Documentation

Meridian Manual

Meridian covers programs, controls, evidence, audits, reporting, remediation, trust workflows, and SOX-capable oversight.

Audience: Compliance, risk, audit, and operating leadsFocus: Programs, evidence, audits, and remediationStatus: Public manual

Meridian Manual

What this manual covers

Meridian is the Cadres operating system for audit, compliance, and control follow-through. It brings programs, controls, evidence, reporting, remediation, and stakeholder visibility into one working model.

This manual is written for the teams who need Meridian to stay understandable in production. It starts with the public operating model, then layers in detailed operator guides drawn from the product manuals without exposing private implementation or setup material.

Meridian Topics

Browse the manual.

Compliance Core

Compliance Core

Programs, Controls & Evidence

Program structure, framework mapping, control ownership, evidence models, and operational posture.

  • Programs, frameworks, policies, and control ownership
  • Evidence coverage, gap analysis, and control intelligence
  • Risks, maps, dashboards, and multi-framework posture

Compliance Core

Evidence & Audit Operations

Evidence readiness, audit workflow, auditor collaboration, questionnaires, and review cadence.

  • Evidence lifecycle and review readiness
  • Audit workflow, auditor portal, and questionnaires
  • Audit reports, scheduled reporting, and bulk review operations

Oversight & Follow-through

Oversight & Follow-through

Reporting, Remediation & Trust

Executive reporting, trust workflows, remediation follow-through, reviews, and stakeholder visibility.

  • Executive summaries, reporting, and stakeholder-ready views
  • Trust center workflows and controlled external communication
  • Remediation bridge, alerts, and follow-through into operating work

Detailed Operator Guides

Detailed Operator Guides

Programs

Program structure, scope ownership, framework planning, and the operating boundary for a compliance effort.

  • Creating a Program
  • Step 1: Program Details
  • Step 2: Select Frameworks

Detailed Operator Guides

Controls

Control creation, ownership, mapping, exceptions, testing, and the workflow that makes a control library usable.

  • Creating Controls
  • Naming Conventions
  • Managing Control Status

Detailed Operator Guides

Control Intelligence

Coverage analysis, control relationships, and higher-signal views that help teams manage a control estate as it grows.

  • Getting Started
  • Reading Program Health
  • Requesting Program Health (Step-by-Step)

Detailed Operator Guides

Evidence

Evidence collection, review state, freshness, and the working practices that keep evidence tied to real controls.

  • Uploading Evidence
  • File Upload
  • What happens on upload

Detailed Operator Guides

Evidence Coverage

Coverage visibility, readiness gaps, and the relationship between controls, evidence, and audit confidence.

  • What the Coverage Grid Shows
  • Reading Cell States
  • Understanding Auto vs. Manual Bindings

Detailed Operator Guides

Gap Analysis

Requirement coverage, gaps, exceptions, and the review model teams use to judge audit readiness honestly.

  • Getting Started
  • Using Gap Analysis
  • Viewing the Gap Analysis

Detailed Operator Guides

Audit Workflow

Audit planning, request handling, operator coordination, and the cadence that keeps audit work from becoming a scramble.

  • Step 1: Create the Audit Cycle
  • Step 2: Move to Fieldwork
  • Step 3: Review Controls

Detailed Operator Guides

Auditor Portal

Bounded external access, auditor collaboration, and the model Meridian uses to share review material without losing control.

  • Inviting Auditors
  • Creating an Invite
  • What the Auditor Receives

Detailed Operator Guides

Audit Reports

Audit outputs, review packages, and the reporting layer teams use to communicate current audit state clearly.

  • Audit Report
  • When to use it
  • Reading the MAP badges

Detailed Operator Guides

Access Reviews

Periodic access review execution, reviewer accountability, and the workflow that keeps sensitive access visible.

  • Creating a Review Campaign
  • Importing Access Data
  • CSV Requirements

Detailed Operator Guides

Executive Summary

Leadership-facing posture views, concise status communication, and the summaries used to explain program state without flattening it.

  • Getting Started
  • Reading the Page
  • Readiness Dial

Detailed Operator Guides

Reporting

Operational reporting, stakeholder visibility, and the reporting surfaces used to track posture over time.

  • Generating Reports On Demand
  • Report Builder
  • Audit Reports

Detailed Operator Guides

Scheduled Reports

Recurring reporting cadence, audience targeting, and the operational discipline around scheduled compliance output.

  • Getting Started
  • Managing Scheduled Reports
  • Creating a Scheduled Report

Detailed Operator Guides

Remediation Bridge

Findings-to-action workflow, ownership handoff, and the model Meridian uses to keep remediation tied to real systems and teams.

  • What It Does
  • Setting Up the Jira Connector
  • Finding the Issue Type ID

Detailed Operator Guides

Trust Center

Controlled external communication, trust materials, and the process for showing posture without oversharing it.

  • Building Your Trust Center
  • Step 1: Create the Trust Center
  • Step 2: Add Content

Detailed Operator Guides

Risks

Risk tracking, ownership, and the way Meridian keeps exposure tied to the controls and findings that drive it.

  • Creating a Risk
  • Editing a Risk
  • Deleting a Risk

Detailed Operator Guides

Risk Heatmap

Concentration of exposure, prioritization signals, and the visual model teams use to discuss risk with leadership.

  • Getting Started
  • Using the Heat Map
  • Viewing the Heat Map

Read Path

Where teams usually start.

  1. Start with Programs, Controls & Evidence to understand how Meridian organizes programs, control ownership, evidence, and posture.
  2. Move to Evidence & Audit Operations when audit readiness, auditor collaboration, and review workflow are the immediate concern.
  3. Use Reporting, Remediation & Trust for executive visibility, trust communication, ongoing follow-through, and connected operating work.

Native Handoffs

How Meridian connects to the suite.

Portal

Portal supplies identity and access context that Meridian can use for reviews, evidence, and access-related controls.

Keystone

Keystone gives Meridian business and financial operating context when commercial or finance controls need to be monitored.

RMM

RMM gives Meridian operational signals and remediation context when infrastructure or endpoint control becomes part of the control environment.