- Example evidence
- The company has access to the source code. The setup notes stop at running the app locally, and the developer says releases are made from their laptop.
- What remains unknown
- Whether the company controls the signing credentials, whether the instructions are current, and whether a new developer can publish an update.
- Why it matters
- Having the code does not establish that the company can release a fix. An urgent update could still depend on the departing developer.
- Recommendation
- Review account ownership with the company, document the build and release steps with the outgoing developer, and have the incoming developer test the process.
- How to verify completion
- The incoming developer produces a test build using company-controlled access and the documented steps. A live release follows the company’s approval process.