{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ACM",
  "title": "Access Control Matrix",
  "definitionRef": {
    "artifactId": "ACM",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ACM.artifactDefinition.v2",
    "title": "Access Control Matrix"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Matrix Title": "Access Control Matrix",
        "Matrix ID": "ACM-MTX-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "IT Operations Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Matrix Title: Access Control Matrix",
        "Matrix ID: ACM-MTX-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: IT Operations Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example defines approved role-based access patterns for Arcfield systems and services, including data scope, privilege, MFA, approval, segregation of duties, review frequency and evidence. This matrix is the mapping used by the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Map roles, systems, permissions and review responsibilities for access governance."
        },
        {
          "Property": "Used by",
          "Value": "IT Operations, System Owners, Access Owners, ISMS Manager, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "IT Operations Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Role-based access design and audit evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.15, A.5.16, A.5.18, A.8.2 and A.8.3"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after major system, role or process changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Define standard access patterns by role, not by named person.",
        "Record the system, data scope, access level and business justification.",
        "Identify whether access is privileged.",
        "Define approval role, MFA requirement and review frequency.",
        "Add segregation-of-duties notes for sensitive access.",
        "Use UAI and access reviews to evidence actual assignments against this matrix.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "access_control_matrix",
      "title": "Access control matrix",
      "schemaRef": {
        "definitionId": "ACM.artifactDefinition.v2",
        "sectionId": "access_control_matrix",
        "columnsRef": "sections.access_control_matrix.columns"
      },
      "rows": [
        {
          "Role": "Support Operations Manager",
          "System or Service": "CloudDesk Support",
          "Data Scope": "Customer support tickets and queue configuration",
          "Access Level": "Manager",
          "Privileged Access": "No",
          "Business Justification": "Manage support queues, assignments and customer escalations.",
          "Approval Required": "Yes",
          "Approver Role": "Support Director",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Cannot approve own access changes.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "ARR-SUPPORT-2026-08",
          "Status": "Active",
          "Notes": "Added after support operations entered ISMS scope."
        },
        {
          "Role": "Support Agent",
          "System or Service": "CloudDesk Support",
          "Data Scope": "Assigned customer tickets",
          "Access Level": "Standard user",
          "Privileged Access": "No",
          "Business Justification": "Handle assigned customer support requests.",
          "Approval Required": "Yes",
          "Approver Role": "Support Operations Manager",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "No administrative configuration rights.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "ARR-SUPPORT-2026-08",
          "Status": "Active",
          "Notes": "Role-based access only."
        },
        {
          "Role": "Cloud Platform Engineer",
          "System or Service": "Cloud administration portal",
          "Data Scope": "Production infrastructure configuration and operational logs",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Maintain cloud infrastructure and support incident response.",
          "Approval Required": "Yes",
          "Approver Role": "CTO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Production changes require separate change approval.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "EXR-001",
          "Status": "Open follow-up",
          "Notes": "Standing admin exception expires 2026-09-30."
        },
        {
          "Role": "Engineering Developer",
          "System or Service": "SecureBuild CI/CD",
          "Data Scope": "Assigned repositories and build pipeline metadata",
          "Access Level": "Contributor",
          "Privileged Access": "No",
          "Business Justification": "Commit and deploy approved application changes.",
          "Approval Required": "Yes",
          "Approver Role": "Engineering Lead",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Release approval separated from code authoring.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "CIL-2026-Q3",
          "Status": "Active",
          "Notes": "Privacy checkpoint training scheduled."
        },
        {
          "Role": "Internal Auditor",
          "System or Service": "EvidenceHub pilot",
          "Data Scope": "Audit evidence index and control metadata",
          "Access Level": "Reviewer",
          "Privileged Access": "No",
          "Business Justification": "Review audit evidence and sampling readiness.",
          "Approval Required": "Yes",
          "Approver Role": "ISMS Manager",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Read-only review access; no evidence owner changes.",
          "Review Frequency": "Per audit cycle",
          "Evidence Reference": "ELAI-AUTO-2026-PILOT",
          "Status": "Pilot",
          "Notes": "Review after first access-review cycle."
