Docs
How it works

Compliance - Gather evidence

Getting evidence attached to requirements: what counts as done, what's already covered without you chasing it, and what still needs a person to produce and approve it.

Get evidence attached to requirements. For each requirement you can see exactly what's expected of it and what's currently attached, so a gap is never a guess.

Typical workflow

See what's expected, and what's already there

Open a requirement to see what would satisfy it alongside the evidence currently linked to it, so you're never chasing something that's already covered.

Some evidence you don't have to chase at all

Connected sources report on their own

Once a source like the Microsoft 365 connection is set up, it reports things like MFA enforcement automatically — evidence that legitimately supports several Protect requirements without you having to go looking for it.

Other evidence has to be produced first

Some things can't be inferred from a connected source — they have to exist as a real document before they can count. An incident response plan only counts once it's been reviewed and formally approved; a draft sitting in Policies doesn't satisfy the requirement on its own.

Lex proposes linking existing evidence to the requirements it supports. You approve, adjust or reject each proposal — Lex never links evidence on its own.

On this page