Skip to main content
Reference — generated from the toolkit

Source of truth: toolkit/registers/README.md. Edit it there; this page is regenerated on build.

Registers

Living registers — each a canonical list with a fixed schema, every entry linked to its evidence. A finding that isn't in the right register doesn't exist.

Schemas are defined; rows are populated as their source activities run (mostly STOP).

RegisterPopulated byOwner
tech-debt-register.mdtech-debt auditEngineering
security-debt-register.mdsecurity-gap assessmentSecurity
eol-inventory.mdSBOM baselineEngineering + Security
test-debt-register.mdtest-debt baselineTest
client-commitment-register.mdSTOP client triageDelivery
signal-register.mdCommercial + Support + telemetryProduct
security-exceptions.mdgate waivers (security-relevant)Security
gate-waiver-log.mdall gatesgate owners

Signed risk-acceptance records are filed alongside the register entry they cover.

Waivers and accepted risks always carry a named owner and a hard expiry after which the gate re-blocks.