{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "OPI",
  "title": "Operational Procedures Index",
  "definitionRef": {
    "artifactId": "OPI",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "OPI.artifactDefinition.v2",
    "title": "Operational Procedures Index"
  },
  "organization": "Arcfield",
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Operational Procedures Index",
        "Register ID": "OPI-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "Operations Lead",
        "Approver": "ISMS Manager",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Operational Procedures Index",
        "Register ID: OPI-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: Operations Lead",
        "Approver: ISMS Manager",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "The Operational Procedures Index provides a controlled, implementation-ready way to maintain visibility and control over recurring security operating procedures. It connects accountable work to source-system evidence, review decisions and follow-up actions so that the artifact can support both day-to-day operation and audit sampling. This index navigates the certified Arcfield Platform companion set in the surveillance cycle after certificate ARC-ISMS-2025-001. It is not itself the evidence freeze.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Maintain visibility and control over recurring security operating procedures."
        },
        {
          "Property": "Used by",
          "Value": "IT Operations, Security Operations, Service Owners"
        },
        {
          "Property": "Maintained by",
          "Value": "Operations Lead"
        },
        {
          "Property": "Evidence role",
          "Value": "supporting tool"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 clause 8.1"
        },
        {
          "Property": "Review cadence",
          "Value": "During procedure onboarding, operational review, change, and audit preparation."
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "List each controlled procedure, its owner, trigger or cadence, repository link, version, approval, required run record, dependencies, last review, next review, and current exceptions.",
        "Review and approve the completed artifact before it is used as audit evidence.",
        "Link every material conclusion to an authoritative and exportable source record.",
        "Assign an accountable owner and due date for each unresolved issue.",
        "Review and approve the completed artifact before it is used as audit evidence.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "operational_procedures_index",
      "title": "Operational procedures index",
      "rows": [
        {
          "Procedure ID": "OPI-001",
          "Procedure title": "Production access review",
          "System or service": "Arcfield API",
          "Owner": "ISMS Manager",
          "Trigger or frequency": "Quarterly",
          "Repository link": "GRC / evidence / 2026-Q3",
          "Version": "2026.09.1",
          "Approver": "Top Management",
          "Required run record": "Defined and evidenced",
          "Last review": "Defined and evidenced",
          "Next review": "Defined and evidenced",
          "Status": "Complete",
          "Exception": "Defined and evidenced"
        },
        {
          "Procedure ID": "OPI-002",
          "Procedure title": "Security evidence validation",
          "System or service": "Customer Portal",
          "Owner": "Security Lead",
          "Trigger or frequency": "Annually",
          "Repository link": "Jira SEC-142",
          "Version": "v1.0",
          "Approver": "ISMS Manager",
          "Required run record": "Reviewed by accountable owner",
          "Last review": "Reviewed by accountable owner",
          "Next review": "Reviewed by accountable owner",
          "Status": "In progress",
          "Exception": "Reviewed by accountable owner"
        },
        {
          "Procedure ID": "OPI-003",
          "Procedure title": "Quarterly control review",
          "System or service": "Production CI/CD",
          "Owner": "Control Owner",
          "Trigger or frequency": "Event-driven",
          "Repository link": "Approved cloud vault",
          "Version": "build-4821",
          "Approver": "Security Lead",
          "Required run record": "See linked source record",
          "Last review": "See linked source record",
          "Next review": "See linked source record",
          "Status": "Pending review",
          "Exception": "See linked source record"
        },
        {
          "Procedure ID": "OPI-004",
          "Procedure title": "Supplier control verification",
          "System or service": "Admin Console",
          "Owner": "ISMS Manager",
          "Trigger or frequency": "Quarterly",
          "Repository link": "GitHub PR 4821",
          "Version": "2026.10.0",
          "Approver": "Top Management",
          "Required run record": "Approved with follow-up",
          "Last review": "Approved with follow-up",
          "Next review": "Approved with follow-up",
          "Status": "Complete",
          "Exception": "Approved with follow-up"
        },
        {
          "Procedure ID": "OPI-005",
          "Procedure title": "Release security approval",
          "System or service": "Billing Service",
          "Owner": "Security Lead",
          "Trigger or frequency": "Annually",
          "Repository link": "ServiceNow CHG-2204",
          "Version": "build-4938",
          "Approver": "ISMS Manager",
          "Required run record": "Pending independent review",
          "Last review": "Pending independent review",
          "Next review": "Pending independent review",
          "Status": "In progress",
          "Exception": "Pending independent review"
        }
      ],
      "schemaRef": {
        "definitionId": "OPI.artifactDefinition.v2",
        "sectionId": "operational_procedures_index",
        "columnsRef": "sections.operational_procedures_index.columns"
      },
      "contentType": "register_table"
    },
    {
      "id": "operational_procedures_index_review",
      "title": "Operational Procedures Index review",
      "rows": [
        {
          "Field": "Review result",
          "Value": "Approved as an implementation candidate with JSON Definition, JSON Example and rendered-file QA still required."
        },
        {
          "Field": "Records reviewed",
          "Value": "5 example records"
        },
        {
          "Field": "Open issues",
          "Value": "Contract and renderer implementation pending"
        },
        {
          "Field": "Action owner",
          "Value": "Operations Lead"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-05"
        },
        {
          "Field": "Evidence reference",
          "Value": "OPI-REVIEW-2026-Q3"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 8.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Secure Operations, Network & Endpoint Security",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983462"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "generation": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Index",
    "role": "Navigation across companions; not the evidence freeze"
  }
}
