- **A3 ratchet governance** — `policies/ratchet-governance.yml`: the `prevents: <incident-class>` annotation convention + the `catastrophic-low-frequency` severity tag (makes a control harder to prune; a clean window is expected for rare-but-severe controls). A 9-class incident taxonomy is the WHY-home; a D5-scoped coverage map (deploy/gate controls + the elements rule 6 reads) states its own scope (silence ≠ safety). Scoped `prevents:` markers added to `templates/{handoff-deploy,handoff-implement,gate-report,verification-gate}.md` + `workflows/{greenlight-deploy,eight-phase-flow}.md`. **Pruning is PO-owned and never automatic** — an un-annotated, non-firing element is a *review candidate* only (needs named incident-class, severity, window, negative examples, operator confirmation).
0 commit comments