Skip to content
Blog & Education

Practitioner writing & workflows.

Short articles, longer annotated walkthroughs, and long-form guides on compliance, risk, vendor management, AI in GRC, and audit prep — written from real screens, not slideware.

Looking for a topic we haven’t covered yet?

Vendor Management

21
Walkthrough 9 min

Regulation S-P, per vendor — defined once, evidenced, and reportable

Define what you require of your vendors — an executed Regulation S-P addendum — scope it to the vendors designated critical, and let Talarity ask each of them, hold the evidence, and answer 'who still owes us what' without a spreadsheet.

#vendor#third-party-risk#regulatory
The Talarity team · August 18, 2026
Walkthrough 10 min

Vendor data mapping — know exactly what every vendor holds before you have to

A spreadsheet of 'who has our data' is stale the day you save it. Talarity turns data mapping into a live matrix — every org data type against every vendor, each cell showing whether they store, process, or transmit it, and a derived exposure score that updates as the vendor's risk changes.

#vendor#data-mapping#privacy
The Talarity team · July 21, 2026
Walkthrough 9 min

Vendor risk mapping — turn 'they have our data' into a defensible criticality call

Knowing a vendor holds your data is step one. Talarity turns that into a derived exposure score, a governance-grade criticality designation, and a business-continuity rating — so the vendors that can actually hurt you are marked, visualized, and watched, and you can prove why.

#vendor#risk-mapping#business-continuity
The Talarity team · July 21, 2026
Walkthrough 8 min

Reading the Vendor Dashboard — every metric, its source, and how to move it

A section-by-section guide to the third-party risk rollup: what each KPI, chart, and queue actually measures, which records feed it, and the workflow that changes the number.

#vendor#tprm#dashboards
The Talarity team · July 10, 2026
Walkthrough 6 min

Every SaaS subscription is a vendor — see them by vendor, tie each to its contract

Your software subscriptions live in one list and your vendor contracts live in another, so nobody can answer 'which contract governs Bloomberg, and what did they promise us?' Talarity reframes every software subscription by the vendor behind it — seats, spend, and next renewal rolled up — and links each one to the contract that governs it.

#vendor#subscriptions#contracts
The Talarity team · July 2, 2026
Walkthrough 6 min

Trust Center — turn your security program into a self-serve sales asset

Publish your certifications, security practices, and reports at a branded /trust URL. Prospects download public documents instantly and request gated ones (SOC 2, pen tests) behind an NDA; you approve with one click and they get a time-limited download link — no more emailing PDFs around.

#vendor#trust-center#sales-enablement
The Talarity team · July 1, 2026
Walkthrough 8 min

Hold your vendors to their SLAs — track the promise, catch the breach

Every vendor contract has an SLA — 99.9% uptime, a four-hour response — and almost nobody tracks whether the vendor actually hits it. Talarity turns each SLA into a measured metric: define the targets, record performance, and the moment a vendor slips below contract you get a breach alert and a remediation work item, with an org-wide compliance scoreboard for the board.

#vendor#sla#monitoring
The Talarity team · June 23, 2026
Walkthrough 7 min

Can your vendors actually recover? Track vendor DR coverage

Your disaster-recovery plan is only as strong as the vendors it depends on. You assess vendors for security every year — but have you ever verified that Cirrus Cloud, Keyhold Identity, or your payment processor can recover from a disaster on a timeline your business can survive? The Vendor DR Coverage page makes that gap visible and trackable. Mapped to ISO 22301 and DORA.

#vendor#disaster-recovery#third-party-risk
The Talarity team · June 22, 2026
Walkthrough 10 min

Vendor concentration risk — the danger isn't any one vendor, it's the shape of the portfolio

You can vet every vendor perfectly and still be one outage away from a very bad day — because half your portfolio runs on the same cloud, or three 'independent' vendors all sit on one sub-processor, or a single sole supplier has no alternative. Talarity scores concentration across seven dimensions and surfaces the cascade before it happens.

#vendor#concentration#risk
The Talarity team · May 31, 2026
Walkthrough 10 min

Offboarding a vendor — the wind-down is a control, not a status change

Deleting a vendor record is the easy part. Proving you got your data back, revoked every credential, and have the destruction certificate to show for it — that's the part auditors ask about. Talarity makes vendor termination a gated, evidenced wind-down: in-flight work is cancelled, exit evidence is required before the lights go out, and the whole thing is on the record.

#vendor#offboarding
The Talarity team · May 31, 2026
Walkthrough 9 min

Residual risk, done right — what a vendor's risk actually is after your controls

A vendor's inherent risk is the headline; your residual risk is what you actually carry once your controls are accounted for. Talarity computes residual from the compensating controls you link — but only counts the ones that have passed an effectiveness test, so the number you hand an auditor is defensible, not wishful.

#vendor#residual-risk#controls
The Talarity team · May 31, 2026
Walkthrough 9 min

Vendor risk attestation — the one artifact an auditor actually asks for

You can tier a vendor, chase its SOC 2, score its risk, and remediate its findings — and still have nothing you can hand an auditor. The attestation is the defensible record: a signed, auditor-ready PDF that turns a finished assessment into a piece of evidence, with the risk determination, the findings, the required sign-offs, and the frameworks it satisfies, all in one place.

#vendor#attestation#reporting
The Talarity team · May 31, 2026
Walkthrough 11 min

Vendor contracts, obligations & renewals — the auto-renewal you forgot is a control gap

A vendor contract is a list of promises — SLAs, breach-notification windows, audit rights, exit terms — that nobody re-reads until something breaks or the contract auto-renews with stale security clauses. Talarity tracks the obligations, queues the renewals 90 days out, and makes the renew-or-walk decision a recorded one.

#vendor#contracts#renewals
The Talarity team · May 30, 2026
Walkthrough 10 min

Vendor findings, tracked to closure — with a second set of eyes built in

A failed pentest item, a missing SOC 2, an overdue questionnaire — vendor findings pile up faster than anyone closes them. Talarity tracks each one through a remediation lifecycle, won't let the person who fixed it sign off on their own work, and turns 'we'll deal with it' into a time-bounded, recorded risk acceptance.

#vendor#findings#remediation
The Talarity team · May 30, 2026
Walkthrough 9 min

Onboarding a vendor — from a name in an email to a tiered, approved, defensible record

A vendor isn't onboarded when you've typed its name into a list. It's onboarded when someone owns it, the risk it carries is profiled, an approver has signed off, and the platform has computed a defensible risk tier. Talarity makes that the path of least resistance.

#vendor#onboarding#tiering
The Talarity team · May 29, 2026
Walkthrough 8 min

One vendor program, three depths — set it up once, let it grow with you

Most TPRM tools force a choice: a spreadsheet that can't survive an audit, or an enterprise suite that buries a ten-person team. Talarity's program mode is a single dial — start Simple, grow to Complex, never migrate data or re-learn the tool.

#vendor#program-setup#tiering
The Talarity team · May 29, 2026
Walkthrough 9 min

Vendor monitoring — your assessment was true the day you ran it

A point-in-time vendor assessment starts going stale the moment you finish it. Talarity's monitoring dashboard turns the events that happen between assessments — breaches, leadership changes, incidents — into alerts you triage and reassessment flags you act on.

#vendor#monitoring
The Talarity team · May 29, 2026
Walkthrough 10 min

Vendor questionnaires — send a real SIG or CAIQ, score it the same way every time

Talarity ships an industry questionnaire library (CAIQ, SIG, VSA) you can clone, send to a vendor through a secure portal, and have scored automatically — so due diligence is repeatable evidence, not an email thread with a spreadsheet attached.

#vendor#questionnaires#portal
The Talarity team · May 29, 2026
Walkthrough 9 min

Vendor risk tiering — stop treating your stock-photo SaaS like your payments processor

A defensible vendor program doesn't review every vendor the same way. Talarity computes a repeatable risk tier from weighted factors, and a tiering policy makes each tier mean something concrete — review cadence, required evidence, monitoring, and SLAs — so effort follows risk.

#vendor#tiering
The Talarity team · May 29, 2026
Guide 16 min

Vendor risk operations playbook

An operational playbook for running a TPRM program — tiering, intake, due diligence, contract management, ongoing monitoring, and offboarding. With realistic SLAs and the gotchas nobody documents.

