Muin is in private beta.Watch the public release announcement —talk to us.
Falaah Falaah AI

Compliance Health

See how Muin computes your compliance score across seven weighted factors, read the exec summary on the landing page, and act on what is driving your posture.

Compliance Health is the /compliance landing page. It answers two questions at a glance: where are we today (what needs attention this week) and how healthy is our program overall (what’s the score and what’s driving it).

The page has two tabs — Today and Health — with the tab state kept in the URL so a deep-linked /compliance?tab=health reopens exactly where you left off.

The Two Tabs

TabWhat it showsWho opens it
Today (default)Action items due this week: overdue attestations, DSARs inside their 30-day window, licenses expiring soon, incidents without an ownerCompliance leads working the queue
HealthOverall score gauge, the seven score factors broken out, per-framework completion, evidence freshness trendsExecs reading posture; auditors doing readiness checks

There is no separate Overview page — the former Overview and former Dashboard are merged into these two tabs (Plan 272j IS22). One URL, one landing.


The Compliance Score

Your overall score is a weighted aggregate across seven factors. The formula is defined in one place (ComplianceScoreService.WEIGHTS) and the same formula drives both the landing gauge and the Health tab breakdown — so the number you see on /compliance and the number you see after clicking Health never disagree.

The Seven Factors (exact weights)

FactorWeightWhat it measures
Framework completion25%Share of framework controls marked implemented, tested, or certified
Risk management20%Share of identified risks that are mitigated or accepted (not open)
Training compliance15%Completion rate across assigned programs that are currently in-window
Policy documentation15%Share of active policies with current versions and fresh review dates
Evidence freshness10%Share of evidence items refreshed within their configured TTL
Vendor assessment10%Share of active vendors that have a current risk tier set
License compliance5%Share of tracked licenses that are current (not expired, not inside the alert window without action)

The weights sum to 1.00. If you want them audited, muin.server/src/services/compliance/score_service.py line 40 is the source of truth — the marketing page will never drift from it because CI verifies this table against the constant on every build.

Score Ranges

ScoreReadiness badgeWhat it means
80–100Audit-readyAbove the default SOC 2 readiness threshold (80). The gauge flips green.
60–79ApproachingNotable gaps; the exec summary cites the two or three top drivers
40–59Action neededSignificant gaps across multiple factors
0–39CriticalMultiple factors at or near zero; use the At-a-Glance card to pick the first thing to fix

The 80 threshold is tunable per framework — Frameworks → Framework detail → Readiness threshold. The gauge re-reads that value every time the page loads, so raising or lowering the threshold moves the “audit-ready” line immediately without a recompute.

When the Gauge Says “Not Assessed Yet”

Score calculation needs data. A brand-new tenant with zero frameworks, zero policies, zero training, zero risks, and zero vendors has nothing to score — the gauge renders the empty state rather than “0/100”. Completing the Getting Started checklist (a framework, a policy, a first training assignment) moves the gauge off the empty state within minutes.


The At-a-Glance Exec Summary

Below the gauge is a narrative card — Compliance at a glance — that translates the score into 2–4 sentences. It cites the specific factors and control IDs dragging the posture, grounded in the tenant’s current breakdown.

┌─ Compliance at a glance ─────────────────── [LLM ● Fresh] ─┐
│                                                             │
│ Framework completion is the single biggest lift at 62%      │
│ — SOC 2 CC6.1 and CC7.2 still have untested controls. Risk  │
│ management is healthy at 88%; training is on track. Close   │
│ the two framework gaps to clear the audit-ready threshold.  │
│                                                             │
│ Score 74/100    ↑ +2.3 vs last week    Touches: CC6.1 CC7.2 │
└─────────────────────────────────────────────────────────────┘

Summary Source Badge

Every At-a-Glance card shows a source badge so you always know where the copy came from:

BadgeWhat it meansWhen it fires
LLMBedrock Claude wrote this narrative grounded in your current breakdownMost of the time
FallbackA deterministic rule-based narrative fired because the LLM was slow, rate-limited, or returned something that failed the citation fenceWhen safer to show an honest rule-based summary than risk a hallucinated one
Network errorSummary temporarily unavailable; numeric score is still accurateTransient — a refresh retries

The fence rejects narratives that cite controls or factors not present in the tenant’s actual breakdown. If the LLM output fails the fence, the fallback narrative fires instead — the badge always reflects what you’re actually reading. You never see a fake LLM summary pretending it wrote something the fallback wrote.

