Skip to content

Add access review SoD evidence fixtures#1487

Open
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/access-sod-fixtures-889
Open

Add access review SoD evidence fixtures#1487
jddark62 wants to merge 1 commit into
UnitOneAI:mainfrom
jddark62:improve/access-sod-fixtures-889

Conversation

@jddark62

@jddark62 jddark62 commented Jun 6, 2026

Copy link
Copy Markdown

Summary

  • adds AR-SOD-08 through AR-SOD-14 evidence gates for SoD rule provenance, transaction-path proof, cross-system toxic combinations, scope false-positive guards, compensating-control operation, JIT/emergency activation evidence, and certifier independence
  • adds a SoD evidence model and severity calibration so role-name matches are not over-scored without effective transaction capability
  • extends the report output with a SoD Evidence Summary table
  • adds seven YAML fixtures covering confirmed production toxic access, sandbox/zero-limit false positives, missing rule provenance, unmapped cross-system paths, paper-only compensating controls, complete JIT activation evidence, and self-certified exceptions

Validation

  • git diff --check
  • frontmatter parse check
  • Markdown fence balance check
  • YAML fixture parse check: 7 blocks
  • required marker check for AR-SOD-08 through AR-SOD-14
  • privacy marker scan

/claim #889

Payment details can be coordinated privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant