Skip to content

spike: define reviewer roles, final human dispositions, expiry, and segregation of duties #8

Description

@veil-chow-fyaic

Objective: define who may hold, request evidence, resolve a finding, override a rule, record HUMAN_CLEARED, record HUMAN_BLOCKED or CLOSED_NO_ACTION, and change policy/source activation.

Deliverables:

  • Role and permission matrix
  • Four-eyes and named-human requirements
  • Clearance scope and maximum expiry
  • Final block/no-action authority and audit behavior
  • Change-triggered invalidation and rescreening
  • Emergency access and complete audit behavior

Exit gate: no automated path, service identity, or AI agent can create a final human disposition; clearance is action/scope/version/time bound.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/architectureArchitecture, contracts, and decision recordsphase/1-mvpRequired or evaluated for the Phase 1 service MVPpriority/nowRefine or execute now for the current sprint/critical pathrisk/complianceLegal/compliance interpretation or control risksprint/1Sprint 1 walking skeleton and contractstatus/needs-decisionRequires an explicit project decisiontype/spikeTime-boxed uncertainty reduction ending in evidence or a decision

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions