> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# Use compliance plans

**Add-on product**: This feature is part of Configuration Manager Enterprise, a separately licensed add-on to Configuration Manager. [Learn more](/configuration-manager/overview#configuration-manager-enterprise).

Compliance plans schedule and manage comprehensive compliance reporting across multiple Golden Configurations. Use them to maintain regular compliance checks and generate audit reports.

## What are compliance plans?

Compliance plans orchestrate compliance checks across multiple Golden Configurations, device groups, and schedules. They provide centralized management for enterprise-wide compliance programs and generate consolidated reports for audit and analysis.

## How compliance plans work

Compliance plans follow this process:

#### Define scope

Select Golden Configurations and device groups to check

#### Set schedule

Configure when compliance checks should run

#### Execute checks

Run compliance across all defined scopes automatically

#### Generate reports

Compile results into comprehensive compliance reports

#### Distribute results

Send reports to stakeholders and archive for audit

## Create a compliance plan

To create a new compliance plan:

#### Open the create dialog

Click **Create (+)** in Configuration Manager

#### Select compliance plan

Choose **Compliance Plan** from the dropdown

#### Configure basic settings

* Enter a plan name
* Add a description
* Set the plan owner

#### Create

Click **Create** to open the compliance plan editor

## Configure compliance plan scope

Define what the plan should check.

### Add Golden Configurations

To include Golden Configurations in the plan:

#### Open the Scope tab

Navigate to the Scope section

#### Add Golden Configurations

Click **Add Golden Configuration**

#### Select configurations

Choose one or more Golden Configurations

#### Specify nodes

* Select specific nodes, or
* Include entire tree

#### Save selections

Click **Save** to add to the plan

### Add device groups

To include device groups:

#### Open the Groups section

Navigate to device groups in the Scope tab

#### Add groups

Click **Add Device Group**

#### Select groups

Choose one or more device groups

#### Save selections

Click **Save** to add to the plan

**Scope example:**

```
Compliance Plan: Enterprise Network Compliance
Scope:
  - Golden Config: Campus Switches (all nodes)
  - Golden Config: Data Center Switches (production node only)
  - Golden Config: Firewall Policy (all nodes)
  - Device Group: Branch Office Devices
  - Device Group: Core Network Devices
```

## Set compliance plan schedule

Configure when compliance checks run.

### Schedule options

| Schedule Type | When to Use                    |
| ------------- | ------------------------------ |
| Daily         | Regular compliance monitoring  |
| Weekly        | Comprehensive weekend checks   |
| Monthly       | Monthly audit reports          |
| Quarterly     | Regulatory compliance periods  |
| On-demand     | Ad-hoc compliance verification |

### Configure schedule

To set the plan schedule:

#### Open the Schedule tab

Navigate to scheduling configuration

#### Select frequency

Choose daily, weekly, monthly, or custom

#### Set time

Define when checks should run (consider maintenance windows)

#### Configure options

* Set timezone
* Define retry behavior
* Set timeout limits

#### Save schedule

Click **Save** to apply scheduling

**Schedule examples:**

**Daily monitoring:**

```
Frequency: Daily
Time: 2:00 AM local time
Days: Monday through Sunday
Retry: 2 attempts if failure
```

**Weekly audit:**

```
Frequency: Weekly
Day: Sunday
Time: 1:00 AM local time
Retry: 3 attempts if failure
Timeout: 4 hours
```

## Configure compliance reports

Define how compliance results are reported.

### Report settings

To configure reports:

#### Open the Reports tab

Navigate to report configuration

#### Select report format

Choose PDF, CSV, JSON, or HTML

#### Configure content

* Summary statistics
* Detailed device results
* Configuration diffs
* Trend analysis

#### Set retention

Define how long reports are stored

#### Save settings

Click **Save** to apply report configuration

### Report content options

| Content Type        | Description                        |
| ------------------- | ---------------------------------- |
| Executive summary   | High-level compliance statistics   |
| Device details      | Per-device compliance status       |
| Configuration diffs | Specific configuration differences |
| Trend analysis      | Compliance changes over time       |
| Exception list      | Devices with approved deviations   |

### Distribute reports

To configure report distribution:

#### Open the Distribution section

Navigate to report distribution settings

#### Add recipients

Enter email addresses for report recipients

#### Configure delivery

* Set delivery time (immediate or scheduled)
* Define format preferences per recipient
* Set notification preferences

#### Add integrations

Configure integration with ticketing or monitoring systems

#### Save distribution

Click **Save** to apply settings

## Run compliance plans

### Manual execution

To run a compliance plan immediately:

