At a glance
| Input | Action | Output | Limit |
|---|---|---|---|
| Terms and Confluence pages | Govern meanings and scan recorded usage | Findings and evidence records | No certification or guaranteed compliance |
| Frozen evidence package | Recalculate hashes, counts, membership, and references | Conformance result | Does not prove source correctness or legal validity |
| Release evidence | Create an external-only reissue handoff | Non-executing handoff manifest | No release approval or electronic signature |
| Quality process | Link evidence and export records | Supporting evidence | Does not replace a QMS |
| Evidence archive | Validate content-addressed records and counts | Portable archive | Not legal WORM storage or a complete site backup |
| CAD or PDF file | Record format or structure metadata, provenance, and hash | Metadata-level evidence | Semantic content remains unchecked |
| Candidate trace link | Keep it in the review-only partition | Candidate relationship | Excluded from governed evidence until imported or approved |
| Frozen baseline search | Search indexed subject prefixes | Bounded subject results | No arbitrary full-text search; results can span multiple pages |
| Non-Confluence source | Use GitHub or controlled file upload | Normalized evidence | Named provider profiles do not create production connections |
How it works
- Use Upload controlled evidence to confirm the supported file type and size.
- Use Run verification to check recorded integrity and references. Do not treat the result as source certification.
- Use Forward impact and Reverse provenance to inspect governed links. Review candidate links separately.
- Use Export archive to test portability and integrity. Do not treat the archive as legal WORM storage.
- Use Download reissue handoff to prepare external work. Complete approval and signatures in the designated external system.
Example
A medical-device team freezes approved meanings, document revisions, test evidence, and trace links. The app verifies the recorded package and exports a reissue handoff. The quality team still approves the release and executes electronic signatures in its QMS. An uploaded CAD file contributes its hash and format metadata. It does not contribute interpreted design intent.
What this does not mean
Confluence permissions are read-only. The app does not create, edit, or delete Confluence pages. The manifest declares backend egress only to api.github.com. Named provider profiles are design candidates, not production connections. The 250,000-artifact workload is a local simulation. It does not establish live Forge latency, cost, residency, or capacity.
Related questions
Next step
Evaluate these boundaries against your control model before installation.
View on Atlassian Marketplace