#vendor#tprm#monitoring
April 10, 2026
Article 8 min

The vendor questionnaire problem

You send a SIG. They send back a CAIQ. You wanted SOC 2. They want a phone call. Eight weeks later, the deal is stuck. Here's why third-party assessments are broken — and what actually fixes it.

#vendor#questionnaires#due-diligence
The Talarity team · March 12, 2026

Governance

30
Walkthrough 8 min

Which controls does this policy actually cover? Ask twice.

Import a policy and Talarity immediately narrows 369 controls to the handful it might cover, free and without AI. If you have the AI module, a second pass reads the document properly and grades what it finds, with quotations. Neither pass counts toward a single assessment until a human confirms it — and the database will not let it.

#governance#policies#controls#ai
The Talarity team · August 19, 2026
Walkthrough 24 min

The auditor portal — what a grant actually gives away

Inviting an external auditor creates a scoped, time-boxed, token-authenticated grant that consumes no seat. This is what that grant lets them do — which is more than 'read-only' — where its boundary really sits, and why the scope dialog governs only half of it.

#governance#internal-audit#audit#external-auditor#evidence
The Talarity team · August 15, 2026
Walkthrough 33 min

Workpapers and review notes — proving the test was actually done

A workpaper exists so that somebody who was not in the room can tell whether a control was really tested. This is how to run one end to end in Talarity — the procedures, the outcomes, the finding, and the second signature the product will not let you fake.

#governance#internal-audit#audit#workpapers#controls
The Talarity team · August 13, 2026
Walkthrough 20 min

PBC requests end to end — asking for evidence, and knowing what came back

Prepared-by-Client requests are where audits stall. This is the full round trip in Talarity — raising the request, fulfilling it from the evidence library, reviewing what actually arrived, and the places the product refuses to let a number mean more than it knows.

#governance#internal-audit#audit#evidence#pbc
The Talarity team · August 13, 2026
Walkthrough 13 min

Run an internal audit — and know the difference between clean and unread

Audit Management holds the plan, the request list, the findings and the reports for an internal audit. The counters above them only mean something if you know what each one is counting — and what it is not.

#governance#internal-audit#audit#pbc#findings
The Talarity team · August 12, 2026
Walkthrough 16 min

The number in the board pack, and whether anyone can defend it

Every GRC programme reports numbers. Far fewer can say where a number came from, when it was last computed, or who owns it. The Metric Catalog is the register that answers those questions — and its dashboard leads with the metrics that cannot.

#governance#grc#metrics#measurement
The Talarity team · August 4, 2026
Walkthrough 6 min

The strategic roadmap that survives contact with leadership — one portfolio, honest status, a timeline that tells the truth

See every governance and security initiative as a portfolio: summary cards that drill into the rows they count, a timeline ordered by real target dates, milestone counts rolled up from where the work happens, and filters that narrow both views the same way.

#governance#initiatives#roadmap#planning
The Talarity team · August 3, 2026
Walkthrough 11 min

The improvement backlog that survives contact with the quarter

Every assessment ends with a list of things to fix. Six weeks later nobody can say which started, who owns them, or what has slipped. Initiative Management turns an improvement into owned, dated work: milestones you tick, the risks it addresses attached, and an overdue count that tells the truth.

#governance#grc#initiatives#continual-improvement
The Talarity team · August 2, 2026
Walkthrough 7 min

Metric forecasting that refuses to guess — projections your auditors can interrogate

Generate statistical forecasts from your real metric history, see exactly how much history each method needs, compare methods head to head, and backtest every projection against what actually happened — with honest 'not enough data' answers instead of synthetic curves.

#governance#metrics#forecasting#analytics
The Talarity team · August 2, 2026
Walkthrough 9 min

Data quality: the score that tells you whether your GRC records are worth reporting on

Every GRC programme decays quietly. Owners leave, reviews lapse, evidence ages — and nothing errors. Talarity scores your own records across fifteen dimensions, turns each shortfall into a finding with a denominator, and tracks the line over time, so you find out in March rather than in the audit.

#governance#data-quality#grc-hygiene#metrics
The Talarity team · August 1, 2026
Walkthrough 7 min

The governance front door: one screen that tells you which programme needs you today

Four programmes — policies, third parties, the roadmap, audit workpapers — each with its own page, its own backlog and its own way of going quiet. Governance Management is the screen that shows all four at once, tells you which one is drifting, and puts you inside it in one click.

#governance#grc#programme-management#workflow
The Talarity team · August 1, 2026
Walkthrough 12 min

Conflicts of interest — from the disclosure someone files to the recusal that actually binds

A conflicts register that nobody reads before a decision is an archive, not a control. The point of the programme is the moment someone asks 'am I allowed to vote on this?' — and gets a straight answer.

#governance#compliance#ethics#conflicts-of-interest
The Talarity team · July 31, 2026
Walkthrough 6 min

Change Advisory Board — raise a production change, route it through CAB, and approve it on the record

Production changes are where good intentions meet outages. Talarity's Change Advisory Board gives you a change-request register with automatic risk scoring, a submit-to-CAB workflow, a multi-role approval quorum you record decision-by-decision, and a change calendar — the auditable CC8.1 / A.8.32 evidence a manual change process never leaves.

#governance#change-advisory-board#itil
The Talarity team · July 2, 2026
Walkthrough 6 min

ESG Program Management — track your metrics, disclosures, and initiatives against CSRD, SASB, GRI, TCFD, and CDP

ESG reporting has gone from a nice-to-have to a filing. Talarity's ESG module gives you a metric register with time-series values and targets, framework disclosures (CSRD / SASB / GRI / TCFD / CDP) you take from draft to published, an initiative tracker, and a program dashboard — so your sustainability statement is something you maintain, not something you assemble under deadline.

#governance#esg#csrd
The Talarity team · July 2, 2026
Walkthrough 6 min

AI Governance — a real inventory of your AI systems, mapped to the EU AI Act, NIST AI RMF, and ISO 42001

Your AI footprint grew faster than your governance. Talarity's AI Governance module gives you a live register of every AI system, framework assessments against the EU AI Act / NIST AI RMF / ISO 42001, and control mappings you can attest with evidence — with a dashboard that shows coverage at a glance.

#governance#ai-governance#eu-ai-act
The Talarity team · July 1, 2026
Walkthrough 6 min

Export and verify your audit trail for SOC 2

Pull your full audit trail as a SOC 2 evidence file in any format, then prove it wasn't altered with a one-click tamper-evidence check — backed by a per-row hash chain and a Merkle root your auditor can re-verify offline.

#governance#audit-trail#soc2#tamper-evidence
The Talarity team · June 30, 2026
Walkthrough 6 min

Catch toxic access combinations with Segregation of Duties

Define the pairs of duties no single person should hold — approve and disburse, accept a risk and own its control — and Talarity flags every user who holds both, with ten framework-mapped starter rules out of the box.

#governance#segregation-of-duties#sox#access-control
The Talarity team · June 30, 2026
Walkthrough 6 min

The Governance Hub — your whole governance posture on one screen

RACI ownership, framework alignment, policy attestations, control exceptions, approvals, and workflows aggregated into a single posture view — then generated as a signed, board-and-auditor-ready governance package.

#governance#board-reporting#audit-prep
The Talarity team · June 27, 2026
Walkthrough 6 min

Operational procedures — turn your SOPs from documents into executed, evidenced runs

A procedure is only as good as the last time someone actually followed it. Author SOPs from a template library, then execute them step-by-step — keep, skip, or fail each step with a reason — and finish with a recorded run your auditor can trust.

#governance#procedures#audit-prep
The Talarity team · June 27, 2026
Walkthrough 7 min

Policy templates — a framework-mapped starting library, not a blank page

Writing policies from scratch is slow and inconsistent. Talarity ships 50 pre-built, framework-mapped policy templates across nine categories — preview the real content, fill in your organization's specifics once, and bulk-create your whole starter set as tailored drafts.

#governance#policies#audit-prep
The Talarity team · June 27, 2026
Walkthrough 6 min

The RACI matrix — end the 'I thought you owned that' problem

Assign Responsible, Accountable, Consulted, and Informed across every control, policy, risk, and vendor — then let the Coverage Report show you exactly which ones still have no owner.

