A proposal evidence authority matrix is a claim-specific record of the decisions required before evidence can be used. It names the source custodian, factual validator, evidence steward, disclosure authority, commitment authority and final release approver; states what each person may decide; limits what they need to see; and binds every approval to one claim, evidence version, recipient and use. It is not a generic RACI copied from an organisation chart. One document may require several independent decisions, while one person may legitimately hold more than one role where policy permits and the consequence remains controlled.
The fictional Ravenfell Mobility Services is bidding to operate charging infrastructure for a regional electric-bus fleet. Its response draws on a live-service availability report, a restricted electrical-safety audit, a customer reference, technician records, an insurer letter, an equipment partner statement and a proposed twenty-minute incident response. The bid manager can collect the files, but cannot by that act validate every fact, release a customer name, expose security findings or promise a future response time. Sending the whole packet to a senior executive does not cure the problem. The team needs to identify which exact decision attaches to each claim and who holds that decision right.
Approve decisions, not folders. Begin with the sentence the evaluator will read and the use the buyer requires. Ask separately whether the source is authentic, the interpretation is factually sound, the proposed disclosure is permitted, any future promise is authorized and the assembled response may leave the company. Give each question to a named role with competence and delegated power, provide only the material needed for that decision, and preserve the answer against the exact version. No approval should silently borrow authority from another role.
A file does not have one owner for every purpose
Ravenfell calls the service dashboard, safety report and insurer letter “evidence,” but the label conceals different objects. The dashboard is a changing display derived from operating records. The safety report is a fixed assessment issued under restricted distribution. The insurer letter is a third party statement addressed for a defined purpose. A customer email permits one reference call. A draft service schedule proposes a future obligation. Putting the same owner column beside all five tells the team almost nothing.
Start with an approval object that a reviewer can identify. Record the evidence ID and version, the proposed external sentence or attachment, the buyer requirement, the response location, the recipient and the intended use. “Approve safety report” is too broad. “Confirm that report ES-44 supports the sentence that the offered cabinet design passed the named inspection, and permit the redacted conclusion to be attached to this tender” exposes at least two decisions: factual fit and disclosure.
The buyer may ask for evidence in a particular form. Section 22 of the UK Procurement Act 2023 allows some participation conditions to require evidence verifiable by someone other than the supplier. Current government guidance also distinguishes participation evidence from the tender assessed against award criteria. The bidder therefore maps the exact requested use before designing internal approval. An impressive document approved for marketing may still be the wrong evidence or the wrong form.
This matrix does not decide whether a source is strong, current or within claim scope. Those tests happen in their own records. It answers who may make each remaining decision and what that decision covers. The output is useful only when a later reader can tell why a name appears in a cell and what authority that name actually holds.
| Evidence use | Decision objects | Not settled by possession |
|---|---|---|
| Availability report quoted in method statement | Authenticity, metric interpretation, released wording | Whether the source is representative of the offered service |
| Redacted electrical-safety conclusion attached | Report identity, technical meaning, redaction and disclosure | Permission to expose findings or assessor marks |
| Twenty-minute response promised | Operational feasibility, resource basis, commercial commitment | Authority to bind the future service |
| Customer reference offered | Factual validation, customer permission, contact disclosure | Permission for another tender or public reuse |
Route by evidence class and proposed use, not department
Classify the evidence according to the decisions it creates. Operating records need a custodian and a domain validator. Third-party certificates need identity and scope checks, plus any conditions on reproduction. Customer material needs the customer or a contractually authorized representative for disclosure. Personnel records may require the individual, employer, privacy office or another lawful authority depending on the data and use. Partner evidence stays subject to the partner agreement. A future statement needs the function that can deliver it and the officer who can authorize the commitment.
Do not route only by document name. A penetration-test report might support a narrow sentence, answer a detailed questionnaire and be proposed as an attachment. The factual validator may be the same across all three, but disclosure can differ: the sentence may be allowed, a controlled summary may be available under confidentiality, and the full report may be prohibited. Approval attaches to the proposed disclosure, not to the report as an indivisible object.
