Appendices

Appendix A: Evidence Artifact Catalogue

Working draft

This page renders the current awoss working draft. It is not a released standard, certification program, compliance framework, legal analysis, endorsement, or public conformance claim.

This appendix gives first-pass evidence examples. It is not exhaustive.

ArtifactSupportsExpected ownerMinimum metadataRedaction guidance
Scope recordAWOSS-SCP, AWOSS-GOVOrganization or governancesystem name, boundary, owners, exclusions, dateavoid exporting unrelated system contents
Runtime and tool inventoryAWOSS-SCP, AWOSS-RUN, AWOSS-SRCRuntime platformruntime, tools, connectors, skills, versions, ownersavoid secrets in configuration details
Connected resource inventoryAWOSS-SCP, AWOSS-WSB, AWOSS-SECWorkspace or endpointrepositories, files, SaaS systems, shells, networks, data categorieslist categories and scopes, not confidential payloads
Owner matrixAWOSS-SCP, AWOSS-DEL, AWOSS-GOVOrganization or governanceowner roles, responsibilities, review datesminimize personal data where role data is enough
Authority modelAWOSS-DEL, AWOSS-RUNOrganization or governanceuser roles, service accounts, delegated authority, approval rolesdo not expose credentials or private identity tokens
Runtime policy exportAWOSS-RUN, AWOSS-CTX, AWOSS-SECRuntime platformpolicy version, action classes, allow/deny/approval rulesredact live tokens, prompts, and sensitive examples
Approval policyAWOSS-DEL, AWOSS-RUN, AWOSS-GOVOrganization or governanceapprover roles, triggers, expiry, escalationsummarize approver roles when names are unnecessary
Workspace boundary configurationAWOSS-WSB, AWOSS-SECWorkspace or endpointsandbox, filesystem, repository, network, connector scopesredact sensitive paths only when review remains possible
Source registerAWOSS-SRC, AWOSS-GOVSkill or skill-set sourcesource, maintainer, version, commit, checksum, approval stateshare identifiers and hashes before private source code
Source-trust profile recordAWOSS-SRC, AWOSS-LOG, AWOSS-GOV, AWOSS-VALSkill or skill-set source, runtime platform, or evidence owneraction-unit ID, registry or source signal, publisher or namespace status, manifest/hash/signature if available, declared permissions, local review state, drift, rollback or retirement pathpreserve identifiers, hashes, metadata, and review decisions; avoid proprietary connector internals, tokens, and raw sensitive payloads
Dependency or lockfile recordAWOSS-SRC, AWOSS-VALSkill or skill-set sourcepackage names, versions, hashes, resolution dateavoid embedding private registry credentials
Installation or update receiptAWOSS-SRC, AWOSS-LOGRuntime platformsource, version, actor, timestamp, approval stateremove credentials and unrelated payloads
High-impact action receiptAWOSS-RUN, AWOSS-LOG, AWOSS-VALEvidence or auditevent ID, timestamp, actor, action class, scope, policy outcomerecord metadata and stable references, not raw secrets
Denied-action recordAWOSS-RUN, AWOSS-LOG, AWOSS-VALEvidence or auditpolicy rule, attempted action class, timestamp, actor or runtimeredact attempted payloads that contain sensitive data
Sensitive-data handling recordAWOSS-SEC, AWOSS-LOG, AWOSS-VALWorkspace or endpointdata category, access rule, redaction state, export outcomeavoid raw personal data or secrets
Context-source inventoryAWOSS-CTX, AWOSS-SCPRuntime platforminstruction sources, memory sources, retrieval sources, trust orderdo not export confidential corpus contents unnecessarily
Context-boundary testAWOSS-CTX, AWOSS-VALEvidence or auditscenario, expected policy, result, finding, remediationsummarize exploit details when disclosure would increase risk
Validation reportAWOSS-VAL, all familiesEvidence or auditscope, controls reviewed, method, findings, date, reviewerpublish findings and status before raw test data
Exception registerAWOSS-GOV, AWOSS-VALOrganization or governanceexception, owner, rationale, expiry, remediation planavoid unnecessary personnel and business-sensitive detail
Claim-limit recordAWOSS-GOV, mapping evidenceOrganization or governancestatement, scope, control subset, evidence basis, prohibited claimskeep external-facing wording bounded and reviewable