{
  "schemaVersion": "1.0",
  "generatedAtUtc": "2026-09-12T00:12:54.2997051Z",
  "observationDate": "2026-09-11",
  "context": "Delegated Microsoft Graph v1.0; three separately authenticated role-specific users; one ordinary and one Global Reader target.",
  "notTested": [
    "Defender portal actions",
    "Every privileged role or every tenant",
    "Live-session invalidation",
    "Sign-in with reset passwords",
    "PIM eligibility for group membership or ownership"
  ],
  "sanitization": "User, tenant, client, target, audit-event, and request identifiers; UPNs; secrets; and arbitrary error text are omitted. Source filenames and SHA-256 checksums retain provenance.",
  "sameDelegatedScopesAcrossActors": true,
  "sameTenantAcrossActors": true,
  "sameClientAcrossActors": true,
  "scopeContext": {
    "sameApplicationVerified": true,
    "sameDelegatedScopesVerified": true,
    "sameTenantVerified": true,
    "applicationEvidenceField": "appId in each operator authentication evidence file",
    "authenticationModel": "Distinct delegated user identities using one temporary client application"
  },
  "actorEvidence": [
    {
      "role": "Security Administrator",
      "observedAtUtc": "2026-09-11T23:30:31.7697287Z",
      "serverMeMatchesRecordedActor": true,
      "allActionRecordsMatchActor": true,
      "delegatedScopesPresent": true,
      "applicationRoleClaimsPresent": false,
      "expectedRoleInTokenWids": true,
      "otherNonDefaultWidsCount": 0,
      "authenticationMethods": [
        "tap",
        "mfa"
      ],
      "directAssignmentSnapshotStatus": "Complete",
      "clientIdentityEvidenceField": "appId",
      "directAssignmentExpectedRoleOnly": true,
      "roleEligibilityCoverage": "Initial 403 resolved by a later complete directory-role eligibility scan: zero instances observed. PIM eligibility for group membership or ownership remains outside coverage.",
      "delegatedScopes": [
        "email",
        "openid",
        "profile",
        "User-PasswordProfile.ReadWrite.All",
        "User.EnableDisableAccount.All",
        "User.Read",
        "User.Read.All",
        "User.RevokeSessions.All"
      ]
    },
    {
      "role": "Entra SOC Identity Responder",
      "observedAtUtc": "2026-09-11T23:34:51.9891707Z",
      "serverMeMatchesRecordedActor": true,
      "allActionRecordsMatchActor": true,
      "delegatedScopesPresent": true,
      "applicationRoleClaimsPresent": false,
      "expectedRoleInTokenWids": true,
      "otherNonDefaultWidsCount": 0,
      "authenticationMethods": [
        "tap",
        "mfa"
      ],
      "directAssignmentSnapshotStatus": "Complete",
      "clientIdentityEvidenceField": "appId",
      "directAssignmentExpectedRoleOnly": true,
      "roleEligibilityCoverage": "Initial 403 resolved by a later complete directory-role eligibility scan: zero instances observed. PIM eligibility for group membership or ownership remains outside coverage.",
      "delegatedScopes": [
        "email",
        "openid",
        "profile",
        "User-PasswordProfile.ReadWrite.All",
        "User.EnableDisableAccount.All",
        "User.Read",
        "User.Read.All",
        "User.RevokeSessions.All"
      ]
    },
    {
      "role": "Security Operator",
      "observedAtUtc": "2026-09-11T23:38:06.0140171Z",
      "serverMeMatchesRecordedActor": true,
      "allActionRecordsMatchActor": true,
      "delegatedScopesPresent": true,
      "applicationRoleClaimsPresent": false,
      "expectedRoleInTokenWids": true,
      "otherNonDefaultWidsCount": 0,
      "authenticationMethods": [
        "tap",
        "mfa"
      ],
      "directAssignmentSnapshotStatus": "Complete",
      "clientIdentityEvidenceField": "appId",
      "directAssignmentExpectedRoleOnly": true,
      "roleEligibilityCoverage": "Initial 403 resolved by a later complete directory-role eligibility scan: zero instances observed. PIM eligibility for group membership or ownership remains outside coverage.",
      "delegatedScopes": [
        "email",
        "openid",
        "profile",
        "User-PasswordProfile.ReadWrite.All",
        "User.EnableDisableAccount.All",
        "User.Read",
        "User.Read.All",
        "User.RevokeSessions.All"
      ]
    }
  ],
  "targetEvidence": {
    "directAssignmentSnapshotAtUtc": "2026-09-11T23:39:57.4395724Z",
    "directAssignmentSnapshotStatus": "Complete",
    "ordinaryTargetDirectActiveRoleCount": 0,
    "administratorTargetDirectActiveRoles": [
      "Global Reader"
    ],
