# Osolix Platform Audit Charter — v1

**Status:** Approved · 2026-05-06
**Owner:** Head of AI Development (moderator)
**Cadence:** Continuous, with quarterly re-attestation of horizontal dimensions

---

## 1 · Purpose

The Osolix Platform Audit is an end-to-end, evidence-based attestation that every solution, module, page, tab, function, and workflow on the Osolix platform meets a defined bar across **25 dimensions** before it is considered "shipped."

The audit is run by a multi-disciplinary lens roster, moderated by the Head of AI Development, scored 1–10 per dimension with a **100 % pass mark**, and published as a public scorecard so customers, auditors, and prospects can independently verify the platform's rigour.

This charter formalises the framework so it is repeatable, defensible, and resistant to scope creep.

## 2 · Non-negotiables

1. **Pass mark is 100 % across all 25 dimensions.** No artifact is "shipped" until every dimension scores 10/10.
2. **Every passing artifact carries lens signatures + a date.** Anyone can trace who attested what, when.
3. **Quarterly re-attestation** of the horizontal dimensions (Security, Compliance, Performance, Accessibility, DR). They drift fastest and degrade silently.
4. **Internal scorecard** at `/admin/audit` — Osolix-staff + tenant-admin only. **NEVER public.** Internal QA scoring is not a customer-facing credibility signal (see `memory/audience_layering.md`).
5. **No exceptions, no "good enough."** A 9/10 means the artifact is not ready to ship. The honest score is the contract.
6. **Live functional probes are the SOURCE OF TRUTH.** Owner directive 2026-05-07: synthetic seeded scores are forbidden. The dashboard computes `effectiveScore = min(seededScore, probedScore)` so when reality contradicts a human's score, reality wins. A passing probe is REQUIRED for a passing cell. The audit cannot certify a feature that doesn't actually run.
7. **Certificates auto-suspend when probes fail.** A cert issued before a probe revealed reality is automatically suspended on the dashboard until the probe re-passes AND the cells re-cross the pass threshold. No "grandfathering" of synthetic certifications.

## 3 · The 25 dimensions

| # | Dimension | Pass criteria (summary) |
|---|---|---|
| 1 | **Functional integrity** | Every button works, every form persists, every API responds; happy + error paths covered. |
| 2 | **Integration-ready** | Webhooks, REST/GraphQL, vendor docs alignment (Oracle EBS / SAP / Sage / QuickBooks / Xero / Stripe / Anthropic). |
| 3 | **Brand & theme alignment** | Midnight Navy `#0B1D2B` + Gold `#D4AF37` only; Inter + Plus Jakarta Sans; light + dark mode parity. |
| 4 | **Fully developed** | No half-built features; no `TODO` comments shipped; every leg wired (entity → migration → API → page → sidebar → reports → email → audit log). |
| 5 | **Best-in-market** | Feature parity + a defensible advantage over the strongest competitor for that capability. |
| 6 | **Competitor gap** | Side-by-side feature matrix vs the 6 strongest competitors per solution; dated; visible on `/compare`. |
| 7 | **Real-life workflow** | Every step a real custodian / accountant / auditor / FM / CFO performs is supported end-to-end. |
| 8 | **Standards coverage** | IFRS, IAS, ASC (US GAAP), ISO 55000, ISO 14224, IPSAS; jurisdictional tax (UAE FTA, KSA ZATCA, US IRS, UK HMRC). |
| 9 | **AI integration** | Every workflow has an AI co-pilot OR a documented "no-AI here, by design" justification. |
| 10 | **User experience** | Task completion time, error rate, click-depth, NPS — all benchmarked against the strongest competitor. |
| 11 | **Security & RBAC** | OWASP Top 10 clear; MFA enforced; session timeout; RBAC test matrix; pen-test report on file. |
| 12 | **Multi-tenant isolation** | Automated cross-tenant probe tests on every endpoint; query filter on every entity; no cross-tenant leakage. |
| 13 | **Compliance & regulatory** | SOC 2 Type II, ISO 27001, GDPR, UAE PDPL, KSA PDPL; HIPAA where healthcare; evidence binder on file. |
| 14 | **Performance & scalability** | p95 < 500 ms on every list page; tested at 100 k assets / 1 M txns / 50 concurrent users. |
| 15 | **Accessibility (WCAG 2.2 AA)** | axe-core 0 violations; keyboard-only walkthrough; screen-reader pass; contrast ≥ 4.5:1. |
| 16 | **i18n + RTL** | Arabic RTL on every page; Hijri calendar option; multi-currency; multi-tax-jurisdiction. |
| 17 | **Mobile parity & offline** | Responsive web on every page; native iOS / Android feature-parity; offline scan + queued sync. |
| 18 | **Observability & AI governance** | Structured logs, traces, p50/p95/p99 dashboards; AI-Governance latency + accuracy monitor live. |
| 19 | **Data integrity & migration** | Referential integrity (no orphans); soft-delete + restore; bulk-import wizard; full export. |
| 20 | **Cross-module data flow** | Asset → Lease → Insurance → Disposal: every transition logged; no field re-entry. |
| 21 | **Documentation & onboarding** | In-product tour; help articles; API docs; admin manual; ≥ 5 video walkthroughs per module. |
| 22 | **Email & notifications** | Template QA; deliverability ≥ 99 %; opt-out; multi-language; in-app + email + push delivered. |
| 23 | **Billing & monetisation** | Invoice tax-rule per jurisdiction; dunning; plan switching; refund + credit-note workflow correct. |
| 24 | **Brand voice & microcopy** | Style guide enforced; every error / empty / success message reviewed; no dev-jargon shipped. |
| 25 | **Test coverage & DR** | Unit > 70 %; e2e on every critical path; daily backup; monthly restore drill; status page live. |

