Skip to content

Entitlements

An entitlement is a capability enabled for your tenant. A permission is what a user is allowed to do. Both must be present for a feature to work.


Entitlement and permission together

EntitlementPermissionResult
OnHeldThe feature works
OnNot heldAccess denied
OffHeldThe feature is unavailable
OffNot heldThe feature is unavailable

A permission whose entitlement is off is inert. This is why the permission catalogue records the entitlement each permission depends on.


The entitlements

Every capability in OrviQ is governed by a named tenant feature entitlement.

Entitlement KeyNameUnlocks
compliance_coreCompliance CoreThe regulatory library, requirement and activity extraction, obligation tracking end to end
risk_managementRisk ManagementThe enterprise risk register, inherent and residual scoring, risk treatment governance
control_assuranceControl AssuranceControl register, design and operating-effectiveness assessment, evidence
regulatory_intelligenceRegulatory IntelligenceSource monitoring, change detection and triage, handoff to Smart Extract
ai_risk_intelligenceAI Risk IntelligenceAI-assisted assessment, gap identification, finding generation, remediation recommendation
audit_managementAudit ManagementAudit planning, fieldwork, findings and issue tracking with a full trail
regulatory_inspectionsRegulatory Inspections & ExaminationsInspection lifecycle, item extraction, response workflow, historical submissions
vendor_riskThird-Party Risk ManagementVendor and outsourcing risk assessment and monitoring
policy_governancePolicy GovernanceCorporate policy authoring, atomic statements, review, approval, and lifecycle tracking
content_libraryGovernance Content LibraryOrviQ certified Content 2.0 governance instruments, policy templates, and pack catalog
content_pack_coreCore Governance Library PackAccess to certified universal baseline policies (ORV-PACK-CORE)
content_pack_bankingCommercial Banking Risk PackAccess to banking risk and supervisory governance policies (ORV-PACK-BANKING)
bcm_resilienceBusiness Continuity & Operational ResilienceBIA, continuity and disaster recovery plans, exercises, resilience assessment
incident_managementIncident & Loss Event ManagementIncident register, root-cause investigation, loss accounting, closure governance
continuous_assuranceContinuous Assurance & Automated EvidenceAutomated evidence connections, scheduled collectors, indicators, recalculation
integrations_security_toolsSecurity Tool IntegrationsVulnerability and configuration scanner ingestion (Tenable, Nessus, Nipper, Qualys)
cloud_discoveryCloud & Identity DiscoveryAutomated identity and cloud resource discovery (Entra ID, Azure, AWS, Prowler)
integrations_catalogueIntegration CatalogueDirectory of 22 catalogued integrations (20 available, 2 planned: Splunk and Microsoft Sentinel) with availability and method disclosure
api_accessAPI AccessProgrammatic REST API keys and outbound webhook event delivery
custom_brandingCustom BrandingTenant-specific branding and logo customization
sbp_repositorySBP Regulatory RepositoryCurated regulatory publications and circulars for State Bank of Pakistan
arabic_processingArabic Document ProcessingMulti-lingual ingestion and requirement processing for Arabic documents
ncap_governanceNCAP GovernanceUAE central bank NCAP registration decomposition and submission governance
regulatory_calendarRegulatory CalendarConsolidated deadline, review cadence, and expiry scheduling engine

What is never entitlement-gated

Some capabilities are core infrastructure, available across every tier:

CapabilityWhy
Scope Registry and AssetsAssurance conclusions are meaningless without a declared boundary
The organisational workflow layerGovernance is not a premium feature
Workbench and notificationsHuman action routing
Business referencesEvery entity needs a human-facing identity
Audit trailAccountability

What keeps working when an entitlement is off

This is the question worth asking during evaluation, and the answers are specific.

Continuous Assurance off

Continues to work in full:

  • Control register and crosswalk
  • Manual evidence and evidence links
  • Evidence assertions recorded manually or as attestations
  • Manual control assessments
  • Requirement Assurance — it is part of Compliance Core, not Continuous Assurance
  • Expected evidence and freshness — deterministic and AI-independent

Unavailable: connections, collectors, indicators, automated recalculation.

Requirement Assurance does not require Continuous Assurance

This surprises people. A tenant without the Continuous Assurance entitlement still gets the full five-dimension determination model, driven by manual evidence and periodic assessment. Continuous Assurance raises the cadence and the coverage; it is not a prerequisite for governed compliance.

