{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "PARR",
  "title": "Policy Approval and Review Register",
  "definitionRef": {
    "artifactId": "PARR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "PARR.artifactDefinition.v2",
    "title": "Policy Approval and Review Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Policy Approval and Review Register",
        "Register ID": "PARR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Policy Approval and Review Register",
        "Register ID: PARR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "The Policy Approval and Review Register provides a controlled, implementation-ready way to control policy approval, periodic review, version status, and traceable publication. It connects accountable work to source-system evidence, review decisions and follow-up actions so that the artifact can support both day-to-day operation and audit sampling. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Control policy approval, periodic review, version status, and traceable publication."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Policy Owners, Document Controller"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "operational record"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 clauses 5.2 and 7.5"
        },
        {
          "Property": "Review cadence",
          "Value": "Whenever a policy is drafted, approved, reviewed, revised, or retired."
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Maintain one row per controlled policy and version.",
        "Record owner, approver, approval date, next review, status, repository link, superseded version, and evidence of communication.",
        "Link every material conclusion to an authoritative and exportable source record.",
        "Assign an accountable owner and due date for each unresolved issue.",
        "Review and approve the completed artifact before it is used as audit evidence.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "policy_approval_and_review_register",
      "title": "Policy approval and review register",
      "rows": [
        {
          "Policy ID": "PARR-001",
          "Policy title": "Production access review",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Version": "2026.09.1",
          "Approval date": "2026-08-29",
          "Effective date": "2026-08-29",
          "Next review": "Defined and evidenced",
          "Publication location": "GRC / evidence / 2026-Q3",
          "Communication evidence": "JIRA-SEC-2026-014",
          "Status": "Complete"
        },
        {
          "Policy ID": "PARR-002",
          "Policy title": "Security evidence validation",
          "Owner": "Security Lead",
          "Approver": "ISMS Manager",
          "Version": "v1.0",
          "Approval date": "2026-09-30",
          "Effective date": "2026-09-30",
          "Next review": "Reviewed by accountable owner",
          "Publication location": "Jira SEC-142",
          "Communication evidence": "GRC-EVID-2026-Q3",
          "Status": "In progress"
        },
        {
          "Policy ID": "PARR-003",
          "Policy title": "Quarterly control review",
          "Owner": "Control Owner",
          "Approver": "Security Lead",
          "Version": "build-4821",
          "Approval date": "2026-11-29",
          "Effective date": "2026-11-29",
          "Next review": "See linked source record",
          "Publication location": "Approved cloud vault",
          "Communication evidence": "REVIEW-2026-Q3",
          "Status": "Pending review"
        },
        {
          "Policy ID": "PARR-004",
          "Policy title": "Supplier control verification",
          "Owner": "ISMS Manager",
          "Approver": "Top Management",
          "Version": "2026.10.0",
          "Approval date": "2026-08-29",
          "Effective date": "2026-08-29",
          "Next review": "Approved with follow-up",
          "Publication location": "GitHub PR 4821",
          "Communication evidence": "JIRA-SEC-2026-014",
          "Status": "Complete"
        },
        {
          "Policy ID": "PARR-005",
          "Policy title": "Release security approval",
          "Owner": "Security Lead",
          "Approver": "ISMS Manager",
          "Version": "build-4938",
          "Approval date": "2026-09-30",
          "Effective date": "2026-09-30",
          "Next review": "Pending independent review",
          "Publication location": "ServiceNow CHG-2204",
          "Communication evidence": "GRC-EVID-2026-Q3",
          "Status": "In progress"
        }
      ],
      "schemaRef": {
        "definitionId": "PARR.artifactDefinition.v2",
        "sectionId": "policy_approval_and_review_register",
        "columnsRef": "sections.policy_approval_and_review_register.columns"
      },
      "contentType": "register_table"
    },
    {
      "id": "policy_approval_and_review_register_review",
      "title": "Policy Approval and Review Register review",
      "rows": [
        {
          "Field": "Review result",
          "Value": "Approved as an implementation candidate with JSON Definition, JSON Example and rendered-file QA still required."
        },
        {
          "Field": "Records reviewed",
          "Value": "5 example records"
        },
        {
          "Field": "Open issues",
          "Value": "Contract and renderer implementation pending"
        },
        {
          "Field": "Action owner",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-05"
        },
        {
          "Field": "Evidence reference",
          "Value": "PARR-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Internal Audit & Management Review",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
