Governance Domains

Delivery, and why it is out of scope

Delivery evidence can be collected when a repository is supplied, but it is not scored and is excluded from the published domain weights.

Currentengine 9.0.0Verified 2026-08-30

The position

Delivery governance is not part of the assessment. It is excluded from the offered domains and from the published weights, rather than reported as an unassessed fourth pillar.

Every board pack states this explicitly, so a reader is never left wondering whether it was assessed and failed.

Why

Assessing how changes reach an environment requires read access to the source control that produces them. The AWS-only authorization used by this engagement does not grant that, and should not: it is a different system, with a different owner and a different access decision.

What exists

A collector can gather delivery evidence from a source repository when one is explicitly supplied: workflow presence, branch protection on the default branch, merged pull requests, and recent commit activity.

It is collected as context. It is not scored, does not contribute to the overall rating, and does not appear in the weights.

What a delivery assessment would need

An explicit, separate authorization to read the relevant source control, and a scoring model published to the same standard as the three domains that are in scope. Neither exists today.