Skip to content

Dashboards

OrviQ has three dashboard surfaces, each answering a different question.


Home Dashboard

Where: Home, then Dashboard (/dashboard).

The operational overview: what is happening across your compliance estate, oriented around what needs attention.

Draws on the portfolio aggregate — compliance position, determinations, governed ownership, attestations, findings, action plans and evidence, with by-framework slices.

Who it is for: anyone with report.read, as a daily starting point.


Compliance Dashboard

Where: Reports, then Compliance Dashboard (/compliance-dashboard).

Compliance posture across frameworks: the four populations, satisfaction distribution, dispositions and the gaps.

Who it is for: compliance managers and second-line functions preparing a position.

See Compliance Posture for how to read the figures.


Compliance Visualizer

Where: Reports, then Compliance Visualizer (/visualizer).

A relationship view: how obligations, controls, evidence and risks connect.

Who it is for: anyone trying to understand coverage structure rather than coverage counts.

What the visualizer is genuinely good for

Two questions it answers faster than any table:

  • Which controls carry the most obligations? A control mapped as superset across many requirements is a concentration point — its failure has wide consequences.
  • Which obligations have thin coverage? An obligation whose only mappings are related or supporting looks mapped on a count and is unaddressed in substance.

Reconciliation

The portfolio aggregate reconciles with the requirement projection and the requirement workspace. The same requirement viewed in a dashboard, a register and its own workspace shows the same position.

If two views disagree, check the scope filter first

Posture is always relative to a declared boundary and an adoption. Two views filtered differently will legitimately differ. A genuine reconciliation failure is worth reporting; a scope difference is usually the explanation.


Enterprise-wide, not requirement-only

The findings block in the portfolio aggregate is tenant-wide and source-tagged, covering compliance, RCSA and third-party findings.

This is worth knowing because it is a common source of confusion when comparing to older reporting: a findings count restricted to requirement findings understates the real position by excluding every control-assessment deficiency.


What dashboards do not do

DoDo not
Compute from governed recordsMaintain a separate reporting store
Show what needs attentionChange any compliance position
Reconcile with the registersProduce numbers without a traceable source
Respect your permissionsShow data you cannot see in the register

Running a dashboard is read-only. It writes nothing, produces no audit events and involves no AI.


Permission-scoped visibility

Dashboards show what you can see. Two people opening the same dashboard with different permissions see different totals, and both are correct for their access.

This occasionally causes confusion in meetings. If two colleagues report different figures, compare permissions before assuming a defect.


For working rather than reporting, go to the register:

QuestionGo to
Which obligations need attention?Requirements register, Needs attention tab
Which controls are ineffective?Continuous Assurance
What evidence is stale or missing?Expected Evidence & Freshness
What is outstanding for me?Workbench
What decisions are waiting?Approvals Hub
What is due?GRC Calendar

Permissions

ActionPermission
View dashboards and reportsreport.read
View compliance statuscompliance.read
Export dataexport.data

Troubleshooting

"Dashboard totals differ from the register." Check the scope and framework filters on each. Also check whether the register view is filtered to a tab.

"A colleague sees different numbers." Dashboard visibility follows permissions.

"The findings count is higher than I expected." It is tenant-wide and includes control assessment and third-party findings, not only requirement findings.

"A dashboard is empty." Requires report.read, and the underlying modules require their own entitlements.


OrviQ Enterprise Governance, Risk & Compliance Platform