[{"data":1,"prerenderedAt":216},["ShallowReactive",2],{"changelog-2026-08-31-cloud-evidence-agent-skills":3,"changelog-2026-08-31-cloud-evidence-agent-skills-surround":205},{"id":4,"title":5,"api":6,"authors":7,"body":13,"category":98,"date":99,"description":100,"extension":101,"faq":6,"features":102,"fixes":139,"highlight":160,"image":169,"improvements":171,"meta":199,"navigation":200,"path":201,"seo":202,"stem":203,"__hash__":204},"posts\u002F3.blog\u002F2026-08-31-cloud-evidence-agent-skills.md","Cloud Evidence That Actually Evaluates",null,[8],{"name":9,"to":10,"avatar":11},"Justin Leapline","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fjustinleapline\u002F",{"src":12},"\u002Fimages\u002Fjustinleapline.png",{"type":14,"value":15,"toc":94},"minimark",[16,20,37,44,47],[17,18,19],"p",{},"Collecting evidence was never the hard part. Producing a verdict you can defend is.",[17,21,22,23,27,28,31,32,36],{},"This release connects the last link in that chain. Every integration operation now decodes its own response, evaluates its assertions, and writes a real verdict against the control — and the failure modes that used to resolve silently in your favor no longer do. An ",[24,25,26],"code",{},"AccessDenied"," used to arrive as evidence with zero records, which made a \"no critical Security Hub findings\" check pass. XML from IAM, EC2, and S3 was never decoded, so those checks were reading an empty array. A relative-date predicate compared ISO strings against the literal text ",[24,29,30],{},"CUTOFF_PLACEHOLDER",". Each of those failed by ",[33,34,35],"em",{},"attesting"," a control rather than by erroring, which is the only kind of bug that matters here.",[17,38,39,40,43],{},"Now an undecodable response fails its region, empty evidence returns ",[24,41,42],{},"inconclusive"," and attests nothing, an incomplete sync run is excluded from coverage, and every failing check raises a finding with the evidence attached.",[17,45,46],{},"The connector estate grew to match. AWS sync spans multiple accounts, multiple regions, and AWS Organizations — fanning out with per-account failure isolation, stamping every record with its account and region, and offering chained role access for estates that will not run StackSets. Supabase, Vercel, Netlify, and GitHub cover the teams whose production footprint is a PaaS stack, where hosting, database, and deploy pipeline previously produced no automated evidence at all.",[48,49,50,58,64,70,76,82,88],"ul",{},[51,52,53,57],"li",{},[54,55,56],"strong",{},"Approved exceptions can satisfy a check"," — pointed at specific records, requiring a real approver, and expiring on their own, so an accepted risk is not a permanent carve-out",[51,59,60,63],{},[54,61,62],{},"Agent skills"," bundle instructions, tools, and when-to-use guidance, loading on demand instead of on every turn, with provenance-aware approvals and asynchronous sub-agents",[51,65,66,69],{},[54,67,68],{},"Programs report against individual boundaries",", with account and region scope rules that finally make the PCI CDE case reachable",[51,71,72,75],{},[54,73,74],{},"Assessments scoped to a program"," inherit its controls and every piece of evidence already on file",[51,77,78,81],{},[54,79,80],{},"A desktop app with tabs",", persisted per workspace and reorderable by drag",[51,83,84,87],{},[54,85,86],{},"AI spend attributed by surface and operation",", with a usage report that reconciles itself",[51,89,90,93],{},[54,91,92],{},"CSP enforced",", privileged RPCs behind the service role, and a security pass that closed every advisor finding",{"title":95,"searchDepth":96,"depth":96,"links":97},"",2,[],"changelog","2026-08-31","Multi-account AWS, Supabase, Vercel, Netlify, and GitHub connectors now write real control verdicts — and a failing check raises a finding instead of quietly passing. Plus agent skills, approved exceptions that satisfy a check, per-boundary program reporting, and a desktop app with tabs.","md",[103,106,109,112,115,118,121,124,127,130,133,136],{"label":104,"text":105},"Cloud","AWS sync spans multiple accounts, multiple regions, and AWS Organizations, with per-program scoping, per-account failure isolation, and