Component proving ground

Every value below is invented. Nothing here was computed, fetched or judged, and no part of it reflects real evidence. It exists so the states that must never look alike can be compared side by side.

Outcome — the only coloured element

Two vocabularies at two grains, one visual axis. Register density is the word alone in the outcome colour; detail density is a chip. Two of the five carry no hue at all, because the absence of a conclusion does not belong on a good-to-bad axis.

wire valueregisterdetail
effectiveEffectiveEffective
partially_effectivePartially effectivePartially effective
deficientDeficientDeficient
unable_to_concludeUnable to concludeUnable to conclude
compliantCompliantCompliant
partially_compliantPartially compliantPartially compliant
non_compliantNon-compliantNon-compliant
not_testedNot testedNot tested
wat_is_ditwat_is_ditwat_is_dit
null

The last two rows are the fallbacks: an unrecognised value is shown verbatim and without a hue, and a missing one is an em dash. Neither is allowed to borrow a colour it did not earn.

Severity — no hue, ever

Outcome and severity are orthogonal fields on the same finding, and only one of them can be what colour means. Weight steps up at high and critical; nothing else does.

lowmediumhighcriticala null severity renders nothing at all

Figures and timestamps

Fractions stay fractions. A timestamp states its zone before hydration and switches to the reader's on mount, so it is never a time in an unstated zone.

evidence collected
2 of 3
findings
0
controls in scope
1,204
not measured
last analyzed
never analyzed
unparseable
not-a-date

The four things a finished item can say with no deficiency

All four carry status === "analyzed". Read them as shapes before reading the words: a dashed panel waiting for a person, a heavy rule at full height twice over, and one result that is allowed to look settled.

analyzed · no control_idno-control

No control assigned — nothing was tested.

The screenshot was read and its elements extracted, but no control was attached to it, so no criteria were ever applied. There is no conclusion here to agree or disagree with.

analyzed · control_id set · judgment_failedjudgment-failed

Analysis did not complete.

This is a system failure, not an audit conclusion — do not read it as “no exception”.

judgment failed: 503 The model is overloaded. Please try again later. (request id 9f2c…)

analyzed · control_id set · no findings · no failure recordedno-judgment

No conclusion was recorded.

A control is assigned and the extraction succeeded, but no judgment exists and nothing recorded a failure. This item has not been tested — do not read it as tested.

The evidence endpoint cannot yet tell “judgment has not started” from “judgment never dispatched”. Until a job stage is reported, saying so is more accurate than picking one.

analyzed · 3 findings · none deficientno-deficiencies

3 findings·1Partially effective·2Effective

Judgment ran and none of its conclusions is a deficiency. Each one still needs a person to adopt it.

Review the findings

Failure, on its own

Not red. Red is a dropped connection or a failed submit, and it never appears beside a conclusion — including where a conclusion is missing.

Analysis did not complete.

This is a system failure, not an audit conclusion — do not read it as “no exception”.

judgment failed: connection reset by peer

The same rule, at ordinary length.

One grammar for everything the application says in its own voice, so a reader learns it once.

Paper

The application is the desk; the workpaper is paper on it. Warm white against cool grey, square corners, a real margin, a 72ch measure, and serif — because serif means this text is going into the deliverable.

WP-COMPA-01 · CBCS BC-4.2 · FY2026

Backup job monitoring — design effectiveness

The control requires that failed backup jobs are identified and remediated within one business day. Evidence collected consists of a screenshot of the backup console taken on 4 September 2026, showing job status for the preceding seven days.

Two of the seven days show a failed job. Both were followed by a successful re-run within the same day, and the console records the operator who acknowledged each one.

Sans, inside the sheet, for text that is about the document rather than in it — this note would not appear in the exported workpaper.

Box registration

The claim this product rests on is that a conclusion points at specific pixels. These boxes are positioned in percentages of the rendered image, so they need no resize listener and survive zoom, device-pixel-ratio changes and column reflow — and the container they sit in is exactly the image's box, with no border or padding, because either would offset every box by its own width. Boxes rest as hairlines and take the accent only when pointed at, so the evidence underneath stays readable. E arrived with its coordinates inverted; it is normalized, drawn dashed, and not silently dropped.

A synthetic target: grey blocks at known normalized coordinates.

Resize the window or zoom the browser: every box should stay on its block at any size, because nothing here is measured in pixels.

Did it run?

Colour in this product means outcome, and none of these six stages is an outcome — so state is carried by the left rule instead: 2px solid for a stage that ran, 4px (the Notice weight) for one that failed, 2px dashed and faded for one that did not run at all. Every stage renders in every state. A pipeline that hides its skipped stages is not a shorter page, it is a page that lies about being complete. Two stages are marked no model, because which parts were not the AI is a question an auditor has to answer to their own reviewer.

