The argument
Ten Citations. One Screenshot.
One artifact may support several claims, but each use must identify the distinct fact it proves and the gaps it cannot fill; repetition is not independent corroboration.
The field pattern
A dashboard export appears in the access review, monitoring, vulnerability, change, and incident evidence folders. Each package points to the same green summary. None explains which control objective, population, period, method, review, or exception detail the image establishes for that particular claim.
Why it matters
Evidence Echo inflates apparent coverage while concentrating assurance in one observation. If the artifact’s population, method, timing, or interpretation is weak, the same weakness silently propagates across every claim that cites it.
Reuse can be efficient when it is deliberate. Record one canonical artifact, map each supported fact separately, attach supplemental evidence where necessary, and make dependency on the shared source visible.
Questions that expose the Wack
- How many unique observations sit behind the evidence citations in this package?
- What exact fact does this artifact prove for each control objective?
- Which claims depend on interpretation or supplemental population, operation, review, or exception evidence?
- If the shared artifact were invalid, how many conclusions would change?