Asana logo

Asana

Access
Task Management

Mycroft uses Asana task records as evidence that periodic reviews, assessments and remediation work were completed.

Policy reviews, vendor assessments and training rollouts are recurring controls an auditor samples. Mycroft reads the owner, due date, approval status and completion time on each task, and includes workspace membership in access reviews.

How Mycroft connects to Asana

How it connects
You authorize Mycroft against your Asana workspace.
What Mycroft can access
Read-only workspace membership and task data.

Which controls Asana evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Asana to satisfy it. Collection runs on a schedule and every result is timestamped.

Asana compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Asana
SOC 2CC3.2Identified risks are analysed and addressed.Remediation and risk treatment tasks with owner, due date, approval status and completion timestamp.
SOC 2CC2.2Internal information supporting internal control is communicated.Task assignment and comment history showing that control responsibilities were communicated to named owners.
SOC 2CC6.1Logical access controls restrict access to information assets.Workspace member and guest inventory with access level, reconciled against the current workforce roster.
SOC 2CC9.2Vendor and business partner risks are assessed and managed.Vendor review tasks with assessment completion dates and approval records where vendor due diligence runs through Asana.
ISO 27001A.5.18Access rights are provisioned, reviewed and revoked.Workspace and project membership including external guests, surfaced in the periodic access review.
ISO 27001A.5.36Compliance with policies and standards is monitored.Policy review and attestation tasks with owner, due date and completion evidence for each cycle.

What Mycroft collects automatically

Gathered from Asana on a schedule, dated and stored against the controls above.

  • Task records with assignee, due date, approval status and completion timestamp
  • Project membership and task history for compliance workstreams
  • Workspace member and guest inventory with access levels
  • Approval records where Asana approvals gate a compliance activity
  • Recurring task completion history for periodic reviews and attestations

Manual work this removes

The tasks that disappear from someone's quarter once Asana is connected.

  • Screenshotting completed tasks to evidence a policy review
  • Maintaining an audit-preparation tracker separate from the team's board
  • Building the workspace membership list, including guests, for access reviews
  • Requesting status updates on tasks that already show their status

Asana and Mycroft: frequently asked questions

Read-only workspace membership and task information, used for access reviews and remediation tracking.
For periodic controls (policy reviews, vendor assessments, training rollouts) the auditor asks whether the activity happened, who did it and when. A completed task with an owner, a completion timestamp and an approval record answers all three without a separate tracker.
Optionally, and only in one project you designate. Compliance and remediation items can be raised there with their detail and due date, then followed to completion through the task's own status. The connection can equally be left read-only.

We turn the compliance nightmare into a dream

Talk to us