All Skills Library · Evidence
offboarding-evidence
Access-removed proof as a specimen, not a story.
- Version
- 1.0.0
- Lifecycle
- reference
- License
- Apache-2.0
- Published
- 2026-08-27
- Reviewed
- 2026-08-27
- Source
- witnessops/witnessops-web
content/witnessops/skills/offboarding-evidence/SKILL.md - Bytes
- 875
- SHA-256
539f28cbab67420aaf9a328d743e1345428c26da85cbc81262cb35fc21f21f4d
Plain view · SKILL.mdUTF-8 · exact download bytes
--- name: offboarding-evidence description: > Use when evaluating offboarding or access-removed evidence. Work from raw evidence and a deterministic checklist. Do not narrate access removal that the evidence does not show. --- # Offboarding evidence Access removed is a claim. The specimen has to carry it. ## Workflow 1. Collect the raw evidence (tickets, IdP events, key revocation records). 2. Evaluate against a declared checklist. 3. Hash the evidence set. 4. Write a human-readable report that cites those hashes. 5. Name every checklist item that did not fire. ## Guardrails - Do not claim access was removed because someone said it was. - Do not mix this customer with a labelled sample. - Do not skip the hash step. - If revocation of signing keys is unverified, say Incomplete. ## Outputs - checklist result - SHA-256 manifest - human-readable report