## 3a · Drift automation & alerting — coverage note

Wave 5-FA-9 (completed 2026-06-02) introduced a cross-module automated
alerting layer that does not map cleanly to a single solution or module.
It is registered in the audit inventory under `asset-management` as the
`am/drift-watchers` module and is audited against all 25 dimensions with
these dimension-specific notes:

| Dimension | Notes |
|---|---|
| **4 — Fully developed** | Every leg wired: entities → migration → IDriftSignal engine → controllers → hosted job → snapshot table → React hub + widgets → AuditLog on every action |
| **7 — Real-life workflow** | CFO / Risk Manager daily review: open hub → see KPI strip → expand trend → filter by severity → bulk-ack resolved alerts → configure thresholds per category |
| **8 — Standards coverage** | Sum-insured signal supports IFRS 4/17 insurance adequacy; market-value signal implements IAS 36 §12 impairment indicator detection |
| **9 — AI integration** | No AI co-pilot on the drift signal itself (by design — the math is deterministic); the impairment *test* triggered from a Down-drift alert uses the existing AI Impairment Advisor |
| **18 — Observability** | Nightly job logs tenant count, signal count, upserted/resolved/critical counts via `ILogger`; DriftSnapshot table provides the audit evidence trail |
| **20 — Cross-module data flow** | Drift Watchers consume Asset → Insurance (5-FA-1) and Asset → FairValueAmount (5-FA-2); Down-drift alerts link to the Impairment workflow; AuditLog entries feed the Audit module |
| **22 — Email & notifications** | `NotifyOnCriticalDrift` flag per watcher; in-app notifications delivered to TenantAdmin / AssetManager / Finance roles on new Critical alerts |

## 4 · Artifact hierarchy

Every audit target is a node in a five-level tree.

```
SOLUTION (7)        Asset Mgmt · Inventory · Maintenance · Fleet · Lease · Asset Budget · CWIP
   │
   └─ MODULE         e.g. inside Asset Mgmt: FAR · Additions · Transfers · Retirement · Verification · Tags · Master Data
        │
        └─ PAGE      e.g. /assets, /assets/:id, /assets/new
              │
              └─ TAB       Overview · Financials · Maintenance · Insurance · Lifecycle · Audit
                    │
                    └─ FUNCTION   Add · Edit · Delete · Bulk Import · Export · Print · Approve
                          │
                          └─ WORKFLOW   multi-step (e.g. Transfer = pick → approver chain → confirm → notify)
```

Approximately **4 200 leaves** at full enumeration. Stratified strategy: deep audit on critical paths; automated + sampled audit on the long tail.

