higher - Ensure the Firewall:Read scope is included "SSO/Audit data not available" - These features require Enterprise plan - Contact Vercel to upgrade if needed Rate Limits Vercel API has the following rate limits: - 10 requests per second - 10,000 requests per day Humadroid respects these limits and implements automatic retry with backoff.
Admin Guide Compliance ModuleSetting up your Compliance module in Humadroid.
The Compliance tab is available only for paid accounts. If you’re managing frameworks like ISO 27001 or SOC 2, or you need to maintain an audit-ready internal control system, this is your go-to setup. Compliance Settings Overview Risk Categories Define what risks your company tracks – and how they’re grouped. Humadroid comes with a set of system default risk categories. These are grouped by area (e.g., Compliance, Contractual, External) and include: - Clear descriptions of the risk type - Examples of common threats or violations - Tags to help with classification Default risk categories Default compliance risk categories in Humadroid including contractual, legal, and regulatory risks System default risk categories grouped by type: compliance, legal, contractual, and regulatory. Each includes examples to help with classification. You can use these predefined categories out of the box or create your own, aligned with your structure, teams, or departments. 💡 Example: Create a custom “IT Operational Risk” category if you’re tracking system downtimes or vendor SLA breaches separately. Creating a new risk category Form for adding a new custom risk category in Humadroid with name, identifier, parent category, and examples Define your own risk categories with custom identifiers, color codes, and classification examples tailored to your organization. Scoring Methods Decide how you evaluate and prioritize risks. In this section, you manage risk scoring models that help determine the criticality of each risk. Three default methods are available: - Multi-Impact Assessment Uses a weighted formula based on financial, legal, and reputational impact. - Simple 5×5 Risk Matrix A straightforward model using probability × impact. - Weighted Impact Assessment A nuanced model allowing additional types of impact (e.g., operational). Available risk scoring methods List of default risk scoring methods in Humadroid including Multi-Impact Assessment, 5x5 Risk Matrix, and Weighted Impact Assessment. Choose from predefined scoring models like Multi-Impact Assessment or create your own to align with your organization’s risk evaluation framework. Each model comes with editable treatment thresholds (when a risk becomes significant) and customizable weights. You can also create new methods based on your internal evaluation criteria. 📎 Recommended: In our internal compliance, we're using this method with a higher threshold - it allows us to focus on really important risks and leave a track of those of lesser impact. Custom risk scoring method setup Form for creating a new risk scoring method in Humadroid with custom formulas, treatment thresholds, and impact calculations. Build your own risk scoring method using custom thresholds and impact-based formulas. Ideal for tailoring your compliance evaluation to specific frameworks. Employment Types n Humadroid, Employment Types help you enforce compliance by ensuring the right documents are linked to the right roles. Whether it’s full-time staff, contractors, or interns, each type can have specific policies automatically assigned, such as: - Code of Conduct - NDA - Security or Data Protection Policies This ensures that every person acknowledges the right set of documents based on their role, with no manual chasing. 👉 Full guide: Employment Types in Humadroid → Employment types overview Creating a new employment type Form for adding a new employment type in Humadroid with required documents and activation toggle Create a custom employment type and link it to required documents like Code of Conduct or Security Policy. Documents will be auto-assigned to users based on their role. Advanced Asset Management (Assets Settings) Once Compliance is enabled, you’ll also get access to advanced asset tracking features, so let’s break up how to navigate through Assets settings. Lifecycle States Here, you define and manage equipment lifecycle stages from the beginning, from purchasing to disposal. Humadroid provides a set of