{
  "profile": {
    "name": "CMMC 20X evidence profile",
    "schema_version": "0.1-discussion-draft",
    "schema_uri": "https://cmmc20x.com/downloads/cmmc20x-evidence-profile-v0.1.schema.json",
    "package_id": "syn-pkg-2026-001",
    "published_at": "2026-08-13T00:00:00Z",
    "status": "synthetic-discussion-draft",
    "license": "UNLICENSED",
    "synthetic": true,
    "notice": "Contains no customer, contractor, CUI, FCI, export-controlled, credential, or production data. Not a conformity, assessment, authorization, or program result."
  },
  "scope": {
    "system_id": "syn-enclave-01",
    "name": "Synthetic engineering enclave",
    "boundary_version": "2026-08-01",
    "environments": [
      "synthetic-commercial-cloud",
      "synthetic-managed-endpoints"
    ],
    "cui_flows": [
      "synthetic-design-file-workflow"
    ],
    "providers": [
      {
        "provider_id": "syn-msp-01",
        "function": "endpoint administration",
        "customer_responsibilities": [
          "approve privileged access",
          "review exceptions"
        ],
        "provider_responsibilities": [
          "maintain the managed endpoint agent",
          "produce versioned endpoint administration evidence"
        ],
        "limitations": [
          "does not administer identity policy",
          "does not observe local emergency accounts"
        ]
      }
    ]
  },
  "responsibility_records": [
    {
      "responsibility_id": "resp-msp-mfa-01",
      "provider_id": "syn-msp-01",
      "requirement_id": "3.5.3",
      "allocation": "shared",
      "inherited": true,
      "consumer_duties": [
        "configure identity policy",
        "approve and review emergency-account exceptions"
      ],
      "valid_from": "2026-08-01T00:00:00Z",
      "valid_until": "2026-09-01T00:00:00Z",
      "limitations": [
        "provider evidence covers managed endpoints only",
        "consumer remains responsible for identity and local-account policy"
      ]
    }
  ],
  "claims": [
    {
      "claim_id": "claim-ia-3.5.3-01",
      "requirement_id": "3.5.3",
      "assessment_objective_ids": [
        "3.5.3[a]",
        "3.5.3[b]"
      ],
      "assertion": "Multifactor authentication is enforced for synthetic privileged and network access paths in scope.",
      "owner_role": "synthetic-security-lead",
      "support_status": "uncertain",
      "review_state": "returned",
      "evidence_ids": [
        "evidence-idp-coverage-01",
        "evidence-exception-register-01"
      ],
      "responsibility_ids": [
        "resp-msp-mfa-01"
      ],
      "conflict_ids": [
        "conflict-emergency-coverage-01"
      ],
      "freshness": {
        "maximum_age_days": 7,
        "last_supported_at": "2026-08-10T12:00:00Z",
        "next_review_due": "2026-08-17T12:00:00Z"
      },
      "change_triggers": [
        "identity-policy-change",
        "new-access-path",
        "provider-responsibility-change"
      ]
    }
  ],
  "source_evidence": [
    {
      "evidence_id": "evidence-idp-coverage-01",
      "type": "structured-configuration-export",
      "source_system": "synthetic-identity-provider",
      "collection_method": "read-only-api",
      "collected_by_role": "synthetic-evidence-operator",
      "observed_at": "2026-08-10T12:00:00Z",
      "scope": [
        "synthetic-privileged-accounts",
        "synthetic-remote-access"
      ],
      "coverage": {
        "population_description": "synthetic accounts visible to the identity-provider export",
        "observed_count": 24,
        "expected_count": 24
      },
      "integrity": {
        "algorithm": "sha-256",
        "digest": "d489b55bd14ee968acb329fe6dedf82f8a821d3a52416a249da7037cf1491abd",
        "digest_input": "synthetic URI recorded for schema demonstration; no underlying customer artifact is included"
      },
      "provenance": {
        "origin": "synthetic://identity-provider/export/2026-08-10T12:00:00Z",
        "content_status": "synthetic-placeholder",
        "transformations": [
          "normalized field names for the discussion draft"
        ],
        "chain_of_custody": [
          "generated in synthetic fixture",
          "hashed as a synthetic URI",
          "attached to package syn-pkg-2026-001"
        ]
      },
      "review_state": "machine-checked",
      "limitations": [
        "does not observe local emergency accounts",
        "digest demonstrates an integrity field and does not represent customer content"
      ]
    },
    {
      "evidence_id": "evidence-exception-register-01",
      "type": "reviewed-record",
