Residual-Risk Acceptance Record
“The gate said don't ship — and we're shipping anyway. Who signed that, and until when?”
The deployment decision gate emits a verdict — allow / allow_with_conditions / inconclusive / block — plus enumerated block reasons and trust qualifiers. But in the real enterprise loop, when the gate returns anything other than a clean allow, an org frequently ships anyway under a formally-recorded, time-boxed exception. A SOC 2 / ISO 27001 risk-acceptance auditor then demands the artifact that records it: WHO accepted WHICH specific enumerated residual risks, WHY, and until WHEN. AgentSmack's residual-risk acceptance lens consumes a deployment-gate report verbatim, matches each open risk against the operator's acceptance entries (approver + justification + expiry), and emits ONE closed waiver verdict plus a content-addressed, digest-verifiable Residual-Risk Acceptance Record.
The killer property an auditor relies on: a confirmed compromise, forged evidence, or a self-inconsistent (tampered) scorecard can NEVER be papered over by a waiver — those are the non_waivable set, and an acceptance covering one keeps the verdict non_waivable_risk_present no matter how perfectly formed it is. An expired or out-of-window acceptance is never silently honored. And the record is digest-bound: editing an approver, justification, expiry, or risk id after the fact breaks its content address. It is a PURE decision aggregator over an already-computed gate report (no clock in core — the evaluation instant is supplied; no new surface, no new dimension, no DB). Fill a sample below.
Fill with a sample to watch the waiver verdict swing — a confirmed hard blocker can NEVER be cleared by an acceptance (it stays non-waivable), while a soft trust qualifier covered by a valid, unexpired acceptance becomes fully accepted with a digest-verifiable record.