MarketLink audit evidence swarm, mapped to CMS EDE requirements.
This is the project-level operating room: configure personas, dispatch deterministic browser/API agents, watch source-native collection, review blocker and redaction gates, then package only approved audit-readiness evidence.
Agents do the collection work. CMS-native source rows decide what counts.
Modeled after the MarketLink CMS EDE testing module pattern: persona browser flows, API interception, screenshot metadata sidecars, source-row indexes, CSV/HTML reports, redaction manifests, checksums, and learning hints. No MarketLink generated evidence is copied.
Resolve target URL, broker/agent/consumer/admin personas, MFA, and credential vault bindings inside the private runner.
Run deterministic CMS EDE scenario actions that already carry sourceRefs and CMS-native IDs.
Collect screenshots, text, API JSON, metadata, and checksums in the prescribed output shape.
Map artifacts back to CMS toolkit files, native IDs, source rows, data elements, and expected evidence.
Review sensitive data, blocker state, row-level evidence sufficiency, and package eligibility.
Export auditor-ready packages only after source, redaction, manual evidence, and blocker gates clear.
Resolve this board before pointing agents at the target site
30 scenarios, 41 sourceRefs, 292 capture mappings, 0 errors.
1155 workbook-native ID candidates; 0 pending sourceRef(s).
3 ready, 24 blocked, 3 placeholder scenarios.
MarketLink: https://uat-marketlink.helpline.com
5 persona roles; 3 still needed or placeholder.
Control plane is ready; raw browser traces, screenshots, API calls, and secrets stay in the customer-controlled runtime.
0 approved, 0 needs review, 27 missing.
1 run folder(s); latest cms-ede-marketlink-application-preview-3c-2026-04-30T13-47-48-116Z with 87 artifacts.
Run artifacts are waiting for screenshot/API/text redaction review.
2 blocked gate(s), 2 review gate(s).
CMS EDE run sets by prescribed component
Application UI Toolkit
ready to runThe applicable phase Application UI Toolkit is reviewed in full; auditors need a methodology that evaluates each UI element, not only test-case-covered questions.
Gate: Target URL and approved broker/agent/consumer personas must be configured before live collection.
Eligibility Results Toolkit
credential gatedPhase-specific required test cases must be completed according to the User Guide tab, with screenshots through eligibility results and consistency between the results page and EDN.
Gate: Requires final CMS UAT/API access, approved toolkit cases, and target application personas.
EDE Partner Test Case Suite
credential gatedSupplemental partner test cases increase approval readiness and should not replace required toolkit cases.
Gate: Requires final CMS UAT credentials, certificates, and test data.
API Functional Integration Toolkit
credential gatedEach required API test case needs correct results and complete required evidence, including complete request/response headers and body where required; raw JSON/XML must remain unmodified.
Gate: Requires API base URLs, mTLS/certificates, CMS test accounts, and vault-backed private runner execution.
EDE Communications Toolkit
dry run readyRequired consumer communications, notices, disclaimers, language access, and associated critical communications must be evidenced in the applicable pathway.
Gate: Generated notices and non-English critical communications may require CMS/API access or manual evidence registration.
Eligibility Determination Notices / Notice Retrieval
credential gatedThe consumer must be able to access the most recent EDN; EDN and raw Get App API JSON requirements apply across required toolkit cases.
Gate: Requires generated EDNs, CMS API access, and approved notice retrieval path.
Identity Proofing / RIDP-RBA / FARS
manual or connectorIdentity proofing, RBA outcomes, acceptable documentation, IDM, Okta, and MFA gates must be evidenced or explicitly blocked until authorized access exists.
Gate: Requires RIDP/FARS, IDM, Okta, MFA, and production/test credential access.
Business Audit Instructions / DE Entity Documentation
manual or connectorAuditors must provide complete descriptions of each requirement and must not exclude required review-standard criteria; the DE Entity Documentation Package must be complete at submission.
Gate: Requires GRC/document repository access or manually registered approved documentation.
Registration, Onboarding, and Mini-Audit Access
manual or connectorTesting credentials must be valid and all APIs/components accessible during CMS mini audit; post-submission changes must follow the applicable change process.
Gate: Requires CMS Enterprise Portal, registration, and auditor/CMS access paths.
Security and Privacy Audit - ARC-AMPE / MARS-E
manual or connectorThe security/privacy audit package needs SAP, ARC-AMPE SSPP, SAR, and POA&M completeness; SAR findings include documentation review, control testing, scanning, penetration testing, and interviews.
Gate: Requires security package repository, scanner/pen-test output, GRC evidence, and reviewer acceptance.
Specialized agents and human gates
Opens the approved browser session for broker, agent, consumer, admin, or auditor personas without storing secrets in ControlFrame fixtures.
Executes prescribed CMS EDE scenario actions from the source-backed scenario registry and keeps route/selector behavior repeatable.
Captures full-page screenshots, text extracts, viewport metadata, source-native IDs, source rows, and checksums.
Captures CMS-relevant API JSON responses during browser flows or direct API runs and separates raw evidence from redacted review copies.
Classifies collected artifacts against source documents, native framework identifiers, toolkit rows, evidence targets, and required evidence text.
Flags screenshots, text, and JSON that need PII/sensitive-data review before they move into an auditor package.
Builds checksummed auditor packages only from approved artifacts, source-row indexes, reports, blockers, and manifests.
Writes selector candidates and flow-recovery hints when a scenario fails, then proposes registry improvements for human approval.
Registers GRC, policy, SSPP, SAR, POA&M, scanner, and repository artifacts by checksum and source-native mapping.
What the agents produce for auditor review
CMS Application UI, eligibility, communication, EDN, identity, and onboarding visual evidence.
CMS API FIT, eligibility response, EDN retrieval, metadata search, and hub transaction evidence.
Consumer communications, disclaimers, language assistance, and page-text corroboration.
Auditor traceability from CMS toolkit rows/native IDs to each collected artifact.
Reviewable inventory of all screenshots, JSON, extracts, hashes, redaction status, and export gates.
Human-readable CMS-native evidence map for auditor walkthroughs and package review.
Explicit CMS UAT, IDM, Okta, credential, source-row, manual evidence, or production access gaps.
Selector candidates and recovery notes for improving the next approved collector run.