{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "UAI",
  "title": "Users and Access Inventory",
  "definitionRef": {
    "artifactId": "UAI",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "UAI.artifactDefinition.v2",
    "title": "Users and Access Inventory"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Users and Access Inventory",
        "Register ID": "UAI-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "IT Operations Manager",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Users and Access Inventory",
        "Register ID: UAI-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: IT Operations Manager",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example records Arcfield user and access assignments with department, system, access level, privilege, justification, approval, MFA, lifecycle dates, review result, evidence and status. This inventory is the in-scope Arcfield Platform set on the 11 September 2026 freeze in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Evidence provisioning, review and revocation of access rights."
        },
        {
          "Property": "Used by",
          "Value": "IT Operations, System Owners, ISMS Manager, Access Owners, Internal Auditor"
        },
        {
          "Property": "Maintained by",
          "Value": "IT Operations Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "User access inventory and access review evidence"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2 and A.8.3"
        },
        {
          "Property": "Review cadence",
          "Value": "Quarterly and after onboarding, role change or offboarding events"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Maintain one row per user-account or access assignment.",
        "Capture system, access level, business justification, approver and MFA status.",
        "Identify privileged access explicitly.",
        "Record start date, end date, last review date and review result.",
        "Link evidence for approval, review or revocation.",
        "Reconcile this inventory during access reviews and offboarding.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "users_access_inventory",
      "title": "Users and access inventory",
      "schemaRef": {
        "definitionId": "UAI.artifactDefinition.v2",
        "sectionId": "users_access_inventory",
        "columnsRef": "sections.users_access_inventory.columns"
      },
      "rows": [
        {
          "Account ID": "UAI-001",
          "User or Role": "Support Operations Manager",
          "Department or Team": "Customer Support",
          "System": "CloudDesk Support",
          "Access Level": "Manager",
          "Privileged Access": "No",
          "Business Justification": "Manage support queues and customer escalations.",
          "Approver": "Support Director",
          "MFA Status": "Enabled",
          "Start Date": "2026-08-12",
          "End Date": "",
          "Last Review Date": "2026-08-29",
          "Review Result": "Still required",
          "Evidence Reference": "ARR-SUPPORT-2026-08",
          "Status": "Active",
          "Notes": "Added after support operations entered ISMS scope."
        },
        {
          "Account ID": "UAI-002",
          "User or Role": "Cloud Platform Engineer",
          "Department or Team": "IT Operations",
          "System": "Cloud administration portal",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Maintain cloud infrastructure and support incident response.",
          "Approver": "CTO",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-08-28",
          "Review Result": "Exception open pending automation",
          "Evidence Reference": "EXR-001",
          "Status": "Open follow-up",
          "Notes": "Standing admin access exception expires 2026-09-30."
        },
        {
          "Account ID": "UAI-003",
          "User or Role": "Engineering Developer",
          "Department or Team": "Engineering",
          "System": "SecureBuild CI/CD",
          "Access Level": "Contributor",
          "Privileged Access": "No",
          "Business Justification": "Commit and deploy approved application changes.",
          "Approver": "Engineering Lead",
          "MFA Status": "Enabled",
          "Start Date": "2026-05-15",
          "End Date": "",
          "Last Review Date": "2026-08-27",
          "Review Result": "Still required",
          "Evidence Reference": "CIL-2026-Q3",
          "Status": "Active",
          "Notes": "Privacy checkpoint training scheduled."
        },
        {
          "Account ID": "UAI-004",
          "User or Role": "Internal Auditor",
          "Department or Team": "Compliance",
          "System": "EvidenceHub pilot",
          "Access Level": "Reviewer",
          "Privileged Access": "No",
          "Business Justification": "Review audit evidence and sampling readiness.",
          "Approver": "ISMS Manager",
          "MFA Status": "Enabled",
          "Start Date": "2026-08-18",
          "End Date": "",
          "Last Review Date": "2026-08-29",
          "Review Result": "Pilot access approved",
          "Evidence Reference": "ELAI-AUTO-2026-PILOT",
          "Status": "Pilot",
          "Notes": "Review after first access-review cycle."
        },
        {
          "Account ID": "UAI-005",
          "User or Role": "Former contractor",
          "Department or Team": "Support onboarding",
          "System": "Collaboration workspace",
          "Access Level": "Former member",
          "Privileged Access": "No",
          "Business Justification": "Temporary onboarding support ended.",
          "Approver": "HR Manager",
          "MFA Status": "Enabled while active",
          "Start Date": "2026-07-01",
          "End Date": "2026-08-27",
          "Last Review Date": "2026-08-27",
          "Review Result": "Access revoked and activity reviewed",
          "Evidence Reference": "ACCESS-REVIEW-2026-0827",
          "Status": "Revoked",
          "Notes": "Linked to OFC-2026-014."
        },
        {
          "Account ID": "UAI-006",
          "User or Role": "Supplier Manager",
          "Department or Team": "Operations",
          "System": "Supplier evidence folder",
          "Access Level": "Owner",
          "Privileged Access": "Yes",
          "Business Justification": "Maintain critical supplier evidence and contract follow-ups.",
          "Approver": "COO",
          "MFA Status": "Enabled",
          "Start Date": "2026-03-01",
          "End Date": "",
          "Last Review Date": "2026-08-29",
          "Review Result": "Still required",
          "Evidence Reference": "SINV-REVIEW-2026-Q3",
          "Status": "Active",
          "Notes": "CloudHost addendum action open."
        },
        {
          "Account ID": "UAI-007",
          "User or Role": "Service Owner",
          "Department or Team": "Product",
          "System": "Production platform",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Own Arcfield Platform production named in SAS.",
          "Approver": "CTO",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged assignment against SAS AST-001."