default states: - Ordered - Received - In Stock - Deployed …and more. You can edit these or create your own. Adding a new lifecycle state, by clicking "Add New State" Form for creating a new asset lifecycle state in Humadroid with name, description, terminal status, and custom fields Add custom asset states to match your internal workflows. Use terminal states to define endpoints like “Retired” or “Disposed”. Lifecycle view with state transitions Asset lifecycle flow diagram in Humadroid showing transitions between states like Ordered, Received, In Stock, Deployed, and Under Repair Visualize asset state transitions using a flow diagram. Customize each state and its valid paths to reflect your real-world lifecycle management. ✏️ Pro tip: Use custom transitions to enforce rules like “you can’t deploy before receiving.” Categories Organize your hardware and equipment into categories like laptops, phones, and monitors. While creating a category, you can: - Choose a parent category - Set default lifecycle duration - Select the depreciation method - Flag items for regular maintenance Asset category list List of asset categories in Humadroid including laptops, cameras, mobile phones, and monitors with depreciation status Categorize company assets for easier tracking and reporting. Each category can include depreciation settings and asset counts. Creating a new asset category Form for creating a new asset category in Humadroid with lifecycle settings, depreciation, maintenance interval, and custom fields. Define asset categories with lifecycle duration, depreciation settings, and maintenance reminders. Add custom fields to track additional metadata. Departments Use this to assign assets to teams or cost centers. See how much hardware is tied to Sales, Marketing, or IT. Department overview with assigned assets Departments view in Humadroid showing Accounting and Engineering with assigned managers and asset counts Assign assets to specific departments and track inventory by team. Locations Track asset distribution across your offices, warehouses, or regions. Asset location structure Asset locations view in Humadroid showing Germany with Berlin and Poland with Poznań as sub-locations Organize assets across geographic locations with sub-location support. Ideal for multi-office inventory visibility and compliance traceability. 📄 Document Management Humadroid also enables centralized document control – a crucial piece for ISO/SOC 2 audits. You can: - Upload and manage internal policies, procedures, controls - Assign ownership and version history - Link documents to risks, assessments, or assets - Request acknowledgment from employees (e.g., policy sign-off) This feature does not require setting up in settings. Under Compliance -> Documents, you can start create your documents as you go. Compliance documents with acknowledgment tracking Document dashboard in Humadroid showing compliance policies with versioning, acknowledgment status, and update dates Manage all compliance documents in one place. Track versions, statuses, acknowledgment progress, and link policies to roles or users.
Admin Guide Compliance ModuleHow to Identify Risks in Compliance Projects
Identifying risks is one of the first and most crucial steps when building your compliance project in Humadroid. Done right, it lays the foundation for all your future mitigation efforts, reporting, and governance tracking. Below, we’ll walk you through how to approach risk identification with clarity, structure, and business context. 🧠 What Is Risk Identification? Risk identification is the process of uncovering events or conditions that could negatively affect your organization’s ability to achieve its objectives. In compliance, risks are often linked to: - Legal obligations (e.g., data privacy laws) - Regulatory frameworks (e.g., ISO 27001, SOC 2) - Internal policies (e.g., code of conduct, security protocols) - Operational procedures (e.g., vendor onboarding, remote work) This step is about discovery, not judgment. You don’t have to decide yet how significant or likely a risk is, just that it exists. 