Compliance
What Drata Can (and Can't) Automate for SOC 2 Evidence
Drata automates ~80% of SOC 2 evidence over API. See the 20% it can't touch — app screenshots, access reviews, attestations — and how to cover it.

The fastest way to think about SOC 2 evidence is to separate the two halves of the work. About 80% of it can be pulled through API integrations, the infrastructure and identity configuration that platforms like Drata monitor automatically. The other 20% lives behind your application's UI and in your team's operations: access-control screenshots, RBAC tests, change-approval workflows, and the quarterly attestations only a person can answer.
Drata is excellent at the first half. As a dashboard, for the second half it can only flag what's missing and wait for you to collect it, which costs most teams 40 to 60 hours per audit. Screenata closes that gap with Vera, an agent who does the work instead of adding a longer checklist. She scans the same infrastructure Drata reads, captures the application screenshots Drata can't, chases the attestations in Slack, and files every artifact signed and traced back to a control.
So you have two paths: bolt Vera onto Drata to cover everything the dashboard leaves manual, or run Screenata standalone as an alternative to the Drata-plus-consultant stack. This guide covers both.
Does Drata Automate SOC 2?
Drata automates roughly 80% of SOC 2 evidence, pulling it through API integrations with your cloud, identity, and HR systems (AWS, GCP, Azure, Okta, Google Workspace, and more). What it can't reach is the application-level evidence auditors still ask for, including screenshots of access controls, RBAC verification, and UI workflow documentation, plus the periodic attestations a dashboard can only put on a list. That remaining ~20% is where teams lose 40 to 60 hours per audit, or hand the work to an agent.
What Drata Automates (And What It Can't)
What Drata automates well:
- AWS, GCP, Azure infrastructure configuration
- Identity provider logs (Okta, Google Workspace, Azure AD)
- MDM and endpoint security status
- Background checks and security-training completion
- Vendor risk assessments and policy acknowledgments
What Drata can't do, because it tracks status rather than doing the work:
- Capture screenshots of application-level access controls
- Document UI-based workflows and custom application tests
- Verify role-based access (RBAC) inside your product
- Chase the access reviews and exception sign-offs only a person can give
This is the 20% gap. For a typical audit, teams spend 40 to 60 hours screenshotting, organizing, writing narratives, and uploading the evidence that a dashboard flags but never produces on its own.
Two ways to close it:
- Keep Drata and add Vera for the gap. Drata handles infrastructure; Vera captures the application screenshots, chases attestations, and exports signed packs back into your Drata workspace.
- Replace the stack with Screenata. Vera automates ~70% of evidence through her own API scans (the same sources Drata reads) and covers the application 20%, so one agent handles both halves and writes your policies too.
Does Vanta Automate More of SOC 2 Than Drata?
No. Drata is not unusual here. Vanta, Secureframe, and every other API-first monitoring platform share the identical boundary: they read your cloud, identity provider, and HRIS through integrations, automate roughly 80% of SOC 2, then flag the rest for a human. The 20% that stays manual is the same list across all of them — application-level screenshots, custom-tool reviews, change-approval walkthroughs, and periodic attestations — because none of it lives behind an infrastructure API.
That gap is where most teams lose 40 to 60 hours per audit reconstructing evidence by hand. Whether you run Vanta or Drata, the dashboard tells you what is missing; it does not go collect it. Vera does: she captures the application evidence, chases the attestations in Slack, and files signed, traceable packs, then syncs them back to whichever dashboard you keep. If you're weighing the two platforms directly, see Vanta vs Drata and the full comparison.
Screenata Is an Agent That Runs Your Compliance Program
If you only know Screenata as a screenshot recorder, this is the part that's changed. Screenata is Vera, an AI compliance agent who runs the whole program rather than a single-purpose capture tool. Screenshots are one of several ways she collects evidence, and the smallest one:
| What Vera does | How it works |
|---|---|
| Scans your infrastructure | Connects read-only to GitHub, cloud (AWS/GCP/Azure), and identity providers, then runs continuous checks across 489+ native scans, covering ~70% of evidence fully automated |
| Writes policies from reality | Generates policies grounded in how you actually operate, not templates. The generator is deterministic: the same attestation produces the same sentence, with no LLM creative writing in your control language |
| Captures application evidence | Uses the browser extension and a vision model to capture the UI/RBAC/workflow screenshots APIs can't reach, about 9% of evidence |
| Chases attestations in Slack | DMs the right person for the answers only a human has, reminds at 24h, escalates at 48h, and files the reply as evidence |
| Signs and traces everything | RSA/ECDSA signatures, RFC 3161 timestamps, and SHA-256 hashes, so every artifact ties back through a control test to a policy claim |
| Runs between audits | Daily scans, a 6:30 AM Slack briefing, and scheduled reviews keep evidence fresh instead of going stale the day after certification |
At $499/month, Screenata is built to replace the traditional stack, a GRC dashboard ($7K to $80K/year) plus a vCISO consultant ($8K to $15K/month), rather than just supplement it. If you already run Drata, the rest of this guide shows how Vera slots in for the work it leaves manual.
