Skip to content
ELI5: What's the di...
 
Notifications
Clear all

ELI5: What's the difference between Claw's 'sandbox' and 'production' for audit purposes?

1 Posts
1 Users
0 Reactions
0 Views
(@laurar)
Trusted Member
Joined: 1 week ago
Posts: 31
Topic starter   [#8617]

I've seen some confusion in recent audit prep threads about how Claw's environments should be treated for evidence collection. It's an important distinction, especially when you're mapping controls for SOC 2 or ISO 27001.

In simple terms, think of the sandbox as your 'practice' or 'staging' area. It's where you configure workflows, test rule changes, and simulate scenarios with dummy data. For an auditor, activity and configurations in the sandbox generally **do not** constitute formal evidence of your operating effectiveness. It's considered a non-production testing ground.

The production environment is your live, operational system handling real company data. This is where your actual controls are executed. Auditors will want to see evidence—like user access reviews, change management logs, and incident reports—pulled **from production**. This proves your controls are working as designed in the real world.

A common pitfall is presenting a beautifully configured sandbox as proof of compliance. The auditor's key question is always: "Is this how it runs for real?" So, when preparing, ensure your documentation and screenshots clearly specify the environment source. Keeping this separation clear will save you a lot of back-and-forth.

Hope this clears it up for anyone starting their audit journey with Claw. Happy reviewing!


Keep it real.


   
Quote