# Sea Haven Governance ## Standards and Authority - **Handbook**: `engineering-handbook` is the standards authority for all conventions. - **Jira**: work-status authority. Route product work → DEV, infrastructure/platform → PLAT, security → SEC. Search for duplicates before creating a ticket. ## Branches Use one of: `feature/`, `fix/`, `hotfix/`, `chore/`, `docs/`, `refactor/`, `release/` + kebab-case description. Do not include a Jira key in the branch name. ## Pull Requests - **Title format**: `type(scope): description (DEV-123)` — every non-exempt PR must end with its Jira key. - **Body sections** (exactly, in order): `Summary`, `Validation`, `Tests`, `Notes`. Use "None." under Notes when empty. - State verifiable facts only. Do not justify changes by citing the handbook. No AI-attribution footers. ## Security and Cross-Review - Sensitive surfaces (payment flows, authentication, secrets handling, untrusted input) require security review. - IAM role, policy, or resource-permission changes require cross-family review. Lambda handler signature changes alone do not. ## CI and Workflow References - CI must pass before merge. - Org-level reusable workflow refs must be pinned to a full commit SHA with a `# vX.Y.Z` comment.