Getting Started with Documents

Last updated: March 30, 2026

Overview

Documents are evidence artifacts that help validate your controls. Documents can contain files, URLs, or text content created within Mycroft. Each document can be linked to one or more controls to demonstrate compliance. Documents are perfect for manual documentation requirements like diagrams, reports, records, procedures, or compliance certificates. Documents are either default (provided by Mycroft for specific frameworks) or custom (created by your organization).

Default vs Custom Documents

  • Default documents are provided by Mycroft for specific frameworks (e.g. SOC 2 Type 2, ISO 27001). They cannot be deleted. You can deactivate them if they do not apply to your organization.

  • Custom documents are created by your organization. You can deactivate or delete them.

Document Status

Documents have different statuses:

  • Not started: The document exists but has no evidence artifacts yet.

  • Draft: Evidence artifacts have been added but the document has not been published. Drafts are not visible to auditors.

  • Published: The document has been published and can satisfy linked controls. Published documents create a version that is visible to auditors.

  • Deactivated: The document has been deactivated and no longer affects the status of your controls.

Key Concepts

  • Document tests: These tests check for Documents to contain published evidence. Documents require your organization to upload evidence manually; evidence is not collected or generated automatically.

  • Evidence artifacts: Uploaded files, linked URLs, or text content created with the Document Editor. These are the actual evidence items. A document can contain one or more artifacts of any type.

  • Publishing: Makes a document version available for auditors. Documents pass when you publish evidence. Publishing replaces any previously published version.

  • Version history: Published versions are preserved for audit purposes. You can view all previously published versions in the version history.