audit-evidence-mapping-protocol
Use this skill when compliance controls must be mapped to audit evidence, when evidence collection, retention policy, and legal-hold status need to be assessed across Microsoft 365 workloads, or when an attestation package must be assembled for an auditor or regulator. Defines th
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/audit-evidence-mapping-protocol
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Audit Evidence Mapping Protocol
Purpose
This skill defines how compliance controls are traced to concrete audit evidence, how that evidence is validated for completeness and retention, and how an attestation package is assembled and handed off to the compliance or legal owner. It exists so that evidence gaps are surfaced before an audit begins, retention and legal-hold status are verified against Microsoft Purview policy, and every handoff carries a documented chain of custody. It does not authorize evidence release, does not replace legal or audit counsel, and does not modify retention policies or legal-hold configuration.
When to use
- A compliance or audit team must map controls to evidence artifacts across Microsoft 365 workloads.
- Audit log retention status needs to be verified against organizational policy before a regulatory review.
- A legal hold must be confirmed or flagged as incomplete before an eDiscovery matter proceeds.
- An attestation package must be assembled from distributed evidence sources (Exchange, SharePoint, Entra ID, Dataverse).
- Evidence completeness gaps are suspected and must be inventoried before the auditor window opens.
When NOT to use
- Evidence has already been assembled and validated — hand off directly to the compliance owner.
- The matter is an active legal proceeding requiring litigation-hold decisions — escalate to legal counsel immediately.
- A retention policy change or legal-hold placement is required — that is a production-impacting action and must be escalated to the Purview compliance administrator and the legal owner.
- The matter involves special-category personal data and jurisdiction is unknown — stop and escalate.
Participating agents
d365-security-sod-governance-agent— primary: maps segregation-of-duties controls to evidence artifacts in Dynamics 365 and Power Platform audit logsm365-maestro-agent— orchestrates cross-workload evidence discovery; escalation path to Microsoft Purview specialists (planned: purview-compliance-specialist-agent)
Inputs required
- Control framework or control list (e.g., ISO 27001, SOC 2, NIST CSF control IDs)
- Workload scope (Exchange Online, SharePoint, Entra ID, Dynamics 365, Power Platform, Teams)
- Retention requirements (regulatory, contractual, or internal policy)
- Legal-hold case reference (if applicable)
- Audit window dates
Evidence required
- Existing audit log retention policies from Microsoft Purview (Audit Standard or Audit Premium tier)
- Current legal-hold case list and hold scope from Microsoft Purview eDiscovery
- Control register or risk register from the compliance team
- Prior audit findings or evidence gaps (if available)
Workflow
- Ingest control framework — receive the control list and map each control to a workload and evidence type (audit log, configuration export, access review, policy document).
- Scope workloads — confirm which Microsoft 365 services and Dynamics 365 environments are in scope; note licensing tier (Audit Standard vs. Audit Premium) as it affects default retention (180 days vs. 1 year vs. 10 years with add-on).
- Discover evidence artifacts — for each control, identify the evidence artifact location (Purview Audit log, SharePoint document library, Entra ID access review, Power Platform DLP report).
- Verify retention status — confirm that audit log retention policies cover the required period; flag any control whose evidence falls under the 180-day standard default that requires a longer period.
- Check legal-hold coverage — if a legal hold is active, confirm that evidence in scope is covered by an eDiscovery hold; flag uncovered artifacts.
- Identify evidence gaps — produce a gap register: controls with missing artifacts, expired retention, or uncovered legal-hold scope.
- Escalation gate: evidence completeness — if gap register is non-empty, pause and escalate to compliance owner and m365-maestro-agent for Purview remediation.
- Escalation gate: retention or legal-hold deficiency — if retention is insufficient or a legal hold is not in place, stop and escalate to the Purview compliance administrator and legal owner before proceeding.
- Assemble attestation package — for each control, compile: control ID, evidence artifact reference, evidence location, retention expiry, legal-hold status, evidence quality rating (complete / partial / missing), and open questions.
- Review for privilege and privacy sensitivity — label package sections with privilege sensitivity and privacy sensitivity before handoff.
- Hand off to compliance owner — deliver attestation package with a do-not-do list and open questions; require human sign-off before any evidence is transmitted to an external auditor or regulator.
