Assurance Exchange
Assurance Exchange is the workspace module for preparing scoped disclosure records from approved assurance snapshots. It supports internal passport profiles, passport versions, scoped grants, publications, receipts, and evidence requests without creating an unrestricted external reviewer portal.
Use it when an organization needs to share approved assurance posture with a customer, auditor, group function, supplier, internal oversight team, or authority while preserving source-owner control.
What Assurance Exchange Owns
- Passport profiles for organization, service, supplier, program, contract, or custom scopes.
- Passport versions built from approved snapshot refs and sanitized summaries.
- Internal scoped access grant records for disclosure workflows.
- Snapshot publication records and safe delivery posture.
- Publication receipts and validation summaries.
- Scoped evidence request and response refs.
Assurance Exchange does not own external reviewer sessions, a public assurance-access app, public REST APIs, service accounts, OpenAPI, DMS documents, certificates, raw evidence, posture models, source-owner records, or direct authority-led source feeds.
User Journey
- Open Governance > Assurance Exchange.
- Create a passport profile for the organization, service, supplier, program, contract, or other scope.
- Create a passport version from approved continuous-assurance snapshot refs.
- Record a scoped access grant or publication for the intended recipient.
- Track publication receipts and validation posture.
- Record scoped evidence requests and response refs.
- Use audit packages, work management, compliance posture, and enterprise readiness to consume exchange descriptors.
Disclosure Boundary
Exchange records are metadata and sanitized summaries. They do not grant external users live access by themselves.
External human review, scoped search, auditor questions, finding submission, evidence download, and public verification are handled by the dedicated assurance-access surface. Machine-to-machine access is handled by External Integrations through stable /api/v1 contracts.
Snapshot Safety
Assurance Exchange must not store raw operational data, raw documents, prompts, provider responses, embeddings, vectors, storage paths, secrets, credentials, or protected source text.
Use capability states such as evidence-required, reference-only, roadmap, policy-blocked, deployment-dependent, or not-configured when exchange behavior depends on the assurance-access surface, a public API, a connector adapter, a signing protocol, or an external delivery provider.
Cloud And On-Prem
Cloud and on-prem expose the same Assurance Exchange behavior. Deployment differences belong in provider bindings, delivery posture, customer-managed dependencies, and capability-state labels.
Do Not Use This Module To Claim
- An external assurance-access app is available.
- Public
/api/v1assurance exchange APIs, OpenAPI, SDKs, or webhooks are available. - Government, auditors, or customers receive unrestricted source-system access.
- Snapshots prove legal compliance without review.
- AI makes official findings or disclosure decisions.
- Direct authority-led source feeds are implemented.
Those outcomes require separate promoted specs and evidence.