Skip to content

Product Updates

New features, improvements, and fixes shipping across the platform.

Follow @officiallyiru ↗
Compliance Automation

Google Cloud Platform is now available as a compliance source

Google Cloud Platform is now available in the Iru Compliance connector catalog, replacing the previous coming-soon placeholder.

Connect the Google Cloud project you want Iru to monitor using a read-only service account and JSON key, and Iru collects configuration and inventory evidence across Google Cloud IAM, Cloud Storage, Cloud KMS, Cloud Logging,...

Compliance Automation

Filter actions by unassigned owner or delegate

The Owner and Delegate filters on the Actions list within Compliance Automation now include an Unassigned option, so admins can find the actions nobody owns yet without scanning the table. This pairs with the separate Owner and Delegate columns added in May.

Compliance Automation

Automated evidence skips document-only actions and reports failed source calls

Automated evidence turns itself off on actions that need a signed document. Iru now recognizes the actions that only a person can satisfy — a signed policy or agreement, for example — and turns off automated evidence for them instead of running a collection pass that comes back with "no evidence found." The change is recorded in the action's activity...
Compliance Automation

Policy assignment exclusions and generated-policy editor styling

Exclude specific users from a policy assignment. When publishing or updating a policy, admins can now exclude specific users from the assignment. This is useful when a policy applies broadly but has a handful of exceptions who shouldn't be asked to acknowledge it.

Admins and auditors can now re-include a user who was previously excluded from a policy...

Compliance Automation

Framework selection in the policy generation intake

Policy generation framework picker limited to available frameworks. The framework picker in the policy generation intake now only lists the frameworks a tenant is entitled to (SOC 2, ISO 27001, HIPAA, GDPR by default), so admins never see options they can't actually generate against.

Choose a framework for policy generation intake. Admins can now select the...

Compliance Automation

Sufficiency status column on the Artifacts table

The Artifacts table now shows a Status column that surfaces evidence sufficiency for each artifact, making it clear at a glance which artifacts still need review versus which fully cover their mapped controls.

Compliance Automation

Policy reminder emails now go out weekly instead of daily

Reminder emails for employees with pending policy acknowledgements now send once a week, on Mondays, instead of once a day. The content of the reminder is unchanged — the same pending acknowledgements arrive in one weekly email rather than a daily one.

Compliance Automation

ISO 27001 and ISO 42001 control text is now protected

Control names and descriptions for ISO 27001 and ISO 42001 frameworks are locked from edits to preserve the framework's official language. Local overrides can still be captured in your organization's implementation notes.

Compliance Automation

New safeguards for deleting a framework

Framework deletion restricted to account owners.Only account owners can delete a framework from an organization now. This prevents accidental deletion of a framework mid-audit by admins or auditors who shouldn't have that authority.

Type-to-confirm before deleting a framework.Deleting a framework now requires typing the framework's name into a...

Compliance Automation

Filter framework controls by "needs review" actions

The controls list on a framework now supports a "needs review" filter that surfaces only the controls whose actions still need admin attention, helping teams focus on the remaining work in a framework rollout.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.