External rules set important boundaries without assigning every internal job title. The EU procurement directive protects confidential information designated by economic operators, subject to applicable law. Data protection rules place accountability on the controller and require appropriate access and security controls. The FTC expects objective promotional claims to have a reasonable basis before dissemination. Those duties do not appoint Ravenfell's bid manager, security director or account owner. The company still has to translate the boundary into explicit decision rights.
For each evidence class, write an escalation rule before the bid becomes urgent. If a customer permission is missing, who may seek it and who can accept a no? If a technical reviewer disputes the claim, which role decides the source correction and which role decides the bid wording? If a commitment exceeds a delegation, where does it go? A matrix that names only the happy path becomes useless precisely when authority matters.
Approval does not require unrestricted access to every source
A reviewer needs enough information to make the assigned decision, not automatic possession of the entire underlying record. The operations owner may inspect event-level data and approve a bounded metric record. The bid reviewer can then receive the validated definition, value, period, limitations and stable source reference. The security reviewer can inspect the full safety report inside its controlled repository while the proposal team receives only the cleared extract. This preserves challenge without multiplying copies.
Use a review view matched to the question: controlled original for authenticity; reproducible calculation and source anchors for factual validation; redacted extract and release context for disclosure; operating model, cost and dependencies for a future commitment; assembled render and decision ledger for final release. Least privilege applies to read access as well as editing. NIST CSF 2.0 places roles, responsibilities and authorities inside governance, while ICO accountability guidance expects access to be limited and documented.
A verification outcome must remain inspectable. “Security approved” is too weak because no later reviewer can tell whether security validated the factual claim, cleared the wording or allowed the attachment. Record the question asked, source version inspected, result, limits, reviewer and expiry. Where policy permits, retain a checksum or repository locator rather than copying the restricted file into the bid workspace. The evidence steward can then prove that the decision concerned the same object.
The pattern is not a way to hide adverse facts from decision-makers. If a limitation changes what the claim means, the factual and release approvers need the limitation even when they do not receive raw sensitive data. A bounded review view protects the source while preserving the information material to the decision. It should never turn “restricted” into “assume true.”
| Decision | Minimum useful view | Material that can stay restricted |
|---|---|---|
| Validate availability claim | Metric definition, calculation, population, period, exceptions and source anchors | Customer-level event rows not needed for the conclusion |
| Clear safety disclosure | Full report in controlled viewer plus exact proposed extract | Findings unrelated to the offered design |
| Approve customer reference | Permission text, named contact fields, tender recipient and call purpose | Unrelated account correspondence |
| Approve response-time promise | Staffing, geography, dispatch model, dependencies, cost and exception wording | Personal scheduling records beyond the capacity decision |
A green claim needs all applicable decisions, not one senior signature
Use explicit states that show what remains. An evidence use can move from unowned to source_access_confirmed, fact_validated, disclosure_cleared, commitment_approved and release_approved. Not every claim needs every state: a public historical certificate may require no special disclosure decision, while a purely historical claim has no future commitment. Mark a decision not_applicable with a reason instead of silently skipping the field.
Negative states are equally important. Rejected means a competent authority decided against the use. Blocked means the necessary authority or information is unavailable. Expired means a former decision no longer covers the current use. Superseded means a newer evidence or claim version governs. None can be converted to approved because the deadline is close. The GAO Green Book and the Orange Book both emphasize clear responsibility, appropriate authority and documentation within an effective control environment.
Sequence reviews when one answer changes another. Factual validation comes before asking a customer to permit a statement that may still be wrong. Disclosure clearance precedes placing the restricted extract in the assembled response. Feasibility analysis comes before commercial commitment. Final release follows reconciliation of the actual files. Parallel review is possible when dependencies are explicit, but a downstream approval must reopen if its input changes.