Governance Content Library off

When content_library is enabled, teams can adopt certified Content 2.0 governance packs and templates into the tenant as draft policies.

Adopted Content Library policies survive later entitlement disablement: Adoption creates fully tenant-local PolicyRecord and PolicyStatement rows carrying immutable catalog source references (source_pack_id). If the content_library entitlement is subsequently disabled:

  • All previously adopted policies remain intact in the tenant's Policy Library.
  • Existing adopted policies remain fully editable, versionable, and operationalized.
  • Only browsing the catalog at /governance/packs and creating new adoptions are blocked.

Adoption does not equal compliance

Adopting a policy pack creates internal drafted statements within the tenant. It demonstrates that internal policy text exists; it does not prove operational adherence, control effectiveness, or regulatory compliance.

AI Risk Intelligence off

Every governed workflow continues to work. Registers, approvals, determinations, reports and historical reconstruction are unaffected.

Unavailable: AI mapping proposals, design adequacy checks, AI-suggested expected evidence, advisory drafting, and the Assistant. Smart Extract is unavailable; import and manual authoring are not.

Any module entitlement off

The module's navigation entry and API are unavailable. Nothing else is affected — canonical objects created by that module while it was on remain in the shared registers.


Feature visibility and ship-dark behavior

OrviQ uses two distinct visibility models for unentitled features:

1. Standard discovery items (locked)

For standard business modules (e.g. Continuous Assurance, Audit Management), when an entitlement is disabled, the module appears as a locked navigation item in the secondary navigation bar. This informs teams that the capability exists while gating access.

2. Ship-dark capabilities (hidden)

High-impact infrastructure and telemetry integrations ship dark:

  • Security Tool Integrations (integrations_security_tools) and Cloud & Identity Discovery (cloud_discovery) remain entirely hidden from navigation when disabled. They do not render locked discovery placeholders or upgrade prompts.
  • Backend API routes refuse calls with 403 Forbidden.
  • This ensures security interfaces and infrastructure ingestion endpoints are never exposed in environments where automated polling or scanner ingestion is not licensed or authorized.

Integration Catalogue (integrations_catalogue): When entitled, this provides a read-only directory disclosing the exact availability status (20 available, 2 planned: Splunk and Microsoft Sentinel) and connection methods of 22 catalogued integrations without connecting live credentials.


Viewing your entitlements

Your session's entitlements and effective permissions are visible through the platform's entitlement introspection. Requires settings.read.

Changing entitlements is a subscription matter handled outside the tenant workspace.


Permissions

ActionPermission
View tenant settings and entitlementssettings.read
Edit tenant settingssettings.manage

Example

A mid-sized bank's entitlement set.

EntitlementOnReason
Compliance CoreYesFoundation
Risk ManagementYesFoundation
Control AssuranceYesFoundation
Policy GovernanceYes
Third-Party RiskYesMaterial outsourcing supervision
Audit ManagementYesInternal audit function
Incident & LossYesOperational risk reporting
BCM & ResilienceYesOperational resilience supervision
Regulatory IntelligenceYesHorizon scanning
AI Risk IntelligenceYesExtraction and mapping proposals
Continuous AssuranceNoDeferred to a later phase
Regulatory InspectionsNoNo supervisory examination in the current cycle
API AccessNoPending security review

What the bank runs without Continuous Assurance: the full compliance programme — 264 obligations, 412 controls, requirement assurance across five dimensions, governed determinations and board reporting. Evidence is manual and assessment is periodic.

What it gains when Continuous Assurance is enabled next year: automated telemetry for the roughly 60 controls with an authoritative system of record. The other 350 stay on periodic assessment, which is the right instrument for them.


Troubleshooting

"A permission I granted has no effect." Its entitlement is off. Check the permission catalogue for the entitlement it depends on.

"A navigation item shows a lock." The entitlement is off. It is visible for discovery.

"Turning an entitlement off lost my data." It does not. Canonical objects remain in the shared registers; the module surface becomes unavailable.

"Automated indicators went stale after Continuous Assurance was disabled." Correct. Results stop refreshing and become stale, which moves affected effectiveness to not_assessed rather than leaving a stale green.


OrviQ Enterprise Governance, Risk & Compliance Platform