Workflows

Repository reviews and branch comparisons

Select a branch, reuse an audit profile, inspect source health, and compare reviews without losing scope or commit provenance.

An audit reviews a captured revision of a repository. A branch name can move; the recorded commit identifies the source actually assessed.

Select the source

Open the repository list in the current workspace. Select a connected repository, choose an available branch, and start an audit. Check the repository, branch, and commit shown with the run. Branch access comes from that repository's authorized provider connection.

If the branch or repository is unavailable, repair the connection before retrying. Veriom does not silently review a different branch. GitHub access explains installation selection; other repository providers describes their read-only boundaries.

Save a repeatable profile

In Audit profiles and repository health, choose a repository and create a profile. Give it a recognizable name, select its branch and review purpose, and enter repository-relative include and exclude paths.

For example, a payments profile can include services/payments and exclude services/payments/generated. Omitted paths remain outside the assessment. The profile changes the source sent into ingestion and scanning; it also leaves a scope limitation on reports and comparisons.

Save the profile and use it to start the next review. Each run captures the profile version and settings. Editing or deleting the profile later does not rewrite historical audits. An empty include list means the repository root, subject to exclusions and normal ingestion limits.

Inspect repository health

The repository health view shows recorded access checks and evidence history. Review the checked time, available branch or revision information, failure reason, and suggested next step. A historical successful check does not guarantee that a provider still grants access today.

Use the connection management link when an installation loses access. Reconnect or refresh access, then retry the intended source. Keep the failed check as part of the history rather than treating it as a clean review.

Compare audited branches

  1. Open Compare audited branches and choose the repository.
  2. Select a baseline audit and candidate audit. Both selectors identify the captured branch and commit.
  3. Compare the runs and inspect new, persistent, resolved, and review-required findings alongside architecture changes.
  4. Read the comparability explanation before interpreting a finding as resolved.

The runs must belong to the same repository and have equivalent assessed source scope and comparable analysis policy. Missing coverage, changed paths, unfinished runs, and incompatible policy can make a conclusion require review. A finding absent from a narrower review is not evidence that it was fixed.

Saved comparisons retain their source audit references. A branch comparison is an assessment of captured evidence; it is not a merge approval or proof of the deployed state.

When a run needs recovery

SituationNext action
Repository missing from the pickerCheck the provider account and installation's selected repository access
Branch no longer existsSelect an available branch and start a new review with an explicit scope
Another audit is activeFollow the existing run or cancel it if your role permits; avoid repeated submissions
Scope changed between runsRun comparable profiles or review the result as incomplete
Old report has no recorded revisionKeep that provenance unknown; create a new review to establish it

Continue with finding ownership or the audit lifecycle.

Was this guide useful?

Your response stays in this browser unless you open a GitHub issue.
View source