Skip to content

Solutions / Use case

Compliance automation, from policy to audit evidence.

Every control runs across HR, identity, business apps and engineering tools. When those systems don't talk, access reviews live in spreadsheets, deletion requests miss a system and evidence gets gathered the month before the audit. Tray.ai runs the recurring work and keeps the record, so the audit starts with the evidence already there.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

Jump to the stages
One quarterly access review running end to end: all 214 NetSuite accounts pulled, matched to people in Workday with two leavers found, all nine reviewers answering in Slack, six accounts removed through Okta, the removals confirmed in NetSuite, and the evidence attached to the control in Drata.

The short answer

What is compliance automation?

Compliance automation is running the recurring work behind privacy and security controls, and keeping the evidence it produces: policy acknowledgements, user access reviews, change approvals, consent, data subject requests, retention, and the audit evidence that shows each one ran. It runs across HR, identity, business apps, engineering tools and the compliance tool, and most gaps open in the handoffs between them. Automation makes the controls run on schedule and leaves a record. Whether they meet a framework is still your auditor's call.

  1. 1 Accept policies
  2. 2 Review access
  3. 3 Change review
  4. 4 Honour consent
  5. 5 Answer requests
  6. 6 Delete old data
  7. 7 Collect evidence
Type 2 audited every year, covering the whole platform on every plan
SOC 1 & 2
Gartner Hype Cycles in 2026
14
Willingness to Recommend, 2026 Gartner Voice of the Customer
97%
connectors, from Okta and Workday to Drata and Snowflake
700+

The compliance automation process, stage by stage

Seven stages, each with what breaks and a how-to guide for building it.

  1. 1

    Policy acknowledgement

    Everyone accepts the policies that apply to their role, from their start date, and accepts again when a policy changes.

    Where it breaks: A joiner from March has never accepted the security policy, because the last round went out in January.

  2. 2

    User access review

    Every quarter, the people with access to each in-scope app are checked by someone who knows whether they still need it.

    Where it breaks: The review comes from the identity provider, so the admin account created by hand inside the ERP is never on it.

  3. 3

    Change approval

    Every change to production has a ticket, a reviewer who did not write it and tests that passed.

    Where it breaks: A pull request approved before its last commit ships a change nobody reviewed.

  4. 4

    Consent and preferences

    One system holds each person's consent, and a withdrawal reaches every tool that contacts them within seconds.

    Where it breaks: Someone unsubscribes, and the sales tool emails them nine days later because it never heard.

  5. 5

    Data subject requests

    Access and deletion requests are verified, searched across every system that holds personal data, and answered on time.

    Where it breaks: The search covers the systems somebody remembered, and the support tool with years of tickets is not one of them.

  6. 6

    Retention and deletion

    Records past the period the policy allows are found, checked for holds, and deleted in the source and every copy.

    Where it breaks: The help desk is cleaned up, and the warehouse still holds every ticket since 2016.

  7. 7

    Audit evidence

    Each control's evidence is collected on its own schedule, with its date and source, and gaps reach the owner that week.

    Where it breaks: Evidence gathered in the six weeks before the audit shows the controls in those six weeks only.

Three ways to connect the systems

  • The compliance tool’s own integrations. Good at reading settings, such as whether multi-factor sign-in is required. A settings check never removes anyone’s access, searches a support tool for a deletion request or deletes a record past its date.
  • Scripts and spreadsheets. Full control, and your team owns the fixes, the schedule and the evidence for as long as they run, and the evidence is whatever the script remembered to log.
  • An integration platform. Every control’s workflow in one place, with the same error handling, logging and access control, and a record of every run your auditor can sample. This is Tray.ai: compliance and privacy teams maintain the rules, IT governs them.

The metrics compliance automation moves

What compliance, privacy and security teams measure, and which stage each number depends on.

Policy acceptance coverage
Share of current staff who have accepted the current version of every policy that applies to them.
What moves it Assigning policies from the HRIS on the start date, and again when a policy changes. How to build policy attestation tracking 
Accounts with no owner
Accounts in in-scope apps with no current employee or named owner behind them.
What moves it Pulling accounts from each app and matching every one to a person before the review starts. How to build a user access review 
Changes with full evidence
Share of production changes with a ticket, an approval from someone other than the author and passing tests.
What moves it Checking each change as it ships and flagging any gap to its author the same day. How to build change approval evidence 
Request response time
Days from a data subject request arriving to the response going out, against the legal deadline.
What moves it Starting the clock at receipt and searching from the list of systems that hold personal data. How to build data subject request automation 
Records past retention
Records still held after the period the retention schedule allows, by system.
What moves it Running the schedule as rules per system, with legal holds checked before every run. How to build data retention enforcement 
Open evidence gaps
Controls with missing or failing evidence for the current period.
What moves it Collecting evidence on each control's schedule and sending gaps to the owner the week they open. How to build audit evidence collection 

Compliance automation connectors

The systems compliance automation runs on, grouped by the seat each one fills. Each links to its connector page.

