Organize and govern
Audit and governance workflow
Establish accountable review for policy, access, ownership, and accepted-risk decisions.
Build governance around evidence already stored in JustScan: scan records, policy outcomes, comments, ownership, notification delivery, and audit records. JustScan does not replace your broader compliance system; use it to make security decisions traceable in the delivery workflow.
Establish operating rules
- Define organization ownership for registries, policies, automation tokens, notification channels, and status pages.
- Start policy against representative scan results and communicate which failures block delivery, which need review, and how to request a suppression.
- Require a clear reason and narrow scope for each suppression. Review suppressions when a fixed image is available or at the team's normal risk-review interval.
- Use comments and manual findings to preserve context that scanner output alone cannot capture.
- Review audit records and delivery logs after role, token, ownership, policy, or notification changes.
Evidence handoff
For a release decision, record the image identity, scan completion state, policy verdict, relevant findings, fix availability, and any approved accepted-risk decision. Export or share the scan evidence according to your team's retention process. Do not treat an operational error as a policy pass; pipelines receive it as a distinct outcome.