Skip to content

docs(governance): add privilege revocation policy - #1640

Open
Raydev-tech wants to merge 1 commit into
rinafcode:mainfrom
Raydev-tech:docs/privilege-revocation-policy
Open

Raydev-tech wants to merge 1 commit into
rinafcode:mainfrom
Raydev-tech:docs/privilege-revocation-policy

Conversation

@Raydev-tech

Copy link
Copy Markdown

Overview

Adds the missing privilege revocation policy to Governance/. The Governance/
folder had no Governance/policies/REVOCATION.md, so contributors and
maintainers had no versioned reference for when a granted privilege (repository
access, team or working-group membership, bot and release credentials, and other
named authorities) may be revoked, who may start that process, and how the
affected holder can contest it. This closes that governance gap with a document
and its companion regression test, contained entirely within Governance/.

Related Issue

Closes #1487

Changes

  • [ADD] Governance/policies/REVOCATION.md

    • Grounds for Revocation — a closed, enumerated list: security risk,
      confirmed misconduct, breach of trust, loss of competence or availability,
      and a legal or platform requirement. Explicitly states revocation is never a
      general sanction.
    • Who May Initiate — maintainers, the Security Response Team (which may
      act first and document afterwards on an active risk), the relevant working
      group or role owner, and the holder by voluntary surrender. Forbids an
      initiator deciding a matter they are subject to and requires a
      conflict-of-interest disclosure.
    • Revocation Steps — a five-step sequence: open a private record (holder,
      privilege, ground, evidence) → independent decision → apply the removal and
      rotate every issued credential → notify and record → follow up on any gap.
    • Appeal Path — private filing within 14 calendar days, an independent
      reviewer, a written decision with reasoning within 10 business days, one
      re-review with new evidence, and recorded exceptions for ongoing security or
      legal risk.
    • Ownership and Review / Success / Revision History matching the
      house document structure, with references to the existing MAINTAINER.md,
      SECURITY_RESPONSE_TEAM.md, CONFLICT_OF_INTEREST.md, and
      ESCALATION_PATH.md documents.
  • [ADD] Governance/policies/REVOCATION.test.ts

    • Vitest regression suite that pins the document title, the canonical section
      list, the five enumerated grounds, the four initiation rights, the step
      guarantees, and the appeal windows, and asserts that each governance file it
      references actually exists.

No application code, configuration, or files outside Governance/ are touched.

Verification Results

Installed nothing; the repository's own toolchain ran the new suite.

$ vitest run Governance/policies/REVOCATION.test.ts
 Test Files  1 passed (1)
      Tests  28 passed (28)

Also asserted in-suite:
- policy line width <= 82 columns (house style)
- no unresolved TBD/TODO/FIXME/<placeholder> markers
- referenced governance documents exist on disk
Acceptance Criteria Status
Governance/policies/REVOCATION.md documents grounds for revocation ✅ Closed list of five enumerated grounds
Policy specifies who can initiate a revocation ✅ Maintainers, Security Response Team, role owners, holder
Policy defines the appeal path ✅ 14-day filing, independent review, written decision, re-review
Regression tests added where applicable ✅ Governance/policies/REVOCATION.test.ts (28 tests)
Scope limited to a maximum of two files ✅ One document + one test
No changes outside the Governance/ folder ✅ Only Governance/policies/ touched
Change is documented ✅ Purpose/Scope/Ownership/Revision History in the policy

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Raydev-tech Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a privilege revocation policy for TeachLink Web

1 participant