Blog
sprinto angle right
Product
sprinto angle right
February 2026 Product Updates: Automate Compliance Rules, Close Vendor Lifecycle Gaps, and Speed Up Every Review

February 2026 Product Updates: Automate Compliance Rules, Close Vendor Lifecycle Gaps, and Speed Up Every Review

Compliance automation rules that require backend access to configure slow down every team that needs them. Access reviews force Case Owners and InfoSec teams through repetitive, one-at-a-time actions in unstructured tables. Risk approval workflows cap out at a single step, even when governance policies require sequential sign-offs with conditional logic. Vendor onboarding requests arrive through informal channels with no intake form, no approval trail, and no connection to the vendor register. Vendor exits lack standardized checklists, leaving lingering access and unresolved dependencies. Risks identified by employees on the ground go unreported because there is no structured submission path into the risk register. And task dashboards bury relevant assignments under unfiltered lists, costing teams time every day.

Sprinto’s latest updates are designed to solve exactly that. You can now:

  • Create and manage automation rules directly in the Admin Portal using a UI-based Rule Engine,
  • Take bulk actions on access reviews from a redesigned, structured data table,
  • Configure multi-step approval paths with AND/OR logic for risk workflows,
  • Manage vendor intake through centralized Vendor Requests with configurable forms,
  • Run standardized Vendor Offboarding with task-based checklists,
  • Enable employees to submit risks via the Employee Portal through Risk Intake,
  • Set up multi-step Vendor Approval Paths with automatic routing, and
  • Navigate a refreshed Task Dashboard with default “Assigned to Me” views and interactive filter cards.

Read about these updates in detail below:

1. Create and manage automation rules directly from the Admin Portal

You can now build automation rules in Sprinto’s Admin Portal using a visual Rule Engine, removing the need to rely on backend workflows or engineering support to configure compliance automations.

Navigate to Settings → Automations to view and manage all active rules in one place. The UI-based rule builder lets you create new rules by selecting trigger types, including Create, Update, or both. Each rule follows the same logic model available in the Command Centre, so teams already familiar with existing automations will find a consistent experience. Rules take effect immediately after configuration, enabling faster iteration on workflow logic without waiting on backend changes.

Why is this important?

The Rule Engine in the Admin Portal puts automation setup directly in the hands of compliance and operations teams. Your team can create, edit, and manage rules from a single screen, cutting the time between identifying a workflow gap and closing it.

This is especially valuable for teams running multiple frameworks or programs where compliance workflows evolve frequently. When a new trigger condition is needed, for example assigning a task when a control status changes, your team can configure it in minutes from Settings → Automations without filing a request or coordinating with engineering.

Screenshot

2. Take faster, bulk actions on access reviews with a redesigned table

You can now perform bulk actions on access review entries from a redesigned, structured data table, replacing the previous layout that required repetitive, one-at-a-time decisions.

The Access Review table has been upgraded to a standardized data table format with improved organization for both Case Owners and InfoSec teams. You can select multiple entries and apply bulk actions including Mark as Okay, Revoke, and Downgrade. Sprinto also surfaces contextual recommended actions based on detected issues, helping reviewers make informed decisions without switching between views or cross-referencing external data. The cleaner layout groups entries logically, so teams can work through reviews faster and with greater confidence in their decisions.

Why is this important?

Access reviews are one of the most repetitive workflows in any compliance program. Bulk actions on Mark as Okay, Revoke, and Downgrade let your InfoSec team process dozens of entries in a single pass, directly reducing the hours spent per review cycle.

Contextual recommendations add another layer of efficiency. When Sprinto detects an issue, such as an access anomaly or a role mismatch, it surfaces a recommended action alongside the entry. This means reviewers spend less time investigating each line item and more time confirming or acting on clear signals.

Screenshot

3. Configure multi-step approval paths for risk workflows

You can now set up multi-step approval paths for risks in Sprinto, adding sequential approval stages with configurable AND/OR logic to match your organization’s governance requirements.

Each approval path supports multiple sequential steps. Within any step, you can configure whether all designated approvers must sign off (AND) or whether any one approver’s sign-off is sufficient (OR). Once a step is completed, Sprinto automatically progresses the risk to the next approval stage. If a risk is rejected at any step, the enhanced rejection and resubmission flow guides the submitter through corrections and resubmission, keeping the full decision trail intact.

Why is this important?

Single-step approvals often fail to reflect how governance actually works. A risk flagged by an operations team may need sign-off from both a risk owner and a compliance lead before it reaches the CISO. Multi-step paths with AND/OR conditions let you model these hierarchies directly in Sprinto.

This upgrade also strengthens audit readiness. Every approval step, rejection, and resubmission is tracked, giving your team a complete, time-stamped record of who reviewed what and when. For organizations managing risk across multiple registers or frameworks, this level of traceability makes it easier to demonstrate governance rigor during audits.

Screenshot

4. Centralize vendor intake with structured Vendor Requests

You can now manage vendor onboarding requests through a centralized Vendor Requests workflow in Sprinto, giving your team a single place to receive, review, and act on every vendor intake submission.

Employees submit vendor requests through a configurable request form. Your team controls which fields appear on the form, tailoring the intake process to capture the information that matters for your vendor evaluation criteria. All submitted requests appear in a centralized view where admins can approve or reject each request with full decision tracking. Approved requests can be mapped to an existing vendor in the register or used to create a new vendor record, maintaining a direct link between the intake request and the vendor profile.

Why is this important?

Vendor requests that arrive through Slack messages, emails, or ad hoc conversations create gaps in your vendor register. Centralized intake with configurable forms ensures every request follows the same path and captures the same data points, reducing shadow IT and unmanaged vendor usage.

