Compliance & Assurance

Inspect the controls and records behind agent delivery: who implemented, who reviewed, what was checked, and which decisions stayed with a person.

Control model

Assay separates implementation, review and verification, records attributed decisions, and keeps consequential decisions with a person. The method explains the registers, consistency checks and the limits of each mechanism.

Compliance evidence and limits
The release-keyed audit pack, its recorded evidence, and the controls your organisation supplies.
Methodology and residual gap
What the machinery supports, and what a consistent record cannot prove.
Lifecycle
The review, human merge and post-merge verification stages.
Registers
How the records are maintained and changes become visible.
Platform enforcement
The GitHub boundary; compare with the stated GitLab implementation status.

Review attribution establishes who posted a review; it does not establish that the review was diligent. Platform-specific limits distinguish implemented enforcement from guidance.

Evidence you can inspect

Recorded walkthrough evidence
The evidence ledger behind the example change, with recorded and illustrative elements distinguished.
Review and verification records
How dated, attributed checks and execution witnesses support a verification claim.

The homepage diagram explains the flow. It is illustrative, rather than a record of an execution.

Operational evidence

Board
The operated instance’s work and queues, derived from its records.
Measurements
The reported measurements, their source and time boundaries, and what could not be checked.

The board is derived from agent-authored artifacts with consistency checks; it is not a measurement of ground truth. Measurements describe the operated instance, rather than a promised result for an adopter. Read each page’s source, date and could-not-check states with its figures.

Scope and remaining responsibilities

Compliance evidence is partial. The public toolchain exports a release-keyed audit pack of recorded requirements, briefs, Evidence and review verdicts. Read its scope and limits: the pack is recorded evidence, not ground truth or an audit opinion; organisation-wide controls and corrective-action effectiveness remain gaps.

Assay supplies review and verification records, not certification against a regulatory framework or assurance that an output is correct. Your organisation owns its control design, regulatory mapping and external assurance. Release, deployment and rollback remain outside the current flow.

Evaluate for your organisation
The organizational reading path and the limits of the control story.
Full coverage map
What Assay supplies and what remains yours.