Platform / Autonomous operations
Compliance that runs
on a schedule, not a to-do list
Type II requires months of continuous evidence, and most startups let controls degrade after Type I. Screenata's agents operate on schedules: scanning, checking freshness, drafting remediations, and escalating what needs a human decision.
- Evidence freshness checks
- Daily
- Cloud & code scans
- Weekly
- Access reviews
- Quarterly
- Risk assessment refresh
- Annual
Unresolved issues pin to the top of the feed until resolved
Agents with jobs, not chat windows
Specialized agent personas
Cloud Security, Repository, Code Scanner, Evidence, and Controls agents each own a domain. Each posts structured reports with pass/fail/warn summaries, critical findings, and suggested actions.
- Unresolved issues pin to the top of the feed until resolved
- Reports arrive as structured messages, not dashboard-red-you-never-see
- Cloud Security AgentMon 09:002 warn
- Repository AgentMon 09:04pass
- Evidence Agentdaily 06:00pass
Each owns a domain, each reports pass / fail / warn
Executable runbooks
Compliance tests where the documentation IS the automation. Human-readable steps contain inline action pills, clickable references to real integration checks, so auditors read the same thing the system runs.
- One source of truth: no drift between docs and automation
- Vera generates runbooks; humans can edit them; both can execute them
- Watch each step run sequentially with evidence collected automatically
- 1.Pull the user list from your identity providerokta.users.list
- 2.Diff access against last quarter's approved setaccess.diff
- 3.Draft removal tickets for 2 stale accountstickets.draft
The documentation IS the automation — auditors read what the system runs
Quarterly access reviews, actually run
The review scans your IdP, GitHub, and cloud accounts, drafts removal tickets, and queues them for your approval. Behavioral controls become agent-managed operations, not founder checklists.
- Scan → draft → approve, on an automatic quarterly cadence
A behavioral control, run as an operation
Remediation orchestration
Agents don't just report gaps, they execute fixes with your approval: IAM policy updates, branch protection changes, encryption enablement, and ticket creation in Jira, Linear, or GitHub Issues.
- 6-state lifecycle from detected to verified and closed
- Deduplicated findings, one stable ticket per real issue
- Platform-specific priority mapping for your ticketing system
Tickets land in Jira, Linear, or GitHub Issues
Autonomy with a paper trail
- 01
Scoped
Every agent action maps to a permission entry with a role requirement and risk tier.
- 02
Gated
High-risk actions render approval cards in chat. Legally binding actions always require a human.
- 03
Logged
Every tool invocation and permission decision is recorded, the audit trail is itself SOC 2 evidence.
Watch the agents work
See a weekly scan produce findings, draft remediations, and open tickets, with you approving, not executing.