#governance#raci#ownership
The Talarity team · June 27, 2026
Walkthrough 8 min

From quarter-end to a board-ready disclosure pack

Board season shouldn't mean rebuilding the deck from scratch. Talarity assembles the quarter's capstones — risk, compliance, resilience, vendor — into one board report, drafts the executive narrative, and generates a signed disclosure pack carrying the SEC, SOC 2, ISO, and NIST citations a board's oversight duty requires.

#governance#board-reporting#disclosure#capstone
The Talarity team · June 23, 2026
Walkthrough 6 min

Policy sign-off — who signed, who's missing, and how to close the gap

Send a policy to a group and an individual, then track acknowledgement against your real employee roster: who signed the current version, who's still pending, and who was never sent it — with one click to chase the gap.

#governance#policies#attestation
The Talarity team · June 5, 2026
Walkthrough 7 min

Supporting a policy with procedures — linking, unlinking, and keeping the metadata honest

A policy says what your organisation does and why; a procedure says how. Auditors expect both, and they expect the link between them to be explicit. This article works from the policy side: how to attach procedures from a policy's Procedures tab, what unlinking actually does (and doesn't), and how to keep the policy's own metadata current — owner, approver, category, cadence. The procedure's own fields get their own article.

#governance#policies#procedures
The Talarity team · May 28, 2026
Walkthrough 6 min

Edit it, version it, or write a new one — three things customers conflate

There are three different ways to change a policy in Talarity — fix a draft in place, ship a new version of one that's already live, or start a brand-new policy. The right path depends on whether you've published yet, whether the doc lives in Talarity or as a file, and whether the change needs re-approval. Here's the map.

#governance#policies#versioning
The Talarity team · May 23, 2026
Walkthrough 5 min

Sending a policy for acknowledgement — pick the people, pick the message, send

Type the email if you must, but pick from org members if you'd rather. Choose a template instead of writing the message from scratch. External addresses get a token portal — perfect for new hires who haven't started yet. The Send-for-Acknowledgement modal does three things customers ask for, all in one place.

#governance#policies#attestation
The Talarity team · May 23, 2026
Walkthrough 8 min

Who acknowledged the policy — and who hasn't

Send a policy for acknowledgement to your whole workforce. Talarity shows you per-recipient status in real time, fires reminder tiers automatically, and writes an immutable signed proof for every (employee × version) — ready for the auditor before they ask.

#governance#policies#attestation
The Talarity team · May 23, 2026
Walkthrough 6 min

Policy categories — assign once, filter every view

Give every policy a category, then slice the whole set by domain in one click. One canonical taxonomy — eight policy types plus your own — used across the Policies list, the detail page, and the Artifact Repository.

#governance#policies
The Talarity team · May 22, 2026
Walkthrough 7 min

Stop chasing policies — Talarity tracks every one in two places at once

Upload a policy PDF once. Talarity stores it in the Artifact Repository, registers it in the Policies tab, sets the owner who'll be on the hook for review, and fires reminders 60 / 30 / 14 days before expiry — to the right people, automatically.

#governance#policies#reminders
The Talarity team · May 5, 2026
Walkthrough 6 min

Policy attestation, automated — every employee, every year

Publish the policy once. Send for acknowledgement once. Talarity captures who read it, who didn't, and re-fires every year on cadence — with a per-version proof report saved as an audit-grade artifact.

#governance#policies#attestation
The Talarity team · May 4, 2026

Compliance

62
Walkthrough 14 min

The evidence nobody can delete

A legal hold is a promise that a specific piece of evidence will still exist months from now, made to people who will check. This is where you place one in Talarity, what the record has to survive, and — just as important — what a hold does not freeze.

#compliance#evidence#audit#governance
The Talarity team · August 26, 2026
Walkthrough 21 min

Who touched the evidence

An auditor rarely doubts that your evidence is real. They doubt that it is the same file you collected. Chain of custody is the record that answers them — and the difference between a file Talarity has checked and one it has only been told about.

#compliance#audit#evidence#governance
The Talarity team · August 24, 2026
Walkthrough 11 min

The request that becomes tracked work

Someone asks for something in a message you will have lost by Thursday. Smart Request Intake turns that sentence into a classified, prioritised request — and then into a risk, an incident or a work item that somebody owns.

#compliance#governance#operations#workflow
The Talarity team · August 22, 2026
Walkthrough 9 min

Evidence gap detection: finding what is missing before an auditor does

Talarity runs a deterministic rule pass over your controls and the evidence attached to them, raises a typed finding for each gap, and routes you to the screen that fixes it. Here is what it checks, how it ranks findings, and why one is about your risk register rather than your evidence.

#compliance#evidence#controls#audit-readiness
The Talarity team · August 20, 2026
Walkthrough 10 min

Reviewing evidence before it counts

Evidence Review is where you read what the connectors collected and find out why a run failed. It is not an approval queue, whatever its name suggests — and knowing the difference is what stops an auditor's question becoming a scramble.

#compliance#evidence#automation#audit
The Talarity team · August 20, 2026
Walkthrough 12 min

Collecting evidence without asking anyone

Automated evidence collection connects Talarity to the systems that already hold your proof and pulls it on a schedule. What the engine does, how to set one up, and — the part most walkthroughs skip — where collected evidence actually lands, which is not always where you expect.

#compliance#evidence#automation#integrations
The Talarity team · August 20, 2026
Walkthrough 21 min

Smart Evidence Intake: classifying evidence before a human reads it

Drop a folder of documents into Talarity and each one is classified, mapped to candidate controls, and queued for a decision. Here is what the classifier does, what it deliberately refuses, and what approving a piece of evidence changes elsewhere in your programme.

#compliance#evidence#controls#audit-readiness
The Talarity team · August 20, 2026
Walkthrough 13 min

An exception is a promise to come back

Every control programme grants exceptions. The ones that hurt are not the exceptions themselves — they are the ones nobody ever revisited. Here is how Talarity records a bypass, who decides it, and what makes the promise to return enforceable.

#compliance#controls#governance#audit
The Talarity team · August 19, 2026
Walkthrough 16 min

Evidence has a shelf life

Evidence that satisfied an auditor last March may satisfy nobody this March. Here is how Talarity decides that a document has gone stale, what it does about it, and — just as important — which of its two freshness numbers answers which question.

#compliance#audit#evidence#governance
The Talarity team · August 19, 2026
Walkthrough 11 min

The number that says a control was tested

A control testing dashboard has to answer one question honestly: which controls have been tested, and can you show the work. Here is how to read Talarity's — what each figure counts, where it abstains, and where the page stops.

#compliance#audit#controls#governance
The Talarity team · August 19, 2026
Walkthrough 12 min

The library that quietly went out of date

Every testing programme writes its procedures once. Almost none of them decide who owns each procedure or when it gets read again — so the library keeps returning confident answers about controls that changed years ago. Here is how to write a test procedure that stays true.

#compliance#audit#controls#governance
The Talarity team · August 19, 2026
Walkthrough 21 min

The weakness you can only see across clients

A partner can tell you how any single engagement is going. What is hard to see is the pattern across them — and a scope area that falls short on most of your clients is a fact about the market you serve, not about any one of them. Here is the page that assembles it.

#compliance#audit#advisory#governance
The Talarity team · August 17, 2026
Walkthrough 13 min

An internal audit function is four documents and a calendar

The IIA asks an internal audit function to hold a charter, an annual plan, an audit universe and a quality-assurance programme. This is how Talarity keeps all four in one place, ties each approval to the committee that made it, and shows what is actually due.

#compliance#internal-audit#audit#governance
The Talarity team · August 17, 2026
Walkthrough 20 min

The client nobody is looking at

Every audit surface is scoped to one organisation at a time, so a firm holding twenty client relationships has no single place that shows all twenty. The Assurance Portfolio is that place — and the number it exists to surface is the one that produces no rows anywhere else.

#compliance#audit#advisory#governance
The Talarity team · August 17, 2026
Walkthrough 12 min

The walkthrough is evidence, but only if somebody wrote it down

Inquiry is the weakest form of audit evidence and the one auditors rely on most. This is how Talarity turns a conversation into an attributable record — who was in the room, what they said, what it changed — and hands it over as a file that explains itself.

#compliance#internal-audit#audit#controls#evidence
The Talarity team · August 16, 2026
Walkthrough 20 min

Sampling a control test you can defend a year later

A sample is only evidence if someone can re-run it. This is how Talarity sizes a sample against the AICPA table, draws it four different ways, records the seed that produced it, and hands the whole thing over as a file that explains itself.

