Agent Operating Guide
SOX engine
The Audit plugin's script-backed SOX 404 fieldwork engine: plan a control area's testing, run deterministic procedures, and turn screenshot, video, live-web, or mixed-folder evidence into reviewably annotated workpapers.
The sox family is a script-backed engine for SOX 404 control testing. /sox-testing orchestrates a control area’s testing for a period; helper skills make deterministic work reproducible and turn image, video, live-web, or mixed-folder evidence into reviewably annotated workpapers; six leaf sub-agents keep evidence bytes out of the orchestrator’s context; and a rubric-driven grader scores the finished workpaper in a fresh context window.
Skills
Section titled “Skills”| Skill | What it does |
|---|---|
| /sox-testing | Plan and drive one control area’s testing for a period, control matrix, sample sizing and selection, annotated workpaper, deficiency evaluation, and self-grade at the end. |
| /sox-test | The AssureSwarm bridge: operate one SOX control-testing workflow step: pull the control, run the engine, upload the workpaper, and propose the results for review. |
| /sox-python | Run a deterministic procedure as code (sample draw, three-way match, recomputation, threshold check) and append a reproducible Procedure tab with source, output, runtime, exit code, and a SHA-256. |
| /sox-annotate-xlsx | Turn an xlsx of embedded evidence screenshots into annotated workpaper tabs with movable red-rectangle shapes over each tested field. |
| /sox-from-video | Turn a recorded walkthrough plus transcript into annotated frames, boxed per tested field. |
| /sox-from-web | Collect evidence live from the audited system through Claude for Chrome, read-only, then annotate and assemble. |
| /sox-from-folder | Turn a mixed evidence folder into an annotated workpaper, hashing every file for custody and mapping each image to its sample and tests. |
| /sox-from-template | Profile a firm’s bespoke xlsx layout into a reusable template so the testing skills write into the firm’s own cells. |
| /sox-replay-build | Package a completed workpaper into a portable replay skill that re-runs the same test next period. |
How the engine fits together
Section titled “How the engine fits together”/sox-testing is the front door: it plans the test and delegates. Deterministic tick-and-tie work runs through /sox-python so the source, output, and a script hash land in a Procedure tab. Evidence intake depends on what you have: an xlsx of screenshots, a recorded walkthrough, a live browser session, or a mixed folder: each turns its source into annotated workpaper tabs through the same pipeline. /sox-from-template is a pre-processor for firms with their own workpaper layout, and /sox-replay-build makes a finished test repeatable next period. Inside AssureSwarm, /sox-test is the bridge that runs the whole engine on a single workflow step.
Leaf sub-agents
Section titled “Leaf sub-agents”Six leaf sub-agents keep large or semi-untrusted inputs (screenshot pixels, transcript text, finished-workpaper contents) out of the orchestrator’s context. They are workers, not commands: you never invoke them directly:
- sox-evidence-boxer: per-image pixel bounding boxes for each tested field (no value extraction).
- sox-evidence-context: per-image observed values plus ambient signals (disabled rows, status badges, error banners); runs in parallel with the boxer.
- sox-evidence-reviewer: a position-only double-check of the boxer’s rectangles.
- sox-evidence-mapper: attributes each folder-evidence image to its sample and tests.
- sox-walkthrough-parser: turns a walkthrough transcript into the timestamps of visual-review moments.
- sox-workpaper-grader: grades the finished workpaper against a rubric in a fresh context window.
Auto-judge
Section titled “Auto-judge”The orchestrator decides pass / fail / needs_human per tested attribute from the
agents’ structured output alone: the image bytes never enter its context. An automatic
verdict requires all four gates to clear: an unambiguous observed-vs-expected comparison,
a value-read confidence at or above 0.7, an ok position review, and no disqualifying
context signal (a disabled control, unsaved state, error banner, permission block, or an
inactive status badge). Anything else routes to a human; context signals escalate but
never flip a verdict on their own. Methodology calls, what counts as a deficiency,
stay with audit-support and the human reviewer.
See also
Section titled “See also”- Audit methodology: the methodology reference this engine consults.
- Coach primitives: the generic operators (document upload, item attach) the SOX bridge builds on.
- Audit plugin: overview and install.
Not audit or legal advice. Workpapers and assessments produced by these skills require review by qualified financial professionals before being relied on for SOX 404 compliance.