How can we help?

Search for the articles here or browse the categories below.

Browse by topic

Find guides, tutorials, and answers organised by category.

Popular articles

What other people are reading right now.

Integrations

FleetDM Integration User Guide

Overview AuditBadger connects to FleetDM once at the account level, then uses Fleet host inventory to maintain assets, device assignments, and endpoint compliance evidence. The integration is designed to avoid duplicate inventory work: - Fleet devices are selected by default during the first import review. - An exact serial-number match links the Fleet host to the existing AuditBadger asset instead of creating another asset. - A Fleet owner email that exactly matches an active AuditBadger user can manage the Fleet-owned checkout automatically. - Devices that cannot be matched are shown before import and reported in evidence after import. - Devices left outside the import selection are treated as a coverage gap by default. AuditBadger reads Fleet data but never locks, wipes, enrolls, unenrolls, or otherwise changes a device in Fleet. It also does not retrieve disk recovery keys. Before You Start You need: - AuditBadger account-admin access. - The HTTPS base URL of your Fleet server. - A Fleet API-only user token with a read-only role that can read hosts, host counts, device mappings, Fleet configuration, labels, and policies. - AuditBadger users with work email addresses matching the owner mappings used in Fleet. Use a dedicated API-only Fleet user for unattended collection. Keep its access read-only and revoke the user in Fleet if the integration should no longer connect. Connect FleetDM 1. In AuditBadger, open Settings > Integrations. 2. Open FleetDM. 3. Enter the Fleet server URL, including https://. 4. Enter the API-only user token. 5. Click Connect FleetDM. AuditBadger validates the token and confirms that hosts are readable. The integration page shows the Fleet organization, server, license tier when available, API user, and host count. If AuditBadger reports that the token belongs to a regular Fleet user, replace it with a dedicated API-only user token so scheduled collection is not tied to an interactive employee account. Review And Import Devices After the connection is valid, open Review Devices on the FleetDM integration page. Device import has its own screen so the complete Fleet inventory and every automatic decision can be reviewed together. The summary shows: - Fleet devices: every host visible to the integration token. - Existing assets linked: hosts that will update an existing AuditBadger asset. - New assets: hosts that will create an asset. - Needs attention: hosts with an ownership gap or an asset-matching conflict. Asset Matching AuditBadger matches each Fleet host in this order: 1. The Fleet host ID stored on a previously synced asset. 2. An exact hardware serial-number match. 3. The Fleet host UUID stored on a previously synced asset. For example, if Fleet reports serial P409W6WGWR and one asset in the same AuditBadger account already has serial P409W6WGWR, the importer shows that it will link to that asset. It does not propose a second asset. AuditBadger does not auto-link when the serial is ambiguous or the asset is already associated with a different Fleet host. The importer disables that host and asks the admin to resolve the asset data first. Matching is always limited to the current AuditBadger account. A serial in another customer account can never be linked. Owner Matching AuditBadger ranks Fleet device-mapping emails by source, then uses the highest-ranked candidate that exactly matches an active AuditBadger user. Email comparison is case-insensitive. The importer explains one of these outcomes for every host: - The owner matched an active AuditBadger user. - Fleet supplied an email, but no active AuditBadger user has that email. - Fleet supplied multiple possible owners. - Fleet did not supply a usable owner email. No fuzzy name matching is performed. Exact email matching avoids assigning a company device to the wrong person. Choose The Import Scope All non-conflicting devices are selected the first time the importer is opened. Usually the admin only needs to review the proposed links, optionally map Fleet platforms to asset categories, and click Save And Sync. You can deselect a device, but this creates an intentional Fleet coverage gap. The device inventory verifier fails by default while any Fleet device remains outside the AuditBadger import selection. Map Asset Categories For each Fleet platform, choose an existing AuditBadger asset category or enter a new category name. Category mapping applies only when an imported asset does not already have a category. Existing manual categories are preserved. What Sync Changes In AuditBadger For selected devices, a sync can: - Create missing assets. - Add Fleet metadata to safely matched existing assets. - Fill blank make, model, serial, or category values without overwriting existing manual values. - Create, refresh, return, or reassign Fleet-managed checkouts when the device owner matches an active AuditBadger user. - Mark previously synced Fleet assets as missing when their host disappears from the selected Fleet data. Manual checkouts remain authoritative. If a manual checkout conflicts with Fleet ownership, AuditBadger records a conflict and does not overwrite the manual assignment. Understand Warnings And Failed Checks The FleetDM integration and its device inventory evidence distinguish several conditions: Not Imported Fleet currently exposes more devices than the AuditBadger import selection contains. The complete-coverage verification rule fails by default until the devices are selected or the rule is explicitly relaxed. No Active AuditBadger Owner A Fleet device could not be matched to an active AuditBadger user. Selected devices reduce the owner-mapping percentage and can fail the configured threshold. Unselected devices with the same problem also produce an explicit verifier warning so they do not disappear outside the evidence scope. Ambiguous Owner Fleet returned multiple equally strong owner mappings. AuditBadger does not guess. Review the device mapping in Fleet, then sync again. Sync Conflict The same serial is associated with conflicting Fleet metadata, or a manual checkout disagrees with Fleet ownership. AuditBadger preserves the existing record and reports the conflict for review. Stale Device The device has not checked in within the configured number of days. The default device-inventory verification threshold is 30 days. Evidence Sources FleetDM can provide four automated evidence sources: - Endpoint Device Inventory: import coverage, active AuditBadger owner matching, Fleet status, staleness, and sync conflicts. - MDM Enrollment Status: Fleet MDM configuration and per-device enrollment posture. - Endpoint Disk Encryption: FileVault, BitLocker, or LUKS posture without recovery keys. - Screen Lock Policy Compliance: pass/fail results for the Fleet policies selected as screen-lock evidence. Use Install Evidence on the integration page to attach the appropriate sources to compliance controls. Screen-lock evidence remains unavailable until at least one Fleet policy is selected. Troubleshooting An Existing Asset Is Shown As New Compare the Fleet hardware serial with the AuditBadger asset serial. They must be an exact match. Also confirm the asset belongs to the same AuditBadger account and is not already linked to a different Fleet host. A Device Has An Email But No Owner Match Confirm an active AuditBadger user has exactly that email address. Deactivated, not-yet-active, terminated, or partner-managed users are not valid automatic owners. A Device Is Missing From AuditBadger Open Review Devices and confirm the host is selected. If it is visible but unselected, select it and click Save And Sync. If it is not visible, verify that the Fleet API-only user can read that host. The Importer Cannot Load Hosts Validate the integration connection. Confirm the Fleet URL is reachable, the token is valid, and the API-only user has read access to hosts and device mappings. A Manual Checkout Was Not Replaced This is intentional. AuditBadger never overwrites a manual checkout with Fleet ownership. Resolve the manual checkout or the Fleet mapping, then sync again. Disconnect FleetDM Disconnecting stops Fleet sync and evidence collection. Existing assets, checkouts, and collected evidence are retained. Revoke or delete the API-only user in Fleet if its token should no longer be usable. For product and implementation decisions, see prd_fleetdm-integration.md.

Integrations

DigitalOcean Setup Guide

How to connect a DigitalOcean team to AuditBadger with a custom-scoped, read-only personal access token. Takes about 5 minutes. 1. Create the personal access token 1. In the DigitalOcean control panel, open API → Tokens. 2. Click Generate New Token and name it AuditBadger Compliance Read-Only. 3. Pick the longest expiration your policy allows (or no expiration if available) and note the date — you will enter it in AuditBadger. 4. Under scopes, choose Custom Scopes — do not use the Read Only or Full Access presets. 5. In the scope picker, search for each entry below and tick only its read checkbox. Leave every create, update, delete, and admin checkbox unticked: - account:read - project:read - regions:read - tag:read - droplet:read - image:read - snapshot:read - block_storage:read - block_storage_snapshot:read - firewall:read - vpc:read - vpc_peering:read - reserved_ip:read - load_balancer:read - certificate:read - domain:read - ssh_key:read - uptime:read - actions:read - database:read - kubernetes:read - cdn:read 6. Click Generate Token. 7. Copy the token immediately — DigitalOcean shows it only once. Tick nothing else. In particular never grant api:read, api:write, any write scope, database:view_credentials, kubernetes:access_cluster, app:access_console, security:read, or Spaces key scopes. AuditBadger does not need them, and its API client is hard-limited to an allowlist of GET endpoints, so it will refuse to use them. 2. Connect in AuditBadger 1. Go to Account Settings → Integrations → DigitalOcean (the tab appears when the feature flag is enabled for your account). 2. Paste the token and, if it expires, enter the expiration date so AuditBadger can remind you before collection stops. 3. Save. AuditBadger validates the connection in the background and discovers the team identity via GET /v2/account. 4. Once connected, install evidence sources on your compliance controls (individually from a control, or in bulk via "Install evidence sources"). Token rotation 1. Generate a new custom-scoped token in DigitalOcean with the same scopes. 2. On the integration page, open Configuration, paste the new token, update the expiration date, and save. Evidence sources and collected evidence are kept. 3. After AuditBadger re-validates, delete the old token in DigitalOcean. Troubleshooting - "Permission denied — the token is missing a required scope" - the token was created without one of the scopes above. Generate a new token with the full checklist; scopes cannot be edited after creation. - "Invalid or expired personal access token" - the token was revoked or expired. Generate and paste a new one. - Token expiring soon warning - generate a new token and update the configuration before the expiry date; collection stops when the token expires. - A domain/uptime source collects nothing - the team hosts no DNS zones or uptime checks on DigitalOcean; those sources only produce evidence for resources that exist.

