This playbook is for organizations that want to adopt EEP with low risk and fast time-to-value. Follow the phases in order.
- Assign owners:
- Platform owner (API/event surfaces)
- Security owner (auth/signing/SSRF/replay)
- Operations owner (SLO/incident/observability)
- Confirm baseline runtime:
- Node.js >= 22 for CLI and TS workflows
- Python >= 3.10 for Python package/tooling workflows
- Pick initial conformance target:
- Core for pilot
- Standard for production baseline
- Expose discovery and manifest:
/.well-known/eep.json- Link-header based entity discovery
- Implement subscription flow:
POST /eep/subscribe- WebSub intent verification
- Implement secure webhook dispatch:
- Standard Webhooks headers
- HMAC SHA-256 signing
- 60-second replay window
- Implement gate config and access resolver integration.
- Register semantic verifiers for each active requirement type.
- Keep fail-closed behavior:
- No verifier => requirement unmet => access denied.
- Enable SSE stream and rate-limit headers.
- Adopt SLO/SLI baselines from:
docs/ops/slo.mddocs/ops/incident-response.mddocs/ops/runbook-webhook-delivery.md
- Wire telemetry for security-critical checks:
- replay detected
- nonce consumed
- double-spend detected
- Add dependency policy gates:
npm auditpip-audit
Use @eep-dev/compliance-cli as your external verifier:
npx @eep-dev/compliance-cli \
--target https://api.yourplatform.com \
--api-key YOUR_KEY \
--entity u/your-entity \
--level full \
--report-json ./eep-audit-report.json \
--report-md ./eep-audit-report.mdGate recommendation:
- Block production promotion if:
- any
failresult exists - score drops below your internal threshold (recommended >= 90 for rollout, 100 for certification badges)
- any
- Pilot with one entity and one subscriber profile.
- Enable canary release gates in CI.
- Expand to more entities by template reuse.
- Re-run compliance CLI audits on each release candidate.
- Discovery + manifest endpoint live
- Subscription + intent verification pass
- Signed webhook deliveries pass
- Strict fail-closed gate resolution enabled
- Verifier registry coverage complete for active requirement types
- SSE + rate-limit checks pass
- Compliance CLI report generated and archived in CI artifact store
- Structural proof validation implemented, semantic verifier missing.
- Replay window mismatch between docs/code/examples.
- Production release tag created without compliance report evidence.
Use this playbook with:
docs/guides/testing-and-validation.mddocs/guides/how-to-dispatch.mddocs/guides/how-to-subscribe.md