Controls are the central object in 6clicks' compliance data model -- everything connects to and from them: evidence, tests, tasks, framework provisions, assets, and systems. This feature rebuilds the Controls module on the same Custom Registers architecture used across the platform, placing controls at the heart of a connected compliance data model and unlocking capabilities that were not possible with the legacy module.
Teams can migrate on their own timeline. The legacy Controls module remains fully functional during the transition, and migration is opt-in and customer-controlled.
Key Components:
- Controls Register: A dedicated out-of-the-box register for creating and managing controls, with all standard fields preserved from the legacy module. Control sets allow controls to be organised, grouped, and reused across frameworks and programs.
- Many-to-Many Linking: Controls link to evidence, tests, tasks, and framework provisions in any direction. A single control can satisfy multiple provisions across multiple frameworks simultaneously, and compliance status assessed on a control propagates automatically to every linked provision.
- Hailey Evidence Validation: The control record surfaces a consolidated view of all Hailey evaluations across all linked evidence and tests, giving control owners and compliance managers a single place to see the full validation picture without navigating across individual records.
- Scope Awareness: Filter and manage controls by system or framework, supporting organisations with distinct OT and IT environments, multiple regulatory jurisdictions, and complex entity structures.
- Knowledge Graph Foundation: Linkages across controls, assets, systems, evidence, and tests form the connected data structure that enables Hailey to reason across the full compliance object model and supports future agentic capabilities.
Benefits:
- Compliance status assessed once on a control flows automatically to every linked framework provision, eliminating the need to re-assess the same control multiple times across different frameworks.
- Many-to-many linking removes the architectural constraints of the legacy module without disrupting existing workflows.
- Consolidated Hailey validation on the control record reduces time spent navigating across tasks, evidence, and tests to understand the overall compliance picture.
- Scope awareness keeps views clean and relevant for teams with different responsibilities across complex hybrid environments.
- Consistent UX across all registers reduces onboarding time for teams managing multiple compliance objects.
- Customers migrate at their own pace, with no forced cutover and full parity maintained throughout.
Example use case:
A security team at a critical infrastructure operator manages compliance across ISM, Essential Eight, and SOCI simultaneously. After migrating to the new Controls Register, they discover that 40% of their controls map to provisions across more than one framework. Assessments now propagate automatically, eliminating the duplicate effort of re-assessing the same control three times. When a new SOCI obligation is mapped to an existing ISM control, compliance status flows through immediately with no additional assessment work. The control record surfaces a consolidated Hailey validation summary across all linked evidence and tests, giving the compliance manager a single view of what has been validated, what is outstanding, and what was submitted through automated integrations versus manual task workflows.