# Policy-Gate Review Checklist

The per-concern checklist applied to every policy-applicability evaluation.

- The evaluation uses the versioned policy bundle and the action's recorded applicability inputs — not assumption or memory.
- Control applicability is scoped to the action's actual risk tier.
- Every control result references a concrete control_id and a pass/fail/not-applicable/exception status.
- No framework is applied merely because it is familiar, and none is omitted merely because the system is called internal.
- The output is presented as an owner-confirmable candidate, never as a compliance determination.
- The policy_bundle_version evaluated is recorded for the audit trail.
