Milestone acceptance report
ScopeAudit Milestone Acceptance Report
Atlas Admin Portal
Role-Based User Invitations
Synthetic demonstration using a controlled commissioned-software delivery package.
Report identity & parties
- Audit case
- AUDIT-ATLAS-001
- Audit run
- AUDIT-RUN-ATLAS-001-01
- Graph version
- SCOPEGRAPH-ATLAS-1.0
- Policy version
- VERDICT-POLICY-DEMO-1.0
- Baseline
- BASELINE-1.0
- Audit date
- 2026-07-26
- Commissioner
- Northstar Software
- Supplier
- Vertex Studio
- Auditor
- Nouevra
Executive verdict
Qualified acceptance recommendation
Conditionally reject pending remediation
This verdict is produced using the Product v0 demonstration policy. It is a qualified technical recommendation for a synthetic case, not a legal determination or a guarantee that the software is defect-free.
- A required Editor role is missing despite a completion claim.
- Invitation expiry contradicts an explicit acceptance criterion.
- Critical permission boundaries lack the required automated proof.
- A sensitive authentication change falls outside the authorised scope.
- Audit logging and deployment handover remain incomplete.
Delivery-state contrast
Coverage & severity summary
Missing: 2. Contradicted: 1. No composite acceptance score is used.
Blocking findings
Editor role is not implemented
The supplier claimed all three roles were implemented, but no Editor-role implementation or test evidence exists in the accepted fixture package.
Invitation expiry is 24 hours rather than 48 hours
The implemented invitation-expiry value contradicts the explicit 48-hour acceptance criterion.
Permission isolation lacks adequate test evidence
The fixture package contains role configuration and invitation happy-path tests, but no automated allowed/denied boundary tests that satisfy QA-03.
Authentication middleware changed outside authorised scope
The milestone delivery modifies authentication middleware, but no authoritative requirement or approved change authorises that modification.
Requirement-conformity matrix
| Requirement | Materiality | Evidence status | Related claims / status | Finding |
|---|---|---|---|---|
| REQ-01Support Viewer role | Required | Fully evidenced | CLM-01 ContradictedCLM-06 Contradicted | — |
| REQ-02Support Editor role | Required | Missing | CLM-01 ContradictedCLM-06 Contradicted | F-001 |
| REQ-03Support Admin role | Required | Fully evidenced | CLM-01 ContradictedCLM-06 Contradicted | — |
| REQ-04Send email invitations | Required | Fully evidenced | CLM-06 Contradicted | — |
| REQ-05Invitations expire after 48 hours | Required | Contradicted | CLM-02 ContradictedCLM-06 Contradicted | F-002 |
| REQ-06Enforce role permission isolation | Critical | Fully evidenced | CLM-03 UnsupportedCLM-06 Contradicted | F-003 |
| REQ-07Record role changes in audit logs | Required | Partially evidenced | CLM-04 Partially supportedCLM-06 Contradicted | F-005 |
| REQ-08Provide automated role-boundary tests | Required | Missing | CLM-03 UnsupportedCLM-06 Contradicted | F-003 |
| REQ-09Provide deployment and handover documentation | Required | Partially evidenced | CLM-05 Partially supportedCLM-06 Contradicted | F-006 |
Material findings
Editor role is not implemented
The supplier claimed all three roles were implemented, but no Editor-role implementation or test evidence exists in the accepted fixture package.
- Affected scope
- REQ-02
- Recommendation
- Implement the Editor role, add relevant tests, and revise or reissue the completion claim before acceptance.
Invitation expiry is 24 hours rather than 48 hours
The implemented invitation-expiry value contradicts the explicit 48-hour acceptance criterion.
Permission isolation lacks adequate test evidence
The fixture package contains role configuration and invitation happy-path tests, but no automated allowed/denied boundary tests that satisfy QA-03.
- Recommendation
- Add automated tests covering permitted and denied actions for Viewer, Editor, and Admin roles.
Authentication middleware changed outside authorised scope
The milestone delivery modifies authentication middleware, but no authoritative requirement or approved change authorises that modification.
- Affected scope
- Audit-case scope boundary
- Evidence
- CHG-001DIFF-AUTH-001
- Recommendation
- Revert the change or document and approve it through formal scope control, then provide relevant review and test evidence.
Role-change audit logging is incomplete
Role-change logging exists, but it does not preserve all information required to evidence the previous and new role values.
Deployment and handover documentation is incomplete
A partial handover pack exists, but deployment environment and configuration material required by the statement of work is absent.
- Affected scope
- REQ-09
- Evidence
- EVD-011MISS-REQ-09-DOCUMENTATION
- Recommendation
- Add deployment prerequisites, environment configuration, deployment steps, rollback guidance, and operational ownership information.
Required remediation
Implement Editor role and add relevant Editor invitation and permission tests
Implement the Editor role, add relevant tests, and revise or reissue the completion claim before acceptance.
Completion evidence expected- Updated role configuration
- Editor implementation reference
- Editor invitation and permission tests
Change invitation expiry from 24 to 48 hours and prove the behaviour
Change the expiry value to 48 hours and add a test that proves the agreed behaviour.
Completion evidence expected- Updated invitation expiry configuration
- Focused 48-hour expiry test
Add automated allowed and denied role-boundary tests
Add automated tests covering permitted and denied actions for Viewer, Editor, and Admin roles.
Completion evidence expected- Role-boundary test suite
- Passing allowed and denied test output
Revert or formally authorise the authentication middleware change
Revert the change or document and approve it through formal scope control, then provide relevant review and test evidence.
Completion evidence expected- Revert evidence or approved change record
- Relevant review and test evidence
Complete role-change audit logging
Record actor, target user, previous role, new role, and timestamp for every role change, then demonstrate the behaviour with a focused test.
Completion evidence expected- Updated logging implementation
- Focused role-change audit-log test
Complete deployment and handover documentation
Add deployment prerequisites, environment configuration, deployment steps, rollback guidance, and operational ownership information.
Completion evidence expected- Deployment and environment documentation
- Rollback and operational ownership documentation
Preparing evidence appendix
The authoritative verdict and findings above are ready. Evidence paths are being assembled from the validated graph.