Skip to content

Evidence

Evidence is what you attach to your controls to show an auditor that your security practices are in place. It can be a link, a note, a document you write in Oneleet, or an uploaded file, which is stored as an Image item if it’s an image and as a File item otherwise. Everything you add goes into your workspace’s evidence library on the Evidence page, and from there you link each item to the controls and vendors it supports, answer our evidence requests, and download the evidence linked to a framework’s controls as an evidence report.

Evidence is part of Oneleet’s Compliance features and appears under Compliance in the sidebar. What you can do depends on your workspace role, and Owners can do everything Admins can:

Action Who can do it
View, preview, and download evidence Members, Admins, and Auditors
Add evidence, and link or unlink it on controls Members and Admins
Edit or delete an item Admins, and the member who added it
Create or edit in-app documents Admins
Link or unlink evidence on vendors Admins
Retry an AI analysis, or change AI settings Admins
Download the evidence report Admins and Auditors

Open a control and use the Evidence section of the right-hand sidebar:

  • Drop files onto the dropzone to upload them.
  • Click Add note to write a note, then click Submit note.
  • Click Add link to add a URL, with an optional name.
  • Click Link evidence to pick an item that’s already in your library. Search the list by link, file name, or document title. The button doesn’t appear when every item in your library is already on the control.

Policies aren’t evidence, so they don’t appear under Link evidence. A control that needs a policy is satisfied through its policy check.

Each scope item under the control has its own upload panel, except scope items a monitor verifies automatically, which need no upload. Evidence you add there is linked to the control and counts for that scope item. When a monitor covering the scope item is alerting, the panel is hidden, so click Attach evidence instead to upload.

Where you can, upload an export or a screenshot instead of adding a link. If you do add a link, use one your auditor can open with their own permissions rather than a publicly accessible one.

Files can be up to 40 MB. Accepted types are images (JPG, PNG, WebP, GIF), PDFs, Office files (DOC, DOCX, XLS, XLSX, PPT, PPTX), and text formats (CSV, TSV, TXT, Markdown, YAML, JSON, XML). HTML files aren’t accepted.

Anything you add here is linked to the control right away and recorded in the control’s timeline. Adding any evidence, even a note or a link, marks the control’s evidence check as passing, and evidence added in a scope item’s panel also marks that scope item’s check as passing when it satisfies the scope item. These checks are Oneleet’s, and a passing one doesn’t mean anyone has reviewed the evidence yet.

Adding evidence doesn’t start a review. Once the control has what it needs, click Submit for review in the control’s Control review section, or Resubmit for review if we sent the control back. The control then waits for our review. Your auditor reviews the control separately, as described in What this means for your audit.

If you add recurring evidence, such as quarterly review minutes, to a control we’ve already approved, resubmit the control for review when you’re in a SOC 2 Type 2 observation period or otherwise want that evidence audited. You don’t need to resubmit for evidence you’re only keeping as a paper trail.

The Evidence page lists every item in your workspace, whether or not it’s linked to a control or vendor. Items that other people or Oneleet add elsewhere appear without a reload.

To add evidence here, drag files onto the dropzone, click Drag and drop or browse files, or paste files anywhere on the page. Click Add links to add one or more URLs at once, each with an optional name. The same file limits apply as on a control.

Items you add on the Evidence page aren’t linked to anything yet. To use one on a control, open the control and click Link evidence.

Search on the Evidence page matches an item’s name or file name, but not a link’s URL or a note’s text. A Document item matches the title the document had when you created it, so searching for a later title won’t find it. The Type filter covers images, files, links, and documents, but not notes.

Click an item’s Open button to see who added it, preview it, and see the controls and vendors it’s linked to. Images and PDFs preview in the app, and other file types are download-only.

Admins can write a document in Oneleet and store it as evidence.

  1. On the Evidence page, click Add document.
  2. Choose a template and click Use template.
  3. Write the document and click Create.

The document appears in your library as a Document item. To change it later, open the item and click Edit on the document card, or click the pencil on the item’s row on a control.

