AI

AI Governance Engine

Assurance Summary

A–F Governance KB v1.1.0 · assessment-instrument-1.0.0 · Simulated package
Download HTML
NOTE! Simulation - Sample - Do not use

01 · Decision

FinOps Engine 2026

Blocked In Current Form

Formal Decision Pending

FinOps Engine 2026 demonstrates a materially governed analytical architecture: customer evidence is acquired and sanitized before any generative call, Knowledge Base material is forbidden as proof of current state, maturity and anti-pattern streams are assessed separately, scores are computed after independent evidence checking, tactics are permissioned from locked findings, and a deterministic Quality Gate publishes GO / WARN / BLOCK. The assessed deployment transition is nevertheless blocked because shared-secret identity is below the production control target, and accountable ownership, legal/risk classification, formal lifecycle authorization, privacy/provider governance, AI-specific adversarial assurance, human-impact assurance and residual-risk acceptance are not decision-eligible.

Accountable ownerUnknown — human decision required
Lifecycle transitionVerification & Validation → Deployment
Assessment date2026-09-03
Assessment modeSimulated Cognitive Review
Publication qualityLimited narrative · architecture-rich
Documentation alignmentIncomplete review required
Knowledge statusA–F baseline v1.1.0 + current Playbook mapping
Deterministic controls evaluated100%
Evidence coverage74%
Verified evidence61%
Control assurance27%
Assurance deficitHigh
Gate statusBlock
Leading decision drivers
  • Production identity/session boundary — shared SECRET_KEY is both login password and HMAC signing key; per-user authorization is not enforced
  • Lifecycle / classification / authority package — incomplete and partly unknown; README declares a prototype, not a production multi-user service
  • Privacy, provider contractual governance and AI-security assurance — insufficient for deployment

This is decision support. The Engine cannot issue legal, privacy, security, governance, AI Forum or AI Board approval, accept residual risk, or authorize lifecycle progression.

Interpret the metrics as assurance diagnostics, not a product-quality score. Static source in finops-engine-2026-main, architecture HTML and sample assessment reports can establish implementation and design intent, but not successful production testing or operational effectiveness. Missing evidence remains UNKNOWN and does not receive positive assurance weight. Sample FinOps customer reports are outputs of the assessed system, not evidence that the Engine itself is deployment-ready.

02 · Case identification

Case Profile and Assessment Scope

Identity and intent

Solution name
FinOps Maturity Assessment Engine (2026 main tree)Supported
Accountable owner
Not established in assessed materialsUnknown
Intended purpose
Evidence-gated FinOps maturity diagnosis across 30 capability and 30 anti-pattern criteria, with confidence-bounded roadmap permissioningSupported
Expected value / outcome
Traceable forensic assessment so humans can validate, decide and act; not an autonomous FinOps control plane and not a substitute for expert-approved accuracy certificationSupported

Assessment scope

Current lifecycle stage
Verification & Validation — README states solution development, structural validation and accuracy/reproducibility testingPartial
Target lifecycle stage
DeploymentSupported
Jurisdictions
Not establishedUnknown
Regulatory roles
Not established as provider / deployer / product-owner legal rolesUnknown
Users and affected groups
Internal FinOps / finance / engineering readers are evident; complete affected-person population not establishedPartial

Declared operating boundary

Effective environment
Railway long-lived Node is the governed-dispatch host; Vercel remains a parallel API-handler host. README: not a production-ready multi-user servicePartial
User scope
Anyone who knows the shared SECRET_KEY; no per-user authorizationPartial
Data scope
Customer-uploaded FinOps evidence stays browser-local until privacy-screened text packets; personal/confidential scope still requires classificationPartial
Integration scope
OpenAI, Anthropic and xAI via server-owned routing; PostgreSQL + Redis control plane; optional Vercel Blob remote KBPartial
Autonomy scope
Bounded staged analysis; Quality Gate and human readers retain publication and action authority; no autonomous cloud-spend execution was evidencedSupported

Risk-relevant declarations

Production access
Railway start path and a demo URL named “production” are present; exact approved production boundary, tenants and expiry are unknownPartial
Consequential decisions
Outputs can influence cloud-financial strategy; LOW confidence hides directive roadmaps; no direct spend-changing automation was evidencedPartial
Uses agents / bounded reasoners
Role-routed REASONER / WORKHORSE / QUALITY_CHECKER stages; not a free-form multi-agent marketplaceSupported
Human override / validation
Quality Gate is deterministic; formal deployment/residual-risk decisions remain outside the EngineSupported

Applicability and classification screening

Prohibited-practice candidate
Not determinedUnknown
High-risk candidate
Not determined from a system-specific legal dossierUnknown
Privacy applicability
Conditionally applicable — uploaded customer evidence and OCR text may contain personal or confidential contentPartial
Confidentiality applicability
Conditionally applicable — customer finance artifacts and provider packets are in scopePartial

03 · Documentation gate

Documentation Alignment

Overall statusIncomplete Review Required
Deployment-profile completeness20 / 32
Documentation-to-code alignmentPartial
Deployment readyNo
Source coverageAssessed Submitted Scope

Unknown fields

Accountable owner, jurisdictions, regulatory roles, formal AI-risk classification, boundary expiry, provider data/retention decision, residual-risk authority, complete affected-person scope, DPIA/lawful basis, output-ownership contract

Self-declared / bounded assumptions

README declares the repository is intended for solution development, structural validation and accuracy/reproducibility testing, and is not yet a production-ready multi-user service. Current stage is treated as Verification & Validation on that basis. Railway is treated as the intended governed runtime because server.js and railway.json say so.

