Dashboard & daily triage
The Dashboard is the first screen most people on the compliance and risk team see when they sign in. It answers one question, which is what needs you today. Every number on it drills through to the register behind it. Directors are the exception. A board principal lands on the Board portal instead, which is built for oversight instead of daily work. A business-line owner in the first line opens on their own work, described under My work below.
What the dashboard shows
The headline counts the items waiting on you. The panels below break that count down:
- Overdue & at-risk. This panel lists findings that are overdue or due soon, policies past their review date, risks past review, and records due for a disposition decision.
- Approvals queue. This panel previews the governed decisions pending across the workspace. It is capped, and it is not filtered to the ones you personally can sign. The count of items actually awaiting your sign-off lives on the topbar pill.
- Findings tracker. This panel shows the open issue register at a glance, with severity and aging.
- Framework health. This panel shows coverage for each enrolled framework, with its gap count.
- Needs your attention. This panel lists items the platform could not resolve without a person.
- Recent agent runs. This panel shows what the AI agents produced and what is still awaiting review.
- Audit readiness. This panel shows how prepared you are for the next examination.
- Regulatory updates. This panel lists new rules and guidance, ranked by likely impact on you.
- Recent activity. This panel shows the latest activity on records you are allowed to open. It leaves out internal-audit work, internal-marked entries and security or administrative events, so it is not the audit trail. The full record is on the Audit trail screen.
Panels are gated by role on the server. If you hold job families, your families choose which panels you get, and your role still caps that set. A panel you do not get is omitted instead of shown as a zero. That pattern holds across the product. We hide what you are not entitled to see instead of greying it out, and we never invent a number to fill a space.
My work
My work is the first group in the sidebar. It holds the Dashboard, Tasks & plans, Findings, Audit requests, Audit responses, the Obligations calendar, Drafts, Documents and Agent runs, so the screens you open every day sit together.
The Dashboard has a My work view for the first line. If your only job family is Business-line owner, the Dashboard opens on your own work instead of the standard panels. It lists your open tasks with the soonest due first, the policy attestations and control certifications waiting on you, the vendors whose relationship you own, and the risks, key risk indicators, self-assessments and risk exceptions you own. You can attest to a policy or certify your controls from the row itself. If you hold Business-line owner alongside another family, the same list sits above the standard panels. A member whose access is limited to their own records or to chosen business units also opens on My work. Roles & permissions covers job families and scope.
Working the queue
Daily triage runs top to bottom. Start with Overdue & at-risk, because those items have dates an examiner can check. Anything overdue either needs a new owner, a revised due date with a documented reason, or a corrective action plan that is actually moving.
Next, clear the Approvals queue. Approvals are the bottleneck in most compliance programs. A policy that has been sitting in pending approval for six weeks is a finding waiting to happen. See Approvals & delegation of authority for how routing and sign-off work.
Then work Needs your attention and Recent agent runs. Agent output is a proposal and never a decision. High-confidence results are auto-cleared for review, mid-range results wait for you, and low-confidence results are flagged. Auto-cleared is not approved. How AI works in Zovos covers the confidence bands and the accept, dispute, and escalate actions.
Finally, scan Regulatory updates. Most items are a two-minute applicability call. The ones that apply to you become work in the compliance library.
Assigned work that is not a finding lives in Tasks & plans, in the My work group of the sidebar. Task due dates ride the same date machinery as everything else, so they reach the obligations calendar and your reminders instead of sitting in a separate list. See Tasks & action plans.
Working a register
The big registers share a set of tools, so learning them once is enough. Those registers are findings, the risk register, third parties, the control catalogue and policies.
- Saved views. The filters, sort order and hidden columns you use on a register save as a named view, with update, delete and make-default. Views are yours, not the workspace's.
- Bulk actions. Select rows and apply one change to all of them. A bulk action runs as separate changes, each bound by that record's own lifecycle rules, so a partial outcome is normal. Every record that could not take the change is listed back to you by identifier with the reason it was refused. Nothing is rounded up into a success it was not.
