---
title: "FAQ & troubleshooting"
summary: "Answers to the questions compliance teams ask most: sign-in, browsers, missing screens, exports, AI behavior, and support."
updated: "2026-10-07"
section: "Help"
url: "https://zovos.ai/docs-faq.html"
---

# FAQ & troubleshooting

The questions below are the ones compliance teams at banks and credit unions of every size ask most often in their first months with Zovos. If yours is not here, [contact support](support.html). We would rather answer it than have you guess.

## Signing in

### I never received an invitation email

Ask your administrator to check the member list on the Team and roles screen. A pending invitation can be re-sent from there. Your mail gateway may also have held it. The invitation is sent by WorkOS, our identity partner, from its own sending domain instead of a Zovos address, so a gateway that quarantines unfamiliar senders will catch it. If your institution provisions access through your directory instead, there is no invitation email at all. You simply sign in with your organization's usual single sign-on button once your administrator has assigned you.

### Sign-in says I am not authorized

Contact your administrator first. Access is granted through your identity provider, and the usual cause is a directory group or role assignment that has not been mapped to a Zovos role yet, or a directory sync that has not run since you were added. Zovos refuses an unrecognized assignment instead of defaulting you into a role. That is why the error appears the instant you arrive and not somewhere deeper in the product. An owner fixes it on the **Access & SSO** tab in Settings, where directory groups and roles are mapped onto Zovos roles. Once the mapping is in place, sign in again.

### I cannot invite anyone into a custom role

The mapping has to exist before the invitation. Every workspace starts with directory mappings for the owner, analyst, internal audit, board and risk approver roles, so those invitations work from day one. A custom role has no mapping until an owner adds one on the **Access & SSO** tab in Settings. Until then, an invitation into that role is refused with a message saying exactly that. The same applies if an owner has removed one of the default mappings. Examiners are not invited this way. They get a separate time-boxed session, described below. The order to work in is in [Onboarding your institution](docs-onboarding.html).

### Someone has left, or a laptop was lost

An administrator can open that person's row on the Team and roles screen and see their live sessions. Each one shows the device, where the session started, when it was last active and when it expires. The administrator can end one of them or all of them. A revoked session stops working on its next request. Removing the person in your identity provider is still the right first move. Ending sessions is the control for the gap before your next directory sync runs.

### My role is wrong

Roles are set by your administrator. If your account is managed by your directory, the member row will say so, and the role has to change in your identity provider rather than inside Zovos.

### I need to give an examiner access

Examiners are not added as teammates. An owner grants a time-boxed, scope-limited session for the examination, read-only apart from a few fieldwork actions. See [Roles and permissions](docs-roles-permissions.html).

## Browsers and access

### What do I need to run Zovos?

You need a current version of Chrome, Edge, Safari or Firefox, kept reasonably up to date. Zovos is a browser application, so there is nothing to install and no desktop client. It works on a tablet, but the registers, matrices and workpaper screens are built for a laptop or desktop display.

### Where do I find the allow-list for our proxy?

[Onboarding your institution](docs-onboarding.html) lists what a corporate proxy or firewall may need named. The first entry is the workspace host over HTTPS, including the WebSocket upgrade the collaborative drafts editor uses on that same host. The second is WorkOS, our identity partner, together with your own identity provider, because signing in is a redirect out to them and back. The third is our document storage endpoint, since uploads and downloads go directly between the browser and object storage instead of through the application. Ask [support](support.html) for the exact entry for your environment instead of guessing at it. One related fact belongs in the same conversation. Zovos refuses to be displayed inside a frame, so it cannot be embedded in an intranet portal page.

### Can I restrict where the workspace can be reached from?

Yes. Your workspace can be limited to your institution's own network ranges, which you configure in settings. If you are travelling and suddenly cannot reach Zovos, that policy is the first thing to check with your administrator.

## Using the product

### A screen or menu item I expected is missing

Anything you lack permission for is hidden instead of greyed out, so the navigation you see is the navigation you have. If a colleague can see a screen you cannot, the cause is a difference in roles or in the scope of an access group. See [Roles and permissions](docs-roles-permissions.html).

