Prove and Report
Answer the negative question for a customer, then hand over the answer, the census behind it and the identity checks.
On this page (7)
Prove and Report Documentation
Prove answers the negative question: which of a customer's endpoints did not reach a named set of infrastructure, over a window you choose. This walks one question through to the document you hand over.
Step 1: name the infrastructure and the window
Enter the destinations the customer is asking about, and the window the question covers.
Record both the way the question was asked. The infrastructure and the window are the question, and an answer about a different window is an answer to something nobody asked.
Step 2: run it and read the census first
The answer comes back as the endpoints that did not reach any of it, with the census it rests on underneath.
Read the census before the answer. It states what the negative claim is made over, and a negative claim is only as good as the population behind it.
Step 3: check one endpoint's identity yourself
Evidence takes a single endpoint and shows the public checks behind its identity, each beside the command that reproduces it. Run one while you are there, so the document you are about to send says something you have watched answer:
dig -x 2a04:2a01:b69a:6717:e3b0:51ff:3bf7:f478 +short
The customer can run the same command. That is the point of publishing the identity in public DNS and the public registry: the claim does not rest on your screenshot. Verify an identity is the page to include beside it.
Step 4: put the answer in a report
Reports turns the answer into a client-facing document. The response record is the type that carries what was asked, what was found and what was done about it.
Reports also publishes, schedules a repeat, delivers, and renders a PDF, so a question that will be asked again every period is answered once and then arrives on its own.
Step 5: brand it before it leaves
Brand holds your firm's logo, colour and attribution line, and every artifact the portal produces picks them up. Set it once for the firm rather than per document.
What you should see
The answer names endpoints rather than counting them, and the census stands beside it.
If an estate you expected is missing, check the grant before anything else: an estate you hold no key for is reported as ungranted rather than as nothing reached, and customer keys and grants explains why the portal refuses to let those two look alike.
Where this sits
Proving what did not happen is one half of the record. The other half is who did what, and how much of a framework the book covers; both are in audit and compliance. The actions a report describes are dispatched from a case, which is where their outcomes were written down in the first place.