Governance
Audit trails that write themselves
Provenance as a pipeline property: every artifact knows its intent, its decision, and its approver.
Every compliance program we have seen begins the same way: something ships, and then somebody reconstructs why. The reconstruction is done by humans, from memory and Slack history, weeks or quarters after the fact, and it is treated as an unfortunate cost of doing business in a regulated industry.
It is not a cost of regulation. It is a cost of building systems that do not know their own history.
Provenance is a property, not a report
The reframing that mattered: an audit trail is not a document you produce at the end. It is a property every artifact either has or does not have, from the moment it is created.
In a governed pipeline, a change does not exist as a diff floating in a branch. It exists as a node with edges to the work item that motivated it, the requirement that work item served, the decisions that constrained it, the policies that applied, the tests that covered it, and the human who approved it. None of that is assembled later. It is how the change came into being.
What this looks like in practice
Three properties do most of the work.
Every artifact has a motivating parent
No orphan changes. A change traces to a work item, which traces to a PRD or an incident or an RFC. If something cannot name why it exists, the pipeline refuses it. This is a stricter rule than it sounds, and it is the one that generates the most initial friction — engineers are used to small unattributed fixes. We kept the rule and made creating a motivating parent nearly free.
Every gate records its input, not just its verdict
"Approved by Priya" is nearly useless six months later. "Approved by Priya, against revision c41f, with these three policies passing and this one waived, and here is the waiver rationale" is an audit trail. The extra fields cost nothing to capture and are the difference between evidence and a claim.
Waivers are first-class
Every real organization ships things that violate a policy, under time pressure, with someone senior accepting the risk. Systems that pretend otherwise get bypassed. So waivers are a supported artifact: they have an owner, an expiry, a rationale, and they show up in the evidence pack as exactly what they are. A waiver that has expired and not been renewed is a finding the pipeline raises on its own.
The compliance side effect
Once the graph holds all of this, generating a SOC 2 or ISO evidence pack stops being a project and becomes a query. Bind controls to pipeline stages once, and every release carries its own evidence.
The teams we have deployed this with report the same thing, in the same slightly surprised tone: audit preparation went from a multi-week scramble to an afternoon of checking that the query returned what they expected. Nobody had promised them that. They had assumed the scramble was inherent.
The part that is actually hard
None of this is technically difficult. Writing edges to a graph is not research. The hard part is that the trail is only as honest as the gates, and gates are where organizations lie to themselves.
If your approval step is a person clicking through twelve changes in ninety seconds, your pipeline will faithfully record twelve approvals and produce beautiful, complete, worthless evidence. Automating the trail raises the stakes on the judgment at each gate — which is the subject of another post, and the reason we care so much about where human attention actually goes.
Comments
Loading…
Leave a comment