
Asana
Access
Task Management
Mycroft uses Asana task records as evidence that periodic reviews, assessments and remediation work were completed.
Policy reviews, vendor assessments and training rollouts are recurring controls an auditor samples. Mycroft reads the owner, due date, approval status and completion time on each task, and includes workspace membership in access reviews.
How Mycroft connects to Asana
- How it connects
- You authorize Mycroft against your Asana workspace.
- What Mycroft can access
- Read-only workspace membership and task data.
Which controls Asana evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Asana to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Asana |
|---|---|---|---|
| SOC 2 | CC3.2 | Identified risks are analysed and addressed. | Remediation and risk treatment tasks with owner, due date, approval status and completion timestamp. |
| SOC 2 | CC2.2 | Internal information supporting internal control is communicated. | Task assignment and comment history showing that control responsibilities were communicated to named owners. |
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Workspace member and guest inventory with access level, reconciled against the current workforce roster. |
| SOC 2 | CC9.2 | Vendor and business partner risks are assessed and managed. | Vendor review tasks with assessment completion dates and approval records where vendor due diligence runs through Asana. |
| ISO 27001 | A.5.18 | Access rights are provisioned, reviewed and revoked. | Workspace and project membership including external guests, surfaced in the periodic access review. |
| ISO 27001 | A.5.36 | Compliance with policies and standards is monitored. | Policy review and attestation tasks with owner, due date and completion evidence for each cycle. |
What Mycroft collects automatically
Gathered from Asana on a schedule, dated and stored against the controls above.
- Task records with assignee, due date, approval status and completion timestamp
- Project membership and task history for compliance workstreams
- Workspace member and guest inventory with access levels
- Approval records where Asana approvals gate a compliance activity
- Recurring task completion history for periodic reviews and attestations
Manual work this removes
The tasks that disappear from someone's quarter once Asana is connected.
- Screenshotting completed tasks to evidence a policy review
- Maintaining an audit-preparation tracker separate from the team's board
- Building the workspace membership list, including guests, for access reviews
- Requesting status updates on tasks that already show their status
Asana and Mycroft: frequently asked questions
What can Mycroft see in Asana?
How does an Asana task serve as compliance evidence?
Can Mycroft create tasks in Asana?
We turn the compliance nightmare into a dream
Talk to us


