Skip to content

Evidence from the clipboard

Most compliance evidence is a screenshot: a console showing MFA enforced, a policy banner, a backup job that succeeded. The slow part is never the capture — it is the detour through the desktop, naming the file, finding it again in a file picker, and deleting it afterwards. CyberGuard skips that: with a screenshot on your clipboard, paste it directly onto the evidence form and it becomes the attachment.

Take the screenshot with whatever puts an image on the clipboard on your platform — for example Cmd+Ctrl+Shift+4 on macOS, Shift+Windows+S on Windows, or the region-capture shortcut of your Linux desktop.

Then open the evidence creation form, click anywhere on it so the page has focus, and press Cmd+V or Ctrl+V. The image lands in the Attachment field, exactly as if you had chosen a file. Fill in the name and the rest of the form and save.

The filename is generated from the moment you pasted — date, time and milliseconds, with the image’s own extension. It is unique, so nothing you paste can silently overwrite anything else, but it is not descriptive. The Name you give the evidence is what people will read, so make that one say what the screenshot proves.

Pasting is available on the attachment field of:

  • the evidence creation form,
  • the evidence revision form, when you attach a fresh capture to an existing evidence,
  • the domain form, for a domain image.

Only images are picked up. Pasting a copied file from a file manager, or a block of text, does nothing to the field — use the file picker for those. If the paste appears not to work, the usual cause is that the clipboard holds a file reference rather than image data: re-take the screenshot with a capture shortcut rather than copying the saved file.

  • Capture the whole frame. Include the URL bar, the tenant or account name, and a visible timestamp where you can. A cropped screenshot with no context is the one an assessor asks about.
  • One claim, one evidence. Resist stitching four screenshots into one image. Separate evidence objects can be linked to different requirements and superseded independently.
  • Say what it shows, not what it is. “Conditional access policy requiring MFA for all admins, 16 Sep 2026” beats “screenshot 3”.
  • Attach it while you are there. Creating evidence from inside a requirement assessment links it to that requirement immediately; creating it standalone means going back to link it later.
  • Mind the sensitive pixels. A pasted screenshot goes straight in, so redact tokens, customer names and personal data before you capture, not after.
  • Evidences — the full evidence model, revisions and links.
  • Audits — attaching evidence while answering requirements.
  • General tips — where evidence fits in the wider workflow.