0fad9cd535
Deliverables: - NEW: VS-03-SLICE_SPEC.md (Approval Workflow: Maker-Checker Governance) • State machine: DRAFT → PROPOSED → APPROVED → ACTIVE • RBAC: Maker, Checker, SRE roles with separation of duties • API: Create proposals, list, approve, activate • Data schema: approval_proposals + approval_evidence + approval_events • Evidence linkage: PBO/DSR/OOS artifacts attached to approvals - NEW: VS-04-SLICE_SPEC.md (Audit Trail: GDPR/Compliance) • Immutable INSERT-only audit_events table • Event types: MODEL_CREATED through COMPLIANCE_AUDIT • GDPR compliance: Right-to-be-forgotten (redaction, not deletion) • Retention: 7 years (FSS, PCI-DSS requirements) • Access control: Compliance officer read-only queries Governance Integration: • VS-03: Builds on VS-02 governance foundation + VS-00 PIT envelope • VS-04: Logs VS-03 approval workflow + all model operations • Separation of duties: Maker ≠ Checker (prevents unilateral activation) • Audit trail: Full traceability via correlation_id Enables Phase 2: → Model approval workflow (production readiness gate) → Compliance audit trail (regulatory compliance) → Evidence linkage (decision justification) → GDPR compliance (personal data handling) AGENTS.md v16.0: 13/13 criteria ✅ Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>