01
FIELDWORK EVIDENCE COLLECTION
Real evidence.
Zero busywork.
Your team reviews evidence instead of assembling it. Describe a control in plain English and Fieldwork’s agents log in, capture the proof, and keep it fresh between audits — including on the systems nobody ever integrated.
Book a demo
See the difference
Read–only access
never writes
Full provenance
on every capture
SSO & SCIM
scoped by unit
[ HERO VISUAL ]
Product dashboard showing the single “one platform” view. Compliance status + live security posture in one frame. Static image or 6-sec loop.
If your team can reach them with a log in, so can we
Cloud
Identity
Ticketing
HR
ERP
Internal tools
Vendor portals
Legacy & on-prem
02
THE PROBLEM
You spend more time chasing evidence than reading it
Hundreds of controls, four frameworks, staggered audits, and control owners in business units that don’t report to you. The proof lives in the systems nobody ever integrated: the regional ERP instance, the vendor portal, the acquired company’s stack, the long tail of applications that never got SSO.
ONE APPLICATION. ONE CONTROL. ONE QUARTER.
↓
STEP 01
Find the credential in the password manager and log in
manual
STEP 02
Hunt for the members page, which is somewhere different in every tool
manual
STEP 03
Capture the user list
manual
STEP 04
Confirm MFA and role for every user, one by one
manual
STEP 05
Crop it, label it, date it, file it in the right folder
manual
× every app
Every application holding evidence, not just the integrated ones.
× every quarter
The capture is only valid for the period it was taken in.
× every framework
Then again next cycle, for a different one, in a different format.
03
WHAT CHANGES
The evidence is there before the auditor asks
Not a faster way to chase evidence. A quarter where nobody chases it at all.
Where
Today
With Fieldwork
The ask
Requests fan out to control owners across the business.
→ Control owners stop receiving evidence requests entirely.
What arrives
Screenshots, cropped, undated, wrong period.
→ Every capture carries its source, screen, and timestamp
Drift
A control stops passing. Nobody finds out until testing.
→ Evidence goes stale and you hear the same day
Your team
Senior people spend the quarter assembling, not assessing.
→ Your team reads, works exceptions and signs off
Audit day
You reconstruct a period that already passed.
→ The auditor asks. It is already captured and dated
04
HOW IT WORKS
Four steps. One is yours.
No scripts, no engineering ticket, no waiting for a connector to be built. You describe the control the way you’d explain it to a new analyst.
STEP 01
Write the prompt
Plain language. Where to go, what to capture, and what it proves.
You · once
STEP 02
Agents capture it
They log in, navigate, and take the evidence. Source, screen and timestamp recorded on every run.
Fieldwork
STEP 03
It stays fresh
Captures refresh on your cadence, on demand or nightly, across every entity and region at once.
Fieldwork
STEP 04
It becomes a report
Captures chain into a document output your auditor can take as-is.
Fieldwork
A REAL PROMPT, IN FULL
USER ACCESS REVIEW · QUARTERLY
Go to settings → organization → members, screenshot it to capture that everyone has MFA
That is the entire configuration. It runs on demand or nightly, across every entity and region at once.
05
FRESHNESS
You hear it from us. Not your auditor.
Logins expire. Vendors move pages. Systems change. When a capture can’t be taken, Fieldwork surfaces it with the reason, the same day, instead of filing something wrong or going quiet.
Current
Captured this period
Taken on cadence, inside the window the auditor will test, with provenance attached.
Last run: today · Next: nightly
Aging
Approaching the edge
Still valid, but close to the end of its window. Flagged before it lapses, not after.
Last run: 26 days ago · Cadence: monthly
Blocked
Failed and explained
The credential expired, or the page moved. Named reason, named owner, same day.
Reason: login rejected · Owner: [named]
Nothing sits quietly out of date until someone external finds it
Choose the control you believe can’t be automated.
That’s what we’ll demo
06
COVERAGE
Coverage isn’t a list
A connector library automates the systems a vendor chose to integrate with, on the vendor’s timeline. Every system outside that list stays manual forever, and those are the ones holding your hardest evidence.
—
The acquired stack.
Still in scope, never integrated
—
The regional instance.
Same vendor, different everything
—
The tool built in 2014.
No API and no plans for one.
—
Every application that never got SSO.
Makes up most of the inventory.
[ VISUAL ]
Two columns: “what a connector library covers” vs “what your evidence actually lives in.” Show the long tail as the visibly bigger side. This is the whole argument in one image, so it’s worth the design time.
07
CONTROLS & OVERSIGHT
The agents collect. Your team signs off.
Nothing reaches the audit package without a person accepting it. The automation is itself auditable.
Full provenance on every capture
Source, account, screen, timestamp and run, attached to the evidence and carried into the report.
A named reviewer, every time
A person on your team accepts each capture into the package. Sign-off stays where accountability already sits.
Read-only, scoped access
Agents capture. They don’t change configuration, they don’t write, and their permissions are scoped per control, framework or business unit.
Every agent action logged
A complete record of what ran, when, and what it touched. When your auditor asks how the evidence was produced, there’s an answer.
08
REQUIREMENTS
The details procurement will ask for.
Answered here so nobody has to book a call to find out.
Frameworks
SOC 2, ISO 27001, SOX ITGCs, PCI DSS, HIPAA, ISO 42001, NIST CSF, and your own internal control set.
Access
SSO and SCIM. Permissions scoped by control, framework, or business unit.
Structure
Separate tenants per entity, with one view across all of them.
Data
Residency and retention set to your policy. Encrypted in transit and at rest.
09
EVALUATION
Evaluate it on your hardest controls, not our demo data
Pick three to five manual controls, ideally on the systems without an API. We build and run the workflows in your environment, then you benchmark the output against the evidence your auditor accepted last cycle.
Scope a proof of concept
YOU
Name the controls. Three to five. The uglier the better.
WE
Build the workflows in your environment.
WE
Run them for a week with the full cost breakdown.
YOU
Benchmark against what your auditor already accepted.
10
QUESTIONS
The ones security review will ask
We already have a GRC platform. Does this replace it?
–
It doesn’t have to. Your GRC platform holds the control framework and the workflow; Fieldwork feeds it the evidence it can’t collect on its own. Most enterprise deployments start alongside an existing platform, aimed squarely at the manual controls that platform was never going to reach. If you’d rather consolidate onto Oneleet entirely, that’s a separate and longer conversation, and not the one this page is asking for.
How is this different from a connector library?
+
You’re logging into our systems. How is that controlled?
+
What happens when a vendor redesigns their UI?
+
Will our auditor accept evidence collected by an agent?
+
What about systems behind MFA?
+
11
BRING US YOUR WORST CONTROL
Give the quarter back to the people you hired.
You know the control. The one that takes four hours and three people, every quarter, and teaches you nothing you didn’t already know. Start there, and give those people something better to do.
Book a demo
Scope a proof of concept