Appendices

Appendix A: Evidence Artifact Catalogue

Working draft

This page renders the current aws2 working draft. It is not a released standard, certification program, compliance framework, legal analysis, endorsement, or public conformance claim.

This appendix gives first-pass evidence examples. It is not exhaustive.

ArtifactSupportsExpected ownerMinimum metadataRedaction guidance
Scope recordAWS2-SCP, AWS2-GOVOrganization or governancesystem name, boundary, owners, exclusions, dateavoid exporting unrelated system contents
Runtime and tool inventoryAWS2-SCP, AWS2-RUN, AWS2-SRCRuntime platformruntime, tools, connectors, skills, versions, ownersavoid secrets in configuration details
Connected resource inventoryAWS2-SCP, AWS2-WSB, AWS2-SECWorkspace or endpointrepositories, files, SaaS systems, shells, networks, data categorieslist categories and scopes, not confidential payloads
Owner matrixAWS2-SCP, AWS2-DEL, AWS2-GOVOrganization or governanceowner roles, responsibilities, review datesminimize personal data where role data is enough
Authority modelAWS2-DEL, AWS2-RUNOrganization or governanceuser roles, service accounts, delegated authority, approval rolesdo not expose credentials or private identity tokens
Runtime policy exportAWS2-RUN, AWS2-CTX, AWS2-SECRuntime platformpolicy version, action classes, allow/deny/approval rulesredact live tokens, prompts, and sensitive examples
Approval policyAWS2-DEL, AWS2-RUN, AWS2-GOVOrganization or governanceapprover roles, triggers, expiry, escalationsummarize approver roles when names are unnecessary
Workspace boundary configurationAWS2-WSB, AWS2-SECWorkspace or endpointsandbox, filesystem, repository, network, connector scopesredact sensitive paths only when review remains possible
Source registerAWS2-SRC, AWS2-GOVSkill or skill-set sourcesource, maintainer, version, commit, checksum, approval stateshare identifiers and hashes before private source code
Source-trust profile recordAWS2-SRC, AWS2-LOG, AWS2-GOV, AWS2-VALSkill or skill-set source, runtime platform, or evidence owneraction-unit ID, registry or source signal, publisher or namespace status, manifest/hash/signature if available, declared permissions, local review state, drift, rollback or retirement pathpreserve identifiers, hashes, metadata, and review decisions; avoid proprietary connector internals, tokens, and raw sensitive payloads
Dependency or lockfile recordAWS2-SRC, AWS2-VALSkill or skill-set sourcepackage names, versions, hashes, resolution dateavoid embedding private registry credentials
Installation or update receiptAWS2-SRC, AWS2-LOGRuntime platformsource, version, actor, timestamp, approval stateremove credentials and unrelated payloads
High-impact action receiptAWS2-RUN, AWS2-LOG, AWS2-VALEvidence or auditevent ID, timestamp, actor, action class, scope, policy outcomerecord metadata and stable references, not raw secrets
Denied-action recordAWS2-RUN, AWS2-LOG, AWS2-VALEvidence or auditpolicy rule, attempted action class, timestamp, actor or runtimeredact attempted payloads that contain sensitive data
Sensitive-data handling recordAWS2-SEC, AWS2-LOG, AWS2-VALWorkspace or endpointdata category, access rule, redaction state, export outcomeavoid raw personal data or secrets
Context-source inventoryAWS2-CTX, AWS2-SCPRuntime platforminstruction sources, memory sources, retrieval sources, trust orderdo not export confidential corpus contents unnecessarily
Context-boundary testAWS2-CTX, AWS2-VALEvidence or auditscenario, expected policy, result, finding, remediationsummarize exploit details when disclosure would increase risk
Validation reportAWS2-VAL, all familiesEvidence or auditscope, controls reviewed, method, findings, date, reviewerpublish findings and status before raw test data
Exception registerAWS2-GOV, AWS2-VALOrganization or governanceexception, owner, rationale, expiry, remediation planavoid unnecessary personnel and business-sensitive detail
Claim-limit recordAWS2-GOV, mapping evidenceOrganization or governancestatement, scope, control subset, evidence basis, prohibited claimskeep external-facing wording bounded and reviewable