Source: qdash /policy + /compliance — c65 control-center-v2, compliance-driven pre-defined Policies (P-ids from cycles/c65.control-center-v2/policy-definitions.md)
Compliance frameworks
Active frameworks require policies — an unmet requirement is a gap that degrades posture.
8 policies mapped · 5 would need enabling
6 policies mapped · 2 would need enabling
6 policies mapped · 1 would need enabling
10 policies mapped · 4 would need enabling
2 policies mapped · 0 would need enabling
10 policies mapped · 4 would need enabling
8 policies mapped · 3 would need enabling
7 policies mapped · 4 would need enabling
5 policies mapped · 2 would need enabling
Security posture
68%
across active frameworks
Active frameworks
3 / 12
toggled globally, org-wide
Active policies
10 / 17
pre-defined, individually configured
Open gaps
6
required by an active framework, off
Policies
Activate with the toggle; each policy has its own focused config page.
| Description | Active Compliance Frameworks Requiring this Policy | Config | |
|---|---|---|---|
| Identity & Access2 of 3 active | |||
Agents must be registered and monitored before they run. | Configure | ||
Agents run under org-issued identity, not personal accounts or static keys. | Configure | ||
Agents may not execute with root or admin privileges. | Configure | ||
| Action & Autonomy2 of 4 active | |||
Consequential tool calls require a human approval before agents proceed. | Configure | ||
Agents may only invoke tools on the approved list. | Configure | ||
Agents may only connect to approved MCP servers. | 3 mapped frameworks — none active | Configure | |
Agent code execution is confined to a sandbox at or above the required level. | Configure | ||
| Data Protection3 of 4 active | |||
Secrets and credential files stay out of model context. | Configure | ||
Sensitive content is detected and redacted in prompts and responses. | Configure | ||
Agent traffic may only reach approved destinations. | Configure | ||
Connections below the TLS baseline are refused. | Configure | ||
| Input & Output Integrity0 of 3 active | |||
Inbound prompts are scanned for injection patterns — detect & contain. | Configure | ||
Agent output is checked before it reaches downstream tools. | Configure | ||
Models and tools must match pinned, verified sources. | Configure | ||
| Cost & Consumption3 of 3 active | |||
Fleet and per-agent spend stays under explicit ceilings. | Configure | ||
Agents respect provider quotas instead of burning through them. | Configure | ||
No agent operates below the minimum security-posture score. | Configure | ||
Need something narrower than these? The flexible engine is still there — custom controls →