Whether a control description is substantively adequate against SOX or another framework is a judgement no rules engine can make. A field-presence check is trivial; assessing adequacy is the actual requirement, and it is what an external auditor will do.
Every draft and every adequacy assessment, reviewed by a compliance professional.
Conclude that a control is compliant. Output is advisory — it may say documentation appears to address a requirement, never that it satisfies one.
Existing control descriptions; framework requirements; prior audit findings; test procedures and results
Drafted or revised control documentation, plus an adequacy assessment naming specific gaps
The domain supports the pattern and no vendor in this model sells it. That is a statement about the market rather than about the pattern; v_agent_gaps lists them.