{
  "alcoa": [
    {
      "evidence": "actor=agent:27-audit-trail",
      "label": "Attributable",
      "pillar": "attributable",
      "satisfied": true
    },
    {
      "evidence": "payload is structured JSON (object/array)",
      "label": "Legible",
      "pillar": "legible",
      "satisfied": true
    },
    {
      "evidence": "occurred_at recorded; no created_at to cross-check",
      "label": "Contemporaneous",
      "pillar": "contemporaneous",
      "satisfied": true
    },
    {
      "evidence": "payload_hash=0c8d55…61905",
      "label": "Original",
      "pillar": "original",
      "satisfied": true
    },
    {
      "evidence": "action=audit:reported subject=audit_trail_report:cron-2026-06-08T10:00:15.152Z",
      "label": "Accurate",
      "pillar": "accurate",
      "satisfied": true
    },
    {
      "evidence": "one of study_id / actor_id / subject_id is missing",
      "label": "Complete",
      "pillar": "complete",
      "satisfied": false
    },
    {
      "evidence": "occurred_at, created_at and id form a coherent record",
      "label": "Consistent",
      "pillar": "consistent",
      "satisfied": true
    },
    {
      "evidence": "stored in append-only cro.provenance_event (RLS deny-by-default)",
      "label": "Enduring",
      "pillar": "enduring",
      "satisfied": true
    },
    {
      "evidence": "dereferenceable at /provenance/fab08fa3-078c-43d1-b1d6-f7d9774a8004",
      "label": "Available",
      "pillar": "available",
      "satisfied": true
    }
  ],
  "event": {
    "action": "audit:reported",
    "actor_id": "27-audit-trail",
    "actor_kind": "agent",
    "id": "fab08fa3-078c-43d1-b1d6-f7d9774a8004",
    "model_id": "claude-sonnet-4-7-20260101",
    "model_provider": "anthropic",
    "model_version_id": "a1e38aeb-f356-412e-9b20-81ca4ab580a5",
    "occurred_at": "2026-06-08T10:00:27.753601+00:00",
    "payload": {
      "anomalies": [
        {
          "eventIds": [
            "ba05c45b-2425-4973-b5f9-13965725e786",
            "8030e262-7b86-4ef2-b2e1-266869679736",
            "3fd3566a-3101-4e51-b1fb-f24ac24c5f5d",
            "fa81622b-815a-4cbf-949e-ad8c1299c444"
          ],
          "kind": "high-rate-spike",
          "message": "Actor '12-rbqm-analytics' fired 4 out of 5 events in the window (80%), all 'compute-rankings', at approximately 15-minute cron intervals. While individually each is a scheduled cron invocation, the volume dominance relative to the only other actor ('27-audit-trail', 1 event) and the rapid cadence warrants QA review to confirm the scheduler has not misconfigured the interval or triggered duplicate jobs.",
          "severity": "medium"
        },
        {
          "eventIds": [
            "c6e17486-27c7-4bb4-b64e-9fed38b9e025",
            "ba05c45b-2425-4973-b5f9-13965725e786",
            "8030e262-7b86-4ef2-b2e1-266869679736",
            "3fd3566a-3101-4e51-b1fb-f24ac24c5f5d",
            "fa81622b-815a-4cbf-949e-ad8c1299c444"
          ],
          "kind": "other",
          "message": "All 5 events in the window carry null 'signature_id', including the 'audit:reported' event from '27-audit-trail'. While none are 'promote' actions (which would trigger a hard missing-signature violation), the absence of signatures across all event types — including audit trail reports — should be confirmed as intentional per platform policy for agent-originated cron and audit events.",
          "severity": "low"
        }
      ],
      "eventsExamined": 5,
      "modelVersion": "claude-sonnet-4-7-20260101",
      "payloadHash": "1cd62642acb774ee5cdbb28b75d7ffa61e8c4c5bf4945b83849068122dbd120c",
      "summary": "Window 2026-06-08T09:00:15Z – 10:00:15Z contains 5 events from 2 actors. Agent '12-rbqm-analytics' fired 4 consecutive 'compute-rankings' events (≈every 15 min) versus 1 event from the only other actor, constituting a relative rate spike. No 'promote' actions were observed, so no missing-signature violations on that action type. No A4 autonomy-class references detected. All compute-rankings events carry null signature_id, which is noted but consistent with automated cron invocations; QA lead should confirm whether cron-sourced agent actions are exempt from signature requirements per platform policy.",
      "windowEnd": "2026-06-08T10:00:15.152Z",
      "windowStart": "2026-06-08T09:00:15.191Z"
    },
    "payload_hash": "0c8d55d62558413712f0960b813c390851d9e6ce29da158ec58880b537561905",
    "retrieved_context": [],
    "reviewer_user_id": null,
    "row_hash": "0c8d55d62558413712f0960b813c390851d9e6ce29da158ec58880b537561905",
    "signature_id": null,
    "study_id": null,
    "subject_id": "cron-2026-06-08T10:00:15.152Z",
    "subject_kind": "audit_trail_report"
  },
  "exportedAt": "2026-09-12T08:07:50.496Z",
  "links": {},
  "schemaVersion": "1"
}