User guide

Recurring activities

For activity owners, approvers and Compliance Admins: how recurring controls are scheduled, how each period gets an evidence page, and how you complete, approve or skip a period.

  • Activity owners
  • Approvers
  • Compliance Admins

What a recurring activity is

A recurring activity is a control your company performs on a schedule, such as a quarterly user access review, a monthly vulnerability scan review or an annual penetration test. Auditors want proof that each one happened, every time it was due. Compliance in a Box gives every activity:

  • An activity page in the compliance space with the procedure to follow. These pages sit under Recurring Activities in the page tree.
  • A schedule: how often it runs, when your year starts, and how many days of notice you get.
  • An owner, who does the work, and one or more approvers, who sign off on the evidence.
  • For every period, an evidence page created under the activity page before the period is due. The owner fills it in and submits it for approval.

The activities are created with the rest of your compliance pages when a framework is set up. For the full list of SOC 2 activities, their default cadences and the controls they support, see the SOC 2 content reference.

The Activities tab

Open the app and select the Activities tab. Compliance Admins, activity owners and approvers can see it, and they see every activity, not only their own. Employees who are none of these don't see the tab.

The table has one row per activity, sorted by name (select the Activity column heading to change the order):

ColumnWhat it shows
ActivityThe activity's name. Select it to open the activity's page in the app. A red lozenge such as Page in trash, Page archived or Page deleted means the activity page was removed from the space.
CadenceMonthly, Quarterly, Semi-annual or Annual.
OwnerThe person responsible for performing the activity.
Current periodThe most recent period that has opened, with its status. Waiting for you appears when the evidence is waiting for your approval.
OverdueHow many periods of this activity are overdue, for example 2 overdue. This counts every overdue period, not only the current one.
Next dueThe next period that hasn't opened yet and its due date, for example FY2027 Q4 · due 2027-03-31.
EvidenceA link to the current period's evidence page.

The tab has no filters. To see only the work that needs you, use My Tasks instead. See Dashboard, tasks and reminders.

An activity's page

Select an activity's name to open its page in the app. From top to bottom it shows:

  • Owner and a Procedure page link to the activity page in Confluence.
  • The schedule in words, for example: "Quarterly. Periods follow a year starting in April; each is due on its last day. The evidence page is created 14 days before the due date." If the schedule was ever changed, you also see its version number, who changed it and when. Compliance Admins see an Edit schedule button here.
  • Next periods: the next three periods that haven't opened yet, with the date their evidence page will be created (Evidence page created) and the due date (Due).
  • Periods so far: every period that has opened, newest first, with its Dates, Due date, Status, a link to its Evidence page and the Actions you can take. Use Load more to see older periods.

Under each period's status you may see more detail: which submission round is waiting and for which page version (and "waiting for you" if it's yours to decide), that a round was rejected, which page version was approved, that the page was edited after approval, or who skipped the period and why.

The Actions column only shows buttons you're allowed to use: Submit (or Resubmit), Review, Withdraw and Skip. They are described in the sections below.

Period statuses

Each period of an activity has one of these statuses:

StatusMeaning
OpenThe evidence page exists and is waiting to be completed and submitted.
SubmittedThe owner submitted a version of the evidence page and the approvers are deciding.
RejectedAn approver rejected the submission. The owner revises the page and submits again.
ApprovedEvery approver approved the submitted version. The period is complete.
SkippedA Compliance Admin skipped the period with a written reason. A skipped period is closed and never overdue.
OverdueThe due date has passed and the period is not approved or skipped.

A few details about overdue:

  • A period due today isn't overdue yet. It becomes overdue the day after its due date.
  • A period that was submitted on time but is still waiting for approval after its due date is overdue. Approvers should decide before the due date.
  • Dates follow UTC, so the day changes at midnight UTC rather than in your local time zone.

How schedules work

An activity's schedule has three parts.

How often

The cadence is Monthly, Quarterly, Semi-annual or Annual. Each period starts on the 1st of a month and is due on its last day: the control is performed during the period, and its evidence is due when the period closes. For example, a quarter that runs from October to December is due on 31 December.

When the year starts

Periods line up with your fiscal year. When an activity is created, it takes its year start from Fiscal year starts in in the company profile (January if it was never set). Quarters, halves and years then count from that month.

