← Full mapCurated public summary
Index
Entry 08PUBLIC HANDBOOK

Quality Gates, QA, security, and evidence

Risk R0–R3, gates, QA, data safety, browser/runtime validation, artifacts, Truth Labels, Evidence Chain, Independent AI Review, and Known Debt.

Source & authority

Public explanation

PUBLIC HANDBOOK
Based on
Human Handbook 08 — Quality Gates, QA, security, and evidence
Related normative sources
  • NORMATIVE SOURCEStandard · Quality Gates
Authority
Public explanation — NON-NORMATIVE
Summary

Risk R0–R3, gates, QA, data safety, browser/runtime validation, artifacts, Truth Labels, Evidence Chain, Independent AI Review, and Known Debt.

Quality Gates, QA, security, and evidence form one risk-reduction system. Quality is not established by an agent assertion but by evidence proportional to the impact of the change.

Risk and evidence

DCP Flow classifies risk from R0 to R3 and adjusts required evidence. Browser/runtime validation, tests, artifacts, Golden Flows, and independent review are combined according to the affected surface.

Key points
  • Risk R0–R3.
  • Golden Flow evidence.
  • Browser/runtime validation.
  • Independent AI Review when separation helps.

When a gate fails

Not every failure is a product defect. DCP Flow distinguishes Product Defect, Gate Defect, and Harness/Infra Defect. NOT APPLICABLE and Known Debt are allowed only when justified and traceable.

Key points
  • Product Defect.
  • Gate Defect.
  • Harness/Infra Defect.
  • Known Debt and Truth Labels.

Gate states and readiness

A Quality Gate may be PASS, FAIL, NOT RUN, NOT APPLICABLE, or BLOCKED. These states feed verdicts such as READY FOR HUMAN REVIEW, READY WITH KNOWN DEBT, or NOT READY. NOT RUN and BLOCKED never mean PASS, and no verdict grants merge or release authority by itself.

Key points
  • PASS / FAIL.
  • NOT RUN / NOT APPLICABLE / BLOCKED.
  • READY FOR HUMAN REVIEW.
  • READY WITH KNOWN DEBT / NOT READY.

Quality proportional to risk

DCP Flow uses R0–R3 to scale QA depth and evidence. Dimensions may include functionality, architecture, tests, security, data, UI/UX, integrations, observability, build/runtime, documentation, artifacts, and release readiness. Higher risk requires stronger evidence and recovery, not ceremony for its own sake.

Key points
  • R0 trivial/documental.
  • R1 low.
  • R2 medium.
  • R3 high/critical.

Artifacts, documentation, and the Evidence Chain

Correct source does not guarantee a correct artifact. ZIPs, builds, and packages must be inspected directly. Documentation can drift too, which is why Documentation Coherence matters. Truth Labels —OBSERVED, EXECUTED, INFERRED, and NOT AVAILABLE— support an Evidence Chain from claim to gate, check, artifact, and verdict.

Key points
  • Artifact / Package Gate.
  • Documentation Coherence.
  • Truth Labels.
  • Evidence Chain.
Contextual glossary+
Quality Gate

Checkpoint where evidence determines whether work may progress.

Evidence

Proof of an observed or executed result; not an agent assertion.

Risk Class

Risk Class

Known Debt

Known Debt