Skip to main content

Evidence Artifacts

View and manage collected evidence artifacts

evidenceartifactsfilesmanagement

Evidence Artifacts

Artifacts are the individual pieces of evidence that support your compliance posture. Learn to view, manage, and organize your evidence collection.

Understanding Artifacts

Artifact Types

TypeDescriptionExamples
ConfigurationSystem settings captured via APIConditional Access policies, security settings
ScreenshotVisual captures of configurationsAdmin portal screenshots
DocumentWritten policies and proceduresSecurity policy PDF
LogSystem or audit logsSign-in logs, audit trails
AttestationSigned acknowledgmentsTraining completion, policy acceptance
ReportExternal reports or assessmentsPenetration test results

Artifact Sources

SourceHow Collected
AutomaticCollected during assessments
ManualUploaded by users
IntegrationPulled from connected systems

Viewing Artifacts

Artifact List

Navigate to Evidence > Artifacts to see all evidence:

ColumnDescription
NameArtifact identifier/filename
TypeConfiguration, document, etc.
ControlLinked compliance control
FrameworkAssociated framework
CollectedDate collected/uploaded
StatusCurrent, expired, superseded

Filtering Artifacts

Filter by:

  • Type - Document, screenshot, configuration
  • Framework - Specific frameworks
  • Control - Individual controls
  • Date - Collection period
  • Status - Current, expired

Artifact Details

Click an artifact to see:

  • Full content or preview
  • Metadata (source, date, collector)
  • Linked controls
  • Version history
  • Related artifacts

Managing Artifacts

Uploading Artifacts

Add new evidence:

  1. Go to Evidence > Artifacts
  2. Click Upload
  3. Select file(s)
  4. Complete the form:
    • Link to control(s)
    • Add description
    • Set evidence type
  5. Click Upload

Supported Formats

CategoryFormats
DocumentsPDF, DOCX, XLSX, TXT
ImagesPNG, JPG, GIF
DataJSON, CSV, XML
ArchivesZIP (for multiple files)

Size limits: 25 MB per file, 100 MB per upload batch

Editing Artifacts

Update artifact metadata:

  1. Open artifact details
  2. Click Edit
  3. Modify description, links, or tags
  4. Click Save

Versioning

When evidence is updated:

  1. Upload new artifact
  2. Link to same control
  3. Mark previous as "Superseded"
  4. Version history maintained

Deleting Artifacts

Remove evidence no longer needed:

  1. Select artifact(s)
  2. Click Delete
  3. Confirm deletion

Artifact Organization

Linking to Controls

Connect artifacts to compliance controls:

  1. Open artifact details
  2. Click Link Controls
  3. Search or browse for controls
  4. Select applicable controls
  5. Click Save

One artifact can link to multiple controls if it provides evidence for each.

Tags

Organize with custom tags:

  • annual-review
  • external-audit
  • policy
  • Q4-2024

Filter by tags to find related artifacts.

Collections

Group related artifacts:

  1. Go to Evidence > Collections
  2. Click Create Collection
  3. Name and describe the collection
  4. Add artifacts
  5. Save

Use collections for:

  • Audit packages
  • Policy bundles
  • Review sets

Automatic Evidence

Assessment Evidence

During compliance assessments:

  • Configuration data is captured
  • API responses are stored
  • Screenshots are generated (where applicable)
  • Evidence is auto-linked to controls

Drift Evidence

During drift detection:

  • Configuration snapshots saved
  • Change details recorded
  • Baseline comparisons stored

Evidence Freshness

Automatic evidence is timestamped:

AgeStatus
< 30 daysCurrent
30-90 daysRecent
> 90 daysMay need refresh

Run new assessments to refresh automatic evidence.

Evidence Quality

Good Evidence Includes

  • Clear identification - What system, setting, or control
  • Timestamp - When evidence was collected
  • Context - Why it demonstrates compliance
  • Complete data - Full configuration, not partial

Evidence Review

Periodically review evidence quality:

  1. Check for expired evidence
  2. Verify links are correct
  3. Ensure coverage is complete
  4. Update descriptions as needed

Searching Artifacts

Search by:

  • Artifact name
  • Description text
  • Control name
  • Framework name

Combine criteria:

type:document AND framework:"CIS" AND date:>2024-01-01

Saved Searches

Save frequent searches:

  1. Perform search
  2. Click Save Search
  3. Name the search
  4. Access from Saved Searches

Best Practices

Naming Conventions

Use consistent naming:

  • CIS-2.1.1_MFA-Policy_2024-01-15.pdf
  • screenshot1.png

Regular Updates

  • Refresh automatic evidence monthly
  • Review manual evidence quarterly
  • Update after configuration changes

Documentation

  • Add descriptive context
  • Explain why artifact is evidence
  • Note any exceptions or caveats

What's Next?

Global Search

Search for pages, settings, and documentation