{
  "$comment": "Contract A4 PRACTICE items for the ashr-partner-l1 track, domain positioning-claims. These are published and may be used in lesson quizzes, study guides and agent corpora. The gate quiz is NOT drawn from this file: it draws from the secured pool, which is never served. Every item cites the ASHR.work pages it is grounded in (`cites`) and the repo files the facts were read from (`sources`); claim ids refer to the partner positioning claims C-01 to C-16. No item quotes a price: partners link the live pricing page.",
  "track": "ashr-partner-l1",
  "domain": "positioning-claims",
  "items": [
    {
      "id": "ashr-partner-l1.positioning-claims.01",
      "kind": "mcq",
      "domain": "positioning-claims",
      "stem": "A prospect asks where their data lives. Which line may you use?",
      "options": [
        {
          "key": "a",
          "text": "'All AI runs in India.'"
        },
        {
          "key": "b",
          "text": "'Your business records are stored in India (Mumbai region).'"
        },
        {
          "key": "c",
          "text": "'Your data never leaves India, for any purpose.'"
        },
        {
          "key": "d",
          "text": "'You can choose any hosting region you like.'"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "The database is hosted on AWS in Mumbai (ap-south-1) and functions are pinned to the Mumbai region. That is a claim about where records are stored, not about where every AI workload runs, and there is no per-customer region choice.",
      "cites": [
        "https://ashr.work/help/faqs/data-security-and-compliance",
        "https://ashr.work/security"
      ],
      "sources": [
        "content/help/faqs/data-security-and-compliance.mdx",
        "docs/adr/0005-function-region-bom1.md",
        "vercel.json"
      ],
      "claims": [
        "C-01"
      ]
    },
    {
      "id": "ashr-partner-l1.positioning-claims.02",
      "kind": "mcq",
      "domain": "positioning-claims",
      "stem": "A prospect's IT lead asks: 'Is ASHR.work SOC 2 or ISO 27001 certified?' What is the accurate answer?",
      "options": [
        {
          "key": "a",
          "text": "'Yes, ASHR.work is SOC 2 certified.'"
        },
        {
          "key": "b",
          "text": "'ASHR.work is compliant with SOC 2 and ISO 27001.'"
        },
        {
          "key": "c",
          "text": "'No. ASHR.work does not currently hold SOC 2, ISO 27001 or any other independent certification; we answer vendor security questionnaires directly.'"
        },
        {
          "key": "d",
          "text": "'Our partner certification covers that.'"
        }
      ],
      "answer_key": {
        "correct": [
          "c"
        ]
      },
      "max_points": 1,
      "rationale": "Never 'certified' and never 'compliant'. A partner's training credential says nothing about Demystify's own security certifications.",
      "cites": [
        "https://ashr.work/help/faqs/data-security-and-compliance",
        "https://ashr.work/security"
      ],
      "sources": [
        "content/help/faqs/data-security-and-compliance.mdx"
      ],
      "claims": [
        "C-14",
        "C-16"
      ]
    },
    {
      "id": "ashr-partner-l1.positioning-claims.03",
      "kind": "multi",
      "domain": "positioning-claims",
      "stem": "Which of these lines may a partner use as written? Select all that apply.",
      "options": [
        {
          "key": "a",
          "text": "'ASHR.work prepares PF, ESI, PT and TDS files and Form 16 Part B; you or your CA file them.'"
        },
        {
          "key": "b",
          "text": "'ASHR.work files your statutory returns.'"
        },
        {
          "key": "c",
          "text": "'Built to support DPDP obligations such as data requests, exports and retention.'"
        },
        {
          "key": "d",
          "text": "'ASHR.work is DPDP compliant.'"
        },
        {
          "key": "e",
          "text": "'ASHR.work is available in Hindi.'"
