Skip to content

Shipping Checklist

  • [ ] Assets, trust boundaries, attacker goals, and abuse paths are documented.
  • [ ] Human, workload, and delegated identities are distinguishable and auditable.
  • [ ] Authorization is enforced at each consequential system boundary.
  • [ ] Data, model, dependency, and secret lifecycles have controls and owners.
  • [ ] Agent actions have least privilege, validation, and recovery paths.
  • [ ] Exceptions, evidence, monitoring, and incident response are operational.