Open source
EvidenceFlows by AssureSwarm
AssureSwarm publishes EvidenceFlows, an open-source set of more than 200 audit, SOX, regulatory, controls and department workflow templates, with a runner that takes one person through a template step by step.
EvidenceFlows is free and runs in your browser. Nothing you type or upload leaves your machine. AssureSwarm adds what a team needs: approvals tied to named users, agents through the MCP, linked risk and control data, dashboards and retention.
What you can do for free
- Download any template as a JSON file and reuse it under the CC BY 4.0 license.
- Run a template in your browser. Edit a step's instructions for your run, fill in its forms and attach files; each file is listed with its name, size and SHA-256 hash.
- Sign off a step with your name and role. Signing locks the step until you reopen it.
- Export a printable workpaper of the run, and a run package (the run, its template and its attachments in one zip) that you can keep or open in another browser.
What AssureSwarm adds
| EvidenceFlows | AssureSwarm |
|---|---|
| Local sign-off by the person at the keyboard | Approvals tied to authenticated users, each assigned a review level, with a history of withdrawn approvals |
| No agent access | Agents read step context and upload evidence through the MCP. Any change an agent proposes waits for a named person to approve it. |
| Each run stands on its own | Steps link to risks, controls and other items, with custom fields and lists |
| A printable workpaper for each run | Dashboards for workflow runs, overdue issues, control coverage and owner workload |
| Runs live in this browser and are lost if its site data is cleared, unless you export them | Documents stored, locked, hashed and retained, with an audit log of every action |
| Export a customized template | Import customized templates today; import of finished runs, with their results and sign-offs, is coming |
How local sign-off works
Local sign-off records who signed, when, and a hash of exactly what was signed. It is an attestation by the person at this keyboard. For approvals tied to authenticated users with an audit trail, use AssureSwarm.
From a run to AssureSwarm
In your run, choose “Import into my AssureSwarm” to download an import file, then open the AssureSwarm admin import and select it. The workflow arrives as a new template with your edited instructions, and your team can attach it to its audits, controls and other items. “Export customized template” saves the edited template as a library JSON file for running again locally. Import of a finished run, with its results and sign-offs, is coming.