Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Step 6 of 8: Collect evidence
Compliance Journey
Preview only

Collect evidence

Use available evidence and complete manual uploads.

View Home

Preview mode

Live connectors, billing, AI, and downstream writes are off. Your assessment workspace may still be saved when hosted persistence is active.

Collect evidence

This browser workspace

What this page shows: Evidence is proof that supports assessment answers, findings, remediation, and reports. Evidence can come from guided answers, uploaded/manual records, preview snapshots, or approved future connectors. Live provider evidence remains parked until owner approval. Nothing is pulled from Microsoft or live providers from this page.

What evidence is available
Guided answer
evidence from assessment responses
Manual record
user-provided or reviewed evidence
Preview snapshot
offline/sample/provider-preview evidence
Connector evidence
parked until approved
What evidence is still needed
Needs evidence
missing proof or follow-up required
Your next safe step
No metadata evidence references collected yet.

Start or continue the assessment, review findings, or manually add metadata records below. Connector evidence is parked until approved. Nothing is sent to or pulled from live providers. All uploaded metadata is saved locally offline.

How evidence moves forward
1
Identify evidence need
Needs review
2
Collect or review evidence
Ready
3
Link to finding or task
Preview
4
Add to evidence package
Parked
5
Include in report pack
Not live activated
Offline Local Directory Evidence Collector
Scan local directories to harvest compliance file metadata offline. No files are uploaded to any server. Paths are parsed client-side to build structured local evidence references.
How it works:1. Choose a folder containing your system settings exports, policy PDFs, or database logs.
2. Discovered file names and sizes are automatically classified into Evidence Types (e.g. Policy Documents, Audit Logs).
3. Approve the mappings and import them as local evidence items. They will appear immediately under the Evidence Records table.
Technical Details & Evidence Records
Source: Local browser workspace Evidence references Add evidence reference
Evidence Attachments & Uploads
Link policies, log files, or screenshots directly to compliance controls.
Upload Status:
Sandbox Mode

Evidence file upload is not configured yet. Evidence references remain available. No files are uploaded unless storage is configured.

Use Evidence Reference
Automated Evidence Mapping Preview AvailableAutomation-derived evidence suggestions can be previewed in the Automation workspace. Evidence preview is not persisted yet. Go to the Automation workspace to preview.
Evidence and remediation workflow
Shows what is missing, what is already tracked, who owns follow-up, and what needs attention next.
Missing evidence
0
Tracked evidence
0
Open remediation
0
Overdue
0
Owner coverage
0/0 assigned

This browser only

May not be visible to other team members or on another device.

Evidence is tracked as metadata and references. File upload, storage buckets, connector verification, and AI evidence analysis are not enabled in this release.

Next actions

  • Keep evidence references current and move remediation items through review.
Evidence and remediation metadata is in this browser workspace only and may not be visible to other team members. Check the workspace connection before relying on this for client delivery.
Evidence recordsThis browser only
Evidence requests and records you’ve created from audit-run gaps — owner, due date, status and notes. Metadata only: no files are uploaded. Browser workspace records may not be visible to other team members.
Showing 0 of 0 evidence records

Loading…

Evidence records

7

Verified

2

Expired

1

Sample evidence records
Illustrative evidence records linked to controls and frameworks — sample data showing how evidence references appear. Not real tenant evidence.
AI Inventory export (ZAGOS Governance)
Snapshot of 14 registered AI systems with risk classification from the Governance module.
ai inventory record
Verified
Open
Encryption configuration scan
TLS 1.2+ enforced; at-rest encryption enabled on primary datastore.
scan result
Collected
Open
Data retention policy v3
Retention schedule document — expired and pending refresh.
policy document
Expired
Open
Records of Processing Activities (RoPA)
Current RoPA covering 22 processing activities with lawful basis mapping.
policy document
Verified
Open
IAM policy export
Exported IAM bindings for review of least-privilege adherence.
log export
Pending review
Open
Supplier security questionnaire — Acme Logistics
Partially completed supplier questionnaire — sections on encryption missing.
vendor doc
Pending review
Open
AI provider usage log (sample)
Synthetic AI usage/billing series used for anomaly demo. No real provider contacted.
log export
Collected
Open
Evidence references and attachments represent sandbox compliance data. No real files are stored in the cloud.Evidence request wording: copy to clipboard only. No emails are sent.