chained role access for estates that cannot run StackSets. Every record is stamped with its account, region, and provider.",{"label":107,"text":108},"Integrations","Supabase, Vercel, Netlify, and GitHub join the connector estate — access posture, config hardening, and change-management evidence for teams whose production footprint is a modern PaaS stack rather than a cloud account.",{"label":110,"text":111},"Ticketing","Bi-directional Jira and Linear sync, so remediation lives in the tracker your engineers already use and status flows back without anyone copying it.",{"label":113,"text":114},"Exceptions","An approved exception can now satisfy an assertion. It points at one check and the exact records it covers, requires a real approver, and expires — when the acceptance lapses the control returns to failing on its own. \"Passed with an exception\" stays distinguishable from \"passed clean\".",{"label":116,"text":117},"Agent","Skills became a composition unit — each bundles its own instructions, tools, and when-to-use guidance, loaded on demand rather than injected on every turn. Approvals are provenance-aware, and sub-agents run asynchronously so a long task no longer holds the conversation.",{"label":119,"text":120},"Scope","Report a program against its individual boundaries. Scope rules now cover account and region — the only axes that constrain account-global evidence — so the PCI CDE case is reachable, and boundaries can be created inline from the program itself.",{"label":122,"text":123},"Assessments","Scope an assessment to a program and it inherits the whole control set, plus every piece of evidence already on file. New assessments open with what you have, not blank.",{"label":125,"text":126},"Evidence","Drop a file anywhere in the app and it becomes evidence, targeted by where you dropped it, then read in the background to propose the controls it appears to prove. Bytes go direct to storage, duplicates are caught by checksum, and progress survives navigation.",{"label":128,"text":129},"Trust Center","Themable trust portals — a preset theme ladder with an explicit light\u002Fdark policy, contrast-checked palettes, admin-authored masthead links, and the theme inlined into the first paint so the portal never flashes episki's colors.",{"label":131,"text":132},"Desktop","The desktop app gets a real title bar with tabs — persisted per workspace, reorderable by drag, opened with + or a middle click, and updated in place as you navigate.",{"label":134,"text":135},"AI","Every model call is now attributed to a surface (chat, recipe, plan, autonomous) and an operation, with a usage report that reconciles as it prints. You can see what your AI spend actually went to.",{"label":137,"text":138},"API","The entity registry is published at \u002Fapi\u002Fontology\u002Fcatalog with a content checksum, so an external agent can pin the shape of every entity kind and detect drift with an equality check.",[140,143,146,148,151,154,157],{"label":141,"text":142},"Security","Content Security Policy moved from report-only to enforced, with violation reporting. Privileged RPCs moved behind the service role and revoked from authenticated, SECURITY DEFINER dropped where RLS already enforces the same rule, mutable search paths pinned, an anonymous path onto the comms RPCs closed, and the avatars bucket is no longer a cross-tenant enumeration oracle.",{"label":144,"text":145},"Coverage","A non-2xx AWS response was being wrapped as evidence with zero records, so an AccessDenied made a \"no critical findings\" check pass. XML responses from IAM, EC2, and S3 are now decoded, relative-date predicates compare dates rather than strings, and denied actions are surfaced instead of swallowed.",{"label":104,"text":147},"A second workspace can no longer lock the first out of a shared AWS account, S3 region redirects are followed, STS AssumeRole failures are diagnosable, and stack updates apply from the template the app actually serves.",{"label":149,"text":150},"Workspace","Cached rows and useAsyncData entries no longer bleed across workspaces, and a claim switch in one tab stops rescoping the others.",{"label":152,"text":153},"Chat","Attachments