Screenata

Compliance

How to Bridge the Drata Automation Gap for SOC 2 Evidence

Drata automates infrastructure compliance via APIs, but application-layer evidence and periodic attestations stay manual. This guide explains how Vera, an agent that runs continuous compliance, does the work a dashboard only flags: capturing application evidence, chasing sign-offs, and filing signed, traceable packs, alongside Drata or in place of it.

February 9, 20269 min read
SOC 2DrataEvidence CollectionAutomationCompliance Gaps
How to Bridge the Drata Automation Gap for SOC 2 Evidence

SOC 2 audits still require application evidence, workflow documentation, and clear proof that auditors can review. Platforms like Drata automate infrastructure checks through API integrations, but collection for application workflows stays manual. You likely bought a GRC tool expecting continuous automation, only to find yourself capturing screenshots for custom admin panels, chasing user access reviews, and reconstructing change-management workflows every quarter.

This is the Drata automation gap. It is a limitation of API-based monitoring: APIs query AWS or Okta instantly, but they cannot see what a human sees in a custom interface, and they cannot answer a question only a person can answer. To close the gap, you need an agent that does the work a dashboard only flags. That agent is Vera.

What Is the Drata Automation Gap?

The gap is the set of SOC 2 controls that require evidence from systems where no API integration exists, plus the attestations no system can produce on its own.

Drata, Vanta, and Secureframe connect to structured data sources: cloud providers, identity providers, and version control. They pull configuration to prove a control is met. Drata queries the AWS API to confirm an S3 bucket is encrypted. That evidence is structured and binary.

SOC 2 also requires evidence for application-layer controls and periodic reviews. These include:

  • User access reviews (CC6.1): proving you revoked access in a custom internal admin tool.
  • Change management (CC8.1): showing a deployment approval in a system without a clean API.
  • Configuration settings (CC6.6): proving a toggle is on in a SaaS tool Drata doesn't integrate with.
  • Attestations: confirming the access review actually happened and the right people signed off.

Because these systems lack public APIs, or because a custom integration is too expensive to build and maintain, compliance managers default to manual screenshots and Slack chasing. The result is a split workflow: 80% of evidence is automated by the dashboard, and the remaining 20% consumes most of the audit-prep time. A dashboard flags the work; it does not do the work.

Where Traditional SOC 2 Automation Stops

The line runs between infrastructure monitoring and application state.

Evidence typeAutomated by Drata?Why or why not
Cloud infrastructureYesCloud APIs allow continuous polling of encryption and firewalls
Identity providersYesOkta and Google Workspace APIs expose MFA status and user lists
Device securityYesMDM agents report OS versions and disk encryption
Custom admin panelsNoNo standard API; needs visual verification of permissions
Legacy or on-prem appsNoEvidence exists only in the UI
Complex workflowsNoValidating an approval sequence needs a narrative, not a data point
Periodic attestationsNoA person has to confirm the review happened

A monitoring dashboard reads APIs. It does not navigate a UI, click a control, and capture the result, and it does not DM a colleague to confirm a review. That is the work Vera does.

What Still Requires Manual Work Without an Agent

If you rely on a dashboard alone, you are still collecting evidence by hand for these control families every quarter.

Custom user access reviews (CC6.1)

A dashboard automates access reviews for systems it connects to, like GitHub or Salesforce. Most companies also run internal tools: back-office dashboards, support consoles, and "god-mode" admin panels that touch sensitive data. Auditors want proof you reviewed access to those. Since a dashboard can't connect to your proprietary panel, someone logs in, screenshots the user list, timestamps it, and uploads it, then chases the panel owner to confirm the list is correct.

Change management for non-integrated flows (CC8.1)

A dashboard links Jira tickets to GitHub pull requests well, but edge cases break the automation. A hotfix that bypasses the standard flow, or a deployment tool the dashboard doesn't support, fails the automated check. Someone then reconstructs the chain of custody by hand: the ticket, the approval timestamp, and the deployment log.

"Not monitored" controls

Your dashboard likely has controls labeled manual or not monitored, often policy acknowledgments or settings in tools like Figma, Miro, or niche HR software. Low risk, but they still need evidence, and logging into ten SaaS tools to screenshot a settings page adds up to hours every quarter.

How Vera Bridges the Gap

Vera runs the compliance program as an agent instead of a dashboard you feed. She scans your infrastructure read-only, scopes your control matrix, drafts policies grounded in what she finds, and works the controls on a schedule. For everything a dashboard flags, she does the collection herself.

Her evidence mix is the honest breakdown: about 70% fully API-automated, roughly 9% automated screenshots (the browser extension plus a vision model scoring the capture), about 9% guided capture, and around 5% ingested from your inbox. Zero percent comes from a person uploading files into a dashboard. Screenshots are one of several ways she collects evidence, and the one an API can never reach.

