Cadres IT Operations & Infrastructure
Sheet MER-15 Rev 2026.08
Start Trial

Sheet MER-15 — Audit & Compliance Manual

Reporting

Operational reporting, stakeholder visibility, and the reporting surfaces used to track posture over time.

Audience: Compliance leads and stakeholders Focus: Reporting operations and visibility

Scope

Meridian reporting should reduce translation work, not create another reporting layer operators have to reconcile later. This guide keeps the operating guidance and omits private implementation detail.

Workstream: WS-21

Generating Reports On Demand

The on-demand report endpoints accept an optional ?format=pdf|csv|xlsx query parameter (default pdf). Tabular report types (compliance readiness, executive summary, risk report, audit report) support all three formats. The MSP Client Report supports PDF only.

Structured Compliance Readiness Viewer

The structured readiness viewer lives at the relevant workflow and loads the

Use this page when you need an interactive, browser-readable program status view before exporting an artifact. The page shows:

  • Framework coverage by attached framework version
  • Control status totals, including implemented, partial, not implemented, tests, and not-applicable counts

  • Evidence freshness totals

  • Open-risk severity counts
  • MAP totals and overdue count
  • Open finding totals by classification
  • Policy acknowledgment and training completion summary

The viewer is read-only and requires Meridian.view. If the program belongs to cases instead of disclosing whether that program ID is valid elsewhere.

Programs with no controls, evidence, risks, or framework mappings still render successfully. Empty sections show zero totals or an explicit empty-framework state instead of a page-level failure.

Report Builder

Use the left sidebar: Reporting → Report Builder (the relevant workflow). Settings → Reports & Analytics → Report Builder and the command palette remain available as secondary paths.

  1. Select a Report Type: - Compliance Readiness Report — Full program health for internal review - Executive Summary — Board-ready executive PDF - Risk Report — Risk register summary - Audit Report — Read-only guidance for the audit-scoped viewer path (see below)

  2. For readiness, executive, and risk reports: select the Program from the dropdown.

  3. Select Output Format. When the chosen report type supports more than one format, choose PDF, CSV, or XLSX.

  4. Click Generate & Download. Meridian creates a durable job and shows its queued, rendering, storing, and ready progress. You can leave the page while the fair background worker runs. Cancel is cooperative; a running render may finish its current safe step before cancellation takes effect.

  5. When the job is ready, click Download. Meridian rechecks your current report permission, and the browser verifies the response media type and SHA-256 before saving it. The artifact expires after seven days.

Transient failures retry with bounded backoff. A job that exhausts its attempts moves to Needs attention; use Retry to start a new generation from the same immutable request. Notifications contain only job identity and state, not report content. If a download fails integrity verification, no file is saved; request the same authorized download again.

Audit Reports

Audit reports stay audit-scoped because they require an active cycle context. The primary operator path is Audits → [Audit Name] → View Report, which opens the structured audit report viewer at the relevant workflow.

Use Download PDF for a server-approved issuable report. If the shared assurance summary is blocked, the only artifact option is Export internal draft, which requires acknowledgement and is visibly watermarked. Report Builder does not bypass this contract.

The structured audit report viewer requires Meridian.audit. View-only users do not get access to that page.

Evidence packages are managed from the audit detail page’s Evidence Package panel, not from the Report Builder. That panel supports both Generate package for foreground builds and Generate in background for durable builds. See for cancel, retry, recovery, share-token, and API-served download controls.

Scheduling Automated Delivery

Use the left sidebar: Reporting → Scheduled Reports (the relevant workflow). Settings → Scheduled Reports and the command palette remain available as secondary paths.

Requires: Meridian.view to open the page. Creating, pausing, resuming, editing, and deleting schedules requires Meridian.manage. Audit report schedules require Meridian.audit for read, download, and management actions. MSP Client Report schedules require MSP.view_clients for read, download, and management actions.

Creating a Schedule

  1. Click New Schedule.
  2. Select a Report Type: - Compliance Readiness Report — requires a Program. - Executive Summary — requires a Program. - Risk Report — requires a Program. - Audit Report — requires a Program and an Audit Cycle (see step 4). - MSP Client Report — Program is optional; see the MSP section below.
  3. Select a Program (required for all types except MSP Client Report).
  4. If the report type is Audit Report, select the Audit Cycle from that program. Meridian only accepts audit schedules when the cycle belongs to the selected program.

  5. Set the Schedule — choose a preset (Weekly Monday, Monthly 1st, Quarterly) or enter a custom UTC cron expression (e.g. 0 9 1 * *).

  6. Enter Recipients — comma or newline-separated email addresses.

  7. Select Format. Tabular reports (Compliance Readiness, Executive Summary, Risk Report, Audit Report) support PDF, CSV, and XLSX. The MSP Client Report supports PDF only (multi-client branded layout does not flatten to a single sheet). Format defaults to PDF.