Everything ran

Six stages, two of them without a model. This is the only one of the four that may be read as a result.

How this item was processed

Every stage ran. Each states what it produced; open Details for the model, prompt and token record.

  1. 1

    Upload

    no modelRan

    The file was received and stored under its content hash.

    Details
    type
    image/png
    sha256
    0f9c2e1b7a4d6f83c5e0b1a9d7f4e2c8b6a0d3f5e7c9b1a3d5f7e9c1b3a5d7f9
  2. 2

    Integrity check

    no modelRan

    The bytes decode as an image. These are observations, not a tamper verdict.

    Details
    decodable
    yes
    format
    PNG
    width
    1964
    height
    1018
    has metadata
    no
  3. 3

    Extraction — Pass 1

    Ran

    Read 5 elements off the screenshot, each with a bounding box.

    Details
    model
    gemini-2.5-pro
    prompt template
    azure_ad_conditional_access @ 1.0
    input tokens
    2,431
    output tokens
    918
    total tokens
    3,349
    requests
    1
  4. 4

    Control assignment

    no modelRan

    A control is assigned, so judgment had something to test against.

    Details
    control id
    00000000-0000-0000-0000-0000000000cc
  5. 5

    Judgment — Pass 2

    Ran

    Produced 1 finding against the assigned control.

    Details
    model
    anthropic:claude-opus-4-8
    confidence
    0.82
    reasoning log
    not recorded for Pass 2 — the `pass` column arrives in migration 0013
  6. 6

    Severity

    no modelRan

    Graded from the framework pack's rules, not proposed by the model.

    Details
    severity
    high
No control assigned

Judgment is gated on `evidence.control_id`. Nothing crashed; nothing was tested either.

How this item was processed

3 of 6 stages did not run. Read what each of them says before treating this item as complete — an item that was never judged is not an item with no exceptions.

  1. 1

    Upload

    no modelRan

    The file was received and stored under its content hash.

    Details
    type
    image/png
    sha256
    0f9c2e1b7a4d6f83c5e0b1a9d7f4e2c8b6a0d3f5e7c9b1a3d5f7e9c1b3a5d7f9
  2. 2

    Integrity check

    no modelRan

    The bytes decode as an image. These are observations, not a tamper verdict.

    Details
    decodable
    yes
    format
    PNG
    width
    1964
    height
    1018
    has metadata
    no
  3. 3

    Extraction — Pass 1

    Ran

    Read 5 elements off the screenshot, each with a bounding box.

    Details
    model
    gemini-2.5-pro
    prompt template
    azure_ad_conditional_access @ 1.0
    input tokens
    2,431
    output tokens
    918
    total tokens
    3,349
    requests
    1
  4. 4

    Control assignment

    no modelDid not run

    No control is assigned. Judgment cannot run without one, and did not.

    No record to show.

  5. 5

    Judgment — Pass 2

    Did not run

    Did not run — there was no control to judge against.

    Details
    reasoning log
    not recorded for Pass 2 — the `pass` column arrives in migration 0013
  6. 6

    Severity

    no modelDid not run

    Nothing to grade — no finding was produced.

    No record to show.

Judged, produced nothing

The dangerous one. Analysed, control assigned, no finding, no error — the shape a reviewer reads as “no exceptions”.

How this item was processed

2 of 6 stages did not run. Read what each of them says before treating this item as complete — an item that was never judged is not an item with no exceptions.

  1. 1

    Upload

    no modelRan

    The file was received and stored under its content hash.

    Details
    type
    image/png
    sha256
    0f9c2e1b7a4d6f83c5e0b1a9d7f4e2c8b6a0d3f5e7c9b1a3d5f7e9c1b3a5d7f9
  2. 2

    Integrity check

    no modelRan

    The bytes decode as an image. These are observations, not a tamper verdict.

    Details
    decodable
    yes
    format
    PNG
    width
    1964
    height
    1018
    has metadata
    no
  3. 3

    Extraction — Pass 1

    Ran

    Read 5 elements off the screenshot, each with a bounding box.

    Details
    model
    gemini-2.5-pro
    prompt template
    azure_ad_conditional_access @ 1.0
    input tokens
    2,431
    output tokens
    918
    total tokens
    3,349
    requests
    1
  4. 4

    Control assignment

    no modelRan

    A control is assigned, so judgment had something to test against.

    Details
    control id
    00000000-0000-0000-0000-0000000000cc
  5. 5

    Judgment — Pass 2

    Did not run

    Did not run, and produced nothing. This is not the same as finding no exceptions.

    Details
    reasoning log
    not recorded for Pass 2 — the `pass` column arrives in migration 0013
  6. 6

    Severity

    no modelDid not run

    Nothing to grade — no finding was produced.

    No record to show.

Judgment failed

A crash, carried as `judgment_failed` with the backend's own sentence. Still six stages: the page does not get shorter when it has less to say.

