# Controls

Controls are the core compliance unit in Scytale: each represents a security
requirement mapped to one or more framework criteria (e.g., SOC 2 CC6.1,
ISO 27001 A.9.4). Use this endpoint to retrieve your control set with owner,
applicability, framework mapping, and linked monitors. Filter by audit,
applicability, or owner to build control-status reports and ownership views.

Related resources: Audits, Monitors.

 - [GET /v1/controls](https://developers.scytale.ai/openapi/controls/get_controls.md): Return controls matching the filters, one page at a time. Each row is a full control: code, name, description, owner, framework criteria, framework (id and name), applicability, audit and the monitors
 - [GET /v1/controls/{id}](https://developers.scytale.ai/openapi/controls/get_control.md): Return one control by id - the same shape as a list row. Use it to follow up on a specific control after `get_controls`, or when you already hold an id.