#compliance#internal-audit#audit#controls#evidence
The Talarity team · August 16, 2026
Walkthrough 24 min

The snapshot an auditor can actually check

An audit engagement snapshot freezes six record sets into tables the database refuses to change, and stamps them with a fingerprint the product recomputes on demand. This is what it captures, what 'immutable' means when a trigger enforces it, and how to prove a year later that nothing moved.

#compliance#internal-audit#audit#evidence#controls
The Talarity team · August 15, 2026
Walkthrough 8 min

Send an assessment to 28 accounts and track it as one thing — Assessment Campaigns in Talarity

Adding someone to a campaign that's already open, extending a deadline without re-dating submitted work, reopening a closed cycle without retracting released results — the send-it-then-steer-it half of assessments, as one surface.

#compliance#assessments#campaigns#third-party-risk
The Talarity team · August 2, 2026
Walkthrough 16 min

The work already happened — the hard part is proving it

Your engineers patched the servers, revoked the accounts and closed the tickets. Ticketing (ITSM) turns that finished work into evidence a control operated, so proving it stops being a quarterly scramble.

#compliance#evidence#integrations#audit
The Talarity team · August 2, 2026
Walkthrough 7 min

Reviewing a DR exercise — what to check before you sign it off

Closing a DR exercise doesn't complete it. If you're named as a reviewer, the exercise waits for you. Here's what lands in your queue, what to read before you approve, and what your approval actually does.

#compliance#business-continuity#disaster-recovery#dr-exercise
The Talarity team · July 30, 2026
Walkthrough 7 min

You've been asked to test a system's recovery — here's what to do

A DR test asks you to prove one system comes back, and to record honestly how long it took. Here's what arrives, what each field on the form means, why recording a failure is more useful than leaving it blank, and how to find your own record afterwards.

#compliance#business-continuity#disaster-recovery#dr-exercise#attestation
The Talarity team · July 30, 2026
Walkthrough 9 min

Setting up a DR exercise — scope, testers, and the settings that decide what happens

A DR exercise stays completely silent until you launch it, which means you can build the whole thing now and start it on the date you actually want. Here's every setting, what each one changes, and the three decisions that are hard to undo afterwards.

#compliance#business-continuity#disaster-recovery#dr-exercise
The Talarity team · July 30, 2026
Walkthrough 12 min

Reading the Audit Dashboard — engagement health, findings, PBC, and readiness in one read

A section-by-section guide to the audit rollup: which findings count as open (and why external-auditor drafts don't), how PBC fulfillment is measured, what the Internal Audit Function panel proves, and why the page shows no freshness bar it can't honor.

#compliance#audit#dashboards
The Talarity team · July 20, 2026
Walkthrough 12 min

Reading the Privacy Dashboard — DSAR clocks, consent state, DPIAs, and breach readiness in one read

A section-by-section guide to the privacy rollup: what the DSAR on-time rate actually measures, why consent is shown as current state per subject rather than event volume, how RoPA completeness is scored against Article 30, and why 'not started' is an honest breach-readiness state.

#compliance#privacy#dashboards
The Talarity team · July 20, 2026
Walkthrough 8 min

Enterprise gap analysis — rank every company, then hand leadership a real report

Talarity's Gap Analysis ranks every linked account by assessment score, shows exactly who is overdue or unassigned — and one button turns the whole picture into a finalized, retention-locked PDF with rankings, score changes, common issues, and top priorities.

#compliance#gap-analysis#reporting#assessments
The Talarity team · July 17, 2026
Walkthrough 9 min

Save a security package once, send it on demand

A prospect's security team asks for your SOC 2, your pen test, and your current security policies — again. Package Templates save that set as a reusable definition of pinned items plus rules like 'every current SOC 2 report', resolve it fresh each time you send, and hand it over as a redacted, watermarked, time-limited copy with a record of who received what.

#compliance#audit#evidence#soc2
The Talarity team · July 17, 2026
Walkthrough 7 min

Cross-org assessments — assign, complete, and release without losing the thread

Assign an assessment to a linked organization, let them complete it, and get the results only when they release them — with Talarity nudging the recipient until they do.

#compliance#linked-accounts#assessments
The Talarity team · July 14, 2026
Walkthrough 9 min

Reading the Compliance Dashboard — every metric, its source, and how to move it

A section-by-section guide to the compliance rollup: framework posture, assessment runs, control testing, evidence health — which records feed each number and the workflow that changes it.

#compliance#dashboards#grc
The Talarity team · July 12, 2026
Walkthrough 9 min

Reading the Resilience Dashboard — every metric, its source, and how to move it

A section-by-section guide to the BC/DR rollup: what each coverage number, gap table, and trend actually measures, which records feed it, and the workflow that changes the number.

#compliance#bcdr#dashboards
The Talarity team · July 11, 2026
Walkthrough 6 min

Regulatory Change Management — an obligation register that keeps up when the rules change

Regulations don't hold still. Talarity's Regulatory Change Management gives you a living register of the obligations that apply to you, a log of every change against them, an impact-assessment workflow, and a horizon-scan watchlist for what's coming — so a new rule is a tracked item, not a fire drill.

#compliance#regulatory-change#obligations
The Talarity team · July 2, 2026
Walkthrough 6 min

System Configuration — turn a completed assessment into enforceable, drift-tracked baselines

Every safeguard you scored in an assessment becomes an enforceable expected value. Talarity re-checks the observed state, flags drift, opens remediation automatically, and lets you attach evidence per control — so your controls stay implemented, not just documented once.

#compliance#continuous-monitoring#cis-controls
The Talarity team · July 1, 2026
Walkthrough 6 min

Regulatory submissions — assemble the filing as a case file, not a last-minute scramble

A regulator filing isn't a deadline on a calendar — it's a defensible package: the right capstones, the supporting evidence, an authorized-officer attestation, and a record of exactly what you transmitted. Talarity runs each submission through a Draft → Finalized → Submitted → Acknowledged lifecycle and assembles a sealed dossier with a SHA-256 of what was filed.

#compliance#audit-prep#platform
The Talarity team · June 27, 2026
Walkthrough 9 min

One package, both domains: handing an auditor your assessments and your DR evidence together

Auditors don't want a folder of PDFs from one team and a separate folder from another. Talarity's evidence package bundles a finished compliance attestation and a disaster-recovery attestation into one immutable, watermarked, share-once package — assembled in a picker that browses every report by category, scales to thousands of artifacts, and saves the whole package as a reusable template that pulls the latest version next year.

#compliance#audit#evidence#bcdr
The Talarity team · June 26, 2026
Walkthrough 8 min

Framework crosswalk projection — answer once, see where you'd land on every other framework

You finished a CIS or NIST assessment. Now a customer wants SOC 2, a regulator wants FFIEC, the board wants NIST CSF. Talarity's crosswalk projection takes the answers you already gave and projects them onto any target framework — a likely score, requirement-by-requirement coverage, and exactly which items still need answering — so you start the next framework most of the way done instead of from a blank questionnaire.

#compliance#frameworks#assessments
The Talarity team · June 26, 2026
Walkthrough 8 min

Package your audit evidence once — for the auditor, regulator, or customer

An auditor asks for your evidence and it's scattered across framework reports, vendor attestations, policy sign-offs, and resilience tests. Evidence Distribution Packages assemble the signed artifacts you already produced into one immutable package, then hand it to each audience as a redacted, watermarked, time-limited copy — with a record of who received what.

#compliance#audit#evidence#soc2
The Talarity team · June 25, 2026
Walkthrough 8 min

Continuous compliance: prove your controls held every day, not just at audit

An audit is a photograph; your control environment is a film. Between assessments, controls drift — evidence goes stale, a maturity level slips, a config changes. Talarity establishes a baseline and watches it every day, so drift surfaces as an alert in March instead of a finding in November.

#compliance#continuous-monitoring#drift-detection#ccm
The Talarity team · June 24, 2026
Walkthrough 8 min

Your resilience program is audit evidence — mapped to ISO 22301 and SOC 2

Auditors don't ask 'do you have a DR plan?' — they ask 'show me the evidence for ISO 22301 clause 8.5 and SOC 2 A1.3.' Talarity turns your BIAs, recovery plans, and continuity tests into a DR Test Attestation that auto-cites the exact ISO 22301, SOC 2, ISO 27001, and NIST CSF clauses your resilience evidence satisfies.

