API Outcome-Centric API Policy PortalGuidance ยท Gates ยท Evidence
๐Ÿ”ด RED

disconnect-screen-api

REJECTED - RELEASE BLOCKED

8.5Required 90.0
Repositorypolicy-repository/examples
Refnoncompliant-api
Commitdemo
Timestamp2026-07-27 09:20:22 UTC

Dimension traffic lights

StatusDimensionOwnerScoreGatesFailed gates
๐Ÿ”ด REDBusiness outcome and capability alignmentEnterprise Architecture60.0%3/5OUT-003, OUT-005
๐Ÿ”ด REDSpecification and data-contract qualityAPI Platform0.0%0/5SPEC-001, SPEC-002, SPEC-003, SPEC-004, SPEC-005
๐Ÿ”ด REDLean API and resource designAPI Design Council0.0%0/6LEAN-001, LEAN-002, LEAN-003, LEAN-004, LEAN-005, LEAN-006
๐Ÿ”ด REDSecurity and role-aware authorizationSecurity Architecture0.0%0/6SEC-001, SEC-002, SEC-003, SEC-004, SEC-005, SEC-006
๐Ÿ”ด REDNoSQL transactional and data integrityData and Domain Architecture0.0%0/9INT-001, INT-002, INT-003, INT-004, INT-005, INT-006, INT-007, INT-008, INT-009
๐Ÿ”ด REDCross-layer observability and auditabilitySRE and Observability0.0%0/6OBS-001, OBS-002, OBS-003, OBS-004, OBS-005, OBS-006
๐Ÿ”ด REDTesting automation and mock coverageQuality Engineering0.0%0/4TEST-001, TEST-002, TEST-003, TEST-004
๐Ÿ”ด REDHealth and business-impact exposureSRE and Operations0.0%0/6HLTH-001, HLTH-002, HLTH-003, HLTH-004, HLTH-005, HLTH-006
๐Ÿ”ด REDAI, MCP, and Agent-to-Agent governanceAI Platform Governance50.0%1/2AI-001
๐Ÿ”ด REDLifecycle, versioning, and reuseAPI Product Management0.0%0/4LIFE-001, LIFE-002, LIFE-003, LIFE-004

Gate findings

RuleDimensionSeverityBlockingFinding
OUT-003outcome_capabilityHIGHNoBusiness owner is defined
OUT-005outcome_capabilityHIGHNoAt least one consumer is identified
SPEC-001specification_contractCRITICALYesOpenAPI file exists
SPEC-002specification_contractCRITICALYesOpenAPI structure is valid
SPEC-003specification_contractHIGHNoBackward compatibility is declared
SPEC-004specification_contractHIGHNoStandard error model is declared
SPEC-005specification_contractCRITICALYesSecurity scheme is declared
LEAN-001lean_resource_designHIGHNoAPI is resource-oriented
LEAN-002lean_resource_designHIGHNoAPI is not screen-specific
LEAN-003lean_resource_designHIGHNoCollection and detail access are separated
LEAN-004lean_resource_designHIGHNoPayload is right-sized
LEAN-005lean_resource_designHIGHNoAPI is reusable
LEAN-006lean_resource_designHIGHNoPaths avoid UI and database implementation terms
SEC-001security_authorizationCRITICALYesAuthentication is configured
SEC-002security_authorizationCRITICALYesObject-level authorization is required
SEC-003security_authorizationHIGHNoActor/subject model is defined
SEC-004security_authorizationHIGHNoPolicy-as-code is enabled
SEC-005security_authorizationHIGHNoActing modes are declared
SEC-006security_authorizationCRITICALYesOpenAPI declares security requirements
INT-001nosql_integrityCRITICALYesNoSQL integrity control set is complete
INT-002nosql_integrityCRITICALYesIdempotency is enabled
INT-003nosql_integrityHIGHNoAggregate owner is declared
INT-004nosql_integrityHIGHNoSingle-writer rule is declared
INT-005nosql_integrityHIGHNoConcurrency-control mechanism is declared
INT-006nosql_integrityHIGHNoOutbox/inbox reliability is enabled
INT-007nosql_integrityHIGHNoProjection freshness is measured
INT-008nosql_integrityHIGHNoReconciliation is defined
INT-009nosql_integrityHIGHNoSaga or compensation is defined
OBS-001observability_auditHIGHNoTrace propagation is enabled
OBS-002observability_auditHIGHNoCorrelation ID is enabled
OBS-003observability_auditHIGHNoBusiness transaction ID is enabled
OBS-004observability_auditHIGHNoStructured logging is enabled
OBS-005observability_auditCRITICALYesAudit events are enabled
OBS-006observability_auditHIGHNoRequired observability headers exist in OpenAPI
TEST-001testing_mockingCRITICALYesContract tests exist
TEST-002testing_mockingCRITICALYesAuthorization tests exist
TEST-003testing_mockingHIGHNoFailure-path tests exist
TEST-004testing_mockingHIGHNoScenario-based mock data exists
HLTH-001health_impactHIGHNoLiveness endpoint is declared
HLTH-002health_impactHIGHNoReadiness endpoint is declared
HLTH-003health_impactHIGHNoDependency health endpoint is declared
HLTH-004health_impactHIGHNoCapability health endpoint is declared
HLTH-005health_impactHIGHNoBusiness-impact endpoint is declared
HLTH-006health_impactHIGHNoRequired health paths exist in OpenAPI
AI-001ai_mcp_a2aCRITICALYesMCP exposure is governed
LIFE-001lifecycle_reuseHIGHNoVersioning strategy is declared
LIFE-002lifecycle_reuseHIGHNoDeprecation policy is declared
LIFE-003lifecycle_reuseHIGHNoCompatibility policy is declared
LIFE-004lifecycle_reuseHIGHNoReuse target is declared