    "eligibilityStatus": "Initial 403 resolved by a later complete directory-role eligibility scan: zero instances observed. PIM eligibility for group membership or ownership remains outside coverage.",
    "initialEligibilitySnapshotAtUtc": "2026-09-11T23:39:59.0755688Z",
    "initialEligibilitySnapshotStatus": "Failed",
    "laterEligibilityRunAtUtc": "2026-09-12T00:07:46.9339475Z",
    "laterDirectoryEligibilityStatus": "Complete",
    "laterDirectoryEligibilityInstanceCount": 0,
    "groupPimEligibilityStatus": "NotCovered"
  },
  "auditSnapshot": {
    "observedAtUtc": "2026-09-11T23:43:48.635395Z",
    "collectionStatus": "Complete",
    "returnedRecords": 85,
    "exactRequestIdCorrelationFound": false,
    "limitation": "Complete means the returned query was paginated, not that asynchronous audit ingestion is complete. Absence is not proof no event can appear later."
  },
  "earlierAuditSnapshot": {
    "observedAtUtc": "2026-09-11T23:39:59.8694646Z",
    "collectionStatus": "Complete",
    "returnedRecords": 75,
    "note": "The initial snapshot lacked the Security Operator ordinary-enable audit event. The final snapshot contains the actor/target/time-matched successful enable and update events."
  },
  "observations": [
    {
      "role": "Security Administrator",
      "targetClass": "Ordinary user",
      "action": "Disable",
      "startedAtUtc": "2026-09-11T23:31:52.229568Z",
      "endedAtUtc": "2026-09-11T23:31:52.9305681Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "VerifiedStateChange",
      "accountEnabledBefore": true,
      "accountEnabledAfter": false,
      "actualAccountStateChangeVerified": true,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:26Z",
      "detail": "Disable accepted; post-request read found accountEnabled=false; matching actor/target audit records show true to false.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:31:52.6059963Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[true]",
                "newValue": "[false]"
              }
            ]
          },
          {
            "atUtc": "2026-09-11T23:31:52.6049946Z",
            "activity": "Disable account",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[true]",
                "newValue": "[false]"
              }
            ]
          }
        ]
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Ordinary user",
      "action": "Enable",
      "startedAtUtc": "2026-09-11T23:31:52.9453287Z",
      "endedAtUtc": "2026-09-11T23:31:53.5385805Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "VerifiedStateChange",
      "accountEnabledBefore": false,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": true,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:26Z",
      "detail": "Earlier disable read showed false; enable accepted and post-request read showed true. Audit corroboration is recorded separately.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:31:53.2850331Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[false]",
                "newValue": "[true]"
              }
            ]
          },
          {
            "atUtc": "2026-09-11T23:31:53.2840327Z",
            "activity": "Enable account",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[false]",
                "newValue": "[true]"
              }
            ]
          }
        ]
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Ordinary user",
      "action": "RevokeSessions",
      "startedAtUtc": "2026-09-11T23:31:53.5415064Z",
      "endedAtUtc": "2026-09-11T23:31:54.1101349Z",
      "httpStatus": 200,
      "errorCode": null,
      "classification": "ApiAcceptedTimestampAdvanced",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:31:53Z",
      "detail": "HTTP 200 with true; session-valid-from timestamp advanced. No live session or refresh-token rejection was exercised.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:31:53.8753949Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:31:53.8743948Z",
            "activity": "Update StsRefreshTokenValidFrom Timestamp",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          }
        ]
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Ordinary user",
      "action": "ResetPassword",
      "startedAtUtc": "2026-09-11T23:31:54.112274Z",
      "endedAtUtc": "2026-09-11T23:31:54.9660431Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "ApiAcceptedAuditRecorded",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:31:54Z",
      "detail": "HTTP 204; actor/target/time-matched audit records report a successful password reset. No sign-in with the new password was attempted.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 5,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:31:54.7503691Z",
