Skip to content

Controls

A control is a security practice in your compliance program, such as “Penetration testing performed”. Each control maps to requirements in your frameworks, and Oneleet tracks whether it’s in place through checks on your monitors, policies, integrations, and evidence. When a control’s checks are in order, you submit it to the Oneleet team for review, and it reads Passing once we’ve approved it.

Each control’s status counts toward the progress of its requirements and frameworks. Passing reflects our review, not your auditor’s (see What this means for your audit).

Controls are on the Controls tab of Compliance > Program. Members or higher can assign owners, add evidence, comment, and submit controls for review. Admins or higher can also snooze or disable monitors, see Supported integrations, and delete any evidence. Members can delete evidence they added, except in-app documents, which only Admins or higher can delete.

Auditors can view controls, their checks, and their evidence, but they can’t add evidence, comment, or submit controls for review, and they don’t see a control’s Activity or Implementation notes.

There’s no way to create or delete controls in the app. They’re added for the frameworks in your program, so a workspace with no active frameworks yet sees “No active frameworks” on the Program page instead of its tabs.

Every control is backed by checks, which Oneleet adds based on the kind of control it is. Checks come from these sources:

  • Monitor: passes when the monitor is Passing, and fails when it’s Alerting or Breaching SLA.
  • Policy: passes once a policy of that type is published. It’s in progress while the policy is unpublished. The check also shows who has signed the policy, but signatures don’t change its result.
  • Integration: passes once an integration in that category is connected, and is in progress while it isn’t finished connecting.
  • Evidence attached: passes as soon as any evidence is linked to the control. A control has this check only when it has no other checks, when all its other checks are inactive, or when it has a started evidence request (one with no start date, or whose start date has passed), even one we’ve already approved.

Only monitor checks can make a control Failing. A check whose monitor is snoozed, disabled, or has no applicable assets is inactive, and so is a policy or integration check when you don’t have that policy or integration at all. Inactive checks are collapsed behind Show N inactive checks on the control page and don’t count toward the control’s status.

Oneleet updates checks when your evidence, policies, integrations, or scope change, and rebuilds all of your workspace’s checks once an hour. The control page refreshes every 10 seconds while you have it open.

A control’s status combines its checks with the state of our review:

Status Meaning
Failing At least one monitor check is failing, including a monitor that’s Alerting but still within its SLA.
Needs changes We reviewed the control and requested changes.
In review You submitted the control, and it’s waiting for our review.
In progress Work is underway, or every check passes but we haven’t approved the control yet. An approved control whose checks all pass also reads In progress while any started evidence request is unreviewed, including one that’s still waiting for your evidence.
Not started The control has no checks, or none of its checks have made progress yet.
Passing Every counted check passes, we’ve approved the control, and every started evidence request has been reviewed.

Our review takes priority over the checks. A control you’ve submitted reads In review even when a check is failing, and a control we sent back reads Needs changes whatever its checks say. A requirement reads Met only when it has at least one control and every one of them is Passing.

The Controls tab groups controls by status, from Failing to Passing. A control is listed when any of its requirements belongs to a framework selected in the framework dropdown. In the Evidence Requests filter, a request is upcoming until its start date, then active until we approve it, and completed once approved.

Your filters are kept in the page URL. To download the list, click Export. The CSV covers the rows your current filters show, with each control’s ID, title, status, passing, active, inactive, and total check counts, owner, evidence count, description, and instructions.

To assign an owner, pick a member in the control’s Owner column or on the control page. For several controls at once, select their rows and choose Assign owner or Unassign owner in the action bar at the bottom. Assigning an owner doesn’t send them a notification, so tell them yourself. Each change is recorded in the control’s Activity and in the workspace Audit log.

The owner list leaves out members who are Offboarding or Former. An owner who reaches one of those states stays assigned and shows a status badge, so reassign their controls.

Open the control and find the check in its Checks section. Each check links to the place where you fix it:

  • Monitor: click the check’s action, usually View monitor, and follow its remediation steps (see Monitors).
  • Policy: click Add policy or Publish policy.
  • Integration: click Add integration or Finish connecting.
  • Evidence attached: add evidence as described in Add evidence.

When a monitor’s check doesn’t apply to your organization, an Admin can snooze or disable the monitor from the monitor’s page. Monitor checks are the only ones you can silence this way. Snoozing requires a Reason for snoozing and disabling requires a Reason for disabling, and each snooze or disable is recorded in the workspace Audit log and in the monitor’s Lifecycle in the auditor portal. Give a real justification the auditor can ask about, because snoozing or disabling a monitor isn’t a way to opt out of a requirement.

Monitors added while your workspace is in a SOC 2 Type 2 observation period start snoozed until four weeks after the period ends, so their checks stay inactive until then.

Add evidence in the Evidence section on the right of the control page. Drop files into the upload area (up to 40 MB each), click Add note to write a note, or click Add link to add a URL. To reuse something from your evidence library (the Evidence page in the sidebar), click Link evidence. It lists only items that aren’t linked to this control yet, and policies never appear in it because they aren’t evidence items.

Adding evidence doesn’t submit the control for review. When the control is ready, click Submit for review as described in Submit a control for review.

Adding evidence can change a control’s status, for example through its Evidence attached check or by reopening an evidence request we rejected (see Respond to an evidence request). After you add evidence, the Evidence attached check reads Passing the next time the page refreshes. The control itself reads Passing only when every counted check passes, we’ve approved the control, and every started evidence request has been reviewed, so a request that’s still waiting for your evidence keeps the control from Passing. On a control we haven’t approved yet, adding evidence gets it to In progress at most.

