# Commissioned Work Operating Standard

_Last updated: 16 August 2026_

The public repository records only the disclosure-safe perimeter of commissioned work. Client identities, contracts, billing, restricted data and non-public acceptance records belong in access-controlled operating systems and must not be committed here.

## Standard engagement workflow

| Stage | Required operating artifact |
| --- | --- |
| Lead | account record |
| Qualification | written decision problem |
| Conflict check | internal conflict record |
| Discovery | written notes |
| Proposal | scope + outputs |
| Contracting | MSA / SOW as applicable |
| Confidentiality | NDA as applicable |
| Data processing | DPA / data agreement where required |
| Data receipt | intake manifest |
| Analysis | internal analysis plan / preregistration when useful |
| QA | issue register |
| Red team | challenge memo |
| Delivery | client evidence room |
| Acceptance | signed or email acceptance evidence |
| Invoice | finance ledger |
| Closeout | archival / deletion record |
| Publication | permission matrix |
| Follow-up | case-study / retainer decision |

Small private engagements may use 50% upfront where appropriate. Larger institutions may impose their own procurement and payment terms.

## Required private engagement record

Each engagement must maintain an access-controlled record containing at least:

- client identifier;
- signed date;
- scope and SOW/contract reference;
- billing status;
- data received and data classification;
- publication rights;
- deliverables and methods used;
- QA status;
- delivery date;
- acceptance evidence;
- testimonial permission;
- case-study permission;
- retention/deletion date.

The public registry exposes only fields permitted for disclosure.

## Client evidence room

A mature delivery room should contain, as applicable:

- Executive Decision Memo;
- Evidence Report;
- datasets/deliverables;
- Source Register;
- QA Register;
- Limitations Register;
- Claim Ledger;
- Methodology;
- Technical Appendix;
- reproduction package;
- meeting decisions;
- change requests;
- final acceptance materials.

## Public engagement record

A public engagement page may identify the decision problem, evidence architecture, deliverables, methods, public-source perimeter, limitations and disclosure boundary. It must not imply that synthetic method rehearsals are production client results. It must not claim `PRODUCTION CLIENT DATA`, completion, external review, independent reproduction, testimonial permission or case-study permission unless the corresponding record exists and publication rights permit disclosure.

## Security baseline

Where client data are accepted, the operating baseline is MFA, encrypted devices and storage, password management, role-based access, separated client workspaces, access logging, backup and retention rules, secure deletion, incident response, secrets management, and client-specific permissions. Sensitive client datasets do not belong in public GitHub.