Why Screenshots Are Required for SOC 2
Auditors require visual proof for controls that can't be verified from API data alone:
| Control | What needs a screenshot | Example |
|---|---|---|
| CC6.1, Logical Access | User permission tests, denied access | Screenshot showing a restricted user blocked from an admin panel |
| CC6.2, Access Removal | Terminated-user verification | Disabled account in production |
| CC7.2, Change Management | Deployment approval workflows | PR approval plus the manual QA sign-off and deploy confirmation |
| CC8.1, Vulnerability Management | Scan results reviewed and signed off | Vulnerability dashboard with executive sign-off |
A screenshot carries context a log can't: it's human-readable, it proves the UI behaved as designed, and it shows who did what, when. The catch is that capturing, organizing, and narrating them by hand is the slow part, and that is exactly what Vera takes off your plate.
How Vera Collects SOC 2 Evidence
Step 1: Connect read-only
Connect Vera to GitHub and your cloud and identity provider. She scopes your control matrix, marks what's in and out of scope with justifications, and writes policies grounded in what she finds. No agents to deploy, no code changes.
Step 2: Vera runs the API scans
Across 489+ native checks, Vera automates roughly 70% of evidence (infrastructure configuration, identity logs, endpoint posture) and assembles each result as a signed artifact mapped to its control.
Step 3: Vera captures the application evidence
For controls behind your UI, Vera (or a teammate she prompts) runs the test through the browser extension. It captures timestamped screenshots, a DOM snapshot, and metadata, and a vision model scores the result against the control. For controls only a person can answer, such as "did the access review happen?", she opens an attestation request in Slack and tracks it to resolution.
Step 4: Review, sign, and sync
You approve. Vera files the signed, traceable pack into your audit vault. If you keep a dashboard, she syncs the pack into the matching Drata or Vanta control, moving it from "missing evidence" to covered.
Manual vs. Agent-Run Evidence Collection
| Task | Manual process | With Vera |
|---|---|---|
| Infrastructure evidence | You export configs and screenshots | API scan, ~70% automated |
| Application screenshots | Take 20 to 30 per control, by hand | Captured and scored automatically |
| File organization | Rename and sort by control ID | Auto-organized and mapped |
| Narrative writing | Write a description per screenshot | Drafted by Vera, you approve |
| Attestations | Chase colleagues over email | Vera DMs and escalates in Slack |
| Upload / sync | Manual upload to the platform | One step, or automatic to Drata |
| Between audits | Re-do it all next quarter | Vera keeps running |
For a team with 50 controls, the manual path is roughly 50 hours per quarter. With Vera, your hands-on time is mostly review, and the evidence doesn't go stale the moment the audit ends.
Example: Automating CC6.1 Logical Access
Objective: verify that users without admin privileges can't reach sensitive data.
The manual way (~60 minutes): create a test user, attempt access, take screenshots, write the report in Word, format to PDF, upload to Drata.
With Vera (a couple of minutes, mostly review):
- Vera runs the test against a non-admin account.
- The app returns a 403; the extension captures the screen, the DOM, the URL, and a signed timestamp.
- Vera assembles the evidence pack, maps it to CC6.1, and writes the narrative.
- You approve; she files it and syncs to Drata if you're on it.
The pack contains: CC6.1_Logical_Access_Test.pdf, the timestamped screenshots, metadata.json with tester and timestamp data, and a signed manifest, with every piece traceable back to the control and the policy claim behind it.
Automating SOC 2 Evidence, Control by Control
The fastest way to see where a dashboard stops and Vera keeps going is to walk the controls auditors most often ask for UI proof on. In each case the dashboard catches the configuration; Vera captures the operational evidence behind it.
CC6.1, Logical Access Security
What Drata catches: SSO is enabled, MFA is enforced in your identity provider, password policy meets the bar.
What Vera captures: the application-level proof that roles are actually enforced inside your product, such as a "Support" user blocked from billing, a "Viewer" denied write access, and an admin-only page returning a 403 to everyone else. She runs the test, captures the denial with a DOM snapshot and signed timestamp, and maps it to CC6.1. This is the single most common control auditors reject thin evidence on, because an SSO setting doesn't prove your in-app permissions work.
