Your first half hour

Use the Get Started checklist, then follow five first steps that make Verity useful fast, from owning controls to attaching your first evidence.

2 min readUpdated 2 October 2026
On this page

The first screen you land on is Get Started, a setup checklist that tracks your real progress. This page explains what the checklist covers, then gives you an order of work for your first half hour.

Use the Get Started checklist#

Demonstration workspace
The Get Started checklist, with an overall progress bar and collapsible setup sections that each show how many of their items are complete

Step 1 of 6

Your progress

The bar counts the checklist items you have completed across every section.

The checklist groups setup into five pieces:

SectionWhat it covers
Set up your workspaceThe company details later steps depend on: your website, headquarters and company size.
Secure access to your workspaceWho can get in and what they have to prove: two-factor authentication on your own account, two-factor for admins, and inviting your team.
Scope your auditWhat you are audited against, and over what period: the audit type, the Trust Services Criteria and the observation window.
Work your controlsYour SOC 2 control library, owned and moving: assigning control owners and starting work on them.
Establish continuous compliance for your frameworksConnecting the systems your controls run on.

The counter at the top is your actual state, not a demonstration, and each item links straight to the screen that completes it. Open a section to see its items; each has a button, such as Complete, Invite or Assign, that takes you to the place where you finish it. Connecting systems sits outside the counter: View connections takes you to the Connections page. See How connections work.

You can leave the checklist at any time and come back. Nothing expires.

Spend your first half hour#

You do not have to do everything at once. This order gets you useful fastest.

  1. Look at your controls

    Go to Controls. Every workspace starts with the full SOC 2 control library already adopted, so this list is not empty. See Controls.

  2. Give the important ones an owner

    A control with no owner is nobody's job, and adopted controls start without one. Filter the register by Owner: Unassigned and work down the list. See Give a control an owner.

  3. Put your people in

    Go to Settings > Access Management > People. Invite the people who will own controls, approve policies and answer vendor questions. See People and invitations.

  4. Load what you already have

    Most teams already keep an asset list and a vendor list in a spreadsheet. Import your asset list (see Import assets) and add your vendors (see How vendor risk works).

  5. Attach your first evidence

    Pick one control you know you operate and attach the proof. See Evidence.

Try

    ↑ ↓ to move↵ to open