Decision gates
| Gate | Condition | Action |
|---|---|---|
| Evidence completeness | Any control has missing or partial evidence | Pause; escalate to compliance owner; open remediation task |
| Retention / legal-hold | Retention < required period OR legal hold not confirmed | Stop; escalate to Purview admin and legal owner before proceeding |
| Privilege sensitivity | Evidence touches legally privileged communications | Flag; route to legal counsel before inclusion in package |
| Special-category data | Evidence includes health, biometric, or regulated personal data | Stop; confirm jurisdiction and privacy owner before proceeding |
Refusal triggers
- A request is made to delete, truncate, or shorten retention of in-scope evidence — refuse and escalate.
- A request is made to release evidence directly to an external auditor without human compliance owner sign-off — refuse.
- Credentials, tenant IDs, or personal data are requested to perform evidence discovery — refuse; work from sanitized signals only.
- Jurisdiction of regulated personal data is unknown — refuse to proceed; escalate.
Handoff rules
- Every handoff carries: control ID list, evidence gap register, retention status summary, legal-hold status, privilege sensitivity label, privacy sensitivity label, open questions, and a do-not-do list.
- No agent transmits evidence to external parties. Human compliance owner authorizes all external transmissions.
- Post-handoff, the receiving agent or human confirms receipt and records the handoff in the audit log.
KPIs
- Percentage of controls with complete, verified evidence before audit window opens
- Number of retention gaps identified and remediated before audit
- Time from control mapping to attestation package delivery
- Number of escalations requiring human intervention
References
Files (vanguard-frontier-agentic)
-
references
-
workflow-and-output.md 8.3 KB
# Audit Evidence Mapping Protocol — Detailed Workflow and Output Contract ## Overview This document provides the step-by-step workflow, decision tree, and output contract for the `audit-evidence-mapping-protocol` skill. It is intended for orchestrating agents and human compliance owners who need to understand how evidence mapping proceeds, where gates fire, and what the deliverable looks like. --- ## Detailed Workflow ### Phase 1 — Scope and Ingest **Step 1.1 — Receive control framework** - Input: control IDs, framework name (ISO 27001, SOC 2 Type II, NIST CSF, internal), and control description - Action: normalize control IDs to a canonical internal format - Output: `control_register[]` with fields: `control_id`, `control_description`, `workload_hint`, `evidence_type_hint` **Step 1.2 — Confirm workload scope** - Input: list of Microsoft 365 services and Dynamics 365 / Power Platform environments in scope - Check: confirm Microsoft Purview licensing tier for each workload - Audit Standard: 180-day default retention (as of October 17, 2023) - Audit Premium (E5 or Purview Suite): 1-year default retention for Entra ID, Exchange, SharePoint, OneDrive - Audit Premium + 10-year add-on: up to 10-year retention with explicit policy - Output: `workload_scope[]` with `service`, `environment_id`, `audit_tier`, `default_retention_days` **Step 1.3 — Load retention policy inventory** - Source: Microsoft Purview Audit log retention policies (exported summary, not live query requiring credentials) - Action: match each workload to its applicable custom retention policy; fall back to licensing default - Output: `retention_policy_map[]` with `workload`, `policy_name`, `retention_days`, `priority` --- ### Phase 2 — Evidence Discovery **Step 2.1 — Map controls to evidence artifacts** For each control in `control_register[]`: - Identify the primary evidence type: - Audit log entry (Purview Unified Audit Log) - Configuration export (Power Platform DLP policy, Entra ID Conditional Access policy) - Access review record (Entra ID Access Reviews) - Policy document or runbook (SharePoint) - Dataverse / Dynamics 365 audit trail entry - Record: `evidence_artifact[]` with `control_id`, `artifact_type`, `source_workload`, `location_hint`, `expected_retention_required` **Step 2.2 — Verify evidence availability** - For each artifact: confirm whether the artifact exists within the retention window - Flag: `evidence_status` = `complete` | `partial` | `missing` | `retention_expired` **Step 2.3 — Check legal-hold coverage** - If a legal-hold case reference is provided: - Confirm that each in-scope artifact is covered by an active eDiscovery hold in Microsoft Purview - Flag uncovered artifacts as `hold_status` = `covered` | `not_covered` | `unknown` - If no legal-hold case reference: record `hold_status` = `not_applicable` --- ### Phase 3 — Gap Analysis and Escalation Gates **Step 3.1 — Build gap register** - Populate `gap_register[]` with every artifact where: - `evidence_status` ≠ `complete`, OR - `retention_days` < `expected_retention_required`, OR - `hold_status` = `not_covered` (when a hold case is active) **Gate A — Evidence Completeness Gate** ``` IF gap_register[] is non-empty: → PAUSE workflow → Escalate to: compliance owner + m365-maestro-agent → Action required: remediate gaps before audit window opens → Do NOT assemble attestation package until gaps are resolved or explicitly accepted with risk note ``` **Gate B — Retention / Legal-Hold Deficiency Gate** ``` IF any artifact has retention_days < expected_retention_required OR any artifact has hold_status = not_covered AND legal hold is active: → STOP workflow → Escalate to: Purview compliance administrator + legal owner → Action required: place legal hold or extend retention policy → Do NOT proceed until human confirmation that deficiency is resolved or formally accepted ``` **Gate C — Privilege Sensitivity Gate** ``` IF any artifact is flagged as potentially privileged (attorney-client, work product): → Flag artifact as privilege_sensitivity = HIGH → Route to legal counsel before including in attestation package → Do NOT transmit privileged artifact to external auditor without counsel sign-off ``` **Gate D — Special-Category Personal Data Gate** ``` IF any artifact contains health, biometric, racial/ethnic origin, or other special-category data: → STOP → Confirm jurisdiction and privacy owner → Do NOT proceed until jurisdiction confirmed and privacy owner engaged ``` --- ### Phase 4 — Attestation Package Assembly **Step 4.1 — Compile attestation records** For each control: ``` { "control_id": "<framework>-<id>", "control_description": "...", "evidence_artifact_ref": "<location or log reference>", "source_workload": "Exchange Online | SharePoint | Entra ID | Dataverse | ...", "retention_expiry": "<ISO date>", "legal_hold_status": "covered | not_covered | not_applicable", "evidence_quality": "complete | partial | missing", "privilege_sensitivity": "HIGH | STANDARD", "privacy_sensitivity": "HIGH | STANDARD", "open_questions": ["..."], "gap_notes": "..." } ``` **Step 4.2 — Assemble package header** ``` { "attestation_package_id": "<uuid>", "skill_id": "audit-evidence-mapping-protocol", "skill_version": "0.1.0", "invoked_by": "<agent or human id>", "audit_window": { "start": "<date>", "end": "<date>" }, "control_framework": "<name>", "workloads_in_scope": ["..."], "total_controls": <n>, "complete_evidence": <n>, "partial_evidence": <n>, "missing_evidence": <n>, "retention_gaps": <n>, "hold_gaps": <n>, "escalations_fired": ["Gate A", "Gate B", ...], "package_status": "ready_for_review | blocked_pending_escalation", "timestamp": "<ISO datetime>" } ``` **Step 4.3 — Attach do-not-do list** Every attestation package includes: - Do not transmit evidence to an external auditor or regulator without human compliance owner sign-off. - Do not modify retention policies, legal holds, or eDiscovery cases to close gaps without Purview admin and legal owner approval. - Do not include potentially privileged communications in the package without legal counsel review. - Do not request or retain personal data beyond the minimum necessary to complete the attestation. - Do not interpret this package as legal advice or as a legal opinion on compliance status. --- ## Decision Tree (Condensed) ``` Receive control list └─ Scope workloads + check licensing tier └─ Map controls to evidence artifacts └─ Verify retention and legal-hold status ├─ [Gap register non-empty] → Gate A: pause, escalate ├─ [Retention or hold deficiency] → Gate B: stop, escalate ├─ [Privileged content detected] → Gate C: flag, route to counsel ├─ [Special-category data, unknown jurisdiction] → Gate D: stop └─ [All gates clear] → Assemble attestation package └─ Compliance owner review + sign-off └─ Authorized external transmission (human only) ``` --- ## Output Contract | Field | Type | Required | Description | |---|---|---|---| | `attestation_package_id` | string (UUID) | Yes | Unique package identifier | | `skill_id` | string | Yes | Must be `audit-evidence-mapping-protocol` | | `skill_version` | string | Yes | Semantic version | | `audit_window` | object | Yes | `start` and `end` ISO dates | | `control_framework` | string | Yes | Framework name and version | | `workloads_in_scope` | string[] | Yes | List of Microsoft 365 / D365 workloads | | `attestation_records` | object[] | Yes | One record per control (schema above) | | `gap_register` | object[] | Yes | Empty if no gaps; populated if Gate A fired | | `escalations_fired` | string[] | Yes | Which gates fired | | `package_status` | enum | Yes | `ready_for_review` or `blocked_pending_escalation` | | `do_not_do_list` | string[] | Yes | Mandatory refusal items | | `open_questions` | string[] | Yes | Unresolved items requiring human judgment | | `timestamp` | string (ISO) | Yes | Package assembly datetime | --- ## Audit Log Fields `attestation_package_id`, `skill_id`, `skill_version`, `invoked_by`, `input_hash`, `evidence_quality_summary`, `gates_fired`, `package_status`, `timestamp`
-
