Shipping Checklist¶
- [ ] Assets, trust boundaries, attacker goals, and abuse paths are documented.
- [ ] Human, workload, and delegated identities are distinguishable and auditable.
- [ ] Authorization is enforced at each consequential system boundary.
- [ ] Data, model, dependency, and secret lifecycles have controls and owners.
- [ ] Agent actions have least privilege, validation, and recovery paths.
- [ ] Exceptions, evidence, monitoring, and incident response are operational.