Review tenant security and compliance controls
Review Admin security and compliance indicators as control evidence inputs, with explicit owners, scope, freshness, and independent verification.
Audience, roles, and scope
Admin security and compliance views; this article makes no certification, legal-compliance, or control-effectiveness guarantee.
Who this is for
- Tenant security, privacy, risk, and compliance personnel
Roles
- Security administrator
- Compliance reviewer
- Auditor
Before you begin
- Authorization for security information
- Defined control framework, scope, and evidence period
Article tags
- security
- compliance
- controls
- risk
- audit
Procedures
Follow the sequence and stop when identity, authorization, target, or result differs from the article.
Review a security or compliance control
Connect an indicator to authoritative configuration and operational evidence.
- 1Define the control question
Identify framework, requirement, tenant scope, owner, evidence period, expected state, and acceptance criteria.
- 2Inspect and corroborate
Review the Admin indicator, timestamp, and configuration; compare it with source-system logs, policy, tickets, and approved assurance evidence.
- 3Record gaps and ownership
Document evidence, limitation, risk, remediation owner, due date, and reviewer without overstating compliance.
The review produces scoped evidence and actionable gaps rather than an unsupported compliance conclusion.
Security and data handling
- Use only the identity, tenant, role, and data scope approved for the task.
- Verify targets and expected effects before saving, sending, publishing, exporting, deleting, or approving.
- Keep secrets and regulated data out of screenshots, URLs, free-text diagnostics, and ordinary support messages.
- Restrict exported security evidence to authorized recipients and approved storage.
Known limitations
- A dashboard label or enabled setting does not prove design adequacy, operating effectiveness, certification, or legal compliance.
- Control availability, evidence retention, and framework mapping depend on deployment, contract, and independent assurance.
Troubleshooting
You cannot open Vianordis Admin
Likely cause: The session expired, the account is not entitled, or the required tenant or role claim is missing.
- Open the service through the approved Vianordis entry point and sign in again.
- Confirm the intended organization, tenant, and account are in use.
- If access remains denied, record the time and request an entitlement check; do not attempt direct-URL bypasses.
A documented control or navigation item is not visible
Likely cause: The current role, subscription, tenant configuration, release status, or feature flag does not expose it.
- Confirm the audience, role, prerequisites, and limitations in this article.
- Refresh after a new sign-in and verify the correct tenant context.
- Ask the responsible administrator whether the capability is enabled before reporting a defect.
A saved change or background result is not visible
Likely cause: Validation failed, processing is incomplete, the view is stale, or the feature is locally simulated rather than persisted.
- Review inline validation, status indicators, filters, and the selected tenant or workspace.
- Refresh once and search by a stable identifier before repeating the action.
- Do not repeat irreversible or externally visible actions until the first operation's state is known.
Source verification
Security and compliance routes, labels, and visible controls were reviewed in source; external assurance was not inferred.
Reviewed paths at 8f3a86e
src/app/(base)/administration/security/SecurityView.tsxsrc/app/(base)/administration/compliance/ComplianceView.tsxsrc/database/security.tssrc/database/compliance.ts
Contact support
Contact support when
- A repeatable Vianordis Admin error blocks an approved task
- Expected access, tenant scope, data, or status appears incorrect
- A security, privacy, financial, compliance, or data-loss concern is suspected
Include
- The page, action, expected result, and exact error text
- The time of occurrence with time zone and whether it is reproducible
- Your tenant, role, browser, and sanitized record or correlation identifier
- The troubleshooting steps already completed
Never include
- Passwords, access tokens, API keys, recovery codes, session cookies, or private keys
- Unredacted personal, financial, health, student, employee, or other regulated data
- Confidential documents or message bodies unless support provides an approved secure channel