Skip to main content

How compliance works

Compliance checks your repositories against a set of engineering rules and tells you, for each repository, how far it meets them and what to fix next. It opens from Compliance in the sidebar.

Compliance is part of some plans only. While your organization's plan leaves it out, Compliance is not in the sidebar and a link to it opens a "no access" page (see How plans and billing work). Seeing results also needs the permission to view compliance, and starting scans, fixing gaps or changing rules needs the permission to edit it; fixing gaps also needs permission to create and edit tasks on the project (see How team and access work).

Packs, rules, pillars and levels​

A pack is a set of rules. Jaah offers Ready-made packs; to change one, you Fork it into Your pack and Add rule to it. Each rule states its Intent and Why it matters, which pillar it belongs to, and the level it counts toward. A rule's Mode says how strict it is: Observe rules are recorded but never count toward a level or show as a gap, while Advise and Nudge rules count. A repository's level — L1 and up, or Below L1 — climbs one level at a time: a level is reached when most of its rules that apply to the repository pass (by default, at least four in five), and every level below it is reached too. Rules that are waived, off, out of scope or not applicable are left out of that count.

Scanning​

To start, pick the projects to score and a pack, then select Start analysis. Jaah checks each project's repository on one of your nodes, and each row fills in as its check finishes. A project with no repository or no node reads Not scannable: no repo or Not scannable: no node. Rescan all runs the same selection again, and the Daily scan switch in Settings repeats it every day.

Each rule's result for a repository is one of: Pass, Fail, n/a, Out of scope, Off, Observed, Waived, a judge's verdict, Needs ledger data, Not yet scanned, Scanning or Scan error. Only Pass is green. A rule checked by a judge — an AI reading the repository against a rubric — shows its confidence, or unverified when it is unsure; a confident judge pass counts toward the level, but is never shown green. A check that ends without a result reads Scan error, never Pass.

Fixing, waiving and campaigns​

Open a repository to see its Gaps, Levels by pillar and Every rule. Fix all gaps files a task that fixes them, which opens a pull request on the project. The gap then moves through Fix queued, Fix in progress, PR open and Fix merged — rescan to confirm, or Fix failed, where fixing it can be tried again; it turns green only once a rescan passes.

Waive accepts a gap for a time instead: it names an Owner, an Expires date, a Compensating control and a Reason, and counts as Debt until it lapses.

Start campaign fixes the same failing rules across many repositories at once: you pick the rules, and Jaah files one fix per repository, lowest level first. The Campaign count on the summary strip follows them from queued until each repository is scanned again.

Compliance works on your projects and runs through ordinary tasks, so every fix appears on the board like any other work.