🔍 Where to Look for Risks The sources you use to identify risks will depend heavily on your organization’s specific context, the industry in which you operate, the regulations that apply, and how your internal processes work. Below are several common starting points to help you get going: 1. Framework Requirements: Start with the framework you’ve selected (e.g., ISO 27001, HIPAA, SOC 2). Look at its core requirements and ask: “What could cause us to fail here?” Example (SOC 2 - Security): The principle requires access controls. If your company lacks multi-factor authentication (MFA) for admin users, that’s a potential compliance risk. * 2. Business Processes: Map workflows in HR, finance, operations, and IT. Identify weak points, manual steps, or gaps in documentation. Example: In HR onboarding, if there is no checklist to ensure background checks are done, that’s an operational and legal risk. 3. Previous Incidents: Review past issues like data breaches, audit failures, and support escalations. Example: If a past audit flagged a lack of formal vendor risk assessments, make this a formalized risk to track. 4. External Factors: Look at legal changes, economic shifts, political risks, or vendor instability. Example: New GDPR regulations may expose your organization to penalties if your privacy notices are not up to date. 5. Stakeholder Interviews: Ask team leads in IT, legal, HR, and operations about their concerns. Example: A legal manager might express concern about the lack of training logs for employees. That can be logged as a compliance documentation risk. ⏱️ Timeline & Tips Risk identification for your first project can take anywhere from a few hours to a few days, depending on the size of your organization. ✅ Don’t aim for perfection, aim for coverage ✅ Involve cross-functional teams ✅ Revisit your risks quarterly or after any significant incident or audit 🛠️ How to Add Risks in Humadroid Go to the Compliance section on the left -> Pick the project you want to add Risks -> Go to the "Risks" tab -> click "Add Risk" 1. Enter a Title and Description that reflect your organization’s exposures. 2. Select Risk Category, assign an Owner, and set a Next Review Date so nothing slips through 3. On the Risk Assessment tab, you’ll see the predefined impact categories, based on the Scoring Method you selected earlier. Enter the Likelihood and Potential Impact values in each category, and Humadroid will calculate the risk score. 4. Select a Treatment Strategy (Accept, Mitigate, Transfer, or Avoid) and link any relevant controls or documents for complete traceability. 💡 Note: If the Risk Score Summary is at or above the level of the Treatment Threshold of the picked Scoring Method, then you won't be able to Accept the Risk. You will need to take action on it, as it's too high-risk to accept and move on. Examples of Common Risks: - Lack of MFA for Admin Access Admin users are not required to use multi-factor authentication, increasing the likelihood of unauthorized access. This is a common issue flagged under SOC 2's Security principle, which requires strong access controls. - No documented vendor assessment process Vendors are onboarded on an ad hoc basis without consistent risk assessments. This creates blind spots and is often highlighted in third-party risk management reviews (ISO 27001 A.15). - Outdated privacy policy Your public-facing privacy policy hasn’t been updated despite recent regulatory changes like GDPR rulings or CPRA amendments. This leaves you exposed to potential legal penalties. - Excessive admin rights More employees than necessary have unrestricted access to internal systems. This violates the principle of least privilege and increases the risk surface area in case of an insider threat. - No defined incident response plan Your organization has no written and approved process for handling security incidents. This gap would be flagged during audits and leaves you unprepared in a crisis. Each of these risks connects to a real-world weakness that could compromise your compliance posture, and each one can be turned into a documented, trackable item in your Humadroid project. These examples show how real-world weaknesses translate into clearly trackable risks. 🧩 Link Risks to Other Compliance Components Risks can later be linked to: - Controls (preventive measures you take) - Documents/Policies (e.g., Incident Response Policy) Linking Risks with controls, or documents, allows you to have a full picture and understanding of your project. 📘 Learn more: What are Scoring Methods and how to define them By identifying risks with care and structure, you set up a compliance posture that’s proactive, auditable, and ready for change.
