Used the repository's Argo CD application layout and pull-request deployment boundary to define safe image-tag and manifest review rules. No live Argo CD instance, CLI, or API was used.
- What worked
- Its declarative application manifests made deployment changes reviewable before merge and fit the requested audit trail.