Compliance Shouldn't Be Something You Check On - It Should Watch Itself

PAM-Pro Compliance Dashboard showing a live compliance score of 41 out of 100, Non-Compliant, above a violations banner listing an unlocked audit log, seven overdue rotations, and one unmanaged account

A few weeks ago I wrote about mapping PAM-Pro's evidence to what cyber insurance underwriters actually verify - rotation logs, MFA enforcement records, immutable audit trails. That mapping worked because the platform could produce a report on demand. What it couldn't do was tell you, unprompted, that something had drifted out of compliance since the last time you asked. Compliance was a document you generated, not a thing the system watched.

That's the gap 3.12 closes. Compliance in PAM-Pro is no longer point-in-time. It's continuous.

A Score That Means Something

The Compliance Dashboard now carries a live 0-100 score, computed across four measured controls: credential rotation coverage (checked against each account's own effective policy window, not a single global number), audit log immutability (only counted when it's actually locked - a reversible WORM policy isn't evidence of anything), managed account coverage, and a hard check on critical-account rotation. If a control can't be measured for your tenant, it's excluded from the score entirely rather than counted against you - a compliance number that penalizes you for data it doesn't have isn't trustworthy, and I wasn't willing to ship one.

That decision created its own problem, which only became obvious once the score was on a dashboard instead of in my head: a tenant whose only measurable control was the small one could score a mathematically correct 100 while two-thirds of what the score is supposed to cover went unassessed. That's not a compliant tenant, it's an unmeasured one, and the two shouldn't look the same. Below a minimum coverage threshold, the score now reads "Provisional" instead of "Compliant," no matter what the arithmetic says. An auditor-facing number is worth less than nothing if it can be green for the wrong reason.

Compliance Score card showing a Provisional 100 out of 100 with only 13 percent of the control set measured, and three of four controls marked Not measured

Violations, Not Just a Grade

A single number tells you how you're doing. It doesn't tell you what to fix. Alongside the score, PAM-Pro now detects violations directly - the specific accounts and controls currently out of policy, with drill-down into what each control checks, its current value, and the accounts it flagged, resolved to names you'll recognize rather than internal identifiers.

And because nobody wants an inbox that re-alerts on the same unresolved issue every single day, violation alerts only fire on what's genuinely new since the last check. An account that's been overdue for rotation for two weeks generated one email, not fourteen.

Reports That Show Up Without Being Asked

The evidence PDF that used to require someone to remember to generate it can now be scheduled - delivered to your compliance contact on a recurring cadence, same document, same content, no manual export step. Paired with a score history trend, you get a record of your posture over time instead of a single snapshot each time someone thinks to check.

Compliance Trend chart showing daily score snapshots climbing from the low 60s toward 90 over 30 days, with a gap where no control could be measured rendered as a break in the line rather than a drop to zero
Compliance tooling that only speaks when spoken to isn't monitoring anything. It's a form you fill out.

Also in This Release

Hybrid customers get a new Domain Inventory in Settings, grouping every discovered Active Directory domain by identity, naming which Entra tenants it appears in and which verified UPN suffixes were seen on it. It surfaced a real gap while I was building it: an account that loses live directory sync but keeps its on-premises identity data could previously be misreported as cloud-native - telling an admin a password reset would land in the cloud when it would never reach Active Directory at all. That's now flagged explicitly rather than silently wrong, and I'd rather it show up in a changelog than in an incident report.

Domain Inventory panel listing discovered Active Directory domains by origin, including a domain flagged Sync Off where directory sync is no longer active for its accounts

Full details, including everything fixed and hardened this cycle, are in the release notes.

Why This Matters More Than It Sounds Like It Should

The pattern behind both the underwriting mapping and this release is the same: the honest version of "we're compliant" is never a claim, it's a measurement, and a measurement is only trustworthy if it can also tell you when it doesn't know something. A dashboard that watches your posture between the moments you think to look at it is worth more than a report you remembered to run. That's the version I wanted PAM-Pro to be, and as of 3.12, it is.

© 2026 Huntoso LLC. All rights reserved.