Skip to main content

Reuse & packs

A registered item earns its place when it is connected to the things it proves. This page covers the three ways evidence pays off: linking it to controls, harvesting it from approved questionnaire answers, and bundling it into sealed packs for auditors and customers.

Linking is what turns an artifact into coverage. From an evidence item, open Link Evidence to Controls, pick the control (or framework requirement) the item supports, and set two things:

  • Link type — how the evidence relates to the control: does it implement it, attest to it, document it.
  • Link strength — how much of the control this item covers, on a sliding scale. A quarterly access-review export strongly covers an access-review control; a policy PDF that merely mentions the topic covers it weakly.
ScreenshotThe Link Evidence to Controls dialog: control selection with framework context, the link type selector, and the link strength slider.

Once linked, the relationship is visible from both ends. The evidence record shows a Linked Controls section with each control's framework badge, link strength bar, and validation status; the control shows the evidence backing it. Those links are what control satisfaction, framework assessments, and audit engagements read from — an unlinked item, however excellent, counts toward nothing.

One artifact, many controls

Link the same item everywhere it genuinely applies. Frameworks overlap heavily, and a single strong artifact — an access-review export, a pen-test report — often satisfies sibling requirements across several activated frameworks. Collect once, link many times.

Evidence from approved answers

Questionnaire answers your team approved in the Review Center are small, sourced attestations about your posture, and they register into the same Library as everything else — automatically where your organization has that enabled, or with one click on the approved answer. Once registered, they are ordinary evidence: quality-scored, linkable to controls, and available to future questionnaires, so your approved wording compounds instead of being sent once and forgotten.

The full flow — approval, registration, and what the answer looks like as an evidence record — is covered in the Questionnaires guide: Register evidence & export.

Build an evidence pack

When someone outside your team needs proof — an auditor, a customer, a certification body — you hand them a pack, not a folder of loose files. A pack is an ordered bundle of registered evidence items assembled for one deliverable.

Select the items you want and open Create Evidence Pack. Name it (a name like "SOC 2 Type II Evidence Pack Q1" tells the recipient what they are holding), pick a pack type — Audit Response, Certification, Assessment, Incident Report, or Custom — add an optional description, then reorder or remove items until the bundle reads in the order you want it reviewed.

ScreenshotThe Create Evidence Pack dialog: pack name, the pack type selector, and the reorderable list of selected evidence items, each showing its evidence type and source module.

You can also start a pack from inside a workflow: the Review Center's Create evidence pack button opens the same dialog pre-loaded with the evidence a questionnaire produced.

Seal the pack

Sealing turns a pack from a working bundle into a point-in-time record. Click Seal Pack and confirm; the platform computes a cryptographic hash over the entire pack, and from that moment the pack and every item in it are immutable — no additions, removals, or edits, and any later tampering is cryptographically detectable.

ScreenshotThe Seal Evidence Pack dialog: the irreversibility warning, the summary of pack name and item count, what sealing does, and the confirmation checkbox before Seal Pack.
Sealing is permanent

There is no unseal. The confirmation checkbox is there because this is a one-way door: seal when the bundle is final, not while you are still assembling it. If something must change after sealing, build a new pack — the sealed one stands as the record of what was submitted.

Individual evidence items can be sealed too, from the Evidence Library. Sealing an item is what releases it to external auditors; unsealed evidence stays internal. The same logic applies at both scales: sealed means "this is the version of record."

Export and hand it over

A sealed pack can be exported for submission — that is the artifact you give the auditor or attach to the customer response. Because the seal travels with it, the recipient is not taking your word that the contents are what you collected; the hash proves it. Audit engagements draw on the same registry from their side, so an evidence request in an audit is typically answered by items and packs you have already built here.


That is the full evidence lifecycle: files in, quality and freshness watched, links to controls doing the daily work, and sealed packs going out the door. Start again at the Overview for the map, or jump to any stage from the sidebar.