- As the SaaS and AI stack grew to 84 in-scope apps, Celigo's compliance team tracked SOC 2 posture app by app in a spreadsheet.
- Critical identity controls sat in the same list as low-severity ones, so the team worked them in app order.
- Some apps could not technically support a control, and those gaps looked the same as failures.
- The internal 15-minute session-timeout policy was stricter than SOC 2 and was not measured anywhere.
.png)


