All Skills Library · Evidence

offboarding-evidence

Access-removed proof as a specimen, not a story.

Version
1.0.0
Lifecycle
reference
License
Apache-2.0
Published
2026-08-27
Reviewed
2026-08-27
Source
witnessops/witnessops-web
content/witnessops/skills/offboarding-evidence/SKILL.md
Bytes
875
SHA-256
539f28cbab67420aaf9a328d743e1345428c26da85cbc81262cb35fc21f21f4d
Plain view · SKILL.mdUTF-8 · exact download bytes
---
name: offboarding-evidence
description: >
  Use when evaluating offboarding or access-removed evidence. Work from raw
  evidence and a deterministic checklist. Do not narrate access removal that
  the evidence does not show.
---

# Offboarding evidence

Access removed is a claim. The specimen has to carry it.

## Workflow

1. Collect the raw evidence (tickets, IdP events, key revocation records).
2. Evaluate against a declared checklist.
3. Hash the evidence set.
4. Write a human-readable report that cites those hashes.
5. Name every checklist item that did not fire.

## Guardrails

- Do not claim access was removed because someone said it was.
- Do not mix this customer with a labelled sample.
- Do not skip the hash step.
- If revocation of signing keys is unverified, say Incomplete.

## Outputs

- checklist result
- SHA-256 manifest
- human-readable report
Offboarding evidence — WitnessOps Skills