Appearance
Dashboards
OrviQ has three dashboard surfaces, each answering a different question.
Home Dashboard
Where: Home, then Dashboard (/dashboard).
The operational overview: what is happening across your compliance estate, oriented around what needs attention.
Draws on the portfolio aggregate — compliance position, determinations, governed ownership, attestations, findings, action plans and evidence, with by-framework slices.
Who it is for: anyone with report.read, as a daily starting point.
Compliance Dashboard
Where: Reports, then Compliance Dashboard (/compliance-dashboard).
Compliance posture across frameworks: the four populations, satisfaction distribution, dispositions and the gaps.
Who it is for: compliance managers and second-line functions preparing a position.
See Compliance Posture for how to read the figures.
Compliance Visualizer
Where: Reports, then Compliance Visualizer (/visualizer).
A relationship view: how obligations, controls, evidence and risks connect.
Who it is for: anyone trying to understand coverage structure rather than coverage counts.
What the visualizer is genuinely good for
Two questions it answers faster than any table:
- Which controls carry the most obligations? A control mapped as
supersetacross many requirements is a concentration point — its failure has wide consequences. - Which obligations have thin coverage? An obligation whose only mappings are
relatedorsupportinglooks mapped on a count and is unaddressed in substance.
Reconciliation
The portfolio aggregate reconciles with the requirement projection and the requirement workspace. The same requirement viewed in a dashboard, a register and its own workspace shows the same position.
If two views disagree, check the scope filter first
Posture is always relative to a declared boundary and an adoption. Two views filtered differently will legitimately differ. A genuine reconciliation failure is worth reporting; a scope difference is usually the explanation.
Enterprise-wide, not requirement-only
The findings block in the portfolio aggregate is tenant-wide and source-tagged, covering compliance, RCSA and third-party findings.
This is worth knowing because it is a common source of confusion when comparing to older reporting: a findings count restricted to requirement findings understates the real position by excluding every control-assessment deficiency.
What dashboards do not do
| Do | Do not |
|---|---|
| Compute from governed records | Maintain a separate reporting store |
| Show what needs attention | Change any compliance position |
| Reconcile with the registers | Produce numbers without a traceable source |
| Respect your permissions | Show data you cannot see in the register |
Running a dashboard is read-only. It writes nothing, produces no audit events and involves no AI.
Permission-scoped visibility
Dashboards show what you can see. Two people opening the same dashboard with different permissions see different totals, and both are correct for their access.
This occasionally causes confusion in meetings. If two colleagues report different figures, compare permissions before assuming a defect.
Related registers and views
For working rather than reporting, go to the register:
| Question | Go to |
|---|---|
| Which obligations need attention? | Requirements register, Needs attention tab |
| Which controls are ineffective? | Continuous Assurance |
| What evidence is stale or missing? | Expected Evidence & Freshness |
| What is outstanding for me? | Workbench |
| What decisions are waiting? | Approvals Hub |
| What is due? | GRC Calendar |
Permissions
| Action | Permission |
|---|---|
| View dashboards and reports | report.read |
| View compliance status | compliance.read |
| Export data | export.data |
Troubleshooting
"Dashboard totals differ from the register." Check the scope and framework filters on each. Also check whether the register view is filtered to a tab.
"A colleague sees different numbers." Dashboard visibility follows permissions.
"The findings count is higher than I expected." It is tenant-wide and includes control assessment and third-party findings, not only requirement findings.
"A dashboard is empty." Requires report.read, and the underlying modules require their own entitlements.