> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/compliance/compliance-campaigns.md).

# Compliance Campaigns

## Overview

The Herd Security Compliance page is a centralized hub for managing organizational compliance programs. It enables security and compliance teams to create structured campaigns, assign training and policy requirements to users, track completion progress, and maintain audit-ready records — all from a single interface.

## The Compliance page

At the top of the Compliance page, three **featured framework tiles** — **SOC 2**, **ISO 27001**, and **HIPAA** — give you a one-click starting point. If your organization already has a campaign for that framework, the tile shows its status and links straight to it; if not, the tile offers **Create campaign** and opens the create form with that framework pre-selected.

Below the tiles, a table lists every campaign with its **Framework**, **Status**, **Due Date**, and **Created** date. Use the search box and the **Status** filter (All Statuses, Draft, Active, Paused, Completed, Cancelled) to find a campaign.

## Agentic Campaigns (let Herd AI build it)

Next to **Create Campaign**, the Compliance page has a **Start agentic campaign** button. Instead of assembling a campaign by hand, Herd AI builds an **ongoing** compliance campaign that runs until everyone is compliant — and you can pause it anytime. The wizard has three steps:

1. **Framework** — pick the framework and click **Generate plan**. Herd AI reviews your existing library against the framework's requirements.
2. **Review plan** — each proposed item carries a provenance badge: **Existing training** (already in your library), **From Herd catalog** (a copy will be added), or **Will be generated** (Herd AI creates it for you). Adjust before continuing.
3. **Audience & launch** — choose who's in scope and click **Launch campaign**.

The resulting campaign is named after the framework (e.g. *SOC 2 Compliance (Herd AI)*) and shows an **Ongoing** mode label — it keeps working until everyone is compliant rather than expiring on a date.

***

## Creating a Compliance Campaign

The core action on the Compliance page is creating a Compliance Campaign. A campaign bundles together a compliance framework, associated trainings and tracks, policy acknowledgements, and assigned users into a single trackable program.

### Campaign Details

When creating a campaign, you configure the following fields:

#### Compliance Framework

Select the regulatory or security framework that the campaign is aligned to from the **Compliance Framework** dropdown. Available options are:

* SOC 2
* SOC 1
* ISO 27001
* ISO 42001
* NIST CSF
* GDPR
* HIPAA
* PCI DSS
* SOX
* FISMA
* FERPA
* CMMC
* CCPA/CPRA
* FedRAMP
* FDA 21 CFR Part 11
* CUI/FCI
* Custom

All of these frameworks are built in — you don't need to create them yourself. Choose **Custom** for internal initiatives that aren't tied to a named standard, or leave the field on "Select a framework (optional)" to skip it entirely.

{% hint style="info" %}
Selecting a framework **auto-loads its template**. Herd pre-populates the campaign **name** and **description** and pre-fills the **tracks and trainings** included in that framework's template. An "Includes" panel lists each item — expand a track to see its trainings, click the edit icon to open an item, or click the remove icon to drop any item you don't want before creating the campaign. You can add more items later from the campaign's detail page.
{% endhint %}

If a framework's template includes Herd catalog content, a note explains that a copy is added to your organization's tracks and trainings when the campaign is created, so you can customize it without affecting the catalog.

#### Campaign Name

A required field. The framework template suggests a name, but you can edit it to anything that clearly identifies the campaign, such as "SOC 2 Annual Compliance 2026" or "HIPAA Readiness Q2."

#### Description

An optional free-text field to describe the purpose, scope, and context of the campaign. The framework template suggests a description that you can keep or replace.

#### Campaign Timeline

Set the **Start Date** and **End Date** for the campaign. These default to **today** and **one month from today**, and you can change either. The dates define the active window during which users are expected to complete their assigned work and are used to determine overdue status.

When you're ready, click **Create Campaign**. You'll land on the new campaign's detail page as a draft.

## The Campaign Detail Page

A campaign opens to its detail page, which is organized into two tabs:

* **Overview** — the dashboard, items, policies, and assigned users (described below).
* **Nudges** — the per-campaign reminder history. See [Nudges](/herd-security-docs/compliance/nudges.md) for details.

### Campaign Status

Every campaign moves through a status lifecycle, shown as a badge next to the campaign name:

**Draft → Active → Paused → Completed / Cancelled**

The available action buttons depend on the current status:

| **Status** | **Available actions**               |
| ---------- | ----------------------------------- |
| Draft      | **Activate**, **Delete**            |
| Active     | **Pause**, **Complete**, **Delete** |
| Paused     | **Resume**, **Delete**              |
| Completed  | (read-only)                         |
| Cancelled  | (read-only)                         |

While a campaign is in Draft or Paused, its details, items, and assignments remain editable. Once a campaign is Completed or Cancelled, it becomes read-only.

