This is a blank work-product format, not a client case or claimed result. A real review records the evidence for the specific system and names the people who own the decision.
Decision header
- System and workflow: What will users rely on?
- Proposed release: Which users, data, and functions are in scope?
- Decision owner: Who can approve, limit, or stop the release?
- Review date: When was the evidence current?
Evidence to record
Task quality
Representative test cases, baseline results, known failures, and the agreed release threshold. Record who owns the threshold and the next evaluation run.
Data access
Data flows, identity rules, retrieval filters, and access tests. Record any path that could expose information to the wrong user.
Failure and recovery
Fallback behavior, human review, incident response, and rollback tests. Record when the system must stop, retry, or hand off to a person.
Operating limits
Expected usage, latency, cost, logs, alerts, and recovery capacity. Record limits that must be monitored after launch.
Risk and decision record
For each material gap, record the risk, supporting evidence, mitigation, owner, due date, and retest result. Close with one explicit decision: release, release with a narrower scope, or hold. The decision owner records the rationale, accepted residual risks, and next review point.