Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Glossary

Definitions for common Probo, security, privacy, and compliance terms

View as Markdown

Use this glossary as a quick reference while working in Probo. For an explanation of how the main records connect, read Core Concepts.

Glossary term Definition
Access entry

A snapshot of an identity and its permissions in an access review campaign. An entry can include roles, administrator status, MFA status, account state, and the reviewer’s decision.

Access review

A periodic review of who can access a system and whether that access remains appropriate. In Probo, reviews are organized as campaigns using one or more access sources. See Access Reviews overview .

Access review campaign

A point-in-time access review that combines one or more sources, their snapshotted entries, reviewer decisions, flags, and completion statistics.

Access source

A connected provider or CSV import from which an access review campaign collects identity and permission data.

Agent run

A record of in-product agent work performed over authorized GRC data. An agent run is distinct from a Probo Agent posture collection on a device.

Applicability statement

The decision and rationale describing whether a particular control applies within a Statement of Applicability.

Approval quorum

The set or minimum number of approvers whose decisions are required for a specific document version to proceed.

Asset

A system, application, database, device, service, or other resource an organization needs to protect. Assets can be associated with risks and controls.

Audit

A formal evaluation of whether an organization meets defined requirements. An audit includes its scope, supporting evidence, findings, and remediation work.

Audit log

A chronological record of actions and changes in an organization, used to investigate who performed an operation and when it occurred.

Auditor

An internal or external reviewer who evaluates a compliance program and the evidence supporting it.

Authentication

The process of verifying the identity of a user, device, or service. Passwords, SSO, API tokens, and OAuth are authentication mechanisms.

Authorization

The rules that determine which resources and actions an authenticated identity is permitted to access.

BAA

Business Associate Agreement. A contract required by HIPAA when a business associate handles protected health information on behalf of a covered entity.

Campaign

See Access review campaign.

Compliance framework

An organized set of requirements or controls from a standard, regulation, or assurance program, such as SOC 2, ISO 27001, or GDPR.

Compliance Portal

A public-facing site where an organization shares selected certifications, commitments, references, files, and links without exposing its private Probo workspace.

Commitment

A statement an organization chooses to publish through its Compliance Portal, organized within a commitment group.

Commitment group

A collection used to organize related commitments published through the Compliance Portal.

Control

A requirement or expected outcome within a framework. A control states what the organization must achieve, while a measure describes how it does so.

Control owner

The person accountable for implementing, operating, or reviewing a control and its supporting measures.

Data classification

A category assigned to data based on its sensitivity and handling requirements, such as public, internal, confidential, or restricted.

Data record

A description of information handled by an organization, including its classification, sensitivity, and business impact.

Data subject

An identified or identifiable person whose personal data is processed.

Device

An endpoint enrolled with Probo Agent. Its record can include ownership, platform details, enrollment state, and reported posture.

Document

A controlled policy, procedure, report, or other compliance record that supports versioning, approvals, signatures, publication, archival, and export.

Document version

A preserved revision of a document. Content, approval decisions, and signature requests are associated with a specific version.

DPA

Data Processing Agreement. A contract that defines how a processor handles personal data on behalf of a controller.

DPIA

Data Protection Impact Assessment. An assessment of privacy risks associated with processing that could create a high risk for individuals.

Electronic signature

An electronically recorded signature associated with a specific document version and signer.

Evidence

An artifact that demonstrates a control or measure is operating. Examples include reports, configuration exports, screenshots, approvals, logs, and signed documents.

Finding

A gap, exception, observation, or nonconformity identified during an assessment or audit. Findings are tracked through investigation and remediation.

Framework

See Compliance framework.

Identity provider (IdP)

A service that authenticates users and supplies identity information to applications through protocols such as SAML or OpenID Connect.

Impact

The severity of the consequences if a risk event occurs. Impact is commonly evaluated together with likelihood.

Inherent risk

The level of risk before existing safeguards, measures, or mitigations are taken into account.

