Package review
- Record the package version and test date.
- Inspect installation prompts and requested permissions.
- Confirm update and uninstall procedures.
Security & Data
Use this operating checklist to document provenance, refresh cadence, permission scope, runtime behavior, retention, deletion, and the human gates that surround prospecting data.
| Control area | Required record | Verification method | Status language |
|---|---|---|---|
| Provenance | Provider, source context, field, and collection date | Trace a sample result back to its evidence | Verified / Config-dependent / Not disclosed |
| Refresh cadence | Observed date, expiry rule, and recheck trigger | Test a known changed company or role | Current / Stale / Unknown |
| Credentials | Secret location, owner, scope, and rotation path | Inspect runtime configuration without exposing values | Minimum scope / Excess scope / Unknown |
| Runtime | Network calls, retries, logs, and output destinations | Run a sandbox task and review its activity | Observed / Config-dependent |
| Retention & deletion | Storage location, access, suppression, retention, and deletion | Create and delete a test record across destinations | Verified / Partial / Not tested |
| Human review | Reviewer, acceptance criteria, decision, and timestamp | Audit a rejected and an approved result | Approved / Rejected / Pending |
This checklist is an operating control, not a claim of SOC 2, ISO, GDPR certification, or a legal conclusion. Validate current package behavior, provider documentation, and applicable regional requirements with qualified reviewers.
Use a known cohort that includes one clear match, one exclusion, one ambiguous identity, and one stale event.
npx -y @okki-global/okki-go-taroball