high-assurance-verificationlisted
Install: claude install-skill jposluns/grc_library
# High-Assurance Verification (the sensitive-change harness)
## Project wiring (the parent library's instantiation; adopters substitute their own)
Portable procedure, concrete names. In the parent GRC library this skill runs with:
- Persistent register: the high-assurance register in the consuming project's working state, one row per sensitive item (the item, which trigger conditions make it sensitive, the stages run and their outcomes, the status). Open rows (`pending` / `in-progress` / `deferred`) are surfaced at session resume by the `/resume` command alongside the other standing registers, so an item survives a session boundary.
- Motivating case: adding a control-framework column to the compliance matrix, where each cell carries a control code whose fit no existence gate can check.
- Cadenced companion on matrix changes: the `/matrix-fit` semantic-fit audit (this harness at apply time, the cadence as the closing check).
An adopting project maps each bullet to its own register location, resume-surfacing mechanism, and companion cadences; the procedure below refers to them generically.
## Overview
Most changes are adequately protected by the routine layers: the research-assistant discipline (workers research, the orchestrator re-reads and authors), the mechanical gates, and the per-change and periodic sweeps. A small subset is not. When a change carries a correctness property no gate can check, is large or delicate enough that a hand-edit is itself a defect risk, and