Skip to content

docs: add compliance pipeline pattern cards#39

Open
jpower432 wants to merge 2 commits into
complytime:mainfrom
jpower432:docs/compliance-pipeline-patterns
Open

docs: add compliance pipeline pattern cards#39
jpower432 wants to merge 2 commits into
complytime:mainfrom
jpower432:docs/compliance-pipeline-patterns

Conversation

@jpower432

Copy link
Copy Markdown
Member

Summary

This PR adds a compliance pipeline pattern — a repeatable Gemara-based pipeline where inputs (driver, catalog, governance, scoping model) change per persona but the flow stays constant. Includes CUE schema, four YAML pattern cards and an overview document.

Related Issues

Ref: #26

Review Hints

N/A

Define the compliance pipeline pattern — a repeatable Gemara-based
pipeline where inputs (driver, catalog, governance, scoping model)
change per persona but the flow stays constant. Includes CUE schema,
four YAML pattern cards (foundation-backed OSS, manufacturer CRA,
manufacturer AI, manufacturer finserv), and an overview document.

Assisted-by: Claude (Anthropic, Claude Opus 4.6)
Signed-off-by: Jennifer Power <[email protected]>
Removed sections detailing various manufacturer personas and their corresponding fields and values.

Signed-off-by: Jennifer Power <[email protected]>
@jpower432 jpower432 requested a review from a team as a code owner June 15, 2026 12:43
@jpower432 jpower432 requested review from fortiz-ai, gxmiranda and hbraswelrh and removed request for a team June 15, 2026 12:43
@jpower432 jpower432 changed the title Docs/compliance pipeline patterns docs: add compliance pipeline pattern cards Jun 15, 2026
@jpower432

Copy link
Copy Markdown
Member Author

This does not fully closes #26, but gives a patterns some use cases to demonstrate the pattern leveraging open source catalogs so we could build our pipeline around them.

@jpower432

Copy link
Copy Markdown
Member Author

CI failure is a false positive. Failing on the original PR title.

@hbraswelrh hbraswelrh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. This is very well-done. What an awesome idea? @jpower432 👏

|:------------------|:-----------------------------------------------------------------------------|:--------------|
| **Persona** | Who you are | Identity |
| **Driver** | External motivation — why you act | Input |
| **Catalog** | The standard (Guidance) you assess against | Input |

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We might want to rename this, but it is essentially supposed to an input for how you measure you posture depending on your driver. Governance artifacts are pre-existing. When you complete this, it folds into your baseline.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants