Compliance Monitor Platform
Leading monitor-side engineering for compliance evidence: report-backed checks, recurring manual collection, and evaluation paths.
Overview
Compliance teams need current evidence status for the controls they track. Monitors are how Automated Compliance keeps that status attached to the control. Each monitor tracks a requirement, like "all production devices are encrypted," and connects it to the evidence source or collection workflow used to evaluate it.
As the product evolved, changes to requirements kept reaching into the models, and customers still had to upload much of their proof by hand. I led monitor-side work on evidence collection and evaluation as part of the team developing Automated Compliance through those iterations.
What I built
The product distinguished controls, which described requirements, from monitors, which gathered and evaluated the evidence for them. Within that model, my work covered report-backed monitors, recurring manual evidence, and evaluation and read paths. The separation let us work on how a requirement was checked without treating every new evidence source as a different control.
The question for each monitor was where it could get its proof. Across the product, sources included Checkr, AWS, GitHub, and Rippling's first-party apps. Where a source system could answer the question, an integration or report could supply the evidence; where it could not, we still needed a usable way for the customer to provide it.
I built recurring manual evidence sources so monitors could request evidence on a schedule. A quarterly collection task could then live inside the monitor lifecycle instead of depending on a separate reminder loop. The work also covered consolidating uploads and loading the associated evidence for reads, so manual proof remained connected to the control's history alongside automated proof.
Collaboration
Product collaboration shaped where standard monitors should stay opinionated. A solutions expert helped connect the monitor model to the report library behind many automated evidence paths.
The hard product conversation was how much a standard monitor could assume about a customer's evidence. The manual collection path mattered here: we could guide collection when the available integrations could not supply the proof, without pretending every requirement was already automated.
Outcome
- Report-backed and integration-backed monitors became the main path for the automated evidence checks covered by this work.
- Recurring manual evidence sources kept non-automatable controls inside the same monitor lifecycle, including scheduled requests, uploads, consolidation, and hydrated reads.
I wanted the customer to be able to follow the evidence regardless of how it arrived. Automating a check removed work when the source data was available; keeping manual requests in the same history made the remaining work easier to track.