            "activity": "Update StsRefreshTokenValidFrom Timestamp",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:31:54.7483704Z",
            "activity": "Reset user password",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:31:54.4793442Z",
            "activity": "Update PasswordProfile",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:31:54.4703444Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:31:54.2803349Z",
            "activity": "Update PasswordProfile",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          }
        ]
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Global Reader administrator",
      "action": "Disable",
      "startedAtUtc": "2026-09-11T23:31:55.1523712Z",
      "endedAtUtc": "2026-09-11T23:31:55.5785387Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Global Reader administrator",
      "action": "Enable",
      "startedAtUtc": "2026-09-11T23:31:55.5805547Z",
      "endedAtUtc": "2026-09-11T23:31:55.938019Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "NoOpAcceptedNotAuthorityProof",
      "accountEnabledBefore": true,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "Target was already enabled; HTTP 204 did not demonstrate authority to change a disabled account.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Global Reader administrator",
      "action": "RevokeSessions",
      "startedAtUtc": "2026-09-11T23:31:55.9399668Z",
      "endedAtUtc": "2026-09-11T23:31:56.313847Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Global Reader administrator",
      "action": "ResetPassword",
      "startedAtUtc": "2026-09-11T23:31:56.31575Z",
      "endedAtUtc": "2026-09-11T23:31:56.7202918Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-admin-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Ordinary user",
      "action": "Disable",
      "startedAtUtc": "2026-09-11T23:35:18.5579307Z",
      "endedAtUtc": "2026-09-11T23:35:19.338846Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "VerifiedStateChange",
      "accountEnabledBefore": true,
      "accountEnabledAfter": false,
      "actualAccountStateChangeVerified": true,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:31:54Z",
      "detail": "Disable accepted; post-request read found accountEnabled=false; matching actor/target audit records show true to false.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:35:19.0418869Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[true]",
                "newValue": "[false]"
              }
            ]
          },
          {
            "atUtc": "2026-09-11T23:35:19.0408874Z",
            "activity": "Disable account",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[true]",
                "newValue": "[false]"
              }
            ]
          }
        ]
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Ordinary user",
      "action": "Enable",
      "startedAtUtc": "2026-09-11T23:35:19.3532104Z",
      "endedAtUtc": "2026-09-11T23:35:20.0681364Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "VerifiedStateChange",
      "accountEnabledBefore": false,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": true,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:31:54Z",
      "detail": "Earlier disable read showed false; enable accepted and post-request read showed true. Audit corroboration is recorded separately.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:35:19.7977548Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[false]",
                "newValue": "[true]"
              }
            ]
          },
          {
            "atUtc": "2026-09-11T23:35:19.7967535Z",
            "activity": "Enable account",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[false]",
                "newValue": "[true]"
              }
            ]
          }
        ]
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Ordinary user",
      "action": "RevokeSessions",
      "startedAtUtc": "2026-09-11T23:35:20.0709495Z",
      "endedAtUtc": "2026-09-11T23:35:20.7979173Z",
      "httpStatus": 200,
      "errorCode": null,
      "classification": "ApiAcceptedTimestampAdvanced",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:35:20Z",
      "detail": "HTTP 200 with true; session-valid-from timestamp advanced. No live session or refresh-token rejection was exercised.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:35:20.5402703Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:35:20.5392722Z",
