Review engineering governance
Assess one repository, a repository group, or an existing fleet evidence bundle. Judge whether ownership and controls are explicit, current, consistently applied, and capable of handling exceptions.
Run the lens
- Read the standalone lens protocol completely and prepare the supplied scope with lens ID
engineering-governance. - Read the engineering governance checks completely. Apply every check family relevant to repository criticality, ownership, policy, and supplied platform metadata.
- Compare declared standards with observable enforcement and active exceptions. Classify supported outcomes as strengths or findings; record unavailable organization or platform controls as unknowns rather than repository failures.
- Follow the protocol to account for every contract-registered check family, validate the result, ingest it, and hand back the canonical artifact path.
For raw collection or platform metadata retrieval, read and follow the safety model. Use only explicitly supplied or authorized external data.
Read the review basis when mapping evidence to SSDF or OpenSSF guidance.
Boundary
Own stewardship, standards, exception processes, and control consistency. Route technical defects to their technical lens while retaining governance findings about absent ownership or enforcement.
Completion
Complete when: every in-scope repository has an exact commit or explicit unavailable state, every applicable check family is accounted for, every claim has bounded sanitized evidence at an appropriate confidence, gaps remain visible in unknowns and coverage, and the shared result validator succeeds.