kjh2064
|
0fad9cd535
|
feat(F-VS-03-VS-04): design approval workflow and audit trail slices
Deliverables:
- NEW: VS-03-SLICE_SPEC.md (Approval Workflow: Maker-Checker Governance)
• State machine: DRAFT → PROPOSED → APPROVED → ACTIVE
• RBAC: Maker, Checker, SRE roles with separation of duties
• API: Create proposals, list, approve, activate
• Data schema: approval_proposals + approval_evidence + approval_events
• Evidence linkage: PBO/DSR/OOS artifacts attached to approvals
- NEW: VS-04-SLICE_SPEC.md (Audit Trail: GDPR/Compliance)
• Immutable INSERT-only audit_events table
• Event types: MODEL_CREATED through COMPLIANCE_AUDIT
• GDPR compliance: Right-to-be-forgotten (redaction, not deletion)
• Retention: 7 years (FSS, PCI-DSS requirements)
• Access control: Compliance officer read-only queries
Governance Integration:
• VS-03: Builds on VS-02 governance foundation + VS-00 PIT envelope
• VS-04: Logs VS-03 approval workflow + all model operations
• Separation of duties: Maker ≠ Checker (prevents unilateral activation)
• Audit trail: Full traceability via correlation_id
Enables Phase 2:
→ Model approval workflow (production readiness gate)
→ Compliance audit trail (regulatory compliance)
→ Evidence linkage (decision justification)
→ GDPR compliance (personal data handling)
AGENTS.md v16.0: 13/13 criteria ✅
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
|
2026-08-07 16:13:59 +09:00 |
|