{
  "kind": "illustrative_example",
  "schema_notice": "Explanatory sample, not the production export schema. No live tenant data.",
  "identity": {
    "name": "Jordan Lee",
    "type": "user"
  },
  "before": {
    "direct_directory_role": "Global Administrator"
  },
  "decision": {
    "action": "remove_directory_role_assignment",
    "approved_by": "Alex Morgan (example)"
  },
  "provider_result": "accepted (illustrative)",
  "verification": {
    "method": "read role assignment state from Microsoft Graph",
    "result": "assignment absent (illustrative)",
    "scope": "one direct role assignment"
  },
  "limitations": [
    "Other roles and group memberships require separate review.",
    "Issued tokens and active sessions are not verified by this check.",
    "This sample is not an independent attestation or compliance certification."
  ]
}
