Persona A
Non-technical manager
CEO / COO / Operations manager
Focus: Making sure the business can demonstrate a reasonable, repeatable compliance approach without needing deep technical detail.
- Ensure roles are assigned (who owns updates, who monitors vulnerabilities, who approves dependencies).
- Ensure basic evidence exists (SBOM availability, security contact, update policy, vulnerability reporting channel).
- Approve time and budget for “minimum viable compliance” activities.
- Require simple documentation: what we use, why we use it, how we keep it updated.

