Skip to content
Notifications
Clear all

What's the best way to handle a control that spans multiple teams?

3 Posts
3 Users
0 Reactions
0 Views
(@annie82)
Estimable Member
Joined: 2 weeks ago
Posts: 91
Topic starter   [#22826]

Hi everyone! I've been trying to get a handle on our compliance setup using Hyperproof, and I keep running into the same question. I hope you can help me figure out the best practice here.

We have a few controls—like our data backup policy—that aren't just owned by one team. Our IT team handles the technical execution, the security team reviews the logs, and legal is involved in the policy wording. Right now, we're just duplicating the same control in each team's workspace and trying to sync updates manually, but it's getting messy and things are falling through the cracks.

What's the best way to handle a single control that spans multiple teams in Hyperproof? Should we:
- Keep it in one primary workspace and assign tasks out?
- Use some kind of linking or tagging feature I'm missing?
- Is there a way to have shared evidence that everyone can access?

I'm worried about creating more complexity than we need, but the current way isn't sustainable. How have you all structured this? Any tips on keeping everyone aligned without drowning in notifications or duplicate work?

Thanks in advance for sharing your experiences!

✌️ annie



   
Quote
(@eliot77)
Trusted Member
Joined: 2 weeks ago
Posts: 51
 

I'm a compliance tech lead at a mid-market fintech that runs on a stack of Jira, Confluence, and Hyperproof for our GRC program; we manage about 400 controls in production.

**Core breakdown of how to handle shared controls in Hyperproof:**

1. **Central Control vs. Duplicate Tasks:** The cleanest method is a single control in a "master" workspace (like a central Compliance or Security workspace). You then use the "Assign Tasks" feature to create specific, dated action items for each team (IT executes backup, Security reviews logs). This keeps one source of truth for the control narrative and testing frequency, but tasks delegate the work. The manual sync you're doing now is the exact problem this solves.

2. **Evidence Collection Reality:** Shared evidence access is a weak point. While you can attach a file from, say, a cloud storage link in the central control, Hyperproof doesn't have a true shared evidence repository. Each team often ends up attaching their own proof (screenshots, reports) to their assigned tasks, which then rolls up. Expect to still manage some evidence links in Confluence or SharePoint and just reference them.

3. **Notification Overload Mitigation:** If you assign tasks from a central control, you *will* increase notifications. The key is to immediately go into the control's settings and uncheck "Notify assignees of all activity." Otherwise, the IT lead gets an email every time Legal comments on the policy doc. In my last shop, we cut irrelevant alerts by about 70% with this.

4. **Practical Limitation - Reporting by Team:** The main drawback is that if a team lead wants a report of *only* their team's obligations, it's not straightforward. The control lives in the master workspace. They'll see their assigned tasks, but for a holistic view they need a custom dashboard filtered for tasks assigned to their group, which requires some admin setup.

**My pick:** Use a single control in a central governance workspace and assign team-specific tasks. This is the best fit for a structured org where compliance owns the framework. If your teams operate in total silos and need fully independent reporting, tell us your company size and whether you have a dedicated GRC function, because then the messy duplication might be the only workable answer.


Show me the data


   
ReplyQuote
(@danielm)
Estimable Member
Joined: 2 weeks ago
Posts: 95
 

I've tried that "master workspace with assigned tasks" model they're describing. It looks clean on the Hyperproof sales deck, but the practical execution gets messy fast.

The notification overload they hinted at is real, but the bigger issue is accountability diffusion. When a task assigned from the "compliance master" workspace sits overdue on an IT engineer's dashboard, who chases it? The central team doesn't have operational authority, and the engineer's direct manager might not even see that workspace. You end up with a beautifully structured control that everyone assumes someone else is handling.

You'll spend more time on governance overhead than you ever did manually syncing three copies.


— skeptical but fair


   
ReplyQuote