            "activity": "Update StsRefreshTokenValidFrom Timestamp",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          }
        ]
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Ordinary user",
      "action": "ResetPassword",
      "startedAtUtc": "2026-09-11T23:35:20.8001154Z",
      "endedAtUtc": "2026-09-11T23:35:21.8333001Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "ApiAcceptedAuditRecorded",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:35:21Z",
      "detail": "HTTP 204; actor/target/time-matched audit records report a successful password reset. No sign-in with the new password was attempted.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 5,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:35:21.5525901Z",
            "activity": "Update StsRefreshTokenValidFrom Timestamp",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:35:21.5515918Z",
            "activity": "Reset user password",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:35:21.2855861Z",
            "activity": "Update PasswordProfile",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:35:21.2755829Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:35:20.9965779Z",
            "activity": "Update PasswordProfile",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          }
        ]
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Global Reader administrator",
      "action": "Disable",
      "startedAtUtc": "2026-09-11T23:35:22.0502631Z",
      "endedAtUtc": "2026-09-11T23:35:22.5620086Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Global Reader administrator",
      "action": "Enable",
      "startedAtUtc": "2026-09-11T23:35:22.5641819Z",
      "endedAtUtc": "2026-09-11T23:35:23.0138729Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "NoOpAcceptedNotAuthorityProof",
      "accountEnabledBefore": true,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "Target was already enabled; HTTP 204 did not demonstrate authority to change a disabled account.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Global Reader administrator",
      "action": "RevokeSessions",
      "startedAtUtc": "2026-09-11T23:35:23.0157715Z",
      "endedAtUtc": "2026-09-11T23:35:23.4622792Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Global Reader administrator",
      "action": "ResetPassword",
      "startedAtUtc": "2026-09-11T23:35:23.4645292Z",
      "endedAtUtc": "2026-09-11T23:35:23.9132184Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "soc-responder-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Ordinary user",
      "action": "Disable",
      "startedAtUtc": "2026-09-11T23:38:16.4252529Z",
      "endedAtUtc": "2026-09-11T23:38:17.027643Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "VerifiedStateChange",
      "accountEnabledBefore": true,
      "accountEnabledAfter": false,
      "actualAccountStateChangeVerified": true,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:35:21Z",
      "detail": "Disable accepted; post-request read found accountEnabled=false; matching actor/target audit records show true to false.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:38:16.7905947Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[true]",
                "newValue": "[false]"
              }
            ]
          },
          {
            "atUtc": "2026-09-11T23:38:16.7895981Z",
            "activity": "Disable account",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[true]",
                "newValue": "[false]"
              }
            ]
          }
        ]
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Ordinary user",
      "action": "Enable",
      "startedAtUtc": "2026-09-11T23:38:17.0423764Z",
      "endedAtUtc": "2026-09-11T23:38:17.8376948Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "VerifiedStateChange",
      "accountEnabledBefore": false,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": true,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:35:21Z",
      "detail": "Earlier disable read showed false; enable accepted and post-request read showed true. Audit corroboration is recorded separately.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:38:17.466034Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[false]",
                "newValue": "[true]"
              }
            ]
          },
          {
            "atUtc": "2026-09-11T23:38:17.4640339Z",
            "activity": "Enable account",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": [
              {
                "oldValue": "[false]",
                "newValue": "[true]"
              }
