Synthetic demonstration data

Findings, evidence and report outputs.

This page shows the P3 output model with synthetic demonstration data. It explains what Orbit observed, where the observation came from, how the rule interpreted it, how confident that interpretation is and what a human should do next.

These are not customer findings, not complete tenant coverage and not a legal or audit opinion. They are sample outputs used to make the report, evidence and export model reviewable.

Dashboard metrics

Reproducible indicators, not a black-box score.

Findings
3
Evidence records
4
Human review
1
Low confidence
1

Finding list

Filterable finding model, shown as a static sample.

SeverityConfidenceStatusCategorySourceOwnerObject
Synthetic finding list
FindingSeverityConfidenceStatusCategoryEvidence
Supported application-like object has no accountable ownerfinding-syn-ownership-001mediummediumin-reviewOwnership6 of 6 required elements available
Permission assignment lacks documented purposefinding-syn-permission-001mediumhighopenPermissions6 of 6 required elements available
Sensitivity context unavailable for data-reach interpretationfinding-syn-datareach-001infolowopenData reach6 of 6 required elements available

Finding detail

Facts, interpretation and human decision are separated.

Ownership

Supported application-like object has no accountable owner

A synthetic application-like object has permission context but no accountable owner in the demonstration inventory.

mediummedium confidencein-review
Rule
ownership-known-owner-required · 0.1.0
Observed
2026-07-17T09:00:00.000Z
First seen
2026-07-17T09:00:00.000Z
Last seen
2026-07-17T09:00:00.000Z

Observed facts

  • application: Synthetic Procurement Assistant · source ID synthetic-app-001

Orbit interpretation

The finding is medium severity because missing ownership affects accountability and remediation, but no immediate critical business impact is evidenced in the synthetic sample. Confidence is medium because the owner absence is explicit in the synthetic normalized record, while no independent owner attestation is available.

Human decision

Current status: in-review. Status changes require a reason, actor and timestamp.

Reviewer: synthetic-reviewer-security-architect

Evidence sources

  • ev-syn-owner-001 · supports-finding · synthetic-sampleSynthetic application-like object has no accountable owner in the demonstration inventory.
  • ev-syn-review-001 · human-review · synthetic-sampleSynthetic reviewer moved a finding into review and requested owner validation.

Recommendation

Assign a business owner and technical owner, record the ownership source, and set the next review date before relying on this object for governed workflows.

Evidence completeness: 6 of 6 required elements available

Limitations and assumptions

  • Synthetic demonstration data.
  • This finding does not prove that no owner exists outside the supplied evidence.
  • • Assumption: The normalized owner field is the authoritative field for this sample.

Permissions

Permission assignment lacks documented purpose

A synthetic permission assignment is present, but the sample evidence does not include a documented purpose or approval reference.

mediumhigh confidenceopen
Rule
permission-purpose-required · 0.1.0
Observed
2026-07-17T09:01:00.000Z
First seen
2026-07-17T09:01:00.000Z
Last seen
2026-07-17T09:01:00.000Z

Observed facts

  • permission: Synthetic read permission · source ID synthetic-permission-001

Orbit interpretation

Severity is medium because a permission without documented purpose is a governance gap, but the sample does not evidence write access or immediate critical impact. Confidence is high because the missing purpose is directly represented in the synthetic permission evidence.

Human decision

Current status: open. Status changes require a reason, actor and timestamp.

Evidence sources

  • ev-syn-perm-001 · supports-finding · synthetic-sampleSynthetic permission assignment has no documented purpose or reviewer note.

Recommendation

Document why the permission is required, confirm whether a narrower scope would satisfy the use case, and record a human reviewer decision.

Evidence completeness: 6 of 6 required elements available

Limitations and assumptions

  • Synthetic demonstration data.
  • Purpose may exist in an external system that is outside the sample evidence.

