Controls
Assigning owners and due dates
Last updated July 2026 · 5 min read
Assigning owners and due dates to controls creates accountability and helps your team know exactly who's responsible for what.
Why assign owners?
SOC 2 controls span multiple disciplines — engineering, IT, HR, legal, and finance. Without clear ownership, controls fall through the cracks. When an auditor asks "who is responsible for access controls?" you want to be able to answer immediately.
How to assign an owner
1
Open a control
Go to Controls and click on the control you want to assign.
2
Select an owner
Use the Owner dropdown to select a team member. Only active workspace members appear in this list.
3
Set a target date
Use the Target date field to set a deadline for completing this control.
4
Save
Click Save changes. The owner's name will appear in the evidence table and audit report.
Tip: Owners must be invited to your workspace before they can be assigned. See Inviting your team.
Recommended ownership model
- CC6.1–CC6.3 (Access controls) → Engineering or DevOps lead
- CC7.1–CC7.2 (Monitoring and incident response) → Security lead or CTO
- CC1.1–CC1.2 (Ethics and oversight) → CEO or CTO
- CC2.1 (Communication) → HR or Operations
- A1.3 (Disaster recovery) → Engineering lead
- P1.0 (Privacy notice) → Legal or Compliance