Hi everyone! I've been using Tugboat Logic for a few months now to help manage our SOC 2 compliance, and overall it's been a great experience for keeping things organized. I'm still finding my way around some of the more advanced features, though.
I've hit a specific task that I can't quite figure out, and I'm hoping someone here has walked this path before. I need to export *all* the evidence items attached to a specific control, but I only want the evidence that was uploaded or linked within a specific date range (let's say Q1 of this year). I know I can go into the control and see all the evidence listed, but that seems to be the entire history. I can't find a filter option for the evidence upload/modified date.
My goal is to get a packaged setβlike PDFs, screenshots, policy documentsβfor just that timeframe, ideally in a single zip file or a generated report, to share with an external auditor for a targeted review. I've poked around the Reports section and looked at the "Control Evidence Report," but it appears to generate everything up to the present moment.
Is there a way to do this that I'm missing? Maybe through a custom view or an export setting I haven't enabled? I'm comfortable with SQL and APIs if that's the route I need to take, but I wanted to check if there's a built-in method first before I start trying to pull data directly from the backend. Any pointers or workflows you use would be incredibly helpful!
Ah, the classic "I'd like a report that doesn't include everything" request. I'm not surprised you're struggling. The platforms are designed to show you the full, glorious history, not to let you surgically extract a slice of it. That would actually be useful for an audit, and we can't have that, can we?
You're right about the "Control Evidence Report" being a blunt instrument. It's built for the vendor's checkbox, not your specific auditor's request. In my experience, this kind of date-range filtering is often an afterthought, if it's a thought at all. You might be forced into a manual review, downloading everything from that control and then sorting by the "date modified" on your own filesystem. A deeply unsatisfying solution for a tool marketed on saving you time.
Have you tried reaching out to their support with this exact scenario? I'm curious what their prescribed "best practice" workaround will be. I'd bet good money it involves multiple clicks and exports into a spreadsheet first.
Just my 2 cents
You're right about the filter option feeling missing! It's a common snag. While there isn't a direct one-click filter for evidence date within a control, you can get close using the main Evidence Library.
Instead of going through the control's page, try this: go to the main Evidence Library tab. Use the filters there to select your date range for "Date Added" or "Last Modified." Then, in the same filter panel, look for the field to filter by "Linked Control." Select your specific control.
This should show you only the evidence items for that control that were added within your window. You can then select them all and use the "Export" button (usually a download icon) to get a zip file of just those items. It's a couple extra steps, but it should give you that clean, date-specific package you need for the auditor. Let me know if that works!
Oh, that's a solid workaround! I've used that same method and it does the job.
One thing to watch for: if you're using the "Last Modified" filter, just be aware that an internal reviewer's comment or status change on an older piece of evidence could bring it back into your date range. I always double-check the actual "date added" column in the export preview to be safe.
It would be great if they'd just port those library filters over to the control view directly 🤞
Let the machines do the grunt work