Organization Deliverables Best Practice
These are completed examples of the three deliverables generated by the organization-designer agent.
Compare them with your own output/organization/ files to spot missing items.
Open Source Roles and Responsibilities Definition
Document: role-definition.md
- Company name: Tech Unicorn
- Date written: 2026-03-23
- Author: DevOps Team Open Source Program Manager
Related Standards
- 5230 §3.1.2.1·§3.1.2.2
- 18974 §4.1.2.1·§4.1.2.2·§4.1.2.3
1. Open source program role list
| Role | Owner / department | Key responsibilities |
|---|---|---|
| Open Source Program Manager | DevOps Team (1 person, concurrent role) | Policy establishment, license review, external inquiry response |
| Security Manager | Security Team | CVE scanning, vulnerability response |
| Legal Affairs | Legal Team | License disputes, legal advice |
| Development team representative | Development Team (one per department) | Process compliance, SBOM updates |
| Team champion | 1 person per development team (named) | Open source contact point in each team, policy dissemination |
2. Required competencies per role
| Role | Required competencies |
|---|---|
| Open Source Program Manager | Open source license basics, SBOM tool operation, understanding of OpenChain standards |
| Security Manager | Understanding of CVE/CVSS, vulnerability analysis tool operation, patch management |
| Legal Affairs | Legal obligations of open source licenses, contract review |
| Development team representative | Usage approval process, SBOM generation tool basics |
| Team champion | Basic understanding of the open source policy, in-team communication |
3. External inquiry channels
Related Standards
- 5230 §3.2.1.1
- 18974 §4.2.1.1
- License compliance inquiries: opensource@techunicorn.example
- Security vulnerability reports: security@techunicorn.example
- Response owner: DevOps Team Open Source Program Manager
- Target response time: within 5 business days
4. Access to legal advice
Related Standards
- 5230 §3.2.2.3
- Internal legal team: Yes
- Use of external legal counsel: Initial review by the internal legal team, then engage an external law firm if necessary
5. Vulnerability remediation expertise
Related Standards
- 18974 §4.2.2.3
- Responsible organization: Security Team
- Available external resources: KrCERT support, external security consulting (if required)
6. Best practice conformance verification and periodic review
Related Standards
- 18974 §4.1.2.5, §4.1.2.6
Verification owner
- Verification owner: DevOps Team Open Source Program Manager
- Review cycle: once a year
- First scheduled review date: 2026-12-31
Periodic review method
The role definitions and participant list are reviewed according to the following procedure:
- The review owner compares the current role list with the actual assignment status
- Identify changes (personnel replacements, role additions/removals)
- If there are changes, update this document and reissue the appointment letter (appointment-template.md)
- After the review, record it in the review history table below
Review history
| Review round | Review date | Reviewer | Summary of changes | Notes |
|---|---|---|---|---|
| 1 (initial) | 2026-03-23 | DevOps Team Open Source Program Manager | Initial role definition | |
| 2 |
7. Scaling options by organization size (optional)
As the organization grows and open source management becomes more complex, consider adding the governance structures below.
- OSRB (Open Source Review Board): A committee that handles license, security, contribution, and release approvals. It is composed of the Open Source Program Manager and legal, security, and development representatives, and convenes once a month or when an issue arises.
- OSPO (Open Source Program Office): An organization dedicated to open source strategy and governance. Consider formalizing it once there are three or more dedicated staff members.