#compliance#business-continuity#disaster-recovery#resilience
The Talarity team · June 23, 2026
Walkthrough 7 min

Framework readiness to audit package — the whole cycle on one screen

Audit prep usually means a spreadsheet scramble — chasing evidence, tracking which controls are covered, re-checking what's expired. Talarity keeps a live readiness picture for every framework (SOC 2, ISO 27001, CIS, and more) — coverage, gaps, evidence freshness — and packages it into an auditor-ready export in one click.

#compliance#framework#audit-readiness
The Talarity team · June 23, 2026
Walkthrough 7 min

One control library, every framework — adopt once, comply many

Most teams rebuild their controls for each framework — a SOC 2 set, an ISO set, a CIS set, all describing the same safeguards. Talarity's Common Control Library is one canonical set of 369 controls that maps to every framework at once: adopt a baseline, and your CIS work already counts toward NIST, PCI, SOC 2, and HIPAA.

#compliance#controls#control-library
The Talarity team · June 23, 2026
Walkthrough 7 min

Hand your auditor one BC/DR evidence package — not a folder of PDFs

When an auditor asks you to prove your business-continuity and disaster-recovery program, the evidence is scattered across reports, tests, and exercises. Evidence Distribution Packages assemble your signed BC/DR capstones into one immutable package and hand it to the auditor as a redacted, watermarked, time-limited link — no shared drives, no email attachments. Mapped to ISO 22301 and SOC 2.

#compliance#audit#disaster-recovery#business-continuity#evidence
The Talarity team · June 22, 2026
Walkthrough 7 min

How mature is your disaster recovery? Read your BC/DR readiness score

Coverage tells you what you've tested. The BC/DR readiness score tells you how good your recovery practice actually is — a 10-question maturity model across testing, RTO/RPO, backups, runbooks, and third-party DR, read as a waterfall, gauges, dimension rings, a risk heatmap, and a maturity roadmap. Mapped to ISO 22301 and NIST 800-34. (Extended Risk · early access / Beta.)

#compliance#disaster-recovery#business-continuity#maturity
The Talarity team · June 22, 2026
Walkthrough 6 min

Bulk Import — load a year of evidence in one pass

Audit prep means dropping dozens of artifacts at once — SOC 2s, pen tests, ISO certs, BAAs, policies, procedures. Bulk Import takes the whole folder: drag everything in, give each file its document type and the metadata that type requires, and commit them in one validated pass.

#compliance#artifacts#import
The Talarity team · June 22, 2026
Walkthrough 8 min

Run a DR program, not just DR tests — scope policy, coverage, and a signed report

BIAs, recovery plans, continuity tests, and DR exercises are the artifacts. A DR program is the governance that makes them add up: one scope policy that decides what must be tested and how often, a live coverage number, the gaps surfaced for you, and a signed program report. Here's how Talarity runs it, mapped to ISO 22301, NIST SP 800-34, and DORA.

#compliance#business-continuity#disaster-recovery#resilience
The Talarity team · June 22, 2026
Walkthrough 7 min

Assign DR testers — including the external vendors who respond without a login

A disaster-recovery test is only as good as the people who run it — and some of them don't work for you. Here's how Talarity assigns a tester to every critical asset (defaulting to its custodian), hands the test off to external vendors through a secure no-login portal, and folds their response straight back into your exercise. Mapped to ISO 22301 and NIST SP 800-34.

#compliance#business-continuity#disaster-recovery#vendor-management
The Talarity team · June 21, 2026
Walkthrough 7 min

Business impact analysis at scale — a living BIA portfolio, not a binder that rots

One BIA is an afternoon's work. A BIA program — keeping dozens current, knowing which critical processes still have no recovery plan, and what's due for review — is the real discipline. Here's how Talarity turns your business impact analyses into a portfolio you manage at a glance. Mapped to ISO 22301, NIST SP 800-34, and DORA.

#compliance#business-continuity#business-impact-analysis#resilience
The Talarity team · June 21, 2026
Walkthrough 8 min

Business continuity, end to end — from impact analysis to tested recovery

One surface runs your whole resilience program: rank what matters with a BIA, write recovery plans against it, test them, coordinate asset-level DR exercises, and watch coverage on a single dashboard — mapped to ISO 22301, SOC 2, and NIST 800-34.

#compliance#business-continuity#disaster-recovery#resilience
The Talarity team · June 20, 2026
Walkthrough 12 min

Run a DR exercise — test your whole critical-asset estate, and prove who tested what

A continuity test proves one plan. A DR exercise tests recovery across your whole critical estate at once, with a named tester on each — turning every failure into tracked remediation and every serious one into a scored risk. Mapped to ISO 22301, NIST SP 800-34 and SOC 2.

#compliance#business-continuity#disaster-recovery#dr-exercise
The Talarity team · June 20, 2026
Walkthrough 8 min

Run your first Business Impact Analysis — rank what matters before you plan recovery

A Business Impact Analysis is where a resilience program starts: it names your critical processes and sets the honest MTD, RTO, and RPO numbers every recovery plan and DR test inherits. Here's how to build one in Talarity in about ten minutes — mapped to ISO 22301, NIST SP 800-34, and SOC 2.

#compliance#business-continuity#bia#resilience
The Talarity team · June 20, 2026
Walkthrough 7 min

Test your recovery plan — schedule a continuity test and prove your RTO

A recovery plan you haven't tested is a hope. Schedule a continuity test in Talarity, record the outcome against the plan's target RTO/RPO, and let the result roll up to a recurring schedule — the evidence ISO 22301, NIST SP 800-34, and SOC 2 auditors ask for.

#compliance#business-continuity#disaster-recovery#continuity-testing
The Talarity team · June 20, 2026
Walkthrough 8 min

Write a recovery plan that survives an audit — scenario, steps, RACI, and a test

A recovery plan that's only RTO/RPO numbers fails an audit. Auditors want the ordered steps, who owns them, and proof you tested them. Here's how to build one in Talarity that holds up — mapped to ISO 22301, NIST SP 800-34, and SOC 2 A1.3.

#compliance#business-continuity#disaster-recovery#recovery-plan
The Talarity team · June 20, 2026
Walkthrough 7 min

The assessment that builds your GRC program for you

Most assessments end at a score. Talarity turns a completed assessment into the risks, remediation work items, and KRIs your gaps imply — you review them, apply with one click, and your register fills itself in.

#compliance#assessments#grc
The Talarity team · June 18, 2026
Walkthrough 7 min

From gap analysis to remediation you can actually track

A framework assessment tells you where you stand. Talarity's Gap Analysis turns that score into a prioritized, quantified plan — quick wins, critical fixes, and one-click remediation work items your team owns and tracks to closure.

#compliance#gap-analysis#remediation
The Talarity team · June 18, 2026
Walkthrough 7 min

From incident to root cause: closing the loop, not just the ticket

Most teams close an incident with a status change. Talarity's incident case file drives it to a real root-cause analysis — a 5-whys investigation, corrective and preventive actions you track to closure, and a post-mortem that becomes audit evidence.

#compliance#incident#root-cause
The Talarity team · June 18, 2026
Walkthrough 9 min

Every certificate, report, and proof in one place — the Artifact Repository

Upload a SOC 2, a pen test, a policy, an insurance cert once. Talarity types it, tracks its expiry, reminds the owner before it lapses, governs who can see it, and lets you reuse it across every framework — from one repository.

#compliance#artifacts#evidence
The Talarity team · June 16, 2026
Walkthrough 9 min

Data retention, on a schedule — set it once, prove it forever

Tell Talarity how long every class of data lives, and it does the rest: schedules deletions, holds them for a second approver, freezes anything under legal hold, and keeps audit logs for the seven years your framework demands. One page, six tabs, a full deletion trail for the auditor.

#compliance#data-retention#audit
The Talarity team · June 7, 2026
Walkthrough 8 min

One control, one level — how evidence unlocks a gated assessment

Every safeguard in a gated assessment shows a 0–5 maturity scale. You pick the single level that matches reality today, and Talarity unlocks the higher tiers only as you attach the evidence each one requires. Here's the model, end to end.