Material documentation-to-code drift

README still says scanned/visual-only pages are not processed because local OCR is unavailable. src/services/pdfService.ts and ocrService.ts implement tesseract.js@7 local OCR for sparse/image-heavy PDF pages, with scripts/prepare-ocr-assets.mjs and visual-acquisition tests. Treat OCR as implemented; treat the README sentence as stale.

Aligned implementation facts

Shared-password HMAC auth in lib/auth.js matches README. ADRs 001–003 and the taxonomy registry are declared more authoritative than older visual decks. In-repo architecture.html and the attached 2026-09-03 Evidence-Gated Scanner Architecture HTML are visual 60-criteria catalogs, not the scoring contract. Quality Gate does not cap or rewrite maturity. FinOpsEngineArchitecture.html links a Railway host named production while README withholds production multi-user status.

04 · Deterministic decision boundary

Deterministic Lifecycle Transition Boundary

Verification & Validation → Deployment

Progression remains blocked until the hard gates below are cleared by attributable evidence and named authority.

Progression Blocked

Allowed in current form

Controlled development, structural validation and accuracy/reproducibility testing as stated in README.

Internal / bounded assessment runs with local parsing and privacy-screened packets.

Findings-mode or WARN-bounded strategy output when the Engine’s own Quality Gate requires it.

Not permitted on this package

Treating this simulation, or any FinOps customer report, as deployment approval.

Using Knowledge Base tactics or golden fixtures as proof of a customer’s current FinOps state.

Sending raw files, full tables, page rasters or unsanitized OCR across the governed LLM boundary.

Conditions before deployment

Replace shared-secret auth with attributable identity and tested authorization.

Named AI System Owner, classification dossier, operating-boundary register and expiry.

Privacy / provider / residual-risk decisions with tested controls, plus AI-adversarial evidence.

05 · Assurance language

Evidence Interpretation

Supported

Implementation evidence

A control, boundary or behavior is visible in the 2026-main source tree, ADRs, the 2026-09-03 Evidence-Gated Scanner Architecture catalog, acquisition pipeline or thinking-flow. Implementation is not operational effectiveness.

Partial

Design intent only

The mechanism is described and partly coded, but Q3 evidence of current effectiveness, coverage or production configuration is missing or contradictory.

Unknown

No assessable signal

The submitted scope does not contain enough material to support presence or scoped absence. Silence is not treated as compliance.

Not used

TESTED_ABSENT

No anti-pattern is marked tested-absent. That label requires a scoped, executed, successful, current and independently verified absence test.

06 · Deterministic controls

Hard-Gate Matrix

GateState and basisRationaleClearance requirementAuthority
Assessment intake is not fully documented and aligned for deploymentDOCUMENTATION_ALIGNMENT_REQUIRED Block Deterministic Rule System owner, jurisdiction/classification, complete operating boundary, privacy/provider decisions and formal lifecycle authority are not established. README itself withholds production multi-user status.
  • Document the complete deployment assessment intake
  • Confirm owner, jurisdictions, classification and boundary
  • Reconcile the “production” Railway demo URL with the prototype declaration
Solution Owner, Governance
Critical deployment identity/session control is below targetCRITICAL_DEPLOYMENT_CONTROLS Block Supported SECRET_KEY is both the shared login password and the HMAC signing key. Sessions are HttpOnly cookies with a default role of user. README states that per-user authorization is not yet enforced server-side. Anyone with the secret is equivalent.
  • Replace shared password-as-secret with attributable identity/session control
  • Enforce least privilege and auditable authorization decisions
  • Run representative negative authorization/session tests against the release candidate
Security, Governance
Privacy and confidential-data boundary requires human validationPRIVACY_REVIEW_REQUIRED Review Unknown Customer uploads, OCR and structured tables can contain personal or restricted finance content. Deterministic DLP/redaction exists; lawful basis, rights, retention, provider-training settings and DPIA were not supplied.
  • Classify data categories and purposes
  • Record privacy basis, rights and retention
  • Verify provider/transmission settings and leakage tests
Privacy
AI-specific adversarial assurance is not decision-eligibleAI_SECURITY_ASSURANCE Block Unknown Prompt, retrieval, packet and tool-attack evaluation against the complete system was not in the assessed materials. Quality Gate protects FinOps report grounding; it is not an adversarial security test of the Engine.
  • Produce a system-specific AI threat model
  • Execute representative adversarial cases on the release candidate
  • Retain regression evidence
Security
Deployment requires an attributable human decisionHUMAN_DEPLOYMENT_DECISION Human Review Required Deterministic Rule The Engine’s own design correctly refuses to authorize lifecycle progression. No residual-risk or AI Board decision record was supplied for this version.
  • Complete classification and risk treatment
  • Record residual-risk acceptance and expiry
  • Issue the formal deployment decision at the required authority level
Governance, AI Board

07 · Governance assurance model

A–F Domain Overview

A Purpose, value and classification

Incomplete Review Required

2 of 5 capability families have directly supported evidence · 3 remain partial or unknown. Purpose and prototype boundary are clear in README. Owner, legal classification and formal stage authorization are not decision-eligible. AP-A5 is a detected candidate because a Railway URL is labelled production while the repo declares a prototype.

