Research question and scope
Published September 10, 2026.
This study asks whether completed customer-account merges followed declared verification, authorization, data-movement, and post-merge review controls. The study covers a defined set of systems and merges completed during one audit window. It evaluates process evidence, not the legal identity of customers or the correctness of identity policy.
Methodology
Before extraction, document the eligible systems, merge definition, required evidence, exception paths, and audit period. Draw a reproducible stratified sample by system, operator group, merge reason, and month. Oversample reversed merges for diagnostic analysis, but report them separately from the representative sample.
Two reviewers should test whether the case records identity checks, approval level, source and destination identifiers, fields moved, open-work reconciliation, notification, and a recovery route. Mask direct identifiers in the review dataset. Resolve disagreements under a written rubric and report reviewer agreement.
Measures and analysis
Report the eligible population, sample size, selection seed, unavailable records, and control completion rates with confidence intervals where probability sampling supports them. Show missing evidence by control and system. Compare strata only when sample sizes and selection probabilities permit it. Treat a missing note as missing evidence, not automatic proof that a check did not occur.
Inference boundaries and limitations
This design cannot establish that two profiles belonged to the same person, that a customer authorized every downstream change, or that unobserved data was handled correctly. Logs may be incomplete or altered by migrations. Results do not generalize beyond the sampled systems and period. Oversampled reversals must not be used to estimate the overall error rate without weighting.