### Why can I not approve something I submitted?

Separation of duties prevents it. The approver may not be the submitter, and critical items need two distinct signers. If you are genuinely the only person in the workspace holding the required permission, the decision can still proceed on the sole-operator override, which requires a written justification and is tagged as such in the audit trail. See [Approvals and delegation of authority](docs-approvals.html).

### The gap analysis says the regulatory library is not indexed

Ask your Zovos contact. Agents cite the regulatory library. Until that library has been indexed for your workspace, they decline to run instead of answering without sources. The message you see is the agent naming the missing index instead of producing an uncited answer. Indexing is a one-time step on our side. Despite the wording of the message, it is not something an owner can do in settings. Confirm it before your first agent run. [Onboarding your institution](docs-onboarding.html) puts it in the day-one order.

### A panel is empty rather than showing zero

That is deliberate. A panel with no data behind it, or one withheld from your role, renders nothing instead of a fabricated zero, because a confident zero in a compliance report is worse than an honest blank.

### Something looks wrong on a screen

Use **Report a bug** in the in-app help center. The report carries the screen you were on and your recent in-app actions, and you see exactly what will be attached before it sends. An owner can switch the feature off for the whole workspace, because some institutions forbid sending free-text context to a vendor. When it is off, the option is not shown and you reach [support](support.html) instead.

## Getting your data out

### Can I export my registers?

Yes. Registers such as findings, risks, gaps and loss events export as PDF or spreadsheet files, and most tables offer a quick CSV. Scheduled exports can deliver datasets on a cadence to your own systems.

### Can I hand an examiner or an auditor something they can verify independently?

Yes. Sealed artifacts such as board packs, minutes, workpapers and exam binders carry a content hash recorded in the proof ledger, and a proof pack can be verified offline with a bundled verifier, without trusting the export or us. The audit trail itself is append-only and exports with its filters intact. See [Audit trail and exports](docs-audit-trail.html) and [Your data: exports, backups and retention](docs-data-handling.html).

### What happens to our data if we leave?

Your records remain exportable throughout the term, and offboarding is a defined process described in [Your data](docs-data-handling.html). Our published security posture, including what we do and do not hold today, is on the [security page](security.html).

## How the AI behaves

### Does AI ever change my records on its own?

No. Every AI output arrives as a proposal with its citations and a confidence score, and becomes authoritative only when a named person accepts it with a rationale. High confidence auto-clears into a review queue, and auto-cleared does not mean approved.

### What if a citation is wrong?

A citation the model produces that does not resolve against the regulatory corpus is dropped, loudly and with an audit entry, instead of being stored. Only the immutable run record keeps the raw output.

### Can we turn AI off entirely?

Yes. If your institution's policy forbids sending content to a language model, an owner can disable AI processing for the whole workspace, and every path that would trigger it refuses before anything is written. Some analysis is deterministic and uses no language model at all. That includes absence testing, mock exam checks, clause review and launch delta. There is more in [How AI works in Zovos](docs-ai-in-zovos.html).

### Can we show an examiner how an answer was produced?

Yes. Every run pins its agent, model, prompt template version and hashed inputs, so a re-run reproduces the same inputs verbatim and the question is answerable a year later.

## Notifications and email

### Why have I not had any email from Zovos?

The product does not send email today. Notifications are delivered in the workspace, through the bell in the top bar and the panels on the dashboard. Your email choices on the notification settings screen are stored but inert until email delivery is switched on for the deployment. The screen says so instead of quietly dropping messages. Plan around it. Nothing chases an overdue approval or an expiring attestation by email yet, so the workspace is the place to look.

Slack and Microsoft Teams do not depend on email. Once an administrator connects a channel and turns it on under Notifications, those notifications reach it as well as the bell. See [Connecting integrations](docs-integrations.html).

The one exception is the teammate invitation, which is sent by WorkOS, our identity partner, from its own sending domain. If invitations are the thing that is not arriving, that is the sender your mail team needs to let through.

