When a reviewer identifies a finding that won't be addressed in the current PR, the PR author must file a Jira ticket in the appropriate project (`DEV`, `PLAT`, or `SEC`) before the PR merges. No exceptions — if it's worth commenting on, it's worth tracking.
**Exception:** Repos with GitHub Issues enabled (contractor intake repos such as `shoc-backend` and `shoc-frontend-new`, and open-source fork repos) may use a GitHub issue instead.
Deferred findings handled informally (retro notes, mental to-do lists, "we'll get to it") fall through the cracks. A ticket in the Jira backlog is the minimum bar for accountability.
## Security Review Gates
Two separate gates apply to security-sensitive changes:
**Cross-family review (`cross_review.py`):** Required when the change touches IAM roles, IAM policies, or resource permission boundaries. Run the stateless GPT cross-reviewer via `cross_review.py` in the `security-review` repo. It produces findings-to-verify, not a gospel verdict. After two rounds without convergence, stop and disposition the remainder with Adam. Lambda handler signatures are not a cross-review trigger.
**Security review:** Required when the change touches sensitive authentication paths, secrets handling, IaC/IAM definitions, payment flows, or surfaces that accept untrusted input. These surfaces warrant a structured security review pass in addition to standard code review.