# Policy Update

*Policy-change redlines with maker–checker sign-off — current vs proposed, with cited findings and a confirmed control mapping.*

**Policy Update** delivers a **redline diff set** for a policy change: the current vs
proposed document, a reconciled control mapping, and cited findings — governed by a
**maker–checker** lifecycle so nothing is accepted without a second signer.

## When to use it

A policy or guideline is changing and you need a defensible record of *what* changed,
*how significant* each change is, and *who confirmed it*.

## What the outcome shows

- **Current vs proposed** documents, each with controls and obligations that carry a **citation** (document, control, quote).
- **Pairing** — how current and proposed map together, with a confidence score and a confirmation state.
- **Reconciliation** — control mappings (matched / added / removed / unresolved) with counts.
- **Findings** — each classified (editorial, scope changed, obligation added/removed, strengthened/weakened), with a severity, a confidence, and whether it **requires human validation**.
- **Provenance** — analysis version and SHA-256 hashes of the sources.

## Maker–checker lifecycle

The review moves through **pairing review → finding review → owner review**, and the
gates are enforced:

- Unconfirmed pairings **stop at pairing review**.
- Any finding that requires human validation **stops at finding review**.
- Confirming a pairing records the **actor's id and a timestamp** — that's the checker.
- Every citation is validated against the real control text.

## What you get

A signed policy diff set with a redline canvas, the change list, and a decision bar —
review each finding, confirm the pairing, and approve.
