Add UK AI operational resilience Advisory bundle - #49
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot review this workflow for UK threat spec adherance. |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Claude Opus 5 found substantive adherence gaps: AI functionality was incorrectly used as a scope gate, repository visibility and dependency evidence were missing, dormancy could be treated as safe, and private-code recommendations did not enforce the GOV.UK threat-model triad or periodic reapproval. Commits 942e834 and 49a51dd address these by making AI a threat accelerator, enforcing open-by-default and the minimum control standard, collecting visibility/alert-age/automation evidence, and requiring attacker + publication-added risk + realistic path to harm before any closure recommendation. Focused tests and compatible-manifest compilation pass. |
|
@copilot add an agentic workflow that runs on a schedule (weekly) and ensures that the fleet is still aligned with the original specification. |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Implemented in 4e0cd2c. |
|
@copilot resolve the merge conflicts on this branch. |
…ndle-another-one # Conflicts: # tests/unit/workflow-contract.test.mjs Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Resolved in merge commit |
Introduces an installable Advisory operations bundle that adapts the UK AI operational resilience workflow for centralized, organization-wide execution.
Changes
Central orchestration
Operational resilience advisory
Safety boundaries
Package integration