Skip to content

Who Kanonik is for

Four groups use Kanonik differently. The substrate underneath is the same for all of them: your AI does the work, a server-side check runs on every proposal, a named person approves, and the result is sealed into a record.

Internal GRC and compliance teams

For a CISO, GRC lead, or compliance manager carrying the program.

What usually matters: cutting the manual effort in policy drafting, control mapping and evidence prep, keeping AI-assisted work consistent and defensible, and holding real oversight over what the AI produces.

Common work:

  • Drafting and updating policies and procedures
  • Control assessments and gap analysis
  • Audit narratives and evidence packages
  • Internal readiness reviews

Prompts people actually type:

  • "Using the policy-architect skill, draft our Access Control Policy for ISO/IEC 27001:2022, suitable for a 70-person fintech with remote staff."
  • "Review our control mapping for Annex A 8 and flag gaps using the control-assessment skill."
  • "Generate an audit-ready narrative for our recent penetration test findings."

vCISOs and fractional consultants

For someone carrying several clients at once.

What usually matters: delivering quality work across engagements, clean separation and an audit trail per client, and growing the practice without growing manual effort one-for-one.

Each client runs in its own isolated workspace. The header always names the active one, so a change cannot land against the wrong client by accident. See Navigating your workspace.

Prompts people actually type:

  • "Switch to the Acme Corp tenant. Using the policy-architect skill, draft their Acceptable Use Policy in our house style."
  • "For Beta Health, run a gap assessment against the controls we mapped last quarter."

External GRC consultants and MSPs

For a practice standardising delivery across many engagements.

What usually matters: speeding up and standardising delivery, offering AI-assisted services without giving up quality or defensibility, and spending less time on repetitive documentation.

Common work: accelerating policy and procedure development for clients, supporting audit preparation and evidence collection, and running the same method across every engagement rather than reinventing it per client.

External auditors

For the auditor of record reviewing a client's AI-assisted work.

What usually matters: understanding quickly how AI was used, getting clear and verifiable evidence of proposals, reviews and approvals, and spending less time chasing documentation.

Common work:

  • Requesting signed Auditor Export bundles
  • Reviewing the hash-chained audit trail and the safety-check outcomes
  • Asking how a specific control or finding was produced

Free read-only access is included for the auditor of record on every paid plan. See Exporting your evidence for an audit.

Typical requests:

  • "Can you provide the signed Auditor Export for the ISO 27001 assessment?"
  • "Walk me through how the Access Control Policy was developed, including the safety-check outcome and approvals."