CC6.2, Access Provisioning and Removal
What Drata catches: the identity-provider account list and de-provisioning status.
What Vera captures: the end-to-end onboarding and offboarding workflow, including the ticket, the access grant, and, crucially, the removal of access in each downstream system after a termination. She can chase the offboarding attestation in Slack ("confirm this user's app access was revoked") and file the screenshot proof alongside the API signal.
CC7.2 and CC8.1, Change Management
What Drata catches: branch protection and required PR approvals in GitHub.
What Vera captures: the parts of the deployment that live outside the repo, including the manual QA sign-off, the staging-to-production promotion, and the change-advisory approval for a sensitive release. She records the workflow end to end so the auditor sees the whole approval chain, not just the merge.
CC7.x, Vulnerability and Risk Management
What Drata catches: that a scanner is connected and running.
What Vera captures: the evidence that findings were reviewed and acted on, such as the dashboard showing high-severity issues triaged, the executive sign-off, and the remediation ticket closed. A running scanner proves you look; the review evidence proves you respond.
Periodic Controls, Access Reviews and Risk Assessments
What Drata catches: that a review is due.
What Vera does: schedules and orchestrates the review, DMs each reviewer for their sign-off, tracks who's responded, escalates the stragglers, and files the completed attestation. She coordinates the review and chases the humans; the final judgment stays with your team.
A Week in Vera's Compliance Cadence
Automating evidence works as an ongoing rhythm rather than a one-time event. Once she's connected, Vera runs a standing cadence so the program stays audit-ready instead of going stale between cycles:
- Every morning, a 6:00 evidence-freshness check, a 6:15 readiness snapshot, and a 6:30 Slack briefing summarizing your posture and anything that needs attention.
- Weekly, full cloud and repository scans to catch drift (a new bucket without encryption, a repo that lost branch protection).
- Quarterly, access reviews she schedules, orchestrates, and chases to completion.
- Annually, a risk-assessment refresh.
- Continuously, whenever a control slips, she opens the work and routes it, rather than letting it surface during the audit.
This is the difference between "we passed last year" and "we're ready right now." When a control goes red, Vera opens the remediation work and routes it rather than just surfacing the alert.
How Vera's Screenshot Capture Works (and Why a Dashboard Can't)
The application screenshots are only ~9% of Vera's evidence, but they're the part that lets her augment or replace a dashboard rather than become another one. An API integration can read your AWS config or your Okta logs, but it cannot see your product's UI. That blind spot is the 20% gap, and the capture engine is how Vera covers it.
Capture is triggered by the kind of evidence a control needs. Vera records an end-to-end workflow when a control spans several steps (provisioning, approval, deprovisioning), fires an event-driven capture on a compliance-relevant moment (a login, an access denial, a config change), follows a guided path when a control needs a specific sequence, or captures on a schedule for recurring evidence.
A vision model reads each capture the way a reviewer would, checking button labels, error messages, role badges, and success or denial states, then deciding whether the screen actually demonstrates the control rather than merely relating to it. It attaches a confidence score, and low-confidence captures are flagged for your review instead of being guessed.
Every image carries its provenance. Beneath the screenshot sits a DOM snapshot proving the HTML elements existed as shown, plus the URL, an NTP-synced timestamp, the tester's identity, and browser context. The text in each shot is OCR'd and indexed, so an auditor can search "Access Denied" across hundreds of pages instead of scrolling a folder of PNGs. That bundle of image, DOM, metadata, OCR, and signature is what turns a picture into evidence with a verifiable chain of custody. It is the capability dashboards structurally don't have.
The Evidence That Isn't in a Browser at All
Everything above assumes the console renders in a tab. A good deal of it doesn't. Disk encryption sits in macOS System Settings or the Windows BitLocker panel, endpoint agents ship their own native consoles, and some workflows cross three desktop applications before they finish. A browser extension cannot see any of that, which is where the "just screenshot the admin console" answer quietly runs out.
Screenata Recorder is the desktop half of the same capture engine, a free app for macOS and Windows. It records the screen and resolves every click against the operating system's accessibility tree, so a step arrives as "clicked the FileVault toggle in System Settings" rather than a pair of screen coordinates, and it stays readable after the next OS redesign moves the button. Stop the recording and it uploads, comes back as evidence steps, and binds to the test that needed them.