Integrations

Vercel Integration User Guide

Overview Humadroid's Vercel integration automatically collects compliance evidence from your Vercel deployment platform. Once connected, it continuously monitors your Vercel team configuration, project settings, and security controls to gather evidence that satisfies controls for SOC 2 and ISO 27001 compliance frameworks. Key Benefits - Automated evidence collection - No more manual screenshots or exports - Compliance-focused collection - Evidence collected on schedule (monthly) - Auto-verification - Many evidence sources are automatically checked against compliance rules - Multi-framework support - Single integration satisfies controls across SOC 2 and ISO 27001 - Plan-aware - Automatically adapts to your Vercel plan (Hobby/Pro/Enterprise) Security Model - Read-only access - Humadroid cannot modify your Vercel settings or deployments - Dual authentication options - OAuth integration (recommended) or API Token - Team-scoped access - Access limited to selected team only - Encrypted credential storage - Credentials encrypted at rest - Easily revocable - Disconnect anytime from Humadroid or revoke from Vercel Evidence Sources The Vercel integration collects 9 distinct evidence types across three categories: Access Control Team Members & Roles - Description: Collects team membership and role assignments for access control evidence - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans RBAC Configuration - Description: Documents role-based access control configuration and custom roles - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans Project Access Settings - Description: Collects project-level access restrictions and team assignments - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans SSO/SAML Configuration - Description: Collects SSO enforcement status and SAML configuration - Frequency: Monthly - Auto-Verify: Yes - Plan Required: Enterprise only Deployment Security Deployment Protection - Description: Collects deployment protection settings including authentication requirements - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans (limited on Hobby) Network Security Firewall Status - Description: Collects firewall enablement and managed rulesets (Bot Protection, AI Bots) across projects - Frequency: Monthly - Auto-Verify: Yes - Plan Required: Pro+ WAF Rules - Description: Collects custom WAF rules and managed rule configurations - Frequency: Monthly - Auto-Verify: No (manual review recommended) - Plan Required: Pro+ IP Blocking Rules - Description: Collects IP blocking and allowlist configurations - Frequency: Monthly - Auto-Verify: Yes - Plan Required: All plans (limits vary by plan) Audit & Monitoring Audit Logs - Description: Team activity audit logs for security monitoring - Frequency: Monthly - Auto-Verify: No (manual review required) - Plan Required: Enterprise only SOC 2 Control Coverage The Vercel integration provides evidence for the following SOC 2 (2017) Trust Services Criteria: CC6 - Logical and Physical Access Controls CC6.1 - Logical Access Security The entity implements logical access security software, infrastructure, and architectures to protect information assets - Team Members & Roles - Access policies enforce least-privilege principles - RBAC Configuration - Role-based access controls are properly configured - Project Access Settings - Project-level access is restricted appropriately - SSO/SAML Configuration - Enterprise SSO enforces strong authentication CC6.2 - User Registration and Authorization Prior to issuing system credentials and granting access, the entity registers and authorizes new users - Team Members & Roles - Complete inventory of users with access and role assignments - Audit Logs - User registration and authorization events are logged (Enterprise) CC6.3 - Removal of Access Rights The entity removes credentials and disables system access when no longer required - RBAC Configuration - Role changes and access modifications documented - Audit Logs - Access revocation events are logged (Enterprise) CC6.6 - Logical Access Security Measures The entity implements controls to prevent or detect and act upon unauthorized logical access - Project Access Settings - Project-level access restrictions prevent unauthorized access - Deployment Protection - Deployments are protected from unauthorized access - Firewall Status - Firewall and managed rulesets protect against attacks (Pro+) - WAF Rules - Custom WAF rules provide application-level protection (Pro+) - IP Blocking Rules - Network-level access restrictions are configured CC7 - System Operations CC7.2 - Security Event Logging The entity identifies and logs security events - Audit Logs - Security events are recorded (Enterprise) CC8 - Change Management CC8.1 - Change Management The entity authorizes, documents, and controls infrastructure changes - Deployment Protection - Deployment changes require appropriate authorization - Audit Logs - Infrastructure changes are logged (Enterprise) ISO 27001:2022 Control Coverage The Vercel integration provides evidence for the following ISO 27001:2022 Annex A controls: A.5 - Organizational Controls A.5.15 - Access Control Rules to control physical and logical access to information and other associated assets shall be established and implemented - Team Members & Roles - Access policies enforce security requirements - RBAC Configuration - Role-based access control is implemented - Project Access Settings - Project-level access is controlled - SSO/SAML Configuration - Strong authentication is enforced (Enterprise) A.5.16 - Identity Management The full life cycle of identities shall be managed - Team Members & Roles - Complete inventory of identities - Audit Logs - Identity lifecycle events are tracked (Enterprise) A.5.17 - Authentication Information Allocation and management of authentication information shall be controlled - SSO/SAML Configuration - Authentication is properly configured (Enterprise) - Deployment Protection - Deployment authentication requirements A.5.18 - Access Rights Access rights to information and other associated assets shall be provisioned, reviewed, modified and removed - RBAC Configuration - Access rights are managed through roles - Audit Logs - Access changes are logged (Enterprise) A.5.23 - Information Security for Use of Cloud Services Processes for acquisition, use, management and exit from cloud services shall be established - Firewall Status - Cloud security controls are configured (Pro+) - Deployment Protection - Cloud deployments are protected - Audit Logs - Cloud service usage is logged (Enterprise) A.8 - Technological Controls A.8.3 - Information Access Restriction Access to information and other associated assets shall be restricted - Project Access Settings - Project data access is restricted - Deployment Protection - Deployment access is controlled - IP Blocking Rules - Network access is restricted A.8.9 - Configuration Management Configurations, including security configurations, shall be established, documented, implemented, monitored and reviewed - Firewall Status - Security configurations are documented (Pro+) - WAF Rules - Custom security rules are configured (Pro+) A.8.12 - Data Leakage Prevention Data leakage prevention measures shall be applied - Deployment Protection - Unauthorized access to deployments is prevented A.8.15 - Logging Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed - Audit Logs - Activity logs are maintained (Enterprise) A.8.16 - Monitoring Activities Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken - Firewall Status - Security monitoring via firewall (Pro+) A.8.20 - Networks Security Networks and network devices shall be secured, managed and controlled - Firewall Status - Firewall provides network protection (Pro+) - WAF Rules - Network security rules are configured (Pro+) - IP Blocking Rules - Network access is controlled A.8.21 - Security of Network Services Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored - Firewall Status - Network service security is monitored (Pro+) - IP Blocking Rules - Network service access is controlled Verification Rules Auto-verified evidence sources are checked against the following compliance thresholds: Team Members & Roles - All team members have assigned roles: Required - No orphaned or inactive members: Flagged - Admin role usage: Documented and reviewed RBAC Configuration - Custom roles follow least-privilege: Recommended - Role assignments documented: Required - Sensitive permissions (billing, team management): Flagged for review Project Access Settings - Project access restricted to authorized teams: Required - No overly permissive project settings: Flagged - Production project restrictions: Recommended Deployment Protection - Production environments protected: Required - Authentication required for preview deployments: Recommended - Password protection configured: Optional SSO/SAML Configuration (Enterprise) - SSO enforcement enabled: Required - SAML configuration valid: Required - Identity provider properly configured: Required Firewall Status (Pro+) - Firewall enabled on production projects: Required - Bot Protection managed ruleset enabled: Recommended - All public-facing projects protected: Required WAF Rules (Pro+) - OWASP Core Rule Set enabled: Recommended - Custom rules reviewed: Manual verification - Rule exceptions documented: Required IP Blocking Rules - Blocking rules configured: Optional - Allowlist properly scoped: Recommended - Geographic restrictions (if applicable): Documented Audit Logs (Enterprise) - Audit logging enabled: Required - Log retention appropriate: Recommended - Regular log review: Manual verification Summary: Control Coverage Matrix SOC 2 Controls