Compliance Glossary for Confluence

How do I trace code to regulation?

Select the captured code revision and choose Reverse provenance. Approved or imported links can lead from the code reference to component, system, or business requirements, then to the recorded regulation. Each hop keeps its type, provenance, and evidence reference. Candidate links remain outside the governed path until reviewed.

Last verified against production v6 · 26 September 2026

At a glance

InputActionOutputLimit
Captured GitHub revisionNormalize its source and revision identityGoverned code-reference nodeRepository access and revision capture must succeed
Approved implementation edgeTraverse toward a requirementTyped implementation relationshipA candidate edge does not count as evidence
Approved derivation edgeMove through requirement levelsRecorded requirement chainOnly allowed node and relationship types are accepted
Regulation nodeOpen its retained evidenceRegulatory root recorded by the teamThe app does not interpret legal applicability

How it works

  1. Capture the GitHub revision as governed evidence.
  2. Open Enterprise evidence workspace.
  3. Search for the code reference.
  4. Select Reverse provenance.
  5. Follow the approved requirement chain.
  6. Open the evidence for the regulatory root and every retained hop.

Example

A code revision changes an incident-classification rule. The deposited graph links it to a component requirement. Approved derivation links lead to a system requirement and a regulatory requirement. Leadership can inspect the recorded path and its evidence without reading a query language.

What this does not mean

The trace proves the recorded governed relationships. It does not prove that the regulation applies, that the implementation is correct, or that every dependency is linked. Legal interpretation and technical validation remain external responsibilities.

Related questions

Next step

Capture the exact code revision before relying on its regulatory trace.

View on Atlassian Marketplace
Verification basis: production v6 code, tests, manifest, and operations guidance. Verified 26 September 2026.