dotaction / rulediff Request a back-test ↗
Synthetic policy cascade · v0.2

See where policy stopped.

This is a synthetic format demonstration, not a customer result, legal opinion, compliance assurance or RuleDiff accuracy claim. A real back-test includes owner-adjudicated findings, including misses, valid local exceptions and rejected candidates.
01 / Source record

The parent change is approved before RuleDiff tests it.

Group ICT Risk Policy v7 Requirement GP-07.4 · owner-approved version · approval date and source snapshot hash recorded in a live engagement
Synthetic approved change

Material ICT incidents must be escalated to Group Risk within four hours of classification.

Customer policy owner: approval required before the inheritance test begins.
02 / Cross-entity evidence

Every finding has a passage, reason and review state.

ArtifactEvidence locationComparisonRuleDiff state
NL Incident Procedure.docx§4.2 EscalationFour-hour deadline and Group Risk owner are explicitAddressed
DE Escalation Guide.docx§5.1 NotificationNext-business-day deadline conflicts with the parentNot addressed
FR Reporting Form.docxField 12Captures classification time but names no escalation deadlineCannot determine
BE Local Policy.docx§7.3 ExceptionLocal statutory notification is documented separatelyOwner review
03 / Illustrative remediation

Evidence supports a decision; it does not make one.

Material ICT incidents are escalated by the end of the next business day to Group Risk within four hours of classification. Local statutory reporting obligations remain unchanged.
04 / Measurement contract

The report shows failure as clearly as success.

Incremental findingsreported
False positivesreported
Missesreported
Scan coveragereported
Current pilot boundary

DOCX first.

One approved master-policy change, three entities and up to 30 DOCX policies, procedures, forms or guidance files. The ten-business-day back-test requires no live tenant connection and never modifies controlled originals.

Explicit exclusions
  • legal interpretation, policy approval or compliance certification;
  • macros, encrypted files and embedded objects unless scoped;
  • autonomous decisions or changes to controlled originals;
  • completeness claims without independent adjudication.