-
metadata.json 2 KB
{ "id": "audit-evidence-mapping-protocol", "name": "Audit Evidence Mapping Protocol", "type": "skill", "provider": "generic", "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"], "summary": "Maps compliance controls to audit evidence artifacts across Microsoft 365 workloads, verifies retention and legal-hold status against Microsoft Purview policy, identifies evidence gaps before the audit window opens, and assembles a signed-off attestation package. Covers Audit Standard and Audit Premium retention tiers (180 days, 1 year, 10 years with add-on), eDiscovery legal-hold verification, and privilege and privacy sensitivity labeling of the evidence package.", "source_type": "original", "official_docs": [ "https://learn.microsoft.com/purview/audit-solutions-overview", "https://learn.microsoft.com/purview/audit-log-retention-policies", "https://learn.microsoft.com/en-us/purview/ediscovery", "https://learn.microsoft.com/en-us/purview/data-lifecycle-management" ], "security_notes": "Protocol is recommendation and orchestration only — never an authorization to release evidence to external parties or to modify retention policies, legal holds, or eDiscovery cases. All production-impacting steps (retention policy changes, legal-hold placement, evidence transmission to external auditors) must be escalated to the Purview compliance administrator and the human legal or compliance owner. Never requests credentials, tenant IDs, session tokens, or customer personal data to perform evidence discovery; works from sanitized control and workload scope signals only. Evidence touching legally privileged communications is flagged and routed to legal counsel before inclusion in any package. Special-category personal data triggers a jurisdiction confirmation gate before proceeding.", "last_verified": "2026-06-16", "path": "skills/cross-functional/audit-evidence-mapping-protocol", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 7.8 KB
--- name: audit-evidence-mapping-protocol description: Use this skill when compliance controls must be mapped to audit evidence, when evidence collection, retention policy, and legal-hold status need to be assessed across Microsoft 365 workloads, or when an attestation package must be assembled for an auditor or regulator. Defines the end-to-end flow from control identification through evidence discovery, gap analysis, retention verification, legal-hold confirmation, and attestation sign-off. Does not serve as an authorization to release evidence to external parties; that requires a human compliance or legal owner. Does not replace qualified legal or audit counsel. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-06-16" category: compliance lifecycle: experimental --- # Audit Evidence Mapping Protocol ## Purpose This skill defines how compliance controls are traced to concrete audit evidence, how that evidence is validated for completeness and retention, and how an attestation package is assembled and handed off to the compliance or legal owner. It exists so that evidence gaps are surfaced before an audit begins, retention and legal-hold status are verified against Microsoft Purview policy, and every handoff carries a documented chain of custody. It does not authorize evidence release, does not replace legal or audit counsel, and does not modify retention policies or legal-hold configuration. ## When to use - A compliance or audit team must map controls to evidence artifacts across Microsoft 365 workloads. - Audit log retention status needs to be verified against organizational policy before a regulatory review. - A legal hold must be confirmed or flagged as incomplete before an eDiscovery matter proceeds. - An attestation package must be assembled from distributed evidence sources (Exchange, SharePoint, Entra ID, Dataverse). - Evidence completeness gaps are suspected and must be inventoried before the auditor window opens. ## When NOT to use - Evidence has already been assembled and validated — hand off directly to the compliance owner. - The matter is an active legal proceeding requiring litigation-hold decisions — escalate to legal counsel immediately. - A retention policy change or legal-hold placement is required — that is a production-impacting action and must be escalated to the Purview compliance administrator and the legal owner. - The matter involves special-category personal data and jurisdiction is unknown — stop and escalate. ## Participating agents - `d365-security-sod-governance-agent` — primary: maps segregation-of-duties controls to evidence artifacts in Dynamics 365 and Power Platform audit logs - `m365-maestro-agent` — orchestrates cross-workload evidence discovery; escalation path to Microsoft Purview specialists (planned: purview-compliance-specialist-agent) ## Inputs required - Control framework or control list (e.g., ISO 27001, SOC 2, NIST CSF control IDs) - Workload scope (Exchange Online, SharePoint, Entra ID, Dynamics 365, Power Platform, Teams) - Retention requirements (regulatory, contractual, or internal policy) - Legal-hold case reference (if applicable) - Audit window dates ## Evidence required - Existing audit log retention policies from Microsoft Purview (Audit Standard or Audit Premium tier) - Current legal-hold case list and hold scope from Microsoft Purview eDiscovery - Control register or risk register from the compliance team - Prior audit findings or evidence gaps (if available) ## Workflow 1. **Ingest control framework** — receive the control list and map each control to a workload and evidence type (audit log, configuration export, access review, policy document). 