Glossary
Definitions for common Probo, security, privacy, and compliance terms
Use this glossary as a quick reference while working in Probo. For an explanation of how the main records connect, read Core Concepts.
| Glossary term | Definition |
|---|---|
| Access entry | A snapshot of an identity and its permissions in an access review campaign. An entry can include roles, administrator status, MFA status, account state, and the reviewer’s decision. |
| Access review | A periodic review of who can access a system and whether that access remains appropriate. In Probo, reviews are organized as campaigns using one or more access sources. See Access Reviews overview . |
| Access review campaign | A point-in-time access review that combines one or more sources, their snapshotted entries, reviewer decisions, flags, and completion statistics. |
| Access source | A connected provider or CSV import from which an access review campaign collects identity and permission data. |
| Agent run | A record of in-product agent work performed over authorized GRC data. An agent run is distinct from a Probo Agent posture collection on a device. |
| Applicability statement | The decision and rationale describing whether a particular control applies within a Statement of Applicability. |
| Approval quorum | The set or minimum number of approvers whose decisions are required for a specific document version to proceed. |
| Asset | A system, application, database, device, service, or other resource an organization needs to protect. Assets can be associated with risks and controls. |
| Audit | A formal evaluation of whether an organization meets defined requirements. An audit includes its scope, supporting evidence, findings, and remediation work. |
| Audit log | A chronological record of actions and changes in an organization, used to investigate who performed an operation and when it occurred. |
| Auditor | An internal or external reviewer who evaluates a compliance program and the evidence supporting it. |
| Authentication | The process of verifying the identity of a user, device, or service. Passwords, SSO, API tokens, and OAuth are authentication mechanisms. |
| Authorization | The rules that determine which resources and actions an authenticated identity is permitted to access. |
| BAA | Business Associate Agreement. A contract required by HIPAA when a business associate handles protected health information on behalf of a covered entity. |
| Campaign | |
| Compliance framework | An organized set of requirements or controls from a standard, regulation, or assurance program, such as SOC 2, ISO 27001, or GDPR. |
| Compliance Portal | A public-facing site where an organization shares selected certifications, commitments, references, files, and links without exposing its private Probo workspace. |
| Commitment | A statement an organization chooses to publish through its Compliance Portal, organized within a commitment group. |
| Commitment group | A collection used to organize related commitments published through the Compliance Portal. |
| Consent record | A record of a visitor’s cookie-consent choices, including the categories accepted or rejected and the banner version under which the choice was made. |
| Control | A requirement or expected outcome within a framework. A control states what the organization must achieve, while a measure describes how it does so. |
| Control owner | The person accountable for implementing, operating, or reviewing a control and its supporting measures. |
| Cookie banner | A configurable notice that presents tracking categories and records a visitor’s consent choices according to the applicable consent mode. |
| Cookie category | A group of trackers with a shared purpose and consent behavior, such as necessary, analytics, or marketing. |
| Data classification | A category assigned to data based on its sensitivity and handling requirements, such as public, internal, confidential, or restricted. |
| Data record | A description of information handled by an organization, including its classification, sensitivity, and business impact. |
| Data subject | An identified or identifiable person whose personal data is processed. |
| Device | An endpoint enrolled with Probo Agent. Its record can include ownership, platform details, enrollment state, and reported posture. |
| Document | A controlled policy, procedure, report, or other compliance record that supports versioning, approvals, signatures, publication, archival, and export. |
| Document version | A preserved revision of a document. Content, approval decisions, and signature requests are associated with a specific version. |
| DPA | Data Processing Agreement. A contract that defines how a processor handles personal data on behalf of a controller. |
| DPIA | Data Protection Impact Assessment. An assessment of privacy risks associated with processing that could create a high risk for individuals. |
| Electronic signature | An electronically recorded signature associated with a specific document version and signer. |
| Evidence | An artifact that demonstrates a control or measure is operating. Examples include reports, configuration exports, screenshots, approvals, logs, and signed documents. |
| Finding | A gap, exception, observation, or nonconformity identified during an assessment or audit. Findings are tracked through investigation and remediation. |
| Framework | See Compliance framework. |
| Identity provider (IdP) | A service that authenticates users and supplies identity information to applications through protocols such as SAML or OpenID Connect. |
| Impact | The severity of the consequences if a risk event occurs. Impact is commonly evaluated together with likelihood. |
