Scope record on every case
Subject, purpose, basis and exclusions, written before collection and stamped on the report header. Chronology is what makes it a decision rather than a justification.
Source endpoint on every finding
Specific enough for a reviewer to re-run. Not a tool name, an endpoint.
UTC retrieval timestamp
ISO 8601 with the Z suffix, on every finding including the negative ones. Records change, so an undated claim cannot be verified later.
Raw record retained as returned
Quoted, not paraphrased and not screenshotted. The evidence is the record, not a picture of it.
Severity grading
A small, defined set: high, medium, informational, pass. Defined once so the words mean the same thing in every case your team writes.
Negative findings kept
What was looked for and not found, dated the same way. This is what bounds the work and stops silence being read as coverage.
Report export in PDF and DOCX
Scope header, findings, negative findings, method appendix. The native output, not an afterthought.
Re-run for a diff
Same scope, same modules, new timestamps. What changed between two dated collections is the finding leadership actually wants.
Case library and templates
Shared cases, saved investigation templates and reviewer sign-off on Team and above. See the plan ladder.