The privacy posture matches the browser capture. Typing is recorded as a count of keystrokes, never the characters. Blur engages on its own when a password manager comes to the front, and while it's engaged the recorder also stops reading window titles and accessibility labels, so nothing leaks through the metadata after being hidden in the video. Credential-shaped query parameters are stripped from any URL it captures.
Which one to reach for: the extension for anything that renders in a tab, since a DOM snapshot is stronger provenance than pixels; the recorder for native apps, system settings, and workflows that cross between applications. Most teams run both and choose per control.
Collect Once, Map Across SOC 2, HIPAA, and ISO 27001
A hidden cost of manual evidence is doing it again for every framework, re-capturing the same access test for SOC 2, then ISO 27001, then HIPAA, because each audit runs as its own project. Vera maps evidence through a shared canonical control catalog, so a single artifact satisfies the equivalent control everywhere it applies:
| One piece of evidence | Satisfies |
|---|---|
| An access-denied capture | SOC 2 CC6.1 · ISO 27001 A.9.1.2 · HIPAA §164.312(a)(1) |
| An MFA-enforcement scan | SOC 2 CC6.1 · HIPAA §164.312(d) |
| A change-approval workflow | SOC 2 CC7.2/CC8.1 · ISO 27001 A.12.1.2 |
You collect and review once; Vera handles the mapping into each framework's language. For a multi-framework program, that reuse is often a larger saving than the capture automation itself, because a second framework becomes mostly mapping rather than fresh collection.
Best Practices for Evidence That Passes the First Time
Automation removes the manual labor, but good evidence still follows a few principles. Vera bakes most of these in; the rest are worth knowing.
- Standardize the test, not just the screenshot. A control is only as strong as the procedure behind it. Vera runs the same defined test each cycle, so the evidence is comparable quarter over quarter.
- Capture the whole sequence. Auditors want setup, action, and result, not a lone end-state. The workflow recording keeps the sequence intact.
- Keep evidence inside the audit window. Stale screenshots get rejected. Vera's scheduled captures keep everything current, so you're never re-collecting six months of evidence the week before the auditor arrives.
- Review before you file. Even automated evidence gets a human approval. Vera flags low-confidence captures and shows each screenshot beside its narrative so the review is fast.
- Redact before it leaves your hands. Vera masks PII automatically, and tests against staging or synthetic data are better still where the control allows it.
Common Challenges (and How Vera Handles Them)
Screenshots contain sensitive data. Vera redacts PII automatically before anything is filed or synced, and connects to your systems read-only.
Evidence doesn't match what the auditor expects. Vera packages every control identically, with the objective, procedure, result, tester, and timestamp the AICPA criteria call for, so a reviewer reads one consistent format instead of five.
Integration with your existing stack. Vera exports signed packs as PDF, JSON, and raw images, and syncs directly into Drata or Vanta controls, so adding her to an existing program doesn't mean ripping anything out.
Maintaining evidence across quarters. This is where a dashboard turns red and a manual process starts over. Vera runs continuously, refreshing evidence on a schedule and flagging drift, so the program stays audit-ready between cycles.
The Cost Math
The traditional path to SOC 2 stacks a GRC dashboard on top of a consultant who actually runs the program:
- GRC platform (Vanta/Drata): $7K to $80K/year
- vCISO or consultant to do the work the dashboard flags: $8K to $15K/month
- Auditor: ~$15K
- Your team's time: 40 to 60 hours per audit cycle on manual evidence alone
Screenata folds the platform and the consultant into one $499/month agent. Vera does the evidence collection, the policy writing, and the attestation chasing the consultant would bill for, and she keeps doing it between audits. For a typical startup the total first-year cost lands around $18K, including the auditor, versus roughly $85K on the traditional path. The bigger return, though, is the quarter of engineering time you don't spend on screenshot busywork.
What Happens After You Certify
Most compliance tooling treats certification as the finish line, so the dashboard goes quiet, the evidence ages, and next year's audit is another scramble. An agent changes the shape of that.
After you certify, Vera keeps running: daily scans against your infrastructure, a 6:30 AM Slack briefing summarizing readiness and anything that needs attention, scheduled access reviews she orchestrates and chases, and continuous evidence refresh so nothing drifts stale. When a control slips, such as a new S3 bucket without encryption or an offboarding that didn't revoke access, she catches it and opens the work rather than letting it surface during next year's audit. Continuous compliance comes built in, because it is the ongoing work an agent does once the audit is behind you.
Frequently Asked Questions
Does Drata automate SOC 2?
Drata automates roughly 80% of SOC 2 evidence through API integrations: infrastructure, identity logs, endpoint status, background checks, training, vendor risk, and policy acknowledgments. As a dashboard, it can't capture application screenshots, RBAC tests, or workflow documentation, and it can't chase the attestations a person has to answer.
