Workflows

Explore the platform

Follow a complete review from connected evidence to ownership, approved reporting, and a workspace portfolio.

Start with the interactive demo. It uses a fictional Northstar system and runs in your browser. Change a branch, advance the review, assign a finding, inspect architecture, approve a sample report, and export a sample questionnaire without connecting an account.

The demo illustrates the workflow. Its source access checks, findings, deployment records, and progress are sample data. Resetting or reloading clears your changes. Sample downloads contain only the content you approved in the demo; a sample review does not create a live public link.

Choose a task

AreaWhat to doGuide
Evidence and repositoriesChoose a branch, save its path scope, check repository health, and compare captured commitsRepository reviews
Review and ownershipInspect architectural consequence, assign work, save finding views, and preview CODEOWNERS routingFinding ownership
ArchitectureFollow a root cause, inspect service owners, compare environments, and trace dependency evidenceService and dependency inventory
ReportingSelect content, approve a report, and share an expiring snapshotReport review links
Customer assuranceImport questions, draft cited answers, review exceptions, and export approved responsesQuestionnaires
Team oversightFind stale evidence, unassigned work, and overdue findings across accessible workspacesWorkspace portfolio

Follow one review

  1. Choose the workspace that owns the system. Open Integrations, connect evidence, and select repositories.
  2. Choose a repository branch and profile. Check the captured commit and include/exclude paths before starting the audit.
  3. Follow collection, scanning, Context Engine reconciliation, and specialist review. Scanner observations need applicability and architectural review before becoming reviewed impact.
  4. Open a finding and inspect its evidence, consequence, and remaining uncertainty. Assign an owner or preview ownership routing.
  5. Review the draft report. Confirm its branch, commit, scope, findings, and coverage limitations before approval.
  6. Export the approved report or create a review link with explicitly selected content. Use approved report evidence to answer a questionnaire.
  7. Return to the portfolio to find the next workspace that needs attention.

Understand the evidence states

A connected source can still have missing or stale evidence. An observed deployment does not prove a dependency executes at runtime. A manual statement does not become observed evidence simply because it was saved. An empty finding list does not prove that unassessed paths are secure.

Veriom keeps those distinctions visible so the next action is clear: repair access, collect evidence, complete a review, assign an owner, or approve a supported result.

Automate reviews and keep teams informed

Use Apps and audit automations to schedule a listed branch in your timezone, react to GitHub events, and send audit outcomes to Slack, Discord, email, or your own webhook workflow. Delivery history shows confirmations and retries.

Was this guide useful?

Your response stays in this browser unless you open a GitHub issue.
View source