Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Compliance & Evidence

Control Packs

Use pre-built control libraries to run continuous assessments and generate evidence automatically.

Last updated: June 2026

Who this is for

Admins and auditors who want to assess their environment against structured governance controls and generate evidence automatically.

Before you start

At least one connector must be configured for the relevant system before running most packs. The Linux Posture Pack additionally requires an Edge Agent to be registered and active.

What control packs are

Control packs are pre-built governance check libraries organized around specific risk areas. Each pack contains a set of checks that Nuxari runs against your connected systems. When you run a pack, Nuxari compares observed data from your environment against expected standards, ranks the results by severity, and automatically captures evidence of the evaluation. You do not need to write any checks yourself, packs are ready to use as soon as the relevant connector is configured.

When to use control packs

  • Before or during an audit to gather evidence of your access and configuration posture.
  • After onboarding a new connector to get an immediate view of the environment's state.
  • As part of a recurring schedule to continuously monitor for drift and posture degradation.
  • After completing remediation, using the Canary Pack to confirm corrections are holding.

How to run an evaluation

  1. 1In Nuxari, go to Control Packs.
  2. 2Select the pack you want to run. Review which connectors it requires.
  3. 3Click Run Evaluation. Nuxari will query your connected systems and begin the assessment.
  4. 4When the evaluation completes, navigate to Governance > Findings to review the ranked results.
Each evaluation run is automatically recorded as an evidence event. You can access the evaluation summary in Audit > Evidence and export it for auditors.

How packs stack together

You can run multiple packs against the same environment. Findings are deduplicated and tagged by the pack that produced them, so you have a clear view of which area each finding comes from. Running the Identity Lifecycle Pack and the Privileged Access Pack together, for example, gives you a broader picture of identity and access posture from a single evaluation cycle.

Available packs

Identity Lifecycle Pack

Checks identity provider account lifecycle status, active accounts for departed users, stale accounts, and onboarding completeness.

Privileged Access Pack

Validates high-privilege access assignments across connected systems, including admin role sprawl and separation-of-duty checks.

Cloud Exposure Pack

Reviews cloud resource and permission posture, over-permissioned roles, public resource exposure, and missing security controls.

License Governance Pack

Identifies SaaS license waste and misassignment, unused licenses, licenses assigned to inactive users, and cost optimization opportunities.

SaaS Posture Pack

Checks security configuration settings across connected SaaS tools, MFA enforcement, admin account hygiene, and session policy compliance.

Linux Posture Pack

Performs on-premises host and endpoint checks via an Edge Agent, user account status, sudo privilege review, and service account hygiene.

Remediation Canary Pack

Post-remediation validation that confirms findings have been closed and corrective actions are holding in the source system.

Credential Hygiene Pack

Tracks app registration secrets, certificates, and connector credential age, flagging items approaching expiry or past rotation policy thresholds.

Was this page helpful?