{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "DOP",
  "title": "Documented Operating Procedure",
  "definitionRef": {
    "artifactId": "DOP",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "DOP.artifactDefinition.v2",
    "title": "Documented Operating Procedure"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Documented Operating Procedure",
        "Document ID": "DOP-TPL-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Process Owner",
        "Approver": "ISMS Manager / Process Owner’s manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Documented Operating Procedure",
        "Document ID: DOP-TPL-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Process Owner",
        "Approver: ISMS Manager / Process Owner’s manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This template defines how to document an operating procedure that people can follow consistently: purpose, scope, roles, inputs, step-by-step activities, outputs, records, exceptions and review. It is a procedure template for operational ISMS and business processes — not a data-ownership policy. This is the operating method sampled on the 11 September 2026 freeze during the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "ISMS Manager / Process Owner’s manager"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "ISMS Manager / Process Owner’s manager"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "procedure_template_content",
      "title": "Procedure",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this procedure is",
          "level": 1,
          "text": "This document is Arcfield's Documented Operating Procedure. Provide a reusable structure for documented operating procedures linked to ISMS controls. It is not the policy that sets the rule or the register that stores the live rows. This procedure applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, 27003-27004-MAP, ACM) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this procedure": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this procedure": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, 27003-27004-MAP, ACM."
            },
            {
              "In this procedure": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this procedure": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "purpose",
          "heading": "Purpose",
          "level": 1,
          "text": "Purpose is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Purpose states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — purpose",
              "Rule applied": "Purpose binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-purpose-PROD"
            },
            {
              "Arcfield case": "Customer data / support — purpose",
              "Rule applied": "Support attachments and tenant configuration inherit this purpose rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-purpose-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — purpose",
              "Rule applied": "Name the shared-responsibility split for purpose on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-purpose-SUP"
            }
          ]
        },
        {
          "id": "scope_and_applicability",
          "heading": "Scope and applicability",
          "level": 1,
          "text": "Scope and applicability is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Scope and applicability states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — scope and applicability",
              "Rule applied": "Scope and applicability binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-scope_and_applicability-PROD"
            },
            {
              "Arcfield case": "Customer data / support — scope and applicability",
              "Rule applied": "Support attachments and tenant configuration inherit this scope and applicability rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-scope_and_applicability-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — scope and applicability",
              "Rule applied": "Name the shared-responsibility split for scope and applicability on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-scope_and_applicability-SUP"
            }
          ]
        },
        {
          "id": "roles_and_responsibilities",
          "heading": "Roles and responsibilities",
          "level": 1,
          "text": "Roles and responsibilities is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Roles and responsibilities states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — roles and responsibilities",
              "Rule applied": "Roles and responsibilities binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-roles_and_responsibilities-PROD"
            },
            {
              "Arcfield case": "Customer data / support — roles and responsibilities",
              "Rule applied": "Support attachments and tenant configuration inherit this roles and responsibilities rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-roles_and_responsibilities-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — roles and responsibilities",
              "Rule applied": "Name the shared-responsibility split for roles and responsibilities on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-roles_and_responsibilities-SUP"
            }
          ]
        },
        {
          "id": "inputs_and_prerequisites",
          "heading": "Inputs and prerequisites",
          "level": 1,
          "text": "Inputs and prerequisites is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Inputs and prerequisites states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — inputs and prerequisites",
              "Rule applied": "Inputs and prerequisites binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-inputs_and_prerequisites-PROD"
            },
            {
              "Arcfield case": "Customer data / support — inputs and prerequisites",
              "Rule applied": "Support attachments and tenant configuration inherit this inputs and prerequisites rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-inputs_and_prerequisites-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — inputs and prerequisites",
              "Rule applied": "Name the shared-responsibility split for inputs and prerequisites on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-inputs_and_prerequisites-SUP"
            }
          ]
        },
        {
          "id": "procedure_steps",
          "heading": "Procedure steps",
          "level": 1,
          "text": "Procedure steps is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Procedure steps states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — procedure steps",
              "Rule applied": "Procedure steps binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-procedure_steps-PROD"
            },
            {
              "Arcfield case": "Customer data / support — procedure steps",
              "Rule applied": "Support attachments and tenant configuration inherit this procedure steps rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-procedure_steps-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — procedure steps",
              "Rule applied": "Name the shared-responsibility split for procedure steps on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-procedure_steps-SUP"
            }
          ]
        },
        {
          "id": "outputs_and_records",
          "heading": "Outputs and records",
          "level": 1,
          "text": "Outputs and records is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Outputs and records states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — outputs and records",
              "Rule applied": "Outputs and records binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-outputs_and_records-PROD"
            },
            {
              "Arcfield case": "Customer data / support — outputs and records",
              "Rule applied": "Support attachments and tenant configuration inherit this outputs and records rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-outputs_and_records-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — outputs and records",
              "Rule applied": "Name the shared-responsibility split for outputs and records on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-outputs_and_records-SUP"
            }
          ]
        },
        {
          "id": "exceptions_and_escalation",
          "heading": "Exceptions and escalation",
          "level": 1,
          "text": "Exceptions and escalation is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Exceptions and escalation states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — exceptions and escalation",
              "Rule applied": "Exceptions and escalation binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-exceptions_and_escalation-PROD"
            },
            {
              "Arcfield case": "Customer data / support — exceptions and escalation",
              "Rule applied": "Support attachments and tenant configuration inherit this exceptions and escalation rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-exceptions_and_escalation-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — exceptions and escalation",
              "Rule applied": "Name the shared-responsibility split for exceptions and escalation on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-exceptions_and_escalation-SUP"
            }
          ]
        },
        {
          "id": "related_references",
          "heading": "Related references",
          "level": 1,
          "text": "Related references is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Related references states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Provide a reusable structure for documented operating procedures linked to ISMS controls. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — related references",
              "Rule applied": "Related references binds the named production system and a named owner. Provide a reusable structure for documented operating procedures linked to ISMS controls.",
              "Evidence": "DOP-related_references-PROD"
            },
            {
              "Arcfield case": "Customer data / support — related references",
              "Rule applied": "Support attachments and tenant configuration inherit this related references rule; they are not out of scope because they are temporary.",
              "Evidence": "DOP-related_references-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — related references",
              "Rule applied": "Name the shared-responsibility split for related references on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "DOP-related_references-SUP"
            }
          ]
        }
      ],
      "contentType": "statement_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "27003-27004-MAP ISO 27003 / 27004 Conformance Matrix (Implementation & Certification, Asset Management & Information Classification)",
              "href": "27003-27004-MAP_ISO_27003_27004_Conformance_Matrix.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "ACM Access Control Matrix (Secure Engineering, Access Control & Identity Management)",
              "href": "ACM_Access_Control_Matrix.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "href": "AI_Asset_Inventory.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "AOAVC Asset Owner Asset Validation Checklist (Implementation & Certification, Asset Management & Information Classification)",
              "href": "AOAVC_Asset_Owner_Asset_Validation_Checklist.docx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Annex A Controls",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Procedure",
    "role": "Operating method used on the 11 September 2026 freeze"
  }
}
