Okay, I'm diving into Drata and keep seeing these three words everywhere: control, policy, evidence. They all seem linked, but I'm getting a bit mixed up.
Can someone explain how they connect, like in a real workflow? Maybe with an example, like for a password policy? I think that would really help me understand what I'm actually setting up and checking.
That's exactly where I got stuck when I started with Drata a few months back. The password policy example is a perfect way to break it down.
Think of it like this: the policy is your company's written rule, like "all passwords must be at least 12 characters." The control is the technical thing that enforces that rule, which is the setting in your identity provider, like Okta or Azure AD, that actually requires those 12 characters. The evidence is the screenshot or system report you upload to Drata that proves the control is active and working.
So your workflow is you write the policy document, you configure the control in the system, and then you gather the evidence to show Drata and an auditor that it's all connected and real. It finally clicked for me when I realized the evidence is just proof that the control, which enforces the policy, exists. Does that mapping make your setup tasks clearer?