What the build does, dated.
A licensee buys a maintained product. This page is the evidence: the capability the reference build ships, stated in the month it began shipping it, in the terms an auditor would use in the file. Every entry is traced to the code that makes it true — the same rule the platform applies to a test result.
Shipped capability only. Nothing on this page is planned, and the showcase at this domain runs on synthetic demonstration data.
September 2026
- 11 Sep
Quality review names the item it examined
Every data-integrity finding carries the population identifier of the sample it ran against — the ticket, the user, the log source — on the table, the card and the detail view, and the search box matches it.
- 11 Sep
Log retention measured against the client's policy
The security-logging retention check reads the population's stated policy minimum where a row carries one and applies a one-year floor otherwise; a shortfall is reported as a warning for the reviewer to acknowledge.
- 11 Sep
A draw records the basis of its size
Every sampling run records whether its size came from the frequency-of-control table or the attribute table, and the AU-C 530 evaluation reads that basis when it judges the results.
- 11 Sep
A failed change step is evidenced by its reference
In the change-management chain, a step recorded as failed is evidenced by the reference that records the failure; a step that never happened carries no time, and the sequence check applies to the steps that did.
- 10 Sep
The sample navigator shows the item's own identifier
On the Testing and Traceability steps the navigator prints the population identifier beside the sample index, so the reviewer moves between items by the value the workpaper quotes.
- 10 Sep
The workpaper export streams
The 14-section HTML workpaper streams to the browser in 256 KB chunks, so an engagement of any practical size exports in full from a single request.
- 10 Sep
Scanned PDFs are read in page ranges
Optical character recognition of a scanned PDF runs four pages per call inside a time budget; a range that runs long is halved and retried, and the evidence row states the outcome by name — no facts, too large with the size, or timed out.
- 10 Sep
Population columns map themselves to the template
On upload, the population's columns are matched to the control template's declared fields by exact and fuzzy header match; a generic role is filled only from an unambiguous column, otherwise it shares the declared field's column or stays empty for the auditor.
- 10 Sep
An interim date can be cleared
Engagement settings remove an interim date as readily as they set one, returning the engagement to period-end testing with the roll-forward requirement lifted.
- 10 Sep
The population identifier leads every sample view
Sample data displays the population's declared identifier first regardless of how many other fields the row carries.
- 10 Sep
Degraded shared services are stated, never guessed
When the shared coordination store is unavailable, AI-test progress reports itself as unknown and expensive work refuses to start unguarded; the reviewer sees the condition rather than a silent retry.
- 10 Sep
Bulk acceptance takes PASS results only
Accepting results in bulk applies to PASS verdicts at or above the category's confidence threshold; every other verdict waits for the reviewer's individual decision.
- 9 Sep
Every AI result is versioned
A re-run, acceptance, override, rejection or rationale edit snapshots the prior result into an append-only version table in the same transaction; the reviewer can open earlier versions, and section 7 of the workpaper states when a conclusion changed between runs.
- 9 Sep
The sampling parameters in force are recorded on the result
Each AI result stores the model requested and the model served, the temperature in force and the token limit, and the workpaper states where determinism holds.
- 9 Sep
Algorithm version and population fingerprint on every draw
Every sampling run records the version of the selection algorithm and the SHA-256 fingerprint and row count of the population at draw time, printed in section 6 beside the seed.
- 9 Sep
Any selection can be re-drawn and verified
A button and an endpoint re-derive a selection from its stored seed through the same code path and record whether it is identical, with who verified and when; section 6 prints the result.
- 9 Sep
A fact opens the document, on its page
Every extracted fact links to the evidence file it came from and opens the viewer at that page.
- 9 Sep
Facts are located in their source
At extraction, each fact value is searched for in the document's own text; the reviewer sees “in source” or “not located in source” on the fact, and section 7 prints how many of the facts behind a result were located.
- 9 Sep
Reopening a finalized engagement takes a written reason
Leaving the finalized state requires a reason, recorded with the before and after state in the audit trail and printed on the workpaper cover sheet.
- 9 Sep
A manual result carries its rationale
A manual fail, warning or not-applicable result requires a written rationale; a manual pass requires the evidence it rests on. A judgmental selection requires its basis, printed in section 6.
- 9 Sep
A second signature, or a declaration that there is none
A control's review signature must come from a user other than the one who signed it off or reviewed its AI results — the server refuses otherwise. An engagement with a single auditor declares so by a named person with a reason, and the cover sheet prints the reviewer and date or the declaration. Never blank.
- 9 Sep
Prior reviewer corrections inform the model
For each attribute under test, the model receives the tenant's five most recent reviewer corrections on that attribute, wrapped as untrusted context and instructed to apply the principle, not copy the outcome; the result records which corrections it saw, and section 7 says so.
- 9 Sep
An audit trail that is verified, not just read
A per-tenant SHA-256 hash chain is written on every audit row by a database trigger; a verification function and endpoint check the chain, the export verifies it and prints the outcome in section 12, and the application role holds no update or delete grant on the audit table.
- 9 Sep
Evidence hashes re-verified on demand
A stored evidence file can be streamed back and re-hashed at any time; the match or mismatch is recorded with both hashes, shown as a badge, printed in section 13, and the archive package re-hashes every bundled file.