#compliance#assessments#evidence
The Talarity team · June 3, 2026
Walkthrough 7 min

Lock down a document to one team — Artifact Repository access rules

Some artifacts shouldn't be visible to every member of your org — a customer credit application, a quarterly revenue forecast, a board-only PDF. Talarity gates each artifact by group or by named individual, evaluates the rules in SQL, and hides what shouldn't be seen — automatically.

#compliance#artifacts#access-control
The Talarity team · May 22, 2026
Walkthrough 5 min

Take an assessment together — multi-user, in real time

Two people on the same assessment used to be a recipe for lost progress and duplicate runs. Talarity now treats it as a presence-aware collaboration, with peer answers visible in seconds, typing indicators, per-question attribution, and a hard seven-editor cap.

#compliance#assessments#collaboration
The Talarity team · May 19, 2026
Walkthrough 6 min

Annual Disaster Recovery testing — end-to-end in Talarity

Build the questionnaire once. Schedule it once. Every year, Talarity fans the test out to your internal owners and external partners, collects evidence, and produces a single auditor-ready attestation report — saved for seven years.

#compliance#disaster-recovery#attestation
The Talarity team · May 4, 2026
Guide 14 min

SOC 2 readiness checklist

A practitioner's guide to getting audit-ready — what to do in months 1, 2, and 3 to land a clean Type I report and set up cleanly for Type II.

#compliance#soc2#audit
April 15, 2026
Article 9 min

What the SEC cybersecurity disclosure rule actually requires

Two reporting obligations, one materiality call, and a four-business-day clock. Here's the operational reading of the SEC cyber rule — and the parts most companies are still getting wrong.

#compliance#sec-cyber#frameworks
The Talarity team · April 8, 2026
Article 7 min

Continuous compliance is a tooling problem, not a process problem

Every compliance program eventually decides it needs to be 'continuous.' Most then try to fix it with process. The actual fix is upstream — in the tools that make evidence freshness a default, not a sprint.

#compliance#audit#evidence
The Talarity team · March 25, 2026

Risk

18
Walkthrough 16 min

Periodic asset review, as an obligation — not a date on every record

Requirements aren't only about vendors. Declare a periodic review once, scope it to the assets that matter, and let Talarity track who owes it, hold the evidence, and answer 'which assets are overdue?' — the same engine, a different subject.

#risk#asset-management#governance
The Talarity team · August 21, 2026
Walkthrough 11 min

Reading the Incident Response Dashboard — every metric, its clock, and what moves it

A section-by-section guide to the incident rollup: what each response-time median actually measures, which lifecycle timestamps feed it, where the SEC disclosure clock comes from, and how root-cause discipline shows up as a number you can act on.

#risk#incidents#dashboards
The Talarity team · July 20, 2026
Walkthrough 12 min

Reading the Threat & Vulnerability Dashboard — what's open, what's exploited, and whether your SLAs hold

A section-by-section guide to the exposure rollup: how open findings age, which of them are known-exploited in the wild, where remediation SLAs are breaking, and why the dashboard refuses to show you a KEV zero or a freshness it cannot prove.

#risk#vulnerabilities#dashboards
The Talarity team · July 20, 2026
Walkthrough 7 min

Track an audit's remediation as one number — Work Item Groups in Talarity

Bundle the findings from an audit, a pen test, or a quarterly sprint into a named group, then watch one dashboard tell you what's done, what's overdue, and who's behind — scoped to that group with a single dropdown.

#risk#work-items#remediation
The Talarity team · July 17, 2026
Walkthrough 9 min

Reading the Risk Overview — every metric, its source, and how to move it

A section-by-section guide to the executive risk rollup: what each KPI, chart, and queue actually measures, which records feed it, and the workflow that changes the number.

#risk#dashboards#grc
The Talarity team · July 11, 2026
Walkthrough 6 min

Incident management — from detection to root cause, with the whole chain linked

An incident isn't closed when the fire's out — it's closed when you know why it happened and the fixes are tracked. Talarity runs incidents through a full lifecycle, captures MTTD/MTTR, and links each one to its root-cause analysis, remediation, tasks, risks, and evidence.

#risk#audit-prep#platform
The Talarity team · June 27, 2026
Walkthrough 6 min

Quantified risk (FAIR) — put a dollar figure on cyber risk, not a colored square

"High / Medium / Low" tells a board nothing about how much. Talarity models risk scenarios with the FAIR methodology and Monte Carlo simulation to produce dollar-value loss estimates — annualized loss expectancy, the probability of an incident this year, and exposure projected over time.

#risk#audit-prep#platform
The Talarity team · June 27, 2026
Walkthrough 6 min

Risk scenario analysis — model the ROI of a control before you buy it

What-if modeling for risk decisions: start from your real risk baseline, model a control improvement (or a worsening threat, an insurance transfer, an avoidance), and see the projected risk reduction, ALE change, 3-year ROI, and payback — before you commit a dollar.

#risk#scenarios#quantification
The Talarity team · June 27, 2026
Walkthrough 7 min

When a KRI breaches — from threshold alert to a tracked remediation

A key risk indicator is only worth measuring if a breach triggers action. Talarity watches each KRI against its thresholds, raises an alert the moment one goes red, and turns that alert into a remediation work item linked back to the indicator — so a breach becomes tracked work, not just a number on a dashboard that nobody owns.

#risk#kri#monitoring
The Talarity team · June 26, 2026
Walkthrough 8 min

Threat intelligence — correlate the feeds, surface the indicators, prioritize by exploit

Threat intelligence is only useful if it's connected to your environment. Talarity ingests the feeds you choose, correlates tactical indicators across all of them, and ranks vulnerabilities by what's actually being exploited — so 'there's a new threat' turns into 'here are the three CVEs already weaponized that you should patch first.'

#risk#threat-intelligence#vulnerabilities
The Talarity team · June 26, 2026
Walkthrough 8 min

From scanner finding to GRC — triage a vulnerability into controls, risk, and evidence

A scanner finding is noise until it's connected to the rest of your program — the control it threatens, the risk it represents, the evidence an auditor will ask for. Talarity's vulnerability management imports findings, triages them through a real state machine, and links each one to a control and a risk — turning a CVE into a tracked, accountable part of your GRC posture.

#risk#vulnerabilities#controls
The Talarity team · June 26, 2026
Walkthrough 9 min

"Done" is not "fixed": verifying remediation before you close it

Anyone can mark a remediation done. Talarity's verification workflow makes a second person confirm the fix actually worked — record a pass or fail with evidence, send failures back for re-test, then route a closure sign-off to an approver who isn't the one who did the work. Nothing closes on one person's say-so.

#risk#remediation#verification#audit
The Talarity team · June 25, 2026
Walkthrough 7 min

Define and measure a Key Risk Indicator — the metric that warns you early

A KRI is inert until you define one correctly and feed it real measurements. Here's how to set the thresholds, record the values, and read the signal in Talarity — so a number tells you a control is slipping before an incident does.

#risk#kri#monitoring#metrics
The Talarity team · June 24, 2026
Walkthrough 8 min

The remediation portfolio: every fix you've committed to, tracked to closure

A risk register tells an auditor what's wrong. The remediation portfolio proves what you did about it — owned, milestoned, evidenced plans that close with a sign-off. It's your Plan of Action & Milestones (POA&M), and Talarity runs it as live data instead of a spreadsheet.

#risk#remediation#poam
The Talarity team · June 23, 2026
Walkthrough 11 min

A risk, from the day you log it to the number your board asks for

Identify a risk, score it, treat it, and quantify it in dollars — Talarity runs the whole lifecycle on one record, so 'what's our exposure?' has a defensible answer instead of a guess.

#risk#lifecycle#quantification
The Talarity team · June 18, 2026
Walkthrough 7 min

Connect Microsoft Intune to Talarity — every laptop, every app, every person, in one inventory

Stand up the Intune connector once. Talarity pulls your managed devices, detected software, and directory users into a unified Asset Manager, stamps each row with owner, criticality and lifecycle state, and writes the whole graph to PostgreSQL so your controls, work items, and risks can finally join against real assets.

#risk#assets#intune
The Talarity team · May 13, 2026
Article 8 min

FAIR vs. stoplights: why your CFO doesn't trust your risk register

If your risk reports use red-yellow-green and your CFO still can't act on them, the problem isn't your CFO. Here's the case for quantified risk — in dollars, with confidence intervals.

