Evidence
Writing entitlement findings examiners trust
A finding that only engineers understand is half-finished. A finding that only compliance can read is usually wrong. Entitlement write-ups for API access control audits need both layers without forcing the reader to decode JWT payloads mid-paragraph.
Lead with the control claim
Open with what should be true: for example, that partner clients cannot invoke admin settlement routes. Then state the observation, the evidence pointer, and the risk if unaddressed. Keep gateway rule IDs and log excerpts in an appendix or collapsible annex.
Severity without theatrics
Avoid inflated language. If a mis-scoped client can read balances but cannot initiate payouts, say so. Examiners notice when every finding is labeled critical; so do internal stakeholders who must prioritize remediation.
Evidence pointers that survive staff turnover
Link to durable artifacts: policy repository paths, ticket IDs, or dated exports stored in the audit folder. Screenshot-only evidence ages poorly when the UI changes the week after the review.
Our Protocol Studio memo lab drills this structure. Browse courses or read how alumni used the template in our reviews.