Can Drata fully automate SOC 2 on its own?
No. Drata automates what's available through APIs. The application-level evidence and periodic attestations are work rather than a configuration check, and a dashboard only tracks status. Teams either spend 40 to 60 hours per audit on it or hand it to an agent like Vera.
Can Screenata replace Drata for SOC 2?
For most startups, yes. Screenata is Vera, an agent that runs the program rather than a screenshot add-on. She automates ~70% of evidence through her own API scans of the same sources Drata reads, captures the application screenshots Drata can't, chases attestations in Slack, writes deterministic policies from your infrastructure, maps controls across SOC 2, HIPAA, and ISO 27001, and signs every artifact. At $499/month she's priced to replace the full platform-plus-consultant stack. If you already run Drata, Vera works alongside it to close the gap.
Do auditors accept AI-generated evidence?
Yes, when it's real and traceable: original screenshots (not fabricated), accurate timestamps, tester identity, the control objective, and a clear pass/fail. Vera uses AI for capture, organization, and narrative, never to invent evidence, and every artifact she files is signed and traces back through a control test to a policy claim. Auditors can verify the signatures independently with a free CLI.
How is this different from screen-recording tools?
Screen recorders (Loom, ScreenRec) capture video and stop there, with no control mapping, no audit formatting, no provenance, and no agent doing the rest of the program. Vera captures evidence and maps it to controls, signs it, chases attestations, writes policies, and keeps the program current between audits. Screenata does ship a recorder of its own, Screenata Recorder for macOS and Windows, but what it hands back is a set of control-mapped evidence steps with the element behind each click identified, not a video file someone has to scrub through.
Can this completely replace Vanta or Drata?
For most startups, yes. Vera handles both halves of SOC 2, the API ~70% and the application 20%, plus policy writing, control mapping across frameworks, readiness scoring, and the ongoing work a dashboard leaves to you. At $499/month she replaces the GRC platform ($7K to $80K/year) and the consultant ($8K to $15K/month). If you already have a dashboard, run Vera alongside it to do the work; if you're starting fresh, she stands alone.
Is my data secure?
Yes. Vera connects to your infrastructure read-only, the platform is SOC 2 Type II certified, evidence is encrypted at rest and in transit, and PII in screenshots is redacted before anything is filed. Legally binding actions require your explicit approval, and every tool Vera uses is logged.
How long does setup take?
Connecting Vera is read-only and takes minutes: GitHub, your cloud, and your identity provider, with no agents to deploy and no code changes. From there she scopes your control matrix and writes draft policies grounded in what she finds, so you see your real readiness on day one. The ongoing work is mostly review: approving evidence she's collected and resolving the controls she escalates.
Which controls can Vera handle, and which still need you?
She handles the bulk automatically: infrastructure and identity controls through API scans (~70%), application access and change-management controls through guided screenshot capture (~9%), and recurring evidence on a schedule. By design, she escalates anything that needs judgment, such as an unusual incident, a first-time procedure, an exception sign-off, or an attestation only a person can give ("did the access review happen, and did the right people approve it?"). That honest hand-off is the trust mechanism, because she tells you what she can't determine instead of guessing.
Does Vera replace our auditor?
No. Vera does the preparation, collecting evidence, writing policies, and assembling audit-ready packs, but she is not the auditor. An independent auditor still issues your SOC 2 report. The difference is that because every artifact she produces is deterministic and traceable, the auditor can re-derive your policies from your attestations and verify each signature independently, which tends to make their review faster.
Key Takeaways
- Vera does the work a dashboard only tracks. Drata flags the 20% gap and waits; Vera runs the test, captures the proof, and files it. Closing that gap is hands-on work, and an agent is what performs it.
- Screenata runs the whole program. Screenshots are ~9% of how Vera collects evidence, ~70% is fully API-automated, and she chases the attestations in between.
- Everything is signed and traceable. Each artifact ties back through a control test to a policy claim, verifiable independently.
- Bolt on or replace. Keep Drata and let Vera do the manual work, or replace the platform-plus-consultant stack for around $18K total versus the traditional ~$85K path.
Learn More About SOC 2 Compliance Automation
For the complete guide to automating SOC 2 evidence collection, see our comprehensive walkthrough.
Not sure you even need a consultant? Read Do You Actually Need a vCISO for SOC 2? Probably Not Anymore or The Bootstrapped Founder's Guide to SOC 2.
Connect and see
See your SOC 2 with your real systems.
Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.