Read the graph
The graph is dense on purpose: a mid-sized program has thousands of nodes. It stays readable because every node type has one shape and color, every color means one thing, and the detail panel tells you in words what a line asserts. This page covers each of those in turn, then shows how to use the filters to turn the map into a worklist.
Every dot is a concept, every line is a claim
| Node | Looks like | What it is |
|---|---|---|
| Framework | Purple filled circle | A framework you have activated, such as SOC 2 or ISO 27001. |
| Control | Blue filled circle | A control under a framework. Turns green when proven (see below). |
| Evidence | Small blue dot | A registered piece of evidence linked to at least one control. |
| Crosswalk hub | Hollow circle | One requirement that several frameworks share. Controls from each framework link to it. |
| Your own control | Larger hollow circle, blue outline | A control your organization defined rather than imported from a framework. |
| Attack technique | Linked from your cloud findings | A technique inferred from your cloud posture findings. |
A line between two nodes always reads as a sentence: evidence proves a control, a control belongs to a framework, a hub maps two requirements onto each other. Nothing on the map is decorative.
Click any node and the detail panel opens. Its Relationships rows list what this concept points at, and its Referenced by rows list what points at it. Both are buttons, so you can walk the graph from a framework down to a control, across a hub to the same requirement in another framework, and down to the evidence, without going back to the canvas. The legend in the bottom-left corner is always on screen if you forget which shape is which.
Green is earned, not claimed
The one rule worth memorizing: a control only turns green when someone assessed it compliant and at least one piece of current evidence backs it. Both halves are required.
- A control marked compliant with nothing attached stays blue. That is an assertion, and the panel says so.
- A control whose only evidence has gone stale also stays blue. The panel reads "attached is not proven", and the evidence dot carries a dashed amber ring so you can see the lapsed item from the canvas.
- Evidence freshness is the same freshness the Evidence Locker tracks; see How evidence quality and freshness work. The graph has no opinion of its own about staleness. It shows the platform's.
The Proof filter has two chips, "proven" and "unproven". Toggle one and the graph shows only that half, which is the fastest way to see how much of a framework is actually backed.
Check whether a crosswalk was reviewed
A crosswalk hub claims that two frameworks want the same thing. That claim is what lets one upload satisfy several requirements, so it matters who made it.
Open a hub. If the panel reads "Proposed as one requirement across … not yet reviewed", the links under it are AI suggestions nobody has confirmed. The panel tells you to approve them in Frameworks before reusing evidence across them, and until then the graph draws them as proposals. A reviewed hub says so, and only a reviewed hub should change how you plan evidence. Crosswalks covers the review itself.
Find things
The search box at the top of the page finds controls by name or identifier. Press Enter to jump to the first match and keep pressing it to cycle through the rest. When an active filter hides some of the matches, the search box says how many are out of view instead of pretending they do not exist, so a zero never means "no such control" while a filter is on.
The dropdowns beside the search box narrow the canvas, for example to a single framework. Narrowed dropdowns and pressed chips change color, so you can tell at a glance that a filter is shaping what you see.
Know what you are looking at, and when
The header carries two facts that matter for any conclusion you draw from the map.
- "data as of" is the moment the build was verified against your records. The graph is rebuilt overnight, so a change you made this morning appears tomorrow.
- Scope is your whole organization. Records scoped to a single business unit are deliberately left out, so the graph is the org-wide view and nothing narrower.
Turn a gap into work
- Toggle the Proof filter to "unproven".
- Narrow to one framework. What is left is that framework's real gap list: controls assessed compliant with no current evidence, plus controls whose evidence lapsed.
- Open a control in the panel and note which hubs it hangs off. Where a hub is reviewed, a single new piece of evidence will move every requirement attached to it.
- Go to that control in Frameworks and attach or refresh the evidence. It turns green on the map after the next overnight build.
The graph does not let you edit anything, and that is deliberate. You use it to decide what to do, then do it in Frameworks and Evidence.