#risk#fair#quantification
The Talarity team · April 22, 2026
Guide 12 min

FAIR for CISOs: a quick primer

How quantified risk works, why it produces better decisions than stoplight scoring, and how to operationalize it without retraining your whole team.

#risk#fair#quantification
April 1, 2026

Application Security

5
Walkthrough 12 min

Reading the AppSec Dashboard — findings, SLAs, repo posture, pipelines, supply chain, and API risk in one read

A section-by-section guide to the application-security rollup: what the SLA clock actually measures, why SDLC coverage shows a dash instead of a fake F when there are no repos, how the findings trend is derived from real timestamps rather than a stored snapshot, and how the supply-chain and API sections separate what's addressed from what's merely unassessed.

#appsec#dashboards
The Talarity team · July 20, 2026
Walkthrough 8 min

The AppSec findings register — one deduped row per issue, on an SLA

How Talarity turns SARIF and native scanner output into a normalized, deduped findings register with CVSS severity, remediation SLAs, VEX-free triage, and work-item hand-off.

#appsec#vulnerability-management
The Talarity team · July 18, 2026
Walkthrough 9 min

Your CI/CD pipelines, on an attestation ledger — SLSA, secret scanning, and signed builds you can prove

How Talarity turns your build pipelines into a per-repository security-posture inventory — secret scanning, signed builds, branch protection, required reviews, and SLSA build level — captured as append-only, point-in-time attestations you can hand an auditor.

#appsec#supply-chain-security
The Talarity team · July 18, 2026
Walkthrough 9 min

Ship a PSIRT that customers trust — CVSS v3.1, CSAF 2.0, and a CISA-KEV check on every advisory

How Talarity turns your product vulnerabilities into customer-facing security advisories — scored with CVSS v3.1, exported as CSAF 2.0, checked against the CISA Known Exploited Vulnerabilities catalog, and pushed to affected customers on a draft → published → withdrawn lifecycle.

#appsec#vulnerability-management
The Talarity team · July 18, 2026
Walkthrough 8 min

Software supply chain security — SBOM, VEX, and provenance in one place

Ingest a CycloneDX or SPDX bill of materials, correlate its components against your findings, author machine-readable VEX, verify SLSA provenance, enforce composition policy, diff releases, and export a federal-ready procurement bundle — all from one page.

#appsec#supply-chain
The Talarity team · July 17, 2026

Workforce

11
Walkthrough 10 min

Reading the Workforce Dashboard — every metric, its source, and how to move it

A section-by-section guide to the workforce rollup: what each headcount, seat, training and access number actually measures, which records feed it, and the workflow that changes it.

#workforce#dashboards#governance
The Talarity team · July 13, 2026
Walkthrough 5 min

Access reviews — prove that everyone has exactly the access they should, and no more

Run periodic access certifications over employee SaaS and hardware: a reviewer keeps, revokes, or flags each assignment, and the result is a signed sign-off report your auditor can rely on.

#workforce#access-review#audit-prep
The Talarity team · June 27, 2026
Walkthrough 9 min

Every SaaS app — one accountable owner, and an access review that signs itself off

From the Workforce section: add the SaaS apps your team uses, give each one a custodian (set directly or inherited from its category), track who has access with a per-user note, then run a one-click access review that lands a signed-off, audit-ready report — no spreadsheets.

#workforce#saas#access-review#custodian
The Talarity team · June 27, 2026
Walkthrough 7 min

Asset custodians — assign an owner once, let every asset inherit it

Every asset needs an accountable owner — for audits, for provisioning, for recovery when someone leaves. Assigning a custodian to each laptop one at a time doesn't scale. Talarity's model: assign a custodian to a category, and every asset under it inherits — with per-asset overrides where you need them, and a queue that routes the actual equipment work to the right person.

#workforce#assets#custodians
The Talarity team · June 26, 2026
Walkthrough 8 min

Software licenses, tracked like seats — 20 of 20 for Bloomberg, and exactly who has them

Pull a subscription from Talarity's catalog, set how many seats you bought, and assign them to named people. See what's used, what's free, who holds each one, and what you're spending — without a spreadsheet.

#workforce#licenses#saas#subscriptions
The Talarity team · June 26, 2026
Walkthrough 7 min

Least privilege in practice — build the group, then invite the user

Least-privilege access is a control in every framework (CIS 6, ISO 27001 A.5.15, SOC 2 CC6.1). Talarity makes it the easy path: groups define access page-by-page — read/write, dashboards, data scope — and you invite each user straight into the right group. Here's the two-page workflow end to end.

#workforce#groups#access#permissions
The Talarity team · June 23, 2026
Walkthrough 8 min

Every device accounted for — the equipment custodian's workflow

Own a category, and Talarity routes every equipment task to you — issue a new hire's laptop by serial, assign and upgrade gear, update the record, and recover or revoke it cleanly when someone leaves. One queue, a full audit trail, no spreadsheet.

#workforce#equipment#custodian
The Talarity team · June 13, 2026
Walkthrough 9 min

New-hire onboarding, gated end-to-end — equipment, policies, and sign-off in one flow

Build one joiner bundle of equipment and policies, apply it to a new hire, and Talarity gates the whole thing: custodians issue the gear, the employee's policy acks and receipt confirmation unlock only once every item is provisioned, and the sender watches every stage.

#workforce#onboarding#equipment
The Talarity team · June 5, 2026
Walkthrough 7 min

Pre-built groups in Talarity — pick the role, then assign the work

Twelve system groups ship with every Talarity org. Several are role-shaped on purpose: a Standard User does most of the work, an Assessment Contributor only sees the assessments they were assigned to, a Review Only auditor sees nothing they can change, and a per-module Full Access family scopes a team to just its module. This article walks through the catalog, the scoping rule that catches every admin once, and the one screen that fixes it.

#workforce#roles#permissions
The Talarity team · May 25, 2026
Walkthrough 6 min

New-hire pack vs. one updated policy — two flows, one campaign primitive

On day one a new hire needs to acknowledge five or six policies, not one. On the next quarterly update of the BCP an existing employee needs to re-ack that one policy. Talarity calls these the same thing under the hood — a campaign — but exposes two different triggers so HR doesn't pick six policies one by one, and the auditor still gets clean per-policy records.

#workforce#policies#campaigns#onboarding
The Talarity team · May 23, 2026
Walkthrough 5 min

Where your employee list comes from — and why that unfamiliar name is on it

Five sources populate the Talarity workforce roster — a manual add, a Microsoft Graph sync that pulls your whole tenant, a CSV or HRIS import, and a one-click materialization of users who already have a Talarity login. The Source column on every row tells you which one this name came from, so 'who is this?' is a one-second answer.

#workforce#roster#sync
The Talarity team · May 23, 2026

Auditor & Advisory

2

Platform & AI

26
Walkthrough 15 min

Finding the report you need: five states, what is waiting on you, and what will not delete

A year of monthly packs across a dozen templates is a needle problem. Report history filters on every axis at the server rather than in the browser, tells you what is waiting on you specifically, distinguishes archiving from deleting, and refuses a deletion with the actual reason instead of a greyed button.

#platform#reporting#governance
The Talarity team · August 17, 2026
Walkthrough 18 min

What makes a report evidence: readiness, integrity, commentary, approval, signatures

Generating a report is the easy half. What makes it citable is everything after: whether its inputs were measured at all, whether what you are reading is what was signed, who stands behind the sentences a model drafted, who approved it, who signed and in what order — and what the retention floor will not let you do with it afterwards.

#platform#reporting#governance#audit
The Talarity team · August 17, 2026
Walkthrough 15 min

Building a report: what a block reads, which rows it covers, and what it asks before it runs

The report builder is five decisions, not one: what goes on the page, where each block reads from, which rows it covers, what the report asks the person generating it, and what has to be true before it may be produced at all. Here is the whole build, from a delivered template to a published version.

#platform#reporting#governance
The Talarity team · August 15, 2026
Walkthrough 10 min

The report library: eighty templates you didn't have to write, and what happens when you change one

Delivered templates are Talarity's and cannot be edited in place. Copying one gives you a private draft that nobody else can see until you decide it is worth sharing — and that decision is deliberate, one-way, and recorded.

