Appearance
Entitlements
An entitlement is a capability enabled for your tenant. A permission is what a user is allowed to do. Both must be present for a feature to work.
Entitlement and permission together
| Entitlement | Permission | Result |
|---|---|---|
| On | Held | The feature works |
| On | Not held | Access denied |
| Off | Held | The feature is unavailable |
| Off | Not held | The feature is unavailable |
A permission whose entitlement is off is inert. This is why the permission catalogue records the entitlement each permission depends on.
The entitlements
Every capability in OrviQ is governed by a named tenant feature entitlement.
| Entitlement Key | Name | Unlocks |
|---|---|---|
compliance_core | Compliance Core | The regulatory library, requirement and activity extraction, obligation tracking end to end |
risk_management | Risk Management | The enterprise risk register, inherent and residual scoring, risk treatment governance |
control_assurance | Control Assurance | Control register, design and operating-effectiveness assessment, evidence |
regulatory_intelligence | Regulatory Intelligence | Source monitoring, change detection and triage, handoff to Smart Extract |
ai_risk_intelligence | AI Risk Intelligence | AI-assisted assessment, gap identification, finding generation, remediation recommendation |
audit_management | Audit Management | Audit planning, fieldwork, findings and issue tracking with a full trail |
regulatory_inspections | Regulatory Inspections & Examinations | Inspection lifecycle, item extraction, response workflow, historical submissions |
vendor_risk | Third-Party Risk Management | Vendor and outsourcing risk assessment and monitoring |
policy_governance | Policy Governance | Corporate policy authoring, atomic statements, review, approval, and lifecycle tracking |
content_library | Governance Content Library | OrviQ certified Content 2.0 governance instruments, policy templates, and pack catalog |
content_pack_core | Core Governance Library Pack | Access to certified universal baseline policies (ORV-PACK-CORE) |
content_pack_banking | Commercial Banking Risk Pack | Access to banking risk and supervisory governance policies (ORV-PACK-BANKING) |
bcm_resilience | Business Continuity & Operational Resilience | BIA, continuity and disaster recovery plans, exercises, resilience assessment |
incident_management | Incident & Loss Event Management | Incident register, root-cause investigation, loss accounting, closure governance |
continuous_assurance | Continuous Assurance & Automated Evidence | Automated evidence connections, scheduled collectors, indicators, recalculation |
integrations_security_tools | Security Tool Integrations | Vulnerability and configuration scanner ingestion (Tenable, Nessus, Nipper, Qualys) |
cloud_discovery | Cloud & Identity Discovery | Automated identity and cloud resource discovery (Entra ID, Azure, AWS, Prowler) |
integrations_catalogue | Integration Catalogue | Directory of 22 catalogued integrations (20 available, 2 planned: Splunk and Microsoft Sentinel) with availability and method disclosure |
api_access | API Access | Programmatic REST API keys and outbound webhook event delivery |
custom_branding | Custom Branding | Tenant-specific branding and logo customization |
sbp_repository | SBP Regulatory Repository | Curated regulatory publications and circulars for State Bank of Pakistan |
arabic_processing | Arabic Document Processing | Multi-lingual ingestion and requirement processing for Arabic documents |
ncap_governance | NCAP Governance | UAE central bank NCAP registration decomposition and submission governance |
regulatory_calendar | Regulatory Calendar | Consolidated deadline, review cadence, and expiry scheduling engine |
What is never entitlement-gated
Some capabilities are core infrastructure, available across every tier:
| Capability | Why |
|---|---|
| Scope Registry and Assets | Assurance conclusions are meaningless without a declared boundary |
| The organisational workflow layer | Governance is not a premium feature |
| Workbench and notifications | Human action routing |
| Business references | Every entity needs a human-facing identity |
| Audit trail | Accountability |
What keeps working when an entitlement is off
This is the question worth asking during evaluation, and the answers are specific.
Continuous Assurance off
Continues to work in full:
- Control register and crosswalk
- Manual evidence and evidence links
- Evidence assertions recorded manually or as attestations
- Manual control assessments
- Requirement Assurance — it is part of Compliance Core, not Continuous Assurance
- Expected evidence and freshness — deterministic and AI-independent
Unavailable: connections, collectors, indicators, automated recalculation.
Requirement Assurance does not require Continuous Assurance
This surprises people. A tenant without the Continuous Assurance entitlement still gets the full five-dimension determination model, driven by manual evidence and periodic assessment. Continuous Assurance raises the cadence and the coverage; it is not a prerequisite for governed compliance.
