Skip to main content

Organization Deliverables Best Practice

These are completed examples of the three deliverables generated by the organization-designer agent. Compare them with your own output/organization/ files to spot missing items.


Open Source Roles and Responsibilities Definition

Document: role-definition.md

  • Company name: Tech Unicorn
  • Date written: 2026-03-23
  • Author: DevOps Team Open Source Program Manager
Related Standards
- 5230 §3.1.2.1·§3.1.2.2
- 18974 §4.1.2.1·§4.1.2.2·§4.1.2.3

1. Open source program role list

RoleOwner / departmentKey responsibilities
Open Source Program ManagerDevOps Team (1 person, concurrent role)Policy establishment, license review, external inquiry response
Security ManagerSecurity TeamCVE scanning, vulnerability response
Legal AffairsLegal TeamLicense disputes, legal advice
Development team representativeDevelopment Team (one per department)Process compliance, SBOM updates
Team champion1 person per development team (named)Open source contact point in each team, policy dissemination

2. Required competencies per role

RoleRequired competencies
Open Source Program ManagerOpen source license basics, SBOM tool operation, understanding of OpenChain standards
Security ManagerUnderstanding of CVE/CVSS, vulnerability analysis tool operation, patch management
Legal AffairsLegal obligations of open source licenses, contract review
Development team representativeUsage approval process, SBOM generation tool basics
Team championBasic understanding of the open source policy, in-team communication

3. External inquiry channels

Related Standards
- 5230 §3.2.1.1
- 18974 §4.2.1.1

Related Standards
- 5230 §3.2.2.3
  • Internal legal team: Yes
  • Use of external legal counsel: Initial review by the internal legal team, then engage an external law firm if necessary

5. Vulnerability remediation expertise

Related Standards
- 18974 §4.2.2.3
  • Responsible organization: Security Team
  • Available external resources: KrCERT support, external security consulting (if required)

6. Best practice conformance verification and periodic review

Related Standards
- 18974 §4.1.2.5, §4.1.2.6

Verification owner

  • Verification owner: DevOps Team Open Source Program Manager
  • Review cycle: once a year
  • First scheduled review date: 2026-12-31

Periodic review method

The role definitions and participant list are reviewed according to the following procedure:

  1. The review owner compares the current role list with the actual assignment status
  2. Identify changes (personnel replacements, role additions/removals)
  3. If there are changes, update this document and reissue the appointment letter (appointment-template.md)
  4. After the review, record it in the review history table below

Review history

Review roundReview dateReviewerSummary of changesNotes
1 (initial)2026-03-23DevOps Team Open Source Program ManagerInitial role definition
2

7. Scaling options by organization size (optional)

As the organization grows and open source management becomes more complex, consider adding the governance structures below.

  • OSRB (Open Source Review Board): A committee that handles license, security, contribution, and release approvals. It is composed of the Open Source Program Manager and legal, security, and development representatives, and convenes once a month or when an issue arises.
  • OSPO (Open Source Program Office): An organization dedicated to open source strategy and governance. Consider formalizing it once there are three or more dedicated staff members.

Open Source RACI Matrix

Document: raci-matrix.md

  • Company name: Tech Unicorn
  • Date written: 2026-03-23
Related Standards
- 5230 §3.2.2.1·§3.2.2.2·§3.2.2.4
- 18974 §4.2.2.1·§4.2.2.2·§4.2.2.4

R=Responsible (executes), A=Accountable (approves), C=Consulted (advises), I=Informed (kept informed)


RACI matrix

TaskOpen Source Program ManagerDevelopment TeamSecurity TeamLegalManagement
Open source usage review and approvalARCCI
License compliance reviewRCICI
SBOM generation and managementARIII
Vulnerability scanning and responseCRRII
Policy establishment and updatesRCCCA
Training program operationRIIII
External license inquiry responseRCICI
External security vulnerability reportsCIRII
Self-certification declarationRICCA

Assignees per role

Related Standards
- 5230 §3.2.2.1·§3.2.2.2
RoleAssignee nameDepartmentEmailDedicated / concurrent
Open Source Program Manager(enter name)DevOps Teamopensource@techunicorn.exampleConcurrent
Development team representative(enter name)Development Team(enter email)Concurrent
Security Manager(enter name)Security Teamsecurity@techunicorn.exampleConcurrent
Legal Affairs(enter name)Legal Team(enter email)Full-time

Budget allocation status

Related Standards
- 5230 §3.2.2.2
- 18974 §4.2.2.2
ItemStatus
Dedicated staffing1 concurrent role (DevOps Team)
Open source tool budget(fill in after confirmation)
Legal advisory budgetAvailable (internal legal team in place)
External training budget(fill in after confirmation)

Non-compliance case review procedure

Related Standards
- 5230 §3.2.2.5

When a license non-compliance case occurs:

  1. The Program Manager identifies and records the non-compliance
  2. Assess the severity of the violation with legal team advice
  3. Establish a corrective action plan (license replacement, source code release, etc.)
  4. Re-review according to the output/process/usage-approval.md process
  5. Update the policy/process to prevent recurrence

Internal responsibility assignment procedure

Related Standards
- 5230 §3.2.2.4
- 18974 §4.2.2.4

When new open source-related work arises:

  1. The Open Source Program Manager defines the work
  2. Assign an owner based on the RACI matrix
  3. Update role-definition.md and this document

Open Source Program Manager Appointment Letter

Document: appointment-template.md

  • Company name: Tech Unicorn
  • Issue date: 2026-03-23

Appointment details

Tech Unicorn appoints the following employee as the Open Source Program Manager.

ItemDetails
Name(enter name)
DepartmentDevOps Team
Title(enter title)
Appointment date2026-03-23
ResponsibilitiesOpen source license compliance and security assurance management

Key roles and authority of the Program Manager

  1. Policy establishment and maintenance: Leads the writing and updating of open source policy documents
  2. License review: Reviews open source usage approvals and confirms license obligations
  3. SBOM management: Oversees the SBOM generation, maintenance, and distribution process
  4. External inquiry response: Operates the license compliance inquiry channel (opensource@techunicorn.example)
  5. Training: Plans company-wide open source training and tracks completion status
  6. Self-certification management: Leads the OpenChain ISO/IEC 5230 and 18974 self-certification procedures

Cooperating departments and contacts

DepartmentRoleContact
Security TeamVulnerability scanning and responsesecurity@techunicorn.example
Legal TeamLicense legal advice(enter email)
Development TeamOpen source usage requests and SBOM generation(enter email)

Periodic review

Related Standards
- 18974 §4.1.2.5 (evidence of periodic review of roles and participant list)

This appointment letter is reviewed periodically according to the schedule below.

Review itemReview cycleOwner
Role suitabilityOnce a yearDevOps team leader
Competency requirements metOnce a yearOpen Source Program Manager
Need for replacement1 month before appointment expirationDevOps team leader

First scheduled review date: 2027-03-23

Review history:

Review roundReview dateReviewerResultNotes
1 (initial)2026-03-23(fill in)MaintainedInitial record at time of appointment
2

Signatures

Appointed by
Title(enter executive/team leader title)
Name(enter appointer name)
Signature
Date2026-03-23

This appointment letter is managed together with output/organization/role-definition.md and output/organization/raci-matrix.md.