The agents that fast-track your compliance — and exactly what each one does
A field guide to the KoComply agent roster: policy, workforce, digital estate, codebase, access, vendor, risk and trust — what each one automates and what it still asks you to approve.
- Each agent owns an end-to-end slice of the programme rather than a single alert type.
- Agents share one evidence graph, so proof collected once satisfies every mapped framework.
- Human approval is the only mandatory step in each workflow.
One evidence graph, many workers
The agents are not separate products bolted together. They read and write to a single evidence graph that links your systems, people, vendors, risks and controls. When the Codebase Agent proves branch protection is enforced, the Compliance Health Agent already knows which SOC 2 and ISO 27001 controls that satisfies, and the Questionnaire Agent can cite it in an answer the same day.
Policy Agent
Generates your entire policy set — system description, statement of applicability, acceptable use, HR security, access control, device management, incident response, SDLC, change management, backup and disaster recovery — from your actual company, systems and vendors rather than a generic template pack.
Its drift engine watches for posture changes, new systems, market expansion and regulatory updates, then rewrites the affected clauses and sends the diff for approval.
Workforce Agent
- Runs onboarding and offboarding checklists to completion across HRIS, identity and device tooling.
- Assigns and chases security awareness training until everyone is current.
- Collects policy acknowledgements and keeps the signed register audit-ready.
Digital Estate and Codebase Agents
- Auto-classify cloud entities as production or non-production so non-prod noise stops blocking your dashboard.
- Auto-complete justified exceptions — a public bucket holding only marketing assets is documented, not flagged forever.
- Auto-classify repositories, check peer review and branch protection, and scan commits, logs and CI artefacts for leaked secrets.
Access, Vendor and Risk Agents
- Discover critical systems and map users to them without you maintaining a spreadsheet of entitlements.
- Flag privilege drift, dormant admins and orphaned accounts for a one-click acknowledgement or revoke.
- Discover vendors from SSO, expense and DNS signals, tier them by data sensitivity and re-open reviews when a certificate lapses.
- Maintain a live risk register scoped to your framework, business model and real environment.
Trust, Questionnaire and RFP Agents
Security reviews are where deals stall. These agents answer questionnaires and RFP security sections directly from your evidence graph, keep a public trust centre current with live posture, and route only the genuinely novel questions to a human.
Every agent stops at the same place: a review queue. The reasoning, the source evidence and the proposed change are all visible before you approve.
Let an agent do this part for you
Free forever: validate your digital estate (infra + codebase) and get the AI RFP Agent. Upgrade when you're ready for the full program.
Start free