| Inherent risk | The level of risk before existing safeguards, measures, or mitigations are taken into account. |
| Integration | A connection between Probo and another application or service. Integrations can support access reviews, automation, notifications, or data exchange. |
| Legal basis | The lawful justification relied upon for processing personal data, such as consent, contract, legal obligation, or legitimate interests. |
| Likelihood | An estimate of how probable it is that a risk event or scenario will occur. |
| Membership | The relationship that grants a user a role and access within a Probo organization. |
| Measure | A safeguard, process, or recurring activity implemented to satisfy one or more controls. A measure can support controls across multiple frameworks. |
| MFA | Multi-factor authentication. Authentication that requires evidence from more than one factor, reducing reliance on a password alone. |
| OAuth | An authorization framework that lets an application obtain limited access to another service without receiving the user’s password. |
| Obligation | A legal, regulatory, contractual, or other requirement the organization must fulfill. Obligations can be tracked separately from framework controls. |
| Organization | The top-level workspace in Probo. Members, frameworks, controls, risks, third parties, evidence, documents, and audits belong to an organization. |
| Personal data | Information relating to an identified or identifiable person. Privacy laws may use related terms with jurisdiction-specific definitions. |
| Policy | A documented statement of the organization’s rules, responsibilities, and expected practices. Policies are reviewed, approved, and updated over time. |
| Probo Agent | Probo’s endpoint agent for enrolling devices and reporting posture checks such as encryption, screen-lock, firewall, and operating-system status. |
| Processing activity | A record of how personal data is collected, used, shared, stored, and deleted. It includes purposes, legal bases, data subjects, recipients, and retention details. |
| Publication | The action of creating a reviewed or externally usable representation of a record or list. Publication does not necessarily make internal records public on the Compliance Portal. |
| Remediation | Work performed to correct a finding, reduce a risk, or resolve another identified gap. |
| Retention period | The length of time information is kept before it is deleted, anonymized, or otherwise disposed of. |
| Residual risk | The risk remaining after existing measures and mitigations are taken into account. |
| Rights request | A request from a data subject to exercise a privacy right, such as access, correction, deletion, restriction, or portability. |
| Risk | The possibility that a threat or event will affect the organization’s objectives, security, privacy, or compliance posture. Risks are commonly assessed by likelihood and impact. |
| Risk assessment | A structured analysis of scope, systems, boundaries, processes, threats, and scenarios used to identify and evaluate risks. |
| Risk owner | The person accountable for monitoring a risk and ensuring its treatment is appropriate. |
| Risk register | The maintained set of risks an organization tracks, reviews, owns, and treats over time. |
| Risk scenario | A description of how one or more threats could act within an assessment scope and lead to a risk. |
| SAML | Security Assertion Markup Language. A standard for exchanging authentication and authorization information between an identity provider and a service provider. |
| SCIM | System for Cross-domain Identity Management. A standard used to provision, update, and remove user accounts between an identity provider and an application. |
| Scope | The systems, processes, organizational units, locations, or other boundaries included in a compliance activity, audit, or risk assessment. |
| Service provider | In SSO, the application that relies on an identity provider to authenticate users. Probo acts as the SAML service provider. |
| SoA | Statement of Applicability. An ISO 27001 document that records whether each Annex A control applies, why it is included or excluded, and its implementation status. |
| SSO | Single Sign-On. An authentication approach that lets users access Probo through a central identity provider. Probo supports SAML 2.0 SSO. |
| Subprocessor | A third party engaged by a processor to process personal data on behalf of a controller. |
| Task | An assigned unit of work with an owner and status. Tasks help teams implement measures, collect evidence, complete assessments, and remediate findings. |
| Threat | A potential cause of an unwanted event. In a risk assessment, threats are connected to scenarios that explain how risks may arise. |
| Third party | A supplier, vendor, service provider, or other external organization that supports the business or processes its data. |
| TIA | Transfer Impact Assessment. An assessment of privacy and legal risks associated with transferring personal data between jurisdictions. |
| Tracker | A script, iframe, image, stylesheet, or other browser resource whose loading can be classified and controlled by the cookie banner. |
| Vendor | See Third party. |
| Vendor vetting | The collection and review of information about a third party to support a risk or due-diligence decision. |
| Webhook | An HTTP notification sent when a supported event occurs in Probo. Webhooks let another system react without repeatedly polling for changes. |
| No glossary terms match your search. | |
Next steps
Section titled “Next steps”- Read Core Concepts to understand the relationships between these terms.
- Set up your first organization and framework.
- Explore the MCP tools reference for the records available through the MCP server.