Admin Guide Compliance ModuleFirst Project in Compliance
Compliance work starts with clarity, and that’s precisely what a Compliance Project in Humadroid gives you. Whether you're preparing for an audit, aligning with ISO 27001 or SOC 2®, or just mapping internal risks and controls, projects let you structure the entire effort: from frameworks and risks to controls, documents, and assessments. In this guide, we’ll walk you through: - How to create a compliance project - How to define its structure - How to identify and score risks - How to choose the right treatment strategy - How to link supporting documentation and controls ✅ Step 1: Create a New Project Go to Compliance in the left-hand menu and click + Create New > Project. A modal will appear asking for: - Name and description - Project owner - Start and target dates - Choose the ISO 27001 or SOC 2 compliance framework if you're preparing for an audit, or use a blank project if you want to create your own structure. - Scoring method: This determines how Humadroid calculates risk scores in your projects. Humadroid comes with three predefined Scoring Methods: - Multi-Impact Assessment The default method for combining multiple impact types. Formula: Risk = Probability × [Financial Impact (×1) + Legal Impact (×1) + Reputational Impact (×1)] Treatment Threshold: 9 If the calculated score is ≥ 9, the risk must be formally addressed. Tip: Use this when impacts are equally critical and you need a balanced overview - Simple 5×5 Risk Matrix Classic single-dimensional matrix for quick scoring. Formula: Risk = Probability × Overall Impact (×1) Treatment Threshold: 15 If the calculated score is ≥ 15, the risk must be formally addressed. Tip: Ideal for rapid assessments or when you lack detailed impact breakdowns. - Weighted Impact Assessment Nuanced scoring with emphasis on key impact types. Formula: Risk = Probability × [Financial Impact (×2) + Legal Impact (×1) + Reputational Impact (×1) + Operational Impact (×1)] Treatment Threshold: 12 If the calculated score is ≥ 12, the risk must be formally addressed. Tip: Apply this to highlight the most business-critical impact (e.g., financial). Our recommendation is to read our detailed description of Scoring Methods 👉 What are risk scoring methods. 🧩 Step 2: Define Sections & Controls (Optional) 🧠 If you selected a framework for ISO 27001 or SOC 2® during project creation, you now have a full set of controls to work through. To understand how to go through these controls, link evidence, and assess them properly, check this dedicated guide: 👉 How to Work Through Compliance Controls in Humadroid If you didn’t select a predefined framework (such as ISO 27001 or SOC 2®), you can create your own control structure using the Sections & Controls tab. This is especially useful for internal governance, regulatory requirements, or industry-specific frameworks. Go to the Sections & Controls tab to outline your structure. - Add custom sections for key domains - Add controls under each section to track specific requirements (e.g., Two-Factor Authentication enabled) This step is especially useful when working without a predefined standard. 📌 Step 3: Prepare Policies Before Identifying Risks Before jumping into risk identification, it’s highly recommended to prepare and upload your company’s core policies and guidelines. These documents will serve as the foundation for your compliance strategy and often act as direct evidence for various controls. To add policies, go to the Documents tab in your project. Here you can upload new files or create them directly in the system. Once published, these documents can be linked to specific controls or compliance sections and used as recurring evidence during assessments. Remember that you can (and probably will have to ) add new or edit previously created policies along the way, so it's updated. You can review the list of most commonly required policies and their ISO/SOC 2® control references in this article: Prepare Policies and Guides. These may include: - Information Security Policy - Code of Conduct - Vendor Risk Management Policy - Incident Response Plan Versioned and acknowledged policies help demonstrate that your controls are not just theoretical but actively enforced and reviewed. ⚠️ Step 4: Add your Risks Before adding risks, you should identify them first. This involves reviewing your workflows, vendors, tools, and infrastructure to detect areas of potential exposure. (See our full guide: How to Identify Risks in Compliance Projects) To get started: 1. Go to the Risks tab and click + Add First Risk. 2. Fill in the Risk Information: title, description, category, owner, and next review date. 3. In the Risk Assessment tab, set: - Likelihood (chance of happening) - Impact (e.g., financial, legal, reputational) Your selected scoring method will calculate the risk score. If it crosses your treatment threshold, the system will flag it for action. 4. In the Treatment & Links tab, decide how to handle the risk: - Accept - Mitigate (add controls) - Transfer (e.g., via insurance) - Avoid - Other options: Share, Monitor, Investigate You can also link the risk to specific: - Controls - Documents (like policies, SOPs, audit reports) To upload supporting materials: - Go to Documents in the left menu - Add your files and assign them to this project - Attach them to relevant risks and controls for traceability 🧠 Best Practice: Start With a Risk Register During the Planning phase of the project, it's a good idea to map out all known risks early. This gives you: - Better visibility into required controls - Clarity on compliance scope - A living register that can evolve with the project Each risk is created as Draft and can be moved to Identified, In Treatment, or Closed depending on progress. 📈 Final Result: A Structured, Audit-Ready Project By this point, you’ve built the foundation of your compliance initiative: ✅ Defined your scope and structure ✅ Identified and scored key risks ✅ Selected treatments ✅ Linked documentation and controls From here, you can start assigning owners, monitoring progress, and running assessments, all from a centralized compliance dashboard.
