Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Specification d artefact de livraison

JIT access policy pack

JIT Privileged Access

JIT access policy pack defines the delivery artifact specification for JIT Privileged Access, including structure, evidence expectations, and approval boundaries.

nDSGDORANIS2

Objectif

Provide a reviewable artifact that proves JIT Privileged Access implementation quality for stakeholders, operators, and assurance teams.

Contexte de perimetre

Privilege elevation only through ticketed, expiring, and auditable sessions.

Entrees

- Approved implementation scope and stakeholder requirements

- Source architecture and policy configuration snapshots

- Validation results, test outcomes, and governance notes

Sorties

- Versioned artifact document with ownership metadata

- Traceability links to controls, decisions, and evidence

- Sign-off checkpoint for founder or delegated approver

Criteres d acceptation

- Artifact is complete, unambiguous, and reproducible

- All referenced controls and evidence links resolve

- Final sign-off status and revision history are visible

Notes de preuve de conformite

- [nDSG] Artifact contains evidence section for domain-specific assurance

- [DORA] Artifact contains evidence section for domain-specific assurance

- [NIS2] Artifact contains evidence section for domain-specific assurance

Schema de specification

Role responsable

Delivery Lead with Founder oversight

Validation finale

Founder or delegated Control Plane Principal

Politique de versioning

Semantic revisioning (major.minor.patch) with immutable change log

Cadence de revue

Weekly during rollout, monthly after stabilization

Retention des preuves

Minimum 24 months or regulatory minimum, whichever is longer

Sections obligatoires

- Document objective and decision context

- Scope boundary with included and excluded systems

- Implementation specification and control mapping

- Evidence references and verification results

- Risks, exceptions, and next remediation actions