persist, the send queue can no longer corrupt a turn, silent turn timeouts are gone, and thinking shows before the first token.",{"label":155,"text":156},"Database","Duplicate migration versions de-duplicated with a guard against the next collision, and a three-migration production backlog applied.",{"label":158,"text":159},"Team","Newly invited people appear without a reload.",{"title":161,"description":162,"icon":163,"items":164},"Evidence that produces a verdict, not just a file","Collecting evidence is the easy half. This release connects the other half: every operation now decodes its response, evaluates its assertions, and writes a pass, fail, or inconclusive verdict against the control — and a failing check becomes a finding you can assign. Empty evidence can no longer pass a check, an unreadable response fails its region instead of resolving to nothing, and a sync that did not finish cannot attest a control.","i-lucide-scan-search",[165,166,167,168],"Pass \u002F fail \u002F inconclusive verdicts written per assertion, with the offending records shown","Failing checks raise findings automatically, with severity and the evidence attached","Empty or undecodable evidence returns inconclusive — it never attests a control","An incomplete sync run is excluded from coverage rather than counted as clean",{"src":170},"\u002Fimages\u002Fchangelog\u002Fcloud-evidence-agent-skills.webp",[172,175,178,181,184,187,190,193,196],{"label":173,"text":174},"Third-Party Risk","Vendor risk scoring, continuous monitoring, and an offboarding flow; the questionnaire lifecycle now actually advances through sent, in progress, submitted, in review, and accepted; the review tab shows AI confidence and the trust-center excerpt behind each drafted answer, with per-answer accept and flag. Subprocessors are consolidated onto the vendor record.",{"label":176,"text":177},"Entities","All 16 entity overviews read title, properties, description, with a shared label-gutter property block. Tasks and issues gained one, and every field vocabulary now comes from a single source so the rail and the page can't drift.",{"label":179,"text":180},"Editor","Writing actions are grounded in the record, not just the document — \"continue writing\" now knows what it is describing.",{"label":182,"text":183},"Onboarding","An entitlement-aware setup hub, plus Intercom help-center sync so in-app answers match the docs.",{"label":185,"text":186},"Auth","Password sign-in with OTP fallback, alongside Google, Microsoft, and SAML SSO.",{"label":188,"text":189},"Comms","Every notification names the workspace it came from, and Slack delivery is restored.",{"label":191,"text":192},"Work","Status groups and columns order by workflow rather than alphabetically, issues and tasks share one detail shell, and the back arrow goes back instead of up to the listing.",{"label":194,"text":195},"Recurring","Schedules that fire, configured in the create modal, without writing cron.",{"label":197,"text":198},"Performance","CI wall clock cut from roughly 12m40s to 6m, and RLS read latency reduced across the app.",{},true,"\u002Fblog\u002F2026-08-31-cloud-evidence-agent-skills",{"title":5,"description":100},"3.blog\u002F2026-08-31-cloud-evidence-agent-skills","f_6o0jFrFnQee90RSnekczeckPjf76FvYjIg2wXwZ1Q",[206,211],{"title":207,"path":208,"stem":209,"description":210,"children":-1},"Open Signup, PCI DSS, and Agent-Run Vendor Reviews","\u002Fblog\u002F2026-07-16-open-signup-pci-vendor-agent","3.blog\u002F2026-07-16-open-signup-pci-vendor-agent","The waitlist is gone — anyone can sign up. Plus full-fidelity PCI DSS ROC & SAQ assessments, an agent that runs the vendor evidence lifecycle over email, trust centers served at your own domain root, and an evidence-backed assurance dashboard.",{"title":212,"path":213,"stem":214,"description":215,"children":-1},"Agent-first GRC: what changes when AI runs the program","\u002Fblog\u002Fagent-first-grc","3.blog\u002Fagent-first-grc","Most GRC tools added AI as a feature. Agent-first GRC treats agents as the operator — drafting policies, answering questionnaires, and running the program with humans approving the work that matters.",1788228967168]