Questions

What people ask before they run the first scan.

Short answers. If yours isn’t here, the scan itself is ninety seconds and answers most of them.

Common questions.

What is OrgDrift?+

OrgDrift checks whether your systems agree about your people.

You upload one export from your HR system and one from payroll, commissions, or benefits. OrgDrift reads them side by side and lists every person the two systems describe differently. A termination payroll never got. A raise commissions never saw. A transfer that left someone on two payrolls. It runs in your browser, and your files never leave your computer.

When you need to prove the check ran, each one seals into a Control Execution Record. It is timestamped, tamper-evident, and your auditor can re-verify it from your own source data.

What is cross-system drift?+

Drift is when one change lands in one system and not in the others. Someone is terminated, promoted, moved to a new territory, or put on a new plan. HR records it correctly. Payroll, commissions, or benefits never catch up.

The integration usually looks fine. The pipe ran. The far end rejected the change, remapped it, or quietly ignored it. And because every manual check looks inside one system, nobody sees it until it shows up as a payroll error, a commission dispute, or an audit finding.

Is this the same as Continuous Controls Monitoring (CCM)?+

Close, and the difference matters. Continuous Controls Monitoring grew up around the ERP. Tools like Pathlock and SafePaaS watch transactions and access inside a financial system and flag what breaks a rule. That is real work, and we do not replace it.

Verification asks a different question. Do two systems still agree about the same person and the same dollar? A tool sitting inside your ERP cannot answer that, because it only sees one side. OrgDrift reads both, from outside, and seals what it found as evidence.

If you already run CCM, OrgDrift covers the seam it cannot see. HR to payroll. CRM to commissions. One country payroll to another.

What is Continuous Controls Verification (CCV)?+

Most teams check each system on its own. HR checks HR. Payroll checks payroll. Nobody checks whether the two agree.

Continuous Controls Verification is the habit of running that cross-system check all the time, not once a quarter, and keeping proof that you ran it. It is what DevOps did for software and RevOps did for sales, applied to the checks your auditor asks about. OrgDrift is the first product built for it.

What does the free scan actually show me?+

Findings, severity, and dollar exposure, on your own files, before you pay anything. You see how many people your systems disagree about, how bad each mismatch is, and what it adds up to.

The $10 opens the row-level detail and the exports. If your scan comes back clean, there is nothing to buy and you have paid nothing. See your drift first. Pay only if it is worth it.

What does OrgDrift do with our data?+

Today the scan runs entirely inside your browser tab. There is no upload endpoint to send your file to. Field values are hashed for comparison, and raw employee data never reaches us. We keep the verification evidence and its signatures, nothing else.

Session replay and web analytics are blocked on every route that can render your data, and you can check that by viewing source. Private Mode goes one step further and turns off the last outbound call, so you can disconnect your network and watch a scan finish anyway. Live read-only integrations are on the roadmap.

Who uses OrgDrift?+

Four kinds of people, for four reasons. Payroll and controllership teams check that terminations and rate changes reached payroll. RevOps and sales-comp managers catch plan, territory, and ownership mismatches before a clawback hits a rep. SOX and internal audit directors need evidence they did not produce themselves. CFOs and controllers would rather know now than at quarter close.

We already check this by hand every month and quarter. Why do we need OrgDrift?+

Manual matching is good work. It is just not complete. Your checks run on a cadence, inside one domain, and often inside one country. Drift that crosses those lines slips past all of them, because no reviewer holds every system view at once.

OrgDrift runs continuously, across domains and across countries. It does not replace your team's judgment. It hands them the one view they currently assemble by hand.

And even when the manual check works, it produces a findings list, not evidence. At audit time your team still pulls 45 samples and builds workpapers. OrgDrift turns the same work into evidence as a byproduct, so your auditor pulls the samples themselves.

Doesn't our existing iPaaS (Workato, MuleSoft, Boomi) already handle this?+

An integration platform moves data. OrgDrift verifies it arrived correctly. The failure mode is not that the pipe broke. It is that the pipe ran fine, the far system rejected or remapped the change, and nobody was watching for that. OrgDrift is the independent observer above the pipes.

We already have Optro, Workiva, or Diligent. Isn’t that this?+

GRC platforms manage the framework around controls: the documentation, the workflow, the sign-off. They do not read from your operational systems, and they do not produce independent proof that two systems agreed. OrgDrift sits underneath and feeds Control Execution Records into your GRC platform. They are complementary, not competitive.

How is this different from SafeBooks or other AI matching tools?+

Independence. A tool that lives inside your finance stack, or one whose AI decides what looks wrong, is checking its own work, and an auditor will treat its output that way. OrgDrift is a referee: read-only, outside every system it checks, running fixed rules. The same inputs always produce the same finding, and any auditor can re-verify a result from source. The evidence is the product, not a dashboard summary of it.

Couldn't our IT team just build this?+

They could build the checks. Many teams have. What IT cannot build is independence. A control built and run by the same organization that operates the systems is self-attestation, and auditors discount it. OrgDrift's value is not the comparison logic. It is the independent, tamper-evident Control Execution Record proving the check ran, on what data, with what result. Your auditor can sample it without having to trust your scripts.

Is OrgDrift an AI product? What does VERA actually do?+

Pasting an HR export into a chat assistant gives you an opinion that changes between runs, cannot be signed, and will not survive auditor review. Detection has to be repeatable to count as evidence.

OrgDrift's detection engine runs fixed rules. When a change in one system should have reached another and did not, we surface it. No probability, no guessing. That part is auditable.

VERA is the AI layer on top. It speeds up the work around a finding: naming the root cause, sizing the exposure, drafting the remediation messages and tickets, drafting the Control Execution Record. VERA never publishes evidence on its own. Every record needs a human signature first, and VERA's drafts and inputs are logged too, so your auditor can see exactly what was AI-assisted and what was human-reviewed. This follows the NIST AI Risk Management Framework and ISO/IEC 42001 principles.

Why does OrgDrift matter more as we adopt AI and automation?+

AI and automation speed up the work inside your systems. They also speed up the rate at which those systems drift apart. Schemas change, vendors rename fields, models retrain on slightly different data, and an automation that ran cleanly last quarter starts producing the wrong output. Nobody notices until a payroll run, a commission cycle, or an audit surfaces it.

OrgDrift sits above the automation and checks its work against the systems of record. Continuously, on fixed rules, with signed evidence. The automation keeps its speed. The outcomes stay correct.

Will auditors accept a Control Execution Record as evidence?+

Control Execution Records are built to be cited as independent evidence attached to management's assertion in ICFR testing, the annual review of your financial-reporting controls. A Big 4 workpaper template, so records drop into existing audit procedures without re-documentation, is on the roadmap. The goal is simple: let external auditors pull samples directly instead of waiting on workpapers, which turns weeks into hours.

How long from first visit to first real drift finding?+

The scan on the homepage runs on your own files in about ninety seconds. There is no signup and no integration. A full pass across one pair of systems is under a day end to end. Your first Control Execution Record lands inside the first week.

Who is OrgDrift not for?+

If you run one system of record, with no cross-system payroll, comp, benefits, or CRM flows, you do not need a referee yet. That single system's own controls are enough. OrgDrift earns its keep the moment two systems are supposed to agree about the same person or the same dollar and no single reviewer sees both.

We’re mid-M&A integration. Is it too early for us?+

Mid-integration is exactly when drift is most likely and most expensive. OrgDrift is useful the moment two systems are supposed to agree with each other, which is usually day one.