B Data, privacy, confidentiality and IP

Partial

3 of 5 capability families have implementation evidence · privacy legal basis and IP/output rights are unknown. Local parsing, complete-source DLP, packet re-scan and evidence/KB separation are the strongest B-lane signals.

C Models, agents, providers and supply chain

Human Review Required

2 of 5 capability families have directly supported evidence. Role-based routing and fail-closed dispatch are implemented. Provider due diligence, training/retention terms and component requalification remain incomplete.

D Architecture, security, robustness and evaluation

Remediation Required

2 of 5 capability families have strong implementation evidence · D1 is a supported hard-gate failure · D3 adversarial assurance is unknown. Hash-bound packets, at-most-once send and Quality Gate remain material D2/D4 strengths.

E Human impact, fairness and oversight

Insufficient Evidence

1 of 5 capability families has directly supported evidence (human publication/action boundary). Affected-person map, fairness, recourse, accessibility and competence evidence are not sufficient for a production conclusion.

F Accountability, evidence and lifecycle

Human Review Required

2 of 5 capability families have strong evidence (F2 evidence discipline). Ownership, residual-risk contract, decision-authority matrix and unified monitoring/retirement triggers are incomplete.

07b · Instrument workspace

Capability / Anti-Pattern States

Each pair is judged on Q1 definition & intent, Q2 implementation & operation, Q3 evidence & effectiveness. Implementation evidence is taken from finops-engine-2026-main. Sample FinOps customer reports are treated as system outputs, not as proof that the Engine’s own governance objects are satisfied.

Pairs assessed30 / 30
Questions180
Detected AP candidatesAP-A5 · AP-C5 · AP-D1
TESTED_ABSENTNone
Hard-gate blockD1 identity
Mapped tactics12
A

Purpose, value and classification

A1 · Intended purpose and use boundaries
Supported AP-A1: Unknown
Capability A1

Intended purpose and use boundaries

Purpose is consistently stated as evidence-gated FinOps maturity diagnosis with confidence-bounded action permissioning. README bounds the current repo to development/validation, not production multi-user service. Affected-person and prohibited-use registers are thinner than the purpose statement.

Q1 Definition

Supported — purpose is specific and testable in README, ADRs and thinking-flow.

Q2 Implementation

Partial — product behavior matches the FinOps-assessment purpose; commercial/demo paths are not formally bounded.

Q3 Effectiveness

Unknown — no current-use comparison against a signed operating boundary.

Anti-pattern AP-A1

Undefined or elastic intended purpose

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

A2 · AI suitability, proportionality and value hypothesis
Partial AP-A2: Unknown
Capability A2

AI suitability, proportionality and value hypothesis

Thinking-flow and architecture argue why a single prompt is insufficient and count discrete governed stages. A documented non-AI baseline, stop criteria and measured value vs cost of the Engine itself were not in the pack.

Q1 Definition

Partial — problem and outcome are defined independently of a model brand.

Q2 Implementation

Partial — alternatives are argued architecturally, not as a dated options appraisal.

Q3 Effectiveness

Unknown — no representative value trial of the Engine itself.

Anti-pattern AP-A2

AI-first solutionism or value theatre

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

A3 · Value-chain roles and responsibility boundaries
Insufficient evidence AP-A3: Unknown
Capability A3

Value-chain roles and responsibility boundaries

Provider brands and Railway/Vercel split are named. Final AI System Owner, deployer vs provider duties and component RACI are not.

Q1 Definition

Unknown — roles are not explicitly determined as a complete value chain.

Q2 Implementation

Partial — operating procedures exist for dispatch; ownership assignments do not.

Q3 Effectiveness

Unknown — no evidence that each party discharges assigned duties.

Anti-pattern AP-A3

Role ambiguity and responsibility displacement

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

A4 · Risk, legal and regulatory classification
Unknown AP-A4: Unknown
Capability A4

Risk, legal and regulatory classification

No system-specific applicability dossier, prohibited-practice screen or adjacent-regime analysis was supplied.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-A4

Superficial or static classification

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

A5 · Lifecycle stage and transition boundary
Partial AP-A5: Detected candidate
Capability A5

Lifecycle stage and transition boundary

README: not yet a production-ready multi-user service. railway.json and server.js implement a deployable Railway path. FinOpsEngineArchitecture.html links a demo at finops-engine-2026-production.up.railway.app. That naming is an AP-A5 candidate, not a proven unauthorized production incident.

Q1 Definition

Partial — current/target stages can be inferred, not signed.

Q2 Implementation

Partial — prototype vs Railway host is technically described.

Q3 Effectiveness

Unknown — no attributable transition approval.

Anti-pattern AP-A5

Prototype-to-production drift

Detected candidate. README withholds production multi-user status while FinOpsEngineArchitecture.html names a Railway host “production”. That is documentation/boundary drift, not a proven unauthorized production incident. Not TESTED_ABSENT.

B

Data, privacy, confidentiality and IP

B1 · Data inventory, provenance and lineage
Supported AP-B1: Unknown
Capability B1

Data inventory, provenance and lineage

ADR-001 defines source artifact, Evidence Lane packet, knowledge release, stage execution and model attempt as distinct entities. SHA-256 packet binding and Postgres BYTEA bodies are specified. A complete organizational data inventory covering logs, backups and provider-side copies was not supplied.

Q1 Definition

Supported for assessment-lane objects.

Q2 Implementation

Supported in acquisition and packet assembly.

Q3 Effectiveness

Partial — sample reports show output-to-chunk trace; platform-wide lineage does not.