Data reach

Sensitivity context unavailable for data-reach interpretation

The sample shows potential data-reach context, but sensitivity classification is unavailable and requires human review.

infolow confidenceopen
Rule
sensitivity-context-unavailable · 0.1.0
Observed
2026-07-17T09:02:00.000Z
First seen
2026-07-17T09:02:00.000Z
Last seen
2026-07-17T09:02:00.000Z

Observed facts

  • data-source: Synthetic collaboration repository · source ID synthetic-data-source-001

Orbit interpretation

Severity is informational because missing sensitivity context is a limitation, not proof of exposure. Confidence is low because a key context source is unavailable.

Human decision

Current status: open. Status changes require a reason, actor and timestamp.

Evidence sources

  • ev-syn-purview-missing-001 · supports-limitation · synthetic-sampleSensitivity context is unavailable in this synthetic sample because Purview is planned, not implemented.

Recommendation

Ask a data owner or Purview administrator to validate sensitivity context before making risk or remediation decisions.

Evidence completeness: 6 of 6 required elements available

Limitations and assumptions

  • No Purview connector exists in this repository.
  • This finding must not be interpreted as absence of sensitive data access.

Rule methodology

Rules explain severity, confidence and limitations.

validation

Supported agent-related object should have an accountable owner

Flags supported agent-related objects where the normalized record has no accountable owner reference.

Severity method
Default medium when ownership is missing for an object with business-system or permission context; lower if the object has no authority context.
Confidence method
High when owner fields were read directly; medium when ownership source is unavailable; low when object mapping is inferred.

validation

Permission should have a documented purpose

Flags permission assignments where the intended business or technical purpose is missing from normalized records.

Severity method
Medium by default; high only when broad or write authority is directly evidenced and no purpose is documented.
Confidence method
High with direct permission assignment evidence; medium when permission source is present but purpose metadata is unavailable.

validation

Sensitivity context unavailable for data-reach interpretation

Creates a review item when a finding relies on data-reach interpretation but sensitivity context is unavailable.

Severity method
Info or medium depending on related authority context; do not escalate solely because sensitivity data is missing.
Confidence method
Low when sensitivity context is unavailable; unknown when no connected source can support interpretation.

Severity model

  • critical: Use only when immediate high business or security impact is clearly evidenced. Missing metadata alone cannot create a critical finding.
  • high: Use for high potential impact or privileged authority with insufficient control evidence.
  • medium: Use for relevant governance or permission gaps without evidenced immediate critical impact.
  • low: Use for limited gaps with low expected impact or localized remediation.
  • info: Use for contextual observations without direct risk rating.

Confidence model

  • high: Direct source, clear object mapping, current evidence and no material contradictory signal.
  • medium: Source evidence exists, but one relevant data source is missing, mapping is indirect or assumptions are required.
  • low: Coverage is incomplete, data may be stale or the interpretation requires manual validation.
  • unknown: No reliable interpretation can be made from the available evidence.

Evidence provenance

Source to report chain.

Evidence provenance chain: Microsoft or manual source, collected record, normalized object, rule evaluation, finding, human review, report or export.

Human review

Status changes preserve context.

  1. Open
  2. In Review
  3. Accepted Risk
  4. Remediation Planned
  5. False Positive
  6. Not Applicable
  7. Remediated

openin-review

Reviewer requested accountable owner validation.

synthetic-reviewer-security-architect · 2026-07-17T10:00:00.000Z

Reports and exports

Three report types, three safe sample export formats.

executive-summary

Synthetic Executive Summary Report

Version 0.1.0 · orbit-methodology-0.1-synthetic · synthetic sample.

  • Cover
  • Assessment scope
  • Executive summary
  • Key observations
  • Top findings
  • Evidence coverage

security-findings

Synthetic Security Findings Report

Version 0.1.0 · orbit-methodology-0.1-synthetic · synthetic sample.

  • Scope
  • Data sources
  • Permissions used
  • Methodology
  • Finding overview
  • Detailed findings

audit-supporting-evidence

Synthetic Audit-Supporting Evidence Report

Version 0.1.0 · orbit-methodology-0.1-synthetic · synthetic sample.

  • Assessment identifier
  • Tenant and scope
  • Methodology version
  • Evidence records
  • Findings
  • Human decisions