How this item was processed

A stage failed. Nothing below it should be read as a conclusion about the control, and 1 later stage did not run as a result.

  1. 1

    Upload

    no modelRan

    The file was received and stored under its content hash.

    Details
    type
    image/png
    sha256
    0f9c2e1b7a4d6f83c5e0b1a9d7f4e2c8b6a0d3f5e7c9b1a3d5f7e9c1b3a5d7f9
  2. 2

    Integrity check

    no modelRan

    The bytes decode as an image. These are observations, not a tamper verdict.

    Details
    decodable
    yes
    format
    PNG
    width
    1964
    height
    1018
    has metadata
    no
  3. 3

    Extraction — Pass 1

    Ran

    Read 5 elements off the screenshot, each with a bounding box.

    Details
    model
    gemini-2.5-pro
    prompt template
    azure_ad_conditional_access @ 1.0
    input tokens
    2,431
    output tokens
    918
    total tokens
    3,349
    requests
    1
  4. 4

    Control assignment

    no modelRan

    A control is assigned, so judgment had something to test against.

    Details
    control id
    00000000-0000-0000-0000-0000000000cc
  5. 5

    Judgment — Pass 2

    Failed

    judgment failed: upstream returned 529 after 3 attempts

    Details
    reasoning log
    not recorded for Pass 2 — the `pass` column arrives in migration 0013
  6. 6

    Severity

    no modelDid not run

    Nothing to grade — no finding was produced.

    No record to show.

Register density, at 200 rows

The scale the register is actually used at, rendered through the shipped component rather than a mock. Rows are monochrome: exactly one element carries a hue — the conclusion word — and severity, which is the other axis a reviewer sorts on, gets none at all. The adoption rule under each conclusion is the finding byline's mechanism at 36px: solid where a human stands behind it, dashed where nobody does, absent where there is nothing to adopt. Control refs come from three frameworks with different shapes, titles run from 9 to 118 characters, and the counts include four digits, because a column that only aligns for the data you had is not aligned.

Owner and test type (DE/OE) are not shown: no control in this engagement has a test scoped yet, so every row would be empty. The evidence figure is a count rather than a fraction for the same reason — the denominator comes from what each test says it expects.

A conclusion, and the four ways of standing behind it

The terminal decision. The design problem is not presenting a conclusion — it is presenting one a machine reached without it acquiring the authority of one a person reached. The byline is the mechanism: an unadopted finding carries a drawn, empty signature line, the same shape a paper workpaper uses, so it costs nothing from the rationed accent and survives a photocopy and a screen reader intact. An override is shown as a change, never as a value — a severity a reviewer raised is a different artefact from one the model produced alone, and the two are identical if you print only the effective value. Confidence is the model's own number and is labelled as such; there is no bar, no quality word, and no tick.

Machine conclusion, unadopted

The default state, and the one a reviewer must never mistake for a settled one. The signature line under 'adopted' is drawn and empty.

Finding

Deficienthigh

MFA is not enforced for three accounts excluded via the break-glass group.

ConditionWhat was observed in the evidence.
Multi-factor authentication is not enforced for 3 of the 12 accounts shown in the Conditional Access policy list. The excluded accounts are members of the break-glass group.
CauseWhy the condition exists.
The Conditional Access policy grants an exclusion to the break-glass group, and membership of that group has not been reviewed since the policy was created.
EffectWhat the condition puts at risk.
An attacker holding a valid password for any of the three excluded accounts can authenticate from outside the corporate network without a second factor.

Cites

  • element 1
  • element 4

model confidence 82% — the model’s own number, not a measure of whether it is right.

computed
anthropic:claude-opus-4-8 ·
adopted
not yet adopted

Affirmed

A person agreed with the machine and changed nothing. Same values, signed line — the only difference between this and the state above is who stands behind it.

Finding

Deficienthigh

MFA is not enforced for three accounts excluded via the break-glass group.

ConditionWhat was observed in the evidence.
Multi-factor authentication is not enforced for 3 of the 12 accounts shown in the Conditional Access policy list. The excluded accounts are members of the break-glass group.
CauseWhy the condition exists.
The Conditional Access policy grants an exclusion to the break-glass group, and membership of that group has not been reviewed since the policy was created.
EffectWhat the condition puts at risk.
An attacker holding a valid password for any of the three excluded accounts can authenticate from outside the corporate network without a second factor.

Cites

  • element 1
  • element 4

model confidence 82% — the model’s own number, not a measure of whether it is right.

computed
anthropic:claude-opus-4-8 ·
adopted
  • n.ignacio ·

Overridden

A reviewer raised the severity and rewrote the cause. The machine's values are kept beside the reviewer's, struck through, with the stated reason — printing only `effective` would make this indistinguishable from a finding the model produced this way on its own.

