Evidence
Evidence is what turns a compliance claim into a compliance fact. SolveGRC keeps one registry for everything that proves a control: uploaded documents, scan results, attestations, screenshots, reports, approved questionnaire answers. Whatever the source, every item lands in the same place — the Evidence Locker — with a quality score, a freshness state, and a cryptographic integrity snapshot, so the artifact you attach to a control today is provably the artifact an auditor sees next quarter.
This guide covers where evidence comes from, how to read its quality and freshness signals, and how to reuse it across controls, frameworks, and auditor deliverables.
The lifecycle at a glance
A piece of evidence moves through five stages. The pages in this guide follow the same order:
- Add. Upload a file to Documents or register an artifact directly in the Evidence Locker. Items produced elsewhere in the platform — approved questionnaire answers, posture findings, continuity artifacts — register themselves.
- Quality. Every item is quality-scored at registration and assigned a tier, so you can see at a glance how strong it is.
- Link. Attach evidence to the controls and framework requirements it satisfies, so coverage and reports draw from real artifacts.
- Reuse. One artifact can back many controls across many frameworks, and approved wording feeds future questionnaire answers.
- Seal. Lock an item or a whole evidence pack as a point-in-time record for auditors and customers.
How this connects
The Evidence Locker sits at the center of the platform. It consumes from three directions and feeds four:
What flows in:
- Uploads and documents. Files you add to Documents can be registered as evidence once processed.
- Approved questionnaire answers. An answer your team approved in the Review Center can register as a reusable attestation — see Register evidence & export in the Questionnaires guide.
- Posture findings and continuity artifacts. Automated results from cloud posture scans and continuity work arrive already registered.
What flows out:
- Control satisfaction. Linked evidence is what marks a control as backed by something real.
- Framework assessments. Assessments cite the evidence trail behind each per-control status.
- Audit engagements. Audits pull from the same registry, so an evidence request is answered with items you already hold.
- Evidence packs. Bundles you seal and hand to customers and auditors.
Two things happen without you asking:
- Everything is registered and quality-scored at birth. Evidence produced by the platform does not wait in a queue for someone to file it.
- A nightly sweep marks aging evidence stale, so the registry tells you which artifacts have quietly gone out of date.
Before you start
Most evidence starts life as a file. Upload your policies, reports, and artifacts to Documents and let them finish processing before you register them — a document becomes searchable, citable evidence material once it reaches Ready. The Add and classify page walks through the pipeline.
You will also need:
- Access to the modules. Evidence Library and Documents each appear in the sidebar only if your role has read permission for them, and registering evidence needs create permission. If you do not see a module, ask an administrator.
- Something worth proving. Evidence earns its keep when it is linked to controls and frameworks. If you have not activated a framework yet, the Frameworks guide is the place to start; evidence you register now will be ready to attach the moment controls exist to receive it.
Why the registry is one place
Scattering proof across modules is how organizations end up re-collecting the same SOC report five times a year. Because every module writes into the same registry, an artifact is collected once, scored once, and reused everywhere: the access-review report backing a SOC 2 control also answers the customer questionnaire that asks about access reviews, and shows up ready-made when the auditor requests it. The rest of this guide is about keeping that single copy strong, current, and provable.