Skip to main content

Go-Live Evidence Pack

Operating · ← Obligation map · Evidence pack

The pack is what you hand an examiner (or an exec sponsor) before status on the inventory becomes live. Evidence is continuous after go-live. This page is the minimum bundle at the gate.

THE CLAIM

Evidence is not a binder assembled for the auditor visit. The pack is generated from inventory, the obligation map, and runtime audit. If a field is only in a slide, it does not count.

What the pack contains

ArtifactSource
Inventory row (owner, pattern, data class, status)Inventory
Obligation-to-control rows for this use_case_idObligation map
Policy version pinRuntime audit
Sample ALLOW / DENY / STEP_UP chainRuntime verdict log
Eval / policy-scenario gate resultsPolicy test scenarios
Residual risk acceptanceNamed sponsor on the inventory row

Gate

Status may move to live only when:

  1. Inventory row is complete (named owner, not a mailbox)
  2. Every mapped obligation has a control id that exists
  3. Runtime PEP is on the tool path for this use case
  4. Policy scenarios for this profile pass in CI
  5. Sponsor has accepted residual risk on the record

Miss this pack and you may have ethics slides while the agent ships with no inventory entry. Miss Runtime and you have a pack with no PEP on the tool path.

Failure classes

  • Pack is a PDF with no links to live registers
  • Verdict sample from a different use_case_id
  • Go-live without STEP_UP scenarios on a write path
  • Pack frozen at launch; incidents never feed it

Trace / register fields

evidence_pack_id, use_case_id, policy_version, scenario_suite_id, accepted_by, accepted_at

After go-live, continue on Runtime and feed incidents back into the obligation map.

Runtime playbooks → · Operating blueprint