Compliance
Compliance in the Settings area — route /settings/compliance, reachable by direct link rather than from the sidebar.
This page lives in the Settings area at /settings/compliance. It is not in the sidebar — it is reached by a direct link, or from another page that links to it.
At a glance#
| Dashboard route | /settings/compliance |
| Area | Settings (settings) |
| In the sidebar | No — reachable by direct link |
What it does#
Compliance is a status page: it reads your current privacy and governance posture and shows what is on, what is off, and when each control last ran. From it you can reach the pages that actually configure things — retention and redaction, exports, webhooks, and the audit log.
It stores no settings of its own. It exists so that "are we configured correctly?" is a question you can answer by looking at one screen instead of five.
When to use it#
Before a security review, before a launch in a regulated market, and on a periodic cadence. Also as the onboarding check for a new administrator: it is the fastest way to understand what posture you have inherited.
Workflow#
Read every indicator that is off and decide deliberately
Off is a legitimate choice. Off by default, unnoticed is how most compliance gaps happen — particularly email and IP redaction, which are not on unless you turned them on.
Check the last-run timestamps
An enabled retention policy that has not run is not protecting you. "Enabled" and "working" are different claims and this page distinguishes them.
Follow through to the configuring page
Nothing is changed here. The links take you to where the setting lives.
Confirm against the audit log
The audit log records who changed what. This page shows current state; that one shows how it got that way.
Permissions and prerequisites#
Requires an administrative role, since it surfaces the workspace's governance configuration.
Limits and edge cases#
Read-only. Every actual setting lives on another page.
Current state only. No history — that is the audit log's job.
Scoped to what the platform can see. Obligations arising from your own systems are outside it entirely.
Troubleshooting#
An indicator says off and I believe I enabled it. Check the app and environment scope — several controls are per-app, and enabling one elsewhere does not enable it here.
Retention enabled but never run. It has not reached its first scheduled run, or the policy is enabled with a period nothing has yet exceeded.