# Explainer script — Compliance starts before the auditor arrives

- Article: thought-leadership/compliance-before-the-audit
- Target runtime: about four minutes; measured narration determines the final runtime
- Companion deck: `explainer.html`

A person renders and uploads the finished video, then supplies the YouTube URL for the article’s `video` metadata.

## Runtime

Nine scenes follow one illustrative change into the next export change. The spoken track has 511 words. At 140 words per minute, with a one-second pause per scene, the estimate is 228.0 seconds; a 10% slower take is about 252.3 seconds. These are authoring estimates, not measured audio. The renderer replaces them with measured narration durations.

## Scenes

| # | id | Narration | On-screen beats | Words | ~sec (est) |
|---|---|---|---|---|---|
| 1 | change | Imagine asking a coding agent to restrict customer exports to workspace admins. It could hide the export button, while leaving the server open to anyone who sends a request. How would your team spot that? Assay helps organise the work and the evidence behind it. Let’s follow this example from the request to the release. | Why keep evidence of a change? A coding agent can change the feature. The team still needs evidence that the permission rule works. | 55 | 24.6 |
| 2 | intent | First, make the request precise. An admin must be able to export. Everyone else must be denied, even if they bypass the button and contact the server directly. In Assay, you write these conditions in a brief: a work order that tells the agent what to build and tells the checker what to test. | Describe what must work. Write both cases into the work order: admins can export; non-admins cannot, even through a direct request. | 54 | 24.1 |
| 3 | authority | The agent then proposes a code change. A separate reviewer asks whether it actually enforces the rule on the server. That gives the team a chance to catch a hidden button with an unprotected endpoint. The human keeps the merge decision. Separate permissions support that separation; a second agent alone doesn’t guarantee a good review. | Challenge the implementation. A separate reviewer checks the permission boundary. The human retains the merge decision. | 55 | 24.6 |
| 4 | verification | After merge, someone who didn’t implement the change checks it on the main branch. Can the admin export? Is the direct non-admin request denied? Assay can record the code version, command and an output fingerprint. Keep the output too, so someone can read the result. If a check cannot run, record that gap. | Keep a check you can inspect. Check the merged code. Retain the tested revision, command and output, including any check that could not run. | 53 | 23.7 |
| 5 | cabinet | We now have a request, a review, a check and a decision. We call that linked collection an evidence cabinet. Think of a filing cabinet for the change, where each drawer answers a question. Human design choices go into dated decision records in the repository, linked to their ruling. The cabinet connects these sources so someone can inspect the story. | What is an evidence cabinet? The cabinet links the request, review, check, human decision record and release scope. | 60 | 26.7 |
| 6 | pack | When you release, Assay’s exporter can collect the declared requirements, work orders and linked evidence into a downloadable pack. Its report shows where work is incomplete or a link is missing. Think of the pack as a snapshot of the declared delivery records. Collecting them doesn’t prove the tests were sufficient. The article includes a real fixture pack you can inspect. | Take a snapshot for a release. A release pack collects the declared requirement, brief and linked evidence. Its report keeps gaps visible. | 61 | 27.1 |
| 7 | memory | A month later, someone adds an export format. The admin-only requirement still matters. Today, the team must find the earlier decision and requirement, link them in the new brief, and carry the denied request into its checks. The previous result belongs to the previous code. Assay’s records support that handoff; it doesn’t automatically find every applicable rule. | A month later, the rule still matters. Today: find and link the decision and requirement in the new brief. Check the new revision; the old result stays historical. | 57 | 25.4 |
| 8 | plans | The next step is to make that recall dependable. We’re proposing a query for humans and agents: what decisions and requirements apply to exports? It should return the sources, unresolved conflicts and rules that were replaced, and feed applicable constraints into the next work order. This is feature work, not today’s automation. Source applicability and follow-up records are also planned. | Make the next work remember. PROPOSED: query applicable decisions and requirements, then carry them into later work. Source applicability and follow-up records are planned. | 60 | 26.7 |
| 9 | everyday | That cabinet helps the next engineer preserve the original permission boundary, as well as investigate an export problem. It’s useful even without SOC 2 obligations. Assay doesn’t confer certification; it helps make decisions inspectable. Start with one consequential change: record the human choice, link the requirement, and carry both into the next change with fresh checks. | Useful on the next change. Keep the human choice and standing requirement connected to later work, with fresh checks. | 56 | 25.0 |

## Notes for the recording

Use a conversational delivery. Each scene answers the question raised by the previous one; do not read the on-screen labels as a list. Pause before the cabinet definition and let the viewer inspect its questions. “Evidence cabinet” is a filing-cabinet metaphor for linked records in the repository and code host, not a separate product screen or a new storage service.

Keep the persistent Illustrative label on every frame. The admin-only export is an authored teaching example, not a captured run. The fixture pack in the article is a separate exporter-generated example. Scene seven shows the current manual record-linking handoff; scene eight labels proposed recall and carry-forward automation. Show a fresh check for the later revision, without fabricating a result. The original requirement remains the owner’s continuing constraint; a prior delivery marked done is not an exception to it.

The recording source is `blog/video/compliance-before-the-audit/explainer-gsap.html`, authored at 1920 × 1080. Its nine scene IDs match this table. Use the recording source, rather than the chapter player, for MP4 production.

The renderer uses the full narration as subtitle text. Before upload, split its one-cue-per-scene captions into readable segments and check their alignment against the actual voice take. A paragraph held on screen for a whole scene is not a finished caption treatment. No audio, caption alignment or audience comprehension test has been performed here.
