{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "ARR",
  "title": "Access Rights Register",
  "definitionRef": {
    "artifactId": "ARR",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "ARR.artifactDefinition.v2",
    "title": "Access Rights Register"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Access Rights Register",
        "Register ID": "ARR-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "IT Operations Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Access Rights Register",
        "Register ID: ARR-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: IT Operations Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield access rights with user or role, system, asset, privilege type, approval, business justification, review result, revocation status and evidence reference. Rows are the 11 September 2026 operating sample of the certified Arcfield Platform ISMS in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain auditable access-rights records."
        },
        {
          "Property": "Used by",
          "Value": "IT Operations, System Owners, Access Owners, ISMS Manager, auditors"
        },
        {
          "Property": "Maintained by",
          "Value": "IT Operations Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "ISO 27001 supporting record"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.15, A.5.16, A.5.18, A.8.2, A.8.3"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly or after joiner-mover-leaver events"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Maintain one row per access assignment.",
        "Capture approval, business justification and access level.",
        "Mark privileged and emergency access explicitly.",
        "Review active rights periodically and record the outcome.",
        "Record revocation date and evidence for ended access.",
        "Escalate exceptions and missing evidence to the ISMS Manager.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "access_rights_register",
      "title": "Access rights register",
      "schemaRef": {
        "definitionId": "ARR.artifactDefinition.v2",
        "sectionId": "access_rights_register",
        "columnsRef": "sections.access_rights_register.columns"
      },
      "rows": [
        {
          "Access ID": "ARR-001",
          "User or Role": "Customer Operations Lead",
          "Person Type": "Employee",
          "System": "Customer Portal Admin",
          "Asset ID": "AST-001",
          "Access Level": "Administrator",
          "Privilege Type": "Privileged",
          "Business Justification": "Manage customer support queues and service configuration.",
          "Approver": "Head of Customer Operations",
          "Approval Date": "2026-07-02",
          "Status": "Active",
          "Last Review": "2026-08-29",
          "Review Result": "Confirmed",
          "Revocation Date": "",
          "Evidence Status": "Complete",
          "Evidence Reference": "ACC-REV-2026-Q3-001",
          "Notes": "MFA enforced."
        },
        {
          "Access ID": "ARR-002",
          "User or Role": "Backend Developer",
          "Person Type": "Employee",
          "System": "Source Repository",
          "Asset ID": "AST-003",
          "Access Level": "Contributor",
          "Privilege Type": "Standard",
          "Business Justification": "Develop and maintain customer portal services.",
          "Approver": "Engineering Lead",
          "Approval Date": "2026-07-04",
          "Status": "Active",
          "Last Review": "2026-08-29",
          "Review Result": "Confirmed",
          "Revocation Date": "",
          "Evidence Status": "Complete",
          "Evidence Reference": "ACC-REV-2026-Q3-002",
          "Notes": "Protected branch rules apply."
        },
        {
          "Access ID": "ARR-003",
          "User or Role": "Cloud Platform Engineer",
          "Person Type": "Employee",
          "System": "Cloud Production Tenant",
          "Asset ID": "AST-002",
          "Access Level": "Infrastructure Admin",
          "Privilege Type": "Privileged",
          "Business Justification": "Operate production infrastructure and incident response.",
          "Approver": "CTO",
          "Approval Date": "2026-07-10",
          "Status": "Active",
          "Last Review": "2026-08-29",
          "Review Result": "Exception approved",
          "Revocation Date": "",
          "Evidence Status": "Partial",
          "Evidence Reference": "PAM-EXC-2026-Q3-003",
          "Notes": "Temporary standing admin exception expires 2026-09-30."
        },
        {
          "Access ID": "ARR-004",
          "User or Role": "Finance Analyst",
          "Person Type": "Employee",
          "System": "Billing Platform",
          "Asset ID": "AST-009",
          "Access Level": "Read-only reports",
          "Privilege Type": "Standard",
          "Business Justification": "Monthly revenue reconciliation.",
          "Approver": "Finance Manager",
          "Approval Date": "2026-06-18",
          "Status": "Active",
          "Last Review": "2026-08-29",
          "Review Result": "Changed",
          "Revocation Date": "",
          "Evidence Status": "Complete",
          "Evidence Reference": "ACC-REV-2026-Q3-004",
          "Notes": "Write access removed during Q3 review."
        },
        {
          "Access ID": "ARR-005",
          "User or Role": "External Support Contractor",
          "Person Type": "Contractor",
          "System": "Support Desk",
          "Asset ID": "AST-007",
          "Access Level": "Agent",
          "Privilege Type": "Standard",
          "Business Justification": "Temporary support backlog reduction.",
          "Approver": "Support Manager",
          "Approval Date": "2026-05-12",
          "Status": "Revoked",
          "Last Review": "2026-08-15",
          "Review Result": "Revoked",
          "Revocation Date": "2026-08-16",
          "Evidence Status": "Complete",
          "Evidence Reference": "OFC-2026-018",
          "Notes": "Contract ended; access revoked and verified."
        },
        {
          "Access ID": "ARR-006",
          "User or Role": "Break-glass Administrator",
          "Person Type": "Service account",
          "System": "Identity Provider",
          "Asset ID": "AST-005",
          "Access Level": "Tenant emergency admin",
          "Privilege Type": "Emergency",
          "Business Justification": "Emergency recovery if standard admin access is unavailable.",
          "Approver": "CTO",
          "Approval Date": "2026-07-01",
          "Status": "Active",
          "Last Review": "2026-08-29",
          "Review Result": "Confirmed",
          "Revocation Date": "",
          "Evidence Status": "Partial",
          "Evidence Reference": "BG-ADM-2026-Q3",
          "Notes": "Credential escrow review due 2026-09-15."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "access_review_decision",
      "title": "Access review decision",
      "values": {
        "Review result": "Controlled with one privileged exception and one confirmed revocation",
        "Active access records": 5,
        "Privileged access records": 3,
        "Revocations confirmed": 1,
        "Open exceptions": "ARR-003 temporary standing admin exception",
        "Reviewed by": "IT Operations Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "ACC-REV-2026-Q3"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "Controlled with one privileged exception and one confirmed revocation"
        },
        {
          "Field": "Active access records",
          "Value": "5"
        },
        {
          "Field": "Privileged access records",
          "Value": "3"
        },
        {
          "Field": "Revocations confirmed",
          "Value": "1"
        },
        {
          "Field": "Open exceptions",
          "Value": "ARR-003 temporary standing admin exception"
        },
        {
          "Field": "Reviewed by",
          "Value": "IT Operations Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-08-29"
        },
        {
          "Field": "Evidence reference",
          "Value": "ACC-REV-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Business Impact Analysis & Business Continuity Planning",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "OFC Offboarding Checklist (Building the ISMS, Context of the Organization (Clause 4))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Register",
    "role": "Operating sample of the 11 September 2026 freeze"
  }
}
