Reference — generated from the toolkit
Source of truth: toolkit/registers/README.md. Edit it there; this page is regenerated on build.
Registers
Living registers — each a canonical list with a fixed schema, every entry linked to its evidence. A finding that isn't in the right register doesn't exist.
Schemas are defined; rows are populated as their source activities run (mostly STOP).
| Register | Populated by | Owner |
|---|---|---|
tech-debt-register.md | tech-debt audit | Engineering |
security-debt-register.md | security-gap assessment | Security |
eol-inventory.md | SBOM baseline | Engineering + Security |
test-debt-register.md | test-debt baseline | Test |
client-commitment-register.md | STOP client triage | Delivery |
signal-register.md | Commercial + Support + telemetry | Product |
security-exceptions.md | gate waivers (security-relevant) | Security |
gate-waiver-log.md | all gates | gate owners |
Signed risk-acceptance records are filed alongside the register entry they cover.
Waivers and accepted risks always carry a named owner and a hard expiry after which the gate re-blocks.