{
  "schemaVersion": 1,
  "caseId": "fictional-evidence-case",
  "title": "Fictional supplier and workflow evidence",
  "owner": "Example human reviewer",
  "purpose": "Demonstrate deterministic reports from supplied fictional data. No customer data, market rate or approval.",
  "evaluationDate": "2026-10-03",
  "attachments": [
    {
      "id": "policy",
      "filename": "policy-fictional-report.json",
      "workflow": "Policy Source Review",
      "kind": "report",
      "content": "{\n  \"fictional\": true,\n  \"origin\": \"Local deterministic module called by build-demo.mjs; identity and source rights not independently verified.\",\n  \"input\": {\n    \"asOfDate\": \"2026-10-03\",\n    \"documents\": [\n      {\n        \"id\": \"fictional-access-v2\",\n        \"title\": \"Fictional Demonstration Access Procedure\",\n        \"family\": \"Fictional Access Procedure\",\n        \"version\": \"2.0\",\n        \"owner\": \"Fictional Example Owner\",\n        \"effectiveDate\": \"2026-09-01\",\n        \"expiresDate\": \"2027-09-01\",\n        \"sourceRef\": \"fictional-example://access-procedure/v2\",\n        \"content\": \"FICTIONAL DEMONSTRATION ONLY. No institution policy is connected.\\nAccess reviews are assigned to the named system owner.\\nTemporary access expires after the approved duration.\\nAn exception request requires recorded approval before access is granted.\\nRetain the review record in the approved register.\",\n        \"authorized\": true,\n        \"approved\": true,\n        \"controlling\": true\n      }\n    ],\n    \"questions\": [\n      {\n        \"id\": \"access-review\",\n        \"text\": \"Find exact evidence for access review ownership.\",\n        \"terms\": [\n          \"access reviews\",\n          \"system owner\"\n        ]\n      },\n      {\n        \"id\": \"exception\",\n        \"text\": \"Find exact evidence for exception requests.\",\n        \"terms\": [\n          \"exception request\",\n          \"recorded approval\"\n        ]\n      },\n      {\n        \"id\": \"absent-term\",\n        \"text\": \"Check whether this collection contains the exact phrase quarterly review.\",\n        \"terms\": [\n          \"quarterly review\"\n        ]\n      }\n    ]\n  },\n  \"output\": {\n    \"schemaVersion\": 1,\n    \"tool\": \"policy_source_review\",\n    \"status\": \"ready_for_evidence_review\",\n    \"asOfDate\": \"2026-10-03\",\n    \"sourceIssues\": [],\n    \"sources\": [\n      {\n        \"id\": \"fictional-access-v2\",\n        \"title\": \"Fictional Demonstration Access Procedure\",\n        \"family\": \"Fictional Access Procedure\",\n        \"version\": \"2.0\",\n        \"owner\": \"Fictional Example Owner\",\n        \"effectiveDate\": \"2026-09-01\",\n        \"expiresDate\": \"2027-09-01\",\n        \"sourceRef\": \"fictional-example://access-procedure/v2\",\n        \"authorized\": true,\n        \"approved\": true,\n        \"controlling\": true\n      }\n    ],\n    \"families\": [\n      {\n        \"family\": \"Fictional Access Procedure\",\n        \"status\": \"ready\",\n        \"sourceIds\": [\n          \"fictional-access-v2\"\n        ],\n        \"controllingSourceId\": \"fictional-access-v2\",\n        \"issueCodes\": []\n      }\n    ],\n    \"questionResults\": [\n      {\n        \"id\": \"access-review\",\n        \"text\": \"Find exact evidence for access review ownership.\",\n        \"terms\": [\n          \"access reviews\",\n          \"system owner\"\n        ],\n        \"status\": \"exact_evidence_found\",\n        \"missingTerms\": [],\n        \"matchedTerms\": [\n          \"access reviews\",\n          \"system owner\"\n        ],\n        \"evidence\": [\n          {\n            \"sourceId\": \"fictional-access-v2\",\n            \"title\": \"Fictional Demonstration Access Procedure\",\n            \"family\": \"Fictional Access Procedure\",\n            \"version\": \"2.0\",\n            \"sourceRef\": \"fictional-example://access-procedure/v2\",\n            \"lineStart\": 2,\n            \"lineEnd\": 2,\n            \"excerpt\": \"Access reviews are assigned to the named system owner.\",\n            \"matchedTerms\": [\n              \"access reviews\",\n              \"system owner\"\n            ]\n          }\n        ],\n        \"evidenceTruncated\": false\n      },\n      {\n        \"id\": \"exception\",\n        \"text\": \"Find exact evidence for exception requests.\",\n        \"terms\": [\n          \"exception request\",\n          \"recorded approval\"\n        ],\n        \"status\": \"exact_evidence_found\",\n        \"missingTerms\": [],\n        \"matchedTerms\": [\n          \"exception request\",\n          \"recorded approval\"\n        ],\n        \"evidence\": [\n          {\n            \"sourceId\": \"fictional-access-v2\",\n            \"title\": \"Fictional Demonstration Access Procedure\",\n            \"family\": \"Fictional Access Procedure\",\n            \"version\": \"2.0\",\n            \"sourceRef\": \"fictional-example://access-procedure/v2\",\n            \"lineStart\": 4,\n            \"lineEnd\": 4,\n            \"excerpt\": \"An exception request requires recorded approval before access is granted.\",\n            \"matchedTerms\": [\n              \"exception request\",\n              \"recorded approval\"\n            ]\n          }\n        ],\n        \"evidenceTruncated\": false\n      },\n      {\n        \"id\": \"absent-term\",\n        \"text\": \"Check whether this collection contains the exact phrase quarterly review.\",\n        \"terms\": [\n          \"quarterly review\"\n        ],\n        \"status\": \"missing_evidence\",\n        \"missingTerms\": [\n          \"quarterly review\"\n        ],\n        \"matchedTerms\": [],\n        \"evidence\": [],\n        \"evidenceTruncated\": false\n      }\n    ],\n    \"statistics\": {\n      \"documentCount\": 1,\n      \"familyCount\": 1,\n      \"questionCount\": 3,\n      \"sourceLineCount\": 5,\n      \"totalContentChars\": 299,\n      \"eligibleDocumentCount\": 1,\n      \"searchableDocumentCount\": 1,\n      \"excludedDocumentCount\": 0,\n      \"returnedExcerpts\": 2,\n      \"questionsWithExactEvidence\": 2,\n      \"questionsWithoutExactEvidence\": 1,\n      \"blockedQuestionCount\": 0,\n      \"evidenceLimitReached\": false\n    },\n    \"limits\": {\n      \"maxDocuments\": 32,\n      \"maxQuestions\": 24,\n      \"maxTermsPerQuestion\": 12,\n      \"maxTermChars\": 120,\n      \"maxDocumentChars\": 120000,\n      \"maxTotalContentChars\": 600000,\n      \"maxDocumentLines\": 5000,\n      \"maxLineChars\": 2000,\n      \"maxEvidencePerQuestion\": 20,\n      \"maxEvidenceTotal\": 100\n    },\n    \"limitations\": [\n      \"This is literal evidence retrieval for human review, never a policy answer or compliance opinion.