v1.80.0 ·
The pack nobody asked for by name
The problem
People ask for "SSAE 16 guidance, like SOC 2". SSAE 16 is the retired AICPA standard behind SOC 1 reports (replaced SAS 70 in 2011, replaced by SSAE 18 in May 2017). SOC 1 has no fixed criteria: each company writes its own control objectives. What auditors test in practice are IT general controls, and some of those overlap the SOC 2 pack's controls. Today nothing in the product says so, and a search for "SSAE 16" or "SOC 1" finds nothing.
How it could be solved
Three choices, each one picked so the product says less rather than more.
The first was not to build a SOC 1 pack. A SOC 2 report is tested against fixed criteria, so a pack can check them. A SOC 1 report has no fixed criteria: each company writes its own control objectives, and no two are the same. A pack for that would have to guess them. So the answer is a short note instead. It says what the old name means, says plainly that no SOC 1 pack exists or is planned, and maps four areas a SOC 1 auditor usually tests to the SOC 2 checks that leave related evidence. Each area also says what the checks do not cover, such as who may grant or remove user access. That gap is most of what a SOC 1 auditor tests about access, so leaving it out would have overstated the trail.
The second was to keep the note honest by test, not by care. The note marks each check as either one that leaves evidence or one that is only applied. A test reads the note, compares every mark with what the pack declares, and fails if one drifts. The guard that rejects phrases like "SOC 2 compliant" now also catches SOC 1 and SSAE claims, and it reads the note sentence by sentence, because a claim can wrap across two lines.
The third was how someone finds it. The picker has no search, so a buyer's other names for the same request are written into the SOC 2 option's hint and into the list command's output. The names live in the pack as an optional field with a length limit. A pack without it shows nothing extra, and the pack's version stays the same, so no project is offered an upgrade with nothing in it.
How AIDLC solves it
A SOC 1 note on the SOC 2 pack, so a team asked for "SSAE 16" finds the SOC 2 pack and an honest account of what it does and does not evidence for a SOC 1 auditor.
Minor, not patch: packs gain an optional asked_for_as field, and two commands print it. No
interface is removed; a pack without the field behaves as before.
Changes
packages/content/docs/hygiene-and-compliance.md— new section "SSAE 16, SSAE 18, SOC 1 and SOC 2": the names and their history, who writes SOC 1 control objectives, no SOC 1 pack, and a four-row IT general control mapping with what each row does not cover.packages/content/packs/soc2/pack.yaml—asked_for_as: [SOC 1, SSAE 16]. Pack version stays 0.2.0: the installed layer file is unchanged, so no project sees an empty upgrade.packages/cli/src/compliance/types.ts,schema.ts— the optional field, bounded (40 characters, no{{).packages/cli/src/commands/init.ts— SOC 2 picker hint names SOC 1 and SSAE 16.packages/cli/src/compliance/install.ts,commands/compliance.ts—aidlc compliance listprints the names, text and--json.- Tests: two new files, three extended (see
test-results.md). The no-claims guard now matches SOC 1 and SSAE 16/18 claims and sweeps the docs page by sentence.