review process for spec PRs?

do we WebAppSec have a review process for spec PRs? I.e. that is followed
prior to merging 'em?

this question/topic comes because I have an open Credman PR #138
<> that
would be good to land, and will be crafting further PRs here in the near

So I'm wondering who here (if anyone) ought to sign-off before I click the
github "[squash & merge]"  button?



