You inherit 50+ controls the day we operate your environment.
Checking a control is not operating it.
Compliance automation platforms are good at one thing: confirming that a configuration matches a rule. That is useful, and it is not the work. Someone still has to operate the control, and fix what the check finds.
When we operate your environment, a large share of those obligations are satisfied by work we already run, and the evidence is a by-product of doing it, not a screenshot of a green checkmark. That is compliance built into operations rather than bolted on top. See how it becomes an audit-ready program, then read the map below to see which control families move onto our side of the line.
What control inheritance means
Three ideas, in the language a buyer or an auditor already uses.
Shared responsibility
Every framework, and every cloud platform, splits obligations between you and whoever operates the layer beneath you. Your cloud provider secures the data center; whoever runs your identity, devices, and tenants owns the controls above it. The more of that we operate, the more of the obligation is ours.
Complementary user entity controls
When a provider hands you a SOC 2 report, it lists complementary user entity controls (CUECs): the things you still have to do for the provider's controls to hold. Normally that list is yours to run. When we operate your environment, we run much of it for you, and we make the split explicit so your auditor is not left guessing.
Evidence from operation
Proof that comes from running the control, not a picture of a passing check. Change records, access reviews, ticket history, and logs are by-products of the work we already do. That is the kind of evidence that survives an enterprise vendor security review.
The control map
See which SOC 2 controls move onto our side of the line when we operate your environment, and where the responsibility stays with you.
We run this control as part of operating your environment; the evidence is a by-product of the work.
We operate our portion and document the rest, which stays with your team or your cloud providers.
This stays with your leadership or your business processes; we support it, but we do not own it.
Ownership reflects how we typically operate; your exact split is confirmed during scoping.
SOC 2
All 51 Trust Services Criteria across the five categories (AICPA), grouped by domain.
38 of the 51 criteria move onto our side of the line when we operate your environment; the 13 that stay with you are governance and business-process decisions no operator can hold for you.
Tags reflect how we typically operate when we run your identity, endpoints, cloud, logging and detection, backups, change management, and vendor register. Domains that stay entirely with you are collapsed; open one to see the detail.
CC1 Control environment
5 Yours
CC1 Control environment
5 YoursCC1.1 Commitment to Integrity and Ethical Values
YoursYour leadership sets the tone, the code of conduct, and the ethical expectations for the business; that ownership stays with you.
CC1.2 Board Independence and Oversight
YoursBoard or ownership oversight of your control environment is a governance role only you can hold.
CC1.3 Organizational Structure and Authorities
YoursHow you structure roles, authority, and reporting lines is a decision for your leadership.
CC1.4 Commitment to Competent Personnel
YoursHiring, evaluating, and developing your people stays with you; once roles are defined, we operate the access that follows.
CC1.5 Accountability for Internal Controls
YoursHolding individuals accountable for their control responsibilities is a management function you retain.
CC2 Communication and information
3 SharedCC2.1 Use of Relevant Quality Information
SharedWe supply operational data, logs, and reporting from the systems we run; deciding what information your objectives need stays shared.
CC2.2 Internal Communication of Information
SharedWe document and communicate the controls we operate to your team; communicating your own policies internally stays with you.
CC2.3 External Communication
SharedWe produce the operational evidence external parties ask for; what you tell customers and regulators is yours to own.
CC3 Risk assessment
2 Shared2 YoursCC3.1 Specification of Objectives
YoursSetting your business and compliance objectives is a leadership decision that frames everything beneath it.
CC3.2 Risk Identification and Analysis
SharedWe identify and track technical and operational risk in the environment we run; business and strategic risk you weigh together with us.
CC3.3 Fraud Risk Consideration
YoursAssessing fraud risk across your business processes stays with your leadership and finance functions.
CC3.4 Impact of Changes on Internal Control
SharedWe assess how infrastructure and tooling changes affect controls; organizational and business-model changes you assess with us.
CC4 Monitoring activities
2 SharedCC4.1 Ongoing and Separate Evaluations
SharedWe run continuous monitoring and produce evidence from the systems we operate; independent oversight of the program stays with you.
Replaces a compliance-automation platform's evidence collector.
CC4.2 Communication of Deficiencies
SharedWe surface and route the deficiencies our monitoring finds; how they are escalated and remediated across the business stays shared.
CC5 Control activities
1 We operate2 SharedCC5.1 Control Activity Selection and Development
SharedWe design and run the technical controls in scope; selecting controls for risks outside the environment we operate stays shared.
CC5.2 General Technology Controls
We operateWe operate the general technology controls behind your systems: access, change, and operations management across the platforms we run.
CC5.3 Policies and Procedures
SharedWe provide and version the policies for the operations we run; adopting and enforcing them across your organization stays shared.
Replaces a policy-template subscription.
CC6 Logical and physical access
7 We operate1 SharedCC6.1 Logical Access Security
We operateWe operate identity, single sign-on, and multi-factor enforcement across the tenants and systems we manage.
Replaces a standalone SSO/MFA product.
CC6.2 User Registration and Authorization
We operateWe run joiner and mover provisioning so access is granted only through an authorized, documented request.
Replaces a separate identity-governance tool.
CC6.3 Role-Based Access Management
We operateWe operate role-based access and least-privilege reviews across the systems we manage.
CC6.4 Physical Access Restrictions
SharedDevice-level access controls we operate; data-center and facility access inherits from your cloud providers.
CC6.5 Asset Decommissioning Protections
We operateWe handle secure deprovisioning and data removal when devices and accounts are retired.
CC6.6 External Threat Protection
We operateWe operate the boundary protections, DNS and edge security, and hardening that keep external threats out.
