{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "DCP",
  "title": "Document Control Procedure",
  "definitionRef": {
    "artifactId": "DCP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "DCP.artifactDefinition.v2",
    "title": "Document Control Procedure"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Workflow Title": "Document Control Procedure",
        "Workflow ID": "DCP-WF-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Workflow Title: Document Control Procedure",
        "Workflow ID: DCP-WF-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example shows the document-control lifecycle for ISMS documented information, including request, drafting, metadata assignment, approval, publication, review and retirement. It addresses a frequent audit problem: documents exist, but approval and obsolete-version evidence are not traceable. This is the operating method sampled on the 11 September 2026 freeze during the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Top Management"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Top Management"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "workflow_schema",
      "title": "Workflow schema",
      "steps": [
        "Identify need",
        "Draft or update document",
        "Assign metadata",
        "Review content",
        "Approve publication",
        "Publish controlled version",
        "Monitor review cycle",
        "Retire obsolete version"
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Document Control Procedure. Define how ISMS documented information is created, reviewed, approved, published, changed and retired. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (DR, ISO, RRS) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in DR, ISO, RRS.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "level": 1,
          "text": "Use this table for workflow steps in the Arcfield Platform ISMS. Step ID Trigger Activity Responsible Role Input Output Evidence Reference Status DCP-STEP-001 New or changed ISMS requirement identified Identify document need and assign document owner. ISMS Manager Requirement, audit finding or process change Document request record DCP-REQ-2026-001 Complete DCP-STEP-002 Document request accepted Draft or update controlled document using approved template. Document Owner Document request and current template Draft controlled document DCP-DRAFT-2026-001 Complete DCP-STEP-003 Document request accepted Assign document ID, owner, version, classification and review date. Document Owner Draft document Metadata-complete draft DR-UPDATE-2026-08 Complete DCP-STEP-004 Draft submitted Review content for accuracy, scope and evidence requirements. ISMS Manager Draft document and related evidence Review comments or approval recommendation DCP-REVIEW-2026-001 Complete DCP-STEP-005 Review recommendation issued Approve or reject publication. Approver Role Reviewed draft and comments Approval decision DCP-APP-2026-001 Complete DCP-STEP-006 Publication approved Publish controlled version and remove obsolete version from active use. ISMS Manager Approved document Published controlled document DCP-PUB-2026-001 Complete DCP-STEP-007 Scheduled review or material change Review document currency and decide update, retain or retire. Document Owner Review schedule and change context Review decision DCP-ANNUAL-REVIEW-2026 Open follow-up Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Step ID": "DCP-STEP-001",
              "Trigger": "New or changed ISMS requirement identified",
              "Activity": "Identify document need and assign document owner.",
              "Responsible Role": "ISMS Manager",
              "Input": "Requirement, audit finding or process change",
              "Output": "Document request record",
              "Evidence Reference": "DCP-REQ-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-REQ-2026-001"
            },
            {
              "Step ID": "DCP-STEP-002",
              "Trigger": "Document request accepted",
              "Activity": "Draft or update controlled document using approved template.",
              "Responsible Role": "Document Owner",
              "Input": "Document request and current template",
              "Output": "Draft controlled document",
              "Evidence Reference": "DCP-DRAFT-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-DRAFT-2026-001"
            },
            {
              "Step ID": "DCP-STEP-003",
              "Trigger": "Document request accepted",
              "Activity": "Assign document ID, owner, version, classification and review date.",
              "Responsible Role": "Document Owner",
              "Input": "Draft document",
              "Output": "Metadata-complete draft",
              "Evidence Reference": "DR-UPDATE-2026-08",
              "Status": "Complete",
              "Evidence reference": "DR-UPDATE-2026-08"
            },
            {
              "Step ID": "DCP-STEP-004",
              "Trigger": "Draft submitted",
              "Activity": "Review content for accuracy, scope and evidence requirements.",
              "Responsible Role": "ISMS Manager",
              "Input": "Draft document and related evidence",
              "Output": "Review comments or approval recommendation",
              "Evidence Reference": "DCP-REVIEW-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-REVIEW-2026-001"
            },
            {
              "Step ID": "DCP-STEP-005",
              "Trigger": "Review recommendation issued",
              "Activity": "Approve or reject publication.",
              "Responsible Role": "Approver Role",
              "Input": "Reviewed draft and comments",
              "Output": "Approval decision",
              "Evidence Reference": "DCP-APP-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-APP-2026-001"
            },
            {
              "Step ID": "DCP-STEP-006",
