Hey community π Update for those working in automotive π
UNECE R155 and R156 are now type approval requirements for new vehicle types in UN 1958 markets. They require auditable evidence of who can push what firmware, to which vehicles, under which conditions.
Most platforms have that logic scattered across services in different languages, which is exactly what an auditor canβt follow.
We just published a guide on the authorization layer that actually produces that evidence. It walks through the
YAML
for a single OTA deploy action across five principals (vehicle engineer, production manager, owner, OEM partner, telematics agent), plus supplier data scoping and ECU diagnostics.
Full write-up, with the allow/deny matrix and YAML per principal