by Evidence Source Team Members & Roles - CC6.1: Yes - CC6.2: Yes RBAC Configuration - CC6.1: Yes - CC6.3: Yes Project Access Settings - CC6.1: Yes - CC6.6: Yes Deployment Protection - CC6.6: Yes - CC8.1: Yes SSO/SAML Configuration (Enterprise) - CC6.1: Yes Firewall Status (Pro+) - CC6.6: Yes WAF Rules (Pro+) - CC6.6: Yes IP Blocking Rules - CC6.6: Yes Audit Logs (Enterprise) - CC6.2: Yes - CC6.3: Yes - CC7.2: Yes - CC8.1: Yes ISO 27001 Controls by Evidence Source Team Members & Roles - A.5.15: Yes - A.5.16: Yes RBAC Configuration - A.5.15: Yes - A.5.18: Yes Project Access Settings - A.5.15: Yes - A.8.3: Yes Deployment Protection - A.5.17: Yes - A.5.23: Yes - A.8.3: Yes - A.8.12: Yes SSO/SAML Configuration (Enterprise) - A.5.15: Yes - A.5.17: Yes Firewall Status (Pro+) - A.5.23: Yes - A.8.9: Yes - A.8.16: Yes - A.8.20: Yes - A.8.21: Yes WAF Rules (Pro+) - A.8.9: Yes - A.8.20: Yes IP Blocking Rules - A.8.3: Yes - A.8.20: Yes - A.8.21: Yes Audit Logs (Enterprise) - A.5.16: Yes - A.5.18: Yes - A.5.23: Yes - A.8.15: Yes Additional ISO 27001 Control Coverage A.5.23 - Cloud Services Security - Firewall Status (Pro+): Yes - Deployment Protection: Yes - Audit Logs (Enterprise): Yes A.8.16 - Monitoring Activities - Firewall Status (Pro+): Yes A.8.21 - Security of Network Services - Firewall Status (Pro+): Yes - IP Blocking Rules: Yes Getting Started To set up the Vercel integration: 1. Navigate to Settings > Integrations > Vercel 2. Click Connect Vercel Account 3. Choose your authentication method: - OAuth (Recommended): Click "Connect with Vercel" for one-click authorization - API Token: Manually create and enter a Vercel API token 4. Select the team to monitor (if your account has multiple teams) 5. Validate the connection 6. Enable evidence sources for your compliance controls Option 1: OAuth Connection (Recommended) 1. Click Connect with Vercel button 2. You'll be redirected to Vercel to authorize Humadroid 3. Grant read-only access to your Vercel account 4. You'll be automatically redirected back to Humadroid 5. Select a team if you have multiple teams This method provides automatic token management and scoped permissions. Option 2: API Token (Manual) 1. Log into your Vercel Dashboard 2. Go to Account Settings > Tokens 3. Click Create to create a new token 4. Name: "Humadroid Compliance Read-Only" 5. Scope: Select Full Account for team access 6. Expiration: "No Expiration" recommended for automated collection 7. Click Create Token 8. Copy the token immediately (it won't be shown again) Vercel Permissions Required The integration requires read-only permissions via OAuth or an API Token with Full Account scope: Required Scopes - Team:Read - Access team membership and settings - Projects:Read - Access project configurations - Deployments:Read - Access deployment settings - Firewall:Read - Access WAF and IP blocking rules (Pro+) API Endpoints Used GET /v2/teams - List teams GET /v2/teams/{teamId}/members - List team members GET /v9/projects - List projects GET /v9/projects/{projectId} - Get project details (includes security settings) GET /v6/deployments - List deployments (for protection settings) GET /v1/security/firewall/config - WAF configuration (Enterprise) GET /v2/integrations/sso - SSO configuration (Enterprise) Vercel Plan Feature Matrix Hobby Plan Available Features: - Team Members & Roles - RBAC Configuration (basic roles) - Project Access Settings - Deployment Protection (limited) - IP Blocking Rules (10 IPs max) Not Available: - Firewall Status - WAF Rules - SSO/SAML Configuration - Audit Logs Pro Plan Available Features: - Team Members & Roles - RBAC Configuration - Project Access Settings - Deployment Protection (full features) - IP Blocking Rules (100 IPs max) - Firewall Status - WAF Rules (40 rules max) Not Available: - SSO/SAML Configuration - Audit Logs Enterprise Plan All Features Available: - Team Members & Roles - RBAC Configuration (custom roles) - Project Access Settings - Deployment Protection (full features) - IP Blocking Rules (custom limits) - Firewall Status - WAF Rules (1000 rules max) - SSO/SAML Configuration - Audit Logs - SIEM Streaming - Trusted IPs Troubleshooting Common Issues "Invalid API Token" - Verify the token was copied correctly (no extra spaces) - Check if the token has expired - Ensure the token has Full Account scope "No teams found" - The API token may be personal-only; create a team-scoped token - Verify you have access to at least one team "Firewall data not available" - Firewall features require Pro plan or higher - Ensure the Firewall:Read scope is included "SSO/Audit data not available" - These features require Enterprise plan - Contact Vercel to upgrade if needed Rate Limits Vercel API has the following rate limits: - 10 requests per second - 10,000 requests per day Humadroid respects these limits and implements automatic retry with backoff.

