Files
acdl/skills/compliance.md
T
Jon Chery 2c08c778a9 docs(P4): Atelier skills mapping — 9 skill files + index + BA.A extension (REQ-221, REQ-222)
REQ-221: skills/ directory with 9 Atelier-derived skill files mapped to the
BA.A citizen-developer catalog: api, security, data, testing, observability,
errors, devops, infrastructure-as-code, compliance. Each names the Atelier
source path, distills first-principles to the citizen-dev-relevant subset,
links to agent-checklist triggers, maps to BA.A 5-skill catalog.

REQ-222: docs/skills.md index (9-skill table, Atelier provenance, 8 core
principles C1-C8, consumption instructions, reference-only domains, excluded
domains). PROJECT.md BA.A decision extended with the Atelier-derived skill
catalog reference.

---ci---
project: acdl
phase: 4
milestone: v1.18
status: execute
requirements:
  covered: [REQ-221, REQ-222]
  partial: []
---/ci---
2026-08-06 15:11:12 +00:00

2.4 KiB

Skill: Compliance

Atelier source: domains/compliance/ (first-principles + audit-logs, data-retention, policy-as-code, evidence) Core principles: C1 Correctness, C5 Reversibility BA.A mapping: cross-cutting (all 5 skills) Consumer: read this before any regulated-environment submission.

First Principles (citizen-developer-relevant subset)

  • Audit records are immutable once written. Deletion/mutation is itself an auditable incident. Nova's Decision Ledger (SQLite hash-chain, v1.17; S3 Object Lock + JWS future) enforces this.
  • The set of auditable actions is defined a priori. "We forgot to log it" is a violation. The submission-readiness gate's policyPreconditions declare what the platform will audit.
  • Policy violations block before the action. Checkov runs pre-apply; the confidence signal gates; the HITL gate stops. Compliance is admission-time, not audit-time.
  • Evidence gathered as a byproduct of operation. Not assembled manually at audit time. Every pipeline run emits events into the Decision Ledger + the evidence stream.
  • Every logged action traces to an authenticated principal. No shared/generic identities. The HITL approver identity (D-042) is recorded with every prod/dr promotion.

Agent-Checklist Triggers (§ Compliance)

  • Audit records are immutable once written; deletion/mutation is itself auditable (P1)
  • The set of auditable actions is defined a priori (P2)
  • Policy violations block before the action (admission/CI/CD-time) (P5)
  • Evidence gathered as a byproduct of operation, not assembled manually (P6)
  • Every logged action traces to an authenticated principal; no shared/generic identities (P7)

How Nova Uses This

Nova's compliance posture is framework-agnostic (D-024 in Atelier; the platform lists GDPR, SOX, SOC2, DORA — not any single framework). The compliance skill tells you what the platform enforces (immutable audit, pre-apply policy, evidence byproduct, authenticated principals) and what your application must enforce (the same standards on its own surface). The submission-readiness gate ensures your contract declares policyPreconditions; the compliance skill ensures your application respects them. This is the RACI compliance-standard equivalence made concrete: regardless of upstream source (AI agent, SDLC, dev platform), the same compliance standards apply to every submission.