Skip to main content

Network Diagrams

Every organization has an architecture diagram somewhere: a Visio file, a PDF in a shared drive, a screenshot in a wiki. Auditors ask for it and get a picture. Network Diagrams turns that picture into structured evidence: SolveGRC reads the file into a topology of nodes, connections and zones, proposes the controls each element supports, matches elements to the cloud assets it has discovered, analyzes attack paths, and, once you approve it, registers the diagram as evidence with an integrity hash that proves what was approved has not changed.

Where to find it

Network Diagrams in the sidebar lists your diagrams with their status, element counts and parsing confidence, and is where you upload files or generate diagrams from a cloud account. A diagram that lives inside a document in Documents is also reachable from that document's Topology tab.

The lifecycle

  1. Upload a VSDX, PDF, PNG or JPG, generate from a connected cloud account, or start from a template. See Upload and parse.
  2. Parsing extracts the topology. Visio files are read directly; PDFs and images go through OCR and vision, and anything the AI produced is flagged for review with a confidence score.
  3. Review and edit the result: correct types, add what was missed, set zones, mark criticality and vendors. Every save is a version. See Review and edit.
  4. Controls and evidence: confirm the suggested control mappings, add your own, corroborate elements against cloud inventory, and approve, which registers the diagram as evidence. See Controls and evidence.
  5. Analyze and share: coverage heatmap, attack paths, exports and a redacted copy for outsiders. See Analysis and sharing.

How this connects

  • Frameworks and controls: control suggestions are drawn from the real controls of the frameworks you have activated, and confirmed mappings become evidence links on those controls. See Frameworks.
  • Evidence: an approved diagram is an evidence item in the Evidence Locker, carrying its hash and its counts. See Evidence.
  • Cloud Posture: diagrams can be generated from a connected account, and uploaded diagrams are corroborated against discovered assets. See Cloud Posture.
  • Continuity: connections between corroborated elements are projected into the dependency graph that business impact analysis reads.
  • The AI assistant: parsed diagrams are chunked and embedded, so you can ask about your infrastructure and get answers that cite the diagram.
What this guide leaves out

The weightings behind the coverage score, the attack path score and the parser's confidence are described by their inputs here, not their arithmetic, in step with the rest of the documentation. Each score shows its own breakdown in the product.

Pages in this guide

  • Upload and parse: files, cloud generation, statuses, re-parsing, chunks and deletion.
  • Review and edit: views, element fields, canvas tools, versions, comments, presence, templates and search.
  • Controls and evidence: suggestions, manual mapping, asset corroboration, approval and evidence links.
  • Analysis and sharing: coverage heatmap, attack paths, exports and redaction.