Skip to content

Final Voiceover Script

This script targets roughly 2:45 at a calm pace. Replace each bracketed live value by reading the current public screen immediately before recording. Do not memorize an old snapshot.

Natural owner-voice script

0:00–0:18

“Regulated endpoint teams should not have to reconstruct months of configuration history before every audit. Provifact turns approved change into audit-ready proof by joining Git-reviewed intent, read-only Intune observation, deterministic drift, sanitized publication, and bounded GPT-5.6 explanation.”

“This is a live sanitized tenant package collected [VISIBLE COLLECTION TIME], snapshot [VISIBLE SHORT SNAPSHOT]. Raw tenant and device identities are not public.”

0:18–0:48

“The approved macOS demo baseline contains 98 pinned Level 1 rules. Four exact Intune mappings are reviewed and enter the deterministic denominator. The remaining 94 stay visible as implementation work—not hidden, guessed, or mislabeled as failed controls.”

“Today the package shows [VISIBLE DRIFT COUNT] deterministic findings and [VISIBLE GAP COUNT] collection gaps. Those states come from code, never from the model.”

0:48–1:12

“Opening one finding shows the approved target beside the normalized observation, assignment evidence, the exact reviewed provider definition, stable evidence IDs, and a content fingerprint. The operator guidance is deliberately non-mutating. Provifact has no apply command and no Microsoft Graph write path.”

1:12–1:36

“The baseline matrix makes onboarding work concrete. This row is evaluated; this row still needs an approved management or alternate-evidence path. CIS Level 2, DISA STIG, NIST, and CMMC-oriented columns show exact public technical-profile membership for planning. They are not framework scores, passed controls, certifications, or assessor conclusions.”

1:36–1:52

“Change watch compares the current and immediately prior sanitized packages without creating a tenant data lake. Collection and parser gaps remain visible. If evidence becomes stale, production degrades rather than substituting synthetic data.”

1:52–2:28

“Now I’ll ask Provifact Assistant: What requires my attention?”

“The browser sends only this question, a page enum, the current snapshot ID, and optional selected evidence ID. The Worker chooses a small sanitized context for fixed GPT-5.6 Terra. It uses structured output, no tools, and response storage disabled.”

“The response is labeled AI-generated and review required. Deterministic typed claims and evidence references are checked before display; free prose, limitations, and suggested questions remain quarantined for human review.”

2:28–2:45

“GitHub Actions uses short-lived Entra federation for GET-only collection. Publication is allowlist and scan gated. Provifact cannot change Intune, grant an exception, accept risk, or decide organizational compliance. It makes the evidence chain reviewable before the audit.”

Teleprompter script with click cues

Use this version when cueing the screen and narration together. The wording is intentionally short.

[Mission Control top · 0:00]

Regulated endpoint teams should not have to rebuild months of configuration history before every audit.

Provifact connects Git-reviewed intent, read-only Intune observation, deterministic drift, sanitized publication, and bounded GPT-5.6 explanation.

[Point to mode, collection time, and snapshot]

This is live sanitized tenant evidence collected [VISIBLE TIME], snapshot [VISIBLE SHORT ID]. Raw tenant and device identities are not public.

[Scroll to inventory and priority queue · 0:20]

The approved demo inventory has 98 Level 1 rules. Four exact reviewed Intune mappings enter the deterministic denominator. The other 94 remain visible implementation work. Today the screen shows [VISIBLE FINDINGS] findings and [VISIBLE GAPS] collection gaps.

[Open one genuine finding · 0:48]

Here are the approved target, normalized observation, assignment evidence, exact provider definition, stable evidence IDs, and content fingerprint. The guidance is non-mutating. Provifact has no apply command and no Graph write path.

[Open Baseline Plan · 1:12]

This row is evaluated. This row still needs an approved management or alternate-evidence path. The comparison profiles show exact technical membership for planning—not framework scores, certification, or assessor conclusions.

[Show Change Watch and Evidence Health · 1:36]

Current and prior sanitized packages reveal change without creating a tenant data lake. Gaps and stale evidence remain visible; production never substitutes synthetic findings.

[Open Assistant and ask “What requires my attention?” · 1:52]

The browser sends the question, page type, current snapshot, and optional selected evidence ID. The Worker selects a small sanitized context for fixed GPT-5.6 Terra, with no tools and response storage disabled.

[Point to label, evidence link, and boundary details]

The answer is AI-generated and review required. Typed claims and evidence references are checked against the deterministic package. Free prose and suggested questions remain generated analysis.

[Return to authority boundary · 2:28]

Codex accelerated the provider and evidence contracts, security controls, tests, interface, and validation. I retained the product, security, baseline-approval, and merge decisions.

The live proof is managed Apple on Intune. Another platform or MDM still needs its own read-only adapter, reviewed mappings, credentials, fixtures, and tests.

Provifact cannot change Intune or decide organizational compliance. It makes the evidence chain reviewable before the audit.

Contingency lines

Use at most one applicable line and keep the final cut below three minutes:

  • No resolved drift: “No resolved change appears in this snapshot, and Provifact does not fabricate one. The current and prior package identities remain traceable.”
  • Assistant unavailable: “The model path is temporarily unavailable. Provifact keeps the deterministic evidence visible and does not substitute a fixture answer in production.”
  • Site unavailable: Stop the production recording. Use the credential-free local build only if the final video labels it SYNTHETIC DEMO DATA throughout.
  • New snapshot not propagated: “The reviewed snapshot has not reached production, so I am showing the last verified package rather than claiming a refresh.”
  • Unexpected count: “The public package reports [VISIBLE COUNT]. That aggregate remains an open collection question; no device identity is exposed and no missing record is guessed.”