Monitoring Dashboard

Use the Monitoring Dashboard to see evidence health, control status, and risk exposure in one place

Written By Micah

Your compliance program generates a lot of signal: evidence expires, controls slip, risks get scored, owners change. The Monitoring dashboard pulls that signal into one place so you can answer three questions quickly: what needs attention right now, what will need attention soon, and what should be done about it.

Most numbers, bars, tiles, and rows on the Monitoring dashboard are links. Clicking one opens the Control Library, Evidence Repository, or Risk Management, filtered to exactly the set of items you clicked.

Finding the Monitoring dashboard

Monitoring appears in the main Strike Graph navigation. If you don't see it, one of two things is true:

  • The Monitoring dashboard hasn't been enabled for your organization yet. Reach out to support or your Customer Success Manager to request access.

  • Your role doesn't include access. The Monitoring dashboard requires Manager permissions.

The Monitoring dashboard is organized as a summary header plus a set of tabs: Blast Radius, Risk Landscape, Control Monitoring, and Recent Changes. Your active tab is stored in the page URL, so you can bookmark or share a link to a specific view.

The Monitoring summary header

The summary header sits at the top of the Monitoring dashboard and stays visible on every tab. It gives you a quick read on overall control coverage and evidence health.

Controls in the summary header

The left side shows the percentage of your active controls that are In Place, followed by a segmented coverage bar and a legend broken out by progress status: In Place, Partial, Not In Place, Not Applicable, and Archived.

The In Place percentage is calculated using In Place, Partially In Place, and Not In Place controls only. Not Applicable and Archived controls are excluded from the calculation, so marking controls as out of scope does not lower your coverage percentage. Those controls still appear as segments and counts in the bar and legend.

Click the percentage or any segment of the coverage bar to open the Control Library filtered to that progress status.

Evidence counts in the summary header

The right side of the summary header shows three evidence counts. Each one opens the Evidence Repository, filtered to that set of items:

  • Expired: evidence whose most recent attachment has already passed its expiration date.

  • Expiring in 30d: evidence with an attachment expiring within the next 30 days.

  • Auto-collecting in 30d: evidence configured for automated collection that is due to be recollected in the next 30 days. Comparing this count with the Expiring in 30d count shows how much of your upcoming expiration work Strike Graph will handle for you.

The Blast Radius tab

Blast Radius is a flow diagram that maps the chain of your compliance program: evidence flows into controls, and controls flow into framework criteria. Use it to see which controls and criteria are affected when an evidence item expires, and to find out why a particular criterion has no coverage.

Reading the Blast Radius chart

The Blast Radius chart has three columns. By default, items are grouped rather than listed individually:

  • Left column (Evidence): grouped into health buckets: Healthy, Expiring Soon, Expired, Needs Attention, and No Attachments.

  • Middle column (Controls): grouped by progress status: In Place, Partially In Place, Not In Place, Not Applicable, Unspecified, and Archived.

  • Right column (Frameworks): your active frameworks and their criteria.

The columns are connected by bands called ribbons. The width of each ribbon shows how many relationships it represents, so the widest ribbons are the connections that involve the most items.

Drilling into the Blast Radius chart

Clicking a group in the Blast Radius chart changes what the chart displays:

  • Click an evidence health bucket to replace it with the individual evidence items in that bucket. The Controls and Frameworks columns then show only what those items connect to.

  • Click a control progress group to replace it with the individual controls in that group.

  • Click a framework or domain in the right column to show its child criteria. Criteria numbering is hierarchical, so you can keep clicking until you reach a criterion with no children.

Each selection you make appears as a chip above the Blast Radius chart. Remove a chip to undo that selection. For framework selections, removing the chip moves you up one level rather than returning to the top.

Clicking an individual evidence item, control, or lowest-level criterion opens the Blast Radius detail drawer instead of changing the chart.

