Evidence gives reviewers material to inspect when assessing a control. Attach it to the relevant control record and explain in the assessment rationale what the material demonstrates.

Open the evidence panel

Select the control in Policies or Controls, then open Evidence in its resource panel. The available actions depend on your access and the workspace's evidence settings.

Upload a file

Choose Add evidence… → Upload file, then choose or drag in the appropriate files. File selection starts the upload process; multiple files upload in sequence. Wait for each result and check that the resulting evidence appears against the intended control.

Use meaningful filenames that identify the scope and period, such as a dated access-review export. Retain only material appropriate for the people who can access the record.

Choose Add link, enter a meaningful Name and the URL, then choose Add the link. Check the destination and make sure intended reviewers also have access to the external resource. Adding a URL does not change that resource's own permissions.

Keep evidence useful

Review relevance, date and scope when reassessing a control. A comment can explain a conclusion, but an attachment or link should provide the underlying support. The evidence count reports attached items; it does not measure their quality or establish successful implementation.