Performance Reviews Overview
What Kit's Performance module is, the SOC 2 CC1.4/CC1.5 evidence wedge, and what's included.
Why It Matters
Every SOC 2 Type II audit asks the same two questions about your people: does the organization evaluate competence (CC1.4), and does it hold individuals accountable for their responsibilities (CC1.5)? The standard evidence is a documented performance review process — a written cadence, a completed and dated review per sampled employee, and a completion tracker covering 100% of staff. Most startups scramble to reconstruct this the week before the audit, and backfilled records betray themselves through batch-created timestamps.
Kit’s Performance module runs the reviews and mints the evidence in the same motion. You run a review cycle — manager, self, and optional peer reviews against a structured template — and when you finalize it, Kit freezes one immutable, timestamped evaluation record per participant. The register, the per-person evidence PDF, and the Vanta-shaped CSV export are byproducts of work you were doing anyway, not a separate compliance project.
Note
Performance is included in Kit’s flat $8/seat plan — no separate module fee, no per-feature add-on, no minimum headcount.
Who It’s For
| Persona | Goal | Primary Pain |
|---|---|---|
| Founder / CTO | Pass SOC 2 CC1.4/CC1.5 without a dedicated HR stack | Perf platforms floor at 50 employees or $4k/yr; audit evidence is reconstructed by hand |
| People Lead / Manager | Run fair, consistent review cycles and actually finish them | Chasing reviewers in Slack; free-form docs with no structure; no completion visibility |
| Employee | Understand expectations, get credited for real work, keep a record | Reviews ignore shipped work; AI-era contributions (enablement, direction) go unseen |
How Kit Compares
The sub-50-employee performance lane is structurally underserved. Verified pricing and positioning:
| Product | Price | Segment floor | SOC 2 evidence framing | AI + work-tool evidence | MCP |
|---|---|---|---|---|---|
| Lattice | $10–13/seat | $4k/yr minimum, mid-market | No | No | No |
| 15Five | $4–16/seat | Mid-market (~100+) | No | AI-assisted reviews only | No |
| WorkStory | $9.35–11/user | ~25–250, chat-native | No | One-click AI, no code-host sync | No |
| Windmill | $10/user (10 free) | 20–75 startups, Slack-native | No | Yes (GitHub/Linear/Jira sync) | No |
| Kit | Included in $8/seat | None | Yes — CC1.4/CC1.5 by design | Yes — GitLab signals, fetch-on-demand | Included |
Three things set Kit apart. First, bundling: performance ships inside the same $8/seat that already covers hiring, security training, and your VDP — a startup buying Windmill pays $10/seat for performance alone. Second, SOC 2 framing: no competitor markets reviews as CC1.4/CC1.5 audit evidence; Kit mints the register, the immutable records, and the Vanta-shaped export natively. Third, MCP included: Confirm charges +$3/person/month for MCP access and only sells above 50 employees; Kit ships Performance MCP tools to every account as standard.
The Core Loop
- Define a template — rating and competency questions on a 1–N scale, published before use (Templates and Questions)
- Create a cycle — “H1 2026”, pick a cadence, add participants; managers and self-reviews are assigned automatically (Review Cycles)
- Activate — the question set is frozen, reviewers are notified, and reviews open (Writing Reviews)
- Draft with AI (optional) — evidence-based drafts from goals, prior reviews, and opt-in work signals; a human always edits and submits (AI-Drafted Reviews)
- Finalize — one immutable evaluation record per participant, then export the register for your auditor (SOC 2 Evidence and Exports)
What’s Included
| Feature | Description |
|---|---|
| Review cycles | Annual, semi-annual, quarterly, or ad hoc; draft → active → finalized → archived lifecycle |
| Review templates | Versioned rating + text questions with optional competency tags, snapshotted at activation |
| 360-lite reviews | Manager + self-review by default, named peer reviewers on demand |
| Manager map | One report→manager edge per person seeds each cycle’s default reviewer |
| Goals and check-ins | Lightweight personal goals with progress check-ins that feed review evidence |
| AI-drafted reviews | Evidence-gathering drafts with a hard human-accountability gate — the AI never submits |
| Work signals (GitLab) | Opt-in, fetch-on-demand merged MRs and review activity cited in drafts; nothing warehoused |
| Evaluation register | The SOC 2 completion tracker — live progress while running, frozen snapshots once finalized |
| Immutable evidence records | Append-only, encrypted, timestamped snapshots per participant; updates and deletes are refused |
| Exports | Vanta-style CSV and branded PDF register, plus a per-person evaluation document PDF |
| Review reminders | Automatic nudge and last-call emails against the cycle due date |
| MCP tools + AI assistant | Seven MCP tools under performance_read/performance_write scopes, plus the in-app agent |
Quick Checklist
- Grant your team the Performance module in Team settings (the People Lead preset gets admin)
- Map managers in Performance > Managers
- Create and publish a review template in Performance > Templates
- Create your first cycle in Performance > Review cycles
- After finalizing, download the register CSV for your compliance folder
Next Steps
- Review Cycles — cadence, participants, and the cycle lifecycle
- SOC 2 Evidence and Exports — what your auditor samples and how Kit produces it