Cyber Health Score

Governance and assurance

Evidence Vault overview

What the Evidence Vault is and how evidence records fit your assurance workflow.

Audience
Analysts and above
Required role
Analyst
Plan availability
All plans
Last reviewed

The Evidence Vault is where your workspace stores evidence records and attachments for assurance workflows. Use it to collect policies, screenshots, technical notes, and other material that supports audits, customer reviews, or internal governance.

How Evidence Vault differs from other reports

Product areaPurpose
Evidence VaultTenant-managed evidence records and attachments with review workflow
Compliance EvidenceGenerated compliance-oriented evidence summary for audit preparation
Configurable ReportsUser-created reports that can include approved evidence

These areas work together but serve different purposes. Do not assume a Compliance Evidence view replaces the Evidence Vault.

Evidence record lifecycle

Evidence records move through review states such as:

  • Draft
  • Submitted
  • Changes requested
  • Approved
  • Rejected
  • Archived

The vault also highlights records that are expiring soon so you can renew or replace them before they lapse.

Who can do what

  • Analysts and above can create evidence records and upload attachments.
  • Admins and Owners can review submitted evidence (approve, reject, or request changes).

Storage

Evidence attachments are stored in durable object storage configured for the service. Upload availability depends on your deployment configuration.

Expected result

You understand when to use the Evidence Vault instead of generated reports, and which roles participate in the review workflow.

Return to the documentation home to browse all topics.

Back to documentation