Agent Registry·Assessment·Evidence Reviewer
Assessmentclaude-sonnet-4-6Open source · Free to copy

Evidence Reviewer

Grades every piece of evidence before your auditor sees it. Flags red flags.

Reviews screenshots, log excerpts, policy clips, and configuration exports against specific assessment objectives. Returns an adequacy verdict (Sufficient / Insufficient / Missing) with precise assessor-language gaps and what additional evidence is needed.

Tools:readglob
Frameworks:CMMC L2SOC 2FedRAMPISO 27001HIPAA
Use case 1
You collected evidence and want to know if it will hold up before submitting to the assessor
Per-AO adequacy verdict (Sufficient / Insufficient / Missing) with assessor-language gaps so you can fix issues before submission
Use case 2
Client sends you a folder of screenshots and configs and you need to know what is usable
Indexed map of each file to the specific assessment objectives it addresses, with quality scores and concrete follow-up requests
Use case 3
Pre-assessment review of a control family and you need to surface the weakest evidence first
Ranked list of weak evidence items by audit-failure likelihood, with specific additions that would make each defensible

Try a sample prompt:

evidence-reviewer · live demo · gemini-flash
◇ Curated sample output (real format)

Evidence Review · Q1 Access Review Artifact

File: access-review-Q1-2026.png (320 KB screenshot)

Mapped to: AC.L2-3.1.5 [d], AC.L2-3.1.5 [e]


AC.L2-3.1.5 [d] · "The need to review privileged accounts is defined"

Verdict: SUFFICIENT

What the evidence shows: Screenshot displays a quarterly review cadence in your access governance tool with the next-review-by date populated (2026-07-01). 11 privileged accounts listed, each with reviewer assignment.

Red flags: None for this AO.

AC.L2-3.1.5 [e] · "Privileged accounts are reviewed at the defined frequency"

Verdict: INSUFFICIENT

What the evidence shows: The screenshot is a snapshot of the review TOOL — not evidence the review actually happened.

What is missing:

1. Reviewer attestation (sign-off or approval workflow audit log)
2. Timestamp of completion (currently shows "pending" status for 4 of 11 accounts)
3. Decisions made (which accounts confirmed, which removed, which had access reduced)
4. Evidence of follow-up actions where decisions required removal

Red flags an assessor would call out:

- "Snapshot of a calendar event is not evidence of execution. Show me the completed review."

- "If 4 accounts are still pending review for Q1 (a quarter that closed in March), that itself is a finding under [b]."

What would make this airtight:

1. Export of completed review report from the governance tool (CSV or PDF) showing reviewer name, decision, timestamp per account
2. Ticket/change record for any account that had access modified
3. Sign-off from the system owner attesting to completion
4. If pending accounts are intentional (e.g., escalations), an exception register entry

Suggested follow-up artifact request:

"Please provide the Q1 2026 access review COMPLETION REPORT (not the tool screenshot) showing per-account decisions, reviewer names, and completion timestamps. If any accounts remain pending past quarter-close, please also provide the exception justification."


Coverage Summary for this Evidence Item

Assessment ObjectiveVerdictAction
AC.L2-3.1.5 [a] · Privileged accounts identifiedNOT ADDRESSEDNeed separate artifact
AC.L2-3.1.5 [b] · Need-to-know basisNOT ADDRESSEDNeed separate artifact
AC.L2-3.1.5 [c] · Access restricted to authorized usersNOT ADDRESSEDNeed separate artifact
AC.L2-3.1.5 [d] · Review frequency definedSUFFICIENTKeep on file
AC.L2-3.1.5 [e] · Reviews occur at frequencyINSUFFICIENTRequest completion report

Conformity status for AC.L2-3.1.5: PARTIAL — must collect completion report before submission.

Cmd+Enter to send