Period names depend on the start month:

  • Year starting in January: calendar names, such as 2026 Q3, 2026 H2 or 2026.
  • Year starting in any other month: the fiscal year is named after the calendar year it ends in, with an "FY" prefix. If your year starts in April, April 2026 to March 2027 is FY2027. Its quarters are FY2027 Q1 (April to June 2026) through FY2027 Q4 (January to March 2027). Its halves are FY2027 H1 and FY2027 H2.
  • Monthly activities always use the calendar month, such as September 2026, whatever your fiscal year.

So, with an April year start, the user access review for October to December 2026 is FY2027 Q3, due 2026-12-31.

Days of notice

The days of notice decide how far ahead of the due date the period's evidence page is created. It can be any whole number from 0 to 90. The SOC 2 activities start with 14 days. For example:

  • FY2027 Q3, due 2026-12-31, with 14 days of notice: the evidence page appears on 2026-12-17.
  • The same quarter with 30 days of notice: the evidence page appears on 2026-12-01.

Use more notice for work that takes a long time to organise, such as a penetration test.

The first periods and catching up

The app checks the schedules once a day. The first time it handles an activity, it opens only the current period. Earlier periods are never created after the fact. After that, every period opens in turn. If periods were missed while the app wasn't running (for example, while the subscription was inactive), they are opened when it runs again and show as overdue. A gap that stays visible is more honest evidence than one that silently disappears.

Change a schedule

Only Compliance Admins can change a schedule.

  1. Open the Activities tab and select the activity.
  2. Select Edit schedule.
  3. Set How often, Year starts in and Days of notice.
  4. Check the preview table under "Periods from today with this schedule". It shows the next periods with their dates, when each evidence page will be created and when it is due.
  5. Select Save schedule.

What a change affects:

  • Periods that have already opened keep their dates, names and evidence pages. Nothing that already exists is moved or removed.
  • The next period to open is the first one under the new schedule that ends after the last existing period, so periods are never duplicated.
  • Every change is saved as a new schedule version and recorded in the audit log with the old and new values.

Note: Changing Fiscal year starts in in the company profile doesn't move the schedules of activities that already exist. To realign an existing activity, use Edit schedule on that activity.

If someone else changed the same schedule while you were editing, saving fails and asks you to reload, so you don't overwrite their change.

Evidence pages

When a period's notice date arrives, the app's daily run creates the period's evidence page:

  • Where: as a child of the activity page, in the compliance space.
  • Title: the activity name and the period, for example User Access Review — FY2027 Q3.
  • Content: the activity name, period and due date, a checklist of what to provide, and a heading for each item. For a user access review, that's the systems in scope, the reviewer, the users removed or changed, and the exports attached. The Annual Policy Review evidence page also starts with a list of your policies and their approval dates.
  • Who can edit: only the activity owner and Compliance Admins. Anyone who can view the compliance space can read it.

The page is yours to fill in. Write in the sections, tick off the checklist, and attach exports, screenshots or reports to the page. The app never writes to an evidence page after it creates it.

If the activity's owner changes, edit rights on the activity page and all its evidence pages move to the new owner.

Complete and submit a period

The activity owner or a Compliance Admin can submit a period's evidence. You can do it from the activity's page in the app or from the evidence page itself.

  1. Do the work the activity describes, then complete the evidence page and attach your evidence.
  2. Submit it:
    • On the evidence page, open the Compliance byline item under the page title and select Submit for approval.
    • Or, in the app, open the activity and select Submit in the period's row.
  3. Optionally, add a Note for the approvers.
  4. Select Submit.

The submission is tied to the exact page version you submitted. The approvers review that version, and their approval only ever applies to it.

Important: Editing the evidence page before it is approved cancels the submission. Finish your edits first, then submit. If you need to change something after submitting, edit the page and submit again.

If the activity has no approvers, the submit form shows No approvers and you can't submit until a Compliance Admin assigns one. See Owners and approvers.

Withdraw a submission

While a submission is waiting for approval, the owner or a Compliance Admin can take it back: select Withdraw in the period's row on the activity's page, then confirm with Withdraw. The approvers can no longer decide it, the period returns to Open, and you can submit again later.

After a rejection

If an approver rejects the evidence, the period becomes Rejected and the rejection comment is shown on the activity's page and in the evidence page's byline. Revise the page, then select Resubmit. Each submission is a new round, and the approvers decide again.

Review and approve evidence

If you're an approver for the activity, submitted evidence shows as waiting for you: Waiting for you on the Activities tab, Your approval needed on the evidence page's byline, and a task in My Tasks.

