01

FIELDWORK EVIDENCE COLLECTION

Real evidence.
Zero busywork.

Your team reviews evidence instead of assembling it. Describe a control in plain English and Fieldwork’s agents log in, capture the proof, and keep it fresh between audits — including on the systems nobody ever integrated.

Book a demo

See the difference

Read–only access

never writes

Full provenance

on every capture

SSO & SCIM

scoped by unit

[ HERO VISUAL ]

Product dashboard showing the single “one platform” view. Compliance status + live security posture in one frame. Static image or 6-sec loop.

If your team can reach them with a log in, so can we

Cloud

Identity

Ticketing

HR

ERP

Internal tools

Vendor portals

Legacy & on-prem

02

THE PROBLEM

You spend more time chasing evidence than reading it

Hundreds of controls, four frameworks, staggered audits, and control owners in business units that don’t report to you. The proof lives in the systems nobody ever integrated: the regional ERP instance, the vendor portal, the acquired company’s stack, the long tail of applications that never got SSO.

ONE APPLICATION. ONE CONTROL. ONE QUARTER.

↓

STEP 01

Find the credential in the password manager and log in

manual

STEP 02

Hunt for the members page, which is somewhere different in every tool

manual

STEP 03

Capture the user list

manual

STEP 04

Confirm MFA and role for every user, one by one

manual

STEP 05

Crop it, label it, date it, file it in the right folder

manual

× every app

Every application holding evidence, not just the integrated ones.

× every quarter

The capture is only valid for the period it was taken in.

× every framework

Then again next cycle, for a different one, in a different format.

03

WHAT CHANGES

The evidence is there before the auditor asks

Not a faster way to chase evidence. A quarter where nobody chases it at all.

Where

Today

With Fieldwork

The ask

Requests fan out to control owners across the business.

→ Control owners stop receiving evidence requests entirely.

What arrives

Screenshots, cropped, undated, wrong period.

→ Every capture carries its source, screen, and timestamp

Drift

A control stops passing. Nobody finds out until testing.

→ Evidence goes stale and you hear the same day

Your team

Senior people spend the quarter assembling, not assessing.

→ Your team reads, works exceptions and signs off

Audit day

You reconstruct a period that already passed.

→ The auditor asks. It is already captured and dated

04

HOW IT WORKS

Four steps. One is yours.

No scripts, no engineering ticket, no waiting for a connector to be built. You describe the control the way you’d explain it to a new analyst.

STEP 01

Write the prompt

Plain language. Where to go, what to capture, and what it proves.

You · once

STEP 02

Agents capture it

They log in, navigate, and take the evidence. Source, screen and timestamp recorded on every run.

Fieldwork

STEP 03

It stays fresh

Captures refresh on your cadence, on demand or nightly, across every entity and region at once.

Fieldwork

STEP 04

It becomes a report

Captures chain into a document output your auditor can take as-is.

Fieldwork

A REAL PROMPT, IN FULL

USER ACCESS REVIEW · QUARTERLY

Go to settings → organization → members, screenshot it to capture that everyone has MFA

That is the entire configuration. It runs on demand or nightly, across every entity and region at once.

05

FRESHNESS

You hear it from us. Not your auditor.

Logins expire. Vendors move pages. Systems change. When a capture can’t be taken, Fieldwork surfaces it with the reason, the same day, instead of filing something wrong or going quiet.

Current

Captured this period

Taken on cadence, inside the window the auditor will test, with provenance attached.

Last run: today · Next: nightly

Aging

Approaching the edge

Still valid, but close to the end of its window. Flagged before it lapses, not after.

Last run: 26 days ago · Cadence: monthly

Blocked

Failed and explained

The credential expired, or the page moved. Named reason, named owner, same day.

Reason: login rejected · Owner: [named]

Nothing sits quietly out of date until someone external finds it

Choose the control you believe can’t be automated.

That’s what we’ll demo

06

COVERAGE

Coverage isn’t a list

A connector library automates the systems a vendor chose to integrate with, on the vendor’s timeline. Every system outside that list stays manual forever, and those are the ones holding your hardest evidence.

—

The acquired stack.

Still in scope, never integrated

—

The regional instance.

Same vendor, different everything

—

The tool built in 2014.

No API and no plans for one.

—

Every application that never got SSO.

Makes up most of the inventory.

[ VISUAL ]

Two columns: “what a connector library covers” vs “what your evidence actually lives in.” Show the long tail as the visibly bigger side. This is the whole argument in one image, so it’s worth the design time.

07

CONTROLS & OVERSIGHT

The agents collect. Your team signs off.

Nothing reaches the audit package without a person accepting it. The automation is itself auditable.

Full provenance on every capture

Source, account, screen, timestamp and run, attached to the evidence and carried into the report.

A named reviewer, every time

A person on your team accepts each capture into the package. Sign-off stays where accountability already sits.

Read-only, scoped access

Agents capture. They don’t change configuration, they don’t write, and their permissions are scoped per control, framework or business unit.

Every agent action logged

A complete record of what ran, when, and what it touched. When your auditor asks how the evidence was produced, there’s an answer.

08

REQUIREMENTS

The details procurement will ask for.

Answered here so nobody has to book a call to find out.

Frameworks

SOC 2, ISO 27001, SOX ITGCs, PCI DSS, HIPAA, ISO 42001, NIST CSF, and your own internal control set.

Access

SSO and SCIM. Permissions scoped by control, framework, or business unit.

Structure

Separate tenants per entity, with one view across all of them.

Data

Residency and retention set to your policy. Encrypted in transit and at rest.

09

EVALUATION

Evaluate it on your hardest controls, not our demo data

Pick three to five manual controls, ideally on the systems without an API. We build and run the workflows in your environment, then you benchmark the output against the evidence your auditor accepted last cycle.

Scope a proof of concept

YOU

Name the controls. Three to five. The uglier the better.

WE

Build the workflows in your environment.

WE

Run them for a week with the full cost breakdown.

YOU

Benchmark against what your auditor already accepted.

10

QUESTIONS

The ones security review will ask

We already have a GRC platform. Does this replace it?

–

It doesn’t have to. Your GRC platform holds the control framework and the workflow; Fieldwork feeds it the evidence it can’t collect on its own. Most enterprise deployments start alongside an existing platform, aimed squarely at the manual controls that platform was never going to reach. If you’d rather consolidate onto Oneleet entirely, that’s a separate and longer conversation, and not the one this page is asking for.

How is this different from a connector library?

+

You’re logging into our systems. How is that controlled?

+

What happens when a vendor redesigns their UI?

+

Will our auditor accept evidence collected by an agent?

+

What about systems behind MFA?

+

11

BRING US YOUR WORST CONTROL

Give the quarter back to the people you hired.

You know the control. The one that takes four hours and three people, every quarter, and teaches you nothing you didn’t already know. Start there, and give those people something better to do.

Book a demo

Scope a proof of concept

Oneleet

Compliance beyond the checkbox

Product

Platform

Pentest

Pricing

Trust page

Frameworks

SOC 2

ISO 27001

HIPAA

GDPR

Company

Blog

Careers

Docs

Status

© 2026 Oneleet Inc. All rights reserved.

Privacy · Terms · G2 4.9★ · YC