Skip to content

Agent Operating Guide

SOX engine

The Audit plugin's script-backed SOX 404 fieldwork engine: plan a control area's testing, run deterministic procedures, and turn screenshot, video, live-web, or mixed-folder evidence into reviewably annotated workpapers.

The sox family is a script-backed engine for SOX 404 control testing. /sox-testing orchestrates a control area’s testing for a period; helper skills make deterministic work reproducible and turn image, video, live-web, or mixed-folder evidence into reviewably annotated workpapers; six leaf sub-agents keep evidence bytes out of the orchestrator’s context; and a rubric-driven grader scores the finished workpaper in a fresh context window.

Skill What it does
/sox-testing Plan and drive one control area’s testing for a period, control matrix, sample sizing and selection, annotated workpaper, deficiency evaluation, and self-grade at the end.
/sox-test The AssureSwarm bridge: operate one SOX control-testing workflow step: pull the control, run the engine, upload the workpaper, and propose the results for review.
/sox-python Run a deterministic procedure as code (sample draw, three-way match, recomputation, threshold check) and append a reproducible Procedure tab with source, output, runtime, exit code, and a SHA-256.
/sox-annotate-xlsx Turn an xlsx of embedded evidence screenshots into annotated workpaper tabs with movable red-rectangle shapes over each tested field.
/sox-from-video Turn a recorded walkthrough plus transcript into annotated frames, boxed per tested field.
/sox-from-web Collect evidence live from the audited system through Claude for Chrome, read-only, then annotate and assemble.
/sox-from-folder Turn a mixed evidence folder into an annotated workpaper, hashing every file for custody and mapping each image to its sample and tests.
/sox-from-template Profile a firm’s bespoke xlsx layout into a reusable template so the testing skills write into the firm’s own cells.
/sox-replay-build Package a completed workpaper into a portable replay skill that re-runs the same test next period.

/sox-testing is the front door: it plans the test and delegates. Deterministic tick-and-tie work runs through /sox-python so the source, output, and a script hash land in a Procedure tab. Evidence intake depends on what you have: an xlsx of screenshots, a recorded walkthrough, a live browser session, or a mixed folder: each turns its source into annotated workpaper tabs through the same pipeline. /sox-from-template is a pre-processor for firms with their own workpaper layout, and /sox-replay-build makes a finished test repeatable next period. Inside AssureSwarm, /sox-test is the bridge that runs the whole engine on a single workflow step.

Six leaf sub-agents keep large or semi-untrusted inputs (screenshot pixels, transcript text, finished-workpaper contents) out of the orchestrator’s context. They are workers, not commands: you never invoke them directly:

  • sox-evidence-boxer: per-image pixel bounding boxes for each tested field (no value extraction).
  • sox-evidence-context: per-image observed values plus ambient signals (disabled rows, status badges, error banners); runs in parallel with the boxer.
  • sox-evidence-reviewer: a position-only double-check of the boxer’s rectangles.
  • sox-evidence-mapper: attributes each folder-evidence image to its sample and tests.
  • sox-walkthrough-parser: turns a walkthrough transcript into the timestamps of visual-review moments.
  • sox-workpaper-grader: grades the finished workpaper against a rubric in a fresh context window.

The orchestrator decides pass / fail / needs_human per tested attribute from the agents’ structured output alone: the image bytes never enter its context. An automatic verdict requires all four gates to clear: an unambiguous observed-vs-expected comparison, a value-read confidence at or above 0.7, an ok position review, and no disqualifying context signal (a disabled control, unsaved state, error banner, permission block, or an inactive status badge). Anything else routes to a human; context signals escalate but never flip a verdict on their own. Methodology calls, what counts as a deficiency, stay with audit-support and the human reviewer.

Not audit or legal advice. Workpapers and assessments produced by these skills require review by qualified financial professionals before being relied on for SOX 404 compliance.