Artifacts · 04

Evidence Pack

The Evidence Pack is the audit trail behind a root-cause report: every query run, every data source touched, timestamps, and a content hash so the bundle can be shown to be unaltered. It is the answer to "how do you know?"

Who it's for: Compliance, internal audit, regulators, InfoSec, and sceptical SRE leads.

Contents

What does the Evidence Pack contain?

This is what wins the compliance conversation. When an auditor asks how a conclusion was reached, this is the answer, and no chat-first tool produces it.

01 Every query executed, with parameters and timestamps
02 Every data source touched and the access used
03 Retrieved evidence, log lines, traces, metrics, change records, indexed to report claims
04 Content hash of the bundle for tamper-evidence
FAQ

Evidence Pack, questions.

What is an evidence pack in incident investigation?

An evidence pack is the complete, hashed record of how a root-cause conclusion was reached: queries, sources, timestamps and the retrieved evidence, indexed to each claim in the report. It lets an auditor, regulator or customer verify the RCA rather than trust it.

How do you evidence an RCA for auditors?

Link every claim in the report to a specific artifact, a log line, trace, metric window or change record, and package the retrieval trail with timestamps and a content hash. Onepane produces this automatically for every accepted RCA.

Send us your last 90 days of Sev1s.We'll show you what we would have found.

Not a demo. A replay on your own incidents, scored against the RCA a human actually wrote. Two weeks, no cost.