Capability 05 / 14 · Prove and integrate

Build the audit package from reviewed proof.

EKOS CompliancePreviewStage: Prove

Assemble requirement-scoped evidence into a point-in-time package with source excerpts, provenance, review context, a hash-chained JSON manifest, and a readable PDF binder.

PACKAGE / PKG-AC-2026-07Preview
  1. 001

    Requirement AC-2 · Account Management

    entry sha256: 9f31…c2a4 · prev ∅

  2. 002

    Access Control Policy v3 · §3.1 excerpt

    entry sha256: 5b0e…77f1 · prev 9f31…c2a4

  3. 003

    Q2 Access Review Export · reviewed evidence

    entry sha256: d84a…10be · prev 5b0e…77f1

root sha256: 77aa…09bd

Chain intact
JSON manifestPDF binder · root on cover

Edit, remove, or reorder any entry and verification reports exactly where the chain breaks.

Illustrative product view · a hash-chained manifest and its binder

The problem

Audit preparation becomes a last-minute file hunt when requirement mappings, source excerpts, evidence, and review decisions live in separate systems.

What EKOS does

EKOS walks qualifying reviewed relationships for a framework or citation prefix and assembles the requirements, documents, excerpts, provenance, and review context into a canonical manifest and companion binder.

  • Framework-wide or citation-prefix assembly
  • Inclusion from reviewed evidence relationships
  • Canonical hash-chained JSON manifest
  • Readable PDF binder tied to the package identity
  • Verification that identifies where consistency breaks

How it works

  1. An administrator scopes the package to a framework, or to a citation prefix such as one control family.

  2. EKOS walks the qualifying reviewed relationships and assembles requirements, documents, excerpts, provenance, and review context as of that moment.

  3. The authoritative output is a canonical JSON manifest whose entries are linked by hashes, with the root hash stored in the package catalog.

  4. A readable PDF binder is rendered from the manifest and carries the package ID and root hash on its cover.

  5. Verification recomputes the chain against the catalog and reports the first edited, removed, or reordered entry if consistency breaks.

Business outcome

Teams can produce a consistent, reviewable audit artifact without rebuilding the evidence trail for every request.

Proof and human control

Manifest entries are linked by hashes and tied to a stored root hash, allowing verification to identify edited, removed, or reordered entries.

Example in practice

An auditor requests evidence for a control family. An administrator assembles the scoped package, verifies its root hash, and provides the JSON manifest and PDF binder as a point-in-time record.

Scope today

This capability is in preview. Hash verification shows internal consistency; it does not establish that the evidence is complete, sufficient, truthful, or legally compliant.

Next step

See your own documents become a trail of proof.

A working session with the EKOS team: bring a policy set, a framework, and a hard question. We will walk the loop end to end.