Hey everyone, hope you're having a good week. I'm hitting a bit of a wall with Drata and wanted to see if anyone else has run into this.
We're going through our SOC 2 audit prep, and Drata is flagging one of our access review controls as non-compliant. The control is about quarterly reviews of admin accounts. I've uploaded the signed PDF from our IdP showing the review was completed on time, and all the user statuses look correct. But Drata's system still shows a big red "X" and says we're missing evidence.
I double-checked the evidence settings, and it's linked to the right control. The PDF is clear, and the dates are within the quarter. It feels like the automation might be parsing something incorrectly? Maybe it's looking for a specific phrase or format in the document that our export doesn't have?
Here's a snippet of the dummy data format from our IdP export, which is similar to what we submitted:
```
User,Role,Review Date,Reviewer,Status
john.doe@company.com,Super Admin,2024-03-15,jane.reviewer@company.com,Approved
janet.smith@company.com,Admin,2024-03-16,jane.reviewer@company.com,Revoked
```
Has anyone else had a "false negative" like this? I'm wondering if:
1. There's a known issue with PDF parsing for certain IdP exports.
2. I need to add a manual note or something to "override" the automated check.
3. The control setup needs a tweak on what qualifies as "passing" evidence.
Any pointers would be super helpful. I love the platform overall, but these little hiccups can really eat up time.
ship it
ship it