> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate compliance evidence

> Check control status for ISO 27001, SOC 2, CIS AWS Foundations and NIST CSF, run an access review, and export a checksummed bundle for an audit period.

export const Plan = ({tier}) => <Badge color="blue">{tier} plan</Badge>;

The **Compliance** tab turns the records SRE Agent already keeps into control-by-control evidence. You see which controls your own history and your connected AWS account and GitHub repositories can speak to, raise cards for the ones that need attention, and export a bundle your auditor can verify.

<Plan tier="Business" />

Compliance is a tab of the **Security** page and is visible to org admins. It shows records, not verdicts: statuses describe evidence, and your auditor decides what it satisfies.

## Check control status

<Steps>
  <Step title="Open Compliance">Open **Security** and click the **Compliance** tab.</Step>

  <Step title="Refresh the estate evidence">
    A banner shows when the AWS scan and the GitHub scan last completed, and that they run daily.
    Click **Run posture scans now** to start both. Results appear on the page as they finish. If a
    scan is already running, the page tells you instead of queueing another.
  </Step>

  <Step title="Pick a framework">
    The tabs are **ISO 27001:2022**, **SOC 2**, **CIS AWS Foundations** and **NIST CSF 2.0**.
    Controls are grouped by category, for example Organizational and Technological for ISO, or
    Identify, Protect, Detect, Respond and Recover for NIST.
  </Step>

  <Step title="Read each control">
    Every control shows a reference, a title, a status and a one-sentence summary. Open **Evidence**
    to see the records behind it, each linked to the page in the app where it lives.
  </Step>
</Steps>

| Status | Meaning |
| - | - |
| **supported** | Your records show the control operating. |
| **attention** | Records show something that needs a person to look. |
| **no data** | The platform cannot read what it needs yet. The control tells you the exact read-only grant or the page to connect. |

Only controls the platform can evidence from live records appear. Controls that live in documents, such as policy sets or supplier registers, stay in your own governance tool.

## Act on a control

* **Attention.** Click **Create card with this evidence** to put a high-priority card on the board, labelled `compliance`, carrying the summary and evidence links.
* **No data.** Open **What would light this up: a read-only grant**, review the permission statement, and click **Request this grant as a card** to hand it to whoever owns your AWS account. **Full permission set** opens **Settings**, **Infrastructure**. Every action in the statement is a read.
* **Copy for GRC.** Click it on any control to copy its status, counts and evidence links to your clipboard for a GRC tool, an auditor email or a spreadsheet. The links are absolute, so they work when pasted.

## Run the access review

The **Access review** card generates this month's review as a card on the board. It lists every member, every collected AWS principal and the Identity Center estate, and asks the reviewer you pick for a sign-off. The decided approval becomes the evidence.

<Steps>
  <Step title="Pick a reviewer">Choose a member from **Pick a reviewer**.</Step>

  <Step title="Generate the card">
    Click **Generate review card**. The card appears on the board, and the flash message names it.
  </Step>
</Steps>

## Export evidence for an audit period

An audit period is the window an export speaks for. The page evaluates a rolling 90 days, while an export evaluates the period's own dates.

<Steps>
  <Step title="Create a period">
    Under **Audit periods**, enter a **Name** such as `SOC 2 FY26`, choose the **Framework**, set
    **Starts** and **Ends**, and click **Create period**.
  </Step>

  <Step title="Export the bundle">
    Click **Export bundle** on the period's row. You download a zip.
  </Step>

  <Step title="Keep the hash">
    The period row shows the first characters of the bundle's top hash. It identifies the manifest,
    so you can match a bundle someone presents later to the period that claims it.
  </Step>
</Steps>

The zip contains a summary of every control, one evidence file per control, and a manifest with a checksum for each file. A checksum detects alteration. It does not prove who produced the bundle, and the manifest says so.

<Tip>
  Create the period first and export it after the window has passed, so the bundle covers the whole
  window.
</Tip>

## What happens next

Statuses move as your estate does. Resolve the cards you created, run the scans again, and the control returns to **supported** when the records agree.

## Related

* [Control data privacy and retention](/guides/administer/data-privacy-and-retention): export your retention policy as evidence.
* [Manage people and roles](/guides/administer/organizations-and-roles): the member list the access review covers.
* [Track work on the ops board](/guides/respond/ops-board): where evidence cards land.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.