Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Core Concepts

Understand the key concepts and data model in Probo

View as Markdown

Probo models a compliance program as connected records. Understanding those relationships helps teams avoid duplicate work and preserve traceability from a requirement to its implementation and evidence.

The top-level entity in Probo. All compliance data — frameworks, controls, risks, third parties, evidence — belongs to an organization. Users are invited as members of an organization.

Compliance standards or custom programs your organization follows. Each framework contains controls that define expected outcomes.

Specific requirements within a framework. For example, “Access controls must be implemented for all production systems” or “Data must be encrypted at rest.” Controls represent what needs to be achieved.

Actions and processes your organization implements to satisfy controls. A single measure can satisfy multiple controls across different frameworks. For example, a “multi-factor authentication” measure might satisfy access control requirements in both SOC 2 and ISO 27001.

Potential adverse outcomes tracked by the organization. Risks can be linked to measures, obligations, vendor assessments, and structured risk-assessment scenarios.

Structured analyses made from scopes, nodes, boundaries, processes, threats, and scenarios. Scenarios can link the analysis to risks in the organization’s risk register.

External service providers and suppliers your organization relies on. Third-party management includes tracking contracts, conducting risk assessments, vetting, and monitoring compliance status.

Systems, applications, databases, and infrastructure that your organization operates. Assets are inventoried and linked to the controls and risks that apply to them.

Files and URLs that support the operation of a measure. Linking evidence to the implementation record keeps it reusable across every control supported by that measure.

Actionable items assigned to team members. Tasks track work like implementing a control, reviewing a third party, completing an assessment, or remediating a finding.

Formal evaluations of your compliance posture. Probo helps you prepare evidence packages, organize documentation, and track audit findings and remediation.

Policies, procedures, reports, and other controlled content. Documents support versions, approval quorums, electronic signatures, publication, archival, and PDF export.

Issues identified during an audit or another review. Finding kinds include major nonconformity, minor nonconformity, observation, and exception. Findings can be linked to one or more audits.

Legal and regulatory requirements your organization must fulfill. Obligations are tracked separately from framework controls to capture jurisdiction-specific requirements.

Data records describe information handled by the organization, including sensitivity and business impact.

Records of data processing activities, as required for GDPR compliance. Each record documents what data is processed, the legal basis, retention periods, and data subjects involved.

DPIAs (Data Protection Impact Assessments)

Section titled “DPIAs (Data Protection Impact Assessments)”

Assessments required for high-risk data processing activities under GDPR. DPIAs evaluate the necessity and proportionality of processing, and identify measures to mitigate risks to data subjects.

Assessments for international data transfers. TIAs evaluate whether the destination country provides adequate data protection and what supplementary measures are needed.

A reviewed record of which controls apply to an organization and why. It is commonly used with ISO 27001 but can represent applicability decisions for other control sets.

Campaigns that bring access entries from Probo memberships, CSV data, or connected providers into one review. Decisions, flags, sources, and campaign statistics remain associated with the campaign.

A public-facing portal for selected certifications, commitments, references, files, and links. Portal publication is separate from internal program publication.

Device records represent enrolled endpoints and their reported posture. Agent runs represent in-product agent work over authorized GRC data; they are distinct from Probo Agent device enrollment.

The core workflow in Probo follows this chain:

  • Frameworks contain Controls that define what must be achieved
  • Measures implement Controls — a single Measure can satisfy multiple Controls across Frameworks
  • Risks are mitigated by Measures
  • Evidence supports Measures
  • Tasks drive the day-to-day work of implementing and maintaining compliance
  • Audits verify that everything is in place and operating as expected
  • Findings preserve the issues identified during review
  • Documents formalize approved policies, procedures, and reports