{"uid":"cap_vO_BqRegymO_zGdAEUZ6K","slug":"control-evidence-gap-finder-e684aa36","name":"Control Evidence Gap Finder","description":"Find missing or stale declared evidence before a governance review. Compare up to 40 control requirements with revision- and scope-bound evidence descriptors. Does not inspect evidence contents, evaluate control effectiveness or certify compliance.","url":"https://www.mahastrategies.com/api/v1/micro/control-evidence-gaps","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object","required":["dataClass","policyDigest","requirements","evidence"],"properties":{"evidence":{"type":"array","maxItems":80,"minItems":0},"dataClass":{"enum":["public","synthetic"],"type":"string"},"policyDigest":{"type":"string","maxLength":71},"requirements":{"type":"array","maxItems":40,"minItems":1}},"additionalProperties":false},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","required":["version","offerId","amountBaseUnits","inputDigest","result","boundaries","receiptDigest"],"properties":{"result":{"type":"object"},"offerId":{"enum":["control-evidence-gaps"],"type":"string"},"version":{"enum":["maha-microproducts/0.1"],"type":"string"},"boundaries":{"type":"array","maxItems":128,"minItems":0},"inputDigest":{"type":"string","maxLength":71},"receiptDigest":{"type":"string","maxLength":71},"amountBaseUnits":{"enum":["19000"],"type":"string"}},"additionalProperties":false}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.019","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"registry","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.019/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.019","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.019","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_a1sMktKveQXOo9JPQwc3R","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.019","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Identifies missing or stale evidence items for up to 40 control requirements before a governance or compliance review, comparing requirements against revision- and scope-bound evidence descriptors.","exampleAgentPrompt":"Before our governance review next week, check these 12 control requirements against our current evidence list — use public data class and this policy digest 'sha256:abc123def456' — and tell me which controls have missing or stale evidence.","exampleUseCases":[{"title":"Pre-audit SOC 2 evidence check","prompt":"We have an upcoming SOC 2 audit and I need to know which of our 30 control requirements are missing evidence or have stale evidence — can you run a gap check using our policy digest and synthetic data class and flag anything that's undocumented?"},{"title":"Quarterly governance review prep","prompt":"Before our quarterly governance review, compare these 20 control requirements against our declared evidence descriptors — data class is public, policy digest is 'sha256:9f8e7d6c5b4a' — and list which controls have no matching or out-of-date evidence."},{"title":"Post-revision evidence coverage check","prompt":"We just revised our security policy and I want to make sure evidence is still aligned — check these 15 control requirements scoped to the new revision using policy digest 'sha256:1a2b3c4d5e6f' and tell me what's missing or stale."}],"resultDescription":"Returns a structured result identifying which control requirements have missing or stale evidence, along with boundary metadata (up to 128 items), an input digest, offer ID, version, and receipt digest for auditability. Does not evaluate control effectiveness or certify compliance.","failureModes":["More than 40 requirements submitted — request rejected due to maxItems constraint","Evidence array exceeds 80 items — request rejected","Invalid or missing policyDigest — validation error","Unsupported dataClass value — must be 'public' or 'synthetic'","Malformed bodyType — must be 'json', 'form-data', or 'text'","Payment not processed — x402 payment required before response"],"whenToPreferThis":"Choose this endpoint when you need a lightweight, reproducible pre-review check for evidence gaps across a defined set of control requirements, bounded by a specific policy revision and scope. It is ideal for automated pre-audit pipelines, governance prep workflows, or compliance readiness checks where you want a fast, deterministic gap report without requiring full evidence content inspection or effectiveness evaluation.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:42:47.078Z","isFirstParty":false}