Cadres IT Operations & Infrastructure
Sheet MER-04 Rev 2026.08
Start Trial

Sheet MER-04 — Audit & Compliance Manual

Programs

Program structure, scope ownership, framework planning, and the operating boundary for a compliance effort.

Audience: Compliance managers and program owners Focus: Program structure and scope control

Scope

Programs are the organizing layer Meridian uses to keep frameworks, controls, and operating ownership from turning into a disconnected spreadsheet exercise. The public guide keeps the working model and removes private setup and integration detail.

The programs workspace supports server-side name search alongside status filtering. Audit periods are calendar dates: Meridian renders the submitted day exactly and does not shift it through the operator’s local timezone.

Programs List

Navigate to Programs in the sidebar to see all compliance programs for your account.

Keyboard Navigation: Program rows in the table are keyboard-navigable. Tab to a row and press Enter or Space to open the program dashboard.

Search and status filters run on the server and keep pagination totals authoritative. If the program service fails or returns an invalid page, Meridian clears the non-authoritative rows and shows Retry. The page rejects duplicate program identifiers, mixed-account results, malformed lifecycle/type values, incoherent pagination metadata, and invalid dates instead of rendering them. When searches or filters overlap, only the newest response may update the table.

If the account is in the read-only billing recovery window, the list remains visible but creation entry points are hidden and Meridian shows a renewal hint instead of letting you start a write flow. If the account is hard-expired or Meridian cannot confirm a usable billing contract, the Programs page shows billing recovery guidance instead of a retryable list error.

Hard-expired and contract-locked states also clear any previously rendered program page so protected tenant data is not left visible behind the recovery block. License recovery refreshes the account contract first; the list is fetched again only after the refreshed license state permits it.

Creating a Program

  1. Navigate to Programs in the sidebar.
  2. Click New Program (requires Meridian.manage permission).
  3. Follow the intent-first creation wizard:

Step 1: Intent — “What are you certifying?”

The wizard opens by asking the actual outcome you’re working toward, not an internal taxonomy choice:

  • SOC 2 Type 1 (the default preset — matches the Starter · SOC 2 Type 1 plan): a point-in-time snapshot proving your controls are designed correctly.

  • SOC 2 Type 2: proof your controls operated effectively over a period.

  • SOX ICFR: Internal Control over Financial Reporting program (requires the SOX add-on — locked with an upgrade link if the account doesn’t have it).

  • Something else: reveals the underlying Program Type choice (GRC vs SOX ICFR) and a generic framework picker for anything outside the three presets above. This is the only path where the GRC-vs-SOX-ICFR taxonomy is a decision you make explicitly — the two SOC 2 presets set it for you.

Picking a SOC 2 preset automatically binds the SOC 2 framework and its Type 1/Type 2 target level; you confirm applicability on the next step instead of re-picking the framework from a generic list.

Below the preset cards:

  • Name (required): a descriptive name for the compliance program (e.g., “SOC 2 Type 1 Certification 2026”).

  • Accountable owner (required): defaults to you.

  • Description: optional context about the program’s purpose.
  • By when do you need this ready?: Audit Period Start/End dates. End must not be on or before Start — the wizard blocks Next with an inline message, and the backend rejects the same condition authoritatively even if the frontend check is bypassed.

If the current account has the SOX add-on, the Programs list also shows a dedicated New SOX Program entry point that pre-selects the SOX ICFR intent. If the account does not have the SOX add-on, the wizard shows the SOX card locked with an upgrade link (tenant administrators) or a note to ask a tenant administrator (non-administrators).

Step 2: Frameworks & Applicability

SOC 2 Type 1 / Type 2 intent: confirms the SOC 2 (2017) framework and report type already selected in Step 1, then asks which Trust Services Criteria apply. Common Criteria (Security) is always included — every SOC 2 report covers it — and is shown checked and locked. The other four families (Availability, Confidentiality, Processing Integrity, Privacy) default to checked (matching the previous “instantiate everything” behavior) and can be unchecked individually. Meridian only creates controls for the checked categories, so narrowing to Security alone no longer means manually marking ~30 controls Not Applicable after the fact. You can add more TSC families to an existing program later from the program detail page’s framework management panel.

SOX ICFR / “Something else” intent: the generic framework picker — browse frameworks available on the account’s current plan (a Starter account only sees SOC 2 unless the contract explicitly allows another framework key), check the ones this program will cover, and choose a target level per framework if it has maturity levels. At least one framework must be selected before Next is enabled; the backend rejects a zero-framework create request the same way even if the frontend gate is bypassed — a program with no framework has nothing to certify against.

Step 3: Scope Organizations

  • Add organizations that will be covered by this program, or create a new one inline right here (+ Create a new organization) without leaving the wizard — useful for a brand-new tenant that has no organizations yet.

  • Scope selected here is applied atomically with the program. If any selected organization is archived, missing, duplicated, or outside your account, the create request fails and no partial draft is left behind.

  • Scope is optional at creation, but Meridian will block activation later until at least one organization is scoped (or an approved unscoped- activation exception is on file) — the wizard says this explicitly instead of a vague “add them later.”

Step 4: Review & Create

  • Review your selections — including the TSC applicability list for SOC 2 programs — and click Create Program.

  • The program starts in draft status.

  • Draft programs do not consume an active-program license slot. The slot is consumed only when the program moves to Active or In Audit.

