Risk and compliance
The Risk & Compliance group in the Agentic Transformation Platform (ATP) sidebar holds 10 assessment pages. Each page is run by the same agent, The Harbinger (risk and compliance agent). Use this page to choose the right assessment and prepare the evidence it asks for.
Before you start
- Every page in this group uses the same assessment workspace. To learn how to upload evidence, run an analysis and ask follow-up questions, read Run an assessment.
- Upload metadata and exports only. Each page's Instructions panel says what not to upload.
Open a page in this group
- In ATP, open the menu at the left of the navigation bar.
- Expand Risk & Compliance.
- Select the page you need.
When a page from this group is open, the navigation bar shows the group's pages as tabs, so you can move between them. Pages that don't fit are under More.
Pages in this group
| Page | What it covers |
|---|---|
| Security Governance | Security policies and governance framework. |
| MVP | Minimum viable platform risk review. |
| Identity Access Mgmt. & SSO | User authentication and access control. |
| Infrastructure Security | Network and infrastructure protection. |
| Data Protection | Data encryption and privacy controls. |
| Security Logging & Monitoring | Security event monitoring and logging. |
| Security Incident Response | Incident detection and response procedures. |
| SRC Reporting | Security, risk, and compliance reporting. |
| Auditing | Compliance auditing and assessments. |
| Threat Detection | Threat intelligence and detection systems. |
Instructions on every page in this group
Every page in the Risk & Compliance group shows the same Instructions panel.
The Instructions panel is titled How to Generate Your Security Governance Assessment Report. It says:
To generate your security governance assessment report, The Harbinger only needs security-policy documentation and governance-framework metadata — metadata includes security policies, governance checklists, and compliance documentation.
It lists the evidence to upload:
- Security Policies: Information security policies, acceptable use policies, data classification standards, and security baselines.
- Governance Framework: GRC framework documentation, NIST, SOC2, control frameworks, and oversight and compliance mappings.
- Risk Management: Risk register entries, control-assessment data, mitigation plans, exception documentation, and risk reporting.
- Compliance Requirements: Regulatory compliance documentation, SOC2, PCI-DSS, and compliance obligations data.
- Policy Documentation: Policy review cycles, policy compliance certificates, implementation guidelines, and compliance framework updates.
The panel also shows this note:
Security Note: Avoid submitting highly sensitive security configurations or live infrastructure data — The Harbinger analyzes governance frameworks and policy structures, not specific security device configurations.
Security governance
Select Security Governance to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Security policies and governance framework.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
MVP
Select MVP to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Minimum viable platform risk review.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Identity access management and SSO
Select Identity Access Mgmt. & SSO to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: User authentication and access control.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Infrastructure security
Select Infrastructure Security to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Network and infrastructure protection.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Data protection
Select Data Protection to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Data encryption and privacy controls.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Security logging and monitoring
Select Security Logging & Monitoring to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Security event monitoring and logging.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Security incident response
Select Security Incident Response to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Incident detection and response procedures.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
SRC reporting
Select SRC Reporting to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Security, risk, and compliance reporting.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Auditing
Select Auditing to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Compliance auditing and assessments.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.
Threat detection
Select Threat Detection to open this page. The page header shows the badge Assessment workspace and the line Expert Consultation with The Harbinger. The sidebar describes it as: Threat intelligence and detection systems.
Upload the evidence described in Instructions on every page in this group, then select Run Analysis.