\",\n      \"All source declarations, approvals, rights, ownership and controlling status are supplied by the caller; the engine does not independently verify them.\",\n      \"A declared expiresDate takes effect on that calendar date. Undeclared expiry and source supersession cannot be detected; an old effective date alone does not prove that a source is obsolete.\",\n      \"Any blocking source issue suppresses all collection excerpts until the collection is ready. Non-controlling sources are not searched.\",\n      \"Matches are case-insensitive literal keywords or phrases on one line, with Unicode word boundaries. No stemming, synonyms, OCR, semantic search or cross-line phrases are used.\",\n      \"A found phrase does not establish that an instruction applies, resolve negation, establish source completeness or prove policy adequacy. Missing phrases do not prove absence of a rule.\",\n      \"Content and source references are inert data, never instructions or automatically opened links. Consumers must render strings as text and handle source rights.\",\n      \"Evidence can be capped; evidenceTruncated and evidenceLimitReached disclose omitted matching lines. missingTerms describes literal search coverage, never question resolution.\"\n    ]\n  }\n}",
      "byteLength": 7039,
      "sha256": "cff77e02947acc1da3e2a5815f3e68511f6b4895cacd2e384f8f598779b84713",
      "review": {
        "reviewer": "",
        "reviewedDate": "",
        "note": "",
        "confirmed": false
      }
    },
    {
      "id": "value-case",
      "filename": "value-case-fictional-report.json",
      "workflow": "Workflow Value Case",
      "kind": "report",
      "content": "{\n  \"fictional\": true,\n  \"origin\": \"Local deterministic module called by build-demo.mjs; identity and source rights not independently verified.\",\n  \"input\": {\n    \"workflow\": \"Fictional policy evidence preparation\",\n    \"title\": \"Fictional workflow capacity and cash model\",\n    \"owner\": \"Fictional Example Owner\",\n    \"currentMinutes\": 30,\n    \"proposedMinutes\": 15,\n    \"hourlyCostUsd\": 40,\n    \"setupCostUsd\": 3000,\n    \"monthlyCostUsd\": 250,\n    \"horizonMonths\": 12,\n    \"rolloutMonths\": 2,\n    \"evidenceReviewed\": false,\n    \"evidenceRef\": \"fictional-example://assumptions-only-not-reviewed\",\n    \"cashAction\": \"Fictional assumption: avoid budgeted temporary-staff hours; no approved reduction exists.\",\n    \"cashEvidenceReviewed\": false,\n    \"scenarios\": [\n      {\n        \"name\": \"Capacity only\",\n        \"monthlyVolume\": 400,\n        \"adoptionPercent\": 50,\n        \"realizationPercent\": 50,\n        \"cashablePercent\": 0\n      },\n      {\n        \"name\": \"Partial cashability\",\n        \"monthlyVolume\": 400,\n        \"adoptionPercent\": 75,\n        \"realizationPercent\": 80,\n        \"cashablePercent\": 25\n      },\n      {\n        \"name\": \"Higher cashability assumption\",\n        \"monthlyVolume\": 600,\n        \"adoptionPercent\": 90,\n        \"realizationPercent\": 90,\n        \"cashablePercent\": 50\n      }\n    ]\n  },\n  \"output\": {\n    \"schemaVersion\": 1,\n    \"tool\": \"workflow_value_case\",\n    \"status\": \"draft_unreviewed\",\n    \"input\": {\n      \"workflow\": \"Fictional policy evidence preparation\",\n      \"title\": \"Fictional workflow capacity and cash model\",\n      \"owner\": \"Fictional Example Owner\",\n      \"currentMinutes\": 30,\n      \"proposedMinutes\": 15,\n      \"hourlyCostUsd\": 40,\n      \"setupCostUsd\": 3000,\n      \"monthlyCostUsd\": 250,\n      \"horizonMonths\": 12,\n      \"rolloutMonths\": 2,\n      \"evidenceReviewed\": false,\n      \"evidenceRef\": \"fictional-example://assumptions-only-not-reviewed\",\n      \"cashAction\": \"Fictional assumption: avoid budgeted temporary-staff hours; no approved reduction exists.\",\n      \"cashEvidenceReviewed\": false,\n      \"scenarios\": [\n        {\n          \"name\": \"Capacity only\",\n          \"monthlyVolume\": 400,\n          \"adoptionPercent\": 50,\n          \"realizationPercent\": 50,\n          \"cashablePercent\": 0\n        },\n        {\n          \"name\": \"Partial cashability\",\n          \"monthlyVolume\": 400,\n          \"adoptionPercent\": 75,\n          \"realizationPercent\": 80,\n          \"cashablePercent\": 25\n        },\n        {\n          \"name\": \"Higher cashability assumption\",\n          \"monthlyVolume\": 600,\n          \"adoptionPercent\": 90,\n          \"realizationPercent\": 90,\n          \"cashablePercent\": 50\n        }\n      ]\n    },\n    \"inputIssues\": [\n      {\n        \"field\": \"evidenceReviewed\",\n        \"code\": \"unreviewed_evidence\",\n        \"message\": \"Validate time, cost, volume, adoption, realization and cashability assumptions with the owner.\"\n      },\n      {\n        \"field\": \"cashEvidenceReviewed\",\n        \"code\": \"unreviewed_cash_evidence\",\n        \"message\": \"Review evidence for the named cash action and assumed cashability before labeling cash inputs reviewed.\"\n      }\n    ],\n    \"scenarios\": [\n      {\n        \"name\": \"Capacity only\",\n        \"assumptions\": {\n          \"name\": \"Capacity only\",\n          \"monthlyVolume\": 400,\n          \"adoptionPercent\": 50,\n          \"realizationPercent\": 50,\n          \"cashablePercent\": 0\n        },\n        \"monthlyCapacityHours\": 25,\n        \"monthlyModeledLaborValueUsd\": 1000,\n        \"monthlyModeledCashBenefitUsd\": 0,\n        \"monthlyNetCashFlowUsd\": -250,\n        \"operatingMonths\": 10,\n        \"totalCapacityHours\": 250,\n        \"totalModeledCashBenefitUsd\": 0,\n        \"totalCostUsd\": 6000,\n        \"horizonNetCashFlowUsd\": -6000,\n        \"paybackMonth\": null,\n        \"paybackStatus\": \"not_within_horizon\",\n        \"months\": [\n          {\n            \"month\": 0,\n            \"phase\": \"setup\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 3000,\n            \"netCashFlowUsd\": -3000,\n            \"cumulativeCashFlowUsd\": -3000\n          },\n          {\n            \"month\": 1,\n            \"phase\": \"rollout\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3250\n          },\n          {\n            \"month\": 2,\n            \"phase\": \"rollout\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3500\n          },\n          {\n            \"month\": 3,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3750\n          },\n          {\n            \"month\": 4,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -4000\n          },\n          {\n            \"month\": 5,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -4250\n          },\n          {\n            \"month\": 6,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -4500\n          },\n          {\n            \"month\": 7,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -4750\n          },\n          {\n            \"month\": 8,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -5000\n          },\n          {\n            \"month\": 9,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -5250\n          },\n          {\n            \"month\": 10,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -5500\n          },\n          {\n            \"month\": 11,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -5750\n          },\n          {\n            \"month\": 12,\n            \"phase\": \"operating\",\n            \"capacityHours\": 25,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -6000\n          }\n        ]\n      },\n      {\n        \"name\": \"Partial cashability\",\n        \"assumptions\": {\n          \"name\": \"Partial cashability\",\n          \"monthlyVolume\": 400,\n          \"adoptionPercent\": 75,\n          \"realizationPercent\": 80,\n          \"cashablePercent\": 25\n        },\n        \"monthlyCapacityHours\": 60,\n        \"monthlyModeledLaborValueUsd\": 2400,\n        \"monthlyModeledCashBenefitUsd\": 600,\n        \"monthlyNetCashFlowUsd\": 350,\n        \"operatingMonths\": 10,\n        \"totalCapacityHours\": 600,\n        \"totalModeledCashBenefitUsd\": 6000,\n        \"totalCostUsd\": 6000,\n        \"horizonNetCashFlowUsd\": 0,\n        \"paybackMonth\": 12,\n        \"paybackStatus\": \"within_horizon\",\n        \"months\": [\n          {\n            \"month\": 0,\n            \"phase\": \"setup\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 3000,\n            \"netCashFlowUsd\": -3000,\n            \"cumulativeCashFlowUsd\": -3000\n          },\n          {\n            \"month\": 1,\n            \"phase\": \"rollout\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3250\n          },\n          {\n            \"month\": 2,\n            \"phase\": \"rollout\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3500\n          },\n          {\n            \"month\": 3,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -3150\n          },\n          {\n            \"month\": 4,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -2800\n          },\n          {\n            \"month\": 5,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -2450\n          },\n          {\n            \"month\": 6,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -2100\n          },\n          {\n            \"month\": 7,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -1750\n          },\n          {\n            \"month\": 8,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -1400\n          },\n          {\n            \"month\": 9,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -1050\n          },\n          {\n            \"month\": 10,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -700\n          },\n          {\n            \"month\": 11,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": -350\n          },\n          {\n            \"month\": 12,\n            \"phase\": \"operating\",\n            \"capacityHours\": 60,\n            \"modeledCashBenefitUsd\": 600,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 350,\n            \"cumulativeCashFlowUsd\": 0\n          }\n        ]\n      },\n      {\n        \"name\": \"Higher cashability assumption\",\n        \"assumptions\": {\n          \"name\": \"Higher cashability assumption\",\n          \"monthlyVolume\": 600,\n          \"adoptionPercent\": 90,\n          \"realizationPercent\": 90,\n          \"cashablePercent\": 50\n        },\n        \"monthlyCapacityHours\": 121.5,\n        \"monthlyModeledLaborValueUsd\": 4860,\n        \"monthlyModeledCashBenefitUsd\": 2430,\n        \"monthlyNetCashFlowUsd\": 2180,\n        \"operatingMonths\": 10,\n        \"totalCapacityHours\": 1215,\n        \"totalModeledCashBenefitUsd\": 24300,\n        \"totalCostUsd\": 6000,\n        \"horizonNetCashFlowUsd\": 18300,\n        \"paybackMonth\": 4,\n        \"paybackStatus\": \"within_horizon\",\n        \"months\": [\n          {\n            \"month\": 0,\n            \"phase\": \"setup\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 3000,\n            \"netCashFlowUsd\": -3000,\n            \"cumulativeCashFlowUsd\": -3000\n          },\n          {\n            \"month\": 1,\n            \"phase\": \"rollout\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3250\n          },\n          {\n            \"month\": 2,\n            \"phase\": \"rollout\",\n            \"capacityHours\": 0,\n            \"modeledCashBenefitUsd\": 0,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": -250,\n            \"cumulativeCashFlowUsd\": -3500\n          },\n          {\n            \"month\": 3,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": -1320\n          },\n          {\n            \"month\": 4,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 860\n          },\n          {\n            \"month\": 5,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 3040\n          },\n          {\n            \"month\": 6,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 5220\n          },\n          {\n            \"month\": 7,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 7400\n          },\n          {\n            \"month\": 8,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 9580\n          },\n          {\n            \"month\": 9,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 11760\n          },\n          {\n            \"month\": 10,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 13940\n          },\n          {\n            \"month\": 11,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 16120\n          },\n          {\n            \"month\": 12,\n            \"phase\": \"operating\",\n            \"capacityHours\": 121.5,\n            \"modeledCashBenefitUsd\": 2430,\n            \"costUsd\": 250,\n            \"netCashFlowUsd\": 2180,\n            \"cumulativeCashFlowUsd\": 18300\n          }\n        ]\n      }\n    ],\n    \"assumptions\": [\n      \"Monthly net capacity hours = (current minutes - proposed minutes) × monthly volume × adoption% × realization% ÷ 60. Negative capacity means additional work, not released capacity.\",\n      \"Modeled labor value = net capacity hours × hourly labor cost. Modeled cash benefit additionally multiplies by cashable%; 0% cashability creates zero labor cash savings.\",\n      \"Modeled labor value and cash benefit are alternative views of the same modeled time change and must never be added together.\",\n      \"Setup cost is paid in month 0. The recurring fee is paid in every modeled month, including rollout. Rollout months have zero capacity and zero cash benefit; the first operating month is rolloutMonths + 1.\",\n      \"Input numbers are treated as their decimal string values and calculated as exact rational values. Monthly cash benefit is rounded once to the nearest cent with half-cent ties away from zero; cash-flow totals are then summed in integer cents. Monetary input rates and costs are rounded to cents. Capacity hours are displayed to six decimals.