Admin Guide Compliance Module

Setting up your Compliance module in Humadroid.

The Compliance tab is available only for paid accounts. If you’re managing frameworks like ISO 27001 or SOC 2, or you need to maintain an audit-ready internal control system, this is your go-to setup. Compliance Settings Overview Risk Categories Define what risks your company tracks – and how they’re grouped. Humadroid comes with a set of system default risk categories. These are grouped by area (e.g., Compliance, Contractual, External) and include: - Clear descriptions of the risk type - Examples of common threats or violations - Tags to help with classification Default risk categories Default compliance risk categories in Humadroid including contractual, legal, and regulatory risks System default risk categories grouped by type: compliance, legal, contractual, and regulatory. Each includes examples to help with classification. You can use these predefined categories out of the box or create your own, aligned with your structure, teams, or departments. 💡 Example: Create a custom “IT Operational Risk” category if you’re tracking system downtimes or vendor SLA breaches separately. Creating a new risk category Form for adding a new custom risk category in Humadroid with name, identifier, parent category, and examples Define your own risk categories with custom identifiers, color codes, and classification examples tailored to your organization. Scoring Methods Decide how you evaluate and prioritize risks. In this section, you manage risk scoring models that help determine the criticality of each risk. Three default methods are available: - Multi-Impact Assessment Uses a weighted formula based on financial, legal, and reputational impact. - Simple 5×5 Risk Matrix A straightforward model using probability × impact. - Weighted Impact Assessment A nuanced model allowing additional types of impact (e.g., operational). Available risk scoring methods List of default risk scoring methods in Humadroid including Multi-Impact Assessment, 5x5 Risk Matrix, and Weighted Impact Assessment. Choose from predefined scoring models like Multi-Impact Assessment or create your own to align with your organization’s risk evaluation framework. Each model comes with editable treatment thresholds (when a risk becomes significant) and customizable weights. You can also create new methods based on your internal evaluation criteria. 📎 Recommended: In our internal compliance, we're using this method with a higher threshold - it allows us to focus on really important risks and leave a track of those of lesser impact. Custom risk scoring method setup Form for creating a new risk scoring method in Humadroid with custom formulas, treatment thresholds, and impact calculations. Build your own risk scoring method using custom thresholds and impact-based formulas. Ideal for tailoring your compliance evaluation to specific frameworks. Employment Types n Humadroid, Employment Types help you enforce compliance by ensuring the right documents are linked to the right roles. Whether it’s full-time staff, contractors, or interns, each type can have specific policies automatically assigned, such as: - Code of Conduct - NDA - Security or Data Protection Policies This ensures that every person acknowledges the right set of documents based on their role, with no manual chasing. 👉 Full guide: Employment Types in Humadroid → Employment types overview Creating a new employment type Form for adding a new employment type in Humadroid with required documents and activation toggle Create a custom employment type and link it to required documents like Code of Conduct or Security Policy. Documents will be auto-assigned to users based on their role. Advanced Asset Management (Assets Settings) Once Compliance is enabled, you’ll also get access to advanced asset tracking features, so let’s break up how to navigate through Assets settings. Lifecycle States Here, you define and manage equipment lifecycle stages from the beginning, from purchasing to disposal. Humadroid provides a set of default states: - Ordered - Received - In Stock - Deployed …and more. You can edit these or create your own. Adding a new lifecycle state, by clicking "Add New State" Form for creating a new asset lifecycle state in Humadroid with name, description, terminal status, and custom fields Add custom asset states to match your internal workflows. Use terminal states to define endpoints like “Retired” or “Disposed”. Lifecycle view with state transitions Asset lifecycle flow diagram in Humadroid showing transitions between states like Ordered, Received, In Stock, Deployed, and Under Repair Visualize asset state transitions using a flow diagram. Customize each state and its valid paths to reflect your real-world lifecycle management. ✏️ Pro tip: Use custom transitions to enforce rules like “you can’t deploy before receiving.” Categories Organize your hardware and equipment into categories like laptops, phones, and monitors. While creating a category, you can: - Choose a parent category - Set default lifecycle duration - Select the depreciation method - Flag items for regular maintenance Asset category list List of asset categories in Humadroid including laptops, cameras, mobile phones, and monitors with depreciation status Categorize company assets for easier tracking and reporting. Each category can include depreciation settings and asset counts. Creating a new asset category Form for creating a new asset category in Humadroid with lifecycle settings, depreciation, maintenance interval, and custom fields. Define asset categories with lifecycle duration, depreciation settings, and maintenance reminders. Add custom fields to track additional metadata. Departments Use this to assign assets to teams or cost centers. See how much hardware is tied to Sales, Marketing, or IT. Department overview with assigned assets Departments view in Humadroid showing Accounting and Engineering with assigned managers and asset counts Assign assets to specific departments and track inventory by team. Locations Track asset distribution across your offices, warehouses, or regions. Asset location structure Asset locations view in Humadroid showing Germany with Berlin and Poland with Poznań as sub-locations Organize assets across geographic locations with sub-location support. Ideal for multi-office inventory visibility and compliance traceability. 📄 Document Management Humadroid also enables centralized document control – a crucial piece for ISO/SOC 2 audits. You can: - Upload and manage internal policies, procedures, controls - Assign ownership and version history - Link documents to risks, assessments, or assets - Request acknowledgment from employees (e.g., policy sign-off) This feature does not require setting up in settings. Under Compliance -> Documents, you can start create your documents as you go. Compliance documents with acknowledgment tracking Document dashboard in Humadroid showing compliance policies with versioning, acknowledgment status, and update dates Manage all compliance documents in one place. Track versions, statuses, acknowledgment progress, and link policies to roles or users.

