{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "WIR-S1",
  "title": "Work Instruction Record — Security Cycle 1",
  "definitionRef": {
    "artifactId": "WIR-S1",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "WIR-S1.artifactDefinition.v2",
    "title": "Work Instruction Record — Security Cycle 1"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Document Title": "Work Instruction Record — Security Cycle 1",
        "Document ID": "WIR-S1-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Security Lead",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Document Title: Work Instruction Record — Security Cycle 1",
        "Document ID: WIR-S1-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Security Lead",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example documents the first Arcfield security implementation cycle, including work-package ownership, execution status, evidence, blockers, decisions, quality checks and follow-up actions. This plan is the live Arcfield Platform programme in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "contentType": "control_table"
    },
    {
      "id": "change_log",
      "title": "Revision history",
      "groups": [
        {
          "text": "A published change is a new row. Do not edit an approved version in place."
        },
        {
          "rows": [
            {
              "Version": "1.0",
              "Date": "2026-08-29",
              "Change": "Initial Arcfield Platform publication.",
              "Approved by": "Security Lead"
            },
            {
              "Version": "1.1",
              "Date": "2026-09-11",
              "Change": "Approved Arcfield worked example after the 11 September 2026 internal audit.",
              "Approved by": "Security Lead"
            }
          ]
        }
      ],
      "contentType": "revision_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "groups": [
        {
          "text": "Copy this file as the controlled Word master for your ISMS. The Arcfield identity fields on the cover are the approved worked example. Complete the steps below when you adopt the file for your organization."
        },
        {
          "items": [
            "Fill the cover identity fields (Organization, Version, Classification, Owner, Approver, Effective Date and Next Review Date) when you adopt this file. The Arcfield values shown here are the approved worked example.",
            "Issue your own version and a new Revision history row. Do not edit an approved version in place.",
            "Cite this approved version from related records. Do not copy this file into those records."
          ]
        }
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "work_instruction_content",
      "title": "Work instruction",
      "groups": [
        {
          "id": "introduction",
          "heading": "What this plan is",
          "level": 1,
          "text": "This document is Arcfield's Work Instruction Record — Security Cycle 1. Record execution evidence for security-cycle work packages. It is not the governing policy, the live register or the completion record of a later cycle. This plan applies to the Arcfield Platform (B2B SaaS for regulated fintech and health customers): production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records (ISO, ISOCTRL, TRC) cite this Document Control version. Do not copy these paragraphs into them."
        },
        {
          "id": "scope",
          "heading": "Scope",
          "level": 1,
          "text": "Use this table before you copy a rule into another record or exclude a duty from this file.",
          "rows": [
            {
              "In this plan": "The rules, roles, worked Arcfield example and the records this file owns.",
              "Not in this plan": "The ISMS boundary (ISS), Annex A selection (SoA) or live rows in ISO, ISOCTRL, TRC."
            },
            {
              "In this plan": "Interfaces that must cite this Document Control version, including CI/CD, identity and suppliers where they affect CIA.",
              "Not in this plan": "Live ISS scope rows, SoA applicability decisions, or neighbouring live registers. Those files keep their own approved versions; this file does not duplicate them."
            }
          ]
        },
        {
          "id": "terms",
          "heading": "Terms used here",
          "level": 1,
          "text": "These terms are local to this file. Expand every acronym on first use in the body.",
          "rows": [
            {
              "Term": "Owner",
              "Meaning": "The named role that can be called in an audit for an outcome. A team name is not an owner."
            },
            {
              "Term": "Exception",
              "Meaning": "A time-bound, approved departure with expiry and a compensating control."
            },
            {
              "Term": "CIA",
              "Meaning": "Confidentiality, Integrity and Availability of in-scope information and services."
            },
            {
              "Term": "Document Control version",
              "Meaning": "The approved version cited from neighbouring records. Do not copy this body into those records."
