Over the last few articles we took apart, one by one, the points where awareness compliance breaks down without anyone noticing. We saw how coverage expires in silence while the spreadsheet still shows green. We saw how a percentage can read 100% while you trained only a fraction of the real population. And we saw the four questions an auditor asks you that a spreadsheet can’t answer.
The diagnosis always pointed to the same place. However much effort you put in, a spreadsheet is a snapshot taken once a year, and compliance is a state that changes every day. That’s why we want to show you where we’re taking that state, to a place that keeps an eye on itself: the Compliance Center.
What is the Compliance Center?
The Compliance Center from SMARTFENSE is a dashboard that shows, in real time, how much of your awareness program meets standards like ISO 27001, NIST, PCI-DSS and GDPR, paired with an artificial intelligence agent that spots what’s missing and gradually closes it with a Compliance Plan. It stops being a document you put together for the audit and becomes a screen that reflects your situation at any point in the year.
We’re refining it together with the first teams using it, so what we describe here marks the direction of the tool more than a finished version. If you work with compliance and want to see it against your own data, further down we tell you how to join that group.
What do you see when you open the dashboard?
When you open it, you don’t see one aggregate total, you see the very questions an audit asks, already answered. Each standard appears with its own coverage, because the population isn’t singular. The people who must complete technical training aren’t the same ones who must read and accept an internal policy. The dashboard keeps those populations apart and calculates each one against the organization as it is today, not against a list typed in by hand back in January.
An example makes it concrete. A single company can have two hundred systems and security staff as the population for a technical standard, and the entire organization as the population for a policy everyone must accept. They’re two different denominators living side by side, and the dashboard holds them separately instead of blending them into a single percentage. Each one recalculates on its own whenever someone joins, leaves or changes role.
From there it drills into the detail a percentage hides. You can see, per person, what they completed, since what date they’ve been covered, and whether that training is still valid. If someone joined in September, they show up as pending the moment they arrive. If a training expired, it counts as a gap again instead of staying marked as done forever. Each user’s evidence is already recorded alongside the program, ready to export whenever someone asks for it.
In a single view you have what used to require cross-referencing spreadsheets, emails and shared folders: the real population, the timeline per person, validity and proof of record.
How does the agent close the gaps?
Seeing the problem clearly is already a leap, but it would still leave you with the work of solving it. That’s where the agent comes in, and the division of labor is simple: you supervise; it executes.
To put it to work you define three things. The population that must meet each standard, the monthly budget of training you’re willing to dedicate to your people (how much time you can ask of them without overloading them) and the start date. With that, the agent builds a Compliance Plan and acts every day under clear rules: it assigns one thing at a time so no one gets fatigued, it respects the budget you set, and it always prioritizes the organization’s largest gap, not the easiest one to close.
You never stop being in charge. You set the course, the pace and the limit, and you review progress whenever you want. What you stop doing is the mechanical part, deciding by hand, week after week, who needs what and in what order. That repetitive load is what the agent takes on.
How is it different from the spreadsheet?
The real difference isn’t a prettier screen, it’s where the data comes from. A spreadsheet knows its own list; the Compliance Center reads your organization. The population is derived from the directory you already use, so new hires and role changes show up without anyone entering them. Each training carries its start date and its expiry, so validity reopens on its own when it lapses. And evidence is stored per person from day one, not assembled the night before the audit.
It’s the same idea we’ve been holding to with human risk measured across the whole organization rather than on a hand-picked sample, applied now to compliance. It also connects with the management of standards, policies and procedures that already lives inside the platform. The same place where you publish and govern your policies is what feeds the compliance dashboard.
Compliance that holds up on its own
What we’re after with the Compliance Center is for awareness compliance to stop depending on someone remembering to update a spreadsheet. For it to be a living state, one you look at when you need to and that moves forward even when no one is pushing it that week.
We’re bringing on the first teams who want to use it and share their perspective while we finish refining it. If you want to see your compliance answering these questions about your real population, you can explore the platform or write to us for a demo and join the Compliance Center early adopter group.
Leave a Reply