Customer control owners attach records from the systems where the work occurred. Use configuration exports or policy state, identity and privileged-access reviews, event and monitoring records, approved changes, vulnerability and patch records, backup and recovery tests, incident exercises or records, and termination tests as applicable to the allocated activities.
Reconcile each shared activity across both sides. For incident handling, the evidence should show the reportable scope, disclosure level, notification target time, reporting route, contacts, status tracking, and any stated remedies. For monitoring, record which service aspects the customer can observe and whether access is limited to its own instances. For exit, keep the documented assets, return or export method, removal schedule, deletion expectations, and responsible parties.
If provider evidence describes a capability that the customer has not enabled, configured, monitored, or tested, mark the responsibility line incomplete. Provider availability does not show customer implementation.