Compliance & Governance

Governance that lives in the architecture, not a binder.

CMS Buildings is governed by construction: every action is attributable and timestamped, every change captures a reason, and the audit trail is immutable. Your ops and compliance teams read the configuration directly — they don't have to trust us.

The difference

Governance by construction vs. by configuration.

Traditional BMS and enterprise systems prove compliance by validating a configuration, then re-validating on every change. CMS Buildings builds governance into the node architecture itself, so validation still happens: it's continuous and built in, not a manual re-do.

Governance by configuration

  • Compliance lives in a validated configuration document
  • Someone validates that configuration produces compliance
  • Every change triggers expensive re-validation
  • You hold a vendor license — stop paying, stop running

Governance by construction

  • Compliance lives in the node architecture
  • Your team reads the EaC configuration directly
  • A node change is itself readable and auditable
  • You own portable artifacts your internal team can keep evolving
Governance principles

Every principle, mapped to the architecture.

Each node in a CMS Buildings workspace satisfies at least one governance principle. This is how compliance becomes something you can read, not something you take on faith.

See how this is architected
PrincipleHow CMS Buildings implements it
AttributableEvery action traced to a person or system + timestamp
LegibleReadable, permanent records (non-editable storage)
ContemporaneousRecorded at the moment of action
OriginalFirst-recorded source preserved; copies flagged
AccurateCorrections documented; the original is never deleted
CompleteAll events captured — not just successes
ConsistentLogical chronology via platform time sync
EnduringDurable across the full retention period
AvailableAccessible for audits via surface views + export
Standards

The frameworks your portfolio already answers to, built in.

NFPA life-safety codes

Fire alarm, suppression, and emergency-egress inspection tracking with expiry alerts.

ASHRAE & energy codes

Structured reason-for-change captured on every setpoint and schedule mutation.

OSHA

Workplace-safety inspection tracking with sign-off gating.

ISO 55000

Asset-management governance aligned to the ISO 55000 framework.

Access control

Feature-locked dashboards, controlled by access rights.

Every screen is gated by access rights, so each role sees exactly the dashboards and actions it's authorized for — completely governed and tested. A vendor doesn't want to see tenant data, and that's a configuration, not a code branch.

  • assets:view · assets:commission · assets:reconcile
  • network:query · network:manage · devices:onboard · points:manage
  • compliance:view · compliance:export · review:approve
  • history:approve · admin:access
Role → access rights
Compliance Auditor
audit trail · export
Facilities Manager
commission · reconcile
Controls Engineer
network:query
Building Engineer
history:approve
Read-only
view
“Start with us. Keep developing with your own team.”

Your workspace configuration, governance mapping, and runbooks are version-controlled, portable, and readable by your ops and compliance teams without software expertise. Begin the build with us, then hand it to your internal team to keep evolving — you own the compliance artifacts either way.

Show your auditors compliance they can read.

We'll walk your ops and compliance teams through the governance mapping node by node.