v3.0.0
Review policies now live on each instruction set: which reviewer roles must sign off, whether the person who wrote the current version may approve it (they cannot, unless the policy says so), and how many hours a review may take. Approval responses and audit events name the roles still missing, so a set with two reviewer approvals still waits when the policy asks for an admin.
Submitting starts the review clock. POST /reviews/escalate (and the background scheduler) writes a review_escalated event for every overdue set once, and GET /reviews/workload shows the queue with deadlines plus what each reviewer still owes. Migration 0003 adds the policy and timing columns. 41 tests.