  8. Click Create.

For Audit Report schedules, the form previews the pinned cycle’s current scope, state, evidence freshness, and recipient classification. A recipient-bearing schedule cannot be saved while issuance is blocked. A schedule with no recipients is internal draft-only. The worker rechecks both readiness and recipient policy on every run and sends nothing on drift or failure. Meridian schedules are disabled until an operator selects a cycle and re-enables them.

If no audit cycles exist for the selected program, Meridian blocks creation of the audit schedule until you create one from the audit workflow first.

For MSP Client Report schedules, leaving Program unset includes all active client programs. Setting Program scopes the report to client programs whose name matches the selected MSP program (see MSP Client Compliance Report below).

Managing the External-Recipient Allowlist

Scheduled reports can only be emailed to external addresses whose domain is on the tenant’s external-recipient allowlist. Start from Reporting → Scheduled Reports, then open Recipient Policy (the relevant workflow) to manage this allowlist. The Settings page still exposes a secondary Scheduled Reports card that lands on the same workflow. Requires Meridian.manage to edit; Meridian.view to read.

  • Adding a domain widens the set of external mailboxes that scheduled reports may be emailed to. This is control-sensitive and writes a scheduled_report.recipient_policy_update audit row.

  • Domains are normalized (lower-cased, @ and *. prefixes stripped).

  • The allowlist is per-tenant and applies to every scheduled report in the account.

  • Removing a domain suppresses future deliveries to recipients on that domain. Existing queued deliveries that are suppressed are recorded with a suppression reason in the delivery ledger.

If the recipient picker shows “Domain not allowlisted”, click Manage recipient policy in that error message to navigate directly to the policy page.

Managing Schedules

  • Pause — Temporarily suspend delivery without deleting the schedule. Click the pause icon on the schedule row.

  • Resume — Click the play icon to re-activate a paused schedule.

  • Delete — Permanently removes the schedule. Delivery history is not retained.

Downloading Generated Scheduled Reports

After a schedule runs successfully, the row shows an enabled Download action. Click it to retrieve the latest generated artifact (PDF, CSV, or XLSX depending on the schedule’s configured format) from Meridian. The action is disabled until latest_artifact_available is true. A false value means no scheduled run has successfully stored an artifact yet.

Download permissions match scheduled-report read permissions: audit_report downloads require Meridian.audit, and msp_client_report downloads require MSP.view_clients. Each successful download writes a scheduled_report.download audit row with the report type, target IDs, artifact size, and safe request metadata before bytes are returned.

Compliance Trend Analysis

Navigate to Dashboard → Multi-Program (the relevant workflow).

The dashboard shows 90-day readiness sparklines for each program. To populate trend data, an admin must trigger Snapshot All Programs from Settings on a regular basis (or configure the scheduler to run it automatically).

Multi-Program Dashboard

Navigate to Dashboard → Multi-Program (the relevant workflow).

The Dashboard → Multi-Program card on Settings is shown only when the current account includes the multi_program_dashboard feature. If an operator opens the route directly without that entitlement, Meridian shows the standard upgrade/contact-sales gate instead of a raw API error.

Shows:

  • Total programs and overall average readiness
  • Aggregate open findings and overdue MAPs across all programs
  • Per-program cards sorted by readiness (worst first) to surface problems at a glance
  • 90-day readiness trend sparkline per program

Click any program card to navigate to that program’s full dashboard.

PDF Report Contents

Compliance Readiness Report

Section Description
KPI Strip Readiness %, controls implemented, fresh evidence %, open findings
Framework Coverage Per-framework: requirement count, coverage %, gap count
Control Health Breakdown: implemented / partial / not implemented / N/A
Evidence Freshness Fresh / stale / missing evidence counts
Open Findings & MAPs Count of open findings and overdue action plans

Executive Summary

Designed for board or management presentations. The executive PDF includes a KPI strip, readiness trend summary, deterministic narrative, risk/remediation commentary, evidence/governance commentary, and framework alignment. If the program has no persisted readiness snapshots yet, the trend section states that trend history is not yet available instead of failing generation.

CSV and XLSX exports for Executive Summary remain metric/value files for spreadsheet work. They do not include the PDF’s narrative layout.

Risk Report

Shows risk count by severity, open vs. closed, treatment plan summary, and the top open risks by title and score.

MSP Client Compliance Report

Available only for MSP accounts. Shows a summary of compliance posture across the MSP’s active client relationships: per-program readiness %, controls implemented / total, open findings, and overdue MAPs.

PDF headers use report branding resolved in this order: direct MSP white-label, active white-label owner for a managed client, tenant company name, tenant slug, then Cadres Meridian. When the resolved MSP branding includes a valid rendered in the PDF header alongside the company name. CSV and XLSX artifacts do not include image branding.

When creating an MSP client report schedule, the Program field is optional:

  • Not set — all active programs across all active client accounts are included in the PDF.

  • Set to an MSP program — only client programs whose name matches the selected MSP program are included. Use this to scope a scheduled report to a specific compliance initiative (e.g., “SOC 2 Type 1”) across all clients.

different name are excluded even if they cover the same framework. Name the MSP program consistently with the client programs it mirrors.