Open Source RACI Matrix
Document: raci-matrix.md
- Company name: Tech Unicorn
- Date written: 2026-03-23
Related Standards
- 5230 §3.2.2.1·§3.2.2.2·§3.2.2.4
- 18974 §4.2.2.1·§4.2.2.2·§4.2.2.4
R=Responsible (executes), A=Accountable (approves), C=Consulted (advises), I=Informed (kept informed)
RACI matrix
| Task | Open Source Program Manager | Development Team | Security Team | Legal | Management |
|---|---|---|---|---|---|
| Open source usage review and approval | A | R | C | C | I |
| License compliance review | R | C | I | C | I |
| SBOM generation and management | A | R | I | I | I |
| Vulnerability scanning and response | C | R | R | I | I |
| Policy establishment and updates | R | C | C | C | A |
| Training program operation | R | I | I | I | I |
| External license inquiry response | R | C | I | C | I |
| External security vulnerability reports | C | I | R | I | I |
| Self-certification declaration | R | I | C | C | A |
Assignees per role
Related Standards
- 5230 §3.2.2.1·§3.2.2.2
| Role | Assignee name | Department | Dedicated / concurrent | |
|---|---|---|---|---|
| Open Source Program Manager | (enter name) | DevOps Team | opensource@techunicorn.example | Concurrent |
| Development team representative | (enter name) | Development Team | (enter email) | Concurrent |
| Security Manager | (enter name) | Security Team | security@techunicorn.example | Concurrent |
| Legal Affairs | (enter name) | Legal Team | (enter email) | Full-time |
Budget allocation status
Related Standards
- 5230 §3.2.2.2
- 18974 §4.2.2.2
| Item | Status |
|---|---|
| Dedicated staffing | 1 concurrent role (DevOps Team) |
| Open source tool budget | (fill in after confirmation) |
| Legal advisory budget | Available (internal legal team in place) |
| External training budget | (fill in after confirmation) |
Non-compliance case review procedure
Related Standards
- 5230 §3.2.2.5
When a license non-compliance case occurs:
- The Program Manager identifies and records the non-compliance
- Assess the severity of the violation with legal team advice
- Establish a corrective action plan (license replacement, source code release, etc.)
- Re-review according to the
output/process/usage-approval.mdprocess - Update the policy/process to prevent recurrence
Internal responsibility assignment procedure
Related Standards
- 5230 §3.2.2.4
- 18974 §4.2.2.4
When new open source-related work arises:
- The Open Source Program Manager defines the work
- Assign an owner based on the RACI matrix
- Update role-definition.md and this document
Open Source Program Manager Appointment Letter
Document: appointment-template.md
- Company name: Tech Unicorn
- Issue date: 2026-03-23
Appointment details
Tech Unicorn appoints the following employee as the Open Source Program Manager.
| Item | Details |
|---|---|
| Name | (enter name) |
| Department | DevOps Team |
| Title | (enter title) |
| Appointment date | 2026-03-23 |
| Responsibilities | Open source license compliance and security assurance management |
Key roles and authority of the Program Manager
- Policy establishment and maintenance: Leads the writing and updating of open source policy documents
- License review: Reviews open source usage approvals and confirms license obligations
- SBOM management: Oversees the SBOM generation, maintenance, and distribution process
- External inquiry response: Operates the license compliance inquiry channel (opensource@techunicorn.example)
- Training: Plans company-wide open source training and tracks completion status
- Self-certification management: Leads the OpenChain ISO/IEC 5230 and 18974 self-certification procedures
Cooperating departments and contacts
| Department | Role | Contact |
|---|---|---|
| Security Team | Vulnerability scanning and response | security@techunicorn.example |
| Legal Team | License legal advice | (enter email) |
| Development Team | Open source usage requests and SBOM generation | (enter email) |
Periodic review
Related Standards
- 18974 §4.1.2.5 (evidence of periodic review of roles and participant list)
This appointment letter is reviewed periodically according to the schedule below.
| Review item | Review cycle | Owner |
|---|---|---|
| Role suitability | Once a year | DevOps team leader |
| Competency requirements met | Once a year | Open Source Program Manager |
| Need for replacement | 1 month before appointment expiration | DevOps team leader |
First scheduled review date: 2027-03-23
Review history:
| Review round | Review date | Reviewer | Result | Notes |
|---|---|---|---|---|
| 1 (initial) | 2026-03-23 | (fill in) | Maintained | Initial record at time of appointment |
| 2 |
Signatures
| Appointed by | |
| Title | (enter executive/team leader title) |
| Name | (enter appointer name) |
| Signature | |
| Date | 2026-03-23 |
This appointment letter is managed together with
output/organization/role-definition.mdandoutput/organization/raci-matrix.md.