====== OR-001f — Compliance Officer Operations ====== [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:start|Go to OR-001 — Operation by Identified User Categories]] ===== Statement ===== [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform each Crucible operation allocated to the Compliance Officer Role. ===== Derived From ===== This requirement derives from: * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:start|OR-001 — Operation by Identified User Categories]] The Original Requirement states: > //The system SHALL support operation by:// >> //Developers// >> //DevSecOps Engineers// >> //Platform Engineers// >> //System Administrators// >> //Security Engineers// >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] OR-001f preserves the intent that Compliance Officers participate in Crucible operation by requiring Crucible to perform each operation allocated to the Compliance Officer Role. The separate requirements derived from OR-001 address: * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a|OR-001a — Developer Operations]] * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001b|OR-001b — DevSecOps Engineer Operations]] * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001c|OR-001c — Platform Engineer Operations]] * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001d|OR-001d — System Administrator Operations]] * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001e|OR-001e — Security Engineer Operations]] ===== Rationale ===== Compliance Officers require access to the Crucible operations allocated to the Compliance Officer Role. This requirement ensures that Crucible performs each operation allocated to the Compliance Officer Role. Separating Compliance Officer operations from operations allocated to other user categories supports independent verification, [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and determination of whether Crucible satisfies the operational needs assigned to Compliance Officers. Without this requirement, Crucible could perform operations allocated to other user categories while failing to perform the operations allocated to the Compliance Officer Role. ===== Applies To ===== This requirement applies to: * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * Compliance Officers * Compliance Officer Role * Crucible operations allocated to the Compliance Officer Role * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] * Operation status * Operation results * Operation failures * Operation exceptions * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] * [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environments]] * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]] ===== Verification ===== Verification confirms that: - The Compliance Officer Role is identified - Each Crucible operation allocated to the Compliance Officer Role is identified - Crucible performs each operation allocated to the Compliance Officer Role - The performed operation corresponds to the allocated operation - Crucible produces each status, result, failure indication, exception indication, [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]], [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] item, or other output specified for the operation - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] between the Compliance Officer Role, the allocated operation, and the performed operation ===== Referenced By ===== The following pages reference this requirement: {{backlinks>.#dido:02-crusible}} ===== Delivery Phase ===== Implemented and Verified. ===== Implementation Status ===== Assess whether the current Crucible implementation performs each Crucible operation allocated to the Compliance Officer Role. ===== Requirement Status ===== Review and accept OR-001f as a proposed derived requirement created from the evaluation and decomposition of OR-001 in the Crucible System Requirements Specification, Version 1.1 Draft. ---- ===== Issues ===== The following unresolved issues affect this requirement: Define Compliance Officer Role or reference an authoritative definition. Identify the essential characteristics of the role and distinguish the role from the Developer Role, DevSecOps Engineer Role, Platform Engineer Role, System Administrator Role, and Security Engineer Role. Identify the controlling source that allocates Crucible operations to the Compliance Officer Role. ---- ===== Notes for Editors ===== This requirement page should retain the stable requirement identifier ''OR-001f''. This page is a leaf requirement page and omits a trailing '':start'' from its namespace. The parent OR-001 page is a non-leaf page and retains a trailing '':start'' in its namespace. Changes to the Statement should preserve: * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor * Compliance Officer Role as the recipient of the operation allocation * Allocation of each Crucible operation to the Compliance Officer Role * Performance of each allocated operation by Crucible The unresolved meaning of Compliance Officer Role should remain recorded in the Issues section until an authoritative definition resolves the issue. The source of each operation allocation should remain recorded in the Issues section until a controlling source establishes the allocation. Material changes should receive review and should update the verification criteria, source records, and Issues section. To reference this requirement Statement from another wiki page, insert: {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001f#Statement&noheader&nofooter&noeditbtn}} Do not rename this page after an external citation unless a redirect or move plan is in place. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.