\",\n      \"Payback is the first modeled month whose cumulative cash flow is nonnegative and remains nonnegative through the modeled horizon. Month 0 is immediate only when later modeled cash flows do not undo recovery.\",\n      \"All three scenarios use constant operating volume, adoption, realization and cashability. Additional implementation, support or change costs must be included by the owner in setup and recurring costs.\"\n    ],\n    \"limitations\": [\n      \"Outputs are modeled estimates, never achieved savings, an approved business case, a promise, a headcount-reduction recommendation or authorization for a transaction.\",\n      \"Evidence-review status reflects caller declarations and a supplied reference; it does not prove that evidence was independently checked or that a business owner approved the result.\",\n      \"Any positive cashability remains draft unless a cashAction names the avoidable expenditure and cashEvidenceReviewed is true, together with the workflow owner and reviewed evidence reference.\",\n      \"Released labor capacity is not cash savings unless an evidenced cashable mechanism exists. Cashability must reflect avoidable cash expenditure, not a general productivity assumption.\",\n      \"No discounting, taxes, financing, revenue uplift, risk valuation, seasonality, failure rates or terminal value are modeled. Costs after the selected horizon remain outside this model; recurring obligations do not disappear.\",\n      \"No payback within the horizon is reported as null. It does not establish that later payback is impossible. A zero setup cost can coexist with recurring net losses.\"\n    ],\n    \"limits\": {\n      \"maxMinutes\": 1440,\n      \"maxHourlyCostUsd\": 10000,\n      \"maxSetupCostUsd\": 10000000,\n      \"maxMonthlyCostUsd\": 10000000,\n      \"maxMonthlyVolume\": 1000000,\n      \"maxHorizonMonths\": 120,\n      \"scenarioCount\": 3\n    }\n  }\n}",
      "byteLength": 18567,
      "sha256": "389696ecfc8407b4ece50d79d7c5893ec12758cf4bf5e40017d6ada9aeb720d6",
      "review": {
        "reviewer": "",
        "reviewedDate": "",
        "note": "",
        "confirmed": false
      }
    },
    {
      "id": "invoice",
      "filename": "invoice-fictional-report.json",
      "workflow": "Invoice Evidence",
      "kind": "report",
      "content": "{\n  \"fictional\": true,\n  \"origin\": \"Local deterministic module called by build-demo.mjs; identity and source rights not independently verified.\",\n  \"input\": {\n    \"schemaVersion\": 1,\n    \"currency\": \"USD\",\n    \"evaluationDate\": \"2026-10-03\",\n    \"reviewOwner\": \"Fictional reviewer\",\n    \"completenessConfirmed\": true,\n    \"termsPacket\": {\n      \"id\": \"fictional-terms-2026\",\n      \"title\": \"Fictional flat-rate service schedule\",\n      \"version\": \"Fictional version 1\",\n      \"sourceRef\": \"Fictional example only: approved schedule, page 2\",\n      \"effectiveDate\": \"2026-01-01\",\n      \"expiresDate\": \"2026-12-31\",\n      \"authorized\": true,\n      \"confirmed\": true\n    },\n    \"invoicePacket\": {\n      \"id\": \"fictional-invoice-september\",\n      \"sourceRef\": \"Fictional example only: September invoice, page 1\",\n      \"periodStart\": \"2026-09-01\",\n      \"periodEnd\": \"2026-09-30\",\n      \"authorized\": true,\n      \"confirmed\": true\n    },\n    \"approvedLines\": [\n      {\n        \"id\": \"support\",\n        \"description\": \"Fictional support hours\",\n        \"unit\": \"hour\",\n        \"unitRateUsd\": \"100\",\n        \"allowedQuantity\": \"12\"\n      },\n      {\n        \"id\": \"records\",\n        \"description\": \"Fictional records processing\",\n        \"unit\": \"record\",\n        \"unitRateUsd\": \"0.25\",\n        \"allowedQuantity\": \"5000\"\n      }\n    ],\n    \"invoiceLines\": [\n      {\n        \"id\": \"invoice-support\",\n        \"approvedLineId\": \"support\",\n        \"description\": \"Fictional support hours\",\n        \"unit\": \"hour\",\n        \"quantity\": \"10\",\n        \"unitRateUsd\": \"110\",\n        \"lineAmountUsd\": \"1100.00\"\n      },\n      {\n        \"id\": \"invoice-records\",\n        \"approvedLineId\": \"records\",\n        \"description\": \"Fictional records processing\",\n        \"unit\": \"record\",\n        \"quantity\": \"1000\",\n        \"unitRateUsd\": \"0.25\",\n        \"lineAmountUsd\": \"249.00\"\n      },\n      {\n        \"id\": \"invoice-extra\",\n        \"approvedLineId\": \"unreviewed-extra\",\n        \"description\": \"Fictional unreviewed extra service\",\n        \"unit\": \"item\",\n        \"quantity\": \"1\",\n        \"unitRateUsd\": \"50\",\n        \"lineAmountUsd\": \"50.00\"\n      }\n    ],\n    \"unsupportedTerms\": false\n  },\n  \"output\": {\n    \"schemaVersion\": 1,\n    \"status\": \"needs_review\",\n    \"issues\": [\n      {\n        \"code\": \"rate_difference\",\n        \"message\": \"The declared invoice rate differs from the entered approved rate; review the signed difference.\",\n        \"lineId\": \"invoice-support\"\n      },\n      {\n        \"code\": \"amount_difference\",\n        \"message\": \"The declared invoice amount differs from the modeled amount at the entered approved rate.\",\n        \"lineId\": \"invoice-support\"\n      },\n      {\n        \"code\": \"amount_difference\",\n        \"message\": \"The declared invoice amount differs from the modeled amount at the entered approved rate.\",\n        \"lineId\": \"invoice-records\"\n      },\n      {\n        \"code\": \"invoice_arithmetic_mismatch\",\n        \"message\": \"The declared line amount does not equal quantity multiplied by the declared rate, rounded half up to cents.\",\n        \"lineId\": \"invoice-records\"\n      },\n      {\n        \"code\": \"unmatched_invoice_line\",\n        \"message\": \"Map this invoice line to a reviewed approved line; no expected amount is available.