Review the Threat Model
The canonical model is governance/THREAT_MODEL.md. This is a review procedure, not a duplicate inventory.
Use Criteria
Section titled “Use Criteria”Review before adoption and whenever auth, policy, tokens, keys, revocation, audit, streams, egress, services, ports, secrets, installers, releases, or product boundaries change.
Prerequisites
Section titled “Prerequisites”Pin source/deployed release. Gather rendered deployment, endpoints, secret flow, dependency topology, features, and targeted tests.
Review Procedure
Section titled “Review Procedure”- Confirm deployment fits the documented OSS scope.
- Walk each boundary: untrusted input, mediation, credential, fail-closed behavior, evidence, owner.
- Map assets to the canonical model’s threat categories T1-T14 and run relevant negative checks.
- Review every canonical known limit against deployment.
- Record operator controls: TLS, host isolation, IdP, backup, monitoring, incident process.
- Reject claims relying on enterprise-only or unverified platform controls.
Verification
Section titled “Verification”Retain references/results for accepted threats and owner/containment/acceptance/date for residual risks.
Recovery
Section titled “Recovery”Disable or isolate unsupported boundaries. Report exploitable defects privately.
Next Step
Section titled “Next Step”Apply Harden Security Posture.