When we need something specific for a control, we add an evidence request to it. Each request appears on the control page with a status and a description of what we need. Only Oneleet creates, edits, or removes requests, so you can’t dismiss one yourself.

To see open requests across all your controls, use the Journey page or the Program page. During a SOC 2 Type 2 observation period, and during the SOC 2 audit or an ISO 27001 Stage 1 or Stage 2 audit, the Journey page lists each control that has a request we haven’t approved, with a View control button that opens it. On the Program page’s Controls tab, the Evidence Requests filter offers three options:

  • Active Requests: requests open now, including ones you’ve already answered.
  • Upcoming Requests: requests that open at a later date.
  • Completed Requests: requests we’ve approved.

The Compliance dashboard doesn’t list individual requests. During the observation period, a framework’s card shows how many evidence requests need your attention, and Admins can click that row to open the Journey page.

To answer a request, upload files in the request’s own panel on the control page, and they’re linked to that request. To use an item that’s already on the control, open its row menu, choose Link to pending request, select the request, and click Link evidence. If the control has pending requests and you drop a single file on its main dropzone or on a scope item’s panel, the Link to a pending request dialog opens automatically, unless the AI consent dialog opened for that same drop. To keep the file on the control without attaching it to a request, click No.

Linking evidence to a request moves the request to Ready for review. If we sent the request back with Needs changes, adding new evidence also returns it to Ready for review. While its control is in review, a request shows In review, and it shows Approved once we approve it. A request with a future start date shows the date it opens and has no upload panel until then.

Evidence attached to a request shows only inside that request’s panel, not in the control’s main evidence list. It’s still linked to the control, so choosing Unlink from this request moves it back to the main list.

During a SOC 2 Type 2 observation period, we send reminders by email and Slack about requests that are still open, and the emails go to workspace Admins. We check once a day and remind you about the same request at most every 7 days. To stop these reminders, turn off the Evidence is due during observation period notification preference, listed in the notification catalog.

Click Edit on an item’s row on the Evidence page, or open the item’s row menu on a control and choose Edit evidence. In the dialog, change the item’s Name or Note, change a link’s URL, or upload a new file to replace the current one. For a Document item, the dialog changes only the name and note, so edit the document itself in the document editor.

Replacing a file deletes the old one and changes the item’s type to match the new file, so replacing a File item’s file with an image turns it into an Image item. Any edit, even a rename, runs the AI review again.

To take an item off one control, open its row menu on that control and choose Unlink from this control. This also removes it from any request on the control, and the item stays in your library and on its other controls.

Delete removes the item from every control, vendor, and the Trust Center, and deletes its file. On a control row, it reads Delete for N controls when the item is on several, because deleting there isn’t limited to that control.

Deleting a Document item also deletes the in-app document, and deleting the document from its editor deletes the evidence item.

After you unlink or delete evidence, the control’s checks update in the background. If you remove the last item from a request, the request goes back to waiting for evidence.

Oneleet AI can check each item for the basics an auditor looks for and flag problems before you submit. The review runs only when we’ve enabled AI evidence review for your workspace and an Admin has allowed it under Settings → AI features. That page has an Organization AI access card for every AI feature, with a Grant access or Revoke access button, and below it an AI evidence review switch for this feature.

If no Admin has decided yet, the first time an Admin drops files on a control, a consent dialog asks them to allow or deny AI evidence review before they continue. Choosing Deny stops the dialog from appearing again, and you can change the decision later under Settings → AI features. Uploads and edits still work without consent, but those items get no AI verdict. The Evidence page never shows this dialog.

Each item the review has checked shows one of these badges:

  • Validated by Oneleet AI: the item meets the basic technical requirements for auditor review (a resource identifier and a timestamp).
  • Oneleet AI: followed by Potential issues and the list of problems the review found.
  • Oneleet AI: followed by Internal error or Analysis failed: the review couldn’t finish.