\",\n        \"lineId\": \"invoice-extra\"\n      }\n    ],\n    \"lineResults\": [\n      {\n        \"invoiceLineId\": \"invoice-support\",\n        \"approvedLineId\": \"support\",\n        \"status\": \"discrepancy\",\n        \"quantity\": \"10\",\n        \"declaredRateUsd\": \"110\",\n        \"approvedRateUsd\": \"100\",\n        \"declaredAmountUsd\": \"1100.00\",\n        \"invoiceArithmeticUsd\": \"1100.00\",\n        \"expectedAmountUsd\": \"1000.00\",\n        \"rateDifferenceUsd\": \"10\",\n        \"amountDifferenceUsd\": \"100.00\",\n        \"quantityIssue\": false\n      },\n      {\n        \"invoiceLineId\": \"invoice-records\",\n        \"approvedLineId\": \"records\",\n        \"status\": \"needs_review\",\n        \"quantity\": \"1000\",\n        \"declaredRateUsd\": \"0.25\",\n        \"approvedRateUsd\": \"0.25\",\n        \"declaredAmountUsd\": \"249.00\",\n        \"invoiceArithmeticUsd\": \"250.00\",\n        \"expectedAmountUsd\": \"250.00\",\n        \"rateDifferenceUsd\": \"0\",\n        \"amountDifferenceUsd\": \"-1.00\",\n        \"quantityIssue\": false\n      },\n      {\n        \"invoiceLineId\": \"invoice-extra\",\n        \"approvedLineId\": \"unreviewed-extra\",\n        \"status\": \"needs_review\",\n        \"quantity\": \"1\",\n        \"declaredRateUsd\": \"50\",\n        \"approvedRateUsd\": null,\n        \"declaredAmountUsd\": \"50.00\",\n        \"invoiceArithmeticUsd\": \"50.00\",\n        \"expectedAmountUsd\": null,\n        \"rateDifferenceUsd\": null,\n        \"amountDifferenceUsd\": null,\n        \"quantityIssue\": false\n      }\n    ],\n    \"totals\": null,\n    \"limitations\": [\n      \"This compares explicit structured USD flat-rate evidence. It does not interpret a contract or establish a legal dispute, refund, achieved savings or payment instruction.\",\n      \"Expected amounts use declared invoice quantities and round each quantity-times-rate product half up to cents before totaling. Quantity caps are checked across all lines mapped to the same approved line.\",\n      \"Quantity allowances are checked only against this supplied invoice packet. Other invoices, cumulative usage and delivery evidence are outside this comparison.\",\n      \"Source authorization, confirmation and completeness are reviewer attestations, not independently verified facts. Review-ready means a complete modeled comparison for human review, not approval to pay.\",\n      \"Complete discrepancy totals are withheld while evidence or arithmetic gates remain open. Eligible individual line comparisons can still be shown for review.\"\n    ]\n  }\n}",
      "byteLength": 5670,
      "sha256": "e92d844d3ea2d27b6596da184273fa9be3d8523fac1c76ccdb933838d9979c24",
      "review": {
        "reviewer": "",
        "reviewedDate": "",
        "note": "",
        "confirmed": false
      }
    },
    {
      "id": "vendor-evidence",
      "filename": "vendor-evidence-fictional-report.json",
      "workflow": "Vendor Evidence Review",
      "kind": "report",
      "content": "{\n  \"fictional\": true,\n  \"origin\": \"Local deterministic module called by build-demo.mjs; identity and source rights not independently verified.\",\n  \"input\": {\n    \"schemaVersion\": 1,\n    \"evaluationDate\": \"2026-10-03\",\n    \"reviewOwner\": \"Fictional procurement lead\",\n    \"vendorName\": \"Fictional Harbor Systems\",\n    \"checklistSource\": {\n      \"sourceRef\": \"Fictional buyer checklist page 1\",\n      \"version\": \"Fictional v1\",\n      \"authorized\": true,\n      \"confirmed\": true\n    },\n    \"requirements\": [\n      {\n        \"id\": \"security\",\n        \"title\": \"Fictional security evidence\",\n        \"evidenceType\": \"security-report\",\n        \"owner\": \"Fictional security lead\",\n        \"critical\": true,\n        \"applicability\": \"applicable\",\n        \"notApplicableReason\": \"\",\n        \"notApplicableConfirmed\": false,\n        \"requiredPeriodStart\": \"2026-01-01\",\n        \"requiredPeriodEnd\": \"2026-06-30\"\n      },\n      {\n        \"id\": \"continuity\",\n        \"title\": \"Fictional continuity test\",\n        \"evidenceType\": \"continuity-test\",\n        \"owner\": \"Fictional operations lead\",\n        \"critical\": true,\n        \"applicability\": \"applicable\",\n        \"notApplicableReason\": \"\",\n        \"notApplicableConfirmed\": false,\n        \"requiredPeriodStart\": \"\",\n        \"requiredPeriodEnd\": \"\"\n      },\n      {\n        \"id\": \"insurance\",\n        \"title\": \"Fictional insurance evidence\",\n        \"evidenceType\": \"insurance-certificate\",\n        \"owner\": \"Fictional finance lead\",\n        \"critical\": false,\n        \"applicability\": \"applicable\",\n        \"notApplicableReason\": \"\",\n        \"notApplicableConfirmed\": false,\n        \"requiredPeriodStart\": \"\",\n        \"requiredPeriodEnd\": \"\"\n      },\n      {\n        \"id\": \"onsite\",\n        \"title\": \"Fictional on-site access evidence\",\n        \"evidenceType\": \"access-review\",\n        \"owner\": \"Fictional facilities lead\",\n        \"critical\": false,\n        \"applicability\": \"not_applicable\",\n        \"notApplicableReason\": \"Fictional service has no on-site access in this example.\",\n        \"notApplicableConfirmed\": true,\n        \"requiredPeriodStart\": \"\",\n        \"requiredPeriodEnd\": \"\"\n      }\n    ],\n    \"evidence\": [\n      {\n        \"id\": \"security-current\",\n        \"title\": \"Fictional security report\",\n        \"type\": \"security-report\",\n        \"family\": \"fictional-security\",\n        \"version\": \"Fictional v1\",\n        \"sourceRef\": \"Fictional security report page 1\",\n        \"issuedDate\": \"2026-07-01\",\n        \"expiresDate\": \"2027-07-01\",\n        \"periodStart\": \"2026-01-01\",\n        \"periodEnd\": \"2026-06-30\",\n        \"owner\": \"Fictional security lead\",\n        \"authorized\": true,\n        \"confirmed\": true,\n        \"controlling\": true\n      },\n      {\n        \"id\": \"insurance-old\",\n        \"title\": \"Fictional expired insurance certificate\",\n        \"type\": \"insurance-certificate\",\n        \"family\": \"fictional-insurance\",\n        \"version\": \"Fictional v1\",\n        \"sourceRef\": \"Fictional insurance certificate page 1\",\n        \"issuedDate\": \"2025-09-01\",\n        \"expiresDate\": \"2026-09-01\",\n        \"periodStart\": \"\",\n        \"periodEnd\": \"\",\n        \"owner\": \"Fictional finance lead\",\n        \"authorized\": true,\n        \"confirmed\": true,\n        \"controlling\": true\n      }\n    ],\n    \"mappings\": [\n      {\n        \"requirementId\": \"security\",\n        \"evidenceIds\": [\n          \"security-current\"\n        ],\n        \"reviewed\": true,\n        \"reviewer\": \"Fictional security reviewer\",\n        \"decision\": \"accepted\",\n        \"note\": \"Fictional reviewer accepted this literal mapping for this example only.\"\n      },\n      {\n        \"requirementId\": \"insurance\",\n        \"evidenceIds\": [\n          \"insurance-old\"\n        ],\n        \"reviewed\": true,\n        \"reviewer\": \"Fictional finance reviewer\",\n        \"decision\": \"accepted\",\n        \"note\": \"Fictional mapping retained so the expired evidence remains visible.