        }
      ],
      "answer_key": {
        "correct": [
          "a",
          "c"
        ]
      },
      "max_points": 2,
      "rationale": "Statutory outputs are exports only, DPDP support is 'built to support', never 'compliant', and the ASHR.work interface is English only.",
      "cites": [
        "https://ashr.work/help/faqs/data-security-and-compliance",
        "https://ashr.work/docs/explanation/payroll-engine-model"
      ],
      "sources": [
        "content/help/faqs/data-security-and-compliance.mdx",
        "docs/parity-program/DECISIONS.md",
        "lib/dsr/actions.ts",
        "lib/brand.ts"
      ],
      "claims": [
        "C-07",
        "C-13",
        "C-15"
      ]
    },
    {
      "id": "ashr-partner-l1.positioning-claims.04",
      "kind": "mcq",
      "domain": "positioning-claims",
      "stem": "A prospect has heard that ASHR.work can manage AI agents as workers and asks to buy it. What is the accurate position today?",
      "options": [
        {
          "key": "a",
          "text": "Sell it as an add-on module at the Growth add-on rate"
        },
        {
          "key": "b",
          "text": "Do not sell or demo it as a module: it is admin-only, not in the module catalogue and not priced; it may be described only once it is applied in production and catalogued"
        },
        {
          "key": "c",
          "text": "It is included free in Complete"
        },
        {
          "key": "d",
          "text": "It is a Coming soon module you can pre-sell"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "The workforce records — workers of every kind, time-bound entitlements, a kill switch, access reviews — are built but admin-only and unpriced. Pricing is the owner's decision, not a partner's.",
      "cites": [
        "https://ashr.work/modules"
      ],
      "sources": [
        "lib/modules-catalog.ts",
        "scripts/172_workers_departments.sql",
        "scripts/173_entitlements_approvals.sql"
      ],
      "claims": [
        "C-05"
      ]
    },
    {
      "id": "ashr-partner-l1.positioning-claims.05",
      "kind": "mcq",
      "domain": "positioning-claims",
      "stem": "Which line about AI assistants and ASHR.work may you use?",
      "options": [
        {
          "key": "a",
          "text": "'ASHR.work works with every AI.'"
        },
        {
          "key": "b",
          "text": "'Your own AI assistant can work with ASHR.work through MCP and a documented API, under the same permissions as a person.'"
        },
        {
          "key": "c",
          "text": "'Agents run your HR fully autonomously.'"
        },
        {
          "key": "d",
          "text": "'Any AI can write to payroll through the API.'"
        }
      ],
      "answer_key": {
        "correct": [
          "b"
        ]
      },
      "max_points": 1,
      "rationale": "The hosted MCP endpoint signs a person in and acts within their role. API writes today are limited to leave, and grievance and POSH data is not reachable through the API at any scope.",
      "cites": [
        "https://ashr.work/help/developers/connect-ai-assistants",
        "https://ashr.work/docs/explanation/public-api-and-agents"
      ],
      "sources": [
        "app/api/mcp/route.ts",
        "content/help/developers/connect-ai-assistants.mdx",
        "content/docs/explanation/public-api-and-agents.mdx"
      ],
      "claims": [
        "C-10",
        "C-04"
      ]
    },
    {
      "id": "ashr-partner-l1.positioning-claims.06",
      "kind": "mcq",
      "domain": "positioning-claims",
      "stem": "How may a partner describe their own Demystify Partner Academy credential to a prospect?",
      "options": [
        {
          "key": "a",
          "text": "'Miatz, the Demystify learning product, certified us.'"
        },
        {
          "key": "b",
          "text": "'We are certified by Demystify', said before any academy credential has been issued"
        },
        {
          "key": "c",
          "text": "Once a real credential has been issued: 'Our partners are trained and examined; you can verify a partner's credential online. Training & certification - powered by Miatz.'"
        },
        {
          "key": "d",
          "text": "'Our certification means ASHR.work is ISO certified.'"
        }
      ],
      "answer_key": {
        "correct": [
          "c"
        ]
      },
      "max_points": 1,
      "rationale": "Miatz is a separate company and ASHR.work's learning partner, never a Demystify product. The credential line may be used only after the first real credential is issued, and it says nothing about Demystify's own security certification.",
      "cites": [
        "https://ashr.work/modules",
        "https://ashr.work/help/faqs/pricing-and-plans"
      ],
      "sources": [
        "lib/modules-catalog.ts",
        "CLAUDE.md"
      ],
      "claims": [
        "C-16"
      ]
    }
  ]
}
