> ## Documentation Index
> Fetch the complete documentation index at: https://docs.osto.one/llms.txt
> Use this file to discover all available pages before exploring further.

# AutoComply

> Get your workspace audit-ready — activate a compliance framework, generate policies, track controls and tasks, and run security awareness training.

**AutoComply** (under **Compliance**) automates the busywork of getting audit-ready. Activate a framework like SOC 2, and Osto maps out the requirements, controls, policies, and tasks you need — then helps you generate policies, assign training, and track everything to completion in one place.

> **Path:** Compliance → AutoComply

## First-run setup

The first time you open AutoComply, a **Guided Setup** assistant walks you through enabling compliance for your workspace. It captures a few essentials used throughout your policies and attestations:

<Frame caption="The AutoComply guided setup — a conversational assistant that enables compliance and captures your organization details.">
  <img src="https://mintcdn.com/osto/cnHEjTD9QY3tscQi/images/compliance/autocomply-setup.jpg?fit=max&auto=format&n=cnHEjTD9QY3tscQi&q=85&s=0ce6dd619cb1239a48296922704f3a27" alt="Compliance guided setup assistant asking for the organization's legal name" width="1470" height="716" data-path="images/compliance/autocomply-setup.jpg" />
</Frame>

1. **Enable compliance** for your workspace.
2. **Organization legal name** — exactly as it should appear on contracts and audit documents.
3. **Default policy author** — chosen from your workspace admins; listed as the author on generated policies.
4. **Policy logo** — branding for generated documents.
5. **Activate your first framework**.

<Note>
  Everything you enter during setup can be edited later under **Compliance → Settings**.
</Note>

Once setup completes, Compliance expands into the full AutoComply console, with sections for Frameworks, Policies, Tasks, Awareness Training, and Settings. A role switcher in the top-right toggles between the **Admin** console and the **Employee** self-service view.

## Frameworks

The **Frameworks** page lists the compliance standards you can work toward. **SOC 2 Type II** is available to activate today; others — CCPA, FedRAMP, GDPR, HIPAA, ISO 27001:2022, ISO 42001:2023, and PCI-DSS v4.0 — are on the roadmap and marked *Coming soon*.

<Frame caption="Frameworks — SOC 2 Type II is active; more standards are on the roadmap.">
  <img src="https://mintcdn.com/osto/cnHEjTD9QY3tscQi/images/compliance/autocomply-frameworks.jpg?fit=max&auto=format&n=cnHEjTD9QY3tscQi&q=85&s=e15b9666a4d4144d924a68ad7ede669f" alt="Frameworks page showing SOC 2 Type II active and other standards marked coming soon" width="2940" height="1544" data-path="images/compliance/autocomply-frameworks.jpg" />
</Frame>

Select **View compliance status** on an active framework to open its requirements:

<Frame caption="A framework's requirements — controls grouped by criterion, each tracked to completion.">
  <img src="https://mintcdn.com/osto/cnHEjTD9QY3tscQi/images/compliance/autocomply-framework-detail.jpg?fit=max&auto=format&n=cnHEjTD9QY3tscQi&q=85&s=8a0101334906df784ada1cb28892e81d" alt="SOC 2 requirements page with an overview of requirements and controls and a list of controls by criterion" width="2940" height="1544" data-path="images/compliance/autocomply-framework-detail.jpg" />
</Frame>

The detail view summarizes the framework's **requirements** and **controls** with how many are completed, partial, or pending, and lets you filter by status or search. Each requirement (mapped to its criterion) lists the controls that satisfy it, and you can **add a control** where needed.

## Policies

The **Policies** page is your library of company policies, pre-mapped to your active framework. Each policy moves through a workflow — **Not started → Draft → Needs approval → Approved** — and the summary counts show where everything stands.

<Frame caption="Company Policies — a framework-mapped library with an approval workflow.">
  <img src="https://mintcdn.com/osto/cnHEjTD9QY3tscQi/images/compliance/autocomply-policies.jpg?fit=max&auto=format&n=cnHEjTD9QY3tscQi&q=85&s=9639aea296fcaec28e3569111c0419d7" alt="Company Policies page listing policies with status, framework, and Setup now actions" width="2940" height="1544" data-path="images/compliance/autocomply-policies.jpg" />
</Frame>

Use **Generate Policies** to draft them from Osto's templates (populated with your organization details), filter by framework, and **Setup now** on any row to work through a single policy. The table shows each policy's **status** and **framework**.

## Tasks

The **Tasks** page is your compliance pipeline — the concrete to-dos that move you toward audit-readiness.

<Frame caption="Compliance Tasks — automated and manual to-dos tracked by status and category.">
  <img src="https://mintcdn.com/osto/cnHEjTD9QY3tscQi/images/compliance/autocomply-tasks.jpg?fit=max&auto=format&n=cnHEjTD9QY3tscQi&q=85&s=fd52ce1c92d552ccd8366b8c7a54513a" alt="Compliance Tasks page with status and type breakdowns and a filterable task list" width="2940" height="1544" data-path="images/compliance/autocomply-tasks.jpg" />
</Frame>

Tasks are summarized **by status** (Open, In progress, Done, Failing) and **by type** (Automated vs. Manual). **Automated** tasks are checked by Osto from the platform itself (for example, WAF/WAAP protection, DLP policies, endpoint screen lock, TLS certificates); **manual** tasks are evidence you record yourself (risk assessments, HR documentation, audits). Filter by status, category, or type, and **Sync** to refresh automated checks.

## Awareness Training

AutoComply includes a full **security awareness training** module so you can satisfy the "train your people" controls every framework requires — build programs from a starter pack, assign them to employees, and track completion. It's a feature in its own right:

<Card title="Awareness Training" icon="graduation-cap" href="/how-to-guides/compliance/awareness-training">
  Build training programs and modules, assign them to employees, and track completion — plus the employee self-service experience for completing training and acknowledging policies.
</Card>

## Settings

**Settings** holds the organization details captured during setup — used to populate policy templates and attestations — plus your policy logo.

<Frame caption="Compliance Settings — organization details and policy logo used across generated documents.">
  <img src="https://mintcdn.com/osto/cnHEjTD9QY3tscQi/images/compliance/autocomply-settings.jpg?fit=max&auto=format&n=cnHEjTD9QY3tscQi&q=85&s=4c16867606e1f97381fa90dc90ce0c8f" alt="Compliance Settings page with organization details and a policy logo upload" width="2940" height="1544" data-path="images/compliance/autocomply-settings.jpg" />
</Frame>

Under **Organisation Details** you can edit your legal name, company domain, industry, country, website, default policy author and approver, and default review frequency. Under **Policy Logo**, upload the logo that appears on generated documents. These values flow into every policy and report AutoComply produces.