            ]
          }
        ]
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Ordinary user",
      "action": "RevokeSessions",
      "startedAtUtc": "2026-09-11T23:38:17.8409761Z",
      "endedAtUtc": "2026-09-11T23:38:18.371798Z",
      "httpStatus": 200,
      "errorCode": null,
      "classification": "ApiAcceptedTimestampAdvanced",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:38:17Z",
      "detail": "HTTP 200 with true; session-valid-from timestamp advanced. No live session or refresh-token rejection was exercised.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 2,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:38:18.1698441Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:38:18.1688363Z",
            "activity": "Update StsRefreshTokenValidFrom Timestamp",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          }
        ]
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Ordinary user",
      "action": "ResetPassword",
      "startedAtUtc": "2026-09-11T23:38:18.3739727Z",
      "endedAtUtc": "2026-09-11T23:38:19.1300185Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "ApiAcceptedAuditRecorded",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:38:18Z",
      "detail": "HTTP 204; actor/target/time-matched audit records report a successful password reset. No sign-in with the new password was attempted.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 5,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": [
          {
            "atUtc": "2026-09-11T23:38:18.917837Z",
            "activity": "Update StsRefreshTokenValidFrom Timestamp",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:38:18.9168394Z",
            "activity": "Reset user password",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:38:18.7248402Z",
            "activity": "Update PasswordProfile",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:38:18.7178375Z",
            "activity": "Update user",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          },
          {
            "atUtc": "2026-09-11T23:38:18.5378419Z",
            "activity": "Update PasswordProfile",
            "result": "success",
            "actorAndTargetMatched": true,
            "accountEnabledChanges": []
          }
        ]
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Global Reader administrator",
      "action": "Disable",
      "startedAtUtc": "2026-09-11T23:38:19.3140161Z",
      "endedAtUtc": "2026-09-11T23:38:19.6983887Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Global Reader administrator",
      "action": "Enable",
      "startedAtUtc": "2026-09-11T23:38:19.7005258Z",
      "endedAtUtc": "2026-09-11T23:38:20.071146Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "NoOpAcceptedNotAuthorityProof",
      "accountEnabledBefore": true,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "Target was already enabled; HTTP 204 did not demonstrate authority to change a disabled account.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Global Reader administrator",
      "action": "RevokeSessions",
      "startedAtUtc": "2026-09-11T23:38:20.0733742Z",
      "endedAtUtc": "2026-09-11T23:38:20.4251239Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Global Reader administrator",
      "action": "ResetPassword",
      "startedAtUtc": "2026-09-11T23:38:20.4269594Z",
      "endedAtUtc": "2026-09-11T23:38:20.795542Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": null,
      "accountEnabledAfter": true,
      "actualAccountStateChangeVerified": false,
      "liveSessionInvalidationTested": false,
      "newPasswordSignInTested": false,
      "sessionValidFromAfter": "2026-09-11T23:29:27Z",
      "detail": "HTTP 403 Authorization_RequestDenied for this Global Reader target; the same operation succeeded against the ordinary target.",
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "sourceFile": "security-operator-action-results.json"
    },
    {
      "role": "Security Administrator",
      "targetClass": "Global Reader administrator",
      "action": "EnableFromDisabled",
      "startedAtUtc": "2026-09-11T23:33:38.5682207Z",
      "endedAtUtc": "2026-09-11T23:33:40.065686Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": false,
      "accountEnabledAfterOperator": false,
      "accountEnabledAfterControllerRestore": true,
      "actualAccountStateChangeVerified": false,
      "preconditionReadCount": 0,
      "observationReadCount": 0,
      "firstToLastObservationSeconds": null,
      "observationReads": [],
      "preconditionReads": [],
