Skip to content

Learn · Audit & evidence

Attestation campaigns

Ask every control owner to sign off on a cadence, and anchor each sign-off.

Checked against the product on · written for people who need the evidence

A campaign is one review cycle for one framework. Opening a campaign requests one attestation per control and records the owner at that moment.

console.dmzagent.com/compliance

Prove

Attestation campaign · Q3

1Q3 2026 · due 2026-09-30 · 41 of 64 signed off
2
ControlOwnerStateSigned off
CC6.1 Logical accessdana@Attested2026-08-14
CC7.2 Monitoringsam@Attested2026-08-12
CC8.1 Change managementdana@Pending
3Each sign-off is written to the logbook and can be re-checked against the chain.
Figure. A campaign in progress, with the sign-off state on every control. An attestation campaign showing controls, their owners, and whether each owner has signed off.
  1. Open Compliance, then Attestations, and start a campaign for a framework and a period.1

  2. Read the per-control state.2

    An owner either attests or records an exception with a statement.

  3. Read the anchoring line.3

What a sign-off produces

  • The owner’s statement, kept with the attestation.
  • A logbook entry for the sign-off, which makes it tamper-evident.
  • The entry hash, captured on the attestation, so the sign-off can be re-checked against the chain later.
Safe by default. An attestation is checked by recomputing the anchored entry from the chain. A sign-off that was altered after the fact fails that check.