> For the complete documentation index, see [llms.txt](https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/standards-and-compliance/custom-frameworks.md).

# Custom Frameworks

Build a cloud compliance framework from Heeler's checks, or clone and customize a built-in one, then publish it as a versioned framework.

A custom framework is your own set of controls, each mapped to Heeler cloud checks or marked manual. You build one from scratch, or clone a built-in framework and change it. Once you publish and adopt it, a custom framework is scored and shown like a built-in one under **Standards**, in the **Cloud** section. See [Cloud Frameworks](/mrecEO40m5D6bt7Pq5pE/standards-and-compliance/cloud-frameworks.md).

**Prerequisite:** the **Administrator** role.

## Create a framework

{% stepper %}
{% step %}

### Start the framework

On **Administration → Program → Standards**, select **Build Framework**. Or, on the **Controls** tab of a built-in framework under **Standards**, select **Clone and customize**.
{% endstep %}

{% step %}

### Choose how to start

| Option                       | What it does                                                                                  |
| ---------------------------- | --------------------------------------------------------------------------------------------- |
| **Build a custom framework** | Start empty. Pick the checks, group them, and set your own control IDs and severities.        |
| **Clone and customize**      | Start from a built-in framework or one of your own, then remove, regroup or re-rate controls. |
| {% endstep %}                |                                                                                               |

{% step %}

### Describe it

| Field                  | What it sets                                                                                           |
| ---------------------- | ------------------------------------------------------------------------------------------------------ |
| **Framework to clone** | Clone only. The framework you start from.                                                              |
| **Framework name**     | The name shown on Standards and reports.                                                               |
| **Control ID prefix**  | Letters, digits, `-`, `_` and `.`. Controls are numbered from it, for example `PCB-IAM-01`.            |
| **Description**        | Shown on reports.                                                                                      |
| **Scope**              | `key=value` account or project tags, for example `env=prod`. Leave it empty to evaluate every account. |
| **Owner**              | The framework's owner.                                                                                 |
| {% endstep %}          |                                                                                                        |

{% step %}

### Create the draft

Select **Create and add controls**. The framework is saved as a draft, and the builder opens. Nothing is reported until you publish.
{% endstep %}
{% endstepper %}

## Build the draft

The builder shows the framework's groups and controls, and an **If published now** preview. Changes save as you go.

### Controls

| Field                  | What it sets                                                                         |
| ---------------------- | ------------------------------------------------------------------------------------ |
| **Control ID**         | The control's ID.                                                                    |
| **Group**              | The family it belongs to. A group can carry its own control ID prefix.               |
| **Title**              | The control's title.                                                                 |
| **Requirement text**   | The requirement the control states.                                                  |
| **Internal reference** | Your own reference, for example a policy number.                                     |
| **Manual control**     | The control is decided by evidence, not checks. Its mapped checks are removed.       |
| **Control severity**   | **Highest failing check**, or **Fixed severity**.                                    |
| **Map to framework**   | Other frameworks' controls this control also satisfies, shown as **Also satisfies**. |

### Checks

Add checks to a control from **Heeler checks**, or **Copy from a framework** to reuse another framework's mapping. A check can carry a severity override for this framework. An override requires a **Reason**.

A check that no built-in framework maps starts running once a custom framework maps it.

## Publish

Select **Publish vN**. The version becomes the framework's reported version.

A custom framework is not adopted when you create or publish it. To show it under **Standards**, add it with **Add standard** under **Administration → Program → Standards**. See [Add a framework](/mrecEO40m5D6bt7Pq5pE/standards-and-compliance/cloud-frameworks.md#add-a-framework).

To change a published framework, select **Edit framework**, or **Continue draft vN** for a draft in progress. The published version keeps reporting until you publish the next one. **Discard draft** drops the draft and leaves the published version unchanged.

A custom framework's page shows a **CUSTOM** badge, its version, and who published it and when. **History** opens every published version.

## Related

* [Cloud Frameworks](/mrecEO40m5D6bt7Pq5pE/standards-and-compliance/cloud-frameworks.md) — scores, control statuses and the heatmap.
* [Cloud Checks](/mrecEO40m5D6bt7Pq5pE/findings/cloud/checks.md) — every check you can map.
* [Standards](/mrecEO40m5D6bt7Pq5pE/administer-and-monitor/program-policy/standards.md) — adopt a published framework.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.heeler.com/mrecEO40m5D6bt7Pq5pE/standards-and-compliance/custom-frameworks.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
