Skip to main content

Access, freshness, and scope

The graph shows your whole compliance program on one screen, which is exactly why it is guarded, rebuilt on a fixed cadence, and explicit about what it leaves out. This page explains each of those choices and what to do when the page shows a holding state instead of the map.

Who can open it

Two conditions, both checked on every request:

  • Read permission on Frameworks. The graph draws on your compliance program, so it uses the same permission the Frameworks module does. Evidence nodes additionally need read access to the Evidence Locker, and cloud posture technique nodes need read access to Cloud Posture. Nodes you are not allowed to read are left out of your view of the graph.
  • A two-factor session. The graph exposes sensitive compliance data in one place, so it is only served on sessions protected by two-factor authentication. Enable it in your account settings and sign in again.

The sidebar entry itself follows the same rules: Knowledge Graph only appears when your session could actually open it. If you expect to see it and do not, check the two conditions above before assuming the graph has not been built.

Every view of the graph is written to your organization's audit log, the same log the rest of the platform uses.

When it refreshes

The graph is rebuilt overnight, at 06:00 UTC, for every organization with at least one activated framework. The page header shows "data as of", which is the moment the build was verified against your records.

Two details about that timestamp are easy to misread:

  • A rebuild that finds nothing changed still updates the timestamp. The time means "last confirmed current", not "last changed". A graph whose content has been stable for a week can still say it was verified this morning.
  • Today's changes are in tomorrow's graph. Attaching evidence, assessing a control, or approving a crosswalk shows on the map after the next overnight build. The Frameworks and Evidence pages show the change immediately; the graph is the overnight picture.

What it leaves out

  • Business-unit-scoped records. The graph is the organization-wide view. Controls, evidence, and assessments scoped to a single business unit are deliberately excluded, so nothing on the map is narrower than the whole organization.
  • Anything without a link. The graph is built from relationships. A piece of evidence that is not attached to any control does not appear, because there is nothing to draw it against. Attach it in the Evidence Locker and it is in the next build.
  • Frameworks you have not activated. The catalog is not the graph. Activate a framework and its controls join the map overnight.

What the holding states mean

When the page cannot show the map, it shows one of these instead. Each says what happened and what, if anything, you can do.

You seeWhat it meansWhat to do
Your knowledge graph is still being builtNo finished build exists for your organization yet.Activate a framework and add a few controls or pieces of evidence. The graph appears after the next overnight build. Try again re-checks.
You don't have access to the knowledge graphYour role lacks read permission on Frameworks.Ask an administrator to grant it.
Two-factor authentication requiredYour current session is not protected by two-factor authentication.Enable it in your account settings, then sign in again.
Your session has expiredThe sign-in behind this page has lapsed.Sign in again.
Too many requestsThe graph was requested many times in a short window.Wait a moment and choose Try again.
Couldn't load the knowledge graphThe build could not be served.Choose Try again. If it persists, contact support with the time it happened.

Where the graph lives

The graph is a projection of your records, not a second copy you maintain. Each build is written to your organization's own isolated storage, fingerprinted so that the same records always produce the same build, and served from there. It is never edited by hand and cannot drift from the data it was built from: if the records change, the next build changes with them, and if they do not, the build is byte-for-byte the same. Nothing in SolveGRC treats the graph as a source of truth it could not rebuild from your data.