Policies

Policies are the control catalog; frameworks are the lens on top of it

Underneath every framework is the same catalog of policies. Reading adherence at the policy level explains exactly which control failed and where, instead of stopping at a framework-level pass or fail.

Blog

August 17, 2026 · 9 min read

01

Policies with the least adherence, surfaced first

The Dashboard already surfaces which policies have the lowest adherence across a third party's connected accounts. The Policies view is where a reviewer goes to see exactly why: which resources fail the policy, and in which account.

Policies: adherence per policy across connected accounts, with the least-compliant policies surfaced.
Policies: adherence per policy across connected accounts, with the least-compliant policies surfaced.
02

From policy to violation to source

The violations view traces a policy failure back to its source: which scan target, which resource, and which policy engine rule fired. That traceability is what lets a single fix close a violation that was affecting several frameworks simultaneously.

  • Adherence tracked per policy, not only per framework
  • Violation detail down to the affected resource and account
  • One fixed policy can clear violations across several frameworks at once
Policies — Violations: sources feeding the policy engine, mapped through to open or resolved violations.
Policies — Violations: sources feeding the policy engine, mapped through to open or resolved violations.
1stone Research

Talk to the team about a third-party program

A working session against your actual third-party portfolio: how workspaces are created, which accounts get connected first, and what the Security Score looks like in week one.

Request a walkthrough