one record for one bounded route, object format, trust path, key path, or partner profile. Section Required fields Identity and scope Record ID, track, boundary or object, environment, route or consumer Ownership Technical owner, risk owner, control point, approval authority Risk and target Purpose, data sensitivity, confidentiality/authenticity lifetime, current state, target state, deadline Implementation Exact product, JDK, provider, build, key type, format, peer versions, and effective policy Evidence Positive and negative artefacts, source boundary, population or sample covered, timestamp, result, reviewer Gates Comparable baseline, approved threshold per metric, workflow pass definition Recovery Pause and rollback triggers, authority, procedure, measured time, recovery validation Closure Legacy retirement evidence, or a time-bounded exception with owner, reason, review date, and expiry • Minimum row: • record_id, track, boundary, technical_owner, risk_owner, control_point, current_behaviour, target_behaviour, evidence • Blank is not N/A. If an owner, control point, evidence source, or rollback path is missing, the decision is not productionready. Store the raw artefact, not only a parsed summary. The required fields are this deck's own model for a decision record, not a published standard. Back to Policy in one file lets each track move on its own schedule