Evidence and control mapping
How a document becomes control coverage — confidence scores, the human-confirm gate, and reuse across frameworks.
Core concepts · 2 min read
Evidence is the centre of the product. Everything else — readiness scores, gap lists, the audit binder — is derived from which controls your evidence covers.
What counts as evidence
- Documents you write: policies, procedures, onboarding and offboarding checklists.
- Configuration exports: an IAM password policy, a branch-protection setting, an MFA report.
- Screenshots of settings pages, for systems with no export or API.
- Signals collected automatically from a connected integration.
How mapping works
When you upload a document, it's analysed against the control sets of every framework you've activated. The result is a set of suggested mappings, each with a confidence score and the reasoning behind it.
Crucially, one upload is analysed against every active framework at once. An access-control policy doesn't get filed under SOC 2 — it gets mapped to the SOC 2 criterion, the ISO 27001 control and the DPDPA obligation it satisfies, in a single pass. That's what makes adding a second framework much cheaper than the first.
The human-confirm gate
A suggested mapping does not count toward your readiness until a person confirms it. This is a deliberate constraint, not an unfinished feature: confirmed coverage carries an attributed decision — who accepted the mapping, and when — which is what makes the resulting report defensible.
Evidence freshness
Evidence can carry a validity date. As that date approaches, the Action Center raises a task to replace it — auditors expect evidence current for the audit period, and a two-year-old screenshot of an MFA setting proves nothing about today.