Anti-pattern AP-B1

Invisible or untraceable data flows

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

B2 · Purpose limitation and data minimization
Partial AP-B2: Unknown
Capability B2

Purpose limitation and data minimization

Browser-local originals, text-only governed packets, 2 MB JSON limit and DLP redaction implement minimization for model egress. Field-level necessity and deletion-propagation across Postgres BYTEA / Redis / provider logs are not fully evidenced.

Q1 Definition

Partial

Q2 Implementation

Supported for model-visible packets

Q3 Effectiveness

Unknown for deletion propagation

Anti-pattern AP-B2

Convenience-driven data accumulation

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

B3 · Privacy and data-subject governance
Unknown AP-B3: Unknown
Capability B3

Privacy and data-subject governance

Deterministic privacy scanning exists, including Finnish-aware person-name redaction. Lawful basis, DPIA, rights fulfilment and personal-data classification of customer uploads were not supplied.

Q1 Definition

Unknown

Q2 Implementation

Partial — technical privacy controls exist

Q3 Effectiveness

Unknown

Anti-pattern AP-B3

Privacy-by-documentation only

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

B4 · Confidentiality and information-boundary control
Partial AP-B4: Unknown
Capability B4

Confidentiality and information-boundary control

Packet assembly plus exact outgoing-payload re-scan is the declared raw-evidence barrier. Leakage, cross-tenant and provider-retention tests were not supplied. HttpOnly cookies are better than a JS-readable token; the shared secret still concentrates compromise.

Q1 Definition

Supported as a declared boundary.

Q2 Implementation

Supported in packet path.

Q3 Effectiveness

Unknown for leakage tests.

Anti-pattern AP-B4

Confidentiality leakage through AI channels

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

B5 · Intellectual property, licensing and content rights
Unknown AP-B5: Unknown
Capability B5

Intellectual property, licensing and content rights

Embedded KB JSON and optional remote KB PDFs exist. Licence, training-rights and output-ownership positions for customer reports and model outputs were not supplied.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-B5

Unclear content-rights basis

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

C

Models, agents, providers and supply chain

C1 · Model, agent and tool inventory
Supported AP-C1: Unknown
Capability C1

Model, agent and tool inventory

lib/modelRoutingPolicy.js centralizes REASONER / WORKHORSE / QUALITY_CHECKER with named provider fallbacks. Partial policies fail closed. A living production inventory with versions, owners and change rights was not supplied.

Q1 Definition

Supported in code.

Q2 Implementation

Supported for routed stages.

Q3 Effectiveness

Unknown for current production inventory.

Anti-pattern AP-C1

Shadow models and unowned tools

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

C2 · Evaluation, limitations and intended performance
Partial AP-C2: Unknown
Capability C2

Evaluation, limitations and intended performance

The Engine evaluates customer FinOps evidence. Evaluation of the Engine as an AI system — accuracy, reproducibility, drift — is explicitly deferred to separate expert-approved work. Scenario fixtures are labelled engineering regression only.

Q1 Definition

Partial

Q2 Implementation

Partial

Q3 Effectiveness

Unknown for system-level model eval

Anti-pattern AP-C2

Unevaluated capability claims

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

C3 · Agent and tool-use control
Supported AP-C3: Unknown
Capability C3

Agent and tool-use control

Stages are bounded, schema-checked and fail-closed. evidence_gap_analysis may propose search terms only; it cannot score or change gates. No evidence of free tool-calling agents changing customer cloud estates.

Q1 Definition

Supported

Q2 Implementation

Supported

Q3 Effectiveness

Partial — no production telemetry of attempted boundary violations.

Anti-pattern AP-C3

Unbounded agent autonomy

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

C4 · Provider due diligence and contractual governance
Unknown AP-C4: Unknown
Capability C4

Provider due diligence and contractual governance

OpenAI / Anthropic / xAI are integrated. Due-diligence dossiers, subprocessors, training-use terms, audit rights and exit requirements were not in the pack.

Q1 Definition

Unknown

Q2 Implementation

Partial — technical integration exists

Q3 Effectiveness

Unknown

Anti-pattern AP-C4

Vendor assurance treated as deployer assurance

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

C5 · Supply-chain, update and requalification baseline
Partial AP-C5: Detected candidate
Capability C5

Supply-chain, update and requalification baseline

npm lockfile and named parsers exist. Model and some dependency ranges remain open-ended. Requalification after model change is described as a needed drift procedure, not as an executed baseline.

Q1 Definition

Partial

Q2 Implementation

Partial

Q3 Effectiveness

Unknown

Anti-pattern AP-C5

Untracked component drift

Detected candidate. Named parsers and a lockfile exist, but model identifiers and some dependency ranges remain open-ended, and requalification after model change is described rather than executed. Not TESTED_ABSENT.

D

Architecture, security, robustness and evaluation

D1 · Identity, access and environment separation
Not satisfied AP-D1: Detected candidate
Capability D1

Identity, access and environment separation

lib/auth.js: SECRET_KEY is login password and HMAC key. api/login.js issues an HttpOnly cookie after a shared-password check. issueCookie defaults role to user. README: per-user authorization is not yet enforced. This is a supported identity-control gap, not an inferred one.

Q1 Definition

Not satisfied for production identity.

Q2 Implementation

Implemented as shared secret.

Q3 Effectiveness

Unknown for operational abuse; design is insufficient.

