Skip to content
Notifications
Clear all

What's the best way to train non-technical team leads on using Drata?

5 Posts
5 Users
0 Reactions
9 Views
(@emmaj)
Reputable Member
Joined: 3 months ago
Posts: 305
Topic starter   [#25917]

I've been helping our marketing ops team get comfortable with Drata over the last few months, and training our non-technical leads was the biggest hurdle—but also the most rewarding part. They don't need to understand every technical control, but they do need to confidently navigate their team's compliance status and own their part of the process.

Here’s what worked for us:

**Start with the "Why," not the "How"**
Before any tool walkthrough, we held a short session explaining *why* our compliance framework matters for our customers and company. Connecting Drata tasks directly to client trust and deal velocity made it feel strategic, not just administrative.

**Role-Specific, Bite-Sized Sessions**
We avoided massive, generic trainings. Instead, we created separate 30-minute sessions for different leads:
* **Engineering Leads:** Focused on evidence collection for code management and access reviews.
* **Marketing Leads:** Covered vendor management and how to review/question security questionnaires.
* **People Ops Leads:** Trained on employee onboarding/offboarding checklists and policy acknowledgments.

**Hands-On with Real Scenarios**
We used our actual Drata environment in training, not a demo. We walked through:
* How to find and address *their team's* overdue tasks.
* How to interpret and respond to a failed control (we used a simple example like an expired password policy).
* Where to click to upload a piece of evidence or add a note.

**We also built a few simple job aids:**
- A one-page "Drata Cheat Sheet" with common actions and links.
- A flowchart for what to do when a control fails (e.g., "Assign? Fix? Request an exception?").
- A short checklist for their weekly 5-minute Drata hygiene check.

The key was making it relevant and low-friction. Now our leads treat it as a normal part of their workflow. What approaches have you all tried? I'd love to swap more practical templates.



   
Quote
(@edwardk)
Estimable Member
Joined: 3 months ago
Posts: 162
 

I'm an infrastructure engineer at a ~75 person SaaS company, and we use Drata for SOC 2 and ISO 27001 compliance with our cloud-native stack on AWS and GitHub.

1. **Target Fit**: It's great for mid-market tech companies (~50-300 employees) with a dedicated GRC or security person. For a tiny startup under 20 people, the per-seat cost and process overhead can be too much for the value.

2. **Real Pricing**: Expect $12-20K/year as a starting point. It's priced per employee (not just users in the platform), so headcount growth directly impacts cost. The sales process is firm on this model; you can't just license it for a handful of admins.

3. **Integration Effort**: Initial setup for core services (GitHub, AWS, Google Workspace, HRIS) takes 2-3 weeks of focused work. The data mappings and evidence tests aren't fully automatic - you'll spend time configuring what "passing" looks like for each control.

4. **Key Limitation**: It abstracts technical controls a lot. For non-technical leads, this is a benefit for basic navigation. For engineers, it can feel like a black box when a control fails, requiring you to dig into system logs outside Drata to diagnose the actual issue.

My pick is Drata, but only if you have that internal GRC point person to manage it. If you don't have anyone to own the framework itself, the tool's complexity will overwhelm your team leads. Tell us if you have a dedicated compliance manager and what your annual headcount growth forecast is.



   
ReplyQuote
(@crm_hopper)
Honorable Member
Joined: 7 months ago
Posts: 472
 

Role-specific sessions are the only sane approach. Generic training is a waste of everyone's time.

But you're being too nice about the hands-on part. Using your actual Drata environment is a must, but you have to lock it down first. I've seen leads get spooked and accidentally reassign critical controls because the interface isn't exactly intuitive for non-tech folks. Create a sandboxed demo with fake data if you can, or you'll spend more time fixing their navigation errors than actually training them.

That "strategic, not administrative" angle is crucial, though. Without it, they'll just see it as more audit paperwork.


CRM is a necessary evil


   
ReplyQuote
(@finops_auditor_ray)
Honorable Member
Joined: 6 months ago
Posts: 467
 

> "you have to lock it down first"

This is the real cost that never shows up in the vendor's sales deck. The sandboxed demo isn't free - it's engineering or IT time to build and maintain it. For a company paying $20k/year for the platform, that's another $5k in internal labor just to train people on it safely.

Most budget owners only see the subscription line item.


show me the bill


   
ReplyQuote
(@greentea)
Reputable Member
Joined: 2 months ago
Posts: 241
 

You're right about using the real environment. I found the risk of errors is actually higher if you don't, because they never build real context.

One specific adjustment: we didn't just run hands-on sessions. We paired each lead with a "compliance buddy" from our GRC team for their first two evidence submissions. It turned a training task into a live support channel and reduced follow-up questions by about 70%. The buddy wasn't there to do the work, but to be a quick reference for things like "which dropdown option do I pick here?" That immediate feedback loop built confidence faster than any demo.



   
ReplyQuote