Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.
Defines coding standards, secure-coding requirements, and mandatory peer review before merge.
Ensure code is secure, maintainable, and reviewed by qualified peers before merge.
All code, IaC, and configuration merged to main.
| Activity | R | A | C | I | Cadence |
|---|---|---|---|---|---|
| Author code | Engineer | Tech Lead | Reviewers | Team | Continuous |
| Review PR | Reviewers (2+) | Tech Lead | Security | Team | Per PR |
| Enforce merge gates | Platform Eng | Engineering Director | Security | Team | Continuous |
Inputs
Outputs
| Metric | Target |
|---|---|
| PRs merged without required approvals | 0 |
| Critical SAST findings in main | 0 |
| Record | Retention |
|---|---|
| PR history & reviews | 7 years (git history) |
| Merge gate logs | 3 years |
See the Versions tab for the full change history maintained by the Auto-Doc Engine.
Document code: SOP-SDLC-03 · Aligned to OWASP ASVS L2 / ISO 27001 A.14.2. Controlled document — reproduction outside the UBC QMS requires the Quality Manager's approval.