CERTIMAND / Coverage & limitations
Coverage & limitations
Four representative checks are implemented in the public synthetic demonstration. This is a working validation MVP, not the complete sixteen-control product described in the development roadmap.
| Check | What it demonstrates | Boundary |
|---|---|---|
| C03 · Leaver access | Compare an effective employment end with observed downstream account access and an approved target. | Missing or partial data cannot prove revocation. The demo target of 24 hours is fictional customer policy, not a statutory deadline. |
| C11 · Workload ownership | Check a declared automation identity for a named active owner. | One supported synthetic workload. It does not discover every bot or compute effective permissions. |
| C08 · Strong authentication | Distinguish registered MFA from evidence of enforcement on a declared privileged resource. | No complete Conditional Access analysis. Missing enforcement evidence remains not evaluated. |
| C16 · Review cadence | Compare a customer-defined review deadline with a synthetic completion attestation. | One declared critical system. Detailed review decisions are not supplied. An attestation does not prove removal actions were carried out. |
Source status
HR, Microsoft Entra and GitHub data are synthetic snapshot models. Live collection, customer CSV uploads and source-system authentication are not enabled. No repository code, passwords or credential secret values are collected.
Honest outcomes
PASS means the defined synthetic check is satisfied with its required evidence. FAIL means a bounded discrepancy was observed. NOT_EVALUATED means necessary evidence is missing, stale or unresolved. Coverage is reported separately. A partial snapshot is not proof that a previous finding was resolved.
Reproducible evidence
The downloadable ZIP includes a frozen snapshot, assessment, manifest, limitations and a standalone Go verifier with the pinned rule source. The verifier checks file hashes and replays the assessment using the pinned implementation. The package has no trusted digital signature or qualified timestamp.
Regulatory context
Identity and access-control references are in Articles 20 and 21 of Commission Delegated Regulation (EU) 2024/1774, which supplements DORA. They are not Articles 20 and 21 of the base DORA regulation. Applicability and legal mappings need specialist review; this demo makes no compliance determination.
What comes next
Live read-only connectors, approved policy configuration, customer authentication and recurring evidence are candidates for a defined design-partner scope. Additional sectors, agents, sources and partner capabilities remain roadmap options until demand and economics support them.