How to collect soc 2 audit evidence as Small HR Teams
Every SOC 2 audit cycle, your 2-person HR team becomes the collection point for evidence that touches every system you manage: termination records in Paylocity or ADP, access review confirmation emails buried in Gmail threads, onboarding checklists you built in Notion, offer letters in Google Drive, and background check completions scattered across whatever vendor your company chose last year. The auditor sends a request list with 40 line items. You spend two weeks chasing managers over Slack, re-exporting payroll reports, and reformatting spreadsheets so they match the auditor's template. There is no single place that holds all of it, and every audit you start from scratch.
What you'll set up
Apps, data, and prompts
The combination of Starch apps, the data sources they pull from, and the prompts you use to drive them.
Starch syncs your Paylocity data on a schedule (employee records, payroll runs, termination history) and connects directly to ADP if that's your payroll system. Gmail is synced on a schedule so the email agent reads audit-related threads and drafts replies. Notion is synced on a schedule as the evidence library backbone. Google Drive and any HR document storage (BambooHR, Greenhouse) are reachable via Starch's integration catalog — the agent queries them live when building evidence bundles. Background check portals without a direct API are automatable through your browser — no API needed.
Step-by-step
See this running on Starch
Connect your tools, describe what you want, and the agent builds it. Closed beta is free.
April 2026 SOC 2 Type I prep — 150-person company, 40-item HR evidence request
| Controls auto-satisfied from Paylocity sync (hire/term roster, payroll runs) | 14 |
| Controls requiring document collection (background checks, offer letters, access reviews) | 18 |
| Controls requiring manager confirmation emails | 8 |
| Hours spent on manual evidence collection in prior audit | 32 |
| Hours spent with Starch workflow in current audit | 9 |
In April 2026, your auditor sends a 40-item HR evidence request with a two-week window. Fourteen of those items — termination dates for the 6 employees who left in the past year, the current employee roster with start dates, and the last 4 payroll run records — are already in Starch because Paylocity syncs on a schedule. You mark those 14 controls 'collected' in under 10 minutes. The remaining 26 require documents or confirmation emails. The Email Agent finds 9 relevant emails already in your Gmail — background check completion notices from Checkr and 3 IT access-removal confirmations — and attaches them to the correct Notion control records automatically. Starch drafts follow-up emails to the 7 managers who haven't submitted access review sign-offs and the IT lead who needs to export the user access log. By day 5 of a 14-day window, you have 33 of 40 controls satisfied. The final 7 are flagged in the Task Manager with owner names and due dates. You spend 9 hours total on this audit compared to the 32 hours your team logged last year chasing the same information across the same systems.
How you'll know it's working
What this replaces
The other ways teams handle this today, and how the Starch version compares.
One platform — knowledge management, email agent, task manager all running on connected data. Setup in plain English; numbers stay current via scheduled syncs and live agent queries.
Try it on Starch →Frequently asked questions
Does Starch actually connect to Paylocity, or do I have to export files manually?
We use BambooHR, not Paylocity. Does this still work?
Is Starch SOC 2 certified itself?
Can Starch collect evidence from tools that don't have an API — like our background check vendor's portal?
What about access review evidence? That usually means chasing IT and every department head.
We don't have a dedicated compliance tool. Will Starch replace one?
Can the evidence library in Notion actually stay current between audits, or will it go stale like every other Notion we've built?
Related guides for Small HR Teams
A customer knowledge base is the document — or collection of documents — that answers the questions your customers ask repeatedly.
Read guide →A Slack announcement sounds simple — you're just telling your team something.
Read guide →Benefits enrollment is one of those operator workflows that looks manageable until it isn't.
Read guide →Employee offboarding is the set of steps you run every time someone leaves — voluntary or not.
Read guide →Collect SOC 2 Audit Evidence for other operators
The AI stack built for small in-house legal and compliance teams.
Read guide →The AI stack built for small IT and ITOps teams.
Read guide →The AI stack built for the founder's office.
Read guide →The AI stack built for small finance teams.
Read guide →Ready to run collect soc 2 audit evidence on Starch?
Request closed-beta access. Everything is free during beta.