
Understand the Drata Platform
Training videos (login required) and step-by-step guides for all Drata features
190 articles
- Understanding Connections in DrataConnections in Drata integrate your identity, HRIS, infrastructure, and development tools to automate evidence collection and continuously support compliance.
- Integrate Multiple Identity and HRIS ConnectionsIn this article, you learn how to integrate multiple identity and HRIS connections in Drata.
- How Drata Uses HRIS DataThis article explains how Drata connects to HRIS systems, what employee data is accessed, how that data is stored and used, and what options are available if no HRIS integration…
- Multiple MDM Support (New Experience)Connect multiple MDM providers to Drata to monitor devices across systems with automatic syncing and clear data priority rules.
- Partner Connections: Expanding Compliance with External Tools
- Manage connected infrastructure accountsIn this article, you learn how to manage connected infrastructure accounts.
- Manage connected version controlLearn how Drata displays and evaluates version control access, including write access, merge permissions, and MFA status
- Map accounts to personnel in Drata (New Experience)Learn how to map accounts to personnel in Drata, handle service and system accounts and mark accounts out of scope.
- Ad-hoc identity and account resyncLearn how to manually resync identity and account data in Drata to immediately reflect access and personnel changes.
- Connect your HRIS to DrataLearn how to connect HRIS providers to Drata and the available HRIS providers.
- GitHub Access: Should I use my personal account or a new company account?Use your personal GitHub account, but add your work email and set proper notification routing
- GitHub Rulesets IntegrationHow does Drata support GitHub rulesets
- GitLab MFA configurationsGitLab MFA options for GitLab.com and Self-managed
- Allowlist IP Addresses for WAF Configurations
- Mark Controls In or Out of Scope
- Manage Scope and Exclusions in Drata
- Apply Default Mappings for ControlsRestore Drata's default mappings between controls and framework requirements or monitoring tests.
- Create, Edit, and Manage Controls
- Map evidence and policies to controls (New Experience)
- Assess and Manage Individual Controls
- Manage Required Approval and Control ReadinessLearn how to set up, manage, and delete required approvals for controls, and understand how approval stages affect control readiness.
- Manage Notifications for Required Approvals and Control UpdatesSet up and manage notifications to keep control owners and approvers informed about required approvals and control changes.
- Import Controls in Bulk (New Experience)
- Revert a Control to Drata's Latest DCF TemplateRestore a DCF control to Drata's latest published template when the language in your workspace has diverged.
- Export Control-to-Requirement Mappings
- Annotate a ControlAdd internal notes, tickets, and tasks to controls to provide context for your team.
- Early Access for Monitoring and ControlsLearn more about the newest changes for our monitoring tests and controls.
- Monitoring OverviewLearn how to use Monitoring in Drata to review test results and maintain continuous audit readiness.
- Understanding Test Provisioning and the Test Library (New Experience)
- Test Library (New experience)
- Filter and search tests in Monitoring (New Experience)Learn how to filter, search, and narrow tests in Drata’s Monitoring page to quickly find results, review findings, and resolve compliance gaps.
- View and Manage Test Details (New Experience)Learn how to use the test details page in Drata Monitoring to investigate test results, remediate issues, manage exclusions, and understand how tests impact control readiness and compliance.
- Manage Tests in Monitoring PageManage individual and bulk test actions in Drata's Monitoring page, and understand test details including findings, exclusions, history, and controls.
- Enable AI Summaries for TestsEnable and use AI-generated summaries to quickly understand why custom tests failed, and export findings to CSV for analysis or auditor sharing.
- Add tests from the Test Library to a workspace (New Experience)
- Map Tests to ControlsManually map or unmap tests to controls to ensure monitoring results accurately reflect how your controls are implemented.
- Download Audit Evidence for a Custom Test (New Experience)
- Disable a TestDisable a test when it does not apply to your environment or when the control is monitored outside of Drata.
- Exclude Findings from TestsExclude specific items from a compliance test when they do not apply to your organization, and re-include them when needed.