Admin Guide Compliance Module

How to Identify Risks in Compliance Projects

Identifying risks is one of the first and most crucial steps when building your compliance project in Humadroid. Done right, it lays the foundation for all your future mitigation efforts, reporting, and governance tracking. Below, we’ll walk you through how to approach risk identification with clarity, structure, and business context. 🧠 What Is Risk Identification? Risk identification is the process of uncovering events or conditions that could negatively affect your organization’s ability to achieve its objectives. In compliance, risks are often linked to: - Legal obligations (e.g., data privacy laws) - Regulatory frameworks (e.g., ISO 27001, SOC 2) - Internal policies (e.g., code of conduct, security protocols) - Operational procedures (e.g., vendor onboarding, remote work) This step is about discovery, not judgment. You don’t have to decide yet how significant or likely a risk is, just that it exists. 🔍 Where to Look for Risks The sources you use to identify risks will depend heavily on your organization’s specific context, the industry in which you operate, the regulations that apply, and how your internal processes work. Below are several common starting points to help you get going: 1. Framework Requirements: Start with the framework you’ve selected (e.g., ISO 27001, HIPAA, SOC 2). Look at its core requirements and ask: “What could cause us to fail here?” Example (SOC 2 - Security): The principle requires access controls. If your company lacks multi-factor authentication (MFA) for admin users, that’s a potential compliance risk. * 2. Business Processes: Map workflows in HR, finance, operations, and IT. Identify weak points, manual steps, or gaps in documentation. Example: In HR onboarding, if there is no checklist to ensure background checks are done, that’s an operational and legal risk. 3. Previous Incidents: Review past issues like data breaches, audit failures, and support escalations. Example: If a past audit flagged a lack of formal vendor risk assessments, make this a formalized risk to track. 4. External Factors: Look at legal changes, economic shifts, political risks, or vendor instability. Example: New GDPR regulations may expose your organization to penalties if your privacy notices are not up to date. 5. Stakeholder Interviews: Ask team leads in IT, legal, HR, and operations about their concerns. Example: A legal manager might express concern about the lack of training logs for employees. That can be logged as a compliance documentation risk. ⏱️ Timeline & Tips Risk identification for your first project can take anywhere from a few hours to a few days, depending on the size of your organization. ✅ Don’t aim for perfection, aim for coverage ✅ Involve cross-functional teams ✅ Revisit your risks quarterly or after any significant incident or audit 🛠️ How to Add Risks in Humadroid Go to the Compliance section on the left -> Pick the project you want to add Risks -> Go to the "Risks" tab -> click "Add Risk" 1. Enter a Title and Description that reflect your organization’s exposures. 2. Select Risk Category, assign an Owner, and set a Next Review Date so nothing slips through 3. On the Risk Assessment tab, you’ll see the predefined impact categories, based on the Scoring Method you selected earlier. Enter the Likelihood and Potential Impact values in each category, and Humadroid will calculate the risk score. 4. Select a Treatment Strategy (Accept, Mitigate, Transfer, or Avoid) and link any relevant controls or documents for complete traceability. 💡 Note: If the Risk Score Summary is at or above the level of the Treatment Threshold of the picked Scoring Method, then you won't be able to Accept the Risk. You will need to take action on it, as it's too high-risk to accept and move on. Examples of Common Risks: - Lack of MFA for Admin Access Admin users are not required to use multi-factor authentication, increasing the likelihood of unauthorized access. This is a common issue flagged under SOC 2's Security principle, which requires strong access controls. - No documented vendor assessment process Vendors are onboarded on an ad hoc basis without consistent risk assessments. This creates blind spots and is often highlighted in third-party risk management reviews (ISO 27001 A.15). - Outdated privacy policy Your public-facing privacy policy hasn’t been updated despite recent regulatory changes like GDPR rulings or CPRA amendments. This leaves you exposed to potential legal penalties. - Excessive admin rights More employees than necessary have unrestricted access to internal systems. This violates the principle of least privilege and increases the risk surface area in case of an insider threat. - No defined incident response plan Your organization has no written and approved process for handling security incidents. This gap would be flagged during audits and leaves you unprepared in a crisis. Each of these risks connects to a real-world weakness that could compromise your compliance posture, and each one can be turned into a documented, trackable item in your Humadroid project. These examples show how real-world weaknesses translate into clearly trackable risks. 🧩 Link Risks to Other Compliance Components Risks can later be linked to: - Controls (preventive measures you take) - Documents/Policies (e.g., Incident Response Policy) Linking Risks with controls, or documents, allows you to have a full picture and understanding of your project. 📘 Learn more: What are Scoring Methods and how to define them By identifying risks with care and structure, you set up a compliance posture that’s proactive, auditable, and ready for change.

