Skip to content
PERMISSION/PROTOCOL

Illustrative evaluation · not a customer case study

One workflow. A clear test. Evidence you can review.

A team already reviews changes before deployment. It wants a portable record of who authorized each selected commit. Here is how a scoped GitHub evaluation could test that requirement.

Discuss a workflow like this

$10,000 · 2 weeks · fixed fee

What gets configured

  • One GitHub repository
  • One approval workflow and agreed test path
  • Named approvers and success criteria
  • Required checks and deployment rules for the selected path
  • Receipt inspection and independent verification steps

What your team brings

  • A workflow owner and a GitHub administrator
  • Named approvers and access to a test environment
  • A specific evidence requirement and someone who can judge it
  • Agreement on test cases and acceptance criteria before kickoff

Agree on what a useful result looks like.

These are proposed acceptance tests, not reported results. Enforcement depends on the integration version, configuration, and bypass permissions. Findings may include gaps that need further work.

Approval required

An agent proposes a change covered by the policy.

Acceptance target: The protected path waits for the named reviewer.

Denied request

The reviewer denies that request.

Acceptance target: The selected action stays blocked on the configured path.

Approved request

The reviewer approves a fresh request for the intended commit.

Acceptance target: The gate recognizes that authorization and produces the expected receipt.

Changed commit

The commit changes after approval.

Acceptance target: The earlier approval cannot authorize the new change.

Service unavailable

The authorization service is unavailable during a test.

Acceptance target: Observe the actual behavior, compare it with the agreed requirement, and record any gap.

Evidence review

The reviewer inspects the artifact and verifies its signature.

Acceptance target: The record matches the action, approver, policy, and time; verification is reproducible.

Leave with a reviewable evidence pack.

The agreed deliverables include the workflow configuration, test results, signed artifacts with verification instructions, and an acceptance readout documenting findings and open gaps. Your reviewer decides whether the evidence meets the requirement.

The two-week clock starts once agreed access is available. A broader rollout or extension requires a separate agreement. This example does not promise certification, auditor acceptance, or coverage of other execution paths.