Decision tracking on each request also creates an auditable record of who requested a vendor, who reviewed it, and what the outcome was. For compliance teams managing vendor risk across multiple business units, this eliminates the guesswork around how and why a vendor was onboarded.

Screenshot

5. Standardize vendor exits with task-based Vendor Offboarding

You can now run structured Vendor Offboarding in Sprinto using predefined task checklists, ensuring every vendor exit follows a consistent, trackable process.

Create offboarding checklists with predefined tasks tailored to your organization’s vendor exit requirements. When a vendor moves to the Offboarding stage, Sprinto automatically assigns the relevant tasks to designated owners. All offboarding activities are tracked within the vendor’s profile, giving your team a consolidated view of what has been completed and what remains outstanding for each vendor exit.

Why is this important?

Vendor exits without a standardized process leave residual risks. Lingering access credentials, unresolved data handling obligations, and open contractual dependencies are common when offboarding is managed informally. Task-based checklists in Sprinto ensure every required step is captured, assigned, and tracked.

This also strengthens end-to-end vendor lifecycle management. With Vendor Requests handling intake and Vendor Offboarding handling exits, your team now has structured workflows covering both ends of the vendor relationship. The result is a complete, auditable trail from the moment a vendor is requested to the moment their offboarding tasks are closed.

Screenshot

6. Enable employees to report risks directly through Risk Intake

You can now allow employees to submit risks directly through the Employee Portal using Risk Intake, creating a structured path for risk identification that flows into your existing risk registers.

Employees submit risks from the Employee Portal using a form whose fields and settings are configurable by admins. Submitted risks enter a review queue where admins can review each submission and approve or reject it. Approved risks are added to a selected risk register, ensuring they follow the same governance structure as risks created by the compliance team. Admins can also configure who serves as a reviewer for incoming submissions, giving your team control over the intake pipeline.

Why is this important?

Risks observed by employees closest to day-to-day operations, such as a process gap, an emerging third-party dependency, or an unusual access pattern, often go unreported when there is no formal submission channel. Risk Intake gives every employee a clear, low-friction path to flag risks, while keeping admins in full control of what enters the register.

The review and approval layer is critical. Every submission is evaluated before it reaches a risk register, so your team maintains data quality and avoids clutter. For organizations with multiple risk registers spanning different frameworks or business units, the ability to route approved risks to the correct register keeps your risk landscape organized and accurate.

Screenshot

7. Set up multi-step Vendor Approval Paths with automatic routing

You can now configure multi-step Approval Paths specifically for vendor requests, ensuring every vendor is reviewed through a structured governance workflow before onboarding.

Each Vendor Approval Path supports multiple sequential steps with configurable approvers, AND/OR logic, and timelines. When an employee submits a vendor request, Sprinto automatically routes it through the configured approval path, progressing the request from one step to the next as approvals are completed. Approval status is tracked within the request details, giving both the requester and the approvers visibility into where a request stands at any point.

Why is this important?

Vendor onboarding decisions often involve multiple stakeholders. A procurement lead, an IT security reviewer, and a business unit head may all need to weigh in before a vendor is approved. Multi-step Vendor Approval Paths let you encode these requirements directly into Sprinto, with automatic routing that eliminates manual handoffs between steps.

This also brings accountability to vendor governance. Every approval, rejection, and routing decision is logged with timestamps and approver details. For audit purposes, your team can demonstrate that every onboarded vendor went through a defined, multi-stakeholder review process with clear decision records.

Screenshot

8. Navigate tasks faster with a refreshed Task Dashboard

You can now work from a refreshed Task Dashboard that defaults to an “Assigned to Me” view, surfaces interactive filter cards, and presents tasks in a cleaner, more readable data table.

The Task Dashboard now opens with tasks assigned to you, removing the need to filter down from a global list. Interactive cards at the top of the dashboard let you quickly filter by task states such as Escalated and Pending, giving you a one-click path to the tasks that need immediate attention. Centralized filters provide additional navigation options for teams managing tasks across multiple workflows. The underlying data table has been redesigned for readability, with clearer column layouts and improved information density.

Why is this important?

The Task Dashboard is one of the most frequently visited screens in Sprinto. Defaulting to “Assigned to Me” eliminates the repeated filtering that previously ate into every session. Interactive cards for states like Escalated and Pending surface the most urgent items immediately, helping users prioritize without scanning the full list.

For teams running parallel compliance programs, where tasks flow from access reviews, risk workflows, vendor processes, and control monitoring simultaneously, a faster Task Dashboard compounds into meaningful time savings across every workday.

Screenshot

Sprinto’s February 2026 updates bring stronger governance, full vendor lifecycle control, and faster daily operations

With these updates, your team can spin up automation rules in minutes from a single settings screen without backend tickets, run access review cycles in bulk with contextual recommendations, route risk and vendor approvals through multi-step governance paths that match how your organization actually makes decisions, manage the full vendor lifecycle from structured intake through structured exit with complete traceability, and bring employee-reported risks into your registers through a controlled pipeline that preserves data quality while widening risk visibility across the org.

These updates give compliance and procurement teams direct control over the workflows that define vendor governance, risk intake, and approval accountability across every stage of the GRC program.

Srikar Sai
Author

Srikar Sai

As a Senior Content Marketer at Sprinto, Srikar Sai believes good content should be bookmark-worthy by default. He writes about cybersecurity and GRC, aiming to move the needle with every piece. He’s also an ISO 27001-certified Lead Auditor.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img