{% hint style="warning" %}
**Setup Required before activation.** A draft campaign can't be activated until it has **at least one training or track** and **at least one assigned group**. Until both are in place, a "Setup Required" panel lists what's still missing and the **Activate** button stays disabled.
{% endhint %}

### Summary Metrics

Once a campaign leaves Draft, the dashboard displays four metric cards at the top. (These cards are hidden while the campaign is still a draft, since there's no progress to report yet.)

| **Metric**  | **Description**                                                   |
| ----------- | ----------------------------------------------------------------- |
| Total Users | The number of users enrolled in the campaign.                     |
| Completed   | The count of completed training or policy items across all users. |
| In Progress | Items that have been started but not yet finished.                |
| Overdue     | Items that have passed their due date without completion.         |

### Overall Progress

Below the metric cards, a completion rate is displayed as both a ratio and a percentage, giving a quick, high-level view of how the campaign is tracking.

## Trainings and Tracks

The **Trainings and Tracks** section lists all training programs and tracks assigned as part of the campaign. Each entry shows:

* Item name and type (TRAINING or TRACK)
* Due date for completion (editable inline)
* Progress — modules completed out of the total
* Overdue count
* Actions — such as removing the item

Expand a track row to see the individual trainings inside it. Use **Add** to attach more trainings or tracks while the campaign is editable. The add dialog includes a **Mandatory** toggle — assignments those items create are marked mandatory (for track items, trainings the track assigns later follow the track's own default instead).

Once a campaign is non-draft, you can export this data with the **CSV** or **JSON** buttons for use in audits or external reporting.

## Policy Acknowledgements

Compliance campaigns can also require users to acknowledge organizational policies. Rather than a fixed list, you attach **any policies from your own library**.

Click **Add Policy Acknowledgements** to open the modal. From there you:

1. Set a **due date** that will apply to the policies you select.
2. Search your policy library and check the policies you want to include.
3. Click **Save** to attach them — or use **Create New** to author a brand-new policy without leaving the campaign.

Each attached policy tracks acknowledgement progress (acknowledged vs. pending) across the assigned users, with its own due date and overdue status. You can drill into a policy to see the per-user **Policy Results**, which can be **exported to CSV**.

{% hint style="info" %}
Your policy library lives on the [Policies](/herd-security-docs/policies/policies.md) page. Any policy there — whether uploaded, linked, or auto-synced from OneDrive/SharePoint — can be attached to a campaign.
{% endhint %}

## Users and Groups

The Users and Groups section defines who is enrolled in the campaign. Teams can assign individual users or entire groups, making it easy to scope a campaign to a specific department, team, or the entire organization. (Remember: activating a campaign requires at least one assigned group.)

Progress metrics (completed, in progress, overdue) are calculated based on the users and groups assigned here.

## Sending Reminders

Reminders work two ways — automatically and on demand:

* **Auto-nudge (on by default).** Every campaign item with a due date automatically reminds incomplete users by direct message (Slack or Teams). Reminders start **3 business days before** the due date, repeat **daily**, and stop **5 business days after** the due date. Each item carries its own auto-nudge settings — you can turn auto-nudge off per item or adjust how early and how often it fires.
* **Manual nudges.** From the campaign **Overview** you can nudge the users who haven't finished a specific training, track, or policy acknowledgement at any moment — no need to wait for the schedule.

The campaign's **Nudges** tab shows the combined delivery history for both.

{% hint style="info" %}
Campaign-level nudge **notification delivery** is rolling out. When a nudge is recorded but notifications aren't sent yet, the toast reads **"Recorded nudge for N users (notifications coming soon)."** The nudge is always recorded for tracking, even when the notification itself hasn't been delivered. See [Nudges](/herd-security-docs/compliance/nudges.md) for the full reminder workflow.
{% endhint %}

## Summary

The Herd Security Compliance page brings together everything needed to run a structured, trackable compliance program:

| **Feature**             | **Purpose**                                                                                |
| ----------------------- | ------------------------------------------------------------------------------------------ |
| Campaign Creation       | Pick a framework to auto-load a template, then tailor the name, description, and items.    |
| Status Lifecycle        | Move a campaign through Draft → Active → Paused → Completed/Cancelled.                     |
| Summary Metrics         | Visibility into total users, completions, in-progress items, and overdue counts.           |
| Trainings & Tracks      | Assign and monitor structured training programs with per-module tracking.                  |
| Policy Acknowledgements | Attach any policies from your library and track acknowledgement with per-policy due dates. |
| Users & Groups          | Scope campaigns to specific individuals or teams.                                          |
| Nudges                  | Manually remind users who are behind and review the delivery history.                      |
| CSV / JSON Export       | Download trainings/tracks data (CSV or JSON) and policy results (CSV) for audit evidence.  |

Together these features give security and compliance teams a single source of truth for tracking organizational compliance readiness across any framework.