- 9 Sep
Sampling results evaluated against the planned reliance
For every statistical run the exact binomial upper deviation limit is computed at sign-off against the tolerable rate that sized the sample; a pass conclusion is refused when the run does not support the planned reliance (AU-C 530.12), and section 6 prints the evaluation.
- 9 Sep
The confidence policy is printed with the results
Section 7 opens with the confidence policy — version, approver, date and the statement that a confidence score is the model's self-assessment, not a calibrated probability — and every bulk-accepted result is flagged as such.
- 9 Sep
Roll-forward from interim testing
When an engagement carries an interim date, every signed-off control records the procedures that extend its conclusion to period end (AS 2201.55) before the engagement finalizes; the record prints per control in section 7.
- 9 Sep
Period coverage and population provenance
At upload, the platform counts the rows inside, before and after the period of reliance, records who extracted the population, when, its as-of date and the reconciliation evidence, and prints all of it in section 6. Evidence files carry a source classification — client-provided, auditor-obtained, system-generated or third-party — printed in section 13.
- 9 Sep
The archive package
A ZIP export carries, per sampling run, the population as drawn with the selected flag, the seed, algorithm version, population hash, selected indices and verification result; every evidence file re-hashed with a manifest; the full audit trail; and the workpaper, which prints its own SHA-256. The package hash is returned with the download and recorded in the audit trail, and the cover sheet's “Prepared by” names the auditors who signed the work.
- 4 Sep
Every routed quality check runs
All 38 per-sample data-integrity check types execute, resolving columns by the role the template declares; a check whose role the population does not carry reports itself as not applicable rather than asserting a gap.
- 4 Sep
Age is measured from the engagement, not the calendar
Timeliness and age checks measure against the engagement's interim date or period end, so a signed workpaper reads the same on any later day.
- 4 Sep
A change chain is complete when it evidences its sequence
The five-node change-management chain is complete when each node is evidenced by a reference and its time; steps out of order are reported as a deviation.
- 3 Sep
Deficiency evaluation under PCAOB AS 2201
A control concluded not effective or ineffective carries an evaluation of likelihood and magnitude (AS 2201.63), compensating controls (.68) and material-weakness indicators (.69), required before the control locks and before the engagement finalizes; it prints as section 10 of the workpaper.
- 3 Sep
A manual testing path beside the AI
The auditor records their own result per attribute, citing the evidence for a pass; a manual result supersedes an AI result, and every gate — quality review, sign-off, finalization, export — reads the same effective result.
- 3 Sep
Systematic selection, sample extension and a not-applicable verdict
Systematic selection is a method of its own; a sample can be extended after a deviation; and an attribute whose condition does not arise for an item is recorded as not applicable and excluded from the conclusion.
- 3 Sep
Sample sizes from the frequency-of-control table
Periodic controls are sized from the AICPA frequency-of-control table, including the multiple-times-per-day row for on-demand and continuous controls; the attribute grid applies only when the auditor overrides a risk factor. A conclusion narrative has a floor of 120 characters, and there is no majority verdict.
- 3 Sep
The declared key is the sample's identity
The population's declared key identifies each item on upload, in de-duplication and when the AI correlates evidence to a sample; the reviewer's override, with its reason, prints beside every result in the workpaper, and exceptions raised in bulk follow the reviewer's conclusion.
- 2 Sep
Audit rows commit with the mutation they describe
Every audit-log entry is written in the same database transaction as the change it records, on every route.
August 2026
- 31 Aug
Rate limits bound the tenant, not the office
Expensive work is budgeted per tenant, so a firm's auditors never queue behind the office address they share; every drafting call passes the same account-level gate.
- 30 Aug
A source-escrow bundle for licensees
The licensed work is packaged separately from commercial material, so an escrow delivery contains the software and nothing else.
- 28 Aug
Evidence sources pinned to the deployment's own store
Evidence files are accepted only from the object store the deployment itself writes to, derived from its credentials; the server-side digest is computed from the stored bytes.
- 28 Aug
Public pages verified by script
Every public page is checked by a script for its heading outline, landmarks, canonical metadata and contact-source tagging, and its interactive targets are measured at six viewport widths, before a deploy is declared good.
- 27 Aug
One active draw per control and method; superseded draws kept
A control holds one active sampling run per method; a redraw supersedes the previous run without destroying it, and every read that reports on a sample reports on the active one.
July 2026
- 15 Jul
Evidence hashes verified at export
The workpaper export recomputes the SHA-256 of the evidence it indexes on the server before it prints the index.
- 14 Jul
Tenant isolation forced at the engine
Row-level security runs in FORCE mode on every tenant-scoped table, binding even table-owning roles; the audit log is append-only at two layers — no update or delete grant for the application role, and database triggers that reject the mutation for every role.
- 14 Jul
Full provenance in the workpaper and the testing CSV
Every test prints the model used, the confidence score, the extracted facts with their evidence context, the rationale and the evidence identifiers, in the workpaper and in the testing-results side-export.
- 14 Jul
37 control templates across four categories
The control library covers access, change, operations and security, including the software-development lifecycle, data-migration and interface-monitoring families, each template declaring its population schema, attributes, evidence expectations and quality-review rules.
Maintained means dated. A promise is not on this page.
The 80% coverage floor, the sign-off gates and the 14-section workpaper are described on the platform tour; this page records when each capability arrived.
Want to see one of these in the workpaper?
The provenance model shows where each of these facts lands in the exported file. Questions about any entry are welcome — they create no engagement and no obligation.