\"\n      }\n    ]\n  },\n  \"output\": {\n    \"schemaVersion\": 1,\n    \"status\": \"needs_review\",\n    \"evaluationDate\": \"2026-10-03\",\n    \"vendorName\": \"Fictional Harbor Systems\",\n    \"counts\": {\n      \"supported\": 1,\n      \"missing\": 1,\n      \"stale\": 1,\n      \"notApplicable\": 1,\n      \"needsReview\": 0,\n      \"criticalOpen\": 1\n    },\n    \"requirements\": [\n      {\n        \"requirementId\": \"security\",\n        \"title\": \"Fictional security evidence\",\n        \"owner\": \"Fictional security lead\",\n        \"critical\": true,\n        \"status\": \"supported\",\n        \"evidenceIds\": [\n          \"security-current\"\n        ],\n        \"issues\": []\n      },\n      {\n        \"requirementId\": \"continuity\",\n        \"title\": \"Fictional continuity test\",\n        \"owner\": \"Fictional operations lead\",\n        \"critical\": true,\n        \"status\": \"missing\",\n        \"evidenceIds\": [],\n        \"issues\": [\n          \"missing_mapping\"\n        ]\n      },\n      {\n        \"requirementId\": \"insurance\",\n        \"title\": \"Fictional insurance evidence\",\n        \"owner\": \"Fictional finance lead\",\n        \"critical\": false,\n        \"status\": \"stale\",\n        \"evidenceIds\": [\n          \"insurance-old\"\n        ],\n        \"issues\": [\n          \"mapped_evidence_stale\"\n        ]\n      },\n      {\n        \"requirementId\": \"onsite\",\n        \"title\": \"Fictional on-site access evidence\",\n        \"owner\": \"Fictional facilities lead\",\n        \"critical\": false,\n        \"status\": \"not_applicable\",\n        \"evidenceIds\": [],\n        \"issues\": []\n      }\n    ],\n    \"issues\": [\n      {\n        \"code\": \"expired_evidence\",\n        \"message\": \"The evidence has expired as of the evaluation date.\",\n        \"blocking\": false,\n        \"evidenceId\": \"insurance-old\"\n      },\n      {\n        \"code\": \"missing_mapping\",\n        \"message\": \"Supply an explicit mapping to the evidence for this requirement.\",\n        \"blocking\": true,\n        \"requirementId\": \"continuity\"\n      },\n      {\n        \"code\": \"mapped_evidence_stale\",\n        \"message\": \"Mapped evidence is expired as of the evaluation date.\",\n        \"blocking\": true,\n        \"requirementId\": \"insurance\"\n      }\n    ],\n    \"actionQueue\": [\n      {\n        \"id\": \"action-1\",\n        \"requirementId\": \"continuity\",\n        \"evidenceId\": null,\n        \"owner\": \"Fictional operations lead\",\n        \"action\": \"Resolve missing evidence for requirement continuity.\",\n        \"critical\": true,\n        \"deadline\": null\n      },\n      {\n        \"id\": \"action-2\",\n        \"requirementId\": \"insurance\",\n        \"evidenceId\": null,\n        \"owner\": \"Fictional finance lead\",\n        \"action\": \"Resolve stale evidence for requirement insurance.\",\n        \"critical\": false,\n        \"deadline\": null\n      },\n      {\n        \"id\": \"action-3\",\n        \"requirementId\": \"continuity\",\n        \"evidenceId\": null,\n        \"owner\": \"Fictional operations lead\",\n        \"action\": \"Supply an explicit mapping to the evidence for this requirement.\",\n        \"critical\": true,\n        \"deadline\": null\n      },\n      {\n        \"id\": \"action-4\",\n        \"requirementId\": \"insurance\",\n        \"evidenceId\": null,\n        \"owner\": \"Fictional finance lead\",\n        \"action\": \"Mapped evidence is expired as of the evaluation date.\",\n        \"critical\": false,\n        \"deadline\": null\n      }\n    ],\n    \"limitations\": [\n      \"This compares a buyer checklist with caller-declared evidence metadata and explicit reviewer decisions. It does not ingest documents or judge semantic adequacy, vendor risk, compliance, security or approval.\",\n      \"Supported means the declared mapping, exact type, source/version, date and coverage checks passed. A SOC 2 label, authorization checkbox or accepted decision does not independently establish sufficiency.\",\n      \"All applicability, source rights, confirmations and reviewer decisions are declarations. Source references are inert text and are never fetched.\",\n      \"Expiry is inclusive of the entered date. Blank expiry means expiry was not supplied; it does not establish indefinite freshness. Blank periods mean coverage was not declared or checked.\",\n      \"Every explicitly mapped evidence record must cover the entire entered required period. Partial coverage from multiple records is not combined or inferred.\",\n      \"Actions use supplied owners or the named review owner, have no invented deadlines, and are not sent or scheduled. A missing owner remains explicitly unassigned.\"\n    ]\n  }\n}",
      "byteLength": 8321,
      "sha256": "78d1bba4ca921d757b875b52de9d3b99d1a723610ff32570f47ed2301078a587",
      "review": {
        "reviewer": "",
        "reviewedDate": "",
        "note": "",
        "confirmed": false
      }
    },
    {
      "id": "agent-permissions",
      "filename": "agent-permissions-fictional-report.json",
      "workflow": "Agent Permission Review",
      "kind": "report",
      "content": "{\n  \"fictional\": true,\n  \"origin\": \"Local deterministic module called by build-demo.mjs; identity and source rights not independently verified.\",\n  \"input\": {\n    \"schemaVersion\": 1,\n    \"evaluationDate\": \"2026-10-03\",\n    \"reviewOwner\": \"Fictional inventory reviewer\",\n    \"inventoryComplete\": false,\n    \"agents\": [\n      {\n        \"id\": \"fictional-policy-agent\",\n        \"name\": \"Fictional policy reader\",\n        \"owner\": \"Fictional knowledge owner\",\n        \"purpose\": \"Read the named fictional policy collection.\",\n        \"sourceRef\": \"Fictional configuration register, row 1\",\n        \"version\": \"Fictional 1\",\n        \"configurationAuthorized\": true,\n        \"configurationConfirmed\": true,\n        \"identityRef\": \"Fictional service identity register, row 1\",\n        \"reviewedDate\": \"2026-09-15\",\n        \"nextReviewDate\": \"2026-12-15\",\n        \"tools\": [\n          {\n            \"id\": \"policy-read\",\n            \"name\": \"Read named policy collection\",\n            \"capability\": \"read\",\n            \"dataClassification\": \"internal\",\n            \"resources\": [\n              \"Fictional Policy Collection A\"\n            ],\n            \"scopeMode\": \"named\",\n            \"approval\": \"standing_permission\",\n            \"controlEvidenceRef\": \"Fictional permission test A\",\n            \"controlVerified\": true,\n            \"logEvidenceRef\": \"Fictional read log A\",\n            \"logsVerified\": true\n          }\n        ],\n        \"revocation\": {\n          \"route\": \"Fictional administrator revokes Collection A role\",\n          \"owner\": \"Fictional platform owner\",\n          \"tested\": true,\n          \"evidenceRef\": \"Fictional revocation test A\"\n        }\n      },\n      {\n        \"id\": \"fictional-outreach-agent\",\n        \"name\": \"Fictional outreach assistant\",\n        \"owner\": \"\",\n        \"purpose\": \"Prepare and send fictional account follow-ups.