Quality & freshness
Every registered evidence item carries a quality score from the moment it exists, and the platform keeps watching it afterward: a nightly sweep marks evidence stale as it ages. Together the two signals answer the questions an auditor will ask before you do — how strong is this artifact, and is it still current?
The quality tiers
Each item's quality is summarized as a tier badge — Excellent, Good, Fair, or Poor — with the underlying score shown alongside it. Hover the badge and a tooltip breaks the score into its five dimensions.
Read the tiers as a triage signal, not a grade to chase:
- Excellent evidence is audit-ready as it stands.
- Good evidence supports its controls but has a weak dimension worth knowing about.
- Fair evidence needs work before you would want an auditor reading it.
- Poor evidence is a placeholder — it marks where proof should be, and little more.
What the five dimensions mean
The tooltip's dimension breakdown tells you which kind of weak an item is, and each dimension suggests its own fix:
- Freshness — how recent the artifact is relative to what it claims to show. A two-year-old penetration test scores low no matter how thorough it was. Improve it by re-running the activity and replacing the artifact, or registering the newer version alongside it.
- Completeness — whether the item is fully described: a real title, a description that says what it demonstrates, the metadata filled in. This is the cheapest dimension to raise — edit the record and describe it properly.
- Specificity — whether the evidence speaks to something concrete or in generalities. "MFA enforced for all admin accounts, export attached" is specific; "we take security seriously" is not. Improve it by registering the targeted artifact rather than the umbrella document.
- Verifiability — whether a third party could check the claim: the source is attached, hashed, and traceable rather than asserted. Registered files carry an integrity snapshot for exactly this reason; free-floating claims with nothing behind them score low.
- Authority — how much weight the source carries. An independent audit report outranks an internal spreadsheet; a system-generated export outranks a hand-typed summary. Improve it by sourcing the artifact from the most authoritative system or party available.
The score is a symptom. When an item reads Fair, open the tooltip, find the lagging dimension, and act on that: describe it, replace it with a fresher run, or swap in a more authoritative source. The score follows.
Staleness and the nightly sweep
Evidence does not fail loudly; it just gets old. A nightly sweep walks the registry and flags items whose age has overtaken their useful life, so staleness is a maintained state you can filter on — not something you discover during an audit.
Freshness is also a dimension of the quality score, which means a stale item degrades on its own even if nothing else about it changes. The Health tab of Evidence Analytics collects the consequences in one place: a stale-evidence alert listing the items approaching or past their useful life, each with its current freshness reading, and a click-through to the record so you can refresh or replace it.
What stale means for an audit: a stale item still exists, still hashes, and still proves what was true when it was captured — that is exactly what sealed, point-in-time records are for. What it no longer does is demonstrate that a control is operating now. An auditor testing operating effectiveness will ask for evidence from the review period, and a stale artifact invites the follow-up question you were trying to avoid. Treat the stale flag as a work queue: re-run the underlying activity, register the fresh artifact, and let the old one stand as history.
Watching quality across the whole registry
Evidence Analytics is the org-level view of the same signals. The Overview tab shows total-evidence metric cards, an Evidence by Source chart, and the quality-tier breakdown; the All Frameworks filter in the header narrows every chart to a single activated framework, so you can see where coverage for that framework is strong or thin.
The Quality tab breaks the registry down across the five dimensions and by source module, and lists your lowest-quality items — the practical starting point for an improvement pass. Use Capture Snapshot on the trend chart to record today's quality, and the 30-day trend fills in over time.
The score in the Documents table measures how cleanly text was extracted from a file; the score in the Evidence Library measures how strong the item is as proof. A perfectly extracted document can still be weak evidence, and both scores can be recalculated — documents from the library header's recalculate button, evidence continuously as its dimensions change.
Next: putting quality evidence to work — linking it to controls and bundling it for auditors in Reuse & packs.