Registry
System details
Accountability that doesn't rest on one person
No audit question lands on the wrong desk, and no system depends on one person remembering it. Ownership is recorded on the system itself, so accountability is visible before anyone has to ask.
- Ownership lives on the record, not in a wiki page
- Responsibility is distributed, not stuck on whoever set the system up

Classification that lives on the record, not in someone's head
The metadata your access controls and audit scope are supposed to match lives on the record, not in someone's head. Every system carries its own classification and PII status, so scope and access decisions rest on data instead of memory.
- Classification and criticality set on every system, so nothing sits unscoped
- PII flag and region make regulated systems easy to pull for scope

Status that tells the truth
Nothing gets audited as active after it's gone. Status moves with each system's real lifecycle, so decommissioned systems stop counting as in-scope during an audit.
- Status follows each system through its lifecycle, so a record never claims a system is running after it's gone
- Decommissioning keeps the full record and history intact instead of erasing them
ActiveIn use, in scope, and reviewed on schedule.
Under reviewStill running, but something about it is being reassessed.
DeprecatedBeing wound down. Still here, so still in the record.
RetiredSwitched off, kept on file so past audits still make sense.
System Description
The metadata your audit needs
Ownership & accountability
Escalation paths and decision rights are settled on the record before an incident or an audit tests them.
Classification & PII
Every system's classification and PII status are recorded where they belong — on the record — so your access controls and audit scope match reality.
A status that holds up
Status follows each system through its lifecycle, so decommissioned systems don't get treated as in-scope during an audit.