Compared to the alternatives

You have three ways to close the gap.

Build custom integrations. Your engineers write scripts to query internal tools and push JSON into Drata. Fully automated, but expensive: it pulls engineers off product work, APIs break, schemas change, and maintenance becomes a hidden tax on the roadmap.

Assign a screenshot engineer. A junior engineer or IT manager captures screenshots every week. No development cost, but high human error: people forget timestamps, crop out the URL, or miss the collection window, and you fail an audit because you can't prove a control was active during the observation period.

Put Vera on it. She captures application evidence through the browser extension, chases attestations in Slack, drafts policies from your attested reality, and files signed, traceable packs. She replaces both the platform and the consultant, bringing year one to a SOC 2 Type II to $22K-$33K with the auditor and your team's time counted, versus $77K-$178K for the traditional stack. She needs read-only access to your GitHub org and cloud environment.

For most startups, Vera replaces both Drata and the vCISO or consultant you would need alongside it. See Do You Actually Need a vCISO for SOC 2?

Practical Example: Reviewing Access to an Internal Admin Panel

Here is how CC6.1 works for a proprietary "super-admin" panel.

The manual way (Drata alone): Every quarter, your compliance manager sets a reminder, nags the engineering lead to log into the portal, receives a screenshot of the user list over Slack, converts it to a PDF, and uploads it to Drata control CC6.1.

The way Vera does it: The review comes due on Vera's schedule. She opens a guided capture for the admin panel's user list and runs it through the Screenata browser extension, so the person confirming the review captures the "Active" user list once, with the URL, timestamp, and a DOM snapshot embedded automatically. For the judgment part (are these the right people?), Vera DMs the panel owner in Slack, reminds at 24 hours, escalates at 48, and files their sign-off as an attestation alongside the capture. She assembles the signed pack, links it to CC6.1, and pushes it into Drata.

The collection and chasing are no longer manual, and the final judgment still rests with a person. Vera coordinates the review and captures the evidence; she does not decide who should have access.

The Attestation Problem No Dashboard Solves

Much of the gap is a people problem, not a capture problem. Plenty of controls can only be satisfied by a human answering a question: did the quarterly access review happen and did the right managers sign off, who approved this production exception, was this vendor reviewed before onboarding, did offboarding revoke access everywhere. A dashboard flags these and waits. Someone has to remember, chase colleagues across Slack and email, gather the answers, and upload the proof, every quarter. Vera does the chasing: she DMs the right person, reminds at 24 hours, escalates at 48, and files the reply the moment it lands, with the thread visible. That is the part of the gap a camera can't fix and a dashboard won't touch on its own.

Signed, Traceable Evidence

Every artifact Vera files is hashed, timestamped (RFC 3161), and signed, and it traces back through a control test to a specific policy claim. An auditor can start from a sentence in your policy, follow it to the test and the signed evidence, and verify the signature with a free CLI, no Screenata account required. If you keep Drata, Vera pushes these packs into the matching control so the dashboard shows it covered; if you don't, the audit vault is the source of truth.

What This Costs

A dashboard alone still needs a vCISO or consultant (from a $5K readiness project to a $10K monthly retainer) to write policies, decide what to fix, and run the program it only monitors. With the auditor and your team's time counted, a traditional first year to a SOC 2 Type II lands at $77K-$178K. Vera replaces both: Screenata is $5,988 a year ($499/mo) per framework, bringing the same first year to $22K-$33K. You get 20+ native integrations, 650+ checks, and 27+ agent tools across Slack, email, the CLI and a Claude Code MCP, and GitHub pull-request reviews.

Why Auditors Prefer Visual Evidence for These Controls

Many auditors prefer a screenshot over a raw JSON dump for application-level controls.

A JSON dump from a custom API asks the auditor to trust that your script queried the right database and didn't filter out bad data, which usually triggers a completeness-and-accuracy check to validate the script. A signed capture is closer to self-validating: it shows the interface as a human sees it, with the URL bar, the column headers, and the context, plus a signed timestamp and DOM snapshot proving it was real and in-window. For custom tools, that visual proof is often faster to audit because it needs less explanation than a custom schema.

For most startups, bridging the gap means moving from a dashboard that flags work to an agent that does it. Vera handles the infrastructure monitoring a dashboard does and the application evidence, attestation chasing, policy writing, and guidance it does not. If you already have Drata, Vera works alongside it and syncs signed packs back. For teams getting SOC 2 for the first time, Vera is the more complete path.

Learn More About SOC 2 Automation

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.