- Control ID
- Control ID: Assign one stable identifier that remains unchanged across review, correction, escalation, and closure records. Cite M06-I05 (F12); if insufficient, mark “Not supplied” and name the missing record identity. Do not encode an approval, result, owner identity, or live-system value inside the identifier. Review: the client process owner and any required specialist.
- Role, system, or data class
- For Role, system, or data class, define minimum authorized access, purpose, approved method, storage/retention rule, review trigger, and incident route. Cite M06-I02 (F02), M06-I03 (F06); if insufficient, mark “Not supplied” and name the missing access control. Never use personal credentials, transmit sensitive data through an unapproved channel, or claim access was granted/revoked. Keep pending for the authorized security or privacy owner.
- Supported evidence
- Transcribe the smallest decision-relevant fact supported by the cited module input and preserve its supplied confidence or uncertainty for Supported evidence. Evidence: M06-I01 (F01), M06-I02 (F02), M06-I03 (F06); mark “Not supplied” when absent. Do not convert a report, allegation, estimate, or provisional statement into a verified fact. Escalate to the client process owner and any required specialist.
- Source input ID
- Source input ID: List the exact module input ID beside every material statement, adding its fact ID when present. Cite M06-I01 (F01), M06-I02 (F02), M06-I03 (F06); if insufficient, mark “Not supplied” and name the missing citation trace. Do not cite the case brief as approval or cite an input that does not support the statement. Review: the client process owner and any required specialist.
- Permitted access or purpose
- For Permitted access or purpose, state the precise action, inference, proxy, data use, or claim that is allowed or prohibited and pair any refusal with a safe authorized alternative. Cite M06-I02 (F02), M06-I03 (F06); if insufficient, mark “Not supplied” and name the missing safety boundary. Never write a vague warning that leaves the learner unable to decide what to stop or what is safe. Keep pending for the authorized security or privacy owner.
- Prohibited method
- State that photographed-card handling through chat at M06-I03 (F06) and personal-password login at M06-I04 (F07) are not acceptable access methods; pair each refusal with a request for an approved payment workflow or organization-managed delegated access. If the approved alternative is not supplied, keep access blocked. Do not retain, reuse, or test the unsafe credential or payment data. Escalate to payment and system-security owners.
- Approval or evidence required
- List the authorization record needed for the access or data class: system owner, role and purpose, delegated credential method, data classification, approved payment channel, retention rule, and incident route. M06-I02 (F02), M06-I03 (F06), and M06-I04 (F07) establish the confidentiality and unsafe-method triggers; approvals remain not supplied. Do not use F12 service-quality reporting as access approval. Review: security, privacy, and payment owners.
- Review or revocation trigger
- For Review or revocation trigger, record the supplied controlled revision, effective date, review period, or trigger with its source; otherwise state which temporal value is not supplied. No “Protect and review service” source fact supplies it; mark “Not supplied” and request the missing temporal control. Never reuse a stale value, calculate a date-specific result without a date, or treat receipt date as effective date. Keep pending for the client process owner and any required specialist.
- Storage, retention, or incident route
- Define minimum authorized access, purpose, approved method, storage/retention rule, review trigger, and incident route for Storage, retention, or incident route. Evidence: no direct “Protect and review service” source fact; mark “Not supplied” when absent. Do not use personal credentials, transmit sensitive data through an unapproved channel, or claim access was granted/revoked. Escalate to the authorized security or privacy owner.
- Linked quality or closure control
- Linked quality or closure control: Write a stop/go/escalate rule with its prerequisite, authorized decision role, evidence gate, and pending outcome. Cite M06-I05 (F12); if insufficient, mark “Not supplied” and name the missing decision gate. Do not execute the control, commit funds, release work, or claim a decision occurred in this exercise. Review: the authorized quality owner and required specialist.
- Owner
- For Owner, name the authorized role that must review or decide, then show the decision as pending unless an authorized record is supplied. No “Protect and review service” source fact supplies it; mark “Not supplied” and request the missing decision authority. Never invent a person's name, infer authority from job title, or record approval from silence. Keep pending for the client process owner and any required specialist.
- Status
- Select a truthful state—draft, open, blocked, pending review, or not supplied—and tie it to the evidence still required for Status. Evidence: M06-I04 (F07); mark “Not supplied” when absent. Do not mark complete, accepted, verified, distributed, or closed without the corresponding record. Escalate to the client process owner and any required specialist.