Card context · WIG-1298 — In Review
- 📋 What it requires
- §2/§7: maintain an incident response plan that defines who is notified internally, the escalation path, how affected users are identified, and the timeline for external notification.
- 📄 This document
- Covers the 4 required items (internal notification · escalation · affected-user identification · timeline).
- ⏳ Still missing
- Review/approval, assign who fills each role (Incident Commander · Technical Responder · Legal/Comms), and formally adopt it. Process doc — no code.
🟠 Decisions we need from you
- Confirm who fills each role: Incident Commander, Technical Responder, Legal/Comms.
- Do the escalation path and timelines reflect how we actually operate today?
- Any additional legal/contractual requirement to cover in notification?
Card context · WIG-1307 — Blocked
- 📋 What it requires
- §7: implement real-time alerting for anomalous data-access patterns (bulk downloads, unexpected API calls, access from unusual IP ranges).
- 📄 This document
- A design spec: defines the signals, the already-available data sources, and 2 implementation approaches.
- ⏳ Still missing
- The implementation: choose an approach (SigNoz/New Relic alert rules vs cron) + thresholds, build the alerting for the 3 classes (volume · privileged · geo/IP), route to
privacy@, and verify. The cron option depends on WIG-1324.
🟠 Decisions we need from you
- Choose an approach: alert rules on SigNoz/New Relic (recommended, no new infra) vs a dedicated cron.
- Do you approve building it, and at what priority? (the cron option depends on finishing WIG-1324)
- Do you confirm initial thresholds or delegate them to the team to tune against real traffic?
Card context · WIG-1296 — Blocked
- 📋 What it requires
- §2: conduct regular access reviews (at minimum quarterly) to ensure no unauthorized access to production systems / user data exists.
- 📄 This document
- The quarterly review process: systems in scope, per-quarter steps, an evidence log, and off-cycle triggers (departures / role changes).
- ⏳ Still missing
- Assign an owner, run the first quarter and record evidence, and document the grant/revoke process. Ops/governance — no code.
🟠 Decisions we need from you
- Who is the review owner (accountable for running it each quarter)?
- Is the systems-in-scope list complete (Railway, AWS, Cloudflare, DB, GitHub, vendors, email)?
Every compliance doc we created, grouped by how much review it needs. Each is collapsed — click to expand context + the full document.