Run a compliance scan
A scan checks each chosen project's repository against every rule in one pack and gives the repository a level. Run one when you first open Compliance, and again whenever you want fresh results.
Before you start: Compliance is part of some plans only. While your organization's plan leaves it out, Compliance is not in the sidebar; see Check your plan and limits. Seeing results needs the permission to view compliance; starting a scan needs the permission to edit it on each project you scan.
Start the first scan
- In the sidebar, select Compliance. With no scan yet, the page reads Score your repos against a ready-made pack.
- In Projects, keep the projects to score. Every project you can see starts selected; Select all brings back any you removed. A project marked can't be scanned yet has no repository or no node to scan on; its row says which once the scan runs.
- In Pack, choose the pack to score against. A pack marked ready-made is one of Jaah's; to change its rules you fork it first (see How compliance works).
- Select Start analysis. If it isn't there, the page says why: You can view results. Starting a scan needs compliance edit access.
- Wait while each row shows Scanning. The summary reads X of Y scanned · running, and the header button reads Scanning… until the last row finishes.
- Read the results. Each row shows the repository's level (L1 and up, or Below L1), each pillar's N/M passing, and its Next gap, which expands to Why it matters. A row that reads Scan error shows why, with Open to rescan.
- Select a project's name to open its page, with its Gaps, Levels by pillar and Every rule.
Scan again
- Rescan all, at the top of the page, runs the same projects and pack again. It's unavailable while a scan is running.
- To rescan every day, select Settings, then turn on Daily scan. The section shows Next run and its date. Changing it needs the permission to edit compliance for the whole organization.
What next
Fix what the scan found: Fix all gaps on a repository's page, or Start campaign for the same rules across many repositories. Each fix is an ordinary task that opens a pull request; see How compliance works for how a gap moves until a rescan confirms it.