The Blast Radius detail drawer

The detail drawer lists everything connected to the item you selected. Every entry in the drawer is a link:

  • For an evidence item, the drawer shows its health status, the controls it is linked to along with each control's progress and health, and the framework criteria those controls are mapped to. The Open in Evidence Repository button opens the evidence item.

  • For a control, the drawer shows its progress status, the evidence linked to it, and all mapped criteria grouped by framework. The Open in Control Library button opens the control detail page.

  • For a criterion or framework, the drawer shows the controls mapped to it, plus the evidence linked to those controls.

Showing orphans in Blast Radius

The Show orphans toggle above the Blast Radius chart reveals items that have no connections. When the toggle is on, the chart also includes:

  • Orphaned evidence: active evidence that is not mapped to any control. It appears as an unconnected extension of its health bucket. Orphaned evidence is being collected but is not currently supporting any control.

  • Orphaned criteria: active criteria in your frameworks that have no controls mapped to them. These appear as an unfilled portion of the framework bar in the right column, showing where your framework coverage is incomplete.

Orphaned items are also labeled as orphaned in the Blast Radius detail drawer.

Blast Radius color modes

The Blast Radius chart has two color modes: Category and Health Impact. Category colors each node by what type of item it is, which helps when you are tracing connections. Health Impact colors each node by its health state, which helps when you are looking for groups of unhealthy items.

Blast Radius in very large programs

The Blast Radius chart displays a large number of evidence-to-control relationships, but it does have a limit. If your organization has more than that limit, a banner appears at the top of the chart to tell you that you are seeing a partial view. Clicking into a specific health bucket, progress group, or framework reduces the amount of data enough to show a complete view of that area.

How Strike Graph determines evidence health

The evidence health buckets used in the Monitoring summary header and the Blast Radius chart are evaluated in a fixed order, and the first condition that matches is the one applied:

  1. No Attachments: the evidence item has no attachments.

  2. Expired: the most recent attachment's expiration date has already passed.

  3. Needs Attention: the evidence item is flagged as needing attention, for example by Verify AI.

  4. Expiring Soon: the most recent attachment expires within the next 30 days.

  5. Healthy: none of the above conditions apply.

Because expiration is checked before the needs-attention flag, an evidence item that is both expired and flagged appears as Expired rather than Needs Attention.

The Risk Landscape tab

The Risk Landscape tab shows your active risks three ways: grouped by category, plotted by score, and measured by how well they are mitigated.

Risk category bars

The risk category bars show one horizontal bar per risk category. The length of each bar reflects the number of risks in that category, and the segments within it are broken out by severity band. Risks that have not been scored appear in a separate Unscored segment.

The severity bands and their colors come from your organization's risk scale configuration, so the chart uses your own band names and colors if you have customized them. Click any segment to open Risk Management filtered to that category and severity.

Risk matrix

The risk matrix is a grid of Likelihood against Impact, using your organization's configured axis labels. Organizations using a matrix scoring model see a 5Γ—5 grid, and organizations using an additive scoring model see a 3Γ—3 grid. Each populated cell shows the number of risks in that combination of likelihood and impact, and hovering over a cell lists the risk names.

Only risks that have both a likelihood and an impact set appear in the risk matrix. If you have active risks but the matrix is empty, those risks have not been scored yet.

Risk topography

The risk topography chart is a treemap in which every active risk is a tile. Each tile encodes three pieces of information:

  • Tile size: the number of active controls assigned to mitigate that risk. Larger tiles have more controls assigned.

  • Tile color: the risk category. Tiles in the same category are grouped together.

  • Tile intensity: the proportion of that risk's active controls that are healthy. A solid, fully colored tile means all of its controls are healthy. A faint tile means most of its controls need attention.

Large faint tiles are usually worth reviewing first: the risk has many controls assigned, but most of those controls need attention. Small faint tiles usually indicate a different situation, where the risk has very few controls assigned to it in the first place.

Hovering over a tile shows the risk name, category, severity, and the percentage of its active controls that are healthy. Click a tile to open that risk's detail page. In categories with many risks, the smallest tiles are combined into a single +N more tile. Clicking that tile opens Risk Management filtered to the category.

