| name | phase-4-advanced-month-4 |
| description | Audit evidence collection and compliance validation. Automated archival, OpenSSF Scorecard monitoring, SLSA verification, and continuous proof of controls. |
Phase 4: Advanced (Month 4+)
When to Use This Skill
Phase 4 completes the implementation with three critical areas:
- Audit Evidence Collection - Automated archival of branch protection, PR reviews, signatures, SBOMs
- Compliance Validation - OpenSSF Scorecard, Best Practices Badge, SLSA verification, license checks
- Audit Simulation - Mock audit timeline, gap analysis, remediation
These controls provide continuous proof of compliance.
Implementation
See the full implementation guide in the source documentation.
Related Patterns
- Audit Evidence Collection
- OpenSSF Scorecard
- SLSA Provenance
- Implementation Roadmap Overview
- Phase 3: Runtime