Skip to content

Evidence Management

Evidence management is the process of identifying, tracking, and collecting artifacts that prove your controls are implemented and operating effectively. The platform provides four integrated sections for this workflow.

SectionPurposeAccess
Evidence ScopingSelect and configure evidence trackingCheckbox icon
Evidence ReportingView reports by team or frequencyChart icon
TasksManage evidence collection tasksTasks icon
Systems RegistryRegister systems that collect evidenceMonitor icon

Evidence Scoping is where you track which evidence items your organization will collect. Access it by clicking the Checkbox icon in the sidebar.

Header Stats

  • Tracked — Number of evidence items actively being collected
  • Evidence — Total unique evidence items across scoped controls
  • Progress bar — Visual indicator of tracking coverage

View Mode Toggle

Switch between two perspectives:

ViewShows
ControlEvidence items grouped by control
EvidenceUnique evidence items across all controls

For each evidence item, you can configure:

FieldDescription
Is TrackedToggle to indicate active evidence collection
Collecting SystemSystem responsible for collecting this evidence
Method of CollectionHow evidence is gathered (API, manual, etc.)
FrequencyHow often evidence is collected
OwnerTeam responsible for this evidence
NotesAdditional tracking information

The platform displays available collection interfaces for each evidence item:

  • High automation (⚡) — Fully automated via API
  • Medium automation (⚙️) — Partial automation available
  • Low automation (📋) — Primarily manual collection

When AI suggestions are available, the platform recommends systems from your registry that can collect the evidence.

Like Control Scoping, evidence items support:

  • Assignments — Assign team members to manage evidence
  • Comments — Discuss collection approaches and issues
  • Tasks — Create collection tasks directly from evidence items

Evidence Reporting provides aggregate views of your evidence collection program. Access it by clicking the Chart icon in the sidebar.

The header displays:

  • Total Evidence — All unique evidence items
  • Tracked — Evidence items with active tracking
  • Not Tracked — Evidence gaps to address

View evidence grouped by:

Group ByPurpose
Owner TeamSee workload distribution across teams
Collection FrequencyPlan collection activities by schedule

Each group shows:

  • Group name (team or frequency)
  • Tracked vs. total count with percentage
  • Progress bar for visual tracking
  • List of evidence items in that group
  • Show only tracked evidence — Filter to see just active evidence

Use the team view to identify which teams have the most evidence responsibilities and ensure balanced workloads.


The Tasks section helps you manage evidence collection activities. Access it by clicking the Tasks icon in the sidebar.

ViewShows
My TasksTasks assigned to you
All TasksAll organization tasks
TypePurpose
FeasibilityAssess if evidence can be collected as planned
SetupConfigure systems for evidence collection
CollectionPerform evidence collection activity
ReviewReview collected evidence for completeness
DocumentationDocument collection procedures
IssueAddress problems with evidence collection

Each task displays:

  • Title — Description of the work
  • Evidence ID — Link to related evidence item
  • Priority — Low, Medium, High, or Critical
  • Due Date — Target completion date
  • Status — Not Started, In Progress, or Completed
  • Assigned To — Responsible team member
StatusColor
Not StartedBlue
In ProgressOrange
CompletedGreen

Update a task:

  1. Click Edit on the task card
  2. Change the status
  3. Add completion notes if applicable
  4. Click Save

Navigate to evidence: Click the evidence ID link to jump directly to that evidence item in Evidence Scoping.

The header shows:

  • Total tasks
  • Tasks by status (not started, in progress, completed)
  • Overdue count

The Systems Registry manages the systems that provide evidence for your compliance program. Access it by clicking the Monitor icon in the sidebar.

Registered systems can be:

  • Selected as “Collecting System” in Evidence Scoping
  • Matched to collection interfaces for automation suggestions
  • Tracked for capability coverage
TypeExamples
Cloud ProviderAWS, Azure, GCP
Identity ProviderOkta, Azure AD, OneLogin
TicketingJira, ServiceNow, Zendesk
LoggingSplunk, Datadog, ELK
Security ToolCrowdStrike, Qualys, Tenable
Code RepositoryGitHub, GitLab, Bitbucket
Document ManagementSharePoint, Confluence, Notion
CustomOrganization-specific systems
StatusMeaning
ActiveSystem is operational and available
InactiveSystem is not currently in use
DeprecatedSystem is being phased out
  1. Click + Add System in the header
  2. Complete the form:
    • Name — System display name
    • Vendor — System provider
    • Type — Category from the list above
    • Description — Purpose and capabilities
    • Status — Current operational state
  3. Click Save

When you register systems, the platform:

  1. Identifies compatible collection interfaces based on system type
  2. Suggests these systems when configuring evidence tracking
  3. Helps you understand automation potential

Here’s the recommended workflow for managing evidence:

Before tracking evidence, ensure you’ve selected controls in Control Scoping. Only evidence from scoped controls appears in Evidence Scoping.

Add your organization’s systems to the Systems Registry. This enables:

  • Evidence-to-system matching
  • Automation suggestions
  • Capability tracking

In Evidence Scoping:

  1. Switch to Evidence view for efficient bulk configuration
  2. For each evidence item:
    • Enable Is Tracked toggle
    • Select Collecting System
    • Set Method of Collection
    • Choose Frequency
    • Assign Owner

For evidence requiring manual collection:

  1. Navigate to the evidence item
  2. Create tasks for collection activities
  3. Assign team members
  4. Set due dates aligned with frequency

Use these views for oversight:

  • Dashboard — Overall evidence tracking percentage
  • Evidence Reporting — Team workloads and gaps
  • Tasks — Upcoming and overdue activities

  1. Start with high-automation evidence — Configure evidence with API collection first
  2. Group by team — Assign evidence to appropriate owner teams
  3. Document collection methods — Be specific about how evidence is gathered
  4. Link to systems — Always specify the collecting system
  1. Use appropriate task types — Match task type to the actual work
  2. Set realistic due dates — Align with collection frequencies
  3. Complete tasks promptly — Update status as work progresses
  4. Add completion notes — Document what was done for audit trail
  1. Keep systems current — Update status when systems change
  2. Use accurate types — Enable proper capability matching
  3. Include all relevant systems — Don’t miss evidence sources