\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"version\": \"Fictional 2\",\n        \"configurationAuthorized\": true,\n        \"configurationConfirmed\": false,\n        \"identityRef\": \"\",\n        \"reviewedDate\": \"2026-08-01\",\n        \"nextReviewDate\": \"2026-09-01\",\n        \"tools\": [\n          {\n            \"id\": \"outreach-send\",\n            \"name\": \"Send follow-up\",\n            \"capability\": \"send\",\n            \"dataClassification\": \"confidential\",\n            \"resources\": [\n              \"*\"\n            ],\n            \"scopeMode\": \"wildcard\",\n            \"approval\": \"always_for_action\",\n            \"controlEvidenceRef\": \"Fictional approval test pending\",\n            \"controlVerified\": false,\n            \"logEvidenceRef\": \"\",\n            \"logsVerified\": false\n          }\n        ],\n        \"revocation\": {\n          \"route\": \"Fictional connector disable route\",\n          \"owner\": \"Fictional platform owner\",\n          \"tested\": false,\n          \"evidenceRef\": \"\"\n        }\n      }\n    ]\n  },\n  \"output\": {\n    \"schemaVersion\": 1,\n    \"status\": \"needs_evidence\",\n    \"summary\": {\n      \"inventoryCompleteDeclared\": false,\n      \"evidenceComplete\": false,\n      \"priorityReviewRequired\": true,\n      \"reviewedAgents\": 2,\n      \"declaredTools\": 2,\n      \"evidenceGaps\": 11,\n      \"priorityItems\": 6\n    },\n    \"findings\": [\n      {\n        \"id\": \"finding-1\",\n        \"code\": \"inventory_incomplete\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": null,\n        \"toolId\": null,\n        \"owner\": \"Fictional inventory reviewer\",\n        \"sourceRef\": \"\",\n        \"message\": \"The declared inventory is not marked complete. Agents outside it are not assessed.\",\n        \"action\": \"Complete the declared inventory or record its coverage limits.\",\n        \"declaredReviewDate\": \"\"\n      },\n      {\n        \"id\": \"finding-2\",\n        \"code\": \"missing_agent_owner\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Missing accountable agent owner.\",\n        \"action\": \"Supply the accountable agent owner; do not infer it from the agent label.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-3\",\n        \"code\": \"missing_identity_reference\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Missing declared identity or channel attribution reference.\",\n        \"action\": \"Supply the declared identity or channel attribution reference; do not infer it from the agent label.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-4\",\n        \"code\": \"configuration_not_confirmed\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The entered configuration has not been confirmed against its declared source.\",\n        \"action\": \"Review the exact configuration version and confirm the entered inventory.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-5\",\n        \"code\": \"overdue_review\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The declared next review date is before the evaluation date.\",\n        \"action\": \"Ask the owner to review the current configuration and supply the resulting evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-6\",\n        \"code\": \"missing_revocation_evidence\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"No evidence reference for the revocation route/test is supplied.\",\n        \"action\": \"Reference the revocation evidence for this exact configuration.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-7\",\n        \"code\": \"revocation_not_tested\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"A revocation test has not been declared.\",\n        \"action\": \"Have the authorized operator test the route separately and record the outcome.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-8\",\n        \"code\": \"broad_resource_scope\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The tool declares wildcard or unresolved broad resource scope. This review cannot prove its actual boundary.\",\n        \"action\": \"Review and document a narrower resource boundary or the explicitly accepted scope with the owner.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-9\",\n        \"code\": \"control_not_verified\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Control behavior has not been declared verified. Supplied metadata alone cannot establish enforcement.\",\n        \"action\": \"Have an authorized operator validate the control separately and record its evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-10\",\n        \"code\": \"missing_log_evidence\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"No log evidence reference is supplied.\",\n        \"action\": \"Reference the available tool/action logging evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-11\",\n        \"code\": \"logging_not_verified\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Logging behavior has not been declared verified.\",\n        \"action\": \"Have an authorized operator validate logging separately and record the evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-12\",\n        \"code\": \"sensitive_high_impact_capability\",\n        \"type\": \"priority_review\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The declared send capability touches confidential resources, even if its evidence declarations are complete.\",\n        \"action\": \"Obtain human review of this capability, its data scope and the action-specific approval route before a separate action workflow.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      }\n    ],\n    \"agents\": [\n      {\n        \"agentId\": \"fictional-policy-agent\",\n        \"name\": \"Fictional policy reader\",\n        \"owner\": \"Fictional knowledge owner\",\n        \"evidenceComplete\": true,\n        \"priorityReviewRequired\": false,\n        \"tools\": [\n          {\n            \"toolId\": \"policy-read\",\n            \"name\": \"Read named policy collection\",\n            \"capability\": \"read\",\n            \"dataClassification\": \"internal\",\n            \"declaredApproval\": \"standing_permission\",\n            \"scopeMode\": \"named\",\n            \"evidenceComplete\": true,\n            \"priorityReviewRequired\": false\n          }\n        ]\n      },\n      {\n        \"agentId\": \"fictional-outreach-agent\",\n        \"name\": \"Fictional outreach assistant\",\n        \"owner\": \"\",\n        \"evidenceComplete\": false,\n        \"priorityReviewRequired\": true,\n        \"tools\": [\n          {\n            \"toolId\": \"outreach-send\",\n            \"name\": \"Send follow-up\",\n            \"capability\": \"send\",\n            \"dataClassification\": \"confidential\",\n            \"declaredApproval\": \"always_for_action\",\n            \"scopeMode\": \"wildcard\",\n            \"evidenceComplete\": false,\n            \"priorityReviewRequired\": true\n          }\n        ]\n      }\n    ],\n    \"reviewQueue\": [\n      {\n        \"id\": \"finding-5\",\n        \"code\": \"overdue_review\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The declared next review date is before the evaluation date.