  1. Select Review, either in the evidence page's Compliance byline item or in the period's row on the activity's page.
  2. Check the submission: the round, a link to the exact page version submitted, who submitted it and when, their note, the other approvers' decisions so far, and any earlier rounds.
  3. Select Approve, or write a comment and select Reject. A comment is required to reject.

How the decision works:

  • Every approver must approve. Until they all have, the period stays Submitted and you see "Your approval is recorded; waiting for the other approvers."
  • One rejection rejects the round. The owner can then revise and resubmit.
  • The approvers are fixed when the evidence is submitted. Changing the activity's approvers later doesn't change who decides a submission that is already waiting.
  • Approval is bound to the page version. If the page was edited after it was submitted, your approval is refused and the submission is cancelled. The owner must submit the new version.
  • Self-approval is allowed but flagged. If you own the activity or submitted the evidence yourself, the review form warns you that your approval is recorded as a self-approval. Auditors may ask for an independent approver.

An approved evidence page stays editable. If someone edits it afterwards, the app shows "Edited since approval" with the approved and current version numbers, and the approval stays with the version that was approved. It doesn't move to the edited one.

For how the same approval rules work for policies, see Policies and approvals.

Skip a period

Sometimes a period legitimately doesn't need doing, for example when a system was out of scope that quarter. A Compliance Admin can skip it instead of leaving it overdue.

  1. Open the activity in the Activities tab.
  2. In the period's row, select Skip.
  3. Under Why is it skipped? (required), explain the reason in at least 10 characters.
  4. Select Skip period.

What skipping does:

  • The period becomes Skipped and is never overdue.
  • Who skipped it and the reason are shown on the activity's page and kept in the audit log for auditors.
  • If a submission was waiting for approval, it is cancelled.
  • You can skip an open, submitted or rejected period. You can't skip an approved period.

Important: A skip can't be undone. Write a reason an auditor will understand.

The Compliance byline on evidence pages

Every evidence page has a Compliance item in its byline, under the page title. Its label shows the period's state at a glance and is personal to you:

Byline labelMeaning
Your approval neededYou're an approver and this evidence is waiting for your decision.
Due and a dateThe period is open and not yet submitted.
OverdueThe due date has passed and the period isn't approved or skipped.
Awaiting approvalThe evidence was submitted and the approvers are deciding.
RejectedThe last submission was rejected.
ApprovedThe period is complete. Approved · edited since means the page changed after the approval.
SkippedA Compliance Admin skipped this period.

Select the byline item to open a panel with the activity, period and due date, the owner, the approvers of a waiting submission and their decisions, the rejection details, a link to the approved version, or the skip reason. If you can act, the panel shows Submit for approval (or Resubmit) for the owner and Compliance Admins, and Review for approvers. Withdrawing and skipping are only available on the activity's page in the app.

Owners and approvers

Every activity has one owner and can have several approvers. When the compliance pages are created, the Compliance Admin who set them up becomes each activity's owner and its first approver. Approving evidence for an activity you own counts as a self-approval, so assign the real owners and independent approvers early.

Compliance Admins assign them in the app under Settings → Owners & approvers, the same view used for policies. It is described in Policies and approvals. In short:

  • The owner performs the activity, completes and submits its evidence pages, and can edit the activity page and its evidence pages.
  • Approvers review and approve or reject each period's evidence. An activity needs at least one approver before evidence can be submitted.
  • For an independent review, choose approvers other than the owner.

When an evidence page can't be created

If the app can't create a period's evidence page, the activity's page in the app shows a warning, "Some evidence pages couldn't be created", with the period and the reason. Until the problem is fixed, the period's row shows Not created yet instead of an evidence page link. The app tries again every day, so once you fix the cause, the page appears on the next daily run.

ReasonWhat to do
Another page in the space already has the evidence page's title.The app never takes over or overwrites a page it didn't create. Rename or move the other page.
The activity's page is missing (trashed or deleted).Evidence pages are created under the activity page, so restore the activity page from the space trash.
After a schedule change, a new period has the same name as an earlier one.This can happen when the year start moves. Adjust the schedule, or contact support.
Confluence refused to create the page, or something else went wrong.Usually temporary. The app tries again every day. If it persists, contact support.

For more problems and their fixes, see Troubleshooting and FAQ. If your subscription is inactive, new periods don't open and submitting, approving, withdrawing and skipping are blocked, but you can still view everything. See Administration.

Each activity's periods, with their approvals and skips, also appear in the generated evidence reports. See Evidence, reports and audits.