            }
          ]
        },
        {
          "id": "work_package_definition",
          "heading": "Work package definition",
          "level": 1,
          "text": "Work package definition is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Work package definition states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Record execution evidence for security-cycle work packages. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — work package definition",
              "Rule applied": "Work package definition binds the named production system and a named owner. Record execution evidence for security-cycle work packages.",
              "Evidence": "WIR-S1-work_package_definition-PROD"
            },
            {
              "Arcfield case": "Customer data / support — work package definition",
              "Rule applied": "Support attachments and tenant configuration inherit this work package definition rule; they are not out of scope because they are temporary.",
              "Evidence": "WIR-S1-work_package_definition-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — work package definition",
              "Rule applied": "Name the shared-responsibility split for work package definition on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "WIR-S1-work_package_definition-SUP"
            }
          ]
        },
        {
          "id": "execution_evidence",
          "heading": "Execution evidence",
          "level": 1,
          "text": "Execution evidence is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Execution evidence states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Record execution evidence for security-cycle work packages. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — execution evidence",
              "Rule applied": "Execution evidence binds the named production system and a named owner. Record execution evidence for security-cycle work packages.",
              "Evidence": "WIR-S1-execution_evidence-PROD"
            },
            {
              "Arcfield case": "Customer data / support — execution evidence",
              "Rule applied": "Support attachments and tenant configuration inherit this execution evidence rule; they are not out of scope because they are temporary.",
              "Evidence": "WIR-S1-execution_evidence-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — execution evidence",
              "Rule applied": "Name the shared-responsibility split for execution evidence on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "WIR-S1-execution_evidence-SUP"
            }
          ]
        },
        {
          "id": "blockers_and_decisions",
          "heading": "Blockers and decisions",
          "level": 1,
          "text": "Blockers and decisions is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Blockers and decisions states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Record execution evidence for security-cycle work packages. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — blockers and decisions",
              "Rule applied": "Blockers and decisions binds the named production system and a named owner. Record execution evidence for security-cycle work packages.",
              "Evidence": "WIR-S1-blockers_and_decisions-PROD"
            },
            {
              "Arcfield case": "Customer data / support — blockers and decisions",
              "Rule applied": "Support attachments and tenant configuration inherit this blockers and decisions rule; they are not out of scope because they are temporary.",
              "Evidence": "WIR-S1-blockers_and_decisions-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — blockers and decisions",
              "Rule applied": "Name the shared-responsibility split for blockers and decisions on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "WIR-S1-blockers_and_decisions-SUP"
            }
          ]
        },
        {
          "id": "quality_check",
          "heading": "Quality check",
          "level": 1,
          "text": "Quality check is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Quality check states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Record execution evidence for security-cycle work packages. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — quality check",
              "Rule applied": "Quality check binds the named production system and a named owner. Record execution evidence for security-cycle work packages.",
              "Evidence": "WIR-S1-quality_check-PROD"
            },
            {
              "Arcfield case": "Customer data / support — quality check",
              "Rule applied": "Support attachments and tenant configuration inherit this quality check rule; they are not out of scope because they are temporary.",
              "Evidence": "WIR-S1-quality_check-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — quality check",
              "Rule applied": "Name the shared-responsibility split for quality check on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "WIR-S1-quality_check-SUP"
            }
          ]
        },
        {
          "id": "follow_up",
          "heading": "Follow-up",
          "level": 1,
          "text": "Follow-up is a Arcfield Platform operating rule for Arcfield, not a restatement of this file's purpose. Follow-up states the Arcfield rule, the Arcfield Platform system it binds and the evidence a second person can retrieve. Record execution evidence for security-cycle work packages. Apply it to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Name the owner, the live record and the review date. Cite this approved version from neighbouring records; do not copy this chapter into them.",
          "rows": [
            {
              "Arcfield case": "Arcfield Platform production — follow-up",
              "Rule applied": "Follow-up binds the named production system and a named owner. Record execution evidence for security-cycle work packages.",
              "Evidence": "WIR-S1-follow_up-PROD"
            },
            {
              "Arcfield case": "Customer data / support — follow-up",
              "Rule applied": "Support attachments and tenant configuration inherit this follow-up rule; they are not out of scope because they are temporary.",
              "Evidence": "WIR-S1-follow_up-CUST"
            },
            {
              "Arcfield case": "Supplier or CI/CD — follow-up",
              "Rule applied": "Name the shared-responsibility split for follow-up on hosting, identity and deploy paths. An unnamed interface is an unnamed audit boundary.",
              "Evidence": "WIR-S1-follow_up-SUP"
            }
          ]
        }
      ],
      "contentType": "work_instruction_sections"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
            "[Document Register](DR_Document_Register.xlsx) — Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
            "[Records Retention Schedule](RRS_Records_Retention_Schedule_Register.xlsx) — Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "id": "linked_documents",
          "heading": "Linked documents",
          "level": 1,
          "text": "These companion files sit next to this document in the unpacked package. This file cites them by their approved version. It does not copy their content.",
          "rows": [
            {
              "Kind": "Artifact",
              "Reference": "MDR Mandatory Documents and Records Register",
              "How this document uses it": "The 27 mandatory ISO 27001 documents and records, with owner, required status, approval, review cadence, location and evidence readiness.",
              "href": "MDR_Mandatory_Documents_and_Records_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "DR Document Register",
              "How this document uses it": "Controlled documented information: origin, owner, approver, version, review cycle, retention and location.",
              "href": "DR_Document_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "RRS Records Retention Schedule",
              "How this document uses it": "Retention rules for ISMS, security, privacy, audit and operational records, with owner, period, disposal method and evidence.",
              "href": "RRS_Records_Retention_Schedule_Register.xlsx"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISOCTRL ISO 27001:2022 Controls (Building the ISMS, Annex A Controls)",
              "href": "ISOCTRL_ISO_27001_2022_Controls_Coverage.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            },
            {
              "Kind": "Artifact",
              "Reference": "TRC Training Records (Building the ISMS, Security Awareness & Training Programs)",
              "href": "TRC_Training_Records_Register.xlsx",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record."
            }
          ]
        },
        {
          "id": "external_sources",
          "heading": "External references",
          "level": 1,
          "text": "Cite these ISO clauses and book chapters from workshops and audits.",
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative ISMS requirements this companion artifact supports.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, HR Security: Screening, Onboarding & Offboarding",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Plan",
    "role": "Live programme for the surveillance window"
  }
}
