Compliance
Show who could open what, and why. Whenever you’re asked.
Doclave turns the access you already manage in Dynamics 365 into evidence. Every access change is recorded and traced to the role behind it, and regular checks show where you stand, and what to fix first. Your team works as today.
Compliance › Demo environment
Assessment completed
Overall score
62%
Medium risk
Checks passed
18 / 30
6 failed · 2 warnings
Findings
5
2 high
Frameworks
7
NIS2 · ISO 27001 · GDPR · +4
Framework
Score
Risk
Checks
NIS2
68%
Medium
29 applicable, 6 failed, 2 warnings
ISO 27001
64%
Medium
30 applicable, 7 failed, 2 warnings
GDPR
71%
Medium
24 applicable, 4 failed, 1 warning
Showing 3 of 7 frameworks
Illustrative view of the Doclave compliance assessment
Every access change traced to its role
Access history protected against edits
Your documents never leave your tenant
No obligation. We go through the findings with you and your IT lead.
NIS2 Directive (EU) 2022/2555, Art. 20 and Art. 21(2)(i)
01 — The question
Management signs off on it. Management answers for it.
NIS2 makes cybersecurity a management responsibility. The board approves the measures, oversees them and can be held accountable. For documents, it comes down to three questions. An auditor will ask all three.
Access
Who can open it?
Every permission tied to a role or a record, not a folder someone shared years ago.
Justification
Should they still?
Access that follows today’s role and team, and changes when they do.
Evidence
Can you prove it?
A record linking each access to the business decision behind it.
NIS2 Directive (EU) 2022/2555, Art. 20 and Art. 21(2)(i)
×
02 — The evidence gap
The access is managed. The proof is assembled by hand.
Roles live in Dynamics 365. Documents live in SharePoint. When the auditor asks, someone exports from both, matches them in a spreadsheet and samples the result. It’s slow, manual and out of date the day it’s delivered.
The auditor asks
Today
Do former employees still have access?
Checked by hand, if at all.
Who changed teams, and did their access follow?
Two systems, no shared record.
When did the consultant’s access end?
In Dynamics 365, yes. In SharePoint, unknown.
What did access look like on a given date?
Rebuilt after the fact.
Evidence rebuilt for every audit is a claim, not a record.
✓
03 — How the evidence builds
Every change leaves a record. Every check leaves a result.
Doclave builds the evidence while your team works. There’s nothing to collect before the audit.
The record
Every access change, recorded
When a role, team or owner changes in Dynamics 365, Doclave updates SharePoint access and records the change. Each entry traces back to the record and role that caused it, and the history is protected against edits.
✓ Traced to the Dynamics 365 record
✓ Time-stamped
✓ Protected against edits
The assessment
Your environment, checked
Doclave runs checks across your environment and maps each result to the frameworks you report on. Findings are ranked by severity, so you know what to fix first. Refresh the assessment whenever you need a current view.
✓ Findings ranked by severity
✓ Refresh on demand
✓ Every assessment time-stamped
Role change
Sales → Service
SharePoint access updated
Ref 7f3a…c21
✓ Recorded
04 — One check, many frameworks
Answer NIS2, ISO 27001 and GDPR from one place.
Requirements overlap. Doclave checks once and shows the result against each framework, so one piece of evidence answers several requirements.
Requirement
What Doclave records or checks
What you can show
Access control
NIS2 Art. 21(2)(i) · ISO 27001 A.5.15, A.5.18
Access follows the role in Dynamics 365. Every change is recorded.
Who could access what, and why
Information access restriction
ISO 27001 A.8.3 · GDPR Art. 25
Access granted per role and record, not per folder.
Access limited to business need
Effectiveness and security of processing
NIS2 Art. 21(2)(f) · GDPR Art. 5(1)(f), 32
Regular checks with findings ranked by severity.
Measures assessed, gaps tracked
Supports alignment with
NIS2 · ISO 27001 · GDPR
And more frameworks in the assessment
Doclave supports alignment. It doesn’t replace your legal, security or compliance obligations.
05 — Easy to review
Your auditor will review us too. We made that easy.
Under NIS2, your suppliers are part of your risk. Here’s what Doclave holds, and what it doesn’t.
Documents
Your documents stay in your tenant.
Doclave manages access. Your documents never leave Microsoft 365.
Visibility
Sensitive details hidden by default.
Only users with the right role can reveal sensitive data in the assessment.
Logs
Reference IDs, not names.
Logs hold reference IDs, never names or email addresses.
Hosting
Run from the EU.
Hosted in EU data centres and backed up on a 3-2-1 model.
See your own environment.
Let us run a readiness assessment on your own environment and go through the findings with you. Prefer to see it first? Book a walkthrough.
No obligation. We go through the findings with you and your IT lead.