  • Duplicate-submission protection: if you (the same user) submit the exact same program name and type again within 30 seconds — a double-click or a network retry — Meridian does not create a second program. It returns the program it already created and shows a toast explaining that. Submitting the same name again after that window, or as a different user, creates a genuinely new program as normal.

Program Statuses

Status Meaning What You Can Do
Draft Program is being set up Modify all settings, add/remove frameworks and scope, archive immediately
Active Program is operational Same as draft, plus controls and evidence apply
In Audit Under active audit review Same as active. Return to Active after audit.
Archived Completed or retired Read-only. No modifications possible. Audit cycles, findings, controls, evidence, and related governance links are frozen.

Transitioning Program Status

From the program detail page, use the action buttons in the top-right:

  • Activate: Move from draft to active when the program is configured.
  • Start Audit: Move to in_audit when an audit begins.
  • End Audit: Return to active after audit completion.
  • Archive: Permanently archive the program from draft, active, or in-audit.

Archiving is irreversible. Draft programs can be archived directly without activating them first.

Before Meridian activates a draft, add at least one Scope Organization. This is the normal path because scope identifies the business units the program covers. If scope is intentionally not ready, Meridian opens an Activate without organization scope decision instead of activating silently. The accountable owner must select a current, independently approved unscoped activation exception from Governance, acknowledge the stated consequences, and activate it. That exception must document rationale, compensating action, and a review trigger; Meridian records the owner acknowledgement and exception in the program audit trail. If no exception is available, use Open Obligations in the decision to create and obtain independent approval for one, or add organizations and activate normally. Complete the compensating action and add scope before the exception expires.

If the account has already reached its active-program plan limit, Activate is blocked with a licensing error until a counted program is archived or the contract is widened.

Editing Program Metadata

From the program detail page, click Edit Program in the top-right (visible when you have Meridian.manage and the program is not archived). This opens a modal that edits:

  • Name (required)
  • Description
  • Audit Start and Audit End dates

success/failure via a toast notification. Frameworks and scope are managed from the panels below the page and are not part of this form. While the save is in progress, Meridian keeps the modal open and disables both Save and Cancel so an in-flight update cannot be mistaken for a discarded edit.

The program detail header and Program Info card both show the current program type (GRC or SOX ICFR) so operators can confirm which workflow family the program belongs to.

Managing Frameworks

From the program detail page:

  • Click Add next to the Frameworks section header.
  • Select a framework and optional target level from the dialog. The framework picker identifies both the framework version and whether it is a system or account-owned custom framework.

  • If the account includes cross_framework_mapping, Meridian opens Mapping Suggestions for the newly added framework after the save succeeds.

  • If the account does not include cross_framework_mapping, Meridian keeps you on the program detail page and refreshes the framework list instead of sending you to an unavailable mapping workflow.
  • To remove a framework, click the trash icon next to it.

Cannot modify frameworks on archived programs.

The program quick-link bar includes Access Reviews for operators who can view access-review work. It opens the program-scoped campaign workspace, where authorized compliance managers can create a Meridian review or select a named, tenant-scoped Portal campaign through Import from Portal. Campaign authoring remains in Portal; Meridian adopts a read-only source packet and keeps its local reviewer decisions and remediation tasks separate. See for reviewer recovery, evidence, and closeout procedures.

The Access Reviews link remains available on archived programs for read-only history. The destination suppresses mutation controls when the program or review lifecycle does not permit changes. The quick-link bar only shows Mapping Suggestions and Framework Comparison when the account includes the cross_framework_mapping plan feature, and only shows Export OSCAL when the account includes oscal_export. Every visible quick link has a stable workflow selector, and the complete SOX link set is shown only for a sox_icfr program when the operator has a qualifying SOX or Meridian view permission.

Governed framework removal and exceptional unscoped activation remain open while their mutation is in flight, including when the operator presses Escape. This prevents an async decision from disappearing before its outcome is known. If the required approved exception is missing, Open Obligations is the recovery path.

Managing Scope

Multi-program scope selectors resolve their saved selections in one bounded lookup. If a selected program no longer exists or is not visible in the current tenant, Meridian keeps the ID visible as Unknown program, explains that it could not be resolved, and allows you to remove it. It does not silently drop the selection or treat a lookup failure as an empty result. Use the selector’s Retry action after restoring connectivity or access. At most 50 selected programs can be resolved in one request.

From the program detail page:

  • Select an organization from the picker and click Add to include it in scope.
  • Click x on an organization badge to remove it from scope.

Cannot modify scope on archived programs.

Browsing Frameworks

  1. Navigate to Frameworks in the sidebar.
  2. Browse system frameworks (available to all) and custom frameworks (account-specific).
  3. Click a framework to view its requirements.

Filtering Requirements

On the framework detail page:

  • Category: Filter by requirement category (e.g., “Common Criteria”, “Availability”).
  • Necessity: Filter by obligation level (must/should/may).
  • Level: Filter by maturity level (shows level-specific + level-agnostic requirements).

Requirements are grouped by category with collapsible sections.

Creating Custom Frameworks

Account administrators can create custom frameworks:

  1. Navigate to Frameworks.
  2. Click New Framework (requires Meridian.manage and the custom_framework_builder plan feature).

  3. Provide a key, name, version, and optional description.

  4. After creation, open the framework detail page and click + Requirement to add individual requirements. This detail-page action requires Meridian.manage on a custom framework; system frameworks are immutable and never show the button. The modal binds reference id, title, description, category, necessity (must / should / may), sort order, and optional level. The reference id must be unique within the framework. System frameworks are immutable and do not show the button.