Admin Guide Compliance Module

First Project in Compliance

Compliance work starts with clarity, and that’s precisely what a Compliance Project in Humadroid gives you. Whether you're preparing for an audit, aligning with ISO 27001 or SOC 2®, or just mapping internal risks and controls, projects let you structure the entire effort: from frameworks and risks to controls, documents, and assessments. In this guide, we’ll walk you through: - How to create a compliance project - How to define its structure - How to identify and score risks - How to choose the right treatment strategy - How to link supporting documentation and controls ✅ Step 1: Create a New Project Go to Compliance in the left-hand menu and click + Create New > Project. A modal will appear asking for: - Name and description - Project owner - Start and target dates - Choose the ISO 27001 or SOC 2 compliance framework if you're preparing for an audit, or use a blank project if you want to create your own structure. - Scoring method: This determines how Humadroid calculates risk scores in your projects. Humadroid comes with three predefined Scoring Methods: - Multi-Impact Assessment The default method for combining multiple impact types. Formula: Risk = Probability × [Financial Impact (×1) + Legal Impact (×1) + Reputational Impact (×1)] Treatment Threshold: 9 If the calculated score is ≥ 9, the risk must be formally addressed. Tip: Use this when impacts are equally critical and you need a balanced overview - Simple 5×5 Risk Matrix Classic single-dimensional matrix for quick scoring. Formula: Risk = Probability × Overall Impact (×1) Treatment Threshold: 15 If the calculated score is ≥ 15, the risk must be formally addressed. Tip: Ideal for rapid assessments or when you lack detailed impact breakdowns. - Weighted Impact Assessment Nuanced scoring with emphasis on key impact types. Formula: Risk = Probability × [Financial Impact (×2) + Legal Impact (×1) + Reputational Impact (×1) + Operational Impact (×1)] Treatment Threshold: 12 If the calculated score is ≥ 12, the risk must be formally addressed. Tip: Apply this to highlight the most business-critical impact (e.g., financial). Our recommendation is to read our detailed description of Scoring Methods 👉 What are risk scoring methods. 🧩 Step 2: Define Sections & Controls (Optional) 🧠 If you selected a framework for ISO 27001 or SOC 2® during project creation, you now have a full set of controls to work through. To understand how to go through these controls, link evidence, and assess them properly, check this dedicated guide: 👉 How to Work Through Compliance Controls in Humadroid If you didn’t select a predefined framework (such as ISO 27001 or SOC 2®), you can create your own control structure using the Sections & Controls tab. This is especially useful for internal governance, regulatory requirements, or industry-specific frameworks. Go to the Sections & Controls tab to outline your structure. - Add custom sections for key domains - Add controls under each section to track specific requirements (e.g., Two-Factor Authentication enabled) This step is especially useful when working without a predefined standard. 📌 Step 3: Prepare Policies Before Identifying Risks Before jumping into risk identification, it’s highly recommended to prepare and upload your company’s core policies and guidelines. These documents will serve as the foundation for your compliance strategy and often act as direct evidence for various controls. To add policies, go to the Documents tab in your project. Here you can upload new files or create them directly in the system. Once published, these documents can be linked to specific controls or compliance sections and used as recurring evidence during assessments. Remember that you can (and probably will have to ) add new or edit previously created policies along the way, so it's updated. You can review the list of most commonly required policies and their ISO/SOC 2® control references in this article: Prepare Policies and Guides. These may include: - Information Security Policy - Code of Conduct - Vendor Risk Management Policy - Incident Response Plan Versioned and acknowledged policies help demonstrate that your controls are not just theoretical but actively enforced and reviewed. ⚠️ Step 4: Add your Risks Before adding risks, you should identify them first. This involves reviewing your workflows, vendors, tools, and infrastructure to detect areas of potential exposure. (See our full guide: How to Identify Risks in Compliance Projects) To get started: 1. Go to the Risks tab and click + Add First Risk. 2. Fill in the Risk Information: title, description, category, owner, and next review date. 3. In the Risk Assessment tab, set: - Likelihood (chance of happening) - Impact (e.g., financial, legal, reputational) Your selected scoring method will calculate the risk score. If it crosses your treatment threshold, the system will flag it for action. 4. In the Treatment & Links tab, decide how to handle the risk: - Accept - Mitigate (add controls) - Transfer (e.g., via insurance) - Avoid - Other options: Share, Monitor, Investigate You can also link the risk to specific: - Controls - Documents (like policies, SOPs, audit reports) To upload supporting materials: - Go to Documents in the left menu - Add your files and assign them to this project - Attach them to relevant risks and controls for traceability 🧠 Best Practice: Start With a Risk Register During the Planning phase of the project, it's a good idea to map out all known risks early. This gives you: - Better visibility into required controls - Clarity on compliance scope - A living register that can evolve with the project Each risk is created as Draft and can be moved to Identified, In Treatment, or Closed depending on progress. 📈 Final Result: A Structured, Audit-Ready Project By this point, you’ve built the foundation of your compliance initiative: ✅ Defined your scope and structure ✅ Identified and scored key risks ✅ Selected treatments ✅ Linked documentation and controls From here, you can start assigning owners, monitoring progress, and running assessments, all from a centralized compliance dashboard.