Ravenfell initially receives a managing director approval on a folder containing seven evidence items. The matrix still shows two blocked cells: no customer permission covers disclosure of a depot contact, and the twenty-minute promise exceeds the service director's delegated level. The executive signature does not silently fill either gap. The team removes the contact pending permission and routes the proposed commitment to the authorized commercial committee.
A deputy inherits only documented authority, not someone else's inbox
Names in a matrix become stale. Verify the authority source and its effective period: board or management delegation, contract owner assignment, data governance policy, customer permission, partner agreement, job mandate or tender-specific decision. Record thresholds, excluded subjects and any requirement for joint approval. A senior title indicates organizational position, not the exact power to disclose another party's information or accept a contractual obligation.
Prepare deputies before absence. The substitute must have the same decision right for this subject and consequence, or the workflow must escalate elsewhere. Forwarded email, shared account and temporary system access prove availability, not authority. French and German civil-law provisions on representation illustrate a broader point: acts bind an organization through powers that actually cover the act. The applicable corporate law, constitutional documents and local advice determine the legal result; a proposal matrix should expose the question rather than improvise an answer.
Conflicts also matter. A claim author may have designed the metric or negotiated the promise and still provide valuable input, but a high consequence approval may need someone able to challenge it independently. NIST separation-of-duties guidance focuses on preventing incompatible functions and conflicts. The local policy should define when self-approval is allowed, when a second pair of eyes is required and who decides an exception.
If nobody holds the required power, classify the use as unowned or blocked. Do not nominate the most senior available person after the fact. Management can create or confirm a delegation through the proper governance route, the customer can grant a permission, or the claim can be narrowed or removed. The deadline changes the available choices, not the underlying authority.
Approval travels with a version and a use, not with a topic
Bind each decision to the source identity and version, the exact claim text, the evidence extract or attachment, the language, the recipient, the channel and the decision time. A factual approval for “99.94% charger availability from July 2025 through June 2026” does not cover “more than 99.9% availability across our fleet” or a translated statement that drops the period. A customer permission for a reference call does not authorize publishing the name in a case study.
Reopen rules follow the decision that changed. A corrected source or changed metric definition reopens factual validation. A new attachment, recipient, public channel or customer instruction reopens disclosure. A different service level, remedy, price assumption, territory or subcontractor reopens commitment. A new assembled version reopens final reconciliation even where component approvals remain valid. Record which prior decisions can carry forward and why.
The evidence steward maintains the relationship without deciding the substance. W3C PROV provides useful concepts for entities, activities, agents, roles, derivation and delegation. The matrix can use simpler fields, but it should still distinguish the report from the calculation that produced it, the reviewer from the role they held, and the approval from the artifact it generated. That makes a superseded decision traceable without presenting it as current.
Do not approve a mutable link without capturing the viewed state. Record a controlled document version, signed statement, system snapshot or reproducible query according to policy. If the evidence must remain live, record the verification time and the event that requires another check. The aim is not to freeze reality. It is to prevent a later green badge from pointing at materially different evidence.
The final approver receives a decision ledger, not a pile of initials
Before release, render the response exactly as the buyer will receive it. Reconcile every material claim occurrence, table, image, appendix, filename, document property and translated version against the matrix. Show the final approver the buyer requirement, claim, evidence reference, applicable decisions, remaining limits and any blocked item. The source itself can remain in its controlled repository when the ledger provides an inspectable verification trail.
The final approver checks completeness of authority and accepts the residual release decision within their mandate. They do not retroactively validate a metric they cannot assess, grant a customer permission they do not hold or authorize a commitment beyond their delegation. SEC disclosure-control rules concern a different regulatory setting, but their design lesson is useful: relevant information must reach the people responsible for a timely disclosure decision. A signature without that flow of information is weak control.
Ravenfell's final ledger contains seven rows. The availability claim is fact_validated and release_approved with its period intact. The safety extract is disclosure_cleared for the tender portal, while the full report remains restricted. The customer contact is removed because permission did not arrive. The insurer letter is attached under its stated purpose. The partner statement is approved only for the named equipment. The response-time commitment has authorized wording and dependencies. An obsolete roadmap sentence is marked superseded and absent from the render.
