Audit evidence

What a SOC 2 or ISO 27001 auditor accepts as access evidence

Tessera is not certified against either standard, and no tool makes a company compliant. What a tool can do is produce the artefacts an auditor tests access controls with, which is the part of the work that otherwise falls on somebody with a spreadsheet and a bad week.

The question behind every access control

Both frameworks work the same way underneath. The auditor is not checking that you have a policy. They are testing whether a control operated, throughout the review period, and they test it by sampling: pick a date, pick a system, and show me.

That is why the usual sources disappoint. The policy says access is reviewed quarterly. The ticket system says somebody asked. The server's own logs say a shared account did something. None of the three answers which person could reach production on the twelfth of March, who decided that, and what they did once they were there.

The four artefacts that answer it

Who had access, on a date you name

Grants and revocations are recorded as events when they happen, not merely reflected in the current state. Current state answers what is true today, which is the one question an auditor is not asking.

The approval, not the policy

A just-in-time request carries its reason, its decision and its approver into the log. The artefact is the specific grant rather than a document saying that approval is required. How requests and expiry work.

The session, not a summary

Commands, database queries and full replay of a named session. This is what turns "we log access" into something a sample can be drawn from. How recording works.

A copy the administrator cannot reach

Events are posted to your SIEM as they happen, so a copy lives outside the broker. An audit trail that exists only on the box whose administrators are being audited is the weakest form of the artefact, and reviewers know it. Delivery is best-effort and never blocks anybody's session, so the database stays the source of truth rather than being replaced by the stream.

The controls this usually lands against

Named because they are the ones auditors ask about most often in this area, not as a complete mapping. Your scope decides what applies, and anybody selling you a tidy one-to-one table is selling you a document you will have to defend.

Access removal, CC6.3, is where most of the pain is in practice, and it is the one an expiring grant answers almost by accident: access that ends on its own does not need a leaver process to catch it.

What we will not claim

We hold no certification, our own report does not exist, and a vendor questionnaire that requires one will fail on us today. The support commitment we do make is contractual rather than marketing: security updates for at least five years from the date a version is published, in the licence, for every edition including the free one. The longer argument is in the blog.

Questions people ask before they try it

Is Tessera SOC 2 or ISO 27001 certified?
No. If that is a hard requirement for your vendors today, we are not a fit yet and would rather say so here than in the third call.
Will running Tessera make us compliant?
No, and nothing else will either. Compliance is a property of your organisation, tested against your scope. A tool can produce the evidence for a handful of access controls, which is a real and tedious part of the work, and is not the whole of it.
What does an auditor actually ask for?
Almost always the same shape: pick a date in the review period, show who had access to a named system then, show who approved it, and show what they did. A policy document answers none of those.
Can we export it?
Yes. Auditors work in spreadsheets and PDFs, and evidence you cannot get out of a dashboard is a demo. On Ultimate the events are also posted to your SIEM as they happen, which puts a copy outside the broker; that delivery is best-effort, so it is a second copy rather than a replacement for the log.
How far back does it go?
As far as you tell it to. Retention is bounded by two settings, one for the event log and one for the recordings, and both keep everything by default. A seven-year event log next to ninety days of replays is a normal pairing.
Start freeWhat the audit log records