Artifacts and reports

JSONmetadata.jsonOpen or downloadTXTpolicy-exit-code.txtOpen or downloadJSONpolicy-report.jsonOpen or downloadMDpolicy-report.mdOpen or downloadLOGpolicy-validation.logOpen or downloadTXTtest-exit-code.txtOpen or downloadXMLtest-results.xmlOpen or downloadLOGtests.logOpen or download

Testing and validation logs

policy-exit-code.txt
1
policy-validation.log
# API Policy Validation: disconnect-screen-api

> ๐Ÿ”ด **RED โ€” REJECTED - RELEASE BLOCKED**

- **Policy repository version:** 3.0.0
- **Risk tier:** high
- **Weighted score:** 8.5/100
- **Required score:** 90.0

## Dimension traffic lights

| Light | Dimension | Owner | Score | Weight | Gates | Failed gates |
|---|---|---|---:|---:|---:|---|
| ๐Ÿ”ด RED | Business outcome and capability alignment | Enterprise Architecture | 60.0% | 10.0 | 3/5 | OUT-003, OUT-005 |
| ๐Ÿ”ด RED | Specification and data-contract quality | API Platform | 0.0% | 15.0 | 0/5 | SPEC-001, SPEC-002, SPEC-003, SPEC-004, SPEC-005 |
| ๐Ÿ”ด RED | Lean API and resource design | API Design Council | 0.0% | 10.0 | 0/6 | LEAN-001, LEAN-002, LEAN-003, LEAN-004, LEAN-005, LEAN-006 |
| ๐Ÿ”ด RED | Security and role-aware authorization | Security Architecture | 0.0% | 15.0 | 0/6 | SEC-001, SEC-002, SEC-003, SEC-004, SEC-005, SEC-006 |
| ๐Ÿ”ด RED | NoSQL transactional and data integrity | Data and Domain Architecture | 0.0% | 15.0 | 0/9 | INT-001, INT-002, INT-003, INT-004, INT-005, INT-006, INT-007, INT-008, INT-009 |
| ๐Ÿ”ด RED | Cross-layer observability and auditability | SRE and Observability | 0.0% | 10.0 | 0/6 | OBS-001, OBS-002, OBS-003, OBS-004, OBS-005, OBS-006 |
| ๐Ÿ”ด RED | Testing automation and mock coverage | Quality Engineering | 0.0% | 10.0 | 0/4 | TEST-001, TEST-002, TEST-003, TEST-004 |
| ๐Ÿ”ด RED | Health and business-impact exposure | SRE and Operations | 0.0% | 5.0 | 0/6 | HLTH-001, HLTH-002, HLTH-003, HLTH-004, HLTH-005, HLTH-006 |
| ๐Ÿ”ด RED | AI, MCP, and Agent-to-Agent governance | AI Platform Governance | 50.0% | 5.0 | 1/2 | AI-001 |
| ๐Ÿ”ด RED | Lifecycle, versioning, and reuse | API Product Management | 0.0% | 5.0 | 0/4 | LIFE-001, LIFE-002, LIFE-003, LIFE-004 |

