Milestones
List view
Exit condition: the firm onboards, operates, and offboards client organizations from one deployment; firm staff see and work their client portfolio without cross-client disclosure; reusable templates are applied with provenance; client users can sign in through their own identity providers; every client service is recorded as an accepted advisory or attest engagement; and independence walls prevent attest work where advisory services impaired independence. Attest workpaper support stays out of this milestone until M0-D27 decides its scope.
No due date•0/17 issues closedExit condition: every product and architecture decision that blocks a P0 story is recorded with rationale, owner, and date; shared domain ownership conflicts are resolved; the canonical entity and relationship model is approved from direct public sources whose use is acceptable for the Apache-2.0 product; unusable or unclear sources are excluded; blocked stories are refined; and no P0 story still depends on an unresolved validation. This milestone produces decisions, ADRs, and thin technical spikes, not business implementation.
No due date•34/35 issues closedExit condition: the observation period is frozen; complete source-backed populations and samples are traceable; management assertions, auditor work, and product projections remain distinct; the examination is supported; the result is recorded; and the program rolls forward without losing history.
No due date•0/14 issues closedExit condition: recurring controls, evidence, access reviews, policy and provider work, significant-change assessment, and management oversight operated throughout the observation period; the system description is current and source populations are complete and explainable.
No due date•2/18 issues closedExit condition: the team has a frozen point-in-time baseline, an approved system description and management representations, traceable auditor responses, a reproducible handoff, an externally sourced result, and an approved Type II operating plan.
No due date•0/15 issues closedExit condition: required controls and policies are implemented and evaluated; policies are communicated and acknowledged; evidence is captured with provenance and its handling status is explicit, with any undelivered evidence-governance capability (retention, hold, redaction, disclosure) shown as an acknowledged gap; actual human and NHI access is reconciled with approved expectations; accountable work and gaps are visible; and the team can make an evidence-backed Type I entry decision.
No due date•0/47 issues closedExit condition: the team has an agreed system boundary; authoritative workforce context; application, technology, and information inventories; service commitments and system requirements; criteria; roles; controls; risks; providers; and an owned gap plan. The shared platform primitives (authorization, versioned records, review decisions, snapshots, and artifact storage) are proven through their first consuming stories. Import remains an accepted P1 capability after the manual governed-record path and is not required for R1 exit. Nothing in this milestone claims audit readiness or an auditor opinion.
No due date•3/109 issues closed