# Audit week: SOC 2 evidence from a monthly checkup

> The auditor's evidence request lands on Tuesday. A SOC 2 readiness checkup has been collecting the evidence monthly and finding the gaps first.

Source: https://triagic.com/use-cases/audit-week

## The situation [#the-situation]

Tuesday, 09:14. The SOC 2 Type II auditor sends the evidence request: access reviews, off-boarding records, change-management approvals. Due Friday. Last year this cost us three weeks: 214 screenshots, a spreadsheet called `evidence-final-v3.xlsx`, and a `#compliance` channel full of "who owns CC6.2?".

This year the SOC 2 readiness checkup has been running on the first of every month at 07:00. It walks the Trust Services common criteria against every connected system and our own ticket history, records evidence per control, and keeps its findings in a ledger between runs.

## What Triagic looked at [#what-triagic-looked-at]

The checkup is a read-only procedure. This run touched:

* **Postgres**: `pg_roles` for superusers and `rolbypassrls`, `information_schema.role_table_grants` for anything granted to `PUBLIC`, and `pg_stat_activity` to see who is actually connecting as whom.
* **GitHub**: organization members and their roles, outside collaborators on private repositories, deploy keys, and the review state of every merge to the default branch in the last 90 days.
* **Our own ticket history**: incident tickets from the last quarter, which is the evidence for CC7 (how we detect and respond) that no other system holds.

Every call is listed on the run page with its arguments. Nothing was written anywhere.

## What it found [#what-it-found]

Two findings would not survive an evidence request, and one was fixable in under an hour.

**critical: Production Postgres superuser is a shared credential.** Evidence: `pg_stat_activity` showed six distinct `client_addr` values connected as `postgres` in the sampled hour. A shared superuser leaves CC6.1 (logical access over protected information assets) with no attributable actor, since no action can be traced to a person.

**high: No de-provisioning record for three departed users.** Evidence: three GitHub members whose last commit was more than 120 days old, still holding write on two private repositories, with no off-boarding ticket that names them. CC6.3 (access removed on least privilege) regressed since the previous run, and the ledger says so: the finding carries the same key as last month's, with a new "still open" mark.

**medium: Ticket retention is unbounded.** Resolved tickets older than the retention policy were still present. Fixable in under an hour with the retention job that already exists.

We asked the follow-up thread on the run page: &#x2A;Which of these would an auditor flag first if we do nothing?* The answer ranked CC6.1 first, for the superuser with no attributable actor; CC6.3 second, since it's the same gap regressing for a second month; and flagged retention as the quickest to close, at under an hour.

## What changed [#what-changed]

Friday, 16:20. The reply to the auditor has one attachment per control this run could assess, evidence and gaps alike, straight out of the run reports. The shared credential is replaced by per-person roles; the three departed users are removed and the off-boarding ticket is linked from the finding. Next month's run will either close those findings or reopen them under the same key.

Audit prep stopped being three weeks of screenshots. It is a checkup that runs monthly and a reply we send on Friday.

The checkup is in the [open checkup library](/checkups/soc2-readiness). Point it at [Postgres](/integrations/postgres) and [GitHub](/integrations/github), or at whatever you run, and it reads what it can reach.