CC6.7 Data Transmission Controls
We operateWe enforce encryption in transit and controlled transfer across the systems we manage.
CC6.8 Malicious Software Prevention
We operateWe run managed endpoint detection and response and malware prevention on the devices we manage, on the endpoint tooling already in your Microsoft 365 licensing.
CC7 System operations
5 We operateCC7.1 Vulnerability Detection and Monitoring
We operateWe run vulnerability detection and configuration monitoring across the environment we operate.
Replaces a standalone vulnerability scanner.
CC7.2 Anomaly Monitoring
We operateWe centralize logging and monitor for anomalies through managed detection on the systems we run.
Replaces a separate SIEM or log-retention service.
CC7.3 Security Event Evaluation
We operateWe triage and evaluate security events to separate a real incident from noise.
CC7.4 Incident Response Program
We operateWe run the incident-response program: detection, containment, and coordinated response for the environment we operate.
Replaces a separate incident-response retainer.
CC7.5 Incident Recovery
We operateWe restore service and data through the recovery processes we operate after an incident.
CC8 Change management
1 We operateCC8.1 Change Authorization and Implementation
We operateWe operate authorized, tracked change management for the systems we run, with the change record itself as evidence.
Replaces a separate change-management tool.
CC9 Risk mitigation
2 SharedCC9.1 Business Disruption Risk Mitigation
SharedWe operate the backup, recovery, and continuity controls for the environment we run; continuity planning across the business stays shared.
CC9.2 Vendor and Partner Risk Management
SharedWe maintain the vendor register and review the technology suppliers we manage; risk decisions on your own vendors stay shared.
Replaces a standalone vendor-risk (TPRM) tool.
A1 Availability
2 We operate1 SharedA1.1 Processing Capacity Management
SharedWe monitor and manage capacity for the infrastructure we operate; forecasting demand for your own applications stays shared.
A1.2 Environmental and Backup Protections
We operateWe operate backup, environmental monitoring, and recovery protections for the systems we manage.
Replaces a standalone backup/DR service.
A1.3 Recovery Plan Testing
We operateWe run and document recovery testing for the environment we operate, so the plan is proven rather than assumed.
C1 Confidentiality
2 SharedC1.1 Confidential Information Identification
SharedWe enforce handling and access controls for confidential data on the systems we run; classifying what counts as confidential stays with you.
C1.2 Confidential Information Disposal
SharedWe operate secure disposal on the media and systems we manage; disposal in systems outside our scope stays shared.
PI1 Processing integrity
5 SharedPI1.1 Processing Information Quality
SharedWe operate the controls around the platforms that carry your data; the correctness of your application logic stays with your product team.
PI1.2 System Input Controls
SharedWe secure and monitor the systems that receive input; validating your business inputs stays with your team.
PI1.3 System Processing Controls
SharedWe operate infrastructure and access controls around processing; the accuracy of your processing logic stays yours.
PI1.4 System Output Controls
SharedWe control access to and delivery of system output; verifying output against your business rules stays shared.
PI1.5 Storage Controls
SharedWe operate storage access, encryption, and backup on the systems we manage; data-model correctness stays with your team.
P1 Privacy
2 Shared6 YoursP1.1 Privacy Notice
YoursYour privacy notice, and how you describe your data practices, is yours to author and publish.
P1.2 Choice and Consent
YoursCollecting and honoring consent choices is a business-process decision you own.
P1.3 Collection of Personal Information
YoursWhat personal information you collect, and why, is a decision for your business.
P1.4 Use of Personal Information
YoursUsing personal information in line with your stated purposes stays with your team.
P1.5 Retention of Personal Information
YoursSetting retention periods and disposal timelines for personal information is a policy decision your business owns.
P1.6 Data Subject Access
SharedWe help fulfill access and deletion requests on the systems we operate; verifying identity and approving each request stays with your team.
P1.7 Third-Party Disclosure
YoursDeciding which third parties receive personal information, and under what terms, is a business decision you own.
P1.8 Breach Notification
SharedWe detect, contain, and provide the forensic record when an incident touches personal data; the notification decision and communications stay with your team and counsel.
The 51 items in the SOC 2 view are the Trust Services Criteria themselves, the public structure every report maps to. The specific controls you implement against them, and the exact ownership split, are finalized against your scope during onboarding.
Sources: AICPA Trust Services Criteria (SOC 2). This is a public framework structure; the specific controls in your report are unique to your organization, and nothing here represents a Cloud Sentry certification.
A failing check comes with the person who fixes it.
A tool can tell you a control has drifted. It cannot operate the control, and it cannot close the gap; that work still lands on someone. Reviewers are also getting sharper about evidence that was assembled to pass a check rather than produced by doing the work.
Because our evidence is a by-product of operating your environment, it holds up. And a failing check is not a notification you are left to chase; it comes with an accountable operator whose job is to fix it.
A compliance platform
Flags the gap on a dashboard. Closing it is left to you.
An audit-mill report
Looks clean the day it ships, then ages badly under enterprise vendor review.
Cloud Sentry
Evidence is generated by operating the control, and every failing check routes to a named operator who fixes it.
Proof on demand
The evidence, ready when the reviewer asks.
The controls we operate generate their own proof, and it lives in the platform. When a buyer or an auditor asks, you share a scoped, time-bounded view through the Evidence Vault: no account for them to create, and every view logged.
See where the line falls for you.
Read the published plan structure, or walk the whole operated partnership.
Published structure with a written annual escalator cap, and an entry rung you can start today. Read what each tier covers before anyone calls you.
The whole function run end to end, with the controls, the evidence, and one accountable lead who answers for the outcome.