Admin Guide Compliance ModuleHow to Work Through Compliance Controls in Humadroid (ISO 27001 & SOC 2)
When running a compliance project in Humadroid, you'll eventually reach the most critical part: working through individual controls. These controls are the foundation of any compliance framework. Whether you're using ISO 27001 or SOC 2, or just undertaking an internal company's compliance project, the approach is similar, but the expectations and documentation may vary. Before diving in and working on the controls one by one, we recommend taking time to review the full control set. This will provide you with a high-level understanding of what is expected, how different controls interconnect, and where your organization's potential gaps may lie. With that overview, addressing each control becomes more contextual and meaningful. 🔄 As you go through each control, you’ll also be able to better understand which of your identified risks align with specific controls. When adding risks to your project, you can easily link them to corresponding controls, creating a more connected and actionable compliance strategy. What Are Controls? Controls, sometimes called “control points,” are specific safeguards, procedures, or activities that an organization implements to mitigate risks to its information assets. In the realm of information security, a control can be technical (e.g., firewall rules), procedural (e.g., incident response procedures), or organizational (e.g., security policies). Purpose of Controls - Risk Mitigation: Controls aim to reduce the likelihood or impact of threats (e.g., unauthorized access, data leakage, service disruption). - Compliance: Many regulations and standards, like ISO 27001 and SOC 2, mandate that organizations demonstrate specific controls are in place (see below) - Governance and Assurance: Controls establish clear practices and documentation so that internal teams, external auditors, and stakeholders can verify that information security is managed systematically. Relationship Between Policies, Standards, and Controls - Policies/Standards: Define high-level objectives and rules (e.g., “We must encrypt data at rest”). - Controls: Translate those objectives into specific actions or mechanisms (e.g., “Use AES-256 encryption for all database backups”). - Procedures/Guidelines: Provide step-by-step instructions for implementing controls (e.g., “Run pg_dump with the –encrypt flag”). 🔐 ISO 27001: Understanding and Completing Controls ISO 27001 is centered around the concept of Annex A Controls, which support the organization's broader Information Security Management System (ISMS). These controls are grouped into four key sections introduced in ISO/IEC 27001:2022: - A.5 Organizational Controls – Governance, policies, roles, and responsibilities - A.6 People Controls – Background checks, awareness training, disciplinary processes - A.7 Physical Controls – Physical access, equipment security, secure disposal - A.8 Technological Controls – Access management, encryption, backups, monitoring We recommend starting with a full overview of these sections. Understanding the structure will help you recognize how individual controls interrelate. 📄 Example – A.6.4: Disciplinary Process What it requires: A formal disciplinary process must exist to take corrective action in case of information security breaches. Your evidence might include: - A disciplinary policy document outlining procedures - HR guidelines describing escalation steps - Historical log or summary of enforcement actions taken ✅ What’s Expected of You - Review the control’s objective and understand its intent - Assign ownership of the control (recommended for distributed accountability) - Implement controls by adding evidence of how it works in your organization - Upload supporting documentation (e.g., access logs, policies, asset registers) 🔄 Required vs Optional ISO 27001 controls aren’t optional. While organizations may justify exclusions in the Statement of Applicability (SoA), any exclusion must be reasoned and documented. 🔐 SOC 2: Understanding and Completing Controls SOC 2 is structured around the Trust Services Criteria (TSC), which include Security, Availability, Confidentiality, Processing Integrity, and Privacy. The TSC is the official source of information for SOC 2 and should be thoroughly read by anyone preparing for a SOC 2 audit. Check the full Trust Service Criteria document Familiarizing yourself with these categories in advance will help you understand the scope of your audit and ensure comprehensive coverage. - Security (Common Criteria) – Required for all audits - Availability – If you promise high uptime or SLAs - Confidentiality – If you manage confidential client data - Processing Integrity – For transaction accuracy and completeness - Privacy – If you process personally identifiable information (PII) Again, reviewing all categories before starting helps you understand what’s in scope. 