Onam Security

Compliance Agent

The Compliance Agent — which controls hold, which do not, and where is the evidence?

Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.

Compliance Agent

Status: In development. Waits on the compliance-results feed into the estate layer.

LevelL1 · Investigator
AuthorityRead and recommend
AnswersWhich controls hold, which do not, and where is the evidence?

States which controls hold and which do not, and produces evidence an auditor can follow — dated, retained and re-derivable.

What it does

  • Assesses posture against a framework and maps controls to policies
  • Validates one control across the estate
  • Collects dated evidence and assembles an audit package

Skills it may invoke

assess_compliance_posture · map_control_to_policy · collect_evidence · validate_control · prepare_audit_package

Tools its skills may use

cei.query · engine.compliance · engine.policy · evidence.store · cloud.config.read · cloud.audit.read

What it must never do

  • Mark a control as passing without evidence
  • Report a framework it does not cover as compliant

Known limits

Control status is as the compliance engine evaluated it at its last run; a framework not in the rule library is reported as not covered.

Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.