Applicability boundary
This tool checks whether a record is reviewable—not whether the incident, cause or re-authorisation is true.
It can check
- JSON, v1 rule identity and the fifteen-field structure
- Whether incident, authority, clocks, containment, evidence, impact, cause and recovery fields are missing
- Decision expiry and obvious gaps in scope, exclusions, ownership and reopen conditions
It cannot prove
- That an incident occurred, logs are untampered, custody complete or owner identities valid
- That impact is complete, causality established, repairs effective or recovery tests sufficient
- That a system is safe, re-authorisation justified or legal, forensic, audit or certification compliant
FUURAA analysisIncident-decision verification should first reject records that cannot bind incident, version, authority, clocks, trigger, evidence bundle, impact, counter-evidence, recovery tests, independent review, expiry and reopen conditions. Even when all ten checks close, a reviewer must still open raw evidence, challenge causality, repeat consequential tests and confirm that the new decision covers only the scope supported by evidence.