Business outcome, CMS scope, data sensitivity, owner role, risk tier, and approval depth.
AISDLC-aligned traceability, from requirement to evidence.
A program-facing view that connects CMS/EDE requirement sources to Agile epics, sprint lanes, platform functions, test kits, FIT cases, acceptance criteria, security gates, audit disposition, and evidence vault references. It shows the WHPS AI SDLC: Agile discipline adapted for agentic delivery, with human-owned gates and evidence-first controls.
Agile artifacts, agentic execution, and release controls are visible in the same chain.
The traceability matrix is aligned to the WHPS AI SDLC, an Agile framework adapted for agentic delivery. The method keeps product ownership, architecture review, security validation, test evidence, and release authority visible at the right review altitude.
Epics, backlog items, sprint lanes, acceptance criteria, dependencies, and Definition of Done.
Data flow, integration path, trust boundary, threat model, design review, and control alignment.
Platform functions, APIs, UI behavior, notices, controls, and controlled delivery lanes.
FIT cases, UAT capture, regression checks, accessibility, security scans, and remediation evidence.
Screenshots, JSON/API proof, recordings, control mapping, vault links, gaps, and audit disposition.
Named approvals, export readiness, rollback path, archive discipline, monitoring, and change control.
Every visible row maps to a CMS source, Agile backlog lane, AI SDLC gate, test kit, and evidence reference.
This is intentionally a traceability view, not another evidence repository. The matrix keeps the audit chain visible while evidence files remain in the vault for download, review, and archival control.
Rows with source, backlog, test, and evidence references.
This view is limited to requirement sources, Agile backlog, platform functions, test coverage, evidence references, audit disposition, and open gaps.
The matrix shows evidence links and preview references; source artifacts and bulk downloads remain in the evidence vault and current auditor packet packages.
Traceability is complete; auditor evidence readiness is a separate status.
The toolkit-driven traceability matrix can be complete while final evidence remains in capture and review. Evidence completion below reflects export-ready auditor evidence, not historical screenshots or supporting vault artifacts.
Export-ready evidence package completion.
Evidence readiness will separate current review candidates, pending UAT capture, and source-pending scope.
The final packet still needs a current full enrollment walkthrough with screenshots or recording before the evidence package should be presented as export-ready.
| Evidence area | Required | Export-ready | In review | Pending capture | Source pending | Completion |
|---|---|---|---|---|---|---|
| Loading evidence readiness... | ||||||
A familiar Agile status layout without losing requirement-to-proof traceability.
This gives project management, product, QA, and program leadership the table view they expect: requirement area, backlog status, testing posture, evidence status, dependencies, risks, and next actions.
Coverage reflects traceability references, not final auditor evidence completion.
Artifacts referenced through the current evidence vault.
Current staged evidence that still needs final auditor-ready capture or approval.
Items requiring source or scope confirmation before export.
Development status by domain
| Domain | Total | Done | In progress | Pending | At risk | Rate |
|---|---|---|---|---|---|---|
| Loading development status... | ||||||
Evidence status by requirement area
| Requirement area | Supporting artifacts | In review | Pending capture | Source pending | Package |
|---|---|---|---|---|---|
| Loading evidence status... | |||||
Search from requirement source to function, test case, and evidence link.
Each row is built for review: CMS source, Agile epic, sprint lane, backlog item, AI SDLC gate, acceptance criteria, platform function, test kit, case ID, evidence reference, audit disposition, and open gap.
| Trace ID | Requirement source | Agile backlog | AI SDLC gate | Function | Test kit / case | Evidence | Status |
|---|---|---|---|---|---|---|---|
| Loading traceability matrix... | |||||||
The matrix points to evidence. The evidence vault remains the source of downloadable artifacts.
This prevents duplicate artifact copies, avoids version confusion, and keeps auditors aligned to the current packet, historical archive, case ZIPs, vault manifests, and AI SDLC release controls.
Case-level status, package downloads, current evidence, required evidence, and gaps.
Evidence vault Current UAT repositoryModule packages, screenshots, JSON/API probes, documents, and source manifests.
Historical archive Published evidence depthHistorical 2,337-file vault with archive traceability and source inventory.
Control register Control-to-evidence CSVControl references, evidence package links, and review support data.
Traceability is established; remaining work is evidence capture, source confirmation, and final disposition.
Traceability readiness and final evidence completion are separate review states. The matrix shows the path; the open items show what remains before export-ready auditor submission.
- Loading next steps...
- Loading dependencies...
- Loading risks...