SYNTHETIC REFERENCE ENGAGEMENT · NOT A CUSTOMER RECORD
Meridian Healthcare (fictional) · period 2025-07-01 → 2026-06-30
Population, sampling & coverage
A signature proves nobody altered an artifact after capture. It says nothing about whether that artifact was one of four hundred that should have been captured, or how it came to be the one you are looking at. These are the objects that answer that — the population, the seed that selected from it, and the coverage it leaves behind.
2 152
population members enumerated
121
items selected for test
7
deviations recorded
enumerated 2026-07-14
Calloway & Reyes LLP (fictional) · PCI DSS v4.0.1
Northgate Assurance (fictional) · SOC 2 Type II
Populations in scope
6 controls · 2 152 members · 121 tested
| Control | Population | Completeness basis | Selection | Deviations | Opinion held by |
|---|---|---|---|---|---|
1 284 Okta | system-of-record export enumerated from the system that owns the records | 25 of 1 284 random · seed 9f4c1d0a | 2 8% | Calloway & Reyes LLP | |
342 GitHub | system-of-record export enumerated from the system that owns the records | 25 of 342 random · seed 3b7e08a1 | 2 8% | Northgate Assurance | |
363 ServiceNow | asserted by control owner no independent export exists; completeness rests on an assertion | 30 of 363 random · seed c81a6f2d | 1 3.3% | Calloway & Reyes LLP | |
96 Workday | system-of-record export enumerated from the system that owns the records | 25 of 96 random · seed 6d20e9b5 | 1 4% | Northgate Assurance | |
63 Vendor master | reconciled to GL enumerated then reconciled line-by-line to the general ledger | 12 of 63 systematic · seed af53c706 | 1 8.3% | Calloway & Reyes LLP | |
4 ASV portal | system-of-record export enumerated from the system that owns the records | 4 of 4 whole-population | 0 0% | Calloway & Reyes LLP |
Meridian Healthcare, Calloway & Reyes LLP, and Northgate Assurance are fictional. No audit opinion exists; the engagement shows how ControlFrame binds each control to the firm whose opinion its evidence would support.
Population statement
POP-PCI-8.2.1-01
All user accounts holding logical access to the cardholder data environment at any point during the assessment period, including accounts disabled or deprovisioned before period end.
- Enumerated from
- Okta (Universal Directory)method: api
- Total count
- 1 284
- Completeness basis
- system-of-record exportenumerated from the system that owns the records
- Period of coverage
- 2025-07-01 → 2026-06-30enumerated 2026-07-14 09:12:00 UTC
Enumeration query
GET /api/v1/groups/00g4xk92pcCDE0/users + GET /api/v1/logs?filter=eventType eq "group.user_membership.remove" and published gt "2025-07-01T00:00:00Z"
Independent corroborating count
1 291 via Active Directory (ADSI export, independent path)
delta +7
Seven accounts present in AD are provisioned outside Okta as break-glass jump-host locals. Each was traced to the CDE host inventory, confirmed in scope, and added to the population before selection.
explanation approved by Director, Identity Engineering (control owner)
SHA-256 over the sorted member list
0fe0d84b6a2750e852c2528ffe9c5aeccf5fbff48945675e9ecae4566d42d130
SHA-256 over the statement — definition, source, counts, basis and period bound to the member list
db1cdf2a7f6733fd833fe23e445ff8fab02ee60565402d00ed6a63b4db3a6967
Sample of record
SMP-PCI-8.2.1-01
- Method
- random
- Size
- 25of 1 284
- Seed
- 9f4c1d0a77b3e6c2
- Selected by
- Lead assessor · Calloway & Reyes LLP2026-07-15 14:02:00 UTC
Population exceeds 1,000 members and the control operates event-driven, so frequency-based sizing does not apply. 25 selected at random per the assessor's attribute-testing table for populations above 250 with no expected deviations. Seed issued by the QSA before enumeration was disclosed.
The selection rule is k(ref) = SHA-256(seed : populationHash : ref), sorted ascending, first 25 taken. No random state, nothing to trust. Change the seed and the sample changes; restore it and the identical 25 refs come back.
on load, the recorded seed reproduced 25 of 25 refs
Selected members — each spawns its own collection and its own signed artifact
- 01OKTA-USR-151556-0776Contractor · Card Operations · 2025-08-27
- 02OKTA-USR-186740-0273Engineer · Platform Reliability · 2025-09-02
- 03OKTA-USR-196774-0506Engineer · Payments Platform · 2025-09-11
- 04OKTA-USR-231407-0915Engineer · Platform Reliability · 2026-04-02
- 05OKTA-USR-240456-1055Service account · payments-etl · 2026-03-04
- 06OKTA-USR-243688-0690Analyst · Claims Operations · 2025-12-26
- 07OKTA-USR-254403-0540Engineer · Platform Reliability · 2025-10-16deviation
- 08OKTA-USR-255450-0137Engineer · Platform Reliability · 2025-12-09
- 09OKTA-USR-271133-1253Contractor · Card Operations · 2025-09-13
- 10OKTA-USR-338808-1223Analyst · Member Services · 2026-01-24
- 11OKTA-USR-386138-0263Analyst · Member Services · 2026-06-15
- 12OKTA-USR-443799-1274Analyst · Member Services · 2025-11-05
- 13OKTA-USR-475069-1215Analyst · Member Services · 2026-01-26
- 14OKTA-USR-655067-1115Analyst · Claims Operations · 2025-11-24
- 15OKTA-USR-679161-1126Contractor · Card Operations · 2025-12-31
- 16OKTA-USR-735940-0064Analyst · Claims Operations · 2026-03-03
- 17OKTA-USR-737384-0336Engineer · Platform Reliability · 2026-03-08
- 18OKTA-USR-772701-0475Administrator · Identity Engineering · 2025-10-09deviation
- 19OKTA-USR-888334-0784Administrator · Identity Engineering · 2025-10-09
- 20OKTA-USR-904366-0703Engineer · Platform Reliability · 2025-07-21
- 21OKTA-USR-914263-1114Read-only · Internal Audit · 2026-01-07
- 22OKTA-USR-922128-0153Administrator · Identity Engineering · 2026-02-08
- 23OKTA-USR-963926-0570Service account · payments-etl · 2026-06-15
- 24OKTA-USR-964169-0966Analyst · Claims Operations · 2026-03-03
- 25OKTA-USR-996119-1046Service account · tokenizer · 2026-02-27
Deviation ledger
2 of 25 tested · 8%
| Item | Result | Assessor note |
|---|---|---|
OKTA-USR-254403-0540 2025-10-16 | deviation | EXC-MFA-NOT-ENFORCED — account held CDE access for 41 days with phishing-resistant MFA not enforced. Remediated 2026-02-11; the gap is inside the period. |
OKTA-USR-772701-0475 2025-10-09 | deviation | EXC-SHARED-CREDENTIAL — service account credential was shared between two named engineers; unique-ID requirement not met for this account. |
8%
deviation rate
103
projected across 1 284
2 of 25 sampled items deviated (8%). Projected across the population of 1,284 that is 103 items. Selection was random under recorded seed 9f4c1d0a77b3e6c2, so this projection is re-derivable; it is a point estimate, not a statistical upper bound.
Coverage
1 284 occurrences · largest interval without one: 2 d
Coverage is the shape of the period, not a percentage. A visible interval with no occurrence is a question an assessor can ask and the control owner can answer; a green dial is neither.