Egnyte Compliance Center streamlines compliance operations by automating the collection of evidence artifacts for supported controls across multiple regulatory frameworks. Through a comprehensive mapping of Egnyte’s Gov platform capabilities including configurations, settings, reports, and other platform data to specific regulatory controls, Compliance Center enables frequent, consistent, and automated evidence collection for each supported control.
This automation reduces manual effort, improves audit readiness, and ensures that compliance data remains current and reliable.
For any given regulatory framework, Egnyte automates the collection of evidence artifacts only for controls that both:
- Fall within Egnyte’s operational scope
- Operational scope includes Controls that can be mapped to Egnyte's platform and application capabilities such as settings, configurations, reports, etc. Operational scope excludes Controls as defined in Exclusions.
- Support automation through available platform data and configurations
This targeted approach ensures that Egnyte’s Compliance Center delivers meaningful automation where it provides the greatest value, while maintaining transparency about its coverage and limitations.
- Compliance Center is available to the customers on Financial Services Elite and Ultimate plans.
- AI capabilities, such as Compliance Agent, AI Assessment, and Assessment Reports are available to the domains with AI Add-on enabled.
- Compliance Agent is only available to the admin users.
Accessing Compliance Center
Compliance Center is available as a separate menu item in Egnyte.
The Compliance Center home page appears when the user clicks on the menu item.
Regulatory Frameworks
Compliance Center currently supports the following regulatory frameworks:
- FINRA Rule 4511 (b) and (c)
- SEC Rules 17a-4(f)
Overview, Control Management, Files, and Settings are the options available for all the regulatory frameworks.
Overview
- Click on any of the regulatory frameworks available
- The Overview displays the Status, Evidence collection frequency, Evidence collection ends date, and Description. Users can choose to collapse and expand the side panel as needed. The Overview page also has the Settings option.
Settings
For each available regulatory framework, before automated collection of evidence artifacts for supported controls can begin, it is required to configure the evidence collection frequency for the regulatory framework.
- Click on Settings in the Overview page
- Configure the Settings
- Certification name: Name of the certification
- Certification description: Detailed description of the certification
-
Evidence collection frequency: Select the frequency as Every week (default) or Custom. If the user selects Every week, the collection will happen every Monday.
If the user selects Custom, they need to provide the custom frequency in days. The custom frequency can be between 1 to 7 days.
- Evidence collection ends: Select the end date for evidence collection.
-
Notifications: Enable or disable the notifications for evidence collection and/or compliance assessment report completion
Based on these settings, users will receive the notifications accessible from the bell icon at the top-right. -
Folder Permissions: Admins can click on Add users or groups and manage folder permissions.
-
Click on Save.
Control Management
Control Management dashboard displays the Control Name, AI Assessment, Total Evidence, Automatically Collected, Manually Collected, Evidence Source Pages, and Evidence Folder. Users can sort the display by any of the columns. They can also search for specific information using the column-level search filters for Control Name or apply filters for the rest of the columns.
- Users can choose to expand or collapse a specific control category and view the details. They can also expand the Control Name at the top, and all the categories will expand or collapse. Control number and Control text as provided by the source regulatory framework are available for each category.
-
AI Assessment displays the assessment status as Likely Met, Partially met, Needs Review, Assessing, or Couldn’t assess
- Likely Met: Represents a condition when the AI Assessment engine was able to evaluate (or assess) a control as mostly meeting its objectives based upon the control's evidence artifacts. However, a final determination rests with the organization.
- Partially Met: Represents a condition when the AI Assessment engine was able to evaluate (or assess) a control as partially meeting its objectives based upon the control's evidence artifacts but determines that additional evidence artifacts or human review may be required.
- Needs review: Represents a condition when the AI Assessment engine was unable to evaluate (or assess) a control due to insufficient information in the control's evidence artifacts. For example: Controls that are manual by nature, some but not all evidence artifacts are available for a control, etc.
- Assessing: Represents a condition when the AI Assessment engine is currently evaluating (or assessing) a control after an evidence collection cycle.
-
Couldn't assess: Represents a condition when the AI Assessment engine could not evaluate (or assess) a control due to an internal system failure.
- Automatically or manually collected evidence counts are displayed in the respective columns.
- Automatic: Controls that fall within Egnyte’s operational scope and support automation (for collecting evidence artifacts) through available platform data and configurations
- Manual: Controls that are not Automatic; Compliance Center provides pre-created folders into which evidence artifacts can be uploaded. Manually uploaded evidence is automatically copied from the previous evidence gathering cycle to the new cycle.
-
Evidence Source Pages link to Egnyte platform data and configuration pages from which evidence artifacts for the control were automatically collected. Users can click on one of the pages, and they will be navigated to the respective page.