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "controllerAccountEvents": [
        {
          "atUtc": "2026-09-11T23:33:39.8919697Z",
          "activity": "Enable account",
          "result": "success",
          "actor": "Provisioning administrator"
        },
        {
          "atUtc": "2026-09-11T23:33:38.9551609Z",
          "activity": "Disable account",
          "result": "success",
          "actor": "Provisioning administrator"
        }
      ],
      "detail": "Real false-to-true attempt denied; controller subsequently restored the disposable account.",
      "sourceFile": "security-admin-enable-from-disabled.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Global Reader administrator",
      "action": "EnableFromDisabled",
      "startedAtUtc": "2026-09-11T23:35:25.3485998Z",
      "endedAtUtc": "2026-09-11T23:35:26.7108778Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "AcceptedEffectUnverified",
      "accountEnabledBefore": false,
      "accountEnabledAfterOperator": false,
      "accountEnabledAfterControllerRestore": true,
      "actualAccountStateChangeVerified": false,
      "preconditionReadCount": 0,
      "observationReadCount": 0,
      "firstToLastObservationSeconds": null,
      "observationReads": [],
      "preconditionReads": [],
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "controllerAccountEvents": [
        {
          "atUtc": "2026-09-11T23:35:26.5349115Z",
          "activity": "Enable account",
          "result": "success",
          "actor": "Provisioning administrator"
        },
        {
          "atUtc": "2026-09-11T23:35:25.704514Z",
          "activity": "Disable account",
          "result": "success",
          "actor": "Provisioning administrator"
        }
      ],
      "detail": "Request accepted, but no operator-attributed enable effect was observed before controller restoration. No bypass claim is supported.",
      "sourceFile": "soc-responder-enable-from-disabled.json"
    },
    {
      "role": "Entra SOC Identity Responder",
      "targetClass": "Global Reader administrator",
      "action": "EnableFromDisabled",
      "startedAtUtc": "2026-09-11T23:36:54.9309744Z",
      "endedAtUtc": "2026-09-11T23:37:20.4376512Z",
      "httpStatus": 204,
      "errorCode": null,
      "classification": "AcceptedEffectUnverified",
      "accountEnabledBefore": false,
      "accountEnabledAfterOperator": false,
      "accountEnabledAfterControllerRestore": true,
      "actualAccountStateChangeVerified": false,
      "preconditionReadCount": 3,
      "observationReadCount": 11,
      "firstToLastObservationSeconds": 21.483,
      "observationReads": [
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:36:58.4657037Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:00.6177982Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:02.769788Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:04.9057671Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:07.0709233Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:09.2428867Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:11.3826437Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:13.5271551Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:15.6791047Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:17.8166519Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:37:19.9491599Z"
        }
      ],
      "preconditionReads": [
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:36:55.6890475Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:36:56.5400174Z"
        },
        {
          "accountEnabled": false,
          "atUtc": "2026-09-11T23:36:57.3872175Z"
        }
      ],
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "controllerAccountEvents": [
        {
          "atUtc": "2026-09-11T23:37:20.2595818Z",
          "activity": "Enable account",
          "result": "success",
          "actor": "Provisioning administrator"
        },
        {
          "atUtc": "2026-09-11T23:36:55.3338545Z",
          "activity": "Disable account",
          "result": "success",
          "actor": "Provisioning administrator"
        }
      ],
      "detail": "Request accepted, but no operator-attributed enable effect was observed before controller restoration. No bypass claim is supported.",
      "sourceFile": "soc-responder-enable-from-disabled-observed.json"
    },
    {
      "role": "Security Operator",
      "targetClass": "Global Reader administrator",
      "action": "EnableFromDisabled",
      "startedAtUtc": "2026-09-11T23:38:22.2397921Z",
      "endedAtUtc": "2026-09-11T23:38:32.684028Z",
