Documentation agents

Agent-written docs, under change control.

READMEs, API references, ADRs, and runbooks update in the same PR as the code that changed them — attributed, reviewed, and recorded in the same evidence as every other change.

PR merge evidence digest · sample from a demo workspace

markdown
## AutoDevOps merge evidence

Session: claude-session-fincard-demo-002
Repository: fincard-network-verifier
Decision: confirm → approved

- Policy: fincard-demo-2026-04-20
- Approval: audit-fincard-004
- Intent fidelity: 0.94 (event: intent.fidelity.scored)

Digest: sha256:a4e8…9b2f

The same evidence as code PRs, bound to one audit record.

01Controls evidenced

Docs change like code. Evidence them like code.

A generated runbook is a change to a controlled system. It carries the same attribution and change-management evidence as the diff beside it.

  1. FFIEC.SDLC-02Verifier-checkable

    Attributed SDLC Code Provenance

    FFIEC Development & Acquisition Booklet: Software Development Lifecycle Integrity

    How the session record supports it

    Pull request (PR) evidence can bind recorded sessions, commit hashes, policy decisions, and Check Run results into one digest.

    PR Merge Evidence Summary / GitHub Check Run

    Catalog entry
  2. SOC2.CC8-03Verifier-checkable

    Cryptographic Evidence Package Verification

    SOC 2 Common Criteria 8.1: Change Management & System Integrity

    How the session record supports it

    Evidence exports use manifests and SHA-256 digests. Persisted exports record append-only chain entries.

    Evidence Package Manifest / Local Verifier Transcript

    Catalog entry

02The fix

Docs that go through the same gate as code.

Same workflow as code
Doc updates land in the commit or PR that changed the behavior.
Reviewable before merge
Approve or reject the generated doc inside the PR; the decision lands in the audit record.
Template-aware generation
Repo structure and team templates produce docs in your existing format.

03Artifacts

What the agents keep current

READMEs and onboarding

Install steps, commands, and workflows update in the PR that changed them.

API references

Contract-facing docs update when schemas, routes, or integration behavior change.

ADRs, release notes, runbooks

Capture rationale while the diff context is still fresh.

Session replay

FinCard demo

Verification portal sessions view showing replayable agent runs.

Doc-changing agent runs stay tied to session replay, findings, and approval state.

04Who benefits

Three stakeholders, one record

Engineering leads
Onboarding docs and runbooks that reflect what shipped.
Security teams
Every runbook change carries an approver, a decision, and an audit record.
Platform engineers
Set the doc template and policy once; every repo’s generated docs follow it.

Stop treating docs as a separate workstream

Reviewed in the PR, recorded in the same audit trail as the code, evidenced against the same change controls. Start with one repo.