{
  "status": "proposed_template",
  "scope": "Buyer-and-builder planning artifact; no product acceptance results",
  "pilot_customer": "",
  "product_version": "",
  "identity_connection": "",
  "group_mapping_rules": "",
  "revocation_rules": {},
  "recovery_authority": "",
  "rows": [
    {
      "id": "ID-01",
      "trigger": "Admin connects identity provider",
      "expected_outcome": "Only an authorized tenant admin can configure this workspace",
      "owner": "Engineering + customer admin",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-02",
      "trigger": "Pilot user signs in",
      "expected_outcome": "Stable external identity maps to the intended tenant membership",
      "owner": "Identity engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-03",
      "trigger": "Matching email exists elsewhere",
      "expected_outcome": "No cross-tenant account reassignment by email alone",
      "owner": "Identity engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-04",
      "trigger": "Provisioning update is repeated",
      "expected_outcome": "Update converges on the same membership and failures remain diagnosable",
      "owner": "Identity engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-05",
      "trigger": "Group or role mapping changes",
      "expected_outcome": "Obsolete grants are removed under the agreed precedence rules",
      "owner": "Product + customer admin",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-06",
      "trigger": "Membership is disabled",
      "expected_outcome": "New access is denied according to the documented revocation point",
      "owner": "Security engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-07",
      "trigger": "Disabled user has an active session",
      "expected_outcome": "Server-side invalidation or current-membership checks follow the agreed behavior",
      "owner": "Security engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-08",
      "trigger": "Disabled user owns a personal API credential",
      "expected_outcome": "Credential access follows the documented owner and revocation rule",
      "owner": "API engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-09",
      "trigger": "Disabled user has a pending export",
      "expected_outcome": "Result access follows the agreed authorization policy",
      "owner": "Product + API engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-10",
      "trigger": "Ordinary user tries to bypass enforced SSO",
      "expected_outcome": "Bypass is denied and the error does not expose another tenant",
      "owner": "Identity engineering",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-11",
      "trigger": "Identity configuration breaks",
      "expected_outcome": "Designated admin recovery works with agreed verification and audit controls",
      "owner": "Support + security",
      "evidence": "",
      "status": "not_executed"
    },
    {
      "id": "ID-12",
      "trigger": "Admin reviews connection changes",
      "expected_outcome": "Authorized reviewer can inspect actor action target and outcome",
      "owner": "Support + engineering",
      "evidence": "",
      "status": "not_executed"
    }
  ],
  "release_decision": {
    "required_rows": [],
    "unresolved_limitations": [],
    "accountable_owner": "",
    "evidence_reviewed": false
  }
}
