the system of work for security administration

How Evident runs, end to end.

Evident is an integrated delivery of software, AI, and services, priced on outcomes rather than licenses or hours. No one of the three is the product. The fusion is, and outcome pricing is the proof the fusion is real, because only the party that owns all three can guarantee the cost falls.

Evident is a system of work: the software is the control tower that detects change, maps it to obligations, holds the evidence, and shows the basis for every decision. The AI runs the work as agentic tasks. Accenture is the trusted hand that carries the liability and supplies the human approval layer that agentic systems still need.

A software vendor cannot guarantee your admin cost falls, because it does not run your admin. A consultancy cannot price the outcome, because its margin is the hours. Evident can, because Evident is all three.

software ai services one system of work
fig 04the fusion · three inputs, one system of work
the loop

Change to obligation to work to proof, continuous.

Something shifts: a CVE lands in a critical vendor's stack, a posture moves, a regulation updates, a certificate expires, a questionnaire arrives. Evident maps the change to the obligations it touches, the right agentic task runs as a scoped child run, and the output is proof. The loop is scoped to the change, so a reassessment touches the affected control surface, not the whole ritual. The proof is not reconstructed later for the auditor. It is produced by the work itself, as the work runs.

changea cve lands · cert expires obligationcontrols · suppliers mapped workscoped task runs proofledgered · versioned · fresh
fig 01the operating loop · the proof stage carries the refraction
the spine

Answer once, reuse everywhere.

The Trust Graph is the canonical store of suppliers, controls, obligations, evidence, exceptions, and decisions. Every framework requirement, customer questionnaire, and insurer question maps to a control answered once, with typed, versioned, freshness-dated evidence. A full SIG alone is 1,936 questions;5 answered once on the graph, the control behind each answer is reused on the next form, the next framework, the next carrier. Evidence reuse rate is the spine's owned number, and the mechanism behind the fifty percent.

one control, answered once SOC 2 ISO 27001 NIST DORA customer questionnaire insurer question audit pack
fig 05the Trust Graph · one control, many consumers
the work it runs

Eleven agentic tasks, grouped into three ideas.

sense and route
The control tower watches the world and dispatches scoped work, instead of waiting for the annual cycle. This is active security administration.
01Trust Graph (spine)
02Control Tower
do the work of assurance
Inbound and outbound assurance kept live: questionnaires, vendor monitoring, evidence, insurance readiness, disclosure, and a gate inside procurement.
03Questionnaire Factory
04TPRM Engine
05ISMS & Evidence Ops
06Insurance Readiness
07Regulatory Disclosure
08Procurement Gate
govern and prove
Every accepted risk has an owner and an expiry, packs generate from canonical state, and the saving the contract is priced against is visible to client and Accenture alike.
09Audit & Certification Packs
10Exceptions Register
11Defensibility Reporting
why it is different

Three properties a system of record cannot have.

01

Proof is a byproduct of execution.

Every run writes structured history, so reconstructing evidence of what was decided, and on what basis, happens automatically.

02

The work gets cheaper on the record.

Every human correction feeds a learning loop that raises automation over the term, which under outcome pricing is margin while the savings claim stays provable.

03

Accountability is a first-class node.

Human judgment is routed to a named approver and ledgered, with residual judgment routed to Accenture, where the liability lives.

automation up manual touch down term startyear 3
fig 19the learning curve · automation up, manual touch down illustrative

System of record

Stores artifacts, priced per seat
Speeds the team you keep
Cannot price the outcome or sit in procurement

System of work

evident
Observes the work, priced on the outcome
Absorbs the work, no standing team to operate it
Produces the proof and sits inside the procurement workflow
how it is delivered

The partners are not a channel bolted on after the fact.

The design cannot be retrofitted onto a tool stack that started as a place to store files. It requires a runtime where the work itself is the first-class artifact. The partners are how the work gets absorbed and stood behind.

Beyond Work · the execution layerthe rails beneath
Evident software · the control towerdetect, map, hold
Evident AI · the agentic tasksrun the work
Accenture · the trusted handhuman & liability

The client outcome sits at the top, carried by the whole stack.

the whole architecture, in depth

Read the full architecture whitepaper.

Sources

  1. Shared Assessments, 2025; Cloud Security Alliance. SIG 1,936 / SIG Core 627; CAIQ v4 261 questions.