A request is raised against the control it concerns, so the answer arrives attached to the question rather than in a mail thread.
The auditor's own workspace: one engagement, one place to request, review and record a decision.
OneAudit is the auditor's side of the engagement, as its own application. Where the evidence workspace serves the organisation being audited, OneAudit serves the firm doing the auditing: one engagement, one place to request, review and record a decision.
It exists because the auditor is the one participant who is usually given a shared folder and a spreadsheet. An audit conducted that way is reconstructed afterwards rather than recorded as it happens.
One engagement in one place: scope, requests, responses and decisions, recorded as the audit happens rather than assembled afterwards.
The same discipline applied to internal reviews, with the decision and its reasoning captured at the point it is made.
The folder and the spreadsheet are how findings lose their context. Here a request stays attached to the control it concerns.
A request is raised against the control it concerns, so the answer arrives attached to the question rather than in a mail thread.
The auditor sees what the organisation has deliberately released, and internal working state stays internal.
A pass, a finding or a request for change is written as it is made, with its reasoning, and it cannot be quietly amended afterwards.
Scope, period and framework are set once, and everything in the engagement inherits them.
Scope, period and framework are set once. Everything raised inside the engagement inherits them, so nothing has to be restated on each request.
A question is attached to the control it concerns, so the answer arrives with its context instead of in a thread.
The organisation decides what to release. You see that, and you can tell what you have not been given, which is often the more useful signal.
A pass, a finding or a request for change is written with its reasoning at the time, and cannot be quietly amended later.
Stated deliberately. A product that only lists what it can do leaves the reader to discover the boundary themselves, usually at the worst moment.
The judgement is the auditor's. The application makes it recordable, traceable and hard to lose.
You see released material. Internal working state stays with the organisation, which is what makes them willing to work in the open.
The certificate remains the certification body's instrument, issued through its own process.
A decision and its reasoning are recorded as made. Changing a position leaves a trail, because an audit record that can be edited silently is evidence of nothing.
The paired product. What an organisation releases there is what appears here, which is why requests and answers stay attached to their control.
Both sides read the same control set, so a request means the same thing to the auditor and to the organisation.
Certification preparation on the client side lines up with the engagement structure here.
| Feature | Milestone | Scope |
|---|---|---|
| Engagement with scope, period and framework | v1.0 | In MVP v1.0 |
| Requests raised against a control | v1.0 | In MVP v1.0 |
| Governed view of released evidence | v1.0 | In MVP v1.0 |
| Findings with corrective action tracking | v1.1 | Planned |
| Decision record and report assembly | v1.2 | Planned |
Milestones are roadmap targets rather than shipped dates. Target for MVP v1.0: Q4 2026. Provisioning is white-glove, never self-serve.
Every SecureEdge Advisory product prepares you for a certification, an audit or an assessment. None of them awards one. A certificate is issued by an accredited certification body, an attestation opinion by an independent auditor, and a regulatory finding by a regulator. We prepare the position and facilitate the process; the affirmation is made by someone else, and we do not blur that line.
Everything a product reports is derived from information supplied by your organisation, or by the person representing it. Ratings, maturity levels, readiness figures, mappings between frameworks and any monetary exposure are calculated from those inputs. Where an input is incomplete, out of date or optimistic, the output carries that forward faithfully. A result is therefore a structured statement of the position you have described, not an independent verification that the position is true.
An assessment is a documented position at a point in time. It is useful precisely because it is explicit about what it rests on, and it should be read that way rather than as a proof. Nothing here is a substitute for an audit, and no output should be presented to a regulator, a customer or a board as one.
Part of a family of ten products sharing one governed control library. Provisioning is white-glove and scope follows a due diligence review.