      "source_system": "synthetic-exception-register",
      "collection_method": "approved-export",
      "collected_by_role": "synthetic-evidence-operator",
      "observed_at": "2026-08-09T17:00:00Z",
      "scope": [
        "synthetic-emergency-accounts"
      ],
      "coverage": {
        "population_description": "synthetic emergency-account exception rows",
        "observed_count": 1,
        "expected_count": 1
      },
      "integrity": {
        "algorithm": "sha-256",
        "digest": "680d023a0786ef09773006a50a0c4177094d3aea62847236a91d7ddc25d056c8",
        "digest_input": "synthetic URI recorded for schema demonstration; no underlying customer artifact is included"
      },
      "provenance": {
        "origin": "synthetic://exception-register/export/2026-08-09T17:00:00Z",
        "content_status": "synthetic-placeholder",
        "transformations": [],
        "chain_of_custody": [
          "generated in synthetic fixture",
          "hashed as a synthetic URI",
          "attached to package syn-pkg-2026-001"
        ]
      },
      "review_state": "human-reviewed",
      "limitations": [
        "register documents an exception but does not prove factor enforcement",
        "requires reviewer interpretation"
      ]
    }
  ],
  "conflicts": [
    {
      "conflict_id": "conflict-emergency-coverage-01",
      "status": "open",
      "subject_ids": [
        "claim-ia-3.5.3-01",
        "evidence-idp-coverage-01",
        "evidence-exception-register-01"
      ],
      "description": "The identity-provider export reports complete coverage for its visible population while the exception register identifies a local emergency-account path outside that export.",
      "required_action": "Collect source evidence for local emergency-account factor enforcement or narrow and re-review the claim."
    }
  ],
  "deterministic_checks": [
    {
      "check_id": "check-package-conformance-01",
      "rule_version": "draft-0.1",
      "input_ids": [
        "claim-ia-3.5.3-01",
        "evidence-idp-coverage-01",
        "evidence-exception-register-01",
        "conflict-emergency-coverage-01"
      ],
      "executed_at": "2026-08-13T00:00:00Z",
      "result": "pass-with-limitation",
      "tested": [
        "schema-conformance",
        "identifier-uniqueness",
        "reference-integrity",
        "source-time-scope-and-integrity-fields",
        "layer-separation",
        "synthetic-data-boundary",
        "material-change-propagation"
      ],
      "does_not_decide": [
        "evidence-authenticity",
        "evidence-sufficiency",
        "requirement-satisfaction",
        "assessment-result",
        "authorized-decision"
      ]
    }
  ],
  "machine_analysis": [
    {
      "analysis_id": "analysis-candidate-01",
      "status": "candidate-for-human-review",
      "model_version": "synthetic-model-version",
      "input_ids": [
        "claim-ia-3.5.3-01",
        "evidence-idp-coverage-01",
        "evidence-exception-register-01",
        "conflict-emergency-coverage-01"
      ],
      "created_at": "2026-08-11T15:00:00Z",
      "candidate_finding": "The structured export supports factor coverage for observed paths; the local emergency-account conflict requires human examination.",
      "limitations": [
        "not an assessment finding",
        "not an authorized decision",
        "synthetic output does not establish model quality"
      ]
    }
  ],
  "human_dispositions": [
    {
      "disposition_id": "review-01",
      "reviewer_role": "synthetic-qualified-reviewer",
      "analysis_id": "analysis-candidate-01",
      "decision": "return-for-additional-evidence",
      "rationale": "The local emergency-account path is inside the stated boundary but not covered by evidence of factor enforcement.",
      "decided_at": "2026-08-11T16:30:00Z",
      "superseded_by_change_id": "change-01"
    }
  ],
  "authorized_decisions": [
    {
      "decision_id": "decision-none-01",
      "status": "not-issued",
      "authority": "none",
      "legal_or_program_effect": "none"
    }
  ],
  "material_changes": [
    {
      "change_id": "change-01",
      "event": "new-access-path",
      "occurred_at": "2026-08-12T14:00:00Z",
      "affected_ids": [
        "claim-ia-3.5.3-01",
        "evidence-idp-coverage-01",
        "analysis-candidate-01",
        "review-01"
      ],
      "effect": "support-status-uncertain",
      "required_action": "Collect source evidence for the new path, resolve or restate the open conflict, and repeat accountable human review.",
      "recorded_by_role": "synthetic-security-lead"
    }
  ]
}
