Quick Reference Guide
Last updated: March 30, 2026
Document Types Summary
Default document: Provided by Mycroft for frameworks; can be deactivated but not edited or deleted.
Custom document: Created by your organization; can be deactivated or deleted.
Document Status Summary
Not started: Document exists but has no evidence artifacts.
Draft: Evidence artifacts added but not published. Drafts are not visible to auditors.
Published: Document is published and can satisfy linked controls. Document tests pass when you publish evidence. Published documents are visible to auditors.
Deactivated: Document is excluded from compliance metrics.
Evidence Artifact Types
File: Upload files (max 30MB per file). Supported file types: .csv, .doc, .docx, .jpg, .jpeg, .pdf, .png, .svg, .txt, .webp, .xls, and .xlsx (12 file types total).
URL: Add links with optional screenshot generation.
Document editor: Create formatted text content within Mycroft using the WYSIWYG editor.
Common Workflows
Create custom document: Compliance → Documents → Add document → fill name, description, owners → submit → add evidence → publish.
Add evidence: Open document → Evidence tab → choose artifact type (File/URL/Editor) → fill details → add.
Publish document: Open document → Evidence tab → ensure draft has artifacts → Publish → confirm.
Link to controls: Open document → Controls tab → Add controls → select controls → add.
Assign owners: Open document → double-click owners area or Options → Change owner → select owners → confirm.
Bulk assign owners: Compliance → Documents → select multiple documents → Assign owners → select owners → confirm.
Add a comment: Open document → Comments tab → type comment → submit.
Deactivate document: Open document → Options → Deactivate document → enter reason → deactivate.
Delete custom document: Open custom document → Options → Delete document → confirm.
Download evidence: Open document → Evidence tab → click artifact → download button.
Export all: Compliance → Documents → More → Export all → wait for email with ZIP download link.
Key Concepts
Evidence and documents
Evidence artifacts (files, URLs, text) live within documents.
Documents must be published to satisfy linked controls. Document tests pass when you publish evidence.
Document tests require your organization to upload evidence manually; evidence is not collected or generated automatically.
Published versions are fixed for audit purposes; drafts can be edited.
Publishing and versions
Publishing creates a fixed version for compliance.
Old published versions are preserved in version history.
You can edit published documents by creating new versions, editing the draft, and publishing again.
Owners and comments
Owners are assigned per document via Change owner (e.g. from Options or the owners area). Documents can have business owners and security owners; bulk assignment helps assign owners across multiple documents.
Comments are added in the Comments tab and do not affect document status (pass/fail is determined by evidence and publishing).
Effective dates
Set effective dates when adding or editing artifacts.
Backdate artifacts to reflect when evidence went into effect.
Effective dates help maintain accurate audit trails.