Governance Exception Request
Complete all fields. Incomplete requests will be returned without review. Submit as a PR to
docs/policies/governance-exception-register.mdwith this file attached, or open an issue taggedgovernance-exception.
Requestor
- Name / Team:
- Date Submitted: YYYY-MM-DD
- Contact:
Exception Details
Control being deviated from (reference governance.md section or policy name):
Example: CI-02 — mypy must not use continue-on-error
Description of the deviation:
What exactly will be different from the required control?
Business / technical justification:
Why cannot the control be implemented as specified right now?
Risk assessment:
- Likelihood of harm if exploited: Low / Medium / High
- Impact if exploited: Low / Medium / High
- Overall risk level: Low / Medium / High / Critical
Compensating controls in place:
What is being done to mitigate the risk while the exception is active?
Time Bounds
- Requested start date: YYYY-MM-DD
- Requested expiry date: YYYY-MM-DD (max 12 months; max 90 days for High risk)
- Remediation ticket: TICKET-XXX (must exist before exception is approved)
- Remediation target date: YYYY-MM-DD
Break-Glass Procedure
If this exception relates to an emergency override of a security control (e.g., deploying without a passing security scan due to a P0 incident), document the break-glass steps below. All break-glass activations must be logged in the incident postmortem.
Post-activation review required within: 24 hours
Approvals
| Role | Name | Date | Decision |
|---|---|---|---|
| Security | Approve / Reject | ||
| Platform Engineering Lead | Approve / Reject | ||
| CISO (High risk only) | Approve / Reject |
Exception ID (assigned on approval): EX-XXX