Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Compliance program

Understand how frameworks, controls, measures, tasks, evidence, and applicability records connect

View as Markdown

A Probo organization is the boundary for a company’s compliance records and memberships. Inside it, a compliance program connects external requirements to the work and proof that demonstrate how those requirements are met.

  1. A framework groups requirements from a standard or a custom program.
  2. A control describes an outcome the organization is expected to achieve.
  3. A measure describes what the organization actually operates to satisfy one or more controls.
  4. A task assigns a concrete piece of work, optionally with a due date.
  5. Evidence is a file or URL supporting the operation of a measure.

Controls and measures are many-to-many. A reusable measure such as an access review can support controls in several frameworks, which avoids duplicating the same implementation work.

A Statement of Applicability records which controls apply to an organization and why. It is versioned separately from day-to-day measure work so teams can review and publish a deliberate scope.

Frameworks, controls, measures, tasks, evidence, risks, documents, audits, and obligations can be linked rather than copied. These relationships provide traceability from a requirement to its implementation, supporting material, risks, and audit results.

Publishing a list or statement creates a stable representation for review. Draft records remain editable until the responsible team is ready to publish them.

Organization membership determines access to the program. Assign work to named users and use the audit log to investigate important changes. SSO and SCIM manage access to Probo itself; access reviews review access imported from Probo and connected systems.