Skip to content

chore(governance): audit the add-on checklists #10–#16 against the delivered pilot #65

Description

@Fluory

Goal

The pilot is built (Epics #2, #17, #18 merged), but the seven add-on checklists (#10–#16, 88 items) have 0 items ticked. Before any acceptance or the stage change to P2, every item must be either proven, deliberately out of scope, or a tracked gap.

Acceptance criteria

  • Every item of add-on: Security baseline checklist #10–add-on: Customer engagement (brief, domains, milestones) checklist #16 carries exactly one verdict in its issue body:
    • [x] + evidence (file path, test name or PR link) when implemented
    • n/a (P2) / n/a (showcase) + one-line reason when it belongs to a later stage
    • gap → #<nr> when missing: a follow-up issue with goal, acceptance criteria, test plan (label feature or security, not ready – the orchestrator decides)
  • Each checklist issue gets a summary comment: proven / n/a / gaps, with the follow-up numbers
  • Evidence is checked in the code or CI, never taken from a PR description alone
  • No product code changes in this issue (findings become follow-up issues)

Not part of this task

  • Fixing the gaps, editing ADR-0001, docs/technical/deployment-vercel.md or the exceptions register (showcase work runs in parallel)

Test plan

Criterion Check
all 88 items have a verdict script or manual count in the PR, 0 unmarked items
evidence real spot check of 10 items by the fresh review subagent

Security/Privacy affected?

Yes – reads the security and data-protection checklists (#10, #11); gaps there get the label security.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    readyDefinition of Ready met – may be claimed

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions