Skip to main content
ZEV GOVERNANCE BOOTSTRAP v5 · CURRENT

Universal Independent Reviewer Governance for Software Projects

Zev Governance Bootstrap

A risk-adaptive governance system for AI-assisted software implementation, independent review, and controlled release.

MarkdownTXT
Control room status governance model
OWNER AUTHORITYFINAL
REVIEWER GATEINDEPENDENT
CODING AGENTIMPLEMENTER
RELEASE CONTROLOWNER AUTHORIZED

THE ARTIFACT BOUNDARY

Who gets what?

The universal bootstrap establishes the relationship. The generated Project Governance Lock carries the project-specific state. The Coding Agent receives an authorized Reviewer implementation prompt.

UNIVERSAL BOOTSTRAP

Independent Reviewer

Reusable v5 resource. It is not a direct Coding Agent prompt.

PROJECT GOVERNANCE LOCK

Independent Reviewer

Project-specific acceptance criteria, evidence rules, and the report placeholder.

CODING AGENT PROMPT

Coding Agent

One copy-ready authorized instruction generated by the independent Reviewer.

START HERE · HOW TO USE IT

A compact loop from bootstrap to closeout.

Follow the handoff in order. The universal bootstrap starts governance; the Project Governance Lock carries the project state.

STEP 01 / 08YOU

1. PLAN YOUR PROJECT

Before implementation, sufficiently define requirements, scope boundaries, architecture, business rules, risks, and acceptance criteria.

NEXT HANDOFF →

INTERACTION 1 · GOVERNANCE LOOP

Information moves; authority stays clear.

Select a state or let the control room advance. Motion is a signal for the current handoff, not decoration.

PROJECT CONTROL PLANE01 / 06
OWNERREVIEWERCODING AGENT
EVIDENCE PACKET

PLANNING & REQUIREMENTS

Scope, architecture, risks, and protected decisions are defined before coding.

INTERACTION 2 · PASTE BOUNDARY

Where do I paste the report?

The Coding Agent report goes into the same Reviewer conversation—the Universal Bootstrap is used once to start.

BEGIN CODING AGENT REPORT

[PASTE CODING AGENT REPORT HERE]

END CODING AGENT REPORT

SAME REVIEWER CONVERSATION

Send only the newest complete Implementation Report because governance is already in context.

NEW REVIEWER CONVERSATION

Provide the saved Project Governance Lock (GOVERNANCE_LOCK.md) with the latest report inserted.

INTERACTION 3 · EVIDENCE SCANNER

Assertion is not attestation.

Explore the evidence class before deciding whether a claim can close a gate.

CLASS A

Agent Attested

The Coding Agent reports a claim; prose alone does not become M-class evidence.

M / I / O / R / A are a shared vocabulary for reviewing evidence. They do not turn an agent’s prose into machine evidence.

INTERACTION 4 · REVIEW VERDICT

What happens at the gate?

Choose the verdict to see the next workflow state. A blocked evidence gap is not permission to rewrite valid implementation.

NEXT WORKFLOW STATE

Gate closes. Next authorized milestone or action proceeds.

FAILURE MODES

What this protects you from

SELF-APPROVAL

Green tests do not let the Coding Agent close an independent gate.

MOVING GOALPOSTS

Locked acceptance criteria make review changes visible and accountable.

FAKE CONFIDENCE

Test counts are not proof when the test validity was never inspected.

SPLIT-BRAIN STATE

One writable authority prevents UI, editor, or cache state from silently diverging from or overwriting canonical persisted state.

REVIEW LOOPS

One consolidated finding pass reduces blocker-by-blocker drift.

UNSAFE RELEASE

Production authorization remains an Owner-controlled decision.

Advantages

  • independent gate
  • locked acceptance criteria
  • evidence discipline
  • scope protection
  • consolidated blockers
  • risk-adaptive verification
  • safer release engineering
  • repository-native project memory

Trade-offs

  • larger initial bootstrap
  • slightly slower project setup
  • strong verification takes time on high-risk work
  • Owner decisions may still be required
  • optional controls can be overkill for tiny projects
  • cannot guarantee zero bugs

PROJECT LIFECYCLE

More structure upfront. Less uncertainty later.

Implementation milestones and release gates are related, but they are not the same state.

IDEA
DEFINITION OF READY
MILESTONES
INDEPENDENT REVIEWS
ROADMAP COMPLETE
OPERATIONAL READINESS
STAGING WHEN REQUIRED · CONDITIONAL
OWNER PRODUCTION AUTHORIZATION
CONTROLLED RELEASE
OWNER SMOKE WHEN REQUIRED · CONDITIONAL
PROJECT CLOSED
MAINTENANCE

QUICK GUIDE

Understand the loop first.

Use this interactive explanation to learn the roles, evidence boundary, report placement, and verdict states without reading the full governance document.

FULL GOVERNANCE

Searchable v5 reference.

When you need the exact operating rules, open the canonical v5 text. View, Copy, Markdown, and TXT derive from the same source.

VERSION HISTORY

One current resource, preserved archives.

RISK-ADAPTIVE FIT

Use the control strength that matches the risk.

Full governance is strongest where persistence, users, money, or multiple milestones make uncertainty expensive.

WHEN TO USE · STRONG FIT

production websitesSaaSclient/business applicationsAPIsauthenticated systemspersistent-data systemspayment/financial systemsworkflows/automationAI productsmulti-milestone software

WHEN NOT TO USE · FULL FORM MAY BE EXCESSIVE

throwaway prototypeslearning snippetsdisposable experimentstrivial local scripts

Risk-adaptive does not mean no controls; optional release and security ceremony is activated when the project risk warrants it, rather than automatically for every small or local project.