Valeo · security governance / January 2026

Evidence expires too: treating freshness as part of the evidence model

A screenshot or export from last year can be factually correct and still fail to demonstrate current operation. Evidence existence and evidence freshness had to become separate states.

2 min read
Valeo · security governance
evidencefreshnessautomationaudit

Situation

Several items carried the assumption that once evidence had been collected, the work was permanently complete. Dynamic systems do not work that way: permissions, patch levels, device inventories and configurations change. An old export often proves only that a process worked at one point in the past, not that it still works now.

Approach

I added evidence creation time and expected refresh cadence to the register. The interval was not identical for every evidence type: a policy changes at a different pace from a vulnerability report or access list. Where evidence generation could be automated, I preferred that path over manually created screenshots.

Outcome

Statuses became more expressive: missing evidence, present and current evidence, and present but stale evidence needing regeneration were no longer collapsed into the same state. That prevented a large set of supposedly green items from becoming a last-minute surprise just before the audit.