Control model
Assay separates implementation, review and verification, records attributed decisions, and keeps consequential decisions with a person. The method explains the registers, consistency checks and the limits of each mechanism.
- Compliance evidence and limits
- The release-keyed audit pack, its recorded evidence, and the controls your organisation supplies.
- Methodology and residual gap
- What the machinery supports, and what a consistent record cannot prove.
- Lifecycle
- The review, human merge and post-merge verification stages.
- Registers
- How the records are maintained and changes become visible.
- Platform enforcement
- The GitHub boundary; compare with the stated GitLab implementation status.
Review attribution establishes who posted a review; it does not establish that the review was diligent. Platform-specific limits distinguish implemented enforcement from guidance.
Evidence you can inspect
- Recorded walkthrough evidence
- The evidence ledger behind the example change, with recorded and illustrative elements distinguished.
- Review and verification records
- How dated, attributed checks and execution witnesses support a verification claim.
The homepage diagram explains the flow. It is illustrative, rather than a record of an execution.
Operational evidence
- Board
- The operated instance’s work and queues, derived from its records.
- Measurements
- The reported measurements, their source and time boundaries, and what could not be checked.
The board is derived from agent-authored artifacts with consistency checks; it is not a measurement of ground truth. Measurements describe the operated instance, rather than a promised result for an adopter. Read each page’s source, date and could-not-check states with its figures.
Scope and remaining responsibilities
Compliance evidence is partial. The public toolchain exports a release-keyed audit pack of recorded requirements, briefs, Evidence and review verdicts. Read its scope and limits: the pack is recorded evidence, not ground truth or an audit opinion; organisation-wide controls and corrective-action effectiveness remain gaps.
Assay supplies review and verification records, not certification against a regulatory framework or assurance that an output is correct. Your organisation owns its control design, regulatory mapping and external assurance. Release, deployment and rollback remain outside the current flow.
- Evaluate for your organisation
- The organizational reading path and the limits of the control story.
- Full coverage map
- What Assay supplies and what remains yours.