{
 "use_case": "incident-notification-pack",
 "title": "Incident notification pack: ransomware at a payroll SaaS vendor, with a wrong time, a missed deadline and a claim the log contradicts",
 "about": "A synthetic incident log (VPN, EDR, chat, forensics, disclosure committee), the entity fields, and two supplied notices: a Form 8-K Item 1.05 draft and a NIS2 incident notification. Planted: the 8-K gives the detection time an hour late and a stale host count, and has no sentence on the financial impact; the NIS2 notification says no personal data was exfiltrated while the log records a 38 GB upload of HR exports; the NIS2 early warning went out 31 hours after awareness. The pack must hold both sentences, name the right time, list the missing element and the contradictions between the notices, show the early-warning clock as late, and the signed report and the hash-chained timeline must verify.",
 "licence": "Synthetic: Brightwater Payroll Cloud, its people, customers, IP addresses (RFC 5737 documentation ranges) and forensic firm are fictional (decosa_api/verticals/incident/synth.py). Part of decosa-api, AGPL-3.0-or-later.",
 "inputs": [
  {"file": "inputs/incident.json", "what": "Incident id, title and the entity's time zone."},
  {"file": "inputs/entity.json", "what": "Entity fields, cited as P.<field>."},
  {"file": "inputs/log.json", "what": "The incident log: time (with zone), source, text and tags (aware, materiality_determined, submitted:<regime>.<report>)."},
  {"file": "inputs/notices.json", "what": "The two supplied notices, each sentence ending with [E3, P.name]-style citations."}
 ],
 "steps": [
  {
   "id": "pack",
   "method": "POST",
   "path": "/incident/pack",
   "timeout": 300,
   "body": {
    "incident": {"$file": "inputs/incident.json"},
    "entity": {"$file": "inputs/entity.json"},
    "log": {"$file": "inputs/log.json"},
    "notices": {"$file": "inputs/notices.json"},
    "regimes": ["sec_8k", "nis2"],
    "synthetic": true
   }
  },
  {
   "id": "verify",
   "method": "POST",
   "path": "/incident/verify",
   "auth": false,
   "body": {"report": {"$ref": "pack.report"}, "pack_md": {"$ref": "pack.pack_md"}, "log": {"$file": "inputs/log.json"}}
  },
  {
   "id": "record",
   "method": "POST",
   "path": "/record/verify",
   "auth": false,
   "body": {"record": {"$ref": "pack.record"}}
  },
  {
   "id": "tampered",
   "method": "POST",
   "path": "/incident/verify",
   "auth": false,
   "body": {"report": {"$ref": "pack.report"}},
   "tamper": {"at": "report.status", "set": "all_traced"}
  }
 ],
 "checks": [
  {"says": "the pack needs attention", "path": "pack.status", "equals": "needs_attention"},
  {"says": "the wrong detection time is held as a time mismatch", "path": "pack.sentences[sid=sec_8k.item_1_05#1][0].reasons", "equals": ["time_mismatch"]},
  {"says": "the held time names the logged one", "path": "pack.sentences[sid=sec_8k.item_1_05#1][0].times[status=mismatch][0].detail", "contains": "03:12 UTC"},
  {"says": "the no-exfiltration claim is held", "path": "pack.sentences[sid=nis2.notification#7][0].status", "equals": "held"},
  {"says": "the 8-K lacks a sentence on the financial impact", "path": "pack.report.notices[id=sec_8k.item_1_05][0].coverage.impact", "equals": "missing"},
  {"says": "the two notices give different host counts", "path": "pack.contradictions.fact", "contains": "systems_affected"},
  {"says": "the NIS2 early warning was late by 7 hours", "path": "pack.clocks[report=early_warning][0].late_by", "equals": "7 h 0 min"},
  {"says": "the 8-K is due at 17:30 Eastern on the fourth business day", "path": "pack.clocks[report=item_1_05][0].due", "equals": "2026-09-22T21:30:00Z"},
  {"says": "the signed report verifies", "path": "verify.valid_signature", "equals": true},
  {"says": "the report matches the log it was run on", "path": "verify.log_matches", "equals": true},
  {"says": "the hash-chained timeline verifies", "path": "record.ok", "equals": true},
  {"says": "a report with its status changed no longer verifies", "path": "tampered.valid_signature", "equals": false},
  {"says": "every model call has a signed receipt", "receipts": "signed", "min": 10}
 ]
}