Anti-pattern AP-D1

Shared or unauditable access

Detected candidate. SECRET_KEY is both login password and HMAC signing key; per-user authorization is not enforced. Anyone who knows the secret is equivalent. This is a supported identity-control gap, not TESTED_ABSENT.

D2 · Secure architecture and robustness controls
Supported AP-D2: Unknown
Capability D2

Secure architecture and robustness controls

PostgreSQL canonical BYTEA packets, Redis send-authorization fence, at-most-once after SEND_AUTHORIZED, outcome_unknown on crash, and fail-closed model-routing startup are implemented in code and ADR-001.

Q1 Definition

Supported

Q2 Implementation

Supported

Q3 Effectiveness

Partial — no independent security test report.

Anti-pattern AP-D2

Prompt-or-convention security

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

D3 · AI-specific threat model and adversarial assurance
Unknown AP-D3: Unknown
Capability D3

AI-specific threat model and adversarial assurance

No system-specific AI threat model, attack corpus or adversarial execution evidence was supplied.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-D3

Ungoverned prompt/retrieval/tool attack surface

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

D4 · Evaluation, grounding and fail-closed quality control
Supported AP-D4: Unknown
Capability D4

Evaluation, grounding and fail-closed quality control

Evidence-check, targeted rescan, deterministic scoring, required-tactic dispositions, split fact-check, sanitation and Quality Gate GO/WARN/BLOCK are implemented. Unresolved required tactics keep Quality Gate at BLOCK.

Q1 Definition

Supported

Q2 Implementation

Supported

Q3 Effectiveness

Partial — sample runs show the gate working; they are not a certified accuracy study.

Anti-pattern AP-D4

Fluent output treated as proof

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

D5 · Monitoring, incident and change detection
Partial AP-D5: Unknown
Capability D5

Monitoring, incident and change detection

/livez and dependency-aware /readyz exist. Unified monitoring of quality, privacy, provider drift, fairness and material change is not established as a governance trigger catalog.

Q1 Definition

Partial

Q2 Implementation

Partial

Q3 Effectiveness

Unknown

Anti-pattern AP-D5

Silent degradation

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

E

Human impact, fairness and oversight

E1 · Affected persons, rights and impact pathways
Unknown AP-E1: Unknown
Capability E1

Affected persons, rights and impact pathways

Users are described as FinOps Lead / CFO / Engineering readers. Indirectly affected people in customer source files are not mapped.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-E1

Unidentified affected population

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

E2 · Fairness, subgroup and contextual evaluation
Unknown AP-E2: Unknown
Capability E2

Fairness, subgroup and contextual evaluation

Persona views change narrative lens, not fairness evaluation of the Engine’s judgments across customer populations.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-E2

Fairness assumed from intent

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

E3 · Human oversight and intervention
Supported AP-E3: Unknown
Capability E3

Human oversight and intervention

Quality Gate cannot be overridden by the explanatory model. LOW confidence forces findings mode. Formal approval remains human. Competence, staffing and oversight SLAs for production operators were not supplied.

Q1 Definition

Supported

Q2 Implementation

Supported

Q3 Effectiveness

Unknown for operational oversight effectiveness

Anti-pattern AP-E3

Human-in-the-loop theatre

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

E4 · Transparency and contestability of outputs
Partial AP-E4: Unknown
Capability E4

Transparency and contestability of outputs

Reports expose evidence quotes, traces, Quality Gate reasons and hygiene appendices. A practical recourse path for a mis-assessed organization is not specified.

Q1 Definition

Partial

Q2 Implementation

Partial

Q3 Effectiveness

Unknown

Anti-pattern AP-E4

Uncontestable machine narrative

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

E5 · Accessibility, competence and use conditions
Unknown AP-E5: Unknown
Capability E5

Accessibility, competence and use conditions

No accessibility, training or competence evidence was supplied.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-E5

Unsafe use by unprepared operators

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

F

Accountability, evidence and lifecycle

F1 · Accountable ownership and decision rights
Unknown AP-F1: Unknown
Capability F1

Accountable ownership and decision rights

No named AI System Owner or executable decision-right matrix was supplied.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-F1

Orphaned AI system

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

F2 · Evidence, traceability and auditability
Supported AP-F2: Unknown
Capability F2

Evidence, traceability and auditability

ADR-001 lineage vocabulary, packet hashes, stage executions, model attempts, evidence-check adjustments and Quality Gate reasons are first-class. Sample reports carry that trail.

Q1 Definition

Supported

Q2 Implementation

Supported

Q3 Effectiveness

Partial — live production audit retrieval was not exercised in this simulation.

Anti-pattern AP-F2

Untraceable conclusions

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

F3 · Risk treatment and residual risk
Unknown AP-F3: Unknown
Capability F3

Risk treatment and residual risk

No system-specific risk/tolerance/treatment contract or residual-risk decision was supplied.

Q1 Definition

Unknown

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-F3

Risk accepted by silence

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

F4 · Decision authority, delegation and expiry
Partial AP-F4: Unknown
Capability F4

Decision authority, delegation and expiry

Architecture correctly separates recommendation from approval. The authority matrix, quorum, SLA and expiry for this version do not exist in the pack.

Q1 Definition

Partial

Q2 Implementation

Unknown

Q3 Effectiveness

Unknown

Anti-pattern AP-F4

Recommendation treated as approval

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

F5 · Monitoring, incident, change and retirement triggers
Partial AP-F5: Detected candidate
Capability F5

Monitoring, incident, change and retirement triggers

Run cleanup workers exist. Unified retirement, material-change and reassessment triggers for the Engine itself are incomplete. Prototype declaration plus a Railway URL named production is a watch item, not proven forever-on unauthorized production.

