Turn a SOC 2 audit into an organized evidence package. Joy maps your policies, tickets, config exports, and access reviews against the Trust Services Criteria, showing for each control what's already on hand, what's still missing, and who owns the gap.
We have a [SOC 2 type] audit coming up, and our observation window is [window]. Here's the context: [context]. Organize our evidence against the Trust Services Criteria into an audit-ready index, showing for each control what evidence we already have in the Knowledge Center, what's still missing, and who owns each gap.
An illustrative example. Your output will reflect your own sources, data, and prompts.
I've organized your evidence against the Trust Services Criteria, drawing on the policies, tickets, config exports, and access reviews already in your Knowledge Center. Each control shows what's on hand against what's still missing, with an owner named on every gap so you know exactly who to chase before the window closes.
Here is your evidence organized by control. For each one, what is already in the Knowledge Center, where it stands, and who owns closing the gap.
| Control | Evidence on hand | Status | Owner / next step |
|---|---|---|---|
| CC1.4 — Background checks on new hires | Background-check policy; completed checks for the 9 people hired in the window | On hand | People Ops — complete |
| CC6.1 — Logical access controls | Access control policy; SSO and MFA enforcement config export from Okta | On hand | Security — complete |
| CC6.2 — Provisioning and deprovisioning | Onboarding tickets present; offboarding tickets for 2 of the 5 leavers not yet linked | Partial | IT Ops — attach the 3 missing offboarding tickets |
| CC6.3 — Quarterly access reviews | Q2 and Q3 user access reviews, signed off in the Knowledge Center | On hand | Security — complete |
| CC7.2 — Security monitoring and alerting | Monitoring runs, but the alert configuration export and a sample triaged alert are not gathered | Missing | Security — pull the alert config and one worked alert |
| CC7.3 — Incident response | Incident response plan; no incident occurred in the window, so a tabletop exercise record is needed in its place | Missing | Security — run and document a tabletop |
| CC8.1 — Change management | Change policy on hand; pull-request approval and deploy records exist in the tooling but are not exported as evidence | In progress | Engineering — export a sample of PR approvals and deploys |
| A1.2 — Backups and recovery | Backup policy; backup job config export on hand; last restore test predates the window | Partial | IT Ops — run an in-window restore test and log it |
Six of the eight controls have complete or partial evidence; the real work is the four gaps. Two of them, CC7.2 monitoring and CC7.3 incident response, are the ones an auditor tends to push on, and both sit with Security, so that is where I would start. The change-management exports (CC8.1) and the offboarding tickets (CC6.2) are quick to close once someone is assigned. Nothing here is fabricated evidence — each row reflects what is actually uploaded, so the missing rows are genuinely missing, not just unindexed.
Want me to draft the gap request note you can send each owner, or sequence the four gaps into a readiness timeline for the rest of the window?
SOC2 Evidence Collector takes the criteria you're audited against and whatever context you can give it, and organizes your evidence into an index mapped control by control. Joy, the JoySuite assistant, checks each Trust Services Criterion against what's in your Knowledge Center, marks the evidence on hand against what's still missing, and names an owner for every gap.
Tell Joy which SOC 2 report you're going for, the observation window, and the criteria in scope. Mention anything you already know is solid or missing. Rough is fine.
Ask for an evidence index mapped to the Trust Services Criteria, with each control marked on hand or missing and an owner on every gap. Joy fills in the standard controls and sensible owners if you don't spell them all out.
Get your evidence laid out control by control, with statuses and owners, and the gaps pulled into a clear read at the end. Check it against what's actually uploaded and how your controls really run.
Ask for a tweak, "move the change-management export to Engineering" or "add a row for vendor reviews," then copy the index into your GRC tool, shared drive, or the note you send each gap owner.
Save this ask as a custom command on the assistant your team already uses, so anyone can run it in one step.
Evidence is organized against the Trust Services Criteria the way an auditor asks for it, so the index lines up control by control with the request.
Each control is marked on hand, partial, or missing, so you see the coverage gap at a glance instead of digging for it across drives.
Every gap names who's responsible for closing it, so nothing sits unclaimed as the observation window and fieldwork approach.
The controls without evidence get called out with a read on which ones an auditor tends to push on, so you know what to close first.
Turn the open gaps into a short note you can send each owner with the evidence you need and by when.
Sequence the gaps into a working plan for the weeks before the observation window closes.
Start from last year's evidence set and mark what carries over, what needs refreshing, and what's newly in scope.
Run the same index at a point in time to check control design before you commit to a Type II window.
It organizes your evidence against the Trust Services Criteria into an audit-ready index. You give Joy the context and it maps each control to the policies, tickets, config exports, and access reviews in your Knowledge Center, marks what's on hand against what's missing, names a gap owner, and reads out the gaps to close first.
No. Joy organizes and indexes the evidence you've uploaded to your Knowledge Center, and can read from a connected system only where a connector actually supports it. It won't fabricate evidence or claim to auto-pull from tools it isn't connected to. A control shows as covered only when the evidence is really there.
Whichever ones you're audited against. The Security (Common Criteria) set is always in scope, and you can add Availability, Confidentiality, Processing Integrity, or Privacy. Tell Joy the criteria in scope and it maps your evidence to the relevant controls, from logical access to change management to incident response.
When your Knowledge Center holds the prior report's evidence, Joy uses it to tell what carries over and what's already in place from what needs refreshing for the new window, so you're not rebuilding the index from a blank criteria list.
Joy names a suggested owner on each gap, and you can reassign any of them in the same conversation, "move the change-management export to Engineering." Then copy the index into your GRC tool or the note you send each owner. Joy drafts and organizes; it doesn't send.
Join the waitlist and be first to try this workflow when JoySuite launches.