Evidence packs

Open Evidence packs from the main navigation. Owners, admins, and auditors can generate packs and read generation history. Viewers see an access explanation and can ask their owner for export access.

Generate a report

  1. Under Generate a pack, choose a Reporting period: the last 1, 7, 30, 90, or 365 days.
  2. Choose PDF for a readable report or CSV for spreadsheet data.
  3. Select Generate PDF or Generate CSV. The file downloads when ready.
  4. Save the file and its generation record for your review.

The selected period and format are part of the page link. Overview also offers Export PDF, Export CSV, and a link to Evidence packs that carries its selected period. A pack uses the chosen period, not the investigation filters from Detections, All events, or a saved view. Use the relevant screen's CSV export when you need filtered records.

What a pack includes

  • Catalogued tools and recorded detections by severity, block events, and coaching overrides.
  • Current enforcement mode and enrolled-device count, with policy/configuration changes in the period.
  • Monitoring scope and limits, with evidence mappings for SOC 2, ISO 27001, ISO 42001, and AI literacy controls.

Mappings provide evidence toward controls; they do not certify compliance. Catalogue membership does not mean your organization approved a tool. Recorded detections do not establish successful sends, and enrolled-device counts do not establish a count of employees or a seat-coverage percentage.

Activity totals use UTC days and include the first day in full; today's totals can still update. Change history uses the trailing date window. Configuration and enrollment describe the generation snapshot. Employee identifiers, raw change targets, and change payloads are omitted.

Reports can only use retained data. Selecting 365 days does not restore older records already removed under your plan's retention rules. If more than 200 policy or configuration changes fall in the period, choose a shorter period to generate a complete pack.

Inspect history and verify a file

Expand a Generation history record to see its summary, format, period, author, generation time, pack version, and SHA-256 hash. Copy hash copies the full value. Compare the SHA-256 hash of your saved file with the record to confirm the bytes match.

For example, on macOS use shasum -a 256 /path/to/report.pdf; in Windows PowerShell use Get-FileHash -Algorithm SHA256 C:\path\report.pdf. Substitute the path of your saved PDF or CSV.

Load older packs continues through history. Refresh history includes newer generations. A recorded generation confirms a pack was produced; it does not confirm your browser saved the file.

Generate again or recover a download

Blank keeps the generation record and hash, not a stored copy of the file. Use these settings selects a prior record's period and format. Generating again uses current records and creates a new file and hash; it does not retrieve the original bytes.

Cancel generation, a timeout, leaving the page, or changing report settings can stop the local download after the server recorded a pack. Refresh history before trying again. If file verification fails, no download starts; check the displayed error and refresh history before generating another pack.

To investigate individual findings behind a report, return to Activity → Detections. To see who changed a setting, open Settings → Audit log.

View this page as Markdown →