Q1 Definition

Partial

Q2 Implementation

Partial

Q3 Effectiveness

Unknown

Anti-pattern AP-F5

Operate-forever prototype

Not marked TESTED_ABSENT. A scoped, executed absence test was not supplied.

08 · Independently verified support

Confirmed Strengths

Customer originals remain browser-local. Deterministic ingress, type gates and complete-source privacy scanning run before any generative call. Secrets block; supported PII is redacted, including Finnish-aware person-name patterns.

Trace: src/services/deterministicPrivacyService.ts · scripts/test-privacy-service.mjs · acquisition pipeline HTML

Knowledge Base material is explicitly forbidden as proof of the assessed organization’s current state. forbidden_uses include customer_current_state_claim and source_evidence_quote.

Trace: src/knowledge_base/README.md · ADR-001 invariant 1

Governed packets are schema-validated and hash-bound. PostgreSQL stores canonical BYTEA bodies; Redis holds coordination only. Send is at-most-once after SEND_AUTHORIZED; post-send uncertainty is outcome_unknown, not silent retry.

Trace: docs/architecture/ADR-001-execution-and-evidence-lineage.md · server.js · railway.json

Phase 1 forensic judgments are independently evidence-checked before Phase 2 math. Silence is Data. Required roadmap tactics use accepted / contraindicated / citation_rejected / missing dispositions; unresolved required tactics keep Quality Gate at BLOCK.

Trace: ADR-003 · src/services/qualityGateService.ts · thinking-flow

Quality Gate is deterministic GO / WARN / BLOCK with evidence-density floor 30%. An explanatory model may annotate the decision and cannot change it. LOW confidence collapses the roadmap to findings mode.

Trace: src/services/qualityGateService.ts · sample Summary and Master Data reports

evidence_gap_analysis may propose bounded search terms from low-evidence summaries. It cannot search, select evidence, score, classify or change gates. Deterministic local matching stays inside the privacy-approved Source Registry.

Trace: ADR-001 invariants 8–11 · src/services/gapAnalyzerService.ts · README Gap Analyzer clause

Resolution-based maturity (ADR-002) keeps unknown criteria as NA rather than averaging them as zero. Authoritative derived_analytical_evidence_v1 may support findings only when cited with ID and exact summary line; crucial-item coverage cannot score.

Trace: docs/architecture/ADR-002-resolution-based-maturity-model.md · src/services/maturityModelService.ts · src/services/derivedEvidence/

Local OCR is implemented for sparse or image-heavy PDF pages (tesseract.js@7, eng+fin). Graph structure and non-text visual semantics remain withheld. README’s “OCR unavailable” sentence is not the live code path.

Trace: src/services/pdfService.ts · src/services/ocrService.ts · scripts/test-visual-acquisition.mjs

Model routing is server-owned across OpenAI, Anthropic and xAI with explicit REASONER / WORKHORSE / QUALITY_CHECKER roles. Partial policies fail closed at process start.

Trace: lib/modelRoutingPolicy.js · server.js startup · README role table

Session cookie is HttpOnly, Secure and SameSite=Lax. The password is posted to /api/login and is not retained in browser sessionStorage as a Bearer token in this tree.

Trace: lib/auth.js issueCookie · src/services/authService.ts · api/login.js

09 · Confidence and progression conditions

Blocking Gaps and Unknowns

D1 · Production identity and session boundary
Shared SECRET_KEY is both password and HMAC key. Per-user authorization is not enforced. Attributable identity and least privilege are not established.

A3 / F1 · Accountable ownership
Assessed materials do not identify the final accountable AI System Owner or executable governance decision rights.

A4 · Classification and applicability
Jurisdiction, regulatory roles, prohibited-practice screen, risk class and adjacent legal regimes are not established in a system-specific dossier.

A5 / F4 · Lifecycle and authorization
README withholds production multi-user status. Exact current/target stage, permitted operating boundary, acceptance criteria, decision authority and expiry are not formally evidenced. A Railway URL is labelled production.

B3 / B4 / B5 · Privacy, confidentiality and content rights
Technical DLP exists. Lawful basis, rights, retention, provider processing settings, leakage tests and output-ownership remain incomplete.

C4 / C5 · Provider and supply-chain governance
Provider due-diligence/contractual data controls and a governed component/update/requalification baseline are incomplete.

D3 · AI-specific adversarial assurance
No system-specific AI threat model, representative adversarial execution or regression suite was supplied.

E1 / E2 / E5 · Human impact, fairness and competence
Affected-person pathways, fairness evaluation, practical recourse, accessibility and operator competence evidence are not established.

F3 / F5 · Residual risk and retirement
No system-specific risk/tolerance/treatment contract, attributable residual-risk decision or unified monitoring/retirement trigger catalog was supplied.

10 · Approved response patterns

Governance Action Playbook

Approved Actions Available

12 current Playbook action patterns are mapped to the material findings and unknowns in this simulation. Completion creates evidence for reassessment; it does not directly close findings or clear gates.

TAC-ARCHITECTURE-D1-02 · Enforce Identity, Network, Secret, Tenant and Environment Separation

Activation reason: D1 shared SECRET_KEY password/HMAC and missing per-user authorization

Replace the single-secret login with attributable identity. Separate authentication secret from session-signing material. Enforce least privilege so protected boundaries do not depend on knowing one password.

