Disclosure & Notification Pipeline

Disclosure & Notification Pipeline A workflow diagram generated by Archify. 01 / Sources 02 / Layer 05 Assurance & Continuous Compliance 03 / Audiences 04 / Evidence Select duties Draft + approve Send + record Registry entry · facts per system · Sources › Select duties Registry entry facts per system Trigger · incident, change · Sources › Select duties Trigger incident, change Duty matrix · audience, clock · Layer 05 Assurance & Continuous Compliance › Select duties Duty matrix audience, clock Templates · versioned as code · Layer 05 Assurance & Continuous Compliance › Draft + approve Templates versioned as code Approval · one voice · Layer 05 Assurance & Continuous Compliance › Draft + approve Approval one voice Disclosures · notice, card, page · Audiences › Send + record Disclosures notice, card, page Notified parties · provider, authority · Audiences › Send + record Notified parties provider, authority Notice records · who, what, when · Evidence › Send + record Notice records who, what, when publish send duties logged facts draft event Legend Agent logic Policy Context / trace External system

Generated, not hand-written

  • • The transparency page and system card are rebuilt from the registry on every release
  • • A duty matrix maps registry facts to notices, surfaces and clocks
  • • A rendering test fails the build when a notice disappears from a surface

Triggers start clocks

  • • An incident, breach, material change or retirement emits a trigger
  • • The pipeline selects the audiences and starts each clock
  • • Holding statements exist in skeleton before any incident

Every notice is evidence

  • • Each notice records audience, template version, approver and time
  • • The deployment decision and incident records point at them