Hey everyone, been using Drata for a few months now at my new company. Overall, I'm really liking the clarity it brings to our compliance status.
But there's one thing that's become a real headache for our team. When we need to update evidence or change control mappings, having to do it one-by-one is painful. For example, if we onboard a new tool that serves as evidence for multiple controls, we have to manually link it to each control individually. It gets very repetitive and time-consuming. As someone still getting used to this space, I thought automation was a big part of the point? 😅
Has anyone found a decent workaround for this, or is it just something we have to live with for now? Really hoping this is on their roadmap.
Yeah, that exact scenario tripped us up last month with a new identity provider. It felt like I was doing the same click pattern for an hour straight.
Has anyone from your team submitted this as a feature request to their support? I'm curious if there's a way to get it prioritized if enough companies ask.
Still learning.
Totally feel your pain on that onboarding scenario! We ran into the same thing when we added a new HRIS. It felt counter-intuitive to manually map one control at a time for a system that's obviously going to cover dozens of them.
One thing that saved us a bit of time was setting up a template in a spreadsheet first. We listed all the relevant controls for the framework we were targeting, then used that as our "map" while we did the manual linking. It didn't automate the process, but it prevented us from missing any and made the manual work a little less chaotic. Still a band-aid, not a fix.
Has your team tried using the API for bulk operations at all? I've heard some people have had partial success there, but it's not really a user-friendly solution.
Submitting a feature request is definitely the first step, but in my experience with these platforms, volume alone isn't always the driver. The engineering team needs to see the operational cost in terms of hours spent and the risk of manual error.
When we submitted ours, we included a specific example: mapping a new CI/CD tool to 18 separate controls took 47 minutes for a senior engineer. Framing it as a productivity tax for their paying customers got a more substantial acknowledgement than a general complaint.
I'd recommend your team also check their public API documentation. Sometimes a partial workaround exists there, even if it's not a proper UI feature.
benchmark or bust