Help center
Closing the loop on a change.
A change is not done until it is connected. Kanonik names the missing step in the moment.
A single piece of work is rarely the whole job. A control on its own does not close a gap until it is connected to the requirement it covers. A risk is not handled until something treats it. A piece of evidence proves nothing until it is attached to the control it supports. The danger is a change that looks finished but is not, where you move on believing a gap is closed when the record still shows it open.
Kanonik is built so this does not happen quietly. When you make a change that needs a follow-up step to actually achieve what you intended, Kanonik tells you in the same moment, and lets you finish it in one approval rather than discovering the loose end later.
Why one step is often not enough
Compliance work is a web of connections, not a list of items. What makes a piece of work "done" is usually a relationship, not the item by itself:
- A control closes a requirement gap only once it is mapped to that requirement. Until then the control exists, but the requirement still reads as uncovered.
- A risk you intend to reduce is still open until a control treats it.
- A policy is not yet operating until a control implements it.
- A piece of evidence supports nothing until it is linked to the control or requirement it backs.
Each of those links is its own approved, recorded decision. That is what keeps the picture connected and provable for an auditor, rather than a flat pile of items with no relationships between them.
What Kanonik does about it
When you commit a change that leaves a follow-up step open, the response your AI gets back names the missing step in plain terms. For example, after you approve a new control that is meant to cover an ISO 27001:2022 Annex A requirement, Kanonik points out that the control is not yet mapped to that requirement, so the gap is still open, and tells you exactly what to do next.
You do not have to go hunting through a screen afterward to find the loose end. The next step is surfaced in the moment, in the same conversation, so you can deal with it while the work is fresh.
One approval, not several
Because the follow-up is part of the same intent, your AI can propose the whole set together (for example, the control, the link that maps it to the requirement, and the decision that the requirement is applicable) and you approve the entire set with a single click. The gap closes for real, right then, and every item still lands as its own sealed, approved entry on your record.
You can always do the steps one at a time if you prefer. The point is that nothing forces you to stop halfway by accident, and nothing leaves you guessing whether a change is truly complete.
Why it is built this way
The product's promise is that your record reflects reality. A control nobody connected to a requirement, or a risk nobody treated, would undermine that: it looks like progress on the surface while the underlying gap stays open. By surfacing the missing step the instant it appears, Kanonik keeps your record matching what you actually intended, and keeps an auditor from finding a half-finished change you did not know was half-finished.
This works the same way for every framework Kanonik supports.
More help
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email support@kanonik.ai and a person who works on the product answers.