Security & Governance / Governance Dashboard

Governance Dashboard

Route: /governance Who: OWNER and ADMIN (tenant_admin / org_owner)

The Governance Dashboard is the control center for policy posture across the organization. Use it to review open violations, manage policy exceptions, track remediation, review posture and analytics, and configure governance settings.

i Engineers who only need to fix issues on their stacks should start with My Findings.

Open Violations

128

23 Critical  •  48 High

57 Medium  •  0 Low

!

Exceptions

12

6 Active  •  4 Expiring soon

2 Expired

Remediation

86

42 In progress  •  44 To do

0 Blocked

Posture

78%

Pass 186  •  Fail 52

Total 238

Policy Packs

14

12 Installed  •  2 Outdated

Coverage 92%

Violations Exceptions Remediation Posture Analytics Settings
▣   Last 30 days⌄ Cloud: All⌄ Framework: All⌄ ⟳   Clear filters

Violations by Severity

128 Total
Critical23(18%)
High48(38%)
Medium57(44%)
Low0(0%)
View all violations

Violations by Cloud

128 Total
AWS62(48%)
Azure34(27%)
GCP22(17%)
Others10(8%)
View by cloud

Top Policy Categories

Access Control
32
Network Security
28
Data Protection
24
Logging & Monitoring
18
Encryption
16
View all categories

Policy Gate Modes

Mode Deploy Behavior
Enforce Blocks deployment when enforcing violations exist or gate evaluation fails.
Advisory Records violations but does not block deployment.
Fail-open Blocks on enforcing violations; evaluation errors become warnings.
ⓘ   The policy gate runs during PLAN / APPLY for pre-deployment validation.

Settings Checklist

  • Set the policy gate mode and environment-aware overrides if required.
  • Enable live scanning defaults for new repositories.
  • Connect the audit webhook for governance-category audit events or configure evidence delivery.
  • Review unified schedules for policy compliance, evidence export, and framework assessments.
  • Confirm Change Management integrations such as Jira or ServiceNow under Administration → Integrations.
Evidence delivery: Email and S3 delivery log intent until the required mail and object-store credentials are configured. Webhook delivery sends a live HTTP POST.