#### Open the compliance plan

Navigate to the plan in Configuration Manager

#### Run now

Click **Run Now** in the plan toolbar

#### Monitor progress

View real-time execution status

#### Access results

View or download reports when complete

### Scheduled execution

Compliance plans run automatically based on their schedule:

* Plan starts at scheduled time
* Compliance checks execute for all scoped items
* Reports generate upon completion
* Distribution occurs based on settings
* Results archive for audit purposes

## View compliance plan results

### Access plan reports

To view compliance plan results:

#### Open the compliance plan

Navigate to the plan in Configuration Manager

#### Open the Results tab

Click the Results tab

#### Select a report

Choose a report from the execution history

#### Review results

View summary and detailed compliance data

### Understand report data

Compliance plan reports include:

**Summary metrics:**

* Total devices checked
* Compliant device count
* Non-compliant device count
* Compliance percentage
* Comparison to previous runs

**Detailed results:**

* Per-device compliance status
* Configuration differences
* Golden configuration alignment
* Remediation recommendations

**Trend data:**

* Compliance percentage over time
* Recurring non-compliance issues
* Improvement or degradation trends
* Device-specific compliance history

## Manage compliance exceptions

Some devices may have approved deviations from Golden Configurations.

### Document exceptions

To add an exception:

#### Open the Exceptions section

Navigate to exceptions in the compliance plan

#### Add exception

Click **Add Exception**

#### Define exception

* Select device or device group
* Specify golden configuration node
* Describe the approved deviation
* Set expiration date (if temporary)
* Add approval documentation

#### Save exception

Click **Save** to document the exception

### Review exceptions

Periodically review documented exceptions:

#### Open the Exceptions tab

View all current exceptions

#### Check expiration dates

Identify expired or expiring exceptions

#### Validate necessity

Confirm exceptions are still required

#### Update or remove

Renew, modify, or remove exceptions as needed

## Best practices

**Plan scope strategically:**

* Group related Golden Configurations together
* Align plans with audit requirements
* Consider network segmentation
* Balance scope size with execution time

**Schedule appropriately:**

* Run during maintenance windows
* Avoid peak usage times
* Stagger large plans across time periods
* Consider device impact and load

**Manage reports effectively:**

* Customize reports for different audiences
* Archive reports for audit requirements
* Automate report distribution
* Set appropriate retention periods

**Handle exceptions properly:**

* Require approval for all exceptions
* Document business justification
* Set expiration dates for temporary exceptions
* Review exceptions regularly
* Update golden configs when exceptions become standard

**Monitor plan health:**

* Track plan execution success rates
* Review execution duration trends
* Monitor for recurring failures
* Adjust scope or schedule as needed

## Example: Enterprise compliance plan

**Plan: Monthly Security Compliance Audit**

**Scope:**

* Golden Config: Firewall Security Policy (all nodes)
* Golden Config: Switch Security Settings (all nodes)
* Golden Config: Router Security Baseline (all nodes)
* Device Group: Production Network
* Device Group: DMZ Devices

**Schedule:**

* Frequency: Monthly
* Day: First Sunday of each month
* Time: 12:00 AM EST
* Retry: 3 attempts
* Timeout: 6 hours

**Reports:**

* Format: PDF (executive) + CSV (detailed)
* Content: Summary, device details, diffs, trends
* Distribution:
  * CISO: Executive summary PDF
  * Network team: Detailed CSV
  * Security team: Full PDF report
  * Audit team: Archive all formats

**Exceptions:**

* Lab devices: Development configurations approved
* Legacy systems: EOL devices with documented risks
* Review cycle: Quarterly

## Troubleshoot compliance plans

### Plan execution fails

If a compliance plan doesn't complete:

* Check golden configuration validity
* Verify device connectivity
* Review execution logs for errors
* Confirm adequate execution timeout
* Check for scheduler issues

### Reports not generated

If reports don't appear:

* Verify plan completed successfully
* Check report format configuration
* Review storage capacity
* Confirm report generation settings
* Check for template errors

### Distribution fails

If reports don't reach recipients:

* Verify email addresses
* Check email server configuration
* Review distribution logs
* Confirm integration settings
* Test with manual distribution

## Next steps

#### [Golden configurations](/itential-platform/configuration-manager/golden-configurations/overview)

Create and manage baselines

#### [Build workflows](/itential-platform/studio/workflows/create-and-run-workflows)

Integrate compliance with orchestration