Section 1 of 1
What this verdict captures
This template is structured. The working copy is being finalized by our subject-matter editors — directionally accurate today, refined shortly.
- Capability statement — what the tool actually does, in one paragraph a non-technical reader understands.
- Data boundary — what classes of data the tool is permitted to see, and how that boundary is enforced.
- Identity model — how authenticated users are scoped (SSO? per-user keys? shared service account?).
- Residual risk — what could still go wrong after controls, and what compensates.
- Verdict — Approved / Approved with conditions / Not approved, with the conditions named.