Compliance
Do Auditors Accept AI-Captured Screenshots for SOC 2?
Yes, when the artifact carries what an auditor needs. Auditors evaluate the evidence rather than the hand that captured it, so an agent-captured screenshot is accepted on the same terms as one a person took, and it fails on the same terms. Vanta reported that 36% of the 650,000 images uploaded to its platform over six months were screenshots, which is the best public measure of how much visual proof survives full API automation. Automating the capture removes real hours and leaves two things unsolved: a captured image still has to show that a control operated across the whole period and that the sample came from a complete population, and a cloud browser cannot reach native desktop applications, sessions behind Conditional Access, or anything on premises.

Yes, when the artifact carries what an auditor needs. Auditors assess the evidence rather than the hand that captured it: a legible timestamp, the system and the account visible in frame, the scope of what is shown, and a clear link to the control being tested. A screenshot an agent took is accepted on the same terms as one a person took, and rejected on the same terms.
The question is live because the volume is real. Announcing computer use for its agent in August 2026, Vanta reported that of the 650,000 images uploaded to its platform in the previous six months, 36% were screenshots, because the evidence and control monitoring sat outside an API. Vanta's agent can now drive a browser and capture those screenshots, with a URL allowlist, an approval step before each new navigation, and a record of every artifact created.
That number repays reading carefully. It measures a share of uploaded images rather than a share of all compliance evidence, since reports, configuration exports, and log pulls are not images. What it does tell you is how much visual proof a mature compliance program still generates once the API integrations are finished.
Why the number is stronger than a vendor claim
Most statements about manual compliance work come from a vendor describing the problem it sells against. This one comes from the platform with the largest integration catalog in the category, measured across its own installed base over six months. Those customers are mostly certified already and running the most API automated product available, so 36% measures the residue that survives full API automation rather than teams who have not finished connecting their tools.
Vanta also described screenshot collection as one of its biggest customer requests. Demand pull from paying customers carries more weight than any vendor's estimate of a pain point, including ours.
Our own measurement lines up. Across the 64 SOC 2 controls, roughly 70% of evidence can be collected with nobody involved, through API scans and generated reports. About 9% is guided, where the tool tells you exactly where to click. Another 9% is a screenshot. Around 5% genuinely requires a person to submit evidence by hand.
What capture automation actually fixes
It fixes time, and quite a lot of it. Taking the same screenshot every quarter, cropping it, naming it, and filing it against the right control is unpaid work that nobody at a small company has room for. An agent that opens a page and captures it removes real hours from an audit cycle, and an approval step before each navigation keeps a person in the decision without keeping them on the mouse.
If the screenshot work you have left is public vendor pages, security pages, trust centers, and published subprocessor lists for a vendor review, capture automation covers most of it today. That is a real improvement, and it is where the demo in the launch was set.
The artifact still has to prove something
The first feature request in the launch thread was automated timestamps on the captured screenshots, and Vanta confirmed timestamps are already printed. That exchange points straight at the harder part.
A timestamp establishes when one capture happened. A SOC 2 Type II opinion covers a period, usually three to twelve months, and the auditor is testing whether the control operated throughout that period. One image on one day, however precisely stamped, describes a point in time.
Sampling is the other half. When a control runs many times across the period, the auditor selects a sample from a defined population and expects you to produce that population, including the items that were incomplete or excluded. A folder of captured images does not describe the population it came from. Who held the mouse when the image was taken has no bearing on that requirement.
So the question to ask about capture automation is what the resulting artifact says about period coverage and population completeness.
Where a cloud agent can go
Computer use in these products runs in a cloud browser, and that constrains what it can reach for reasons of architecture rather than model quality.
A cloud browser cannot open a native desktop application, because the application is not installed on it. Plenty of compliance evidence still lives in installed software: endpoint management consoles, older finance and HR systems, clinical and industrial tools, anything with a thick client.
It also does not inherit the session you are already signed into. Reaching an authenticated admin console means the agent needs credentials of its own, which raises a question your auditor will ask: which service account did the compliance vendor hold, what privileges did it carry, and how was its use monitored. Storing admin credentials for your consoles with a third party in order to automate access control evidence is a control question of its own.