- Spreadsheet import. The importer accepts CSV or XLSX and offers a dry-run validation pass first. It reports errors row by row without abandoning the rest of the file. It matches on the register's natural key, so a re-import updates records instead of duplicating them.
- Import-ready CSV export. This is a server-side, audit-logged export of the whole register in the exact column shape the importer accepts. It is distinct from the quick CSV in the toolbar, which saves only the rows currently on screen.
- Custom fields. Your workspace can define its own fields for risks, findings, third parties, policies and controls in Settings, and they then appear on the record alongside ours.
Notifications and the approvals pill
The topbar carries a notification bell and an approvals pill. The pill counts only the items you can actually decide. It does not badge you for work sitting with someone else. Notifications are toned by urgency, and the routing matrix in Settings decides whether an event also reaches you by email digest, Slack, or Microsoft Teams.
The bell shows the notifications addressed to you, plus workspace-wide notifications about records you are allowed to see. A board meeting notice, for example, reaches only the members who sit on that committee. A member whose access is limited to their own records or to chosen business units sees only the notifications addressed to them.
Your workspace owner sets that matrix, but the volume of mail is yours. Each person chooses, for each class of notification, whether it emails them immediately, waits for the daily digest, or sends no email at all. Email delivery is not switched on yet, so those choices take effect when it is. The same panel shows when the reminder sweep that raises most of those notifications last ran, which is the first thing to check when a reminder you expected never arrived.
Getting around quickly
The command palette opens with Command-K or Control-K from any screen and jumps by name to any area you are entitled to see. Type two characters or more and it also searches your records. It covers findings, risks, controls, third parties, policies, documents, complaints, regulatory changes, examinations and decisions, and it lists the matches under the areas in the same keyboard list. Paste a record identifier and that record is the first thing selected. Examiner sessions get the navigation half only. Compliance teams of one to three people live in this palette, and it is the fastest way to move between the risk register, findings, and the policy library without touching the sidebar.
New workspaces also get a Getting started checklist on the Dashboard. It asks you to enroll your frameworks, import your data, run a gap analysis, and triage your first finding. It tracks real workspace state and hides itself once you are set up.
The obligations calendar
The Dashboard shows what is late. The Obligations calendar shows what is coming. Its first tab aggregates the dates your registers already hold into one view. Those dates cover control tests and owner attestations, policy and risk reviews, vendor renewals, exception expiries, examination requests, evidence freshness, continuity exercises, complaint response clocks, partner-program dates, board meetings and open tasks. You can download it as an ICS file, or generate a personal subscription URL in Settings, so the compliance calendar can live in Outlook or Google Calendar next to everything else on your week.
The second tab, Statutory obligations, holds the deadlines the rules fix on the wall calendar instead of deriving from a cadence. Examples are the HMDA loan application register submission, the currency date on your CRA public file, the Call Report cycle, and the OFAC blocked-property report. Three things happen here that the aggregated view cannot do. You scope an obligation to your institution, so one that does not apply is marked not applicable instead of nagging forever. You move an institution-set date onto your real board cycle. And you record a filing, after which the obligation rolls forward on its own schedule. Rows read overdue, due soon, scheduled, not applicable, or complete. Anyone who can see the Dashboard can read the register. Changing it is an owner permission, so a read-only role sees the dates and none of the controls.
Dates are institution-local. An owner sets your timezone in Settings, and every date-only deadline in the product then means the end of that day in that zone. That zone also sets the hour the daily digest goes out.
Notes and limits
The Dashboard is a view over the registers, not a separate report. Every tile is computed from live records, which means a number is only as current as the underlying work. It also means a fresh workspace looks empty on purpose. Until you enroll frameworks and bring in your policies and controls, there is nothing honest to show.
Panel composition is role-based and is not currently customizable per person. If your team wants a panel you do not have, or a tile that would help your board reporting, tell us. The Dashboard is one of the areas we revise most often.