              "Trigger": "Publication approved",
              "Activity": "Publish controlled version and remove obsolete version from active use.",
              "Responsible Role": "ISMS Manager",
              "Input": "Approved document",
              "Output": "Published controlled document",
              "Evidence Reference": "DCP-PUB-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-PUB-2026-001"
            },
            {
              "Step ID": "DCP-STEP-007",
              "Trigger": "Scheduled review or material change",
              "Activity": "Review document currency and decide update, retain or retire.",
              "Responsible Role": "Document Owner",
              "Input": "Review schedule and change context",
              "Output": "Review decision",
              "Evidence Reference": "DCP-ANNUAL-REVIEW-2026",
              "Status": "Open follow-up",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Use this table for roles and responsibilities in the Arcfield Platform ISMS. Role Responsibility ISMS Manager Owns document-control workflow and publication rules. Document Owner Drafts, updates and reviews assigned document content. Approver Role Approves documents before publication where approval is required. Process Owner Confirms operational accuracy and evidence expectations. Internal Auditor Samples document-control evidence during audits. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Role": "ISMS Manager",
              "Responsibility": "Owns document-control workflow and publication rules.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Document Owner",
              "Responsibility": "Drafts, updates and reviews assigned document content.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Approver Role",
              "Responsibility": "Approves documents before publication where approval is required.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Process Owner",
              "Responsibility": "Confirms operational accuracy and evidence expectations.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Internal Auditor",
              "Responsibility": "Samples document-control evidence during audits.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "text": "Use this table for review and decision in the Arcfield Platform ISMS. Field Value Decision Workflow approved for current ISMS document lifecycle. Documents reviewed 12 Changes approved 3 Obsolete documents retired 2 Open actions 1 Reviewed by ISMS Manager Decision date 2026-08-29 Evidence reference DCP-ANNUAL-REVIEW-2026 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Workflow approved for current ISMS document lifecycle.",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Documents reviewed",
              "Value": "12",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Changes approved",
              "Value": "3",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Obsolete documents retired",
              "Value": "2",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Open actions",
              "Value": "1",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Reviewed by",
              "Value": "ISMS Manager",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Evidence reference",
              "Value": "DCP-ANNUAL-REVIEW-2026",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "workflow_schema"
    },
    {
      "id": "workflow_steps",
      "title": "Workflow steps",
      "schemaRef": {
        "definitionId": "DCP.artifactDefinition.v2",
        "sectionId": "workflow_steps"
      },
      "steps": [
        {
          "Step ID": "DCP-STEP-001",
          "Trigger": "New or changed ISMS requirement identified",
          "Activity": "Identify document need and assign document owner",
          "Responsible Role": "ISMS Manager",
          "Input": "Requirement, audit finding or process change",
          "Output": "Document request record",
          "Evidence Reference": "DCP-REQ-2026-001",
          "Status": "Complete"
        },
        {
          "Step ID": "DCP-STEP-002",
          "Trigger": "Document request accepted",
          "Activity": "Draft or update controlled document using approved template",
          "Responsible Role": "Document Owner",
          "Input": "Document request and current template",
          "Output": "Draft controlled document",
          "Evidence Reference": "DCP-DRAFT-2026-001",
          "Status": "Complete"
        },
        {
          "Step ID": "DCP-STEP-003",
          "Trigger": "Draft ready for review",
          "Activity": "Assign document ID, owner, version, classification and review date",
          "Responsible Role": "Document Owner",
          "Input": "Draft document",
          "Output": "Metadata-complete draft",
          "Evidence Reference": "DR-UPDATE-2026-08",
          "Status": "Complete"
        },
        {
          "Step ID": "DCP-STEP-004",
          "Trigger": "Metadata-complete draft submitted",
          "Activity": "Review content for accuracy, scope and evidence requirements",
          "Responsible Role": "ISMS Manager",
          "Input": "Draft document and related evidence",
          "Output": "Review comments or approval recommendation",
          "Evidence Reference": "DCP-REVIEW-2026-001",
          "Status": "Complete"
        },
        {
          "Step ID": "DCP-STEP-005",
          "Trigger": "Review recommendation issued",
          "Activity": "Approve or reject publication",
          "Responsible Role": "Approver Role",
          "Input": "Reviewed draft and comments",
          "Output": "Approval decision",
          "Evidence Reference": "DCP-APP-2026-001",
          "Status": "Complete"
        },
        {
          "Step ID": "DCP-STEP-006",
          "Trigger": "Publication approved",
          "Activity": "Publish controlled version and remove obsolete version from active use",
          "Responsible Role": "ISMS Manager",
