> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.itential.com/itential-platform/2023-2/configuration-manager/golden-configurations/compliance-plans/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server. # Use compliance plans **Add-on product**: This feature is part of Configuration Manager Enterprise, a separately licensed add-on to Configuration Manager. [Learn more](/configuration-manager/overview#configuration-manager-enterprise). Compliance plans schedule and manage comprehensive compliance reporting across multiple Golden Configurations. Use them to maintain regular compliance checks and generate audit reports. ## What are compliance plans? Compliance plans orchestrate compliance checks across multiple Golden Configurations, device groups, and schedules. They provide centralized management for enterprise-wide compliance programs and generate consolidated reports for audit and analysis. ## How compliance plans work Compliance plans follow this process: #### Define scope Select Golden Configurations and device groups to check #### Set schedule Configure when compliance checks should run #### Execute checks Run compliance across all defined scopes automatically #### Generate reports Compile results into comprehensive compliance reports #### Distribute results Send reports to stakeholders and archive for audit ## Create a compliance plan To create a new compliance plan: #### Open the create dialog Click **Create (+)** in Configuration Manager #### Select compliance plan Choose **Compliance Plan** from the dropdown #### Configure basic settings * Enter a plan name * Add a description * Set the plan owner #### Create Click **Create** to open the compliance plan editor ## Configure compliance plan scope Define what the plan should check. ### Add Golden Configurations To include Golden Configurations in the plan: #### Open the Scope tab Navigate to the Scope section #### Add Golden Configurations Click **Add Golden Configuration** #### Select configurations Choose one or more Golden Configurations #### Specify nodes * Select specific nodes, or * Include entire tree #### Save selections Click **Save** to add to the plan ### Add device groups To include device groups: #### Open the Groups section Navigate to device groups in the Scope tab #### Add groups Click **Add Device Group** #### Select groups Choose one or more device groups #### Save selections Click **Save** to add to the plan **Scope example:** ``` Compliance Plan: Enterprise Network Compliance Scope: - Golden Config: Campus Switches (all nodes) - Golden Config: Data Center Switches (production node only) - Golden Config: Firewall Policy (all nodes) - Device Group: Branch Office Devices - Device Group: Core Network Devices ``` ## Set compliance plan schedule Configure when compliance checks run. ### Schedule options | Schedule Type | When to Use | | ------------- | ------------------------------ | | Daily | Regular compliance monitoring | | Weekly | Comprehensive weekend checks | | Monthly | Monthly audit reports | | Quarterly | Regulatory compliance periods | | On-demand | Ad-hoc compliance verification | ### Configure schedule To set the plan schedule: #### Open the Schedule tab Navigate to scheduling configuration #### Select frequency Choose daily, weekly, monthly, or custom #### Set time Define when checks should run (consider maintenance windows) #### Configure options * Set timezone * Define retry behavior * Set timeout limits #### Save schedule Click **Save** to apply scheduling **Schedule examples:** **Daily monitoring:** ``` Frequency: Daily Time: 2:00 AM local time Days: Monday through Sunday Retry: 2 attempts if failure ``` **Weekly audit:** ``` Frequency: Weekly Day: Sunday Time: 1:00 AM local time Retry: 3 attempts if failure Timeout: 4 hours ``` ## Configure compliance reports Define how compliance results are reported. ### Report settings To configure reports: #### Open the Reports tab Navigate to report configuration #### Select report format Choose PDF, CSV, JSON, or HTML #### Configure content * Summary statistics * Detailed device results * Configuration diffs * Trend analysis #### Set retention Define how long reports are stored #### Save settings Click **Save** to apply report configuration ### Report content options | Content Type | Description | | ------------------- | ---------------------------------- | | Executive summary | High-level compliance statistics | | Device details | Per-device compliance status | | Configuration diffs | Specific configuration differences | | Trend analysis | Compliance changes over time | | Exception list | Devices with approved deviations | ### Distribute reports To configure report distribution: #### Open the Distribution section Navigate to report distribution settings #### Add recipients Enter email addresses for report recipients #### Configure delivery * Set delivery time (immediate or scheduled) * Define format preferences per recipient * Set notification preferences #### Add integrations Configure integration with ticketing or monitoring systems #### Save