Read at a desk rather than followed with a phone in your hand. These are decisions and rounds, not taps.
Your first hour
About 40 minutesName the organisation and answer the regulated-data questions, which is what derives your frameworks rather than you picking them off a list. Then bring assets in before anything else: an empty register teaches you nothing about whether the product fits. Import a spreadsheet or connect one source, and leave the rest for later.
- Answer the setup questions honestly, including the ones about regulated data. They decide which of the 12 standards apply to you.
- Choose where the register lives. This governs every sync afterwards and is not easy to change later.
- Import a spreadsheet, or connect Intune, Entra, Jamf Pro or Okta.
- Print QR labels for anything you will be verifying by hand.
Bringing in a spreadsheet you already have
About 15 minutesYou do not have to reshape your file first. Columns are matched by looking at the values, not just the headers, so a column called “Who” full of names is recognised as an assignee. Columns that are yours alone become typed custom fields rather than being dropped. Repeated vendors and contracts in the sheet become one record each, with the assets linked to them.
- Point it at the file. Nothing is written until you confirm the mapping.
- Check the columns it could not place; those become custom fields if you want them.
- Confirm. The import is logged before it writes, and can be undone in the same session.
Running a verification round
Depends on the estateVerification is the thing auditors actually test: not that a spreadsheet exists, but that somebody laid eyes on the machine. This is what the phone is for, and the step-by-step version of the phone half is above.
- On the Mac, filter to what has not been verified inside your policy window.
- Walk the floor with the phone. Read the tag, cross-check the serial by barcode or OCR, confirm you have seen it.
- Reassign custody on the spot if the machine has moved. The change records whether or not the Mac is awake.
- Back at the desk, the round shows in the trail with who acted and when.
Producing an audit evidence pack
MinutesThe pack is assembled from what the register already holds, so the work happens before the auditor arrives rather than during. Your inventory is mapped to 66 controls across 12 standards, and 15 evidence reports are kept ready.
- Open Compliance and check the coverage for the framework being tested.
- Generate the Audit Evidence Pack: full inventory, audit trail, sanitization certificates and worklists.
- Every artifact in the pack is mapped to the control it answers, so you are handing over an index rather than a folder.
Retiring a machine so it stands up later
A few minutes per machineDisposal is where most registers quietly fail an audit, because the evidence chain is the thing being tested and it is usually the thing nobody kept. Manifest records it as a chain rather than a status change.
- Record the sanitization category against NIST SP 800-88: clear, purge or destroy.
- Name the witness and the authoriser, and attach the wipe certificate.
- The record stays in the register. A machine that was disposed of still happened, and its record is the artifact an auditor asks for.