name: "🛡️ Audit"
about: "Propose, conduct, or document a security, accessibility, code, or process audit."
title: "[Audit] Audit maintenance ownership documentation for shared .github defaults"
labels:
Audit Summary
Audit the current guidance gap around maintenance ownership in the shared .github adoption work.
This audit should determine what ownership information maintainers need when adopting shared .github defaults into other repositories, and where that ownership guidance should live so it stays clear, lightweight, and maintainable.
The work sits under the parent task to create a repeatable adoption guide for shared .github defaults. That parent issue already establishes the need to distinguish reusable assets from repo-local assets, reduce onboarding friction, and prefer the smallest workable solution. This audit should validate the maintenance-ownership part of that guidance before documentation is finalised.
Audit Checklist / Scope
In Scope
Out of Scope
Findings / Risks
Working Findings
Risks
Remediation Actions
Acceptance Criteria
Additional Acceptance Criteria For This Audit
Additional Context
Parent Issue
#17 — Create repo adoption guide for shared .github defaults
Source Issue
#330 — Document maintenance ownership
Relevant Guidance
AGENTS.md sets global AI, quality, security, accessibility, and maintenance expectations
.github/custom-instructions.md defines repo-local boundary rules for the .github control-plane repository
Suggested Audit Standard
Use a documentation-first, minimum-maintenance lens:
- prefer a clear ownership model over automation
- avoid inventing new process unless the benefit is obvious
- keep guidance explicit enough for maintainers adopting shared defaults into existing repositories
- ensure the final wording is in UK English and easy to reuse in reviewer-facing documentation
Definition of Ready (DoR)
Definition of Done (DoD)
name: "🛡️ Audit"
about: "Propose, conduct, or document a security, accessibility, code, or process audit."
title: "[Audit] Audit maintenance ownership documentation for shared .github defaults"
labels:
type: "Task"
parent_issue: "[Task] Write and validate repo adoption guide with explicit checklists for shared .github files #17"
source_issue: "[Audit] Audit maintenance ownership documentation for shared .github defaults #330"
status: "draft"
created_by: "@ashleyshaw"
created_at: "2026-05-19"
context:
summary: "Audit how maintenance ownership should be documented within the shared .github adoption guidance."
relates_to:
focus:
Audit Summary
Audit the current guidance gap around maintenance ownership in the shared
.githubadoption work.This audit should determine what ownership information maintainers need when adopting shared
.githubdefaults into other repositories, and where that ownership guidance should live so it stays clear, lightweight, and maintainable.The work sits under the parent task to create a repeatable adoption guide for shared
.githubdefaults. That parent issue already establishes the need to distinguish reusable assets from repo-local assets, reduce onboarding friction, and prefer the smallest workable solution. This audit should validate the maintenance-ownership part of that guidance before documentation is finalised.Audit Checklist / Scope
In Scope
AGENTS.md.github/custom-instructions.mdOut of Scope
.githubrepository filesFindings / Risks
Working Findings
AGENTS.mdprovides global operating rules, but does not clearly define maintenance ownership for adopted.githubassets in consuming repositories..github/custom-instructions.mddefines boundary rules and repository scope, but does not yet appear to give maintainers a simple ownership model for adopted files.Risks
.githubrepo and consuming repositoriesRemediation Actions
.githubcontrol-plane repo owns the shared baseline.github/custom-instructions.mdwhere usefulAcceptance Criteria
Additional Acceptance Criteria For This Audit
.githubdefaults.github/custom-instructions.md.githubrepo owns versus what consuming repos own after adoptionAdditional Context
Parent Issue
#17— Create repo adoption guide for shared.githubdefaultsSource Issue
#330— Document maintenance ownershipRelevant Guidance
AGENTS.mdsets global AI, quality, security, accessibility, and maintenance expectations.github/custom-instructions.mddefines repo-local boundary rules for the.githubcontrol-plane repositorySuggested Audit Standard
Use a documentation-first, minimum-maintenance lens:
Definition of Ready (DoR)
Definition of Done (DoD)