| V-01 |
Approved-context package check |
Preventive |
Before a work order is released to an agent |
Security architecture |
Human |
Blocks |
Context manifest listing the requirement row, acceptance criteria, CMS or business source reference, architecture decision record, and applicable standard. An incomplete manifest holds the work order. |
Documented standard |
| V-02 |
Workspace credential scope check |
Preventive |
At agent session start and on every credential request during the run |
Security architecture |
Algorithmic |
Blocks |
Session record carrying issued scope, expiry, and every denied request. Standing production, DB2, or PHI-store credentials are never issued to a generation context. |
Documented standard |
| V-03 |
PHI boundary scan |
Inline |
On every generated diff, fixture, log statement, and test dataset in the work order |
Platform engineering |
Algorithmic |
Blocks |
Run-manifest entry recording pattern class, file, line, and cleared or blocked state. A positive result stops the loop before the change can be staged. |
Documented standard |
| V-04 |
Secret and credential exposure scan |
Inline |
On stage of any change, before commit |
Platform engineering |
Algorithmic |
Blocks |
Scan record attached to the diff. A positive result voids the staged change and triggers rotation of any exposed material, recorded against the incident path. |
Documented standard; the same control is a control gate 05 deliverable |
| V-05 |
Protected-lane and diff-scope guard |
Inline |
On any write outside the declared file scope, or into a protected DB2 coexistence, payment-boundary, or evidence-tooling path |
Security architecture |
Algorithmic |
Blocks |
Blocked-path record on the run manifest naming the attempted path and the owning lane. Extending the scope requires a revised work order, not an in-run override. |
Documented standard |
| V-06 |
Contract and schema conformance |
Inline |
On change to any CMS EDE request or response handler, service schema, or published interface |
Platform engineering |
Algorithmic |
Blocks |
Conformance result per contract version, stored with the build and referenced from the release packet. |
Documented standard |
| V-07 |
Dependency and license policy |
Gate |
On build, and on every dependency addition or version change |
Security engineering |
Algorithmic |
Blocks |
Software composition analysis report with vulnerability severity, license disposition, and resolved findings. |
Documented standard; control gate 05 deliverable |
| V-08 |
CMS EDE requirement conformance review |
Gate |
On any release candidate affecting an EDE-mapped requirement |
CMS EDE requirements owner |
Agentic |
Flags |
Finding list mapped row by row to the traceability spine, each finding carrying a named human disposition before the gate can close. |
Documented standard; the traceability spine it reads is implemented today at 21 mapped rows |
| V-09 |
Intent-versus-implementation review |
Gate |
On every release candidate produced with AI assistance |
Named code reviewer |
Agentic |
Flags |
Independent review record naming reviewer lineage, the findings raised, and the reviewing engineer's disposition on each. The reviewer works from the requirement, not from the generated diff. |
Documented standard |
| V-10 |
Evidence completeness check |
Gate |
When a release or audit evidence packet is assembled |
Evidence owner |
Algorithmic |
Flags |
Packet index listing present and missing artifact types with manifests and hashes; a named reviewer records export-readiness. Current MarketLink state: 0 export-ready, 1 review candidate, 11 pending captures, and 1 source-pending case. |
In force — evidence vault and current auditor packet are operating |
| V-11 |
Release authority sign-off |
Gate |
At control gate 13, before any production movement |
Release authority |
Human |
Approves |
Named release decision with residual-risk record, exceptions, rollback path, deployment ID, and support handoff. This disposition is never delegated to an agent. |
In force — named human release authority |
| V-12 |
Drift and regression watch |
Continuous |
Continuously after release, and on every model, prompt, or dependency change to a released component |
Operations owner |
Algorithmic |
Flags |
Telemetry record, variance report, and a remediation item or incident routed to a named owner. Findings that an earlier verifier should have caught return as a verifier change. |
Documented standard; runtime telemetry and incident readiness are already release-packet requirements |