Reuse & packs
A registered item earns its place when it is connected to the things it proves. This page covers the three ways evidence pays off: linking it to controls, harvesting it from approved questionnaire answers, and bundling it into sealed packs for auditors and customers.
Link evidence to controls
Linking is what turns an artifact into coverage. From an evidence item, open Link Evidence to Controls, pick the control (or framework requirement) the item supports, and set two things:
- Link type — how the evidence relates to the control: does it implement it, attest to it, document it.
- Link strength — how much of the control this item covers, on a sliding scale. A quarterly access-review export strongly covers an access-review control; a policy PDF that merely mentions the topic covers it weakly.
Once linked, the relationship is visible from both ends. The evidence record shows a Linked Controls section with each control's framework badge, link strength bar, and validation status; the control shows the evidence backing it. Those links are what control satisfaction, framework assessments, and audit engagements read from — an unlinked item, however excellent, counts toward nothing.
Link the same item everywhere it genuinely applies. Frameworks overlap heavily, and a single strong artifact — an access-review export, a pen-test report — often satisfies sibling requirements across several activated frameworks. Collect once, link many times.
Evidence from approved answers
Questionnaire answers your team approved in the Review Center are small, sourced attestations about your posture, and they register into the same Library as everything else — automatically where your organization has that enabled, or with one click on the approved answer. Once registered, they are ordinary evidence: quality-scored, linkable to controls, and available to future questionnaires, so your approved wording compounds instead of being sent once and forgotten.
The full flow — approval, registration, and what the answer looks like as an evidence record — is covered in the Questionnaires guide: Register evidence & export.
Build an evidence pack
When someone outside your team needs proof — an auditor, a customer, a certification body — you hand them a pack, not a folder of loose files. A pack is an ordered bundle of registered evidence items assembled for one deliverable.
Select the items you want and open Create Evidence Pack. Name it (a name like "SOC 2 Type II Evidence Pack Q1" tells the recipient what they are holding), pick a pack type — Audit Response, Certification, Assessment, Incident Report, or Custom — add an optional description, then reorder or remove items until the bundle reads in the order you want it reviewed.

You can also start a pack from inside a workflow: the Review Center's Create evidence pack button opens the same dialog pre-loaded with the evidence a questionnaire produced.
Seal evidence for release
Sealing is what releases an item beyond your team — it marks the item as the version of record and makes it visible to an external auditor; unsealed evidence stays internal. From the Evidence Library, seal an item with the lock action on its row. Sealing is per item, so you decide exactly what leaves your workspace, and the Release column shows sealed versus internal at a glance.

Seal an item when it is final and you intend an auditor or customer to see it — not while you are still revising it. Unsealing withdraws it from external release again, so the decision stays in your hands: sealed means "this is the version we are standing behind."
A pack then bundles evidence for one deliverable. Build the pack, make sure the items it holds are sealed for release, and it is ready to hand over — each item's seal is what makes the bundle defensible.
Export and hand it over
A pack can be exported for submission — that is the artifact you give the auditor or attach to the customer response. Because each sealed item carries its own integrity record, the recipient is not taking your word that the contents are what you collected. Audit engagements draw on the same registry from their side, so an evidence request in an audit is typically answered by items and packs you have already built here.
That is the full evidence lifecycle: files in, quality and freshness watched, links to controls doing the daily work, and sealed packs going out the door. Start again at the Overview for the map, or jump to any stage from the sidebar.