Add Evidence to Documents

Last updated: March 30, 2026

Overview

Evidence artifacts are the files, URLs, or text content you add to documents. Each document can contain one or multiple evidence artifacts. The document description includes guidance about what kinds of evidence might be applicable. Some documents offer templates to help you get started. Document tests require your organization to upload evidence manually; evidence is not collected or generated automatically.

When to Use

  • You need to add evidence to a document to satisfy linked controls.

  • You have files, URLs, or text content that demonstrates compliance (e.g., diagrams, reports, records, procedures, or compliance certificates).

  • You want to backdate evidence to reflect when it went into effect.

Artifact Types

Documents support three types of evidence artifacts:

File

  • Upload files from your computer (PDF, images, Word documents, etc.).

  • Maximum file size: 30MB per file.

  • Supported file types: .csv, .doc, .docx, .jpg, .jpeg, .pdf, .png, .svg, .txt, .webp, .xls, and .xlsx (12 file types total).

URL

  • Add links to external resources or web pages.

  • Option to generate a screenshot from the URL automatically.

  • URLs should reference publicly accessible web pages, accessible without authentication so that auditors can verify evidence directly.

  • Useful for linking to teammate CVs, trust pages, public certifications & certificates, and status & incident pages.

Document Editor

  • WYSIWYG (What You See Is What You Get) editor to create and format document content within Mycroft.

  • Create formatted text documents directly in the product.

  • Supports rich text formatting: bold, italic, headings, lists, links, and more.

  • Content is saved as an artifact within the document.

How to Add Evidence to a Document

To add evidence artifacts to a document:

  1. Navigate to ComplianceDocuments and open the document (click the document name). You land on the Evidence tab automatically.

  2. If the document has no evidence yet, you'll see an upload area with three options: File upload, Add URL, and Document editor.

  3. Choose the artifact type you want to add:

    • File upload: Click File upload, select a file from your computer, then fill in the artifact details (title, description, effective date).

    • Add URL: Click Add URL, enter the URL, optionally enable screenshot generation, then fill in the artifact details (title, description, effective date).

    • Document editor: Click Document editor, create your content in the editor, then save.

  4. For each artifact, you can edit its details:

    • Title / Filename (required): A name for the artifact. Use a simple name that helps auditors identify the file.

    • Description (optional): Additional context about the artifact.

    • Effective date: The date this evidence went into effect. You can backdate artifacts to when they went into effect.

  5. Click Add or Save to complete.

Evidence artifacts appear in the draft section until the document is published. After publishing, artifacts move to the published version.

Editing Artifact Details

To edit an existing artifact:

  1. Navigate to the document's Evidence tab.

  2. Find the artifact in the draft or published section.

  3. Click the dropdown menu icon for the artifact and select Edit details.

  4. Update the title, description, or effective date as needed.

  5. Click Save to confirm changes.

Note: Editing artifacts is only possible if the Document is in a draft state. To edit artifacts on a published Document, click the Create new version button to create a new draft. You must publish the document again for changes to take effect.

Setting Effective Date

The effective date indicates when evidence went into effect. You can backdate artifacts to reflect historical dates:

  1. When adding or editing an artifact, use the Effective date field.

  2. Click the calendar icon to open the date picker.

  3. Select the date when the evidence went into effect (you can select dates in the past).

  4. The effective date helps maintain accurate audit trails for compliance.

Important: Backdating artifacts to when they went into effect is useful when adding evidence that was created or went into effect before it was uploaded to Mycroft.

File Upload Format and Size Limits

  • Maximum file size: 30MB per file.

  • Supported file types: .csv, .doc, .docx, .jpg, .jpeg, .pdf, .png, .svg, .txt, .webp, .xls, and .xlsx (12 file types total).

  • Files are stored securely and can be downloaded for audit purposes.

URL Links

URL artifacts allow you to link to external resources:

  • Enter the full URL (https:// or http://).

  • Optionally enable screenshot generation to capture a visual record.

  • URLs should reference publicly accessible web pages, accessible without authentication so that auditors can verify evidence directly.

  • Useful for linking to teammate CVs, trust pages, public certifications & certificates, and status & incident pages.

Screenshot Best Practices

When adding URLs as evidence:

  • Enable Capture a screenshot to automatically generate a visual record of the web page.

  • Screenshots are useful for documenting the state of external systems or dashboards at a specific point in time.

  • Screenshots are generated automatically when you add a URL with the screenshot option enabled.

Document Editor

The Document editor is a WYSIWYG (What You See Is What You Get) editor within Mycroft:

  • Create formatted text documents directly in the product.

  • Supports rich text formatting: bold, italic, headings, lists, links, and more.

  • Content is saved as an artifact within the document.

  • You can edit document editor artifacts later to update content.

Note: Document editor content is stored within Mycroft and does not require external file hosting. Text inputs using the Document Editor are one of the supported evidence artifact types for documents.