templatesException Request

Governance Exception Request

Complete all fields. Incomplete requests will be returned without review. Submit as a PR to docs/policies/governance-exception-register.md with this file attached, or open an issue tagged governance-exception.


Requestor

  • Name / Team:
  • Date Submitted: YYYY-MM-DD
  • Contact:

Exception Details

Control being deviated from (reference governance.md section or policy name):

Example: CI-02 — mypy must not use continue-on-error

Description of the deviation:

What exactly will be different from the required control?

Business / technical justification:

Why cannot the control be implemented as specified right now?

Risk assessment:

  • Likelihood of harm if exploited: Low / Medium / High
  • Impact if exploited: Low / Medium / High
  • Overall risk level: Low / Medium / High / Critical

Compensating controls in place:

What is being done to mitigate the risk while the exception is active?


Time Bounds

  • Requested start date: YYYY-MM-DD
  • Requested expiry date: YYYY-MM-DD (max 12 months; max 90 days for High risk)
  • Remediation ticket: TICKET-XXX (must exist before exception is approved)
  • Remediation target date: YYYY-MM-DD

Break-Glass Procedure

If this exception relates to an emergency override of a security control (e.g., deploying without a passing security scan due to a P0 incident), document the break-glass steps below. All break-glass activations must be logged in the incident postmortem.

Post-activation review required within: 24 hours


Approvals

RoleNameDateDecision
SecurityApprove / Reject
Platform Engineering LeadApprove / Reject
CISO (High risk only)Approve / Reject

Exception ID (assigned on approval): EX-XXX