Dalus + Confluence
Publish the architecture, a review pack or the hazard picture where the rest of the organisation already reads, stamped with the revision it came from and updated in place rather than piling up snapshots. One of them reads the review comments back and maps them to the model.
3 workflows
Confluence design description
The architecture, published where people who never open Dalus will read it.
Confluence stakeholder review pack
A pack scoped to one decision, with numbered questions, that reads the comments back afterwards.
Confluence hazard log mirror
The hazard picture published for people outside the safety team, with implemented kept apart from verified.