2. **Scope workloads** — confirm which Microsoft 365 services and Dynamics 365 environments are in scope; note licensing tier (Audit Standard vs. Audit Premium) as it affects default retention (180 days vs. 1 year vs. 10 years with add-on). 3. **Discover evidence artifacts** — for each control, identify the evidence artifact location (Purview Audit log, SharePoint document library, Entra ID access review, Power Platform DLP report). 4. **Verify retention status** — confirm that audit log retention policies cover the required period; flag any control whose evidence falls under the 180-day standard default that requires a longer period. 5. **Check legal-hold coverage** — if a legal hold is active, confirm that evidence in scope is covered by an eDiscovery hold; flag uncovered artifacts. 6. **Identify evidence gaps** — produce a gap register: controls with missing artifacts, expired retention, or uncovered legal-hold scope. 7. **Escalation gate: evidence completeness** — if gap register is non-empty, pause and escalate to compliance owner and m365-maestro-agent for Purview remediation. 8. **Escalation gate: retention or legal-hold deficiency** — if retention is insufficient or a legal hold is not in place, stop and escalate to the Purview compliance administrator and legal owner before proceeding. 9. **Assemble attestation package** — for each control, compile: control ID, evidence artifact reference, evidence location, retention expiry, legal-hold status, evidence quality rating (complete / partial / missing), and open questions. 10. **Review for privilege and privacy sensitivity** — label package sections with privilege sensitivity and privacy sensitivity before handoff. 11. **Hand off to compliance owner** — deliver attestation package with a do-not-do list and open questions; require human sign-off before any evidence is transmitted to an external auditor or regulator. ## Decision gates | Gate | Condition | Action | |---|---|---| | Evidence completeness | Any control has missing or partial evidence | Pause; escalate to compliance owner; open remediation task | | Retention / legal-hold | Retention < required period OR legal hold not confirmed | Stop; escalate to Purview admin and legal owner before proceeding | | Privilege sensitivity | Evidence touches legally privileged communications | Flag; route to legal counsel before inclusion in package | | Special-category data | Evidence includes health, biometric, or regulated personal data | Stop; confirm jurisdiction and privacy owner before proceeding | ## Refusal triggers - A request is made to delete, truncate, or shorten retention of in-scope evidence — refuse and escalate. - A request is made to release evidence directly to an external auditor without human compliance owner sign-off — refuse. - Credentials, tenant IDs, or personal data are requested to perform evidence discovery — refuse; work from sanitized signals only. - Jurisdiction of regulated personal data is unknown — refuse to proceed; escalate. ## Handoff rules - Every handoff carries: control ID list, evidence gap register, retention status summary, legal-hold status, privilege sensitivity label, privacy sensitivity label, open questions, and a do-not-do list. - No agent transmits evidence to external parties. Human compliance owner authorizes all external transmissions. - Post-handoff, the receiving agent or human confirms receipt and records the handoff in the audit log. ## KPIs - Percentage of controls with complete, verified evidence before audit window opens - Number of retention gaps identified and remediated before audit - Time from control mapping to attestation package delivery - Number of escalations requiring human intervention ## References - [Learn about auditing solutions in Microsoft Purview](https://learn.microsoft.com/purview/audit-solutions-overview) - [Manage audit log retention policies](https://learn.microsoft.com/purview/audit-log-retention-policies) - [Microsoft Purview eDiscovery solutions](https://learn.microsoft.com/en-us/purview/ediscovery) - [Microsoft Purview Data Lifecycle Management](https://learn.microsoft.com/en-us/purview/data-lifecycle-management)
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.