Odau

Audit & Compliance

The evidence Odau holds, mapped to the control areas auditors ask about, and the trail of what was done in Odau.

OverviewPrivileged AccessAudit & Compliance

What Odau Holds

Odau's own mapping of its records to control areas. It is not verified against the text of any standard, and it states no view on whether a control is met.

Asset Inventory
SOC 2 CC6.1 · ISO 27001 A.5.9 · NIST CSF ID.AM · CSA CCM DCS

0 application records, one per real application, each with the date it was first seen.

0 vendors and 0 contract records attached to them.

No application has a retirement date on record, so the inventory shows what is held, not what has been decommissioned.

Logical Access
SOC 2 CC6.1–CC6.3 · ISO 27001 A.5.15 · NIST CSF PR.AA · CSA CCM IAM

0 active access grants, each naming the person, the application and the level.

0 of them at an elevated level.

Single sign-on enforcement recorded on 0 of 0 applications.

Single sign-on enforcement is not recorded on 0 applications.

Access Requests & Approval
SOC 2 CC6.2 · ISO 27001 A.5.18 · NIST CSF PR.AA · CSA CCM IAM

0 access requests decided, each recording who decided and when.

A grant is written when access is confirmed given in the vendor's tool, so grants that predate Odau carry no requester or approver.

Deprovisioning
SOC 2 CC6.2 · ISO 27001 A.5.11 · NIST CSF PR.AA · CSA CCM IAM

No access grant has been revoked through Odau, so there is no deprovisioning evidence on record at all.

Access & Application Review
SOC 2 CC6.3 · ISO 27001 A.5.18 · NIST CSF ID.GV · CSA CCM IAM

0 of 0 applications carry a review date within the last 12 months.

0 have been reviewed at some point.

0 applications have no review recorded in the last 12 months.

Change & Procurement Approval
SOC 2 CC8.1 · ISO 27001 A.8.32 · NIST CSF PR.IP · CSA CCM CCC

0 procurement decisions recorded against configured approval chains.

1 entries in the audit trail below, each naming an actor, an action and a time.

The trail records what was done in Odau. Changes made directly in a vendor's tool are not visible to it.

Data Handling
SOC 2 CC6.7 · ISO 27001 A.5.34 · NIST CSF ID.AM · CSA CCM DSP

Data sensitivity classified on 0 of 0 applications.

Whether an application trains on company data is recorded on the application itself.

0 applications have no data sensitivity classified.

Odau does not hold the vendors' own terms, so what the training data includes is a question for those terms.

Audit Trail

1 entry on record.

When
Who
What
Aug 18, 2026
Ali N
Odau was created with Ali N as its first administrator.

The Evidence Package

An evidence package would gather the records above into a single dated file: the application and vendor inventory, the access grants and their levels, the decisions on record with who made them, the review dates, and the audit trail for a chosen period.

Odau cannot produce it yet. There is no file generation and no delivery anywhere in the product, so there is no button here rather than one that does nothing. The records themselves are readable on the pages that own them, and every figure on this page can be reached from those pages today.

What This Mapping Is

The control identifiers above are Odau’s own mapping of the records it keeps to the areas those frameworks cover. It is not checked against the text of any standard for completeness, and it is not an assessment: nothing here states that a control is met, partially met, or failed. Odau surfaces evidence, and certification remains the customer’s responsibility.

The standards’ own control text is not reproduced here. The identifiers are given so a reader can look each one up in the standard itself.