The governance journey

Seven ordered steps from "organization set up" to "governed, with evidence for an auditor" — each computed from stored facts, never a checkbox, with what is done, what is next, why it matters and where to do it.

Organization → Governance journey, at the top of the Governance section of the sidebar. It is also linked from the end of the setup wizard, and a progress card on the organization's Overview page shows the next step until every step is done, then gives way to a one-line link back.

The setup wizard covers setup. The journey starts where it stops: the path from a connected organization to one whose pull requests are judged, whose enforcement is verified on the host, and whose evidence can be handed to an auditor.

The steps

Every step is computed on the server from stored facts. There is no checkbox to tick.

# Step Done when
1 Connect a repository An active code-host connection and a code-host repository in a workspace. The bundled sample never counts.
2 See coverage Every connected repository is judged (monitor or enforce) or left off on purpose. Off is the default, so it is not a decision until someone presses Leave it off on purpose on the workspace's Compliance page.
3 Choose the rules An approval policy, plus an active policy in any stage. Madebook's default approval rules count and are labelled as the default. Simulating first is recommended, not required; the latest simulation is shown.
4 Turn compliance on A repository in enforce. Monitor counts as started.
5 Verify enforcement Every enforced repository has an enforced reading from the host no older than 12 hours. A personal-token connection can never pass — the check cannot be pinned to it — and the step says the GitHub App is needed. A misconfigured reading carries its fixes; a stale one asks to verify again.
6 Review a pull request A pull request judged on its current head commit and approved independently, or a review capsule reviewed by someone other than its session's starter.
7 Export evidence A signed pull request or mission package was built. One that has since expired still counts, with a note to rebuild one. A whole-record export is not a package.
— Link CodeBook or OpenBook (optional) An active peer link. Not available here when no sibling is configured.
— Set an outcomes baseline (optional) An explicit baseline, or the default one has ended.

What each step shows

Three states, as in the setup wizard: done, needs something (with started when part of it is there), and could not check when the facts behind it could not be read — never shown as done. Each step says why it matters and links to the page that does it.

Every link says whether you may use it and, if not, which roles can. The target pages enforce their own permissions regardless.

Repositories in workspaces you cannot open are counted in the steps but never named, and the per-workspace breakdown lists only the workspaces you can reach.

Who can see it

Anyone who can read the organization, viewers included. No host is called to compute it, and every query is bounded.