Decision depth

Buy the smallest amount of evidence that can change the decision.

The tiers are not “more safety for more money.” They answer different owner questions with different evidence ceilings. Choose the cheapest scope that can resolve the uncertainty you actually have.

Qualification
Free
20 minutes

Scope / Authority Triage

Use when the first unknown is whether the workflow is even a useful audit target. We isolate the external action, the authority owner and the staging/test boundary.

Evidence ceiling
  • 1 critical action identified
  • Authority owner identified
  • Staging/test fit check
Not purchased
  • No tested finding
  • No written security conclusion
  • No deep evidence review
Qualify the workflow
Narrow decision
$1,500
fixed

Entry Audit

Use when one suspected failure controls the decision. We test one action chain and one primary hypothesis to determine whether it is reproducible and worth repairing.

Evidence ceiling
  • 1 critical action chain
  • 1 primary failure hypothesis
  • Bounded reproduction
  • Concise finding memo
Not purchased
  • No full Authority Ledger / Evidence Contract
  • No multi-scenario failure plan
  • No included retest
Test one uncertainty
Authority Budget

What permission surface are you deciding about?

Scope expands when the owner needs a defensible answer about more actions, objects, approvals or integrations — not because a higher price buys a stronger guarantee.

Evidence Before Effect

How much proof must exist before the action?

The commercial ladder buys different evidence depth. The primary audit tests whether decision-time evidence and external confirmation are strong enough for the authority being exercised.

False Green

How broadly do we test apparent success?

A narrow audit may test one suspected mismatch. The primary audit can include multiple agreed scenarios where internal success, freshness or external state may diverge.

Selection rule

Start from the owner decision, then buy the evidence.

Free
“Should we spend time auditing this workflow at all?”

Use triage when the action, owner or staging boundary is still unclear.

$1.5k
“Is this specific failure real enough to act on?”

Use the Entry Audit when one hypothesis dominates the engineering decision.

$4.9k
“Should this workflow keep, gain or lose authority?”

Use the primary audit when the answer requires multiple failure scenarios, an Authority Ledger + Evidence Contract, evidence-at-decision-time and a retestable owner backlog.

Decision matrix

Scope grows because the question gets harder.

This matrix is designed for budget or procurement review. The commercial difference is evidence depth and decision breadth — not a larger guarantee.

DimensionFree triageEntry auditPrimary audit
Owner questionIs this worth auditing?Is this one failure real?Has this workflow earned its Authority Budget?
Audit object1 proposed action1 critical action chain1 staging/test workflow
Failure depthNo failure tested1 primary hypothesis10–20 agreed scenarios
Authority analysisOwner + boundary onlyOnly what the finding requiresAction/object/approval map included
Evidence depthQualification evidence onlyEnough to accept/reject one findingEvidence Before Effect + confirmation + recovery
False Green coverageNot testedOnly if part of the hypothesisExplicitly tested where applicable
Primary outputAudit / do not auditRepair / reject hypothesisExpand / constrain / repair / retest
RetestNoNot included1 included
Hardening

Repair follows evidence.

Implementation is quoted separately only after a finding identifies the real control gap. The repair scope is tied to the owner decision, rollback risk and retest criteria; there is no fixed “make it safe” package.

Claim boundary

Engineering evidence, not certification.

The work can support decisions about logging, traceability, authority and control behavior inside the tested scope. It does not certify the system, guarantee security, guarantee defect absence or replace legal advice.

Before access

Start with one action and one owner.

The public intake prepares a scope brief only. It does not authorize testing. Do not submit credentials, private keys, wallet seeds, production secrets or customer secrets.

Map the action chain