rows: [] can look done in the UI. Green means approved statements are present — and status still starts as unset."> rows: [] can look done in the UI. Green means approved statements are present — and status still starts as unset.">
Yellow Theme

Next start · November 2026

Notes / Engineering note

Part of the yellow theme method · stage 1

2026-10-04

An empty matrix is not a green board

A control schema with rows: [] can look done in the UI. Green means approved statements are present — and status still starts as unset.

Thesis: Shipping the row shape without approved statements is a wrong green. The board must refuse invented SOC 2 sentences. Exactly nine approved Common Criteria–style control lines load at readiness; status stays unset until review; evidence pointers stay empty until a real pack points at a row.

What we shipped first

We published a control-matrix schema the ops board could fetch: id, statement, status, evidence pointer, method stage. The first live document returned an empty rows array on purpose. The table rendered. The endpoint was green. Nothing on the board was a control anyone had approved.

That empty response looked like progress. It was only plumbing. A schema with zero statements is not a control matrix.

The working shape

Statements arrive as a fixed set — nine lines, approved wording only. No filler criteria, no invented engagement copy. Each row carries yellow-team-method at readiness (numeric stage 4 in data). Status is labeled unset only until a real review lands. Evidence pointers stay null until a pack actually points at the row.

Example of an approved statement (verbatim; not invented):

Protected systems are only reachable by an identity the client already runs, and that restriction is in the code that builds the system.

That line is CC6.1 in the approved set. The other eight stay in the catalog — this note does not reprint a product matrix.

Wrong green is a live schema with zero approved statements. The working shape loads the fixed rows and keeps status unset.

// Wrong green: schema live, zero approved statements.
const matrixV1 = {
  method_id: "yellow-team-method",
  rows: [], // board looked ready; nothing was approved
};

// Working shape: fixed approved rows; status still unset.
const matrixV2 = {
  method_id: "yellow-team-method",
  rows: [
    {
      id: "CC6.1",
      statement:
        "Protected systems are only reachable by an identity the client already runs, and that restriction is in the code that builds the system.",
      status: "unset",
      evidence_pointer: null,
      method_stage: 4, // readiness — show the name in UI, keep the number in data
    },
    // …eight more approved rows; do not invent extras
  ],
};

Checklist

Related: the pack carries brief, not stage six. How we deliver: methodology · readiness.

Engineering commentary only — not audit, legal, or certification advice.