  • Apply the tactic mechanism to the specific assessed finding: D1 shared SECRET_KEY password/HMAC and missing per-user authorization.
  • Create and version the principal outputs: IAM policy; identity provider integration; secret separation; role/authorization matrix; negative authorization tests.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Security Architect; Identity & Access Owner; Service Owner · State: Recommended / requires accountable execution and reassessment

TAC-PURPOSE-A3-01 · Establish the AI Value-Chain Role and Accountability Model

Activation reason: A3/F1 accountable ownership and decision-right gap

Identify material actors, separate legal/regulatory roles from operating accountability, and assign final accountable authority for material duties.

  • Apply the tactic mechanism to the specific assessed finding: A3/F1 accountable ownership and decision-right gap.
  • Create and version the principal outputs: Actor & role inventory; accountability matrix; decision-right map; unresolved-role register.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: AI System Owner; Governance Owner; Business Owner · State: Recommended / requires accountable execution and reassessment

TAC-PURPOSE-A4-01 · Establish a System-Specific Applicability and Classification Dossier

Activation reason: A4 legal/risk classification remains unknown

Determine jurisdiction, actor role, prohibited-practice screening, AI risk classification and adjacent regimes from actual system/use facts while preserving uncertainty.

  • Apply the tactic mechanism to the specific assessed finding: A4 legal/risk classification remains unknown.
  • Create and version the principal outputs: Applicability/classification dossier; role/jurisdiction matrix; prohibited-practice screen; uncertainty register.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Legal; Governance; AI System Owner · State: Recommended / requires accountable execution and reassessment

TAC-PURPOSE-A5-01 · Establish Version-Specific Lifecycle Stage and Operating Boundary

Activation reason: A5 exact lifecycle and operating boundary is not formally established

Define the exact system version, canonical lifecycle stage and operating boundary. Reconcile the prototype declaration with the Railway host named production.

  • Apply the tactic mechanism to the specific assessed finding: A5 exact lifecycle and operating boundary is not formally established.
  • Create and version the principal outputs: Lifecycle stage & boundary register; permission matrix; transition authority record; expiry/exception register.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: AI System Owner; Governance; Security · State: Recommended / requires accountable execution and reassessment

TAC-DATA-B3-01 · Operationalize Privacy Basis, Rights and Impact Assessment

Activation reason: B3 privacy legal and rights pathway is unknown

Classify personal-data categories in uploads, OCR and logs; record basis, rights, retention and DPIA triggers.

  • Apply the tactic mechanism to the specific assessed finding: B3 privacy legal and rights pathway is unknown.
  • Create and version the principal outputs: Data-category register; lawful-basis record; rights procedure; DPIA/threshold analysis.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Privacy; AI System Owner · State: Recommended / requires accountable execution and reassessment

TAC-DATA-B4-02 · Enforce Secrets, Tenant, Provider and Output Confidentiality Boundaries

Activation reason: B4 provider/secret/confidentiality boundary requires production-grade evidence

Apply least privilege, provider routing evidence, secret exclusion, protected logs/caches and controlled outbound content, then test leakage.

  • Apply the tactic mechanism to the specific assessed finding: B4 provider/secret/confidentiality boundary requires production-grade evidence.
  • Create and version the principal outputs: Tenant/identity policy; secret-separation design; routing controls; confidentiality filters; leakage-test evidence.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Security; Privacy; Platform Owner · State: Recommended / requires accountable execution and reassessment

TAC-MODELS-C4-01 · Establish Provider Due-Diligence and Contractual Governance Baseline

Activation reason: C4 provider contractual and data-governance evidence is incomplete

Assess provider data practices, subprocessors, security evidence, limitations, change rights, audit/information rights, incidents, continuity and exit needs.

  • Apply the tactic mechanism to the specific assessed finding: C4 provider contractual and data-governance evidence is incomplete.
  • Create and version the principal outputs: Provider due-diligence dossier; contract requirement matrix; subprocessor/data record; limitation register; exit requirements.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Vendor Owner; Legal; Privacy; Security · State: Recommended / requires accountable execution and reassessment

TAC-ARCHITECTURE-D3-01 · Establish AI-Specific Threat Model and Attack-Surface Baseline

Activation reason: D3 system-specific AI threat model is not evidenced

Model generative, retrieval and packet attack paths, protected assets, attacker goals, controls, exclusions and adversarial test obligations.

  • Apply the tactic mechanism to the specific assessed finding: D3 system-specific AI threat model is not evidenced.
  • Create and version the principal outputs: AI threat model; attack-surface inventory; abuse cases; attack-to-control mapping; test requirements.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Security Architect; AI/ML Lead; Risk Owner · State: Recommended / requires accountable execution and reassessment

TAC-ARCHITECTURE-D3-04 · Execute AI-Specific Adversarial Evaluation and Regression Assurance

Activation reason: D3 representative adversarial execution and regression evidence is missing

Derive realistic attack cases from the threat model, execute against the complete system and convert material failures into versioned regression evidence.

  • Apply the tactic mechanism to the specific assessed finding: D3 representative adversarial execution and regression evidence is missing.
  • Create and version the principal outputs: Adversarial evaluation plan; attack corpus; execution evidence; finding/remediation register; regression suite.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Security Testing Lead; AI Evaluation Lead; AI System Owner · State: Recommended / requires accountable execution and reassessment

TAC-HUMAN-E1-01 · Establish Affected-Person, Rights and Impact-Pathway Baseline

Activation reason: E1 affected-person and rights impact baseline is not established

Identify direct and indirect affected people/groups in both operator and customer-source populations.