        },
        {
          "Role": "Supplier Manager",
          "System or Service": "Supplier evidence folder",
          "Data Scope": "Critical supplier evidence and contract follow-ups",
          "Access Level": "Owner",
          "Privileged Access": "Yes",
          "Business Justification": "Maintain supplier assurance evidence and contractual follow-ups.",
          "Approval Required": "Yes",
          "Approver Role": "COO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Legal approves contract changes separately.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "SINV-REVIEW-2026-Q3",
          "Status": "Active",
          "Notes": "CloudHost addendum action open."
        },
        {
          "Role": "Former Contractor",
          "System or Service": "Collaboration workspace",
          "Data Scope": "No active access",
          "Access Level": "Revoked",
          "Privileged Access": "No",
          "Business Justification": "Temporary onboarding support ended.",
          "Approval Required": "Yes",
          "Approver Role": "HR Manager",
          "MFA Required": "Yes while active",
          "Segregation of Duties Note": "Access removed after offboarding.",
          "Review Frequency": "After offboarding",
          "Evidence Reference": "ACCESS-REVIEW-2026-0827",
          "Status": "Revoked",
          "Notes": "Revocation confirmed."
        },
        {
          "Role": "Service Owner",
          "System or Service": "Production platform",
          "Data Scope": "Production runtime configuration and tenant isolation settings",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Own Arcfield Platform production changes named in the Systems Architecture Statement.",
          "Approval Required": "Yes",
          "Approver Role": "CTO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Production changes require signed CI/CD; no standing SSH.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged pattern derived from SAS AST-001 Production platform."
        },
        {
          "Role": "IT Operations Manager",
          "System or Service": "Identity provider tenant",
          "Data Scope": "SSO, MFA policy and directory administration",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate the identity-provider tenant used for SSO and MFA on the SAS control plane.",
          "Approval Required": "Yes",
          "Approver Role": "CTO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Directory changes separated from application release approval.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged pattern derived from SAS AST-005 Identity provider tenant."
        },
        {
          "Role": "Engineering Lead",
          "System or Service": "CI/CD",
          "Data Scope": "Production pipeline definitions and signed deploy keys",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Engineering Lead owns CI/CD change that can alter production, per SAS organization and roles.",
          "Approval Required": "Yes",
          "Approver Role": "CTO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Release approval separated from code authoring.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged pattern derived from SAS AST-011 CI/CD."
        },
        {
          "Role": "Security Lead",
          "System or Service": "Logging and detection",
          "Data Scope": "Detection rules, security-event correlation and privileged-access audit logs",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Security Lead owns detection rules and privileged-access review on the SAS observability path.",
          "Approval Required": "Yes",
          "Approver Role": "CISO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Cannot close incidents that the same person triaged without a second reviewer.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged pattern derived from SAS AST-012 Logging and detection."
        },
        {
          "Role": "Engineering Lead",
          "System or Service": "Backup and restore",
          "Data Scope": "Encrypted in-region restore onto Production platform",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Restore is a privileged path onto production; SAS BCM names Backup and restore.",
          "Approval Required": "Yes",
          "Approver Role": "CTO",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Restore tests require a witnessed run; operator is not the sole approver.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged pattern derived from SAS AST-013 Backup and restore."
        },
        {
          "Role": "ISMS Manager",
          "System or Service": "ISMS evidence repository",
          "Data Scope": "Document Control versions and exportable evidence index",
          "Access Level": "Owner",
          "Privileged Access": "No",
          "Business Justification": "Freeze Document Control versions and escalate unnamed trust paths, per SAS.",
          "Approval Required": "Yes",
          "Approver Role": "Top Management",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Read-write on evidence index; no production runtime rights.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical non-privileged pattern derived from SAS AST-003 ISMS evidence repository."
        },
        {
          "Role": "Support Operations Manager",
          "System or Service": "Support platform",
          "Data Scope": "Support role into tenant application, as drawn on the SAS boundary",
          "Access Level": "Manager",
          "Privileged Access": "No",
          "Business Justification": "Operate the in-scope support platform named in SAS (AST-014). Distinct from the CloudDesk Support alias already on this matrix.",
          "Approval Required": "Yes",
          "Approver Role": "Support Director",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Cannot approve own access changes.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical non-privileged pattern using the SAS/AI asset name Support platform."
        },
        {
          "Role": "Break-glass Operator",
          "System or Service": "Production platform",
          "Data Scope": "Emergency production configuration",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Standing break-glass onto production. SAS requires privileged access with MFA and no standing production SSH.",
          "Approval Required": "Yes",
          "Approver Role": "CTO",
          "MFA Required": "No",
          "Segregation of Duties Note": "Break-glass is not reviewed by a second person before use.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: privileged SAS production path without MFA Required. Didactic gap, not a silent PASS."
        },
        {
          "Role": "Identity Helpdesk",
          "System or Service": "Identity provider tenant",
          "Data Scope": "End-user MFA reset and credential recovery",
          "Access Level": "Operator",
          "Privileged Access": "Yes",
          "Business Justification": "Reset customer and staff authenticators on the identity-provider tenant.",
          "Approval Required": "Yes",
          "Approver Role": "IT Operations Manager",
          "MFA Required": "No",
          "Segregation of Duties Note": "Helpdesk can reset the MFA that this matrix should require.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: privileged IdP recovery role without MFA Required."
        },
        {
          "Role": "Platform SRE",
          "System or Service": "Privileged access",
          "Data Scope": "Privileged-access jump path drawn on the SAS control plane",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate the SAS 'Privileged access' box. That name is not an AI Asset name.",
          "Approval Required": "Yes",
          "Approver Role": "Security Lead",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Production SSH is forbidden; this row still names a box that AI does not list.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Open follow-up",
          "Notes": "Error: SAS architecture box used as System; no AI Asset name match. Unresolved natural key."
        },
        {
          "Role": "Secrets Administrator",
          "System or Service": "Secrets store",
          "Data Scope": "Production secrets fetched by the runtime orchestrator",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Manage the SAS secrets store used on signed deploys.",
          "Approval Required": "Yes",
          "Approver Role": "Security Lead",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Secret rotation separated from application release.",
          "Review Frequency": "Monthly",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: SAS control-plane box is not in the SAS/AI in-scope asset table."
        },
        {
          "Role": "Tenant Operator",
          "System or Service": "Tenant A application",
          "Data Scope": "Tenant-isolated application instance on Production platform",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate a tenant instance drawn on the SAS data plane. SAS says do not invent Asset Inventory IDs for those boxes.",
          "Approval Required": "Yes",
          "Approver Role": "Service Owner",
          "MFA Required": "Yes",
          "Segregation of Duties Note": "Tenant A operator cannot administer Tenant B.",
          "Review Frequency": "Quarterly",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: SAS tenant box without an AI Asset ID/name. Unresolved System natural key."
        }
      ],
      "contentType": "matrix_table"
    },
    {
      "id": "access_matrix_review",
      "title": "Access matrix review",
      "values": {
        "Review result": "19 access patterns reviewed after SAS-derived MFA rows were appended; 12 privileged patterns; follow-up on standing exceptions and privileged rows without MFA Required.",
        "Rows reviewed": 19,
        "Privileged access patterns": 12,
        "Rows needing follow-up": 4,
        "Review focus": "SAS-named systems, privileged MFA Required, and SAS boxes that are not AI Asset names.",
        "Reviewed by": "IT Operations Manager",
        "Decision date": "2026-09-17",
        "Evidence reference": "ACM-REVIEW-2026-09"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "19 access patterns reviewed after SAS-derived MFA rows were appended; 12 privileged patterns; follow-up on standing exceptions and privileged rows without MFA Required."
        },
        {
          "Field": "Rows reviewed",
          "Value": "19"
        },
        {
          "Field": "Privileged access patterns",
          "Value": "12"
        },
        {
          "Field": "Rows needing follow-up",
          "Value": "4"
        },
        {
          "Field": "Review focus",
          "Value": "SAS-named systems, privileged MFA Required, and SAS boxes that are not AI Asset names."
        },
        {
          "Field": "Reviewed by",
          "Value": "IT Operations Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-17"
        },
        {
          "Field": "Evidence reference",
          "Value": "ACM-REVIEW-2026-09"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Internal Audit & Management Review",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "CIL Continual Improvement Log (Building the ISMS, Continual Improvement (Clause 10))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Matrix",
    "role": "Mapping or selection used by the certified ISMS"
  }
}
