Automated Microsoft Entra ID evidence collection
Auditors don't just want a policy document — they want proof: who has access, what permissions they hold, whether MFA is actually enforced, and what your configuration looked like on a given date. Pulling that out of Entra ID by hand, every audit cycle, is slow and easy to get wrong. This is on our roadmap, not shipped today — here's exactly what that means.
The problem with manual Entra evidence
- Screenshot-driven audits: Conditional Access policies, sign-in logs, and role assignments get captured as static screenshots that are stale the moment they're taken.
- Spreadsheet group membership: exporting who belongs to which security group, and cross-checking it against who should still have access, is a manual reconciliation exercise every quarter.
- No point-in-time MFA proof: "MFA is enforced" is a policy statement, not evidence — auditors want to see enforcement state at a specific date, not just today.
- Evidence rots between cycles: admin turnover, ticket sprawl, and undocumented changes mean last quarter's export often can't be reproduced or verified later.
- It repeats every cycle: SOC2, ISO 27001, and vendor security reviews all ask overlapping questions about the same Entra tenant, so the manual work gets redone from scratch each time.
What we're building — roadmap, not live
None of the items below exist in Chasa today. This is a planned connector, and we're publishing the plan early rather than waiting to announce it as finished. Track live status on our Trust Center.
- User access exports: pulling a full list of Entra ID users and their assigned roles into a structured, exportable record.
- Group membership evidence: a point-in-time snapshot of security group membership, so "who had access when" is answerable months later.
- Permission mapping: tying role assignments back to the systems and data they actually grant access to, not just the role name.
- MFA enforcement proof: evidence that Conditional Access / MFA policies were active and applied to the relevant users at a given date — not just a policy toggle.
- Configuration snapshots: periodic captures of tenant-level security settings, so drift between audit cycles is visible instead of assumed away.
- Audit-ready PDF/JSON exports: evidence packaged in a format an auditor or security reviewer can consume directly, instead of a folder of screenshots.
Why Chasa, and why now
This isn't a cold start. Chasa already runs an evidence-automation model in production today, just scoped to accounts receivable: every AI-drafted invoice chase requires a human to review and hit send, and that approval step creates a timestamped, auditable record — which is exactly the pattern financial controllers use for SOX AR evidence automation right now. Microsoft Entra ID is the next connector we plan to build using that same approach — human-verified, timestamped, exportable evidence — extended from AR audits into general access and identity evidence for SaaS compliance. See the full category context on our evidence automation page, and how it lines up against SOC2 and ISO 27001 evidence needs.
Use the part of Chasa that's live today
Chasa's AI-drafted, human-approved invoice follow-ups — with QuickBooks/Xero/CSV sync, HMAC-signed webhooks, and role-based workspace access — are live right now. Entra ID evidence is what we're building next.
Auditing on a deadline? Talk to us about your audit timeline and we'll tell you honestly whether our roadmap fits it.