JustScan Documentation
Organize and govern

Audit and governance workflow

Establish accountable review for policy, access, ownership, and accepted-risk decisions.

Build governance around evidence already stored in JustScan: scan records, policy outcomes, comments, ownership, notification delivery, and audit records. JustScan does not replace your broader compliance system; use it to make security decisions traceable in the delivery workflow.

Establish operating rules

  1. Define organization ownership for registries, policies, automation tokens, notification channels, and status pages.
  2. Start policy against representative scan results and communicate which failures block delivery, which need review, and how to request a suppression.
  3. Require a clear reason and narrow scope for each suppression. Review suppressions when a fixed image is available or at the team's normal risk-review interval.
  4. Use comments and manual findings to preserve context that scanner output alone cannot capture.
  5. Review audit records and delivery logs after role, token, ownership, policy, or notification changes.

Evidence handoff

For a release decision, record the image identity, scan completion state, policy verdict, relevant findings, fix availability, and any approved accepted-risk decision. Export or share the scan evidence according to your team's retention process. Do not treat an operational error as a policy pass; pipelines receive it as a distinct outcome.

On this page