Assessment workflow

From repository evidence to an approval-ready report

One guided workspace keeps the assessment, evidence package, report, and final human decision connected to the same immutable repository snapshot.

  1. Run

    Create an authorized assessment engagement and capture the exact repository state.

  2. Verify

    Review exact-commit evidence, scanner dispositions, limitations, and cross-format report consistency.

  3. Approve

    Use Final Review to accept the exact report package. NICO never authorizes client delivery automatically.

ONGOING ENGINEERING OVERSIGHT

See what changed after an accepted assessment.

Retainer Ops does not rerun the full assessment and does not deploy code. It compares current GitHub evidence with one exact accepted baseline, identifies blockers and release concerns, and prepares weekly and monthly material for human review.

ONE CONTROL

Refresh ongoing evidence

Read-only GitHub evidence

What it checks: current commit, commits, pull requests, open issues, workflow results, CodeQL activity, releases, deployments, and verified blocker signals. It never treats an empty field as proof that risk is clear.

Optional business context

These notes add decisions and business context that GitHub cannot prove. They cannot turn failed or unavailable technical evidence into a clean result.

Advanced project scope