  • Apply the tactic mechanism to the specific assessed finding: E1 affected-person and rights impact baseline is not established.
  • Create and version the principal outputs: Affected-person map; rights/interests register; impact-pathway model; vulnerability analysis; reassessment triggers.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: AI System Owner; Governance; Human-Impact Owner · State: Recommended / requires accountable execution and reassessment

TAC-ACCOUNTABILITY-F3-01 · Establish System-Specific Risk, Tolerance and Treatment Contract

Activation reason: F3 system risk/tolerance/treatment and residual-risk basis are incomplete

Define system-specific risks, inherent/current/residual risk, treatment objectives, organizational tolerance, evidence requirements and acceptance authority.

  • Apply the tactic mechanism to the specific assessed finding: F3 system risk/tolerance/treatment and residual-risk basis are incomplete.
  • Create and version the principal outputs: AI risk register; risk method/tolerance matrix; treatment objectives; residual-risk definition; authority matrix.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Risk Owner; AI System Owner; Governance · State: Recommended / requires accountable execution and reassessment

TAC-ACCOUNTABILITY-F4-01 · Establish Decision Authority, Delegation, Quorum, SLA and Expiry Contract

Activation reason: F4 formal decision authority and expiry contract is incomplete

Define human authority for lifecycle, exception, residual-risk and escalation decisions, with explicit separation from AI recommendation.

  • Apply the tactic mechanism to the specific assessed finding: F4 formal decision authority and expiry contract is incomplete.
  • Create and version the principal outputs: Decision authority matrix; delegation/quorum rules; SLA/escalation matrix; expiry rules; AI-recommendation separation.
  • Verify the new artifacts against the current release candidate and reassess the mapped governance objects before any lifecycle decision.
Owners: Governance; AI System Owner; Decision Authority · State: Recommended / requires accountable execution and reassessment

11 · Formal decision rights

Human Authority

The Engine recommends readiness and required actions. Authorized humans make formal decisions.

Solution Owner

Pending Human Decision

Confirm the accountable owner, exact intended purpose, current/target lifecycle stage and operating boundary. Reconcile the prototype declaration with any Railway host named production.

Security

Pending Human Decision

Replace shared-secret authentication, approve the production identity/session architecture, and verify D1/D3 remediation, negative authorization tests and adversarial evidence.

Privacy

Pending Human Decision

Determine personal/confidential data scope in uploads and packets, processing basis, rights, provider/retention controls and required privacy impact review.

Legal

Pending Human Decision

Determine jurisdictions, provider/deployer roles, prohibited-practice screen, AI risk classification and adjacent legal applicability.

Governance

Pending Human Decision

Approve governance ownership, risk treatment, exceptions, reassessment triggers and the exact lifecycle decision package.

Ai Forum / Ai Board

Pending Human Decision

Issue the formal deployment decision at the authority level determined by the completed classification; record scope, conditions, validity and expiry.

12 · Audit reference

Audit Identity

Package hashSIMULATION — no Engine runtime hash
Engine versionsimulated-assurance-summary against governance-engine-0.3.0 contract
Rulesetreadiness-rules-2.1.0 · applied interpretively
Knowledge baselineAI Governance Categories & Anti-Patterns v1.1.0
Instrumentassessment-instrument-1.0.0 · 30 / 30 pairs · 180 questions
Tactic PlaybookMapped patterns from current Playbook · 2026-08-20
Assessment modeSIMULATED_COGNITIVE_REVIEW
Package schemaassurance-summary-1.5.0 look-alike · not a signed 2.6.0 package
Subject treefinops-engine-2026-main.zip
Declared product versionfinops-assessment-engine 1.0.0
Architecture witnessesREADME · ADR-001/002/003 · architecture.html · 2026-09-03 Evidence-Gated Scanner Architecture HTML · FinOpsEngineArchitecture.html · acquisition pipeline · thinking-flow · sample reports
Evidence source setfinops-engine-2026-main.zip + attached architecture/pipeline/thinking-flow HTML + 2026-09-03 60-criteria catalog + two sample Engine reports + A–F instrument

The source/code materials remain the evidence basis. This HTML exposes stakeholder-readable trace anchors and governance conclusions rather than raw source content, credentials or customer evidence. Because this is a simulation, do not treat the missing package hash as an integrity proof. A later sibling tree (2026-09-02 deployed zip) was not used as implementation evidence for this package.

13 · Scope and interpretation

Limitations

No formal Intake dossier naming the accountable owner, jurisdictions, complete regulatory roles, exact approved current/target lifecycle decision and boundary expiry was supplied.

Static source code and architecture HTML can establish implementation evidence but not production effectiveness. Test scripts were treated as test-design artifacts unless successful execution evidence was supplied; this simulation did not re-run the FinOps test suite.

No current production telemetry, end-to-end adversarial execution report, provider due-diligence/contract package, privacy impact/rights record, operational incident exercise, residual-risk decision or formal lifecycle approval was supplied.

No anti-pattern is presented as TESTED_ABSENT. Absence requires a scoped, executed, successful, current and independently verified absence test.

Sample FinOps customer reports demonstrate the Engine’s output contract. They are not evidence that FinOps Engine, as an AI system, has cleared A–F deployment gates.

This report does not establish legal compliance, accept residual risk, certify the solution or authorize deployment. It is not a live AI Governance Engine package.