## Connecting your AI assistant

### Can my AI assistant see other customers' data?

No. Your assistant connects to your own workspace only. The workspace it can reach is derived from your verified Zovos sign-in and never from anything the assistant supplies. It can never read another customer's data, and it only ever acts within your own Zovos role. See [Connect your AI assistant](docs-connect-ai-assistant.html).

### Does Zovos send my data to the assistant vendor?

No. You choose the assistant, and Zovos only answers the authenticated requests it makes on your behalf. Zovos never pushes your data to a vendor it selected, and your data is never used to train a foundation model. Your system credentials and logins never reach Zovos at all. When an assistant runs a control test, it authenticates to your systems with your own credentials on your own machine. What Zovos holds is described on the [security page](security.html).

### How do I turn the connector on, and which assistants work?

An owner enables it per workspace under **Settings → Integrations → AI assistants**. It is off until they opt in. Once on, you can connect Claude, ChatGPT, Cursor, Microsoft Copilot, or Gemini by pointing the client at the Zovos endpoint and signing in with your organization selected. The per-client steps are in [Connect your AI assistant](docs-connect-ai-assistant.html).

### Can the assistant change or approve things on its own?

No. A control test it submits waits for a reviewer other than you before any rating changes. Imports, rollbacks, new tasks and comments on a finding or a risk show a dry run and write only after you confirm. Evidence and import-file uploads are stored when the assistant makes them, but change no register or rating on their own. The assistant can never approve, sign, or dispose of anything, it can never change a record's status, and it cannot administer users. Those actions stay with a named person under separation of duties. Every tool call is recorded in your audit trail, and an examiner session cannot read or change any workspace data over the connector.

### How do I disconnect an assistant?

An owner opens **Settings → Integrations → AI assistants → Connected clients**, which lists every connected assistant and when it was last active, and clicks **Revoke** to stop that client on its next request. It can be restored later from the same panel.

## Testing controls with your own AI assistant

### Can I really run a control test with my own AI assistant?

Yes. With the Zovos Evidence Protocol you point your own assistant at Zovos. That can be Claude, GitHub Copilot, Cursor, or ChatGPT. The assistant fetches the published procedure, runs the test with its own tools against your own system, and submits the result plus the raw evidence. An administrator enables it per workspace under **Settings → Integrations → AI assistants**, and you need a verified email. See [Test controls with your own AI assistant](docs-ai-control-testing.html).

### Does an AI submission change our control ratings on its own?

No. Every external submission enters "pending review" and nothing moves a rating until a person distinct from the tester accepts it. On acceptance the outcome maps to effectiveness, the owner's attestation for the period is satisfied, and a failed test opens a draft finding. By default 5 % of accepted submissions are randomly re-tested. Your administrator can set that anywhere from 0 to 100 %.

### Does Zovos get our system credentials or logins?

Never. Your assistant authenticates to your system with your own credentials on your own machine. Zovos receives only the result and the artifacts you attach. The tester of record is you, derived from your Zovos login. The assistant's name and model are recorded but shown UNVERIFIED, and they are never an authorization signal.

### What must we never upload as evidence?

Never upload credentials, tokens, API keys or connection strings. Never upload SAR, BSA/AML or CTR content, which is legally confidential. Never upload customer PII beyond the minimum the control requires. Strip them before upload. Zovos also scans every artifact, refuses credential or SAR content, and quarantines PII. That scan is a backstop, and it does not replace keeping this material out.

## Pricing

### Does adding an access group change our price?

No. Building an access group, giving it to more people or mapping it from your directory never changes the price. An access group only bundles roles, job families and a scope.

### Do job families or seat counts change the price?

No. Zovos is priced by your institution's asset tier, and every module is included at every tier. Job families never change the price. The price is not set per seat either. Your agreement records a contracted seat count for planning, and the seat usage shown in settings is informational rather than a cap. Current tiers are on the [pricing page](pricing.html).

## Reaching support

Email support from the [support page](support.html). We usually acknowledge new requests within a week, and anything blocking an examination is handled first. Tell us the screen, what you expected, and the display ID of the record involved. That is usually enough for us to find it without asking you for a second round of detail.
