> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Platform Workflows

> How frameworks, controls, actions, and evidence fit together in Iru Compliance: setup, assignments, sources, readiness, and audit-ready reporting.

These workflows show how **frameworks**, **controls**, **actions**, and **artifacts** connect in Iru Compliance, from choosing a standard through evidence collection and readiness.

<Info>
  Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support).
</Info>

## How It Works

You select frameworks, refine controls and actions, attach evidence (manually or from **Sources**), and track readiness in framework and action views. Integrations can attach evidence automatically when they are connected and **action** descriptions name the system and evidence type clearly.

As integrations and policy artifacts change, [Adaptive Compliance](/en/compliance/adaptive-compliance) can propose updates to control and action text. You review each recommendation and approve only the changes you want; audit periods and uploaded evidence are not changed by that workflow.

## Core Workflow: From Framework to Compliance

#### Framework Setup

<Steps>
  <Step title="Navigate to the Account Menu Button">
    In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu) (same flow as **Recommended setup** in [Getting Started With Compliance](/en/compliance/getting-started-with-compliance)).
  </Step>

  <Step title="Open Organization profile">
    Select **Organization** to open **Organization profile**. Iru may also prompt for this during framework setup.

    <Frame>
      <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-org.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=f8a368153bc4b87d3a4aa49961d54a20" alt="Account menu with Organization option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-org.png" />
    </Frame>
  </Step>

  <Step title="Enter edit mode">
    On **Organization profile**, click **Edit** at the top right.
  </Step>

  <Step title="Complete your company details">
    Fill in the fields that apply. For example: **company logo**, **company name**, **business description**, **industry**, **business type**, **company size**, **company language**, whether you have an **IT department**, and **security team size**. Keep this information current as your environment changes.
  </Step>

  <Step title="Save your changes">
    Click **Save changes**.
  </Step>

  <Step title="Navigate to Frameworks">
    On the left navigation bar, expand **Compliance** and select **Frameworks**.

    <Frame>
      <img src="https://mintcdn.com/iru/7HsGH7lnQ8GpVmI0/assets/media/images/iru-navigation-compliance-frameworks.png?fit=max&auto=format&n=7HsGH7lnQ8GpVmI0&q=85&s=5e04644a65deaff37057dcfc8e3bd8fc" alt="Left navigation: Compliance expanded, Frameworks selected" width="432" height="1056" data-path="assets/media/images/iru-navigation-compliance-frameworks.png" />
    </Frame>
  </Step>

  <Step title="Add a framework and starting point">
    Click **Add framework**, choose a standard, then complete **Select your \[framework] starting point** (generate, migrate, CSV, or manual). See [Frameworks Management](/en/compliance/frameworks-management).

    <Frame>
      <img src="https://mintcdn.com/iru/Zf_576ytuhylbaXM/assets/media/images/iru-compliance-frameworks.png?fit=max&auto=format&n=Zf_576ytuhylbaXM&q=85&s=8c9c328bf6ec391806beeb22c05e6c4e" alt="Frameworks page with Add framework, framework cards, audit period, and controls" width="2234" height="1046" data-path="assets/media/images/iru-compliance-frameworks.png" />
    </Frame>
  </Step>

  <Step title="Refine controls and actions">
    Review and edit generated or imported controls and actions as needed.
  </Step>
</Steps>

#### Control Management

<Steps>
  <Step title="Review controls">
    Open each framework and review generated or imported controls.
  </Step>

  <Step title="Customize controls">
    Edit wording, add controls, or remove items so they match how your organization operates. When **Sources** or policy artifacts change later, check **Home** → **Insights** or **Review Control Updates** on a framework for Iru AI recommendations. See [Adaptive Compliance](/en/compliance/adaptive-compliance).
  </Step>

  <Step title="Map and validate">
    Confirm each control still maps to the right framework requirement and that owners and evidence expectations are clear.
  </Step>
</Steps>

#### Action Execution

<Steps>
  <Step title="Assign actions">
    Assign actions to owners and set due dates.
  </Step>

