Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Control Packs

The evaluation engine for continuous governance

Pre-built control libraries for identity, access, cloud, SaaS, and endpoint governance. Deploy a pack and immediately get continuous assessment, severity-ranked findings, and automated evidence.

How it works

Continuous assessment from day one

Deploy, evaluate, find, remediate, prove. In that order. Always.

Deploy in minutes, not months

Select a pack, connect it to your environment via an existing integration, and evaluations begin immediately. No custom rule authoring, no professional services engagement required to get started.

Findings, not raw data

Each control evaluation produces a severity-ranked finding with a clear description and a linked remediation path. You see what requires action, not an unfiltered log of every evaluated object.

Evidence for every evaluation

Each control run captures the evaluation input, result, timestamp, and control ID in a structured evidence record. The record exists the moment evaluation completes, no manual collection required.

Catalog

Seven packs covering five governance domains

Identity, access, cloud, SaaS, and endpoint, each pack is independently deployable and stackable with the others for complete coverage.

7
Packs
109
Controls
5
Domains
IdentityIdentity Lifecycle Pack
18 controls
Entra IDOkta+1
AccessPrivileged Access Pack
14 controls
Entra IDAWS IAM
CloudCloud Exposure Pack
22 controls
AWSAzure+1
SaaSLicense Governance Pack
11 controls
M365Google Workspace
SaaSSaaS Posture Pack
16 controls
GitHubGoogle Workspace+1
EndpointLinux Posture Pack
19 controls
Edge Agent
AssuranceRemediation Canary Pack
9 controls
Edge AgentEntra ID
Control Evaluation Cycle
01
Pull connector data

Identity provider, cloud config, SaaS assignments, or host evidence collected via Edge Agent

02
Evaluate controls

Each control rule runs against the collected data, comparing actual state to expected policy

03
Classify findings

Deviations become findings with severity (Critical / High / Medium / Low) and control ID

04
Capture evidence

Evaluation input, result, timestamp, and control mapping written as an immutable evidence record

05
Route to remediation

Findings with remediation paths surface to the governance platform for approval-gated action

Evaluation cycle

Pull, evaluate, classify, evidence, on every run

Control packs run the same cycle on every evaluation pass. The cycle is deterministic. The evidence is automatic. Nothing requires analyst intervention to produce a finding.

  • ·Configurable evaluation frequency per pack (default: 15-minute cycle)
  • ·On-demand evaluation available at any time
  • ·Partial evaluation recorded when a connector is temporarily unavailable
  • ·Re-evaluation after remediation confirms whether a finding is genuinely closed
Evidence output

A control evidence record on every run

Every time a control evaluates, a structured evidence record is written. Control ID, evaluation result, input data snapshot, timestamp, and hash, all included automatically.

  • ·Framework mappings included, NIST 800-53, ISO 27001, SOC 2 TSC
  • ·SHA-256 hash on every record, tamper detection built in
  • ·Exportable per control, per pack, or as a full evidence bundle
  • ·Evidence exists for passing controls too, not just failures
control_evidence_record.json
{
"controlId":"PAK-02-C11",
"packName":"Privileged Access Pack",
"controlName":"MFA required for admin accounts",
"evaluationResult":"FAIL",
"severity":"HIGH",
"orgId":"org_acmecorp",
"evaluatedAt":"2026-06-06T14:00:00Z",
"inputSnapshot": {
"totalAdminAccounts": 12,
"mfaEnabled": 9,
"mfaNotEnabled": 3
 },
"frameworkMapping": {
"NIST_800_53": ["IA-2","IA-2(1)"],
"SOC2_TSC": ["CC6.1"]
 },
"hash":"sha256:b7f2a9c3e1d0...",
"findingId":"fnd_01jxa2k9"
}
Access Drift Investigation

Every finding. Full context.

When access drifts beyond approved baselines, Nuxari surfaces the full picture: what was approved, what was observed, which control was violated, and what evidence was captured.

  • ·Approved vs actual access shown side-by-side in every finding
  • ·Evidence snapshot automatically attached to every drift record
  • ·One-click remediation workflow creation from any finding
app.nuxari.io/access-drift/fnd-0094
N
Access Drift Finding
CRITICAL
Azure role assignment exceeds approved baseline
Access DriftIdentityAzure
Policy violated
Least-privilege role enforcement
Control reference
AC-6 · Least Privilege
Current access
Contributor
Approved baseline
Reader
Identity
Jordan Lee · Azure Subscription
Detected
Today, 09:14 UTC
Evidence snapshot · Captured automatically
"observed": "Contributor", "approved": "Reader"
sha256: a1b2c3d4e5f6a7b8...
Illustrative UI · Demo data only
FAQ

Common questions

Can I customize what a control pack evaluates?

Each control pack ships with a default rule set. Custom control authoring is available via JSON schema, you can extend an existing pack or create a domain-specific pack for environments the catalog does not yet cover.

How frequently do controls evaluate?

Evaluation frequency is configurable per pack. The default is continuous with a 15-minute reconciliation cycle. You can also trigger on-demand evaluation runs at any time.

What happens if a connector becomes unavailable during an evaluation run?

The evaluation skips the unavailable connector and records a partial evaluation event. The platform alerts operators to the gap and retries on the next cycle. Evidence records are not fabricated from incomplete data.

How do control packs relate to compliance frameworks?

Each control in a pack includes optional framework mappings (NIST 800-53, ISO 27001, SOC 2 Trust Services Criteria). These mappings appear in evidence records but do not constitute formal compliance certification.

Can I write a control pack from scratch?

Yes. Control packs are defined via JSON schema and can be authored for custom environments, proprietary systems, or frameworks not yet in the catalog. Documentation and tooling for custom pack authoring are in the product roadmap.

Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.