Platform
Govern the rulebook your analysis runs against.
Import a GRC Access Control ruleset, convert it into one clean model, and author your own rules on top of a shared base library — then approve and activate it. Nothing gets analysed against an unapproved rulebook, which is exactly what makes the conflicts downstream defensible when an auditor asks where a rule came from.
Authorruleset-check
Govern the rulebook every SOD check runs against
- 01Import
- 02Author
- 03Approve
- 04Activate
GRC AC export→base v4approved and activated before anything is analysedRisks 214Functions 118T-codes 512Auth objects 361
- Import and convert. Bring in a GRC Access Control or Pathlock ruleset export and convert it into one clean model — with a dry-run preview of what will change before anything is committed.
- Author on a shared base. Build and version client-specific rules on top of a shared base library, so every engagement starts from the same known-good policy instead of a fresh spreadsheet.
- Approve, then activate. Analysis only runs against an approved, activated base ruleset. That gate is what makes every downstream conflict defensible when an auditor asks where the rule came from.
Ruleset Check · Base RulesSearch… ⌘KAC
Active base ruleset
activev4 version214 risks118 functions512 T-codes361 auth objects
Converted from a GRC AC export · approved by D. Okafor on 6/14/2026. Analysis will not run against an unapproved ruleset.
| Risk ID | Risk name | Rating | Area | Functions |
|---|---|---|---|---|
| FI-001 | Post and Approve AP Invoices | CRITICAL | FI | 2 |
| FI-002 | Vendor Master and Payment Processing | HIGH | FI | 2 |
| MM-001 | Create PO and Post Goods Receipt | HIGH | MM | 2 |
| BASIS-001 | Create Users and Assign Roles | CRITICAL | BASIS | 2 |
| SD-001 | Sales Order and Credit Release | MEDIUM | SD | 2 |
Pending import · dry-run preview
18 added7 changed189 unchanged4 awaiting approval
Nothing is committed until an org admin approves the version and sets it as base.
Interactive replica · illustrative data — no real client systems or content.
Try Ruleset Check in the live app ↗