Compliance - Gather evidence
Getting evidence attached to requirements: what counts as done, what's already covered without you chasing it, and what still needs a person to produce and approve it.
Get evidence attached to requirements. For each requirement you can see exactly what's expected of it and what's currently attached, so a gap is never a guess.
Typical workflow
See what's expected, and what's already there
Open a requirement to see what would satisfy it alongside the evidence currently linked to it, so you're never chasing something that's already covered.
Some evidence you don't have to chase at all
Connected sources report on their own
Once a source like the Microsoft 365 connection is set up, it reports things like MFA enforcement automatically — evidence that legitimately supports several Protect requirements without you having to go looking for it.
Other evidence has to be produced first
Some things can't be inferred from a connected source — they have to exist as a real document before they can count. An incident response plan only counts once it's been reviewed and formally approved; a draft sitting in Policies doesn't satisfy the requirement on its own.
Lex proposes the links, you approve them
Lex proposes linking existing evidence to the requirements it supports. You approve, adjust or reject each proposal — Lex never links evidence on its own.
Compliance - Owned work
Turning a gap list into owned work: Lex proposes a task for each priority gap, you approve it, and reassign the owner on a live worklist once it's tracked.
Compliance - Score assessment
Scoring the assessment period: Lex proposes evidence-backed scores for you to approve, you rate everything else directly, and the two kinds of score stay distinguishable afterwards.