PacSpace
Talk to us
Evaluators and auditors · What to ask for

What to ask a lab for before you rely on its record.

The asks below fit in an access agreement or an engagement letter. Each one narrows what you'd otherwise have to take on the lab's word.

The asks

In the order you'd set up an engagement.

02

Which kinds of entries the lab writes.

Tool calls, network connections, file changes, model versions and settings, approvals, monitor flags: whatever is in scope. The lab chooses what to write, so know what the record covers before you rely on it.

03

Writing that started before your window opened.

Entries before and after the period put a start and an end on any gap inside it.

04

Which fields you'll see.

The seals alone, chosen fields, or every field. What's withheld is counted for you, never shown.

05

The record's history file.

So you can check again on your own computer with the open-source checker, without PacSpace or the lab.

06

What you may say about your access.

Agree in writing what you may publish about the access you were given and the access you weren't.

07

The right to ask for more fields later.

The lab reveals them in a new link, which replaces the old one, or in a file built from the record. Each field is checked against its entry's seal.

Wording to adapt

A clause you can start from.

For [the systems in scope], [the lab] will write [the kinds of entries] to a PacSpace record from [a date before the engagement period], and give [the evaluator] a link to that record for [the engagement period], revealing [these fields]. [The evaluator] may keep the record's history file and check it again on its own systems. [The evaluator] may publish what access it was given and what it wasn't.

This is a starting point, not legal advice. Your counsel and the lab's decide the terms.

If the lab doesn't record yet

If you evaluate a lab, ask for a link.

The lab records with two lines of code. Checking needs nothing from you but the link and its code, from wherever you work.

Talk to us and we'll open a live record with you.

Talk to us

Bring the case you think breaks it.

We would rather be evaluated by use than by description. Talk to us and we'll put you in a live environment: commit a record, do your best to change it, then check it yourself, with us out of the loop. The change shows.

The record must exist.