Conditional Access and device compliance policies add a further limit. A tenant that requires a managed device or a known network will refuse a browser running in someone else's cloud, by design, since that is what the policy exists to do. Anything on premises or behind a VPN sits outside reach for the same reason.
The residue Vanta measured sits mostly in internal consoles, while public pages are the part a cloud agent reaches comfortably today.
What to ask a vendor about screenshot evidence
- Can it capture from an application installed on a laptop, or only from a web page?
- Does it use my existing signed in session, or does it need its own credentials to my admin consoles?
- What happens when Conditional Access or a managed device policy blocks it?
- Is each captured image filed against a specific control test, with the claim it supports recorded alongside it?
- For a Type II, what does the tool show the auditor about period coverage and population, beyond the individual capture?
Questions four and five are what separate a capture tool from an evidence system, and they are the ones an auditor's information request will eventually ask on your behalf.
How Screenata handles the non API share
Screenata runs capture on the machine you already work on, through a browser extension and a desktop recorder, rather than in a cloud browser. It uses the session you are already signed into, so there are no separate credentials for a compliance vendor to hold. It records the whole screen, which puts native applications in scope. It runs from inside your own device and network posture, so a policy that requires a managed, compliant device is satisfied by the same machine you already use for the work.
A person is still driving that capture, and we would rather say so plainly than call it autonomous. The trade is real: you click, and in exchange the capture reaches systems a cloud browser cannot open. Across the rest of the program, 700+ automated checks collect evidence with nobody involved, and every captured artifact is filed against the control test it supports, with the claim it proves recorded next to it.
The 36% is real, and publishing it was the right call. Taking the labor out of that share is worth doing. The work that comes after the capture, showing an auditor that a control operated across a period and that a sample came from a complete population, is where the audit is decided.
Frequently asked questions
- Do auditors accept screenshots captured by an AI agent?
- Yes, provided the artifact carries what the auditor needs. Auditors assess the evidence itself rather than who captured it: a legible timestamp, the system and account visible in frame, the scope of what is shown, and a clear link to the control being tested. An agent-captured screenshot is accepted on the same terms as one taken by a person, and rejected on the same terms. What automation does not settle is period coverage and population completeness, which a SOC 2 Type II opinion depends on and a single capture cannot demonstrate.
- What percentage of compliance evidence is screenshots?
- Vanta reported in August 2026 that 36% of the 650,000 images uploaded to its platform over the previous six months were screenshots. That figure is a share of uploaded images rather than a share of all evidence, since reports, configuration exports, and log pulls are not images. It is a useful benchmark because it was measured across an installed base that is largely certified already and running a mature set of API integrations, so it reflects the visual proof that remains after API automation is finished.
- Does automating screenshot capture satisfy a SOC 2 Type II auditor?
- Not on its own. A timestamped capture establishes when one image was taken, while a Type II opinion covers a period of three to twelve months and tests whether the control operated throughout it. Auditors also select samples from a defined population and expect to see that population, including excluded and incomplete items. A folder of captured images does not describe the population it came from, and that requirement does not change based on whether a person or an agent took the screenshot.
- Can a cloud based computer use agent capture evidence from a desktop application?
- No. Computer use agents in compliance platforms run in a cloud browser, so a native desktop application is not installed on the machine they control. The same constraint blocks systems behind a VPN or on premises, and Conditional Access or device compliance policies will refuse a browser running in a third party cloud. A cloud agent also does not inherit the session you are already signed into, so reaching an authenticated admin console requires giving the vendor its own credentials.
- What should I ask a vendor about automated screenshot evidence?
- Ask whether it can capture from an application installed on a laptop or only from a web page, whether it uses your existing signed in session or needs its own credentials to your admin consoles, what happens when Conditional Access blocks it, whether each captured image is filed against a specific control test with the claim it supports recorded, and what the tool shows an auditor about period coverage and population completeness for a Type II.
Connect and see
See your SOC 2 with your real systems.
Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.