Integration

A connection between Probo and another application or service. Integrations can support access reviews, automation, notifications, or data exchange.

Likelihood

An estimate of how probable it is that a risk event or scenario will occur.

Membership

The relationship that grants a user a role and access within a Probo organization.

Measure

A safeguard, process, or recurring activity implemented to satisfy one or more controls. A measure can support controls across multiple frameworks.

MFA

Multi-factor authentication. Authentication that requires evidence from more than one factor, reducing reliance on a password alone.

OAuth

An authorization framework that lets an application obtain limited access to another service without receiving the user’s password.

Obligation

A legal, regulatory, contractual, or other requirement the organization must fulfill. Obligations can be tracked separately from framework controls.

Organization

The top-level workspace in Probo. Members, frameworks, controls, risks, third parties, evidence, documents, and audits belong to an organization.

Personal data

Information relating to an identified or identifiable person. Privacy laws may use related terms with jurisdiction-specific definitions.

Policy

A documented statement of the organization’s rules, responsibilities, and expected practices. Policies are reviewed, approved, and updated over time.

Probo Agent

Probo’s endpoint agent for enrolling devices and reporting posture checks such as encryption, screen-lock, firewall, and operating-system status.

Processing activity

A record of how personal data is collected, used, shared, stored, and deleted. It includes purposes, legal bases, data subjects, recipients, and retention details.

Publication

The action of creating a reviewed or externally usable representation of a record or list. Publication does not necessarily make internal records public on the Compliance Portal.

Remediation

Work performed to correct a finding, reduce a risk, or resolve another identified gap.

Retention period

The length of time information is kept before it is deleted, anonymized, or otherwise disposed of.

Residual risk

The risk remaining after existing measures and mitigations are taken into account.

Rights request

A request from a data subject to exercise a privacy right, such as access, correction, deletion, restriction, or portability.

Risk

The possibility that a threat or event will affect the organization’s objectives, security, privacy, or compliance posture. Risks are commonly assessed by likelihood and impact.

Risk assessment

A structured analysis of scope, systems, boundaries, processes, threats, and scenarios used to identify and evaluate risks.

Risk owner

The person accountable for monitoring a risk and ensuring its treatment is appropriate.

Risk register

The maintained set of risks an organization tracks, reviews, owns, and treats over time.

Risk scenario

A description of how one or more threats could act within an assessment scope and lead to a risk.

SAML

Security Assertion Markup Language. A standard for exchanging authentication and authorization information between an identity provider and a service provider.

SCIM

System for Cross-domain Identity Management. A standard used to provision, update, and remove user accounts between an identity provider and an application.

Scope

The systems, processes, organizational units, locations, or other boundaries included in a compliance activity, audit, or risk assessment.

Service provider

In SSO, the application that relies on an identity provider to authenticate users. Probo acts as the SAML service provider.

SoA

Statement of Applicability. An ISO 27001 document that records whether each Annex A control applies, why it is included or excluded, and its implementation status.

SSO

Single Sign-On. An authentication approach that lets users access Probo through a central identity provider. Probo supports SAML 2.0 SSO.

Subprocessor

A third party engaged by a processor to process personal data on behalf of a controller.

Task

An assigned unit of work with an owner and status. Tasks help teams implement measures, collect evidence, complete assessments, and remediate findings.

Threat

A potential cause of an unwanted event. In a risk assessment, threats are connected to scenarios that explain how risks may arise.

Third party

A supplier, vendor, service provider, or other external organization that supports the business or processes its data.

TIA

Transfer Impact Assessment. An assessment of privacy and legal risks associated with transferring personal data between jurisdictions.

Tracker

A script, iframe, image, stylesheet, or other browser resource whose loading can be classified and controlled by the cookie banner.

Vendor

See Third party.

Vendor vetting

The collection and review of information about a third party to support a risk or due-diligence decision.

Webhook

An HTTP notification sent when a supported event occurs in Probo. Webhooks let another system react without repeatedly polling for changes.