- Exclusions vs. Disabling a Test (Concept Guide)When should you use each option within Drata?
- Excluding Infrastructure resourcesExclusions in Drata let you exclude specific resources or test findings from compliance monitoring to reduce noise, manage audit scope, and focus on relevant evidence.
- Exclusion labels within GCPImplementing exclusion labels for specific resources
- Exclusion tags within AWSImplementing exclusion tags for specific resources
- Exclusion tags within AzureImplementing exclusion tags for specific resources
- Identify and Add Missing Azure Permissions for DrataUnderstand why Drata Azure tests fail and how to add the required Microsoft Graph API and Azure RBAC permissions to restore monitoring.
- Identify and Add Missing AWS Permissions for Drata
- Identify and Add Missing GCP Permissions for Drata
- Resolve SSL/TLS Compliance Testing Issues in Drata
- DratabotHow to verify the Dratabot
- Manually Running a Control TestTests automatically run every evening (PST) in Drata, but you're also able to manually trigger them anytime
- Conditions That Affect 'Fix Now' and 'Test Now' Button VisibilityFix Now and Test Now Button Visibility in Drata Explained
- Evidence OverviewCentralize, manage, and track audit-ready evidence across controls with Drata's Evidence Library.
- Evidence Renewal DateSet and manage renewal dates for evidence to keep controls audit-ready and avoid compliance gaps.
- Create EvidenceAdd and manage evidence in Drata's Evidence Library to support control readiness and audit preparation.
- Add Jira Tickets as EvidenceUse Jira tickets as evidence to demonstrate how compliance and security work is tracked and completed.
- Delete Evidence (New Experience)
- Manually Export Evidence Data from DrataLearn how to manually download evidence from Drata using the Evidence Library, Controls, Event Tracking, or Audit Hub.
- Example Evidence for Not Monitored Controls Linked to Policies
- Drata Evidence Library SyncSync frequently-requested compliance and security documents from Drata's Evidence Library to SafeBase.
- New File Format SupportThis article covers the new file formats supported in Evidence Library, Controls, and RIsk Management.
- Evidence Library: Multiple Artifacts & Multi-File Upload (New Experience)
- Policy Center OverviewUse the Policy Center to manage the policies required for audit readiness and ongoing compliance. From a single place, you can create, edit, review, approve, publish, and track policies throughout…
- Create a policyThis article explains how to create a custom policy and replace an existing Drata template.
- Assigning Policies to Specific GroupsControl which personnel must acknowledge each policy by assigning policies to specific identity provider groups, all personnel, or no personnel.
- View and edit a policyThis article explains who can edit a policy, how to make updates, and how approvals and versioning work in the new experience.
- Add comments in your policyThis article explains when you can comment or edit a policy, how comments work, and how Policy Owners manage edits during reviews.
- Delete a Policy DraftLearn how to delete a policy version in Draft status, including which policy types and versions can be deleted.
- Understanding the Approval ProcessLearn how policy approvals work in Drata, how to configure approvers and tiers, and how to publish a policy once approval is complete.
- Policy Owner Notifications
- Map policies to controls in DrataMapping policies to controls allows Drata to evaluate control readiness and run policy-related compliance tests.
- Manage policy renewals
- Download your Policies
- Archive and restore policiesThis article explains when policies can be archived, why some policies can’t be archived, and how to restore archived or replaced policies.
- External Policy: Use BambooHR to manage your policiesUse this workflow if your organization manages policies and acknowledgments in BambooHR and uses Drata for audit evidence and control mapping.
- External Policy: Use Confluence or Notion to manage your policiesUse this workflow if your organization manages policy content in Confluence or Notion and uses Drata as the system of record for audit evidence and control mapping.
- Managing Policies Synced from Confluence in Drata
- Manage and Configure Policy Controls in Drata
- Creating an SLA for Employee Onboarding CompletionUse this article to understand and configure the onboarding grace period that determines when compliance tests begin evaluating new personnel.