If the control lists Available templates, click Create to write an in-app document from a template, or Link to attach a document you’ve already created from it.

If you’re not sure what evidence a control needs, read its description and instructions, see What makes good evidence, or mention @oneleet in a comment in the control’s Activity section. A comment that mentions @oneleet opens a support conversation with the Oneleet team, and mentioning a workspace member emails that member.

To remove an item from one control, open its menu and choose Unlink from this control. The item stays in your evidence library, and on any other controls it’s linked to, with its original upload date. Delete (or Delete for N controls when the item is linked to more than one control) removes the item from every control it’s linked to and deletes the file.

After you unlink or delete evidence, the control’s checks update once background processing finishes. When an unlink removes the last evidence from an evidence request, that request goes back to unreviewed, and when it removes the control’s last evidence, the Evidence attached check goes back to pending. Either way, the control drops out of Passing until you add new evidence, and a reopened request also needs our review.

We sometimes request additional evidence on a control. Requests appear in the Control review section, and each active request has its own upload area that attaches evidence directly to that request. To attach an item that’s already on the control, open its menu and choose Link to pending request. When you upload a single file to a control with active requests, Oneleet offers to link it to a request, but dropping several files at once skips that offer.

A request that hasn’t opened yet reads “Evidence can be submitted for this request beginning {date}.” and has no upload area until then. Uploading to a request we rejected reopens it for our review, so an approved control that was Passing reads In progress until we review that request.

When a control is finished, click Submit for review in its Control review section. The checklist above the button reads “All active checks are passing or within your SLAs” and “Required evidence is provided”. To submit, every active check must pass or come from a monitor that isn’t Breaching SLA, and every active evidence request must have evidence. A monitor that’s Alerting makes the control Failing but doesn’t block submission. Hover over the disabled button to see which condition is unmet. A control with no checks can’t be submitted.

Submitting sends the control to the Oneleet team, not your auditor, and it reads In review until we respond. Submit each control from its own page. After we review the control, the outcome appears in the timeline of its Control review section:

  • Approved by: the control reads Passing if every counted check passes and every started evidence request has been reviewed. Otherwise, its status follows its checks: Failing if a monitor check is failing, Not started if none of its checks have made progress, and In progress in every other case. Approvals don’t send email.
  • Changes requested by, or Additional evidence requested by when we left no notes and the control has at least one evidence request: the control reads Needs changes. Any notes we left appear in the timeline. If there are no notes and no evidence requests, the timeline reads “No details provided. Please get in touch.” Make the changes, then click Resubmit for review.

After you add recurring evidence to an approved control (such as quarterly review minutes or a policy re-reviewed for the year), click Resubmit for review. This takes the control back to In review, even if it was Passing. To withdraw a submission, click Cancel review. This returns our review to where it stood before you submitted, so cancelling a resubmission of an approved control leaves it approved, and cancelling a resubmission of a control we’d sent back returns it to Needs changes. In any other case, the control’s status reflects its checks as they are now, so if a check changed during the review, the control won’t read what it did before you submitted.

Evidence needs to be dated within the current audit period. When a new period begins, unlink last period’s uploads so your controls can collect fresh evidence.

  1. On the Controls tab, select the controls to clear.

  2. In the action bar, click Unlink evidence.

  3. In the confirmation dialog, click Unlink evidence.

This removes only files and images you uploaded. Links, notes, in-app documents, and files Oneleet generated stay attached. The Evidence column counts Oneleet-generated files too, so a control can show a file and the unlink can still report “No uploaded evidence to unlink”.

Unlinked files stay on the Evidence page with their original date in its Added column, and you can link them again. Each control’s Activity lists the files removed from it, and the workspace Audit log records the bulk action. Once background processing finishes, a control that lost its last evidence, or whose evidence request did, drops out of Passing, as described in Add evidence.

Passing means the Oneleet team approved the control, not your auditor. Submitting a control for review sends nothing to the auditor. Your auditor keeps a separate review of each control in the auditor portal, with the statuses Open, Pending evidence, and Approved, and a control reads Open there until the auditor acts on it. In the auditor portal, a requirement counts as met only through the auditor’s own approvals.

Auditors only accept evidence dated within the current audit period, or within the observation period for a SOC 2 Type 2 audit. The auditor portal shows all evidence linked to a control along with its dates, which is why you clear last period’s evidence when a new period begins.

A monitor that breaches its SLA during a SOC 2 Type 2 observation period can become an exception on the audit report.

In the auditor portal, a snoozed monitor appears in its Lifecycle with the snooze reason. A disabled monitor appears only as an Inactive entry reading “This monitor is disabled for your organization”, without the reason the Admin gave. Comments and history in a control’s Activity section aren’t visible to the auditor.

  • You can’t disable a control or mark it out of scope, and you can’t mark a requirement not applicable. Only monitor checks can be silenced, as described in Fix checks that aren’t passing.
  • Auditors see your submissions attributed to your workspace’s team, not to the member who submitted.
  • Removing a framework is done by the Oneleet team. It keeps any control you’ve done work on, such as assigning an owner, linking evidence, commenting, or going through review.
  • Dismiss on Available templates and Supported integrations is saved in your browser only, so the section reappears on another device or browser.
  • Comments can be up to 10,000 characters, but formatting, extra paragraphs, and mentions count toward that limit, so the text you can type is shorter. Links added as evidence can be up to 2,000 characters, with a name of up to 255.