- Evidence Folder displays the path to the folder (in Collaborate) where evidence artifacts for the control are stored. Clicking on an Evidence Folder navigates to the corresponding Files view
- No. of Artifacts is the count of evidence artifacts collected at a control-level
AI Assessment
Compliance Center provides its users with the ability to view the AI-powered assessment status and the details for each control. Users can view the details, such as assessment result, evidence analyzed, findings, conclusion, and possible remediation actions for each control based on the AI Assessment outcome.
- Click a specific row to view AI Assessment details.
At the control level, the details are initially compressed for each of the categories. Users can click on the individual dropdowns to view the AI assessment details. - Users can click on the Explore option at the top to begin interacting with the Compliance Agent.
AI Assessment is automatically executed with each evidence cycle.
Domain Configuration
In the AI Assistant, the possible remediation actions are displayed based on the identified configuration gaps. Admins can choose to apply the necessary domain setting changes using the Compliance Agent.
For instance, in the action suggested below, admins can click on Update Trash and Version Policy and they will be re-directed to the Compliance Agent to continue their interaction, provide the necessary details, and update the domain configuration. Similarly, if they click on Open Configuration Agent, they will be redirected to the Configuration Agent.
Search, Sort, and Filter Options
Users can search by Control Name by entering the search keyword in the column-level search. The results matching the control name and/or description will be displayed.
By default, the details are sorted alphabetically based on the Control Name. Users can sort the results using any of the desired columns. They can also use and apply the column-level filters and view the filtered details. Records can be filtered by AI Assessment status as Any (default), Likely Met, Partially Met, Needs review, Assessing, Couldn’t assess.
Users can filter controls based on Total Evidence, Automatically Collected, Manually Collected evidence, and Evidence Source Pages with any (default), Has artifacts, or No artifacts options.
Additionally, they can view controls by Any (default), Available, or Missing evidence folder.
Click on Hide Filters and the filters will be hidden from the Control Management view. Click on Filters to view the filters again.
Download and Export Options
Click on Download All to download the zipped folder of all evidence artifacts collected for all controls. Users can also download these evidence artifacts at the individual category or record-level using the respective download icons.
Export option provides the option to export list and Assessment Report. Users can click on Controls to export the dashboard view in the CSV format.
If the user clicks on Assessment Report, the report will be generated.
Once generated, the assessment report will be available in the Files -> Reports folder for the specific date. If the user created multiple reports on the same date, all the versions will be available for the specific date.
While a report is being generated, the Assessment Report will be disabled.
Files
Depending upon the evidence collection frequency, the Compliance Center creates a new folder for each evidence-gathering cycle. These folders can be viewed in the Files option. For example, if the evidence collection frequency is set to 1 day then a new folder is created every day when the evidence gathering cycle starts. Each evidence folder is structured in this format:
- Folder for Date of Evidence Gathering
- Folder per Control Category
- Folder per Control belonging to the Control Category
- Folder per Control belonging to the Control Category
- Folder per Control Category
Compliance Center evidence folders are also available in Collaborate -> Files -> Shared -> Compliance Center.
Home Page
Users can click on the Home option from any of the pages in the Compliance Center.
They will be redirected to the Home page. The users can then browse through any of the regulatory frameworks.
Role-Based Access
Admins can enable role-based access for Compliance Center.
- Navigate to Collaborate -> Settings -> Configuration -> Users Types & Roles -> Roles and click on a specific role
- In the pop-up window switch the toggle to enable can access Compliance Center and click on Save. Users mapped with the role will be able to view and manage control artifacts and assessments.
Compliance Agent
Egnyte’s Compliance Agent analyzes the control evidence and maps it to applicable Cybersecurity regulations. Users can ask the Compliance Agent questions to verify evidence for specific controls, assess evidence completeness, and accelerate audit readiness.
- Click on the AI Assistant icon in the side-bar
- Compliance Agent will open and the users can interact with the agent by typing their query or using audio input. The agent will process the query and provide the response
- For the responses generated, users can copy, share, save response, download, regenerate answer, and provide feedback as available for all the Egnyte agents
Compliance Agent offers users with the Egnyte agents’ capabilities, such as utilising prompts library to view and insert prompts, start a new chat, view and manage historical records, and share chat.
Users can click on the settings icon; however, they cannot modify the source(s) for the Compliance Agent.
It is recommended for the users to access Compliance Agent from within the Compliance Center and in the context of a specific regulation, to get the most accurate responses.
Compliance Reports
Admins can generate an audit report that captures configuration changes and events in the Compliance Center, so that they can demonstrate accountability, detect unauthorized changes, and provide evidence artifacts for regulatory assessments. They can click on the Reports option to access Compliance Center reports.
Exclusions
Regulatory frameworks cover a broad range of control categories, such as risk assessment, personnel training and awareness, physical security, and others. Controls within these categories are not eligible for automated evidence collection through Egnyte.