        },
        {
          "Account ID": "UAI-008",
          "User or Role": "IT Operations Manager",
          "Department or Team": "IT Operations",
          "System": "Identity provider tenant",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate SSO and MFA on the SAS identity-provider tenant.",
          "Approver": "CTO",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged assignment against SAS AST-005."
        },
        {
          "Account ID": "UAI-009",
          "User or Role": "Engineering Lead",
          "Department or Team": "Engineering",
          "System": "CI/CD",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Own signed CI/CD change that can alter production.",
          "Approver": "CTO",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged assignment against SAS AST-011."
        },
        {
          "Account ID": "UAI-010",
          "User or Role": "Security Lead",
          "Department or Team": "Security",
          "System": "Logging and detection",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Own detection rules and privileged-access review.",
          "Approver": "CISO",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged assignment against SAS AST-012."
        },
        {
          "Account ID": "UAI-011",
          "User or Role": "Engineering Lead",
          "Department or Team": "Engineering",
          "System": "Backup and restore",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Privileged restore onto Production platform.",
          "Approver": "CTO",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "SAS-EV-001",
          "Status": "Active",
          "Notes": "Typical privileged assignment against SAS AST-013."
        },
        {
          "Account ID": "UAI-012",
          "User or Role": "Break-glass Operator",
          "Department or Team": "IT Operations",
          "System": "Production platform",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Emergency production access. ACM does not require MFA on this role.",
          "Approver": "CTO",
          "MFA Status": "Enabled",
          "Start Date": "2026-09-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Exception open pending MFA requirement",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: privileged Ist exists; ACM MFA Required = No so enablement is out of scope."
        },
        {
          "Account ID": "UAI-013",
          "User or Role": "Platform SRE",
          "Department or Team": "IT Operations",
          "System": "Privileged access",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate the SAS privileged-access box.",
          "Approver": "Security Lead",
          "MFA Status": "Disabled",
          "Start Date": "2026-08-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Exception open pending MFA enablement",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Open follow-up",
          "Notes": "Error: ACM requires MFA; Ist is Disabled. System name is not an AI Asset name."
        },
        {
          "Account ID": "UAI-014",
          "User or Role": "Secrets Administrator",
          "Department or Team": "Security",
          "System": "Secrets store",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Manage SAS secrets store.",
          "Approver": "Security Lead",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: MFA recorded, but System is a SAS box not in the AI table."
        },
        {
          "Account ID": "UAI-015",
          "User or Role": "Tenant Operator",
          "Department or Team": "Engineering",
          "System": "Tenant A application",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate SAS tenant instance without an AI Asset ID.",
          "Approver": "Service Owner",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Still required",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: MFA recorded on a SAS tenant box that has no AI name."
        },
        {
          "Account ID": "UAI-016",
          "User or Role": "Identity Helpdesk",
          "Department or Team": "IT Operations",
          "System": "Identity provider tenant",
          "Access Level": "Operator",
          "Privileged Access": "Yes",
          "Business Justification": "Reset authenticators. ACM MFA Required = No on this role.",
          "Approver": "IT Operations Manager",
          "MFA Status": "Enabled",
          "Start Date": "2026-08-15",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Exception open pending MFA requirement",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: privileged Ist; ACM does not require MFA. Enablement out of scope."
        },
        {
          "Account ID": "UAI-017",
          "User or Role": "Runtime Operator",
          "Department or Team": "Engineering",
          "System": "Runtime orchestrator",
          "Access Level": "Administrator",
          "Privileged Access": "Yes",
          "Business Justification": "Operate the SAS runtime orchestrator. No ACM pattern exists for this Role×System.",
          "Approver": "Engineering Lead",
          "MFA Status": "Enabled",
          "Start Date": "2026-07-01",
          "End Date": "",
          "Last Review Date": "2026-09-17",
          "Review Result": "Unmapped privileged assignment",
          "Evidence Reference": "ACM-GAP-2026-09",
          "Status": "Active",
          "Notes": "Error: privileged UAI with no ACM join. Enablement UNKNOWN."
        }
      ],
      "contentType": "register_table"
    },
    {
      "id": "access_review_decision",
      "title": "Access review decision",
      "values": {
        "Review result": "17 access records reviewed after SAS-derived assignments; 13 privileged records; open exceptions on MFA gaps and unmapped privileged access.",
        "Access records reviewed": 17,
        "Privileged records": 13,
        "Revocations pending": 0,
        "Open exceptions": 4,
        "Reviewed by": "IT Operations Manager",
        "Decision date": "2026-09-17",
        "Evidence reference": "UAI-REVIEW-2026-09"
      },
      "rows": [
        {
          "Field": "Review result",
          "Value": "17 access records reviewed after SAS-derived assignments; 13 privileged records; open exceptions on MFA gaps and unmapped privileged access."
        },
        {
          "Field": "Access records reviewed",
          "Value": "17"
        },
        {
          "Field": "Privileged records",
          "Value": "13"
        },
        {
          "Field": "Revocations pending",
          "Value": "0"
        },
        {
          "Field": "Open exceptions",
          "Value": "4"
        },
        {
          "Field": "Reviewed by",
          "Value": "IT Operations Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-17"
        },
        {
          "Field": "Evidence reference",
          "Value": "UAI-REVIEW-2026-09"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Implementation & Certification, Asset Management & Information Classification",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ARR Access Rights Register (Secure Engineering, Access Control & Identity Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983455"
            },
            {
              "Kind": "Artifact",
              "Reference": "CIL Continual Improvement Log (Building the ISMS, Continual Improvement (Clause 10))",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "ELAI Evidence Log / Audit Pack Index (Implementation & Certification, Audit Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Inventory",
    "role": "In-scope Arcfield Platform inventory on the freeze"
  }
}
