Keep mission commitments within delegated authority.
Software releases and operational changes across agencies, contractors, and connected systems.
Discuss a workflow ↗
Government and defense organizations delegate authority across missions, roles, and operating environments. This illustrative workflow follows a proposed mission-software release.
Apply delegated authority to mission software releases and operational changes.
The workflow is illustrative. Each organization defines its own authority, evidence requirements, exceptions, and operating conditions.
Mission software capability release to an operational environment
A mission-software release brings together development, testing, readiness review, and approval for a defined operational environment.
Authority Control point. After mission context, test evidence, security evidence, user acceptance, and operational-readiness information have been assembled, but before deployment into the selected operational environment.
Workflow basisDoDI 5000.87, DoD Enterprise DevSecOps Fundamentals Version 2.5, Continuous Authorization to Operate Evaluation Criteria for the DevSecOps use case, and the DevSecOps Continuous Authorization Implementation Guide.
Sources and evidence →Illustrative workflow adapted from public regulatory, standards, acquisition, and operational sources. It identifies a recognizable operating sequence and a possible Authority Control point; compliance obligations and sector requirements are determined separately.
Exceptions follow the organization’s review process. Results may be reevaluated after additional authority, evidence, or review resolves a Defer. The determinations remain Permit, Defer, and Block.