Skip to main content

What runs automatically

A lot of GRC work is not a project you finish — it is a state you maintain. Evidence ages, cloud configurations drift, vendors have bad weeks, new findings appear. SolveGRC does a standing amount of this upkeep on its own, between your logins, so the platform you open in the morning already reflects what changed overnight. This page is the plain-language version of what happens while you are not looking.

As you work — right away

Some things happen the moment you act, without a schedule:

  • A document you upload is extracted, chunked, embedded, registered as evidence, and quality-scored — usually within moments, so it is immediately searchable and citable.
  • A questionnaire you import is parsed into individual questions, ready to answer or route to the AI.
  • An answer you approve becomes reusable evidence and preferred wording for next time.

You do not trigger any of this separately. Feeding the platform is the trigger.

Every few hours — the cloud keeps itself current

If you have connected a cloud account (read-only), SolveGRC re-syncs it on a regular cycle through the day. Each sync:

  • Pulls the current inventory and re-checks it against compliance standards, so findings arrive already mapped to the frameworks they affect.
  • Redraws topology and attack paths from the live state.
  • Watches for anything security-significant — a newly public resource, a loosened permission — and records it in a change feed, emailing you when something crosses a line that deserves attention.

The effect is that your cloud does its own paperwork. You are not exporting configs and diffing them by hand; the platform is doing that continuously and only interrupting you when it matters.

Every night — the quiet maintenance pass

Overnight, SolveGRC runs the housekeeping that keeps yesterday's conclusions honest today:

  • Freshness. Evidence that has aged past its useful window is marked stale so it surfaces as work instead of quietly propping up a score.
  • Drift. The platform looks for controls and posture that have moved away from where they should be, so a gap that opened up doesn't wait for your next manual review to be noticed.
  • Vendor monitoring. Third-party risk signals refresh, so a vendor's changing situation shows up on your side without you polling them.
  • Recompute. Compliance positions are recalculated from the latest evidence and assessments, so the number you see in the morning reflects last night's reality — not last week's.

Why it works this way

Continuous, scheduled upkeep is what separates a compliance snapshot from a compliance program. A once-a-year scramble tells you where you stood on one day. A platform that re-checks freshness, drift, and vendor signals every night tells you where you stand right now, and hands you the short list of things that changed. That standing awareness is the product.

What this means for you

  • Trust the morning view. What you see at login already accounts for overnight changes — you are not looking at a stale board.
  • Watch your inbox for the cloud change feed. The alerts SolveGRC sends are the ones worth interrupting you for; the rest is handled quietly.
  • Refresh what the sweeps flag. Stale evidence and new drift are pre-sorted into your work queue — clearing them is how the automation pays off.
What we don't expose

You can see what the platform checked and what changed. The exact schedules, the thresholds that decide when a change is "significant," and the rules behind drift and vendor scoring stay internal — that is what keeps the signals reliable and hard to game.