Evidence and assurance

Document-supported is not the same as system-verified

How to describe evidence honestly, separate written policy from observed operation, and give reviewers a clearer basis for trust.

Philip Meagher2 min read
Layered assurance levels separating self-declared, document-supported, system-verified, and independently audited claims.

A document proves what the document says

A policy can show that an organisation has defined an access-review process. It does not, by itself, show that every required review occurred or that access was removed when it should have been. Calling both things verified hides an important distinction.

Document-supported evidence means an approved source contains a specific passage supporting the claim. The citation should identify the source version and exact location so another reviewer can inspect it.

System verification records an observation

A read-only connection can observe a relevant configuration or operational state, such as whether branch protection is enabled at a particular time. That observation may strengthen the claim, but it still has a scope and timestamp. A successful point-in-time check should not be described as continuous proof unless continuous monitoring actually exists.

  • What system and resource were checked.
  • Which fields or settings were observed.
  • When the observation occurred.
  • How the result was evaluated.
  • Whether the connector later failed or detected drift.

Use explicit assurance levels

A clear evidence model can distinguish self-declared, document-supported, human-verified, system-verified, and independently audited claims. These levels are not a single quality score. They describe different methods and should retain their own scope, timing, and limitations.

Confidence is separate again. Software may be highly confident that a paragraph is relevant while the paragraph offers weak assurance that the stated process operates in practice.

What happens when verification fails

A connector error should produce an unknown result, not a pass. An expired document should reduce the effective assurance available for new answers. Conflicting active claims should block automatic reuse until a person resolves the contradiction.

These rules may slow a small number of answers, but they prevent speed from creating unsupported promises. The aim is a defensible answer, not merely a completed field.

More in Evidence and assurance

Written by Philip Meagher. Reviewed under the TrustPass editorial policy.