## Gate findings

| Rule | Dimension | Severity | Blocking | Finding |
|---|---|---|---|---|
| OUT-003 | outcome_capability | HIGH | No | Business owner is defined |
| OUT-005 | outcome_capability | HIGH | No | At least one consumer is identified |
| SPEC-001 | specification_contract | CRITICAL | Yes | OpenAPI file exists |
| SPEC-002 | specification_contract | CRITICAL | Yes | OpenAPI structure is valid |
| SPEC-003 | specification_contract | HIGH | No | Backward compatibility is declared |
| SPEC-004 | specification_contract | HIGH | No | Standard error model is declared |
| SPEC-005 | specification_contract | CRITICAL | Yes | Security scheme is declared |
| LEAN-001 | lean_resource_design | HIGH | No | API is resource-oriented |
| LEAN-002 | lean_resource_design | HIGH | No | API is not screen-specific |
| LEAN-003 | lean_resource_design | HIGH | No | Collection and detail access are separated |
| LEAN-004 | lean_resource_design | HIGH | No | Payload is right-sized |
| LEAN-005 | lean_resource_design | HIGH | No | API is reusable |
| LEAN-006 | lean_resource_design | HIGH | No | Paths avoid UI and database implementation terms |
| SEC-001 | security_authorization | CRITICAL | Yes | Authentication is configured |
| SEC-002 | security_authorization | CRITICAL | Yes | Object-level authorization is required |
| SEC-003 | security_authorization | HIGH | No | Actor/subject model is defined |
| SEC-004 | security_authorization | HIGH | No | Policy-as-code is enabled |
| SEC-005 | security_authorization | HIGH | No | Acting modes are declared |
| SEC-006 | security_authorization | CRITICAL | Yes | OpenAPI declares security requirements |
| INT-001 | nosql_integrity | CRITICAL | Yes | NoSQL integrity control set is complete |
| INT-002 | nosql_integrity | CRITICAL | Yes | Idempotency is enabled |
| INT-003 | nosql_integrity | HIGH | No | Aggregate owner is declared |
| INT-004 | nosql_integrity | HIGH | No | Single-writer rule is declared |
| INT-005 | nosql_integrity | HIGH | No | Concurrency-control mechanism is declared |
| INT-006 | nosql_integrity | HIGH | No | Outbox/inbox reliability is enabled |
| INT-007 | nosql_integrity | HIGH | No | Projection freshness is measured |
| INT-008 | nosql_integrity | HIGH | No | Reconciliation is defined |
| INT-009 | nosql_integrity | HIGH | No | Saga or compensation is defined |
| OBS-001 | observability_audit | HIGH | No | Trace propagation is enabled |
| OBS-002 | observability_audit | HIGH | No | Correlation ID is enabled |
| OBS-003 | observability_audit | HIGH | No | Business transaction ID is enabled |
| OBS-004 | observability_audit | HIGH | No | Structured logging is enabled |
| OBS-005 | observability_audit | CRITICAL | Yes | Audit events are enabled |
| OBS-006 | observability_audit | HIGH | No | Required observability headers exist in OpenAPI |
| TEST-001 | testing_mocking | CRITICAL | Yes | Contract tests exist |
| TEST-002 | testing_mocking | CRITICAL | Yes | Authorization tests exist |
| TEST-003 | testing_mocking | HIGH | No | Failure-path tests exist |
| TEST-004 | testing_mocking | HIGH | No | Scenario-based mock data exists |
| HLTH-001 | health_impact | HIGH | No | Liveness endpoint is declared |
| HLTH-002 | health_impact | HIGH | No | Readiness endpoint is declared |
| HLTH-003 | health_impact | HIGH | No | Dependency health endpoint is declared |
| HLTH-004 | health_impact | HIGH | No | Capability health endpoint is declared |
| HLTH-005 | health_impact | HIGH | No | Business-impact endpoint is declared |
| HLTH-006 | health_impact | HIGH | No | Required health paths exist in OpenAPI |
| AI-001 | ai_mcp_a2a | CRITICAL | Yes | MCP exposure is governed |
| LIFE-001 | lifecycle_reuse | HIGH | No | Versioning strategy is declared |
| LIFE-002 | lifecycle_reuse | HIGH | No | Deprecation policy is declared |
| LIFE-003 | lifecycle_reuse | HIGH | No | Compatibility policy is declared |
| LIFE-004 | lifecycle_reuse | HIGH | No | Reuse target is declared |

test-exit-code.txt
0
tests.log
......                                                                   [100%]