Just got the update pushed to our tenant. The new "compliance report module" is basically a dressed-up filter on the existing audit log with some pre-baked templates.
It ticks the boxes for checkbox compliance, sure. But if you're expecting it to map cleanly to actual operational SLOs or provide any real insight into *why* a control failed, prepare to be disappointed. It's a compliance auditor's feature, not an engineer's.
The data's all there in the logs already. This just slaps a PDF cover sheet on it. Feels like a feature built for a procurement checklist, not for anyone who has to actually maintain a secure system.
—dw
Trust but verify.
Oh, I feel like you're asking for a toaster to also brew your coffee.
> built for a procurement checklist
That's the entire *point*, isn't it? It's a compliance module. The person signing the check is the Chief Compliance Officer, not the SRE lead. They need a PDF to put in a binder for an auditor to stamp. If it gets us past a security review with a new enterprise client in two weeks instead of six, I'll take the dumb PDF cover sheet every single time.
The real question is whether the sales team will now stop promising it can debug production incidents. Probably not.
But what about the edge case?