- AI-powered control suggestions for policiesUse AI suggestions to map policies to controls, reduce manual work, and keep compliance mappings accurate and up to date.
- Configure Policies to Support Compliance Test Completion in Drata
- Linking directly to specific employee security policiesEmbedding links to Drata policies in other tools or locations
- Common Policy Management Issues in Drata (and How to Resolve Them)
- Compare Policy Versions with AI
- Troubleshoot Blank Version History in Downloaded Policy PDFsThis article applies when an existing published policy downloads with a blank version history table.
- General AI Policy
- Personnel OverviewLearn how to navigate Drata’s Personnel page, filter and view employee compliance data, and export records for audit readiness.
- Populating and Managing Personnel Data in Drata (Concept Guide)How Drata uses data from your HRIS to supplement personnel information
- Identity sync updates in DrataUnderstand when personnel, user, and device changes will show in Drata
- Confirm your personnelConfirm personnel hold the correct status in Drata
- Mark personnel as Out of Scope (New Experience)
- Personnel exclusionsCreate and manage personnel exclusions to document approved compliance exceptions while keeping users in audit scope.
- Bulk Import Personnel Training Records (New Experience)Upload training completion records for multiple personnel at once using a CSV or Excel file.
- Bulk Import Personnel Background Checks (New Experience)Upload completed background checks for multiple personnel at once using a CSV file, instead of updating each record individually.
- Send reminder email to personnelUse this article to send reminders to personnel who haven’t completed required onboarding items in Drata.
- Reset recurring personnel trainingsReset configure recurring reset schedules. Some trainings must be completed on a recurring basis (such as Security Awareness, HIPAA, or AI Awareness) to maintain compliance and demonstrate ongoing security awareness.
- Resume IdP and HRIS syncs for personnelUse this article to resume syncing personnel details from your connected identity provider (IdP) or human resources information system (HRIS).
- Why active employees may appear as former employees in Drata? (Concept Guide)Use this article to understand why active employees may appear as Former Employee or not appear in the Personnel list in Drata.
- Troubleshoot employment status issues in DrataWhy am I not receiving authentication or login emails from Drata, and how can I resolve this?
- Assets
- Understanding Device Linking, Removal, and Visibility in DrataLearn how unlinking or removing a device affects compliance in Drata and follow troubleshooting steps if a device is missing from the Assets or Personnel pages.
- Virtual Asset Population: AWSDrata automatic population of Virtual Assets
- Azure Virtual Asset
- GCP Virtual AssetsLearn how to automate your GCP asset inventory, how to mark assets our of scope, and how Drata automatically assigns asset owner.
- Bulk Import AssetsUpload a CSV of custom assets using a guided, spreadsheet-style experience.
- TPRM Agent: Create a Criteria
- SafeBase Integration for TPRM ReviewsLearn how to add a vendor’s SafeBase Trust Center in Drata so the TPRM Agent can automatically collect documentation and streamline security reviews.
- Conducting a Security ReviewLearn how to use the TPRM Agent in Drata to collect vendor documentation, run AI-powered security reviews, and interpret assessment results based on your evaluation criteria.
- Vendors overview in Drata
- Vendor insights
- Add a prospective vendorUse prospective vendors to evaluate third parties before onboarding.
- Vendor risks
- Vendor suggestions
- Integrate Zip with Drata Vendor Management
- Vendor Automated Impact Assessment
- Create and Manage Vendor Questionnaires
- Start and manage security reviews for your vendors
- Customize the vendor questionnaire email subject line (New Experience)Only in the New experience, you can customize the subject line used for vendor questionnaire emails.
- Security Questionnaire Automation (SQA) Beta Sunset NoticeSecurity Questionnaire Automation (SQA) Beta will officially sunset on April 30, 2026.
- Customizing Security Review TitlesYou can now customize the titles of Security, SOC, and Uploaded reviews in Drata.
