How do I attach a certificate or report to a provider?
Upload the document once, attach it to every record it supports, and keep a hash that proves it has not changed.
- 1
Open Evidence and choose Upload a document.
- 2
Give it a name a colleague would recognise and upload the file.
You should see: The document listed with its size and the date, and a content hash recorded at upload.
Names in any alphabet are accepted, including Cyrillic and Greek, and download correctly. That was not always true here.
- 3
Open the record it belongs to - a provider, a service, an arrangement - and attach it from the Evidence panel there.
You should see: The document listed on that record.
Worth knowing
One document can be attached to as many records as it supports. A single ISO 27001 certificate usually covers several services, and uploading it repeatedly is how a workspace ends up with four versions and no idea which is current.
Use Verify all integrity on the Evidence screen to re-check every stored document against the hash taken at upload. That is the difference between saying a certificate has not been tampered with and showing it.