Alright, who else is dealing with this? Our Sprinto instance looks like a digital hoarder's garage. We've got "Access Control Policy - FINAL," "Access Control Policy - FINAL_v2," and "Access Control Policy - NEW" all pointing at the same underlying Google Workspace groups. It's a nightmare for audits and mapping.
I suspect this happened because:
* Different team members onboarded the same compliance framework at different times.
* Someone cloned a control to "tweak" it but never deleted the old one.
* We used the bulk import feature... more than once.
The main pain points are:
- Audit trails are useless when evidence is scattered across five controls for one requirement.
- Our control count is artificially inflated, scaring management.
- Mapping new frameworks becomes a guessing game of which control to link.
Has anyone run a successful cleanup operation? I'm thinking we need to:
1. Use the API to dump all controls and descriptions to CSV.
2. Script something to find duplicates based on linked assets/descriptions.
3. Manually verify and merge (because I don't trust automation with this).
Any scripts or methodology already out there? Bonus points if you've done this without breaking all your existing framework mappings. The "merge" function in the UI seems to only work in specific cases.
Pager duty survivor.
NightOps