The Control Monitoring tab

The Control Monitoring tab covers the control program itself: the status of your controls, how often each control needs to be performed, and who owns them.

Frequency Status

The Frequency Status chart shows one row per control frequency, with row height proportional to the number of controls in that frequency. Within each row, segments break the controls down by progress status, and controls flagged as needing attention appear in their own segment.

Use Frequency Status to plan recurring work: it shows how many controls fall into each frequency and how many of those controls currently need attention. Click any segment to open the Control Library filtered to that frequency, progress status, and attention state at once.

Active Controls and Progress

Two doughnut charts appear next to the Frequency Status chart:

  • Active Controls: your controls by health, split into Satisfied, Needs attention, and No evidence. The center label shows the total number of controls. Clicking the Satisfied or Needs attention legend rows opens the Control Library filtered to that status.

  • Progress: your controls by progress status, split into In Place, Partially In Place, Not In Place, Archived, and Not Applicable. Clicking any legend row opens the Control Library filtered to that progress status.

The two charts answer different questions. Progress shows how far along your control implementation is. Active Controls shows whether the controls you have implemented are currently satisfied.

Control Ownership

The Control Ownership chart shows one row per control owner, plus an Unowned row for controls with no assigned owner. Within each owner's row, controls are grouped by progress status, and each control appears as an individual cell colored by its state. Hover over a cell to see which control it represents.

An owner with many cells that need attention may have too many controls assigned or may need support. A large Unowned row means a number of controls have no one accountable for them, which is worth addressing before an audit.

The Recent Changes tab

Recent Changes is a paginated feed of items that have been created or modified in your compliance program, covering controls, evidence, risks, and attachments.

Each row shows the resource type, its name, the action that occurred, who performed it, and when. Actions are written in plain language, such as "Attachment added," "Mapped to control," "Criteria unmapped," and "Scored." Clicking a row opens that resource's detail page. Clicking an attachment row opens the evidence item the attachment belongs to.

Two controls shape the Recent Changes feed:

  • Type filters: All, Controls, Evidence, Risks, and Attachments. Each filter displays its own count for the selected time window.

  • Time window: 7, 30, or 90 days. The default is 30 days.

The feed shows 25 rows per page and displays which range of results you are viewing. Use Recent Changes to see what has changed since you last reviewed your program, or to find out why a control's status changed.

The Comment Activity tab

If Comment Activity is enabled for your organization, it appears as an additional tab on the Monitoring dashboard. Comment Activity is a feed of comments across your controls, evidence, and risks. You can search and filter the feed, open the item a comment was left on, and export the results to CSV.

Tips for using the Monitoring dashboard

  • Cmd-click or Ctrl-click any link to open it in a new tab. This works on every filter link, chart segment, doughnut legend row, treemap tile, and feed row, so you can open several filtered views without leaving the Monitoring dashboard.

  • Choose a tab based on your question. For expiring evidence and its downstream effects, use Blast Radius. For control status and recurring control work, use Control Monitoring. To find out what recently changed, use Recent Changes.

  • Turn on Show orphans when preparing for an audit. Orphaned criteria are framework requirements with no controls mapped to them, and the Blast Radius chart is the only place they are shown.

  • Bookmark the tab you use most. The active tab is included in the page URL.

  • Allow a moment for recent changes to appear. Monitoring data is cached briefly to keep the dashboard fast. If you have just made a change elsewhere in Strike Graph, refresh the page after a few moments.

Empty states on the Monitoring dashboard

Some panels display a message instead of a chart when there is no data to show. Messages such as "No active risks with both likelihood and impact set" or "No active controls with a progress state set" indicate that part of your program still needs to be set up, rather than a problem with the Monitoring dashboard.

Need more help?

If you have questions about the Monitoring dashboard, or would like help interpreting what you are seeing in your own program, reach out through the in-app messenger or contact your Customer Success Manager.