Archive the ledger, exact submitted files, source locators and decisions under the organization's records rules. Preserve rejected and superseded rows long enough to explain the submission, but do not use the proposal workspace as an uncontrolled archive of customer or security material. The complete result is not “all evidence approved.” It is a bounded account of which claims were released, on what authority, with which evidence and under which limits.
| Use | Factual decision | Disclosure or commitment decision | Release result |
|---|---|---|---|
| 99.94% charging availability | Validated for named network and period | Internal metric wording cleared | Approved with period and exclusions |
| Electrical-safety conclusion | Validated against report ES-44 | Redacted extract cleared for this portal | Extract attached; full report withheld |
| Named depot reference | Project facts validated | Customer permission blocked | Name and contact removed |
| Twenty-minute incident response | Feasible under stated staffing model | Commitment approved with dependencies | Approved exact wording used |
What good looks like
Useful outcomes from proposal evidence approval matrix
- Every material proposal claim has one identifiable evidence item and buyer-facing use.
- Source custody, factual validation, disclosure permission, commitment authority and final release are recorded as separate decisions.
- Each decision is assigned to a named person or defined office with a verified delegation and deputy.
- Reviewers receive the minimum evidence necessary for their decision rather than unrestricted copies by default.
- Customer, partner, personal, security and commercially sensitive material retains its original access conditions.
- Approvals cover exact source and claim versions, a recipient, a channel, a language and an expiry or review trigger.
- Unowned, rejected, expired and superseded evidence remains visible and cannot be treated as approved by silence.
- The final release packet shows which decisions are complete without exposing the protected source itself.
Operating model
How to run the work
- 01
Freeze the proposed use
Record the buyer question, exact proposed sentence, evidence item, response location, recipient, channel and consequence before asking anyone to approve it.
- 02
Classify the evidence boundary
Identify who created and controls the source, what access or contractual limits apply and whether the use involves personal data, customer material, security information or a future promise.
- 03
Split the required decisions
Separate authenticity, factual interpretation, disclosure, commitment and final release. Do not put a single approval field beside the file.
- 04
Verify the actual authority
Name the person or office entitled to make each decision and check the applicable policy, delegation, contract, consent or power rather than relying on seniority or availability.
- 05
Design the review view
Give each reviewer the minimum necessary material, such as a controlled original, redacted extract, calculation record or bounded verification result.
- 06
Record exact decisions
Capture approve, approve_with_limits, reject or escalate with the source version, claim wording, conditions, reviewer, time and rationale.
- 07
Reconcile the release packet
Confirm that every material occurrence uses the approved wording and that no attachment, metadata, translation or summary exceeds its permission.
- 08
Expire and reopen deliberately
Reopen after a changed fact, source revision, new recipient, wider channel, altered promise, revoked permission, changed delegation or material edit.
Evaluation
Questions that change the decision
- What exact proposition and evidence version is being approved for which buyer use?
- Who controls the original record, and does custody include any right to disclose it?
- Who is competent and accountable to validate the fact or interpretation?
- Does the claim contain a present fact, historical result, third-party statement or future commitment?
- Whose permission is required for customer, partner, personal, security or licensed information?
- Which role can bind the company to the proposed service, price, roadmap or remedy?
- Can a reviewer decide from a redacted extract or verification outcome instead of the raw source?
- What policy, delegation, contract or consent establishes each authority?
- What change in wording, evidence, audience or context invalidates the decision?
- Who makes the final decision when an authority is absent, conflicted or disputed?
Failure modes
Where teams lose control
Treating the person who can open a system as the owner of every fact in it
Letting a subject-matter expert authorize disclosure or commercial commitments outside that role
Using executive seniority as a substitute for a valid delegation or customer permission
Asking reviewers to approve a whole folder without showing the exact external statement
Circulating customer or security records to every approver when a bounded verification would suffice
Treating a certificate as permission to quote its contents or logos in any channel
Allowing silence, elapsed time or a workflow status to become approval
Applying approval of one language, recipient or tender to another context
Keeping a green status after the source, claim, delegation or permission changes
Assuming software can infer who has legal or contractual authority from a job title
Measurement
Measure the finished job
Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.
