Automated Compliance Library Management
Separating compliance-framework content from application releases, with CSV ingestion, schema validation, and tooling for target environments.
Overview
Compliance content changes constantly: new frameworks arrive, controls get revised, and requirement language gets rewritten. Before Library Management, every content change rode a full application deploy, so even a one-line copy fix had to go through the same release process as a new control template. As the library grew, that coupling put more routine content work on the engineering release path.
I designed and built the content management layer that separated framework content from code releases. Content experts maintained the spreadsheet themselves, and an engineer reviewed the changes and exported a CSV for ingestion.
What I built
The ingestion tool used Pydantic v2 to validate the schema and shape of the content being loaded. It took the CSV rows through a defined ingestion path for the target environment, giving us a way to catch malformed content before it reached customers and keep development and production content aligned.
We could also reseed content from an earlier version idempotently, but content introduced by newer versions remained in place, so it wasn't a full rollback.
I also rewrote the Automated Compliance README around the flow. Moving updates out of an application release only helped if the next person could understand how to prepare, validate, and load them without reconstructing the process from informal onboarding.
Collaboration
I worked with product on the content-update workflow and with the compliance content team on the model the validation path needed to enforce.
Outcome
- Routine compliance-content updates had an ingestion and validation path separate from application releases.
- Content experts maintained the spreadsheet, with engineer review and schema validation before updates reached the target environment.
- The updated README made the content workflow available to the next engineer maintaining it.
I tried to build a comprehensive versioning system, and I should have split the work into clearer milestones. The content-update path was usable, but version comparison and full rollback remained unfinished when the migration work was deferred. As we moved companies between versions more frequently, those gaps meant writing bespoke migrations to repair the data. Looking back, I would have scoped an earlier milestone around the version transitions we actually needed and made the cost of leaving them unsupported more explicit.