- Bulk actions for Current Vendors (New Experience)
- Internal Notes and Observations in Security Reviews (New Experience)
- Automate Recurring Vendor Reviews with the TPRM Agent
- Customize vendor types (New Experience)Learn how to customize vendor types in Drata
- Terminology Updates: Inherent and Residual Risk in Vendor Risk ManagementTo better align with industry-standard Governance, Risk, and Compliance (GRC) frameworks, Drata has updated the terminology used within the Vendor Risk Management (VRM) experience.
- Risk management in Drata: An overviewThis article provides the foundational workflow for managing your risk program within Drata.
- Risk insights overview
- Getting started with a risk assessment (Concept Guide)Understanding how to apply risk management principles to Drata’s Risk Management Standard offering
- Your First Risk Assessment: A Step-by-Step Guide (Concept Guide)New to risk assessments? This help article walks you through it, one simple step at a time.
- Integrating Fraud Risk into Your Risk Assessment (Concept Guide)How to incorporate fraud risk into your organization’s standard risk assessment approach.
- Risk categories in DrataRisk categories in Drata help you organize, filter, and report on risks in your Risk Register.
- Streamlined Risk Register Set Up
- Import Risk in Bulk (New Experience)Custom risks can be uploaded quickly using our guided import flow, making it simple to bring your existing risk inventory into Drata.
- Drata's Risk Library (New Experience)
- Understanding the Drata Risk RegisterNavigate Your Risk Landscape: Explore Drata's Risk Register Headers
- Assess and Manage Individual Risks
- Add and View Residual Risk in the Risk Register (New Experience)
- Custom Formulas for Risks
- Risk Treatment Plan GuidanceRisk Assessment Results and Treatment Plan
- Add an Application Manually for Access Reviews (New Experience)
- Upload or Update Personnel Data for Access Reviews (New Experience)
- Run an Access ReviewAccess Reviews help you review and validate user access across connected applications.
- Example Access Review Procedure
- User Access Reviews for Microsoft 365Ensure the following prerequisites are met before setting up Microsoft 365 for user access reviews.
- Download Access Review Evidence and Review Details
Trust Center
Set up your Trust Center to proactively share your security posture
- SafeBase Trust Center integration in Drata TPRM
- Trust Center Essential and Pro Plans
- Managing and Updating Your Trust Page
- Public Trust page URL
- Publishing your Public Trust page
- Download reports from Trust Center
- Announcements (Trust Center Pro only)
- ComplianceIn this article, you learn how to add compliance files and records to your Trust Center.
- Trust Center: SecurityIn this article, you learn how to add security files to your Trust Center.
- Policies for Trust Center
- Continuous MonitoringContinuous Monitoring within Trust Center
- Topics and Common Questions (Trust Center Pro only)
- Privacy DetailsIn this article, you learn how to display privacy-related information in your Trust Center.
- Preview & View as Visitor
- Submitting and Approving RequestsIn this article, you learn how to submit and approve access requests for private Trust Center content.
- Custom Access Length Expiration (Trust Center Pro only)
- Revoking AccessIn this article, you learn how to display privacy-related information in your Trust Center.
- Pre-Approved Email Domains (Trust Center Pro only)
- Display Details
- Document access managementConfigure the privacy of your more sensitive documents with an NDA, configure email notifications, and set limits on document access length.
- Salesforce: Streamline your documentation access request
- Streamline your documentation access requestConnect a CRM, such as Salesforce, to Drata to provide more context to, and streamline, document access requests.
- Trust Center Analytics Dashboard
- Trust Center - Web Analytics TrackingTrack Trust Center insights with your web analytics provider
- Trust Center: Custom Titles and DescriptionsLearn how to customize your public Trust Center page by updating your section titles and descriptions to align with your business.
- Trust Center: Reorder your sections and documentsLearn how to reorder your sections and documents on your Trust Center page to highlight key information and content for your visitors.
- Security ReportDrata provides you with a security report summarizing your current status for distribution to auditors, customers or others
- What should be included in the annual BCP/DR test and Incident Response test?
