Instruction file imported from ParseANull/SDLCGroundcontrol (
.github/instructions/compliance-evidence.sdlc.instructions.md). Copyright stays with the author.
Compliance Evidence SDLC Instructions
End-to-End Traceability
- Link requirement or issue context to pull requests, test evidence, and deployment records.
- Require risk-tier and compatibility-impact annotations for interface or schema-affecting changes.
- Maintain traceability references in changelog and release notes.
Evidence Capture Standards
- Capture review approvals, status-check outcomes, and deployment approvals for protected-branch changes.
- Preserve test summaries and release verification artifacts for audit-ready retrieval.
- Record policy exceptions with approver identity, rationale, and remediation commitments.
Retention and Access
- Apply least-privilege access to audit evidence stores.
- Retain evidence according to organizational or regulatory requirements.
- Avoid storing sensitive payloads in evidence artifacts when summaries are sufficient.
Review Cadence
- Include evidence completeness checks in quarterly drift review.
- Escalate repeated evidence gaps as process defects with assigned owners.