          "Input": "Approved document",
          "Output": "Published controlled document",
          "Evidence Reference": "DCP-PUB-2026-001",
          "Status": "Complete"
        },
        {
          "Step ID": "DCP-STEP-007",
          "Trigger": "Scheduled review or material change",
          "Activity": "Review document currency and decide update, retain or retire",
          "Responsible Role": "Document Owner",
          "Input": "Review schedule and change context",
          "Output": "Review decision",
          "Evidence Reference": "DCP-ANNUAL-REVIEW-2026",
          "Status": "Open follow-up"
        }
      ],
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Document Control Procedure. Define how ISMS documented information is created, reviewed, approved, published, changed and retired. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (DR, ISO, RRS) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in DR, ISO, RRS.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "workflow_steps",
          "heading": "Workflow steps",
          "level": 1,
          "text": "Use this table for workflow steps in the Arcfield Platform ISMS. Step ID Trigger Activity Responsible Role Input Output Evidence Reference Status DCP-STEP-001 New or changed ISMS requirement identified Identify document need and assign document owner. ISMS Manager Requirement, audit finding or process change Document request record DCP-REQ-2026-001 Complete DCP-STEP-002 Document request accepted Draft or update controlled document using approved template. Document Owner Document request and current template Draft controlled document DCP-DRAFT-2026-001 Complete DCP-STEP-003 Document request accepted Assign document ID, owner, version, classification and review date. Document Owner Draft document Metadata-complete draft DR-UPDATE-2026-08 Complete DCP-STEP-004 Draft submitted Review content for accuracy, scope and evidence requirements. ISMS Manager Draft document and related evidence Review comments or approval recommendation DCP-REVIEW-2026-001 Complete DCP-STEP-005 Review recommendation issued Approve or reject publication. Approver Role Reviewed draft and comments Approval decision DCP-APP-2026-001 Complete DCP-STEP-006 Publication approved Publish controlled version and remove obsolete version from active use. ISMS Manager Approved document Published controlled document DCP-PUB-2026-001 Complete DCP-STEP-007 Scheduled review or material change Review document currency and decide update, retain or retire. Document Owner Review schedule and change context Review decision DCP-ANNUAL-REVIEW-2026 Open follow-up Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Step ID": "DCP-STEP-001",
              "Trigger": "New or changed ISMS requirement identified",
              "Activity": "Identify document need and assign document owner.",
              "Responsible Role": "ISMS Manager",
              "Input": "Requirement, audit finding or process change",
              "Output": "Document request record",
              "Evidence Reference": "DCP-REQ-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-REQ-2026-001"
            },
            {
              "Step ID": "DCP-STEP-002",
              "Trigger": "Document request accepted",
              "Activity": "Draft or update controlled document using approved template.",
              "Responsible Role": "Document Owner",
              "Input": "Document request and current template",
              "Output": "Draft controlled document",
              "Evidence Reference": "DCP-DRAFT-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-DRAFT-2026-001"
            },
            {
              "Step ID": "DCP-STEP-003",
              "Trigger": "Document request accepted",
              "Activity": "Assign document ID, owner, version, classification and review date.",
              "Responsible Role": "Document Owner",
              "Input": "Draft document",
              "Output": "Metadata-complete draft",
              "Evidence Reference": "DR-UPDATE-2026-08",
              "Status": "Complete",
              "Evidence reference": "DR-UPDATE-2026-08"
            },
            {
              "Step ID": "DCP-STEP-004",
              "Trigger": "Draft submitted",
              "Activity": "Review content for accuracy, scope and evidence requirements.",
              "Responsible Role": "ISMS Manager",
              "Input": "Draft document and related evidence",
              "Output": "Review comments or approval recommendation",
              "Evidence Reference": "DCP-REVIEW-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-REVIEW-2026-001"
            },
            {
              "Step ID": "DCP-STEP-005",
              "Trigger": "Review recommendation issued",
              "Activity": "Approve or reject publication.",
              "Responsible Role": "Approver Role",
              "Input": "Reviewed draft and comments",
              "Output": "Approval decision",
              "Evidence Reference": "DCP-APP-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-APP-2026-001"
            },
            {
              "Step ID": "DCP-STEP-006",
              "Trigger": "Publication approved",
              "Activity": "Publish controlled version and remove obsolete version from active use.",
              "Responsible Role": "ISMS Manager",
              "Input": "Approved document",
              "Output": "Published controlled document",
              "Evidence Reference": "DCP-PUB-2026-001",
              "Status": "Complete",
              "Evidence reference": "DCP-PUB-2026-001"
            },
            {
              "Step ID": "DCP-STEP-007",
              "Trigger": "Scheduled review or material change",
              "Activity": "Review document currency and decide update, retain or retire.",
              "Responsible Role": "Document Owner",
              "Input": "Review schedule and change context",
