Trace one obligation from source requirement to controlled release.
A working reference flow through private collection, artifact custody, GRC mappings, human review, and package release. The data and collection are scripted; the governed operating model is the product.
Inspect the full evidence operating chain.
Switch between the four product stages. In collection, run the deterministic reference job. In the repository, select an artifact to inspect its metadata and custody record.
Collect evidence where the source lives.
The sandbox plan binds CMS Y9 · UI-3.2 to the expected workflow proof, artifact contract, control mapping, and custody requirements before work begins.
| Source | Evidence task | Output | Control | State |
|---|---|---|---|---|
| CMS source catalog | Y9 · UI-3.2 enrollment consent flow | Source row + contract | CF-UI-03 | ready |
| Enrollment application | Consent capture and confirmation path | Screenshot + sidecar | CF-UI-03 | ready |
| Enrollment API | Consent event and transaction record | JSON + headers | CF-AU-11 | ready |
| Document repository | Approved consent and privacy notice | PDF + metadata | CF-GV-02 | ready |
One proof spine. Five governed stages.
- 01
Collect at the source
Signed private-runner jobs capture browser, API, configuration, log, and document evidence against a declared evidence contract.
- 02
Govern the repository
Artifacts retain source, version, checksum, sensitivity, freshness, custody history, and reviewer state.
- 03
Map the control graph
One source artifact can support multiple framework projections without hiding the original obligation or reuse confidence.
- 04
Hold for human review
Agents can recommend sufficiency and redaction actions. They cannot approve their own work or release an audit package.
- 05
Release defensible proof
Approved artifacts, manifests, decisions, and custody records become a controlled package with an offline-verifiable receipt.
Agentic review with human authority
Framework-configured agents can plan evidence work, inspect sufficiency, identify sensitive data, and draft the next review action. Customer policy determines the model boundary; agents do not approve their own output or release packages.
Bring your own framework, sources, and review authority.
Invited teams can continue into a protected workspace with real project scope, access controls, runner configuration, and review gates.
Verify project access