For owners & leadership
What is actually verified before you sign this off?
The work gets checked; the record of what was checked rarely reaches the person making the release decision. This page is that record’s short form: the verdict, the counts behind it, and the risks still open.
A status is not an answer to that question
Sign-off usually rests on a status. The item is done, the column has moved, the release is on the agenda. A status records where work sits in a process; it does not record whether anyone checked what the work was supposed to do.
Two things would answer the question honestly, and at the moment of the decision both are usually out of reach: whether the work was checked against the acceptance criteria the team wrote, and what was seen while it was being checked.
Both already exist. The checks ran and their observations were captured. What is missing is the attachment — nothing binds those observations to the item on the sign-off list, so they cannot travel with it.
The sign-off view of the same issue
One issue is rendered twice. Your engineers read the long version: every acceptance criterion, every check, every captured observation. You read this one — the verdict, the counts behind it, and the risks that are still open.
The verdict is arithmetic over the checks and the findings that remain open, not a reviewer’s impression. The counts that produced it sit on the same line as the colour, so the colour is never read on its own.
Each open risk is listed with its severity, and the detail behind it — the steps, the observation, the run it came from — stays in the tracker, one link from the report rather than reproduced at this level.
Red
One or more findings at critical severity are still open. The verdict line carries that count beside the share of automated checks that passed.
Amber
No critical finding is open, but a high-severity finding is, or fewer than 90% of the automated checks passed.
Green
No critical or high-severity finding is open, and at least 90% of the automated checks passed.
Dismissed
A finding dismissed in review takes no part in the verdict, and it stays in the report marked as dismissed rather than disappearing from it.
The answer without a meeting
Getting that verdict today means finding whoever ran the checks and asking them. The tracker answers the question itself: a chat on the issue, in plain language, answered from the record rather than from memory.
- Ask what has changed on an item since you last looked, and get it from the item’s own change history.
- Ask for the current verification state of an item on your agenda, without knowing who to ask.
- Answers are given with the asker’s own access, so the chat cannot become a way round permissions.
- Anything the chat files or changes is recorded against the issue, in the name of the person who asked.
How to be running today
The install path is four steps and belongs to whoever administers the machine: download the desktop app, get past the warning about an unsigned build, point it at a server, sign in with Dust and connect a workspace. There is no procurement step, and nothing for the QA team to build.
If your own estate has to host it instead, the same page carries that option too: the tracker runs as one deployment beside your own database, on your own infrastructure and your own keys.
Free during early access. The AI features run on a small per-user daily allowance that your administrator enables.
What this does not do
- It checks the work against the criteria your team wrote. Thin criteria produce a thin check, and the report will show a criterion passing because almost nothing was asked of it.
- It does not replace judgement; it gives judgement something to stand on — a stated verdict, the counts behind it, and the risks that are still open.
- It does not approve anything. The verdict records what was checked and what remains open, and the signature stays yours.
There is no contract to sign, and that is deliberate
Buying software buys you a vendor to hold responsible, and an institution normally wants that. What it also buys is a supplier standing between your team and every retest, every change of criteria and every outage — plus a renewal to justify each year.
This is software written by one developer and licensed to the organisation that runs it. Your own engineers can read the verification path under that agreement, run the same checks against the same build and get the same findings, and keep running it whether or not the author is still around. That is not a promise of support; it is a way of not needing one.
- No seat count, no renewal date, and no purchase for anyone to approve during early access.
- What crosses between the tracker and the agent is a documented interface, so a contractor or your own team works against a boundary rather than a black box.
- The independence question — who checks the checker — and what happens to a finding that does not hold up are answered in full in the pack.