Agent templatesCompliance
Workflow template
Compliance / setup guide

Make your review process ready for scrutiny.

The Compliance agent template is for enterprise compliance, security, and operations teams that need to organize evidence, test controls, and route findings for human review. It is a preparation and certification workflow—not a promise of automatic regulatory compliance.

The certification lens
A reviewer should be able to answer these three questions without guesswork.
What is in scope?
What evidence supports it?
What changed since last review?

01 / Before you start

Bring the context your reviewer will need.

Good certification starts with a well-defined operating context. Have these pieces ready before you configure the template.

Setup requirements

The agent can help structure the work, but your team supplies the authority, scope, and source-of-truth material.

01

An enterprise account

A Modelab enterprise workspace where the template can be configured and reviewed.

02

Named owner and reviewer

One person accountable for the package, plus a reviewer who can approve the result.

03

A target deployment environment

The cloud or internal environment where the workflow will be run and tested.

04

Applicable frameworks and policies

The controls, internal policies, and external frameworks that define your scope.

05

Data classification and retention rules

A clear description of what data may be used, retained, or excluded from the workflow.

06

Approved sources and representative tests

Source locations and test cases that reflect the work the agent will perform in practice.

02 / The setup sequence

Six moves from scope to handoff.

Keep each step reviewable. If a decision cannot be explained, it is not ready to be part of the certification package.

  1. 01

    Define scope and controls

    Write down the workflow boundary, the policies it should check, and the outcomes that count as acceptable.

  2. 02

    Connect approved inputs

    Identify the allowed source locations and connect only the documents, exports, and artifacts in scope.

  3. 03

    Configure review and approval rules

    Set reviewer ownership, escalation paths, approval thresholds, and what happens when a check is inconclusive.

  4. 04

    Run representative tests

    Use a repeatable test set with expected outcomes so reviewers can compare results and spot drift.

  5. 05

    Resolve findings

    Investigate gaps, update the configuration or sources, and close critical findings before handoff.

  6. 06

    Submit the package for certification

    Collect the scope, source list, test results, approvals, and version trail into the review package.

03 / Supported inputs

Start with sources your team already trusts.

Sensitive data should be limited to approved sources and formats. If an input is not supported, convert it to a supported format or discuss the right path with support before connecting it.

Keep sensitive material inside approved locations and follow your organization’s classification and retention rules throughout setup.

01 / Policy library
Policy and control documents

Internal policies, control descriptions, procedures, standards, and framework mappings in approved document formats.

02 / Evidence trail
Evidence and audit artifacts

Audit workpapers, access reviews, logs, tickets, attestations, screenshots, and other traceable evidence.

03 / Structured data
CSV and JSON exports

Structured exports that preserve field names, dates, identifiers, and the context needed to interpret each record.

04 / Review prompts
Test cases and review questions

Representative scenarios, expected answers, edge cases, and reviewer questions that define a reliable outcome.

04 / Certification standard

Certification is a documented handoff, not a green button.

When the checklist is complete, submit the package for review. The certification handoff captures the approved scope, source set, test results, findings, and sign-offs so another person can understand what was evaluated.

Readiness checklist
Confirm each item before requesting certification.

Documented scope

The workflow boundary and applicable controls are explicit.

Current source material

Every source is approved, relevant, and current for the review.

Repeatable test set

Tests include expected outcomes and can be rerun consistently.

Owner and reviewer sign-off

The accountable owner and an independent reviewer have approved the package.

No unresolved critical findings

Critical gaps are resolved or explicitly dispositioned before handoff.

Auditable version and date trail

The package records what changed, when, and which sources were reviewed.

Know when to re-review.

Certification describes a specific version of the workflow. Trigger a re-review when the scope, connected inputs, applicable controls, or approval rules change. A new date and version trail keeps the record honest.

Ready when you are

Put the evidence trail in place before the review starts.

Start with the workflow template, or talk through your sources and certification scope with the Modelab team.