Skip to main content

Create, Edit, and Manage Controls (New Experience)

Updated this week

💡 Still using the classic Drata experience? Refer to Controls: Manage Control Details and Mappings, Edit a Control, or Create a Control for the original UI.

Overview

Controls implement and articulate the policies, processes, and activities your organization uses to meet compliance requirements.

In Drata, you can:

  • Create custom controls to meet specific needs.

  • Map controls to framework requirements.

  • Link evidence (policies, reports, external files).

  • Edit both Drata Common Framework (DCF) controls and your custom controls.

  • Assign control owners and approvers.

  • Add internal notes, tickets and tasks for context, collaboration, and management.

Prerequisites

  • Only Administrators and the Information Security Lead can create, edit, and annotate controls.

  • Control owners can be Administrators, Information Security Leads, Control Managers, or Workspace Managers.

  • Workspace Managers with read-only access cannot be control owners.

Create a Control

Goal: Add a custom control to meet compliance needs.

  1. Go to the Controls page.

  2. Select Create Control < Create a single control.

  3. In the Create control, complete required fields:

    • Name (required)

    • Code (required; supports letters, numbers, and symbols)

    • Description (required)

  4. Map the control to one or more framework requirements.

  5. Map the control to additional objects:

    • One or more framework requirements, automated tests, evidences, and policies

  6. Select Save to create the control.

To learn how to add or update in bulk, go to Import or Update Controls in Bulk.

Edit a Control

Goal: Update existing DCF or custom controls.

  1. Go to the Controls page.

  2. Select a control to open its detail page.

  3. Select the Edit icon on Info section.

  4. Update required and optional fields:

    • Name (required)

    • Code (required, but only editable for custom controls)

    • Description (required)

    • Question (optional)

    • Activities (optional)

  5. Select Save.

After saving:

  • Select See all updates to open the Events page and view full history.

Assign or Remove Control Owners

Goal: Manage responsibility for controls.

  • Control owners ensure evidence is linked, automated tests pass, and controls are audit-ready.

  • Owners can be assigned from the control detail page or the control list view on the Controls page.

Assign an Owner

  1. Open a control’s detail page

  2. In the Control Owners section, click assign and select a person to assign them.

Remove an Owner

  1. Open a control’s detail page

  2. In the Control Owners section, select the X on the owner pill.

Bulk Assignment or Removal

  1. From the Controls page, select one or more controls.

  2. Select the Assign/remove control owners in the grey bar to open the modal.

  3. Assign or remove control owners:

    • Assign: Add new owners to all selected controls.

    • Remove: Remove owners from all controls where the owner exists by selecting the X on the owner pill.

  4. Confirm to save changes and close the modal.

Annotate a Control

Goal: Add internal notes, tickets, and tasks for control management.

  1. Open a control detail page and the utilities panel within it.

  2. Add, edit or delete notes in the Internal Notes section.


  3. You can also create tickets from the panel.

  4. Create tasks from the panel.

Notes / Troubleshooting

  • Scope requirement: Controls must be mapped to at least one requirement.

  • Evidence: Add or remove evidence at any time.

  • Control codes: Editable only for custom controls, not DCF controls.

  • History tracking: All updates are logged in the Events page.

  • Owner eligibility: Owners must hold a qualifying role. If a user’s role is removed, or they are marked “Former Employee/Contractor,” they are no longer a control owner.

  • Filtering: Filter controls by owner in the list view to find controls quickly.

  • Exports: Owners are included in CSV downloads in the Control Owners column.

Did this answer your question?