Finding

Deficienthighseverity was low

changed by a.rivera from low · Three standing members in a break-glass group is not an emergency path.

MFA is not enforced for three accounts excluded via the break-glass group.

ConditionWhat was observed in the evidence.
Multi-factor authentication is not enforced for 3 of the 12 accounts shown in the Conditional Access policy list. The excluded accounts are members of the break-glass group.
CauseWhy the condition exists.
The break-glass exclusion is documented and approved, but the group has 3 standing members rather than the 1 the policy allows.Model wrote: The Conditional Access policy grants an exclusion to the break-glass group, and membership of that group has not been reviewed since the policy was created.

changed by a.rivera · The model missed the approved-exception document.

EffectWhat the condition puts at risk.
An attacker holding a valid password for any of the three excluded accounts can authenticate from outside the corporate network without a second factor.

Cites

  • element 1
  • element 4

model confidence 82% — the model’s own number, not a measure of whether it is right.

computed
anthropic:claude-opus-4-8 ·
adopted
  • a.rivera · changed severity, cause ·

Citing evidence that is not there

The model cited element 9 of a 5-element extraction. Rendered as a live citation it would send a reviewer to look at nothing while appearing to send them somewhere, so the dangling ref is named and the citation is not offered.

Finding

Deficienthigh

MFA is not enforced for three accounts excluded via the break-glass group.

ConditionWhat was observed in the evidence.
Multi-factor authentication is not enforced for 3 of the 12 accounts shown in the Conditional Access policy list. The excluded accounts are members of the break-glass group.
CauseWhy the condition exists.
The Conditional Access policy grants an exclusion to the break-glass group, and membership of that group has not been reviewed since the policy was created.
EffectWhat the condition puts at risk.
An attacker holding a valid password for any of the three excluded accounts can authenticate from outside the corporate network without a second factor.

Compensating controls

Sign-in risk policies are enabled tenant-wide and would challenge an anomalous sign-in from these accounts.

Cites

  • element 2

This finding also cites an element that is not in the extraction (raw ref 8). The citation cannot be followed.

model confidence 0% — the model’s own number, not a measure of whether it is right.

computed
anthropic:claude-opus-4-8 ·
adopted
not yet adopted

A field the machine left empty

An `unable_to_conclude` finding proposes no severity at all, so a reviewer recording one is filling a blank rather than overruling a value. The note says `set`, not `changed`, and does not print the machine's side — there is no machine side. Found on real seeded data, where the same panel read “changed … from —”.

Finding

Unable to concludelow

set by r.martina — the model proposed none · Two of the three accounts are break-glass and covered by the PAM check-out log; residual exposure is one dormant account.

The screenshot shows the role catalog rather than the Conditional Access configuration, so MFA enforcement cannot be determined from it.

ConditionWhat was observed in the evidence.
Multi-factor authentication is not enforced for 3 of the 12 accounts shown in the Conditional Access policy list. The excluded accounts are members of the break-glass group.
CauseWhy the condition exists.
The Conditional Access policy grants an exclusion to the break-glass group, and membership of that group has not been reviewed since the policy was created.
EffectWhat the condition puts at risk.
An attacker holding a valid password for any of the three excluded accounts can authenticate from outside the corporate network without a second factor.

Cites

  • element 1
  • element 4

model confidence 90% — the model’s own number, not a measure of whether it is right.

computed
anthropic:claude-opus-4-8 ·
adopted
  • r.martina · changed severity ·

The workpaper, on the desk

The deliverable, and the one screen where the metaphor is doing literal work: the application is the desk — cool, grey, fluid — and this is a sheet of paper lying on it. Warm white, square corners, a real margin, a 72ch measure, serif. Sections are rendered by the shape of their content rather than by their name, so a section type this build has never seen still prints, with a generated heading and a note saying the heading is ours. A frontend that renders only what it was taught would silently print a shorter workpaper than the one on record. Empty sections say they are empty rather than vanishing — `management_response` is blank by design until a person fills it, and a workpaper that hides its blanks looks finished.

Control ref CC6.6 · Framework SOC 2 v1.0 · Status draft

Working Paper — CC6.6 Boundary Protection — MFA

draft · composed · template m2-1

One section (sampling_basis) is newer than this screen; it is shown below with a generated heading.

Criteria

MFA is enforced for access from outside the corporate network for all users, without weakening exclusions.

Source
SOC 2 CC6.6

Elements extracted

NameValueElement type
Require MFAOfftoggle
Excluded groupsbreak-glass

Management response

Not filled in. This section is part of the workpaper and is currently empty.

Review trail

Preparer
n.ignacio

Sampling basis(unrecognised section)

A section type this build has never seen, shown rather than dropped.

Ink, rationed

The accent is spent on four things and nothing else: the active navigation item, the one primary button on a screen, focus rings, and real links. Tab through the buttons below to see the fourth.