Collection Guidance & the System Catalogue
The platform ships with a built-in system catalogue: curated knowledge for 47+ common products (Cloudflare, GitHub, Okta, AWS, Microsoft 365, Intune, Snyk, and many more) describing exactly how to collect audit evidence from each one. Every catalogue entry provides step-by-step collection recipes at four maturity levels, researched from official vendor documentation.
What You Get Per System
Section titled “What You Get Per System”Each catalogue system includes a recipe ladder:
| Level | Approach | Example |
|---|---|---|
| L1 — Manual | Sign in and export by hand | Download the audit log CSV from the admin console weekly |
| L2 — Scheduled | Built-in scheduled reports/exports | Configure the vendor’s scheduled report emailed to an evidence mailbox |
| L3 — API-driven | Scripted collection on a schedule | Call the vendor’s API daily with a read-only token |
| L4 — Managed pipeline | Continuous streaming with completeness checks | Webhooks/log streaming into your SIEM with gap alerting |
Every recipe step includes the real console navigation path or API endpoint, the vendor role or permission it requires, security notes on credential handling, audit notes on evidentiary value, and links to the official vendor documentation.
Getting Guidance in the Evidence Workspace
Section titled “Getting Guidance in the Evidence Workspace”Collection guidance appears in the evidence work area:
- Open an evidence item in the Evidence Workspace
- The Collection Suggestions panel lists your registered systems capable of providing that evidence
- Click a system chip to open its Collection Guide — the step-by-step recipe for your current maturity level
- Follow the steps, collect the artifact, and upload it against the evidence item
The guide also shows a Next Level Preview so you can see what upgrading your collection process would involve, and feedback buttons so you can flag recipes that don’t match your setup.
Guidance Confidence
Section titled “Guidance Confidence”Each recipe carries a confidence badge showing where it came from:
| Badge | Meaning |
|---|---|
| System-specific | Your system is directly linked to its catalogue entry (added via the picker) |
| Vendor guide | The platform matched your system to a catalogue entry by its name/vendor |
| Type-generic | No catalogue match — generic guidance for the system type |
To turn a name-based match into a direct link, edit the system and pick its template from the catalogue.
AI-Generated Guidance for Custom Systems
Section titled “AI-Generated Guidance for Custom Systems”For systems that aren’t in the catalogue (internal tools, niche products), you can generate tailored guidance:
- Open the evidence item and select the system in Collection Suggestions
- Click ✨ Generate collection guidance for this system (requires editor access)
- The platform researches the vendor’s documentation and produces a full L1–L4 recipe ladder — this takes a couple of minutes
Generated recipes are private to your organisation and carry a clear “AI-generated — verify against vendor docs” badge. Treat them as a strong starting point: verify console paths and API details against the vendor’s current documentation before building processes on them.
Recommended Workflow
Section titled “Recommended Workflow”- Add systems from the catalogue (Systems Registry) so guidance is linked from day one
- Start at L1 — get evidence flowing manually so nothing is blocked on engineering work
- Use the recipes to climb — each level’s recipe includes the setup steps, permissions, and vendor docs for the next automation step
- Watch your maturity scores rise in the Evidence Health dashboard as collection methods improve
