You are going through your first SOC 2. You bought Vanta or Drata, connected it to your identity provider and your cloud, watched the dashboard fill up with green checkmarks, and reasonably concluded you had this handled.
Then the auditor asks for something the dashboard cannot give them, and suddenly two people are spending a week digging through Slack and inboxes trying to reconstruct what happened in March.
What your compliance tool is genuinely good at
Keep it. It is doing real work. Those tools plug into systems that hold technical state, so they are excellent at proving technical state: multi-factor authentication is enforced, disks are encrypted, this account is currently disabled, that server is patched. Collecting that automatically, around the clock, is a huge improvement over screenshots in a folder.
What it cannot do
It cannot prove a person followed a process. It can show you that an account is disabled today. It usually cannot show who decided to disable it, whether the right manager approved the request, whether the steps ran in the order your policy says, or what happened with that one contractor whose offboarding went sideways because they were part-time through an agency.
That gap matters because a meaningful chunk of SOC 2 is not about settings. It is about a process that crosses HR, IT, and Security and breaks at the seams between them.
What the auditor actually asks for
Here is the shape of the request, and it surprises people the first time. They rarely ask "is MFA on." They ask for a sample. Something like: give me these eight people who left in the last six months, and for each one, show me that access was removed, that someone approved it, and that it happened inside the window your own policy promises. Then the same for six people who joined.
That is a question about what humans did, one case at a time. Not a dashboard state.
A document that says you do it is not proof that you did it. Your auditor knows the difference.
Why the policy PDF makes it worse
The instinct is to write a policy describing the offboarding process and file it. Understand what that does: you have now formally documented a control. If your evidence does not show people following it, you are not neutral, you are failing a control you defined yourself. A written procedure nobody demonstrably follows is a worse position than a modest one you can actually prove.
What actually counts as evidence
For any given run of the process, an auditor wants to see the boring specifics: which steps were performed, who performed each one, when, the approval captured at the moment it was needed rather than emailed around afterward, and any exception flagged and explained instead of quietly skipped. A record of what happened, for this person, on this date.
How a small company produces this without a compliance team
You do not add an evidence step at the end. You build the evidence into the process so it falls out of doing the work.
In practice: the approval is a step in the flow, not a message you go hunting for in three months. The person completing the step signs off right there, and that sign-off is stamped and printable. Exceptions get recorded as exceptions instead of disappearing. Do that once and audit season stops being an archaeology project, because the evidence was created continuously by the people doing the job.
That is exactly what the offboarding demo shows: the access-removal path with approvals and attestations built into the steps. Click through it and you will see what an auditor would be handed.
A caveat worth saying out loud. None of this makes you compliant on its own, and I am not your auditor. It makes the human half of your controls provable, which is the part small teams consistently get caught on.
The part I actually care about
Here is my honest bias. Compliance is a good reason to finally fix a process, but it is a bad reason to be the only reason. The companies that get real value out of this are the ones who fix the offboarding process because it was genuinely sloppy and risky, and then notice that the audit evidence came along for free.
Fix the thing because it is broken. Pass the audit because you fixed it. That order works much better than the other one.