Compliance and ticketing

Where controls are tracked, evidence is gathered and gaps are assigned.

Identity and HR

Where people, roles and access are recorded, and where most access controls are proven.

Apps that hold personal data

Where consent, requests and retention rules have to reach.

Engineering and cloud

Where changes are reviewed and shipped, and where infrastructure settings are read.

Documents and policies

Where policies are versioned and documents fall under the retention schedule.

Collaboration

Where reviewers, owners and approvers are asked and reminded.

Data and reporting

Where evidence, decisions and deletions are kept for the audit period.

Anything not listed connects through the full connector library, or directly through its API.

Processes next to compliance

These produce evidence or share systems with compliance automation without being stages of it.

IT and security

How to build access request and approval

Route to the system owner, grant with an expiry by default, provision automatically, and produce the access review as a by-product. The prompts that build it.

People operations

How to build employee offboarding deprovisioning

Revoke on the leave date, cover every system instead of the ones you remember, transfer what they owned, and prove it. The Headless prompts that build it.

People operations

How to build a training completion sync

Assign from role rather than a spreadsheet, carry completions into the HRIS, and produce evidence per person instead of a percentage. The Headless prompts.

Legal and compliance

How to build vendor security review

Tier on what the vendor can reach, ask questions that match the tier, track conditions to closure, and re-review before the evidence expires. The prompts.

IT and security

How to build security alert triage

Enrich before a human sees it, suppress the known-benign, escalate on asset value, and measure what you closed rather than what fired. The prompts.

IT and security

How to build vulnerability to ticket routing

Rank on exploitability and exposure rather than CVSS, group by fix instead of by finding, and route to whoever ships the patch. The prompts that build it.

Legal and compliance

How to build a contract lifecycle sync

Extract the obligations rather than storing a PDF, put renewal and notice dates where somebody will see them, and never let the signed version drift. The prompts.

Frequently asked questions

Does compliance automation make us SOC 2 or GDPR compliant?

+

No. Whether your controls meet a framework is a judgement your auditor or regulator makes. Automation makes the controls run on time, removes what a review says should go, and keeps the evidence, which is usually the part an audit finds missing.

How is this different from a compliance tool like Drata?

+

A compliance tool tracks your controls, reads settings from connected systems and holds the evidence. Tray.ai runs the work around it that a settings check can't do, such as removing access after a review, searching every system for a data subject request and deleting records past their date, and sends the evidence back to the compliance tool.

Which systems does Tray.ai connect in compliance automation?

+

Compliance and ticketing (Drata, Jira, ServiceNow), identity and HR (Okta, Azure Active Directory, JumpCloud, Workday, BambooHR), the apps that hold personal data (Salesforce, HubSpot, Zendesk, Marketo, Outreach, Braze, NetSuite), engineering and cloud (GitHub, GitLab, Azure DevOps, Datadog, Splunk), and the document stores, chat and warehouse around them. Anything without a connector connects through its API.

Is Tray.ai itself audited?

+

Yes. Tray.ai is audited for SOC 1 and SOC 2 Type 2 every year, and both reports cover the whole platform on every plan. The reports are available through the Tray.ai trust center. They cover Tray.ai's own controls. Your controls are still yours, and your auditor still tests them.

Can compliance and privacy teams run this without engineering?

+

Yes. The apps in scope, review rules, retention schedule and control map open in Tray Build, the visual canvas, so compliance and privacy change them as policy changes. IT governs the credentials and who can change what.

Where do AI agents fit in compliance automation?

+

In the reading and the sorting. Agents can find personal data in free-text support tickets during a request, summarize why a change skipped review, and draft the explanation for an evidence gap for its owner to check. Removing access and deleting records run on fixed rules, with a person approving where the guide says so.

Do we have to replace our compliance tool or identity provider?

+

No. Tray.ai connects the systems you already run and carries the data between them. The stages above describe the work and the evidence, not which tools you use.

Last reviewed 2 October 2026.

See compliance automation running on your stack.

Walk through your systems and stages with a Tray.ai expert.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

Browse the how-to guides