📄 Example of understanding a control point – CC6.3: Authentication - What it requires: Systems require authentication using strong credentials - Your evidence might include: - Password policy - MFA settings screenshots - Admin account provisioning checklist 🔄 Required vs Optional All controls under the Security category (the Common Criteria) are mandatory. Other TSC categories (Availability, Confidentiality, etc.) are only required if they’re in scope. For instance, if you don’t process sensitive personal data, Privacy controls may not apply. 🧰 What Humadroid Provides for Both Frameworks Regardless of whether you select ISO 27001 or SOC 2, Humadroid provides a standardized control workspace. Each control in your chosen framework includes: - Control title and description - Area to describe the implementation - Space to attach related evidence - Linking to supporting documents - History tracking of assessments - Control ownership and review reminders - Assessment history This consistent interface simplifies the process and helps your team stay aligned during compliance preparation. 🧠 Best Practices When Working Through Controls - Don’t leave descriptions blank - even if you upload a file - Use versioned documents from your Compliance > Documents section - Assign owners to controls so you can track accountability - Set review dates to stay audit-ready throughout the year - Be honest about partial implementations - these are helpful in tracking progress By understanding what each control requires and preparing the necessary documentation, you can make audit preparation faster and reduce compliance risk.
Admin Guide Compliance ModuleEmployment Types in Humadroid
In Humadroid, Employment Types are used to classify different forms of work relationships in your company, from full-time employees to contractors and interns. You’ll find them under: Settings → Compliance → Employment Types 🔐 Employment Types + Required Documents: A Smart Compliance Match Define and manage employment types with role-specific document requirements. Link critical policies directly to executive or contractor positions for better audit control. When you create or edit an employment type, you can assign required documents to it, for example: - Employment contract or B2B agreement - Employee Code of Conduct - NDA (Non-Disclosure Agreement) - GDPR/Data Protection Policy - Internal Security Policy This means every new hire assigned to that employment type will automatically be expected to review and acknowledge the right documents, and no manual steps are needed. 📂 Where Do the Documents Come From? The documents must have been previously created and published in the Documents section of the Compliance module. Once live, they become available for selection when editing employment types. 💡 Remember: To assign documents to Employment Type, once you create a document, you need to publish it, and only then will you have this document as an option while creating or editing Employment Type. ✅ What This Enables: - 📋 Automated onboarding – No need to remember which doc goes to whom. It’s set once by employment type. - 🔎 Visibility – You can track who has acknowledged which documents and follow up as needed. - 📉 Fewer errors – Admins don’t have to manually assign individual policies to each new hire, it's automatically assigned to employment types. 🔄 Updating a Document: Versioning & Notifications When you create a new version of a document (using the “Create New Version” button), you override the old version, and once you publish the new version, it becomes a valid version. Once published: - ✅ All assigned users are automatically notified that a new version is available - ✅ The previous acknowledgments are reset, users must confirm they’ve reviewed the updated content - ✅ You get real-time visibility into who has (or hasn’t) acknowledged the new version This ensures that no outdated procedures remain in circulation, and that compliance tracking stays up to date, especially critical for policies like security, incident response, or business continuity. 💡 Remember: a new version must be explicitly published to take effect. Only then will it replace the previous version in your policy set. 🔧 Use Case Example: Let’s say a new developer joins on a B2B contract. You assign them the “Contractor” employment type, which already has these documents linked: - NDA - Security Policy - Data Handling SOP They’ll receive only the policies relevant to their role, no irrelevant HR materials like benefit guides or paid leave policies.