Sign in to Scrut and go to Compliance → Evidence Tasks using the left navigation panel.
Click the All Evidences tab.
Click on an evidence task that you want to automate using the Scrut Monitor.

On the Evidence Detail page, click the Add Attachment button.

Choose Scrut Monitor.

You'll see a list of Connected and Supported Apps.

Click the Configure button next to the app you want to use for collecting evidence.

The configure workflow window opens.

Enter the Evidence Name, Type, and other details as required.
Choose the Cadence (how often you want Scrut Monitor to fetch the evidence), select the Evidence Format, and click Save.

Note:
If auto-publish is enabled, the evidence task will automatically publish on a set schedule when new evidence is attached.
If disabled, the task status will change to draft when new evidence is attached.
Once configured, Scrut Monitor will be successfully set up and will automatically fetch the required evidence and attach it as per the defined cadence.

Understanding the Scrut Monitor Report

Sample report generated by Scrut Monitor
Once Scrut Monitor runs and attaches evidence, you can open the report to see exactly how the data was collected.
Each Scrut Monitor report includes an API Endpoints Used section that lists the specific API calls made to fetch data from your connected integration. For each endpoint, you can access its official documentation directly from the report.
What this section shows:
The exact API endpoints used to collect the evidence (for example,
iam:ListUsers,iam:ListMFADevices,iam:ListGroupsForUserfor an AWS IAM report)Clickable links to the integration's official API documentation for each endpoint
Why this matters:
Auditors and reviewers can independently verify the data source and confirm that the evidence was pulled from the correct APIs
Removes ambiguity about where compliance data originates
Makes audit reviews faster and more reliable
To download a report, click the download button in the preview.
FAQs & Troubleshooting
1: How can I determine which evidence collection tasks can be automated with the Scrut Monitor?
Scrut automates evidence collection through various integrations. For a comprehensive list of evidence collection automated by the Scrut Monitor, please follow these steps:
Sign in to Scrut and click Integrations on the left navigation panel.
Click on any Integrations tile and view the Automated Evidence available in the side panel.
This provides a list of all evidence collection tasks automated by a specific integration.

2: Can I delete a Scrut Monitor workflow?
Yes. Open the artifact to which you've added the workflow. Scroll to the Scrut Monitor section and click the three-dot icon to delete the workflow. Choose Delete All Attached Evidences to delete only the evidence, and click Delete to remove the automated workflow.

3: How to determine when the Scrut Monitor has attached the evidence?
Look for the Last Synced timestamp to determine when the attachment was last updated.