      "httpStatus": 403,
      "errorCode": "Authorization_RequestDenied",
      "classification": "RequestDenied",
      "accountEnabledBefore": false,
      "accountEnabledAfterOperator": false,
      "accountEnabledAfterControllerRestore": true,
      "actualAccountStateChangeVerified": false,
      "preconditionReadCount": 3,
      "observationReadCount": 4,
      "firstToLastObservationSeconds": 6.466,
      "observationReads": [
        {
          "atUtc": "2026-09-11T23:38:25.680805Z",
          "accountEnabled": false
        },
        {
          "atUtc": "2026-09-11T23:38:27.8329349Z",
          "accountEnabled": false
        },
        {
          "atUtc": "2026-09-11T23:38:29.9848386Z",
          "accountEnabled": false
        },
        {
          "atUtc": "2026-09-11T23:38:32.147237Z",
          "accountEnabled": false
        }
      ],
      "preconditionReads": [
        {
          "atUtc": "2026-09-11T23:38:22.940161Z",
          "accountEnabled": false
        },
        {
          "atUtc": "2026-09-11T23:38:23.7948394Z",
          "accountEnabled": false
        },
        {
          "atUtc": "2026-09-11T23:38:24.6429794Z",
          "accountEnabled": false
        }
      ],
      "auditCorroboration": {
        "exactRequestIdCorrelationCount": 0,
        "actorTargetTimeWindowMatchCount": 0,
        "matchBasis": "Actor ID + target ID + recorded case time window; not exact request-ID correlation unless count is nonzero.",
        "events": []
      },
      "controllerAccountEvents": [
        {
          "atUtc": "2026-09-11T23:38:32.5086188Z",
          "activity": "Enable account",
          "result": "success",
          "actor": "Provisioning administrator"
        },
        {
          "atUtc": "2026-09-11T23:38:22.6175627Z",
          "activity": "Disable account",
          "result": "success",
          "actor": "Provisioning administrator"
        }
      ],
      "detail": "Real false-to-true attempt denied; controller subsequently restored the disposable account.",
      "sourceFile": "security-operator-enable-from-disabled.json"
    }
  ],
  "sourceEvidence": [
    {
      "file": "role-audit-events.json",
      "sha256": "f8ff4960b2b2f5186919766d9b419050a1dc7792205d7a8cff3bb40195cedb3f"
    },
    {
      "file": "role-audit-events-final.json",
      "sha256": "3af95515f4257c244a17e5a34cc425c3a35fec9218051d490a0951e99e1027a8"
    },
    {
      "file": "role-assignments-test-snapshot.json",
      "sha256": "b0cc8c4b2c871a58b2f6963aab7737f885f64466194282c7fc0ec4d1cf7d324e"
    },
    {
      "file": "role-eligibility-snapshot.json",
      "sha256": "305bb77325c81754258d2f2e2df8e7957b1c55dd621053d0df1221cf91e5f030"
    },
    {
      "file": "readiness-audit-complete.json",
      "sha256": "703e20a552fbed4bb232f96abf79e221f6f40f5e21f881243b79bf75e82bbfe5"
    },
    {
      "file": "role-definitions-before.json",
      "sha256": "ec06ca217e68f44933fe71f2e7d42218d15ab80da58ab0f7b518995c261e9db8"
    },
    {
      "file": "admin-auth.json",
      "sha256": "2c4e83cc57a903bf9d0ab813bc4fd2dc0d2469849dd93468c9005631151141ef"
    },
    {
      "file": "security-admin-auth.json",
      "sha256": "e2c7ccf9b8c87944c2e44d70e321226cbc84d659cd11ca446c05dc251ff05bf4"
    },
    {
      "file": "security-admin-action-results.json",
      "sha256": "d4e446a7b9b96932b045e66a4cfcc69afe385c830818fdf1a745d3f8f5b07be2"
    },
    {
      "file": "soc-responder-auth.json",
      "sha256": "ac58eec2de2bd9a11e3a8963f44a2c5c4c91034c396d4e6d9a5eed9cef2faf40"
    },
    {
      "file": "soc-responder-action-results.json",
      "sha256": "8aab8809f10eb254cf5ca6fa9aa7c5473fa280e2e2fa79156ece290e34f35ff4"
    },
    {
      "file": "security-operator-auth.json",
      "sha256": "9831c5cdcb0fb20c874da736b16d87012f10c33e91f6cf9654b344ddd2e084e0"
    },
    {
      "file": "security-operator-action-results.json",
      "sha256": "9286cc9025dd704173177ef8441fa7f9d605bff2970ecb4f7cfd518bf380695c"
    },
    {
      "file": "security-admin-enable-from-disabled.json",
      "sha256": "be34971ff2443a79a45f5151fdb8f9b5370f96e1019ae3856d6d031c8daeb755"
    },
    {
      "file": "soc-responder-enable-from-disabled.json",
      "sha256": "081eafc1375460a213412c48574288e6d6e6e15b958c989bd8340a357fa5dc75"
    },
    {
      "file": "soc-responder-enable-from-disabled-observed.json",
      "sha256": "fda98e86be19d4f2301c2f5aa1585a8965ae6793c4327591e7b7b7013617654c"
    },
    {
      "file": "security-operator-enable-from-disabled.json",
      "sha256": "556bb5da8bd69ca88a1a1482bfcd2f7ba314c62b7424c4c9e90aa5496af8b49c"
    }
  ]
}
