Surfaces the CLI-only governance layer (sovra governance): plan propose/approve/version, accept-risk, verify-and-close, and the two audit logs.
← Back to scan to publish tickets on an approved plan. If you opened this page in a new tab (the usual path, from Findings' "Open in Plans" link), just switch back to that tab instead — your scan report is still there.
Approve / Verify below record a typed name + role as an audit attribution in the invocations and decisions log — this is not an authenticated login. There is no per-user auth behind this local UI; the audit trail is what makes a denial provable, not the button being disabled.
Project
Planned entries
Target
Ecosystem
Relation
Flags
Blast radius
Status
Ticket / review
Plan summary
Approve plan gate 1
On approve
1. Plan locked — immutable; a new/changed finding creates v(n+1), never edits this version in place.
2. Publish tickets from the scan page's Replacement plan panel (idempotent — safe to re-run).
3. Verify & close (below) resolves each ticketed entry once a re-scan shows its flags cleared — never on a claim, only on re-measurement.
Verify & close re-scan
Re-scans the target fresh and closes any plan entries whose flags are now clear — the same "trust comes from re-measurement" contract as the CLI.
Decisions the WHY of each human gate
When
Kind
By
About
Rationale
Invocations every governed call, allowed or denied
When
Action
Actor
Role
Outcome
Reason
Denied rows are the proof, not an assumption: a role without permission is refused server-side and the refusal itself is logged.
Decisions and invocations are logged per tenant, not per project — this page filters them to the selected project client-side.