- Percentage of material claims with all applicable authority decisions named
- Number of evidence items still marked unowned before final review
- Median time from evidence intake to factual and disclosure decisions
- Percentage of restricted reviews completed without copying the full source
- Number of approval requests returned because claim or source version was missing
- Count of future commitments routed to verified commitment authority
- Number of approvals reopened by a material change before submission
- Number of unauthorized claim occurrences found during release reconciliation
- Percentage of deputies whose authority was verified before an absence occurred
Questions
Common questions
Should the bid manager own all proposal evidence?
The bid manager can own coordination and closure. That does not usually grant authority to validate every specialist fact, release customer material or bind the company to every future commitment. Record those decisions separately.
Is the source owner also the claim approver?
Not automatically. A source custodian can identify the controlled record, while a domain owner validates interpretation and another role authorizes external wording. Combine roles only where the actual mandate and risk allow it.
Does legal need to approve every evidence item?
No. Define legal or compliance triggers such as unusual contractual representations, personal data, third-party restrictions, disputed rights or regulated claims. Routine factual validation should remain with competent business owners unless policy requires more.
Can customer-confidential evidence support a proposal claim?
Potentially, but access to the source and disclosure to the buyer are separate decisions. Use the least revealing inspectable form, keep the source controlled and obtain the permission required for the exact recipient and use.
Can one executive approval cover the entire proposal?
It can serve as final release only if the executive has that mandate and the component factual, disclosure and commitment decisions are complete. Seniority does not supply missing customer permission or specialist validation.
What if an approver is away near the deadline?
Use a deputy whose authority was established in advance or follow the defined escalation. Access to the absent person's inbox is not delegation. If authority cannot be obtained, narrow, remove or block the claim.
When must an evidence approval be repeated?
Reopen the relevant decision after a material source, claim, translation, recipient, channel, permission, commitment, delegation or context change. Do not repeat unrelated approvals when their bounded inputs remain identical.
Can software assign and approve proposal evidence?
Software can classify likely decisions, route tasks, enforce access and detect stale or missing states. It should not invent delegations, infer customer consent from silence or release a material claim when the competent authority remains unresolved.
Sources
Primary references
- The Green Book: Standards for Internal Control in the Federal Government United States Government Accountability Office
- OMB Circular A-123, Management's Responsibility for Internal Control United States Office of Management and Budget
- NIST SP 800-53 Rev. 5, Security and Privacy Controls National Institute of Standards and Technology
- The NIST Cybersecurity Framework 2.0 National Institute of Standards and Technology
- Data ownership model UK Government
- The Orange Book: Management of Risk HM Treasury
- The AQuA Book: guidance on producing quality analysis UK Government Analysis Function
- Procurement Act 2023 UK Parliament
- Guidance: Conditions of Participation UK Cabinet Office
- Federal Acquisition Regulation Part 15 United States General Services Administration
- FTC Policy Statement Regarding Advertising Substantiation United States Federal Trade Commission
- Guides Concerning the Use of Endorsements and Testimonials United States Federal Trade Commission
- Certification of Disclosure in Companies' Quarterly and Annual Reports United States Securities and Exchange Commission
- Evaluation of Corporate Compliance Programs United States Department of Justice
- General Data Protection Regulation European Union
- Directive 2014/24/EU on public procurement European Union
- Guidelines 07/2020 on controller and processor concepts European Data Protection Board
- Guide to accountability and governance Information Commissioner's Office
- Accountability principle Information Commissioner's Office
- PROV-O: The PROV Ontology World Wide Web Consortium
Ziva
Proposal software for source-grounded RFP, RFI, DDQ and questionnaire response work.
Bid, proposal, presales, security and compliance teams. Start with the workflow, constraints and evidence you already have.