PublishedGuidanceLAST REVIEWED · 30 AUG 2026
AATS in CI
Use checks to detect declared control gaps before release.
Overview
The proposed AATS GitHub Action checks a reviewed manifest in CI. It is not yet published under ColomboAI-com/aats-action@v1 and cannot issue certificates.
- Review manifest changes alongside code and policy changes.
- Use least-privilege workflow token permissions.
- Treat PR comments as a summary of self-declared readiness.
- Reassess runtime configuration after deployment.
Production checklist
- Keep credentials in a server-side secret store.
- Set explicit cost, latency, privacy, provider, and regional constraints.
- Capture route and evaluation evidence for incident review.
- Test timeouts, cancellation, fallback, and denied-policy paths before rollout.
Was this page helpful?