Skip to main content

Knowledge Graph

The Knowledge Graph is a map of your compliance program as SolveGRC actually holds it: every framework you have activated, every control under those frameworks, the crosswalk hubs that tie equivalent requirements together, every piece of evidence attached to a control, and the attack techniques your cloud findings point at. SolveGRC rebuilds it overnight from the same records the rest of the platform runs on. What you see is a picture of your data, not a diagram somebody drew and forgot to update.

Two readers use the graph. You do, on the Knowledge Graph page, to see at a glance which controls are proven and which are only asserted. The AI assistant does too: when you ask it about a control or a framework, it searches and walks this same graph and cites the concepts it used, so its answer and your map never disagree.

Where to find it

Knowledge Graph appears in the left sidebar once your organization has a finished build. A build needs at least one activated framework, and the first one runs on the next overnight cycle after activation, so a framework you activate this morning shows up as a graph tomorrow. Until a build exists the entry stays hidden rather than opening onto an empty page.

Opening the page needs two things: read permission on Frameworks, and a session protected by two-factor authentication. Access, freshness, and scope explains why, and what each of the page's holding states means.

What the graph contains

  • Frameworks you have activated, as purple nodes.
  • Controls under those frameworks, as blue nodes. A control turns green only when it has been assessed compliant and at least one piece of current evidence backs it.
  • Evidence attached to controls, as small blue dots. Evidence that has gone stale carries a dashed amber ring.
  • Crosswalk hubs, as hollow nodes: one hub stands for a requirement that several frameworks share, which is what makes reusing evidence across frameworks possible.
  • Your own controls, the ones you defined rather than imported, as larger hollow nodes with a blue outline.
  • Attack techniques inferred from your cloud posture findings.

Every line between two nodes is a claim: this evidence proves that control, this control belongs to that framework, this hub maps these two requirements onto each other. Read the graph walks through each node type, what a green control actually means, and how to tell a reviewed crosswalk from a proposed one.

What it is for

The graph is most useful when a question is easier to see than to write as a filter.

  • Find the controls you are asserting but not proving. Filter to "unproven" and pick a framework. What remains is your real gap list: controls marked compliant with nothing current attached.
  • Check a crosswalk before you lean on it. A hub that was proposed by the AI and never reviewed is a suggestion, not a mapping. The graph says which is which, so you know whether one upload really covers two frameworks.
  • See what a change touches. Select a piece of evidence and the graph shows every control that depends on it, across every framework.
  • Give the assistant something solid to stand on. Ask it "which SOC 2 controls lack evidence" and it answers from this graph, with citations you can open.

How this connects

The Knowledge Graph consumes what the rest of SolveGRC produces and adds no data of its own. It reads:

  • Frameworks and controls, including your assessments. See Frameworks.
  • Crosswalk mappings, reviewed and proposed. See Crosswalks.
  • Evidence linked to controls, with its freshness state. See Evidence.
  • Cloud posture findings, projected onto attack techniques. See Cloud Posture.

Two things read from it:

  • The AI assistant, through its knowledge graph search and navigation tools. See Ask the assistant.
  • Questionnaire drafting. Each AI-drafted answer pulls the most relevant graph concepts alongside your documents, so a draft can cite the control and evidence behind a claim as well as the policy paragraph. See How AI answers are grounded.
This runs on a schedule

The graph is rebuilt overnight, at 06:00 UTC. The page header shows the exact "data as of" time the build was verified against your records. A change you make today is in tomorrow's graph, and nothing you do on the page edits the underlying data: to fix a gap you go to Frameworks or Evidence, and the graph reflects it after the next build.

Pages in this guide

  • Read the graph: nodes, edges, colors, filters, and how to turn a gap into work.
  • Ask the assistant: asking questions the graph can answer, and reading the trace behind each reply.
  • Access, freshness, and scope: who can see the graph, when it refreshes, what it leaves out, and what each holding state means.