The evaluation engine for continuous governance
Pre-built control libraries for identity, access, cloud, SaaS, and endpoint governance. Deploy a pack and immediately get continuous assessment, severity-ranked findings, and automated evidence.
Continuous assessment from day one
Deploy, evaluate, find, remediate, prove. In that order. Always.
Deploy in minutes, not months
Select a pack, connect it to your environment via an existing integration, and evaluations begin immediately. No custom rule authoring, no professional services engagement required to get started.
Findings, not raw data
Each control evaluation produces a severity-ranked finding with a clear description and a linked remediation path. You see what requires action, not an unfiltered log of every evaluated object.
Evidence for every evaluation
Each control run captures the evaluation input, result, timestamp, and control ID in a structured evidence record. The record exists the moment evaluation completes, no manual collection required.
Seven packs covering five governance domains
Identity, access, cloud, SaaS, and endpoint, each pack is independently deployable and stackable with the others for complete coverage.
Identity provider, cloud config, SaaS assignments, or host evidence collected via Edge Agent
Each control rule runs against the collected data, comparing actual state to expected policy
Deviations become findings with severity (Critical / High / Medium / Low) and control ID
Evaluation input, result, timestamp, and control mapping written as an immutable evidence record
Findings with remediation paths surface to the governance platform for approval-gated action
Pull, evaluate, classify, evidence, on every run
Control packs run the same cycle on every evaluation pass. The cycle is deterministic. The evidence is automatic. Nothing requires analyst intervention to produce a finding.
- ·Configurable evaluation frequency per pack (default: 15-minute cycle)
- ·On-demand evaluation available at any time
- ·Partial evaluation recorded when a connector is temporarily unavailable
- ·Re-evaluation after remediation confirms whether a finding is genuinely closed
A control evidence record on every run
Every time a control evaluates, a structured evidence record is written. Control ID, evaluation result, input data snapshot, timestamp, and hash, all included automatically.
- ·Framework mappings included, NIST 800-53, ISO 27001, SOC 2 TSC
- ·SHA-256 hash on every record, tamper detection built in
- ·Exportable per control, per pack, or as a full evidence bundle
- ·Evidence exists for passing controls too, not just failures
{
"controlId":"PAK-02-C11",
"packName":"Privileged Access Pack",
"controlName":"MFA required for admin accounts",
"evaluationResult":"FAIL",
"severity":"HIGH",
"orgId":"org_acmecorp",
"evaluatedAt":"2026-06-06T14:00:00Z",
"inputSnapshot": {
"totalAdminAccounts": 12,
"mfaEnabled": 9,
"mfaNotEnabled": 3
},
"frameworkMapping": {
"NIST_800_53": ["IA-2","IA-2(1)"],
"SOC2_TSC": ["CC6.1"]
},
"hash":"sha256:b7f2a9c3e1d0...",
"findingId":"fnd_01jxa2k9"
}Every finding. Full context.
When access drifts beyond approved baselines, Nuxari surfaces the full picture: what was approved, what was observed, which control was violated, and what evidence was captured.
- ·Approved vs actual access shown side-by-side in every finding
- ·Evidence snapshot automatically attached to every drift record
- ·One-click remediation workflow creation from any finding
Common questions
Can I customize what a control pack evaluates?
Each control pack ships with a default rule set. Custom control authoring is available via JSON schema, you can extend an existing pack or create a domain-specific pack for environments the catalog does not yet cover.
How frequently do controls evaluate?
Evaluation frequency is configurable per pack. The default is continuous with a 15-minute reconciliation cycle. You can also trigger on-demand evaluation runs at any time.
What happens if a connector becomes unavailable during an evaluation run?
The evaluation skips the unavailable connector and records a partial evaluation event. The platform alerts operators to the gap and retries on the next cycle. Evidence records are not fabricated from incomplete data.
How do control packs relate to compliance frameworks?
Each control in a pack includes optional framework mappings (NIST 800-53, ISO 27001, SOC 2 Trust Services Criteria). These mappings appear in evidence records but do not constitute formal compliance certification.
Can I write a control pack from scratch?
Yes. Control packs are defined via JSON schema and can be authored for custom environments, proprietary systems, or frameworks not yet in the catalog. Documentation and tooling for custom pack authoring are in the product roadmap.
The full governance stack
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.