#platform#reporting#governance
The Talarity team · August 14, 2026
Walkthrough 14 min

From a delivered template to a signed PDF — the reporting section end to end

Seventy-seven delivered report templates, four audience starting points for a five-minute answer, a drag-and-drop canvas for a bespoke one, and a governed document that proves what it says. Here's how the pieces fit together.

#platform#reporting#audit#evidence
The Talarity team · August 9, 2026
Walkthrough 10 min

The Connector Marketplace — deciding what to plug into your GRC platform

Every connector you add is a supplier holding a key to your estate. The Connector Marketplace is the one place that answers all four questions at once — what exists, what it will need from you, where it gets configured, and whether it is still working.

#platform#integrations#connectors
The Talarity team · July 31, 2026
Walkthrough 11 min

Outbound webhooks — pushing GRC events into the systems your team already watches

Nobody logs into a GRC platform to find out a control just failed. Outbound webhooks push the event to the pager, the SIEM and the warehouse your team already watches — signed, retried, and auditable delivery by delivery.

#platform#integrations#webhooks#automation
The Talarity team · July 31, 2026
Walkthrough 11 min

From API key to first call — reading the Talarity REST API reference

The endpoint catalog on this page is generated from the running API, so the scopes it tells you to request are the scopes it enforces. Here's how to read it, scope a key, and get a 200 back.

#platform#api#integrations
The Talarity team · July 30, 2026
Walkthrough 7 min

Put your logo on every email Talarity sends — co-branding in three minutes

Add your organization's logo, colors, and a custom message to the invitations, reminders, and assessment requests Talarity sends on your behalf. A live preview shows exactly what recipients see, and a test email lands in your inbox before anything goes out.

#platform#branding#email#vendor
The Talarity team · July 17, 2026
Walkthrough 8 min

Design your request catalog — the form, the route, and the fulfillment

Every request type on your portal is three decisions: what the requester answers, who approves it, and what Talarity does when it's approved. Here's how to shape the built-in types and build your own — so an approval doesn't just say yes, it produces the vendor, the seat, or the work item, on the right register.

#platform#guest#portal#catalog#workflow
The Talarity team · July 12, 2026
Walkthrough 7 min

Stand up your request portal — one governed front door for every ask

Turn on a per-organization portal where contractors, new hires, and teammates request a vendor, a software seat, or a laptop — and every approved request fulfills itself into the register it belongs in, with an audit trail attached. Here's the ten-minute setup.

#platform#guest#portal#setup
The Talarity team · July 12, 2026
Walkthrough 8 min

From request to reality — approve once, and Talarity creates the vendor, the seat, or the work item

Requests your team files in the portal land in one approval queue. Approve a New Vendor and Talarity creates the tiering-ready vendor record; approve a License Seat and it allocates from the pool; approve equipment and it enters provisioning — and anything it can't finish becomes a staff work item, never a dropped request.

#platform#requests#approvals#automation
The Talarity team · July 10, 2026
Walkthrough 7 min

Guests, without the sprawl — invite external people to one portal, control every door, promote when they join

Contractors, candidates, and vendors-to-be need a way in that isn't a full seat and isn't a shared inbox. Talarity's guest management gives each one a single portal identity: invite by email, toggle portal access, watch their open requests, and promote them to a full user the day they're hired — guest seat freed, standard seat consumed, no re-onboarding.

#platform#guests#access#identity
The Talarity team · July 10, 2026
Walkthrough 7 min

Your team's front door — request a vendor, a seat, or a laptop, and track it to delivery

Give everyone who works with you one place to ask for what they need — a new vendor, a software seat, a cloud service, a laptop — sign in with a one-time link, submit against a catalog, and watch each request move from approval to auto-fulfillment on a live timeline.

#platform#guest#portal#requests
The Talarity team · July 10, 2026
Walkthrough 6 min

Claiming your work — turn an org-wide pile of unassigned tasks into your own queue

Every control test, remediation, finding, and vendor review that no one owns yet lands in one claimable pool. Grab what you can run with — single or in bulk — and it becomes yours, tracked through a Create → Assign → Execute → Review → Verify workflow, with a one-click release back to the pool when plans change.

#platform#work-items#operations
The Talarity team · June 27, 2026
Walkthrough 6 min

Linked accounts — run every subsidiary and client as its own governed workspace

Holding companies, MSPs, and franchisors don't have one org to govern — they have many. Talarity's Linked Accounts lets a parent organization create and oversee child workspaces, each with its own primary admin and a parent-side reviewer who gets read-only access scoped to just that account.

#platform#governance#audit-prep
The Talarity team · June 27, 2026
Walkthrough 7 min

Onboarding on autopilot — every new user lands with their tasks already assigned

Set the onboarding once. When anyone joins your organization, Talarity automatically assigns the tasks, policy acknowledgements, document uploads, and checklists they need — surfaced in their My Work the moment they first sign in, with a popup or a blocking gate if it's required.

#platform#onboarding#workforce#automation
The Talarity team · June 27, 2026
Walkthrough 8 min

Recurring cross-org data subscriptions — set it once, share on every cycle

A standing subscription fans a child org's assessments, policies, controls, risks, KRIs, and evidence to its parent automatically — every new entity, every cycle — until someone revokes. Here's how the recurring primitive works, and how the data owner stays in control.

#platform#data-sharing#multi-entity
The Talarity team · June 27, 2026
Walkthrough 8 min

Connecting Talarity to your stack — SSO, provisioning, API keys & webhooks

A GRC platform shouldn't be an island. Talarity's integrations hub connects it to the systems you already run — sign-in through your identity provider, auto-provision users from your directory, hand out scoped API keys, and push events to your own automation over signed webhooks. Here's how each one works.

#platform#integrations#sso#api
The Talarity team · June 26, 2026
Walkthrough 8 min

Notifications & SLAs — decide who gets told, how often, and when an item is late

A GRC platform throws off a constant stream of events — approaching deadlines, approvals, renewals, cross-org requests. Talarity lets an admin set, once, who gets notified, on which channel, how often, and what counts as 'late' — and lets every user fine-tune their own. Here's how to configure both.

#platform#notifications#sla#administration
The Talarity team · June 26, 2026
Walkthrough 6 min

The Calendar — every GRC deadline in one place, before it's overdue

Policy reviews, assessment due dates, vendor reassessments, remediation deadlines, control tests — in most programs each lives in its own corner and surprises you when it's late. Talarity's Calendar pulls every dated obligation across the platform into one view, flags what's overdue and what's due this week, and lets you add your own reminders — so nothing slips because it was filed somewhere you weren't looking.

#platform#calendar#deadlines
The Talarity team · June 26, 2026
Walkthrough 7 min

Setting up a new organization — a guided checklist, not a blank slate

The first day on a GRC platform usually means staring at an empty dashboard wondering where to start. Talarity opens with a guided setup checklist that walks you through the basics — profile, branding, retention, frameworks, and per-module onboarding — and tracks your progress so the whole org gets to value fast.

#platform#onboarding#setup#getting-started
The Talarity team · June 24, 2026
Walkthrough 8 min

Build the dashboard you actually start your day on

Talarity used to put eight fixed role dashboards in the sidebar. It now puts one there — Area Insights — with a Configure tab beside it holding the whole page-template library and the eight originals as starting points. You add the tabs you want, tune how the page renders, and save the result as a dashboard that is yours alone or shared with everyone in the org.

#platform#dashboards
The Talarity team · June 23, 2026
Walkthrough 8 min

Sharing data across linked organizations — both sides of the request, end to end

Two primitives — one-shot requests and standing subscriptions — fan compliance, risk, and evidence data between parent and child orgs. Every cascade, every consent, every revoke is captured in an immutable audit log, on both sides.

#platform#multi-entity#data-sharing
The Talarity team · May 27, 2026
Article 6 min

Why we built Talarity

Compliance was a fire drill we'd run too many times. So we built one platform to replace four — with AI built in, not bolted on, and risk quantified in dollars.

#platform
The Talarity team · May 1, 2026
Article 8 min

Multi-entity GRC: when subsidiaries become a feature, not a bug

Most GRC tools were built for single companies. The moment you have subsidiaries, divisions, or regional entities, the tooling breaks in predictable ways. Here's the architecture problem — and what fixing it actually requires.

#platform#multi-entity
The Talarity team · February 28, 2026