At a glance
| Input | Action | Output | Limit |
|---|---|---|---|
| Captured GitHub revision | Normalize its source and revision identity | Governed code-reference node | Repository access and revision capture must succeed |
| Approved implementation edge | Traverse toward a requirement | Typed implementation relationship | A candidate edge does not count as evidence |
| Approved derivation edge | Move through requirement levels | Recorded requirement chain | Only allowed node and relationship types are accepted |
| Regulation node | Open its retained evidence | Regulatory root recorded by the team | The app does not interpret legal applicability |
How it works
- Capture the GitHub revision as governed evidence.
- Open Enterprise evidence workspace.
- Search for the code reference.
- Select Reverse provenance.
- Follow the approved requirement chain.
- Open the evidence for the regulatory root and every retained hop.
Example
A code revision changes an incident-classification rule. The deposited graph links it to a component requirement. Approved derivation links lead to a system requirement and a regulatory requirement. Leadership can inspect the recorded path and its evidence without reading a query language.
What this does not mean
The trace proves the recorded governed relationships. It does not prove that the regulation applies, that the implementation is correct, or that every dependency is linked. Legal interpretation and technical validation remain external responsibilities.
Related questions
Next step
Capture the exact code revision before relying on its regulatory trace.
View on Atlassian Marketplace