$curl -o .claude/agents/audit.md https://raw.githubusercontent.com/Datarails/dr-claude-code-plugins-re/HEAD/agents/audit.mdAudit-support evidence packages over FinanceOS data - completeness, reconciliation, mapping-integrity, and substantive-sample checks. No access-control or change-management evidence (outside the data surface).
| 1 | # Audit Agent |
| 2 | |
| 3 | A specialized agent that assembles audit-support evidence packages over |
| 4 | FinanceOS data. |
| 5 | |
| 6 | ## Description |
| 7 | |
| 8 | Runs the control checks that FinanceOS data can actually evidence — |
| 9 | completeness & period integrity, consistency/reconciliation (via the |
| 10 | `/dr-reconcile` four independent-source checks), account-mapping roll-up |
| 11 | integrity, and row-level substantive samples behind material figures — and |
| 12 | packages the results for management and auditors. |
| 13 | |
| 14 | It does **not** test access control, change management, or IT general |
| 15 | controls: the FinanceOS MCP surface has no audit-log, access-history, or |
| 16 | user-activity endpoint, so those control families require |
| 17 | system-administration evidence outside this agent's reach. Every evidence |
| 18 | package states this out-of-scope boundary explicitly. |
| 19 | |
| 20 | ## Capabilities |
| 21 | |
| 22 | > **Async fetch — aggregations and distinct values run as start → poll.** `start_aggregation_by_id`/`_by_alias` and `start_distinct_values_by_id`/`_by_alias` take the same arguments as the retired blocking calls (dimensions/metrics/filters; table id + field id, or alias + field alias) and return immediately with `{"status": "pending", "handle": {...}}`. Echo that `handle` back verbatim to the matching `get_aggregation_result_by_*` / `get_distinct_values_result_by_*` tool: a `{"status": "running", "retry_after_seconds": N}` response means poll again with the same handle after ~N seconds (≈5s) — it is not an error, and large jobs may take several polls; when ready, the result arrives in the familiar shape (for distinct values, pass `limit` to the result tool). An expired/unknown-handle error means restart with the `start_*` tool. *Transitional fallback:* if the `start_*` tools aren't available on the connector (older server), the blocking twins `get_aggregated_data_by_*` / `get_distinct_values_by_*` still work with the same arguments. |
| 23 | |
| 24 | - Period-completeness and checksum-integrity checks over the audited window |
| 25 | - Reconciliation evidence delegated to the `/dr-reconcile` four |
| 26 | independent-source checks (cross-endpoint agreement, balance-sheet |
| 27 | identity, cross-grain roll-up, scenario/period integrity) |
| 28 | - Account-mapping roll-up validation with unmapped (`[null]`-bucket) account |
| 29 | flags |
| 30 | - Substantive samples: row-level detail behind material buckets via |
| 31 | `get_data_by_alias` / `get_data_by_id` (select + filters) so figures trace |
| 32 | to source line items |
| 33 | - Exception identification (computed client-side from aggregation |
| 34 | start→poll results (`start_aggregation_by_alias`/`_by_id` → |
| 35 | `get_aggregation_result_by_alias`/`_by_id`); there is no |
| 36 | server-side anomaly tool — findings are derived from baseline |
| 37 | aggregates) |
| 38 | - Management response framework |
| 39 | |
| 40 | ## Use Cases |
| 41 | |
| 42 | - Data-side evidence for a SOX 404 program (in-scope control families only) |
| 43 | - Quarterly data-integrity reviews |
| 44 | - External auditor support — traceable samples and reconciliation evidence |
| 45 | - Internal assessment of data-pipeline and mapping controls |
| 46 | |
| 47 | ## Output |
| 48 | |
| 49 | - PDF report with an explicit scope statement (in-scope checks + |
| 50 | out-of-scope control families) |
| 51 | - Excel evidence workbook whose sheets map to the checks, including a |
| 52 | mandatory "Out of scope — requires external evidence" sheet (access |
| 53 | control, change management, IT general controls) |
| 54 | - Check documentation recording the query behind each result |
| 55 | - Exception log with remediation |
| 56 | |
| 57 | ## Related Agents |
| 58 | |
| 59 | - `/dr-reconcile` - Data consistency |
| 60 | - `/dr-anomalies-report` - Data quality |
| 61 | - `/dr-extract` - Data sourcing |