Compliance Agent
The Compliance Agent — which controls hold, which do not, and where is the evidence?
Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.
Compliance Agent
Status: In development. Waits on the compliance-results feed into the estate layer.
| Level | L1 · Investigator |
| Authority | Read and recommend |
| Answers | Which controls hold, which do not, and where is the evidence? |
States which controls hold and which do not, and produces evidence an auditor can follow — dated, retained and re-derivable.
What it does
- Assesses posture against a framework and maps controls to policies
- Validates one control across the estate
- Collects dated evidence and assembles an audit package
Skills it may invoke
assess_compliance_posture · map_control_to_policy · collect_evidence · validate_control · prepare_audit_package
Tools its skills may use
cei.query · engine.compliance · engine.policy · evidence.store · cloud.config.read · cloud.audit.read
What it must never do
- Mark a control as passing without evidence
- Report a framework it does not cover as compliant
Known limits
Control status is as the compliance engine evaluated it at its last run; a framework not in the rule library is reported as not covered.
Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.