Skip to main content

Evidence campaigns

Collecting evidence from many clients is the same set of questions asked many times. The Evidence area lets you write the questions once as a template, send them to a set of clients as a batch, review what comes back in one inbox, and notice when several clients hand you the same file.

Templates

An evidence request template is a reusable list of prompts: each prompt has a title, a description of what you need and why, an optional control reference, an evidence type (document, screenshot, attestation, log export, configuration, policy export, report) and a priority. The template carries a code, a default priority, a default due period (14 days unless changed) and a default evidence type, and is a draft, active or archived. Only active templates can be batched. A template holds up to 100 prompts.

Administrators and compliance managers author templates. Built-in templates are locked; Clone to edit copies one into a draft you own. The page is at /msp/evidence/templates.

Batches

A batch is one template sent to an audience with a due date and a reminder schedule. New batch walks three steps:

  1. Template: name the batch and pick an active template.
  2. Audience: every client on a service package, or an explicit list of up to 50 clients. Set an optional due date and the reminders, as offsets in days: positive before the due date, negative after, zero on the day (seven, three and zero by default; up to ten).
  3. Review and dispatch.

Dispatch creates one real evidence request per prompt per client, inside that client's active audit, and schedules the reminders. Two things make a client skip: the client has no active audit, or you are not an administrator and have no active delegated session in that client at the moment of dispatch. Auditors cannot dispatch.

The batch list shows each batch with its template, target count, how many items were dispatched, how many await triage and how many are overdue, and its status (queued, dispatching, dispatched, partially failed, failed, cancelled). The counters above total the active batches, pending triage and overdue items. A batch queued for a week without being dispatched is cancelled automatically.

Opening a batch lists its items per client with dispatch state, fulfilment, triage state and, for skipped or failed items, the reason. On an outstanding item the bell sends a reminder now. Administrators can cancel a batch that has not fully dispatched: pending items are skipped and future reminders cancelled, while requests already delivered to clients stay live on their side.

Reminders go out on their own from the schedule, and a client's upload is reflected on the batch within a few minutes.

Triage

Evidence Triage is one inbox for everything clients have uploaded against your batches. Each row shows the request, the client, batch and template, and how long the upload has waited (marked in amber after a week). Filter by client or template.

Three decisions, each with a note the client sees: Accept, Revise (ask for changes so they can resubmit) or Reject. The decision is written back to the client's own request and the client is notified. Auditors can read the inbox but not decide. The dashboard's Evidence Triage card shows the count waiting and the top three.

Patterns

Evidence Patterns (/msp/evidence/patterns) lists cases where two or more of your clients uploaded byte-identical evidence in the last 30 days, found by a nightly comparison of content hashes. Each signal shows the number of clients, a confidence, the hash and when it was first seen. Sometimes that is fine (a shared vendor template) and sometimes it is not (a policy copied from another client); either way Acknowledge records what you found and dismisses it, and the same match will not resurface for seven days.