Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Control Packs

Pre-built governance controls. Activated, not configured from scratch.

Control packs are curated sets of access controls organized by governance domain. They define what is evaluated, what constitutes a finding, and what evidence is automatically collected.

What is a control pack

A control pack is a group of controls that share a governance purpose. Each control in a pack is a discrete evaluable rule: it defines the condition being checked, how deviations are classified, which control reference it maps to, and what evidence is collected when a finding is detected.

Control packs are pre-built by the Nuxari team. Organizations activate the packs relevant to their environment and risk profile. There is no blank-slate configuration, packs are designed to be useful from day one.

What this means for your organization
Instead of writing governance rules from scratch, your team activates the relevant control packs, maps them to connected systems, and starts receiving findings. The evaluation logic is maintained by Nuxari, your team focuses on reviewing and remediating findings.

Control domains

Control packs are organized around governance domains. Current and planned domains:

Identity & Access
Role assignments, group memberships, and baseline drift across identity providers.
Cloud Permissions
Azure RBAC, AWS IAM, and GCP IAM deviations from approved baselines.
SaaS Governance
M365, GitHub, and Okta license and access baseline enforcement.
Offboarding
Residual access detection after employee departure workflows complete.
Privilege Escalation
Admin and owner roles outside approved scope, privilege creep patterns.
License Management
Assigned but unused or unauthorized license detection and reclamation.
Edge & Hybrid
On-premises access governance coverage via Edge Agents.

Control references

Nuxari maps controls to reference frameworks. This allows evidence collected by Nuxari to be organized around framework control areas for auditor review. Frameworks supported (mapping is descriptive, not certifying):

  • NIST SP 800-53, AC (Access Control), AU (Audit), IA (Identification and Authentication)
  • ISO 27001, A.9 Access Control
  • CIS Controls v8
  • SOC 2 CC6, Logical and Physical Access Controls
Important

The presence of a control reference in Nuxari means evidence collected is relevant to that control area, not that your organization is certified or compliant with the referenced framework. Certification requires formal auditor assessment.

Evaluation and findings

Control pack evaluations run on a configurable schedule (daily by default) and on-demand. Each evaluation cycle produces pass and fail results per control per user per resource. Pass results generate clean-state evidence records. Fail results generate findings that surface in the Access Drift dashboard.

After a successful remediation, the Policy Engine automatically re-evaluates the affected resources to confirm the finding is resolved and the new state matches the approved baseline.

Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.