Skip to content
Governance

For Legal & Compliance

An artefact,
not a thread.

You are asked what was decided, by whom, and whether it landed. Governance answers with a record that reads the same in a year as it did on the day.

Found

Risk quoted “absolute safety” from the live page and cited the approved fact it contradicts, at version 4.

Routed

Policy assigned severity and sent it to Legal. The agent did not choose either.

Decided

Priya Raman, reviewer, approved the replacement wording. The approval is the artefact, not a message about it.

Acted

The CMS write was previewed, approved, and executed against /products/atlas-x200.

Verified

The live URL was read again. The sentence is gone. Only then did the issue close.

Closed by a rescan of the published URL, not by a status change.Reads the same in a year

What you are up against

Three questions you cannot currently answer.

You are asked what is live

Not what was approved. What is on the site right now, and whether anyone has read it since it shipped.

Exposure

The record is a thread

The decision was made in Slack eight months ago by someone who has left. There is no artefact you can hand anyone.

Evidence

Closed is a guess

The ticket says done. Nobody read the published page again to check.

Closure

Control

The controls you would ask for anyway.

None of these are settings somebody can leave off. They are properties the application is built to hold.

  1. 01

    Roles

    A reviewer can change workflow state. A viewer cannot. Enforced server-side.

  2. 02

    Approval

    No external send or CMS write executes without a preview and an explicit approval.

  3. 03

    Tenancy

    The organisation is derived from the verified session. No request can select another one.

  4. 04

    Provenance

    Agent output cites its evidence and never sets its own severity.

More review capacity is useless without closure.
Why closure is a separate step

Bring your hardest question.