The situation
Tuesday, 09:14. The SOC 2 Type II auditor sends the evidence request: access reviews, off-boarding records, change-management approvals. Due Friday. Last year this cost us three weeks: 214 screenshots, a spreadsheet called evidence-final-v3.xlsx, and a #compliance channel full of "who owns CC6.2?".
This year the SOC 2 readiness checkup has been running on the first of every month at 07:00. It walks the Trust Services common criteria against every connected system and our own ticket history, records evidence per control, and keeps its findings in a ledger between runs.
What Triagic looked at
The checkup is a read-only procedure. This run touched:
- Postgres:
pg_roles for superusers and rolbypassrls, information_schema.role_table_grants for anything granted to PUBLIC, and pg_stat_activity to see who is actually connecting as whom.
- GitHub: organization members and their roles, outside collaborators on private repositories, deploy keys, and the review state of every merge to the default branch in the last 90 days.
- Our own ticket history: incident tickets from the last quarter, which is the evidence for CC7 (how we detect and respond) that no other system holds.
Every call is listed on the run page with its arguments. Nothing was written anywhere.
What it found
Two findings would not survive an evidence request, and one was fixable in under an hour.
critical: Production Postgres superuser is a shared credential. Evidence: pg_stat_activity showed six distinct client_addr values connected as postgres in the sampled hour. A shared superuser leaves CC6.1 (logical access over protected information assets) with no attributable actor, since no action can be traced to a person.
high: No de-provisioning record for three departed users. Evidence: three GitHub members whose last commit was more than 120 days old, still holding write on two private repositories, with no off-boarding ticket that names them. CC6.3 (access removed on least privilege) regressed since the previous run, and the ledger says so: the finding carries the same key as last month's, with a new "still open" mark.
medium: Ticket retention is unbounded. Resolved tickets older than the retention policy were still present. Fixable in under an hour with the retention job that already exists.
We asked the follow-up thread on the run page: Which of these would an auditor flag first if we do nothing? The answer ranked CC6.1 first, for the superuser with no attributable actor; CC6.3 second, since it's the same gap regressing for a second month; and flagged retention as the quickest to close, at under an hour.
What changed
Friday, 16:20. The reply to the auditor has one attachment per control this run could assess, evidence and gaps alike, straight out of the run reports. The shared credential is replaced by per-person roles; the three departed users are removed and the off-boarding ticket is linked from the finding. Next month's run will either close those findings or reopen them under the same key.
Audit prep stopped being three weeks of screenshots. It is a checkup that runs monthly and a reply we send on Friday.
The checkup is in the open checkup library. Point it at Postgres and GitHub, or at whatever you run, and it reads what it can reach.