              "Output": "Review decision",
              "Evidence Reference": "DCP-ANNUAL-REVIEW-2026",
              "Status": "Open follow-up",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Use this table for roles and responsibilities in the Arcfield Platform ISMS. Role Responsibility ISMS Manager Owns document-control workflow and publication rules. Document Owner Drafts, updates and reviews assigned document content. Approver Role Approves documents before publication where approval is required. Process Owner Confirms operational accuracy and evidence expectations. Internal Auditor Samples document-control evidence during audits. Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Role": "ISMS Manager",
              "Responsibility": "Owns document-control workflow and publication rules.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Document Owner",
              "Responsibility": "Drafts, updates and reviews assigned document content.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Approver Role",
              "Responsibility": "Approves documents before publication where approval is required.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Process Owner",
              "Responsibility": "Confirms operational accuracy and evidence expectations.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Internal Auditor",
              "Responsibility": "Samples document-control evidence during audits.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        },
        {
          "id": "review_and_decision",
          "heading": "Review and decision",
          "level": 1,
          "text": "Use this table for review and decision in the Arcfield Platform ISMS. Field Value Decision Workflow approved for current ISMS document lifecycle. Documents reviewed 12 Changes approved 3 Obsolete documents retired 2 Open actions 1 Reviewed by ISMS Manager Decision date 2026-08-29 Evidence reference DCP-ANNUAL-REVIEW-2026 Cite this Document Control version from neighbouring records.",
          "rows": [
            {
              "Field": "Decision",
              "Value": "Workflow approved for current ISMS document lifecycle.",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Documents reviewed",
              "Value": "12",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Changes approved",
              "Value": "3",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Obsolete documents retired",
              "Value": "2",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Open actions",
              "Value": "1",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Reviewed by",
              "Value": "ISMS Manager",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Evidence reference",
              "Value": "DCP-ANNUAL-REVIEW-2026",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "workflow_steps"
    },
    {
      "id": "roles_and_responsibilities",
      "title": "Roles and responsibilities",
      "groups": [
        {
          "text": "Use this table or list as the working record. Name owners, systems and evidence so a second person can apply the same rule."
        },
        {
          "rows": [
            {
              "Role": "ISMS Manager",
              "Responsibility": "Owns document-control workflow and publication rules.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Document Owner",
              "Responsibility": "Drafts, updates and reviews assigned document content.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Approver Role",
              "Responsibility": "Approves documents before publication where approval is required.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Process Owner",
              "Responsibility": "Confirms operational accuracy and evidence expectations.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            },
            {
              "Role": "Internal Auditor",
              "Responsibility": "Samples document-control evidence during audits.",
              "Evidence reference": "DCP-EV-2026-Q3",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "role_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "review_and_decision",
      "title": "Review and decision",
      "values": {
        "Decision": "Workflow approved for current ISMS document lifecycle.",
        "Documents reviewed": 12,
        "Changes approved": 3,
        "Obsolete documents retired": 2,
        "Open actions": 1,
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-08-29",
        "Evidence reference": "DCP-ANNUAL-REVIEW-2026"
      },
      "groups": [
        {},
        {
          "rows": [
            {
              "Field": "Decision",
              "Value": "Workflow approved for current ISMS document lifecycle.",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Documents reviewed",
              "Value": "12",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Changes approved",
              "Value": "3",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Obsolete documents retired",
              "Value": "2",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Open actions",
              "Value": "1",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Reviewed by",
              "Value": "ISMS Manager",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Decision date",
              "Value": "2026-08-29",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            },
            {
              "Field": "Evidence reference",
              "Value": "DCP-ANNUAL-REVIEW-2026",
              "Evidence reference": "DCP-ANNUAL-REVIEW-2026",
              "Evidence status": "Complete"
            }
          ]
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Asset Management & Information Classification",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Procedure",
    "role": "Operating method used on the 11 September 2026 freeze"
  }
}
