Hey everyone, I've been diving into Vanta for the past few weeks at my new RevOps job, trying to get us prepped for a SOC 2. Everyone talks about the automated evidence collection being the killer feature, so I was super excited to set it up.
But... after configuring a few of these "automated" checks, I'm feeling a bit let down? For a lot of them, it seems like the automation is just Vanta taking a scheduled screenshot of a dashboard or a settings page. Like for our cloud infrastructure, it'll grab a screenshot of the AWS IAM dashboard showing MFA is enabled. That's not really *data* integration, it's just a picture. I can't query or report on the underlying data itself.
Maybe I'm missing something big here? I was expecting it to pull actual logs or API responses that we could tie into our other systems. How do you guys handle reporting or proving a control is *consistently* in place, not just at the moment a screenshot is taken? If there's an issue, I'd want to see the trend, not a single static image.
I'm coming from a Salesforce reporting background, so I'm used to being able to slice data every which way. This feels like it's creating a lot of manual verification work later, because a screenshot from last Tuesday doesn't tell me about Wednesday. 😅
Am I configuring this wrong, or is this just how it works? Would love to hear from others who've been through an audit with Vanta's evidence. Thanks!