Skip to content

Add access review certifier evidence gates#1168

Open
tick25108-cpu wants to merge 1 commit into
UnitOneAI:mainfrom
tick25108-cpu:codex/access-review-certifier-evidence
Open

Add access review certifier evidence gates#1168
tick25108-cpu wants to merge 1 commit into
UnitOneAI:mainfrom
tick25108-cpu:codex/access-review-certifier-evidence

Conversation

@tick25108-cpu
Copy link
Copy Markdown

Summary

Addresses #1159 for the access-review skill.

This update adds certifier eligibility checks to the existing access review flow:

  • distinguishes tracked, authorized, time-bounded delegation from untracked or out-of-scope delegation
  • adds self-review and conflicted-certifier checks for users who certify their own access or can modify the same access they approve
  • adds required evidence fields for reviewer of record, actual certifier, delegation scope, decision timestamp, admin authority, and independence exceptions
  • marks certification completion as provisional when approve/revoke decisions exist but certifier eligibility is not evidenced
  • adds certifier independence metrics to the summary report and retention requirements for eligibility/delegation evidence

Verification

  • Ran git diff --check
  • Documentation/skill guidance only; no runtime tests required

Bounty

Submitting this as an Improver contribution under the repository contribution guidelines.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant