On this page
- The product, release and evidence scope come before the findings.
- A source observation and an approved conclusion are different records.
- A useful result makes the next unanswered question easy to find.
The fictional product and the review boundary
Consider a small team shipping Harbour Notes, a desktop application with an update service. It wants to review release 1.4. The team has a source revision, a dependency lockfile, a security contact policy and some release instructions. It has not yet settled every support or reporting decision.
Those facts are invented for this walkthrough. The rows below are an editorial example, not output from running the ConformOps engine, and they do not determine the product's legal scope or classification. That distinction matters: a realistic looking table is not evidence that any analysis took place.
What the evidence says and what it leaves open
Read each row from left to right. The observation is deliberately narrower than the question the manufacturer ultimately needs to answer.
| Supplied record | Observation | Still unanswered |
|---|---|---|
| Security contact policy | A route for reporting a vulnerability is documented | Who monitors it and how the team has tested the process |
| Dependency lockfile | Some component versions are recorded | Whether the inventory covers the delivered product |
| Release instructions | The update process is described | What testing supports the security of that process |
| Product facts | A support commitment has been proposed | Its rationale, approved dates and what users are told |
Follow one gap to a useful next action
The first row does not need a slogan or another score. It needs the person responsible for vulnerability intake to show how reports are handled. A useful next action is to locate the triage procedure and the record of an exercise, then compare them with the contact route supplied for this release.
If the procedure does not exist yet, record that honestly and assign the work. If it exists elsewhere, add the relevant evidence through the supported workflow. If a decision is required, an authorised person must review and record it. Uploading a document should not impersonate that decision.
The guide to getting unstuck helps you choose between product support, an evidence owner and a qualified adviser.
What would happen after the inputs change?
Suppose the team replaces its supplied inventory after finding that the original omitted a component. An earlier assessment would still describe the inputs it actually used. The new document should not silently change the meaning of that old run.
ConformOps keeps the newest attempt separate from the completed baseline and makes relevant stale input conditions visible. A fresh assessment can examine the changed material. This is why a report needs release and run identity, and why an old approval should not simply follow a changed input set.
Download the example and ask better demo questions
The fictional walkthrough as JSON contains the same illustrative records and their limitations. It is an educational data file, not an actual ConformOps export format, SBOM or assessment result. You can also use the blank evidence worksheet to write down your own questions.
When evaluating a real tool, ask it to show one requirement from input to evidence reference to open decision. Ask what happens when the lookup fails or the source changes. Finally, ask to inspect the files you can export and the access you keep when coverage ends. Those questions reveal more than a tour of dashboard colours.
If you want to see the workflow with your own authorised material, the Free preview is the next step. Complete paid outputs are broader than that limited preview, but neither is a legal conclusion or a substitute for the applicable conformity assessment.
Frequently asked questions
Is this a real customer's CRA assessment?
No. Harbour Notes and all observations on this page are fictional teaching examples. They are not customer evidence or output from an executed ConformOps assessment.
Can I see the example without giving an email address?
Yes. This page, the fictional JSON walkthrough and the blank worksheet are public downloads. An account is needed to run a preview with your own material.
What should I look for in a CRA software demo?
Look for a named input scope, traceable observations, explicit missing information, human decision boundaries and usable exports. Ask to see a failure state and what happens when an input changes.