Compliance Control Walk

Use when you need to demonstrate that a regulatory control (access, audit logging, encryption, retention, consent) actually exists in the running system — not just on a wiki. Triggers on: SOX, ISO 27001, SOC 2, GDPR, HIPAA, PCI, audit, 'show me the audit log for X', 'is PII encrypted at rest', 'who can read this field', 'is consent checked here', control walkthrough, evidence collection. Do NOT use for: a single test-run verification (use obra/superpowers verification-before-completion), or for static code review (use the matching `*-code-reviewer` for that). Complementary to goal-driven-development, which orchestrates the spec-to-code flow; compliance-control-walk is the regulator-frame counterpart that runs against the production-shape behaviour, not the test suite.

liyown Updated

File contents

liyown/superpower-enterprise/tree/main/skills/compliance-control-walk commit d161127d98

Frequently asked questions

npx skillmds@latest add liyown/compliance-control-walk