distribution Click **Save** to apply settings ## Run compliance plans ### Manual execution To run a compliance plan immediately: #### Open the compliance plan Navigate to the plan in Configuration Manager #### Run now Click **Run Now** in the plan toolbar #### Monitor progress View real-time execution status #### Access results View or download reports when complete ### Scheduled execution Compliance plans run automatically based on their schedule: * Plan starts at scheduled time * Compliance checks execute for all scoped items * Reports generate upon completion * Distribution occurs based on settings * Results archive for audit purposes ## View compliance plan results ### Access plan reports To view compliance plan results: #### Open the compliance plan Navigate to the plan in Configuration Manager #### Open the Results tab Click the Results tab #### Select a report Choose a report from the execution history #### Review results View summary and detailed compliance data ### Understand report data Compliance plan reports include: **Summary metrics:** * Total devices checked * Compliant device count * Non-compliant device count * Compliance percentage * Comparison to previous runs **Detailed results:** * Per-device compliance status * Configuration differences * Golden configuration alignment * Remediation recommendations **Trend data:** * Compliance percentage over time * Recurring non-compliance issues * Improvement or degradation trends * Device-specific compliance history ## Manage compliance exceptions Some devices may have approved deviations from Golden Configurations. ### Document exceptions To add an exception: #### Open the Exceptions section Navigate to exceptions in the compliance plan #### Add exception Click **Add Exception** #### Define exception * Select device or device group * Specify golden configuration node * Describe the approved deviation * Set expiration date (if temporary) * Add approval documentation #### Save exception Click **Save** to document the exception ### Review exceptions Periodically review documented exceptions: #### Open the Exceptions tab View all current exceptions #### Check expiration dates Identify expired or expiring exceptions #### Validate necessity Confirm exceptions are still required #### Update or remove Renew, modify, or remove exceptions as needed ## Best practices **Plan scope strategically:** * Group related Golden Configurations together * Align plans with audit requirements * Consider network segmentation * Balance scope size with execution time **Schedule appropriately:** * Run during maintenance windows * Avoid peak usage times * Stagger large plans across time periods * Consider device impact and load **Manage reports effectively:** * Customize reports for different audiences * Archive reports for audit requirements * Automate report distribution * Set appropriate retention periods **Handle exceptions properly:** * Require approval for all exceptions * Document business justification * Set expiration dates for temporary exceptions * Review exceptions regularly * Update golden configs when exceptions become standard **Monitor plan health:** * Track plan execution success rates * Review execution duration trends * Monitor for recurring failures * Adjust scope or schedule as needed ## Example: Enterprise compliance plan **Plan: Monthly Security Compliance Audit** **Scope:** * Golden Config: Firewall Security Policy (all nodes) * Golden Config: Switch Security Settings (all nodes) * Golden Config: Router Security Baseline (all nodes) * Device Group: Production Network * Device Group: DMZ Devices **Schedule:** * Frequency: Monthly * Day: First Sunday of each month * Time: 12:00 AM EST * Retry: 3 attempts * Timeout: 6 hours **Reports:** * Format: PDF (executive) + CSV (detailed) * Content: Summary, device details, diffs, trends * Distribution: * CISO: Executive summary PDF * Network team: Detailed CSV * Security team: Full PDF report * Audit team: Archive all formats **Exceptions:** * Lab devices: Development configurations approved * Legacy systems: EOL devices with documented risks * Review cycle: Quarterly ## Troubleshoot compliance plans ### Plan execution fails If a compliance plan doesn't complete: * Check golden configuration validity * Verify device connectivity * Review execution logs for errors * Confirm adequate execution timeout * Check for scheduler issues ### Reports not generated If reports don't appear: * Verify plan completed successfully * Check report format configuration * Review storage capacity * Confirm report generation settings * Check for template errors ### Distribution fails If reports don't reach recipients: * Verify email addresses * Check email server configuration * Review distribution logs * Confirm integration settings * Test with manual distribution ## Next steps #### [Golden configurations](/itential-platform/configuration-manager/golden-configurations/overview) Create and manage baselines #### [Build workflows](/itential-platform/studio/workflows/create-and-run-workflows) Integrate compliance with orchestration