Governance
Capture app context first, then complete domain-filtered controls with pass/fail/na evidence in one exportable workflow.
reviewer: can read and update reviews.tenant_admin: can read, update, finalize, and export reviews.platform_admin: inherits full review access for support and oversight workflows.Exported bundles include the review template snapshot, answered controls, computed risk summary, prioritized remediation actions, and immutable lifecycle events for reviewer accountability.