Quick Reference Guide

Last updated: March 30, 2026

Document Types Summary

  • Default document: Provided by Mycroft for frameworks; can be deactivated but not edited or deleted.

  • Custom document: Created by your organization; can be deactivated or deleted.

Document Status Summary

  • Not started: Document exists but has no evidence artifacts.

  • Draft: Evidence artifacts added but not published. Drafts are not visible to auditors.

  • Published: Document is published and can satisfy linked controls. Document tests pass when you publish evidence. Published documents are visible to auditors.

  • Deactivated: Document is excluded from compliance metrics.

Evidence Artifact Types

  • File: Upload files (max 30MB per file). Supported file types: .csv, .doc, .docx, .jpg, .jpeg, .pdf, .png, .svg, .txt, .webp, .xls, and .xlsx (12 file types total).

  • URL: Add links with optional screenshot generation.

  • Document editor: Create formatted text content within Mycroft using the WYSIWYG editor.

Common Workflows

  • Create custom document: ComplianceDocumentsAdd document → fill name, description, owners → submit → add evidence → publish.

  • Add evidence: Open document → Evidence tab → choose artifact type (File/URL/Editor) → fill details → add.

  • Publish document: Open document → Evidence tab → ensure draft has artifacts → Publish → confirm.

  • Link to controls: Open document → Controls tab → Add controls → select controls → add.

  • Assign owners: Open document → double-click owners area or OptionsChange owner → select owners → confirm.

  • Bulk assign owners: ComplianceDocuments → select multiple documents → Assign owners → select owners → confirm.

  • Add a comment: Open document → Comments tab → type comment → submit.

  • Deactivate document: Open document → OptionsDeactivate document → enter reason → deactivate.

  • Delete custom document: Open custom document → OptionsDelete document → confirm.

  • Download evidence: Open document → Evidence tab → click artifact → download button.

  • Export all: ComplianceDocumentsMoreExport all → wait for email with ZIP download link.

Key Concepts

Evidence and documents

  • Evidence artifacts (files, URLs, text) live within documents.

  • Documents must be published to satisfy linked controls. Document tests pass when you publish evidence.

  • Document tests require your organization to upload evidence manually; evidence is not collected or generated automatically.

  • Published versions are fixed for audit purposes; drafts can be edited.

Publishing and versions

  • Publishing creates a fixed version for compliance.

  • Old published versions are preserved in version history.

  • You can edit published documents by creating new versions, editing the draft, and publishing again.

Owners and comments

  • Owners are assigned per document via Change owner (e.g. from Options or the owners area). Documents can have business owners and security owners; bulk assignment helps assign owners across multiple documents.

  • Comments are added in the Comments tab and do not affect document status (pass/fail is determined by evidence and publishing).

Effective dates

  • Set effective dates when adding or editing artifacts.

  • Backdate artifacts to reflect when evidence went into effect.

  • Effective dates help maintain accurate audit trails.