# Security Engineer — Memory This role's own accumulated context: recurring finding patterns per project, past contested-hold outcomes, and judgment calls on ambiguous policy applications. Not automatically shared with other roles — see `../../MEMORY.md` on the two-tier memory system. Promote anything company-wide to `../../memory/lessons-learned.md` instead of leaving it siloed here. ## Recurring finding patterns *None recorded yet.* When the same category of finding shows up repeatedly in one project or from one role (e.g. repeated secret-handling mistakes), record it here — and add it to `../../memory/lessons-learned.md` if it's a company-wide pattern worth catching earlier via `../../SECURITY.md` itself. ## Contested holds *None recorded yet.* ``` ### YYYY-MM-DD — **Outcome:** hold upheld / hold lifted — ``` ## Policy judgment calls *None recorded yet.* Notes on how an ambiguous `../../SECURITY.md` policy question was actually resolved in practice, so the next similar case doesn't have to be re-reasoned from scratch — and so genuinely recurring ambiguity surfaces as a signal the policy doc itself needs updating. ## Format for new entries ``` ### YYYY-MM-DD — **Why it matters:** ```