Evidence

The Evidence Locker holds the proof that your organisation does what its policies say, and a second person must approve each item before it counts towards a control.

Evidence (the proof that a control is actually working) can be a certificate, a report, a screenshot, a log extract or an audit letter. Each item carries a name, a type, an optional source system, an owner and dates, and links to the controls it supports. Every new item starts as Awaiting review. Under four-eyes review (a second person checks the work), it counts towards no control until someone other than the uploader approves it.

Evidence cannot be deleted

The locker is append-only. Each stored file is hashed with SHA-256 so tampering can be detected. No role can delete an item, Admin included. A wrong upload stays in the locker as Rejected, and an outdated one becomes Superseded.

Who uses it

What's on this screen

The locker is at /evidence, headed Evidence Locker. Four actions sit in a row on the right: Evidence Gaps (AI), Refresh Triage (AI), Collection Rules and the primary action, Upload Evidence.

The filter bar sits below them. It has a Search evidence… box with a Search button, plus All Types and All Sources dropdowns. On the second line are a Filter by tag… box with its own Search button, and the All review states dropdown. The type and source lists are built from the values in your own locker.

The table has a select-all checkbox, then Name, Type, Review, Source, Size, Owner, Created and, if you scroll right, Actions. Each name starts with a type chip such as doc and ends with the file extension, such as .pdf. Review shows one of four badges: Awaiting review, Approved, Rejected or Superseded. The captured list shows all four. The list has no expiry column: a Valid Until date appears only on the detail page.

Finding and opening evidence

  1. To add something new, select Upload Evidence at the top right. The Upload Evidence dialog opens (see the next section).
  2. Type a name in the Search evidence… box. The table narrows as you type. You can narrow it further with the type, source, tag and All review states filters. For example, choose Awaiting review to see what is waiting for a reviewer.
  3. Tick a row's checkbox. A bulk bar appears above the table, showing Link to Control, Export or both, depending on your role.
  4. Select an item's name. Its detail page opens at /evidence/{id}.
  5. Check the Review badge before you rely on an item. Only Approved evidence counts towards a control.
The Evidence Locker, with its AI actions, filters and Review column — /evidence.
The Evidence Locker, with its AI actions, filters and Review column — /evidence.

Scroll the table right to reach Actions. Preview opens the file in a panel over the list, and Download fetches the original file. Both appear only when a file is stored. AI Classify appears for roles that can edit evidence.

Uploading evidence

The dialog has a dashed drop zone at the top, with metadata fields below it. The drop zone lists the accepted formats: PDF, Office documents, TXT, CSV, JSON, XML, common image types and ZIP. The limit is 50 MB per file, and Aegis refuses any other file.

Field What to enter
Evidence Name Filled in from the first file's name, and you can edit it. It applies only to a single-file upload. With several files, each item takes its own file name.
Type * Required. The dialog opens on Document.
Source System Where the file came from, such as AWS, Okta or Jira.
Link to Frameworks Hold Ctrl or Cmd to choose several. Until you choose one, Link to Controls reads Select a framework first.
Link to Controls The controls this evidence supports, from the frameworks you chose.
Valid Until, Tags The expiry date, and tags separated by commas.
Link to Vendor Optional. Use it for supplier audit reports or questionnaires. The default is None.
  1. Drag files onto the drop zone, or select browse files. Each file appears under the zone with a control to remove it. Then fill in the fields described above.
  2. Select Upload. It stays greyed out until Evidence Name has a value, as in the capture, where no file has been added yet. Each file uploads in turn with its own progress indicator. The dialog then closes, and the new rows appear with an Awaiting review badge.
  3. To stop without saving anything, select × at the top right or Cancel.
The Upload Evidence dialog: drop zone, metadata fields and framework and control pickers — /evidence.
The Upload Evidence dialog: drop zone, metadata fields and framework and control pickers — /evidence.
Evidence without a file

You can submit the form without a file, once you have typed an Evidence Name. This records that an artefact exists in another system without copying it into Aegis. The item then has no Preview or Download action.

Reviewing evidence (four-eyes)

Open an item that shows Awaiting review. The Four-eyes review panel sits under the header. It explains that the evidence does not count towards any control until someone other than its uploader approves it. The header has a Download File button, and the Preview and Extracted Text panels follow below.

  1. Check the review badge. If it reads Awaiting review and you did not upload the item, Approve and Reject appear beside it. If you did upload it, the buttons do not appear.
  2. Read the file in the preview, then select Approve. The Approve evidence dialog opens.
  3. Or select Reject. The Reject evidence dialog opens and asks for a reason.
An evidence item awaiting four-eyes review — /evidence/:id.
An evidence item awaiting four-eyes review — /evidence/:id.
  1. Add a note in Comment (optional). When you reject, this field becomes Reason (required) and you must fill it in.
  2. Select Approve. A confirmation appears and the badge changes to Approved. The panel now shows Reviewed by, Reviewed on and your note. From now on, the evidence counts towards its linked controls.
  3. To leave the item undecided, select Cancel or ×.
The Approve evidence dialog — /evidence/:id.
The Approve evidence dialog — /evidence/:id.

Rejected evidence stays in the locker with your reason and never counts towards a control; the uploader adds a corrected file as a new item. If a message says the evidence was already reviewed, someone decided first, so reload the page.

Replacing approved evidence with a new version

  1. Open an Approved item. The review panel shows who approved it and when.
  2. Read Version history, which appears once an item has more than one version. It lists every version with its badge, file name and date, and highlights the version you are viewing.
  3. Select an older version's name to open it. Superseded versions stay readable, but they no longer count towards any control.
  4. Select Upload new version. The upload dialog opens again, set up to create a new version.
An approved item with its version history — /evidence/:id.
An approved item with its version history — /evidence/:id.
  1. Read the blue note. The new version starts as awaiting review. The current version keeps counting until someone other than you approves the new one, and only then is it marked superseded. It is never deleted.
  2. Drop the replacement file. You can add only one file here. The name and type are filled in from the current version.
  3. Select Upload. The new version joins the version history as Awaiting review. Until a reviewer decides on it, Upload new version stays hidden.
Uploading a new version of approved evidence — /evidence/:id.
Uploading a new version of approved evidence — /evidence/:id.

The rest of the detail page

Further down:

Link existing items with Link to Control in the list's bulk bar; remove a link from the control in Compliance frameworks.

Checking that evidence keeps arriving

Collection Rules opens /evidence/collection-rules. A rule never creates evidence; on your schedule it checks that a source has delivered something since the last check. A miss records FAILED and turns the rule's Status to ERROR.

  1. Select Collection Rules, then New rule. A form appears.
  2. Enter a name and the Evidence type. Choose a Source system (optionally a connector), a Frequency and a Rule owner, then save.
  3. Use Pause, Edit or Delete to manage the rule. Deleting a rule stops the checks but keeps all the evidence the source delivered.

The AI assist

The three AI helpers are read-only. They describe and suggest, and a person decides.

Tips and limits

Where this connects

Approved evidence proves the controls in Compliance frameworks, which are watched in Control monitoring and mapped in Control mapping. Evidence also supports risks, policies and vendors. Before an assessment, see Audit readiness and the external audit walkthrough.