Trend Delta

The +2.3 vs last week readout compares the current overall score to the value from seven days ago. Values between −0.5 and +0.5 render as “Stable” — small oscillations from cache expiry or minor data refreshes don’t get flagged as movement.


Dashboard Walk-through

Today Tab

The Today tab is a work queue. It aggregates items that need a human decision this week across all of compliance:

WidgetPulled fromClick-through goes to
My pending compliance workAttestations due, DSARs you own, tasks assigned to youThe originating page (policy, DSAR, HumanTask)
Active compliance workflowsWorkflow runs currently in progressWorkflows module → run detail
Compliance review queueItems routed to a compliance reviewer (policy acks, questionnaire approvals)The reviewer’s inbox for that item
Recent alertsNew regulatory alerts + drift notifications surfaced in the last 7 daysRegulatory Alerts detail or Frameworks page

Employees who aren’t compliance owners mostly live in My pending compliance work — it’s the single place to see “what does compliance want from me today.”

Health Tab

The Health tab is the analytical view:

SectionWhat it shows
Overall gauge + At-a-GlanceThe numeric score, readiness badge, and exec summary narrative
Score breakdownEach of the seven factors with its current value and weight contribution
Framework cardsEach active framework with its own completion percentage and control counts
Evidence freshnessDistribution of evidence items by age band (0–30d / 30–90d / 90d+)
Deadline listUpcoming policy reviews, attestations, license renewals, and certifications in the next 30 days

Click any framework card to open that framework’s detail page (see Frameworks). Click an evidence age band to filter the Documents tab to items in that band.


How Scores Change

Scores are cached for 5 minutes (ComplianceScoreService.CACHE_TTL_SECONDS), so small edits don’t thrash the gauge. After that window the next load recomputes against live data.

Actions that immediately invalidate the cache:

  • Implementing or testing a control
  • Closing a risk (moving it out of open status)
  • Completing a training assignment
  • Refreshing evidence (uploading a new version)
  • Renewing a license
  • Setting a vendor’s risk tier
  • Publishing a new policy version

Other edits (descriptions, tags, assignee changes that don’t affect status) don’t move the score — the formula reads status fields, not prose.


FAQs

How does the score work?

Your score is a weighted sum of seven factors (see the table above). Each factor is a ratio in [0, 1] — for example, training compliance is “programs completed / programs assigned and in-window.” Each ratio is multiplied by its weight, and the sum is scaled to 0–100. The seven weights sum to 1.00 and are defined in ComplianceScoreService.WEIGHTS.

Why does it say “Not assessed yet”?

The tenant has no active frameworks, policies, training, risks, or vendors yet — there’s nothing to measure. Add any of those (usually, activating your first framework is the fastest step) and the score starts computing within minutes.

What affects my score the most?

Framework completion (25%) and Risk management (20%) combined make up 45% of the score, so those two move the needle fastest. In practice, the At-a-Glance narrative tells you which factor is currently the biggest drag for your specific tenant — usually the one with the lowest ratio, not necessarily the one with the highest weight.

Is the AI exec summary a hallucination risk?

The backend enforces a citation fence: any framework, factor, or control code the LLM names must actually exist in your tenant’s current breakdown. Narratives that fail the fence get replaced with a deterministic rule-based summary, and the Fallback badge is shown so you know. The numeric score shown above the card is always computed from real data, never from the LLM.

Why did my score drop by a point overnight with no changes?

Evidence freshness decays with time. A document that was 29 days old yesterday and 30 days old today may have crossed a freshness band, reducing its contribution. This is expected behavior — the factor is meant to decay. Refreshing evidence in the Documents module restores it.

Can I change the weights?

Not for beta. The seven weights are tuned across the platform and CI verifies the doc table matches the code constant. Adjustable weights are tracked in Plan 276 for post-beta.