Files
acdl/docs/metrics/policy_compliance_rate.md
T
Jon Chery b054849a99 docs(P4): metrics catalog + NORTH_STAR integration + trust snapshot + no-humans thesis (REQ-186,191..195,204,210..213)
P4 (Wave 3, docs) — REQ-186, 191, 192, 193, 194, 195, 204, 210, 211, 212, 213

New docs:
- docs/METRICS.md — canonical KPI catalog (grounded/derived/deferred)
- docs/metrics/*.md — 13 per-KPI definition-of-success docs (D-127)
- docs/METRICS_DEFERRED_ROADMAP.md — 8 deferred metrics + hot-path plan + re-eval triggers (REQ-210)
- docs/NO_HUMANS_THESIS.md — thesis defensibility brief (REQ-213)

New tools:
- core/metrics/trust_snapshot.py — 5 trust metrics + chain-integrity verdict + snapshot hash (REQ-211)
- scripts/check_north_star_diff.sh — CI check for NORTH_STAR strategic section changes (REQ-204)

Modified:
- .ciagent/config.json — strategic_direction_file: .ciagent/NORTH_STAR.md (REQ-186)

---ci---
project: acdl
phase: 4
milestone: v1.17
status: execute
---/ci---
2026-08-04 20:05:06 +00:00

606 B
Raw Blame History

Zero-Trust Policy Compliance Rate — Definition of Success

KPI: Zero-Trust Policy Compliance Rate Target: not a committed target (operational signal)

What this number means: the percentage of infrastructure assets continuously verified as compliant with security baselines and policies.

How it's computed: 1 count(assets WHERE last_scan.status ≠ pass) ÷ count(assets). Sourced from fact_policy_check (Checkov results).

What "good" looks like: 100% means every resource passed every policy check. The Nova tagging standard (nova_tagging.py, hard mode) is the primary check.