\",\n        \"action\": \"Ask the owner to review the current configuration and supply the resulting evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-8\",\n        \"code\": \"broad_resource_scope\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The tool declares wildcard or unresolved broad resource scope. This review cannot prove its actual boundary.\",\n        \"action\": \"Review and document a narrower resource boundary or the explicitly accepted scope with the owner.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-9\",\n        \"code\": \"control_not_verified\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Control behavior has not been declared verified. Supplied metadata alone cannot establish enforcement.\",\n        \"action\": \"Have an authorized operator validate the control separately and record its evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-10\",\n        \"code\": \"missing_log_evidence\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"No log evidence reference is supplied.\",\n        \"action\": \"Reference the available tool/action logging evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-11\",\n        \"code\": \"logging_not_verified\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Logging behavior has not been declared verified.\",\n        \"action\": \"Have an authorized operator validate logging separately and record the evidence.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-12\",\n        \"code\": \"sensitive_high_impact_capability\",\n        \"type\": \"priority_review\",\n        \"priority\": \"priority\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": \"outreach-send\",\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The declared send capability touches confidential resources, even if its evidence declarations are complete.\",\n        \"action\": \"Obtain human review of this capability, its data scope and the action-specific approval route before a separate action workflow.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-1\",\n        \"code\": \"inventory_incomplete\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": null,\n        \"toolId\": null,\n        \"owner\": \"Fictional inventory reviewer\",\n        \"sourceRef\": \"\",\n        \"message\": \"The declared inventory is not marked complete. Agents outside it are not assessed.\",\n        \"action\": \"Complete the declared inventory or record its coverage limits.\",\n        \"declaredReviewDate\": \"\"\n      },\n      {\n        \"id\": \"finding-2\",\n        \"code\": \"missing_agent_owner\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Missing accountable agent owner.\",\n        \"action\": \"Supply the accountable agent owner; do not infer it from the agent label.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-3\",\n        \"code\": \"missing_identity_reference\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"Missing declared identity or channel attribution reference.\",\n        \"action\": \"Supply the declared identity or channel attribution reference; do not infer it from the agent label.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-4\",\n        \"code\": \"configuration_not_confirmed\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"The entered configuration has not been confirmed against its declared source.\",\n        \"action\": \"Review the exact configuration version and confirm the entered inventory.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-6\",\n        \"code\": \"missing_revocation_evidence\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"No evidence reference for the revocation route/test is supplied.\",\n        \"action\": \"Reference the revocation evidence for this exact configuration.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      },\n      {\n        \"id\": \"finding-7\",\n        \"code\": \"revocation_not_tested\",\n        \"type\": \"evidence_gap\",\n        \"priority\": \"routine\",\n        \"agentId\": \"fictional-outreach-agent\",\n        \"toolId\": null,\n        \"owner\": \"\",\n        \"sourceRef\": \"Fictional configuration register, row 2\",\n        \"message\": \"A revocation test has not been declared.\",\n        \"action\": \"Have the authorized operator test the route separately and record the outcome.\",\n        \"declaredReviewDate\": \"2026-09-01\"\n      }\n    ],\n    \"limitations\": [\n      \"This is a deterministic review of a supplied, declared inventory. It does not discover unregistered or hidden agents, fetch configuration sources, connect accounts, grant permissions or execute actions.\",\n      \"Configuration confirmations, control/log verification, revocation tests, source references and identity references are reviewer declarations. This tool does not independently verify controls, identity, authentication or enforcement.\",\n      \"Evidence completeness and priority review are separate. Evidence-complete does not authorize a capability, approve any particular action, establish compliance, or certify an agent as safe.\",\n      \"Capabilities, classifications, scope and approval modes are explicit input labels. MCP tool annotations or local metadata cannot establish the true capability boundary or prove human-versus-agent channel attribution.\",\n      \"MCP readOnlyHint is untrusted descriptive metadata, never enforcement. Effective behavior and permissions remain independently unverified even when supplied verification booleans are true; wildcard or unknown scope stays unresolved for read capabilities too.\",\n      \"Opaque provider role names do not establish direct, inherited, app-only or delegated permissions. Ask separately for the accountable sponsor, administrator and provider export timestamp; these follow-up details are outside this fixed inventory schema.\",\n      \"Review dates are supplied UTC calendar dates. Queue dates are copied only from the declared next review date; this tool schedules nothing and invents no deadline.\",\n      \"Wildcard/unresolved scope and mutating actions with no declared approval are review rules in this prototype, not a universal security policy, blacklist, legal conclusion or numerical security score.\"\n    ]\n  }\n}",
      "byteLength": 19364,
      "sha256": "61a5f479088e4e05c41b19d2439288d5581136bc0d04d11dacfe293ee5d80225",
      "review": {
        "reviewer": "",
        "reviewedDate": "",
        "note": "",
        "confirmed": false
      }
    }
  ]
}
