Bylaw | Evidence — my weekly field notes on the risks companies face and how to prove they’re handled

On-site, where the internet can’t reach.

Some of your most important controls don’t live in any system — a locked server room, how documents are shredded, the visitor log at the front desk, the posted procedure on the wall, the physical safeguards an auditor still asks to see. Those get captured on-site, in real time, and governed in the same record that watches everything else.

On-site governance capture

The controls software can’t see.

Most evidence is read straight from your systems. But auditors, insurers, and regulators also ask about the physical and human controls no API exposes. I capture those in person — photographed, witnessed, timestamped, and signed — and fold them into the same governed record as everything online.

  • Physical access — server rooms, records storage, restricted areas.
  • Document handling — shredding, disposal, retention, clean-desk.
  • Posted procedures, signage, and emergency or continuity plans.
  • Visitor logs, badge access, and on-site identity checks.
  • Device and media disposal, and hardware chain-of-custody.
  • On-site training, drills, and staff attestations.

Click-and-capture, in person.

I walk the site myself, capturing each control with the Bylaw method. Each physical or human control is captured at the source — a photo, a reading, a witnessed check — tagged to the rule it proves, timestamped, and hash-chained exactly like a signal pulled from a system. IT-only tools can’t see past the network; this is the part of governance they leave on the table.

From there it behaves like every other observation. The same edge wall blocks identifiers before anything is stored, the capture is sign-off-gated, and it lands in the same standing record as your cloud, identity, and productivity proof. On-site checks run on a cadence — quarterly or annual — so the physical posture stays current instead of being reconstructed the week an auditor arrives.

One walk-through answers the physical and procedural controls behind HIPAA physical safeguards, SOC 2 physical security, ISO 27001 Annex A, and most enterprise and insurer site reviews — captured in real time, governed in one place with everything else.