Governance Content Library off
When content_library is enabled, teams can adopt certified Content 2.0 governance packs and templates into the tenant as draft policies.
Adopted Content Library policies survive later entitlement disablement: Adoption creates fully tenant-local PolicyRecord and PolicyStatement rows carrying immutable catalog source references (source_pack_id). If the content_library entitlement is subsequently disabled:
- All previously adopted policies remain intact in the tenant's Policy Library.
- Existing adopted policies remain fully editable, versionable, and operationalized.
- Only browsing the catalog at
/governance/packsand creating new adoptions are blocked.
Adoption does not equal compliance
Adopting a policy pack creates internal drafted statements within the tenant. It demonstrates that internal policy text exists; it does not prove operational adherence, control effectiveness, or regulatory compliance.
AI Risk Intelligence off
Every governed workflow continues to work. Registers, approvals, determinations, reports and historical reconstruction are unaffected.
Unavailable: AI mapping proposals, design adequacy checks, AI-suggested expected evidence, advisory drafting, and the Assistant. Smart Extract is unavailable; import and manual authoring are not.
Any module entitlement off
The module's navigation entry and API are unavailable. Nothing else is affected — canonical objects created by that module while it was on remain in the shared registers.
Feature visibility and ship-dark behavior
OrviQ uses two distinct visibility models for unentitled features:
1. Standard discovery items (locked)
For standard business modules (e.g. Continuous Assurance, Audit Management), when an entitlement is disabled, the module appears as a locked navigation item in the secondary navigation bar. This informs teams that the capability exists while gating access.
2. Ship-dark capabilities (hidden)
High-impact infrastructure and telemetry integrations ship dark:
- Security Tool Integrations (
integrations_security_tools) and Cloud & Identity Discovery (cloud_discovery) remain entirely hidden from navigation when disabled. They do not render locked discovery placeholders or upgrade prompts. - Backend API routes refuse calls with
403 Forbidden. - This ensures security interfaces and infrastructure ingestion endpoints are never exposed in environments where automated polling or scanner ingestion is not licensed or authorized.
Integration Catalogue (integrations_catalogue): When entitled, this provides a read-only directory disclosing the exact availability status (20 available, 2 planned: Splunk and Microsoft Sentinel) and connection methods of 22 catalogued integrations without connecting live credentials.
Viewing your entitlements
Your session's entitlements and effective permissions are visible through the platform's entitlement introspection. Requires settings.read.
Changing entitlements is a subscription matter handled outside the tenant workspace.
Permissions
| Action | Permission |
|---|---|
| View tenant settings and entitlements | settings.read |
| Edit tenant settings | settings.manage |
Example
A mid-sized bank's entitlement set.
| Entitlement | On | Reason |
|---|---|---|
| Compliance Core | Yes | Foundation |
| Risk Management | Yes | Foundation |
| Control Assurance | Yes | Foundation |
| Policy Governance | Yes | — |
| Third-Party Risk | Yes | Material outsourcing supervision |
| Audit Management | Yes | Internal audit function |
| Incident & Loss | Yes | Operational risk reporting |
| BCM & Resilience | Yes | Operational resilience supervision |
| Regulatory Intelligence | Yes | Horizon scanning |
| AI Risk Intelligence | Yes | Extraction and mapping proposals |
| Continuous Assurance | No | Deferred to a later phase |
| Regulatory Inspections | No | No supervisory examination in the current cycle |
| API Access | No | Pending security review |
What the bank runs without Continuous Assurance: the full compliance programme — 264 obligations, 412 controls, requirement assurance across five dimensions, governed determinations and board reporting. Evidence is manual and assessment is periodic.
What it gains when Continuous Assurance is enabled next year: automated telemetry for the roughly 60 controls with an authoritative system of record. The other 350 stay on periodic assessment, which is the right instrument for them.
Troubleshooting
"A permission I granted has no effect." Its entitlement is off. Check the permission catalogue for the entitlement it depends on.
"A navigation item shows a lock." The entitlement is off. It is visible for discovery.
"Turning an entitlement off lost my data." It does not. Canonical objects remain in the shared registers; the module surface becomes unavailable.
"Automated indicators went stale after Continuous Assurance was disabled." Correct. Results stop refreshing and become stale, which moves affected effectiveness to not_assessed rather than leaving a stale green.