  <Step title="Review descriptions">
    Owners read the action text and confirm what evidence is required.
  </Step>

  <Step title="Collect evidence">
    Upload artifacts or let connected **Sources** attach them when descriptions and permissions allow.
  </Step>

  <Step title="Collaborate">
    Use comments and delegation when work needs to move between people.
  </Step>

  <Step title="Track progress">
    Watch status and deadlines on the **Actions** views and framework readiness.
  </Step>
</Steps>

#### Evidence Management

<Steps>
  <Step title="Upload artifacts">
    Add files from **Artifacts** or from an action or control when the UI offers an upload.
  </Step>

  <Step title="Use sources">
    Connect **Sources** so integrations can attach artifacts when action text and permissions align.
  </Step>

  <Step title="Validate and link">
    Let validation run where the product supports it, then confirm artifacts sit on the right actions and controls.
  </Step>

  <Step title="Review for audits">
    Before an audit window, spot-check that required evidence is present and current.
  </Step>
</Steps>

#### Readiness Assessment

<Steps>
  <Step title="Monitor progress">
    Use framework and action views to see what is still open.
  </Step>

  <Step title="Close gaps">
    Fix missing actions, weak evidence, or failed validation before you report readiness.
  </Step>

  <Step title="Report status">
    Export or summarize status for stakeholders using the reports your tenant provides.
  </Step>
</Steps>

## Integration Workflows

#### Automated Evidence Collection

<Steps>
  <Step title="Connect sources">
    Expand **Compliance**, select **Sources**, and turn on the **toggle** for each integration. See [Sources Management](/en/compliance/sources-management) for connector guides.

    <Frame>
      <img src="https://mintcdn.com/iru/7HsGH7lnQ8GpVmI0/assets/media/images/iru-navigation-compliance-sources.png?fit=max&auto=format&n=7HsGH7lnQ8GpVmI0&q=85&s=595982441fd777b333b3ecfea24adc24" alt="Left navigation: Compliance expanded, Sources selected" width="424" height="1056" data-path="assets/media/images/iru-navigation-compliance-sources.png" />
    </Frame>
  </Step>

  <Step title="Write actionable descriptions">
    In each action, name the system and evidence type so connectors know what to fetch (see [Actions Management](/en/compliance/actions-management)).
  </Step>

  <Step title="Let sources sync">
    Sources refresh on a schedule; status and last sync appear on each source card. New, updated, or removed connections can prompt control update recommendations within about a day. See [Adaptive Compliance](/en/compliance/adaptive-compliance).
  </Step>

  <Step title="Validate and confirm">
    Review attached artifacts and validation results on the action or control.
  </Step>
</Steps>

#### Manual Evidence Upload

<Steps>
  <Step title="Choose files">
    Pick policies, exports, screenshots, or other files that satisfy the action or control.
  </Step>

  <Step title="Upload on Artifacts or the action">
    Add titles and descriptions when prompted, then upload (see [Artifacts Management](/en/compliance/artifacts-management)).
  </Step>

  <Step title="Confirm validation">
    Address any failed validation or replace files that are out of date.
  </Step>
</Steps>

## Collaboration Workflows

#### Team Coordination

<Steps>
  <Step title="Assign and delegate">
    Give actions to owners; reassign or delegate when responsibility shifts.
  </Step>

  <Step title="Use comments and activity">
    Use comments for questions and the activity log to see what changed. For a tenant-wide view of compliance activity, see [Unified Activity](/en/iru/platform-overview/unified-activity).
  </Step>

  <Step title="Watch deadlines">
    Track due dates and notifications so work does not stall.
  </Step>
</Steps>

#### Audit Preparation

<Steps>
  <Step title="Compile evidence">
    Confirm each required control has supporting artifacts in Iru.
  </Step>

  <Step title="Fix gaps">
    Upload missing files, fix failed validation, or adjust actions before the audit.
  </Step>

  <Step title="Package for reviewers">
    Export or hand off bundles your auditor expects (reports, folders, or Trust Center links, depending on your process).
  </Step>
</Steps>