## 5 · Audit waves (strict execution order)

| Wave | Type | Scope | Owner lens | Output |
|---|---|---|---|---|
| **W0** | Inventory | Auto-generate the artifact tree from routes, controllers, sidebar config | Chief Architect | Audit registry populated |
| **W1** | Horizontal foundation | Security · Multi-tenant isolation · Compliance · Performance · Accessibility · i18n · Observability · DR | CISO + SRE + Compliance + Accessibility | Pass certificate per dimension |
| **W2** | Cross-module data flow | The 12 real-life flows that span modules | Chief Architect + Vertical Leads | Flow diagrams + integration test suite |
| **W3** | Vertical solution audits | One pass per solution; every page+tab+function gets all 25 dimensions | Solution Lead + 8 lenses | Per-solution scorecard |
| **W4** | Competitor gap matrix | Feature table vs the 6 strongest competitors per solution | Product Lead + Sales | Updated `/compare` page + product backlog |
| **W5** | Real-life persona walks | 5 personas × 7 solutions = 35 end-to-end scripted walks | UX Lead + Vertical Leads | Persona dossiers + UX backlog |
| **W6** | AI integration audit | Every workflow gets AI present-or-justified-absent | Head of AI Development | AI map per workflow |
| **W7** | Documentation & onboarding | Help articles, API docs, video walkthroughs, in-product tour | Docs Lead | Help centre + onboarding scoring |
| **W8** | Final moderator audit | Re-score every artifact at 100 %; sign certificate | Head of AI Development | Platform Audit Certificate v1 |

## 6 · Scoring + governance

* **Score:** 1–10 per dimension per artifact; integer.
* **Pass:** all 25 dimensions at 10/10. No exceptions.
* **Lens signature:** every passing artifact carries the lens IDs + dates that signed it.
* **Re-audit triggers:** any code change to that artifact → re-run the dimensions touched.
* **Certificate expiry:** horizontal-dimension certificates expire 90 days after issue.
* **Conflict resolution:** the Head of AI Development arbitrates when two lenses disagree on a score; the moderator's call is final and recorded.

## 7 · Lens roster

| Lens | Role |
|---|---|
| Head of AI Development | Moderator; final scorecard sign-off; conflict arbiter |
| Chief Architect | "Fully wired" definition; integration patterns |
| CISO | Dimensions 11, 12 |
| Chief Compliance Officer | Dimension 13 |
| Chief Reliability Engineer (SRE) | Dimensions 14, 18, 25 |
| Accessibility Lead | Dimension 15 |
| Localisation Lead | Dimension 16 |
| Mobile Engineering Lead | Dimension 17 |
| Data Governance Lead | Dimensions 19, 20 |
| Product / UX Lead | Dimensions 10, 24 |
| Sales / Customer Success | Dimensions 5, 6, 21 |
| QA / Test Engineering | Dimensions 1, 25 |
| DevOps / DevEx | Dimensions 14, 25 |
| Finance / Billing | Dimension 23 |
| Industry Vertical Leads (RE, Construction, Healthcare, Hospitality, O&G, Public Sector) | Dimensions 5, 6, 7, 8 (per-vertical) |

## 8 · Out of scope

* Non-platform marketing collateral (handled by the marketing audit, separate charter).
* Internal tools used only by Osolix staff (not customer-facing).

## 9 · Change control

This charter is versioned in the repository. Any change to dimensions, scoring, or lens roster requires the Head of AI Development to issue a `v1.x` revision with a changelog entry and a re-attestation plan for the affected dimensions.