The problems can include a missing resource identifier or timestamp, except on links, which the review never flags for either. Hover over the label for details and, when there is one, a suggestion under Oneleet AI suggests. On the Evidence page, an item with a problem shows a warning icon.

If you’re an Admin, run a failed analysis again by clicking the refresh icon labeled Retry Oneleet AI analysis on the item’s row on a control. The Evidence page doesn’t offer a retry.

Workspace members with the Auditor role see the AI badges in the Oneleet app, but the Auditor Portal doesn’t show them.

Every hour, we attach documents we generate, such as published pentest reports, your risk register, and completed access reviews, to the matching controls as File evidence. The Statement of Work doesn’t wait for the hourly pass. We attach it to the Third-party security oversight conducted control as soon as we generate it.

Each source has one evidence item, so when we regenerate a document, it replaces that item instead of adding a new one. If you’ve renamed the item, your name stays, but we rewrite its note. A document whose control isn’t in your frameworks isn’t attached anywhere.

Use evidence on vendors and the Trust Center

Section titled “Use evidence on vendors and the Trust Center”

Admins can upload files, add links, or link library items in the Evidence section of a vendor’s assessment page, and unlink them from there too. See Vendors for the rest of the assessment.

To publish evidence on your Trust Center, click Add document on the Trust Center’s Documents tab, then choose Evidence in the type filter on the Add document to trust center page. Only files and images are listed.

The evidence report is a ZIP file with a framework’s evidence and related program records, such as your policies and risk register. On the Compliance dashboard, click the three-dot menu on a framework’s row and choose Download evidence report. On the legacy dashboard, click Download Evidence Report on the framework’s card instead.

The report is built for the framework’s most recent audit and includes only evidence linked to controls in that framework. Library items that aren’t linked to any of its controls are left out, and evidence linked only to a vendor goes in vendor_register/vendor_evidence/ instead. The report includes every linked item, whatever its date.

All evidence files go in a single evidence/ folder, and evidence_mapping.csv lists which control each file belongs to. An item linked to several controls appears once, and files with the same name get -2, -3, and so on added to the name. Links are listed in links.csv, and notes are in a notes/ folder.

The report skips an item and lists it in missing_files.txt when its file is missing or was never stored, when an in-app document’s content is missing, or when an attachment on an evidence request has no download link. Any other download failure stops the whole report.

Nothing unlinks automatically when a new audit starts. To collect fresh evidence for the new period, go to the Program page, select controls on the Controls tab, and click Unlink evidence. Members and Admins can do this.

This removes uploaded files and images from the selected controls. Links, notes, in-app documents, and documents we generate stay attached. The unlinked files stay in your library as a record of the earlier period, and you can link them again.

Oneleet’s review and your auditor’s review are separate. A passing evidence check, Validated by Oneleet AI, an approved evidence request, and a control review all come from Oneleet. Your auditor accepts each control separately in the Auditor Portal.

Auditors assigned to your audit can see and download your whole evidence library in the Auditor Portal’s Evidence section as soon as you add each item, whether or not it’s linked to a control. A control’s evidence also shows to the auditor right away, before you submit the control or we approve a request.

Evidence doesn’t expire in Oneleet, and nothing in the app compares an item’s date to your audit period. Auditors only accept evidence that’s dated within your audit period (for SOC 2 Type 2, the observation period) and shows a visible timestamp and an identifier for the system it came from. For more on what auditors look for in each item, see What makes good evidence.

  • Names can be up to 255 characters, notes up to 10,000, and links up to 2,000.
  • The Add links dialog closes as soon as you click Add. If a link fails to save, you don’t see a message, and the other links still save.
  • Evidence uploaded through the API or MCP server with a service key has no owner (shown as “—” in the Owner column), so only Admins can edit or delete it. It also doesn’t add an entry to the control’s timeline. See Service keys and MCP.
  • The Auditor Portal dates each item on a control by when it was last updated, while Oneleet shows when it was added.
  • In the Auditor Portal, Notes and Documents show no file. On a control, a Document item reads “In-app document (preview unavailable in audit portal).”