Kanonik

Help center

Getting started with Kanonik.

What Kanonik is, how the core loop works, and the right first move.

Kanonik is new-gen GRC. It is your compliance system of record: your assets, vendors, risks, controls, policies, framework decisions, and the proof behind every one of them live in Kanonik. There is no separate platform underneath it.

The part that is different from older tools: you do not do the compliance work inside Kanonik, and you do not fill in forms. Your own AI does the work. Kanonik provides four things around it: the record, a safety check that runs before anything lands, a one-click approval, and a tamper-evident audit log. This page explains the loop and the right first move.

What Kanonik gives you

Kanonik holds the record and guards every change to it.

  • The record. A connected model of your program. Things in scope and how they relate, kept current as your AI works.
  • The safety check. An automated review that runs on Kanonik's servers before any change can be approved. It cannot be skipped. Low-confidence items go to a review queue instead of landing.
  • The approval. A single-use link. Clicking it is what records the change. Saying "yes" in your chat is never enough on its own.
  • The audit log. A permanent, tamper-evident timeline of who proposed what, the safety-check result, who approved it, and when. Nothing is quietly edited or removed.

You approve. You do not edit compliance objects by hand in the dashboard. If something needs to change, you tell your AI and it produces a new version for you to review.

Your AI does the work

Your AI is Claude Desktop, Claude Code, or any MCP-capable client, loaded with Kanonik's signed skills. The skills load automatically over the connection, so there is nothing to install. Once connected, your AI knows how to do compliance work against your record: draft policies, identify controls, map them to the framework, and more.

Kanonik holds no credentials to your own systems. When your AI needs to look at your cloud accounts, your code, or your tickets, it connects to those through its own tools, not through Kanonik.

The core loop

Day to day, the rhythm is the same every time.

  1. You ask your AI to do a piece of compliance work.
  2. It drafts the change and runs the draft through Kanonik's safety check.
  3. You review the draft and the safety-check result in the chat.
  4. When you are settled, your AI gives you a single-use approval link.
  5. You click the link, and the change is sealed in your audit log.

If you are not settled, you do not click. You tell your AI what to change, and it drafts again. Only the click records anything.

The right first move

The instinct from older tools is to write a policy first. That is the wrong place to start here. Start with risk-driven discovery and let everything else follow from it.

The order that works:

  1. Your AI finds your assets, vendors, and risks first.
  2. Then the controls that treat those risks.
  3. Then it maps those controls to the framework.
  4. Policies come last, written to match the controls you actually have.

Done this way, your record reflects your real program, and your policies describe controls that exist rather than ones you wish you had. A good opening ask is simply: "Help me start my ISO 27001:2022 program. Find my assets and risks first."

Kanonik runs ISO 27001:2022, SOC 2 (Trust Services Criteria), GDPR, and NIST CSF 2.0 today, and one program serves them all. See Working to more than one framework.

Where to go next

Two steps and you are working.

  1. Connect your AI. Open "Connect your AI" in the dashboard and follow the short setup to wire your client to Kanonik. The skills load on their own. The walkthrough is in Connecting your AI.
  2. Ask it to start. Use a starter prompt, or just describe your goal in plain words. Your AI proposes the first change, the safety check runs, and the result waits for you under "Needs you."

From there, the work happens in your AI client, and the dashboard is where you review, approve, and see your record grow.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.