Evidence
Evidence is your workspace’s library of the files, images, links, notes, and documents that demonstrate your security practices to an auditor. You attach each item to the controls it supports (or to a vendor), and at audit time you download one evidence report for the whole framework. With AI Evidence Review turned on, Oneleet AI also checks each item against basic auditor requirements.
Evidence is included with Compliance. Any workspace member can add evidence and link it to controls. Admins can also link evidence to vendors and create, edit, or delete documents; editing or deleting any other item is limited to admins and the person who added it. Auditors can view and download evidence but can’t upload, and downloading the evidence report requires the admin or auditor role. Each file can be at most 40 MB.
Add evidence to the library
Section titled “Add evidence to the library”Open Evidence in the sidebar. Files, links, and documents added at the top of the page go into the library unlinked; you attach them to controls later. The library holds five kinds of item:
- File and Image: an uploaded file. A file your browser identifies as an image is stored as an Image; everything else is a File.
- Link: a URL, with an optional display name.
- Note: free text, added from a control.
- Document: a document you write in Oneleet from a template.
Upload files
Section titled “Upload files”Drag files onto the upload area, click Drag and drop or browse files, or paste files from your clipboard. If an upload fails, its card offers Retry.
Accepted files are images (jpg, png, webp, gif), text and data files (csv, tsv, txt, md, yaml, json, xml), PDFs, and Office documents (doc, docx, xls, xlsx, ppt, pptx). HTML files aren’t accepted.
Add links
Section titled “Add links”Click Add links and enter each URL, with an optional name. Click Add link to add another row. Use publicly accessible links, since the auditor needs to open them.
Create a document from a template
Section titled “Create a document from a template”Click Add document, choose a template, and click Use template. Write the document and click Create. It appears in the library as a Document named after its title. To change it later, open the item and click Edit on its Document card, or click the pencil on the item’s row on a control.
Attach evidence to a control
Section titled “Attach evidence to a control”Most evidence is added from the control it supports. On a control’s page, the Evidence section in the right-hand sidebar lists the evidence linked to that control and gives you four ways to add more:
- Drop files on the upload area.
- Add note: type the note and click Submit note.
- Add link: enter a URL and an optional name.
- Link evidence: pick an existing item from the library. This button appears only while the library has items that aren’t on this control yet.
Anything you add here is linked to the control immediately, and the link is recorded in the control’s timeline. An item can be on any number of controls, and the Used by badges in the library show how many controls and vendors use it.
To take an item off a control without removing it from the library, open the row’s menu and choose Unlink from this control. Delete removes it from the library and every control it’s on.
Respond to evidence requests
Section titled “Respond to evidence requests”Oneleet may ask you for specific evidence on a control. Each request appears in the control’s Evidence section with its status and a description, and has its own upload panel. A request starts out pending and becomes ready for review once evidence is attached. Oneleet then either approves it or sends it back for changes; adding new evidence to a request that was sent back marks it ready for review again.
Some requests have a start date. Until then, the request says when evidence can be submitted and has no upload panel.
You can fulfill a request in two ways:
- Upload directly in the request’s panel. Evidence uploaded there is linked to that request.
- Link an existing item. Open the item’s menu on the control, choose Link to pending request, select the request it fulfills, and click Link evidence.
When you upload a single file to a control that has pending requests, the Link to a pending request dialog opens on its own. Click No to keep the file on the control without attaching it to a request. To detach an item from a request later, choose Unlink from this request in its menu.
While an audit’s observation period is active, workspace admins get a reminder about open evidence requests by email and Slack. Turn it off with the Evidence is due during observation period preference; see the notification catalog.
AI Evidence Review
Section titled “AI Evidence Review”Oneleet turns AI Evidence Review on for your workspace; there’s no switch for it in the app. Even then, nothing is reviewed until an admin allows it under Settings → AI features. The Organization AI access card, where you click Grant access or Revoke access, applies to every AI feature, and the AI evidence review switch below it applies to this one. An admin who hasn’t decided yet is asked the first time they drop a file on a control, and can change the answer later on the same page.
Once an admin allows it, Oneleet AI reviews each item when it’s uploaded or edited and shows a badge next to it, both on the control and in the library. The badge reads Validated by Oneleet AI when the item passes, and Oneleet AI: followed by a summary of the problem otherwise.
The review checks for what an auditor needs to accept an item as proof: an identifier for the resource the evidence shows, and a timestamp. It also judges whether the item is relevant to the control it’s linked to.
Hover over the problem summary for the full list of issues and, when Oneleet AI has one, a suggested fix under Oneleet AI suggests. If the analysis failed rather than finding issues, an admin can run it again from the item’s row on a control by clicking Retry Oneleet AI analysis; library rows don’t offer a retry.
When you upload a file without giving it a name, Oneleet AI suggests one. On a control, the item shows an AI-named badge; hover over its name to see the original file name, or choose Revert to original name in the item’s menu to go back to it.
Open, edit, or delete an item
Section titled “Open, edit, or delete an item”Click Open on a library row to see the item, who added it, and the controls and vendors it’s linked to. Images and PDFs show a preview; other file types are download only. The page URL includes the item, so you can share it with a teammate.
Click Edit to rename an item, add a note, change a link’s URL, or replace a file or image with a new upload. If you clear the name, the item falls back to the AI-suggested name, or to the file name if there isn’t one. Because an item is shared by every control it’s on, the edit dialog warns you when other controls use it; your change shows on all of them.
Click Delete to remove an item from the library and every control it’s linked to; the dialog tells you how many controls that is. Deleting a Document also deletes the document itself. After a deletion, Oneleet re-runs its AI control review for the affected controls.
Download the evidence report
Section titled “Download the evidence report”On the Compliance dashboard, open the Framework actions menu on a framework row and click Download evidence report. The report downloads as a ZIP once it’s built.
The report covers the framework’s most recent audit. All evidence files go in one folder rather than a folder per control; evidence_mapping.csv records which control each file belongs to, and notes and links are included alongside the files. It also bundles the other material an auditor asks for: policies, the system description, the risk register, access reviews, penetration test reports, the vendor register and vendor evidence, monitor results, and scope. If a file can’t be retrieved, the report still generates and lists it in missing_files.txt.
Evidence for vendors and the Trust Center
Section titled “Evidence for vendors and the Trust Center”A vendor’s assessment page has its own Evidence section where you upload files, add links, or link existing library items to that vendor. See Vendors.
To publish a file or image to your Trust Center as a document, go to Trust Center → Documents, open Add documents to your trust center, and choose the Evidence tab. Links, notes, and documents can’t be published there.
Limits and notes
Section titled “Limits and notes”- Evidence has no expiry or renewal date; the only date shown is when it was added. To refresh evidence for a new audit period, unlink the previous period’s evidence in bulk from the Program page. What makes good evidence covers this and what auditors look for.
- Policies aren’t evidence. They don’t appear under Link evidence; a control that needs a policy is satisfied through its policy check instead.
- Evidence can also be managed through the API with a service key; see Service keys and MCP. Items uploaded that way have no owner, so the Owner column shows a dash.
- Auditors working in the Auditor Portal see an Evidence tab listing your full library, and a control’s evidence once they begin reviewing it.