b054849a99
P4 (Wave 3, docs) — REQ-186, 191, 192, 193, 194, 195, 204, 210, 211, 212, 213 New docs: - docs/METRICS.md — canonical KPI catalog (grounded/derived/deferred) - docs/metrics/*.md — 13 per-KPI definition-of-success docs (D-127) - docs/METRICS_DEFERRED_ROADMAP.md — 8 deferred metrics + hot-path plan + re-eval triggers (REQ-210) - docs/NO_HUMANS_THESIS.md — thesis defensibility brief (REQ-213) New tools: - core/metrics/trust_snapshot.py — 5 trust metrics + chain-integrity verdict + snapshot hash (REQ-211) - scripts/check_north_star_diff.sh — CI check for NORTH_STAR strategic section changes (REQ-204) Modified: - .ciagent/config.json — strategic_direction_file: .ciagent/NORTH_STAR.md (REQ-186) ---ci--- project: acdl phase: 4 milestone: v1.17 status: execute ---/ci---
606 B
606 B
Zero-Trust Policy Compliance Rate — Definition of Success
KPI: Zero-Trust Policy Compliance Rate Target: not a committed target (operational signal)
What this number means: the percentage of infrastructure assets continuously verified as compliant with security baselines and policies.
How it's computed: 1 − count(assets WHERE last_scan.status ≠ pass) ÷ count(assets). Sourced from fact_policy_check (Checkov results).
What "good" looks like: 100% means every resource passed every policy check. The Nova tagging standard (nova_tagging.py, hard mode) is the primary check.