SPEC-0013: Scrum Mode Audit Triage
Overviewā
A --scrum flag for /sdd:audit that adds a team-based triage ceremony on top of the standard six-category drift analysis. After completing the standard audit, a six-role scrum team groups raw findings into functional themes, applies prioritization (P1/P2/P3) and effort estimation (XSāXL), challenges false positives, distinguishes code-fix findings from artifact-update findings, and produces a prioritized remediation roadmap. ADRs and OpenSpecs are the source of truth; code that deviates is presumed wrong unless the triage team explicitly argues the artifact has become stale. See š ADR-0014.
Requirementsā
Requirement: Scrum Flag and Mode Activationā
The /sdd:audit skill MUST accept a --scrum flag. When set, the skill SHALL first complete the full standard audit analysis (all six drift categories, severity assignments, findings table) and then execute the triage ceremony phases. The --scrum flag MUST compose with scope arguments: /sdd:audit auth --scrum SHALL limit both the standard audit and the triage ceremony to the auth domain. The --scrum flag MUST be mutually exclusive with --review; if both are provided, --scrum MUST take precedence.
Scenario: Scoped scrum auditā
- WHEN the user runs
/sdd:audit security --scrum - THEN the standard audit analyzes only security-domain artifacts and code, and the triage team triages only the security-domain findings
Scenario: Full-project scrum auditā
- WHEN the user runs
/sdd:audit --scrumwith no scope - THEN the standard audit runs against the full project and the triage team triages all findings
Scenario: Flag precedenceā
- WHEN the user provides both
--scrumand--review - THEN
--scrumtakes precedence,--reviewis silently ignored, and the scrum ceremony runs
Requirement: Triage Team Compositionā
The skill MUST spawn exactly five specialist agents to triage raw findings alongside the orchestrating lead. Agent personas MUST be defined verbatim in the SKILL.md with the following role-specific mandates:
| Role | Audit-Specific Mandate |
|---|---|
| Product Owner | Prioritize findings by business impact and user exposure; decide which findings are "accept for now" vs. "must fix before next release"; document priority decisions with reasoning |
| Scrum Master | Estimate remediation effort per theme (XS/S/M/L/XL); flag themes that are too large for one sprint and propose splits; ensure themes are sprint-actionable |
| Engineer A | Assess technical complexity and implementation risk of fixes; identify themes that require large refactors vs. targeted patches |
| Engineer B (Grumpy) | Challenge whether each finding is genuine drift or intentional architectural evolution; hold a high bar for accepting "this is fine actually"; explicitly call out when the PO wants to defer a MUST/SHALL violation |
| Architect | Validate that ADRs and specs are still the correct source of truth; identify findings where the correct resolution is an artifact update (via /sdd:adr or /sdd:spec) rather than a code fix |
Scenario: Engineer B disputes a findingā
- WHEN Engineer B argues a finding reflects intentional evolution, not drift
- THEN the Architect evaluates the argument and decides: code fix required, or artifact update needed
Scenario: Architect recommends artifact updateā
- WHEN the Architect determines the code reflects a better architectural decision than the current spec or ADR
- THEN the finding MUST be flagged as "ARTIFACT UPDATE NEEDED" with a suggestion to run
/sdd:adror/sdd:specto capture the evolution, rather than being added to the code-fix remediation backlog