Explicit approval state
Production decisions are represented as explicit approval state rather than inferred from application behavior.
Security
Steerlane's current product includes governance controls around approved state, reviewer identity, audit events, and reapproval decisions. Broader enterprise security capabilities are listed separately where they are still planned.
Security posture principle
We would rather show a capability as planned than imply a security control that does not yet exist.
Current product controls
These are product-state and governance controls supported by the current implementation. They should not be interpreted as a completed enterprise security program.
Production decisions are represented as explicit approval state rather than inferred from application behavior.
An approved baseline binds the accepted workflow state to the assurance state that supported the decision.
Governance actions can be recorded as explicit audit events with actor and target context.
Where human review is required, reviewer identity and review state remain explicit rather than disappearing into an automated decision.
Candidate workflows can remain ineligible for reapproval when required assurance or review conditions have not been satisfied.
Candidate evaluation actions can carry actor identity into the audit trail rather than existing as anonymous state changes.
Architecture principles
These principles describe the architecture direction. They are not certifications or promises that every deployment option is already implemented.
The product architecture should prefer references, structured evidence, and scoped workflow state over copying more customer data than is necessary for assurance decisions.
The long-term deployment model should support clear separation between Steerlane's control layer and the customer's models, tools, data systems, and execution environment.
Evidence should remain attributable to its source and reusable without requiring Steerlane to become the system of record for every underlying artifact.
Development, testing, and production approval states should remain distinguishable so experimental changes are not confused with approved production state.
Planned enterprise controls
These are expected enterprise requirements, but they remain planned until the relevant implementation and operational evidence exists.
Important
Steerlane does not currently claim SOC 2 certification, SSO / SAML availability, configurable data residency, BYOC, or enterprise key-management capability.
Claim boundary
Current governance controls should not be confused with a completed enterprise security stack.
No certification claim
Certification requires independent controls, operating evidence, and formal audit work beyond the current product implementation.
No identity-platform claim
Reviewer and actor identity exists in governance state, but that is not the same as a production enterprise identity and access-management layer.
No hosting-boundary claim
The architecture direction supports explicit deployment boundaries, but those deployment modes are not presented as generally available today.
No silent automation claim
Where assurance or reapproval requires human judgment, the product keeps reviewer identity and review state explicit.
Design-partner evaluation
A design-partner pilot should include an explicit discussion of workflow boundaries, evidence handling, reviewer roles, and enterprise security requirements.