Expressible
Sample decision record

This is what Expressible produces.

Not a score — an audit-defensible decision record. Below is an illustrative RMF pre-adjudication output for a single control, showing the deliberation, the evidence-sufficiency finding, preserved dissent, calibrated confidence, claim-level citations, and the human attestation gate.

Illustrative example. Synthetic data — not a real system, assessment, or customer.
Artifact under review
SSP §AC-2 — Account Management
Governing control: NIST SP 800-53 Rev. 5 · AC-2 · assessed against SP 800-53A objectives
Determination
Other than satisfied
Confidence 0.86 · recommended for human review

Draft control-implementation statement

"The system disables user accounts automatically when a user is separated. Account management is handled through the enterprise identity provider."

Assessment objective (SP 800-53A)

Determine that the organization disables accounts within the organization-defined time period (30 days) when accounts are no longer required or a user is terminated, and that the disabling is evidenced.

Perspective deliberation

PASS
Completeness

A control narrative is present and addresses account disabling and identity management.

IMPROVE
Consistency

The statement says disabling is "automatic," but the architecture document describes a manual, ticket-based offboarding step. The two should be reconciled.

FAIL
Evidence-sufficiency

A narrative exists, but no artifact demonstrates that disabling occurs within the required 30 days. No log, configuration export, or screenshot is cited. The claim is present; the evidence is not.

IMPROVE
Clarity & specificity

"Automatically" is unspecified — the trigger, timing, and responsible role are not stated.

PASS
Traceability

The statement maps cleanly to AC-2 and to the identity-provider component in the system inventory.

The core test

Not whether the claim exists — whether the evidence supports it. A control can pass Completeness (a narrative exists) yet fail Evidence-sufficiency (the narrative is unsupported). That distinction is made explicit here, not buried in a single number.

Preserved dissent — counter-case

Devil's-advocate perspective: if the identity provider enforces SCIM deprovisioning on HR termination events, the control may in fact be satisfied. Recommend requesting the SCIM configuration export and termination-event logs to confirm before an other-than-satisfied determination is finalized. This counter-case is retained in the record rather than discarded.

Abstention

Where evidence was insufficient to determine satisfaction, the system abstained and flagged for human review rather than inferring compliance.

Claim-level citations

  • Source span: SSP §AC-2, ¶1 ("disables user accounts automatically")
  • Governing control: NIST SP 800-53 Rev. 5, AC-2 (Account Management)
  • Assessment objective: SP 800-53A, AC-2 determination statement (disabling within defined period, evidenced)

Human attestation gate

The system recommends and evidences; a named human decides and attests. No determination is finalized without this step.

ISSO — reviewed & annotated attested · 2026-04-14T15:22Z

"Concur with the evidence-sufficiency finding. Action: request SCIM configuration export and termination-event logs from the IdP team; re-evaluate on receipt. Not forwarding to assessment until evidenced."

Illustrative example with synthetic data. Not a real system, assessment, or customer. The same record structure is produced across missions — the perspectives, corpus, and attestation role are configured to each.

See it on your own artifacts

We'll configure the substrate to your control baseline, your corpus, and your attestation roles — and run it on your data, inside your boundary.