What's real here: the PR-gate policy is the actual sovra-policy.json the CI gate reads. The tracker profile is saved in this browser only, to prefill Publish. Roles are read live from the enforcement layer.
PR-gate / compliance policy
Your tenant's own gate policy, stored server-side . The CLI's sovra gate reads a local sovra-policy.json; export this one there to use the same rules in CI.
Score floors (0 = no minimum)
Forbidden signals
License policy
Tracker integration profile
Saved in this browser's local storage only — never sent to Sovra's server except when you click Publish tickets on a scan. Prefills the Publish panel so you stop retyping it.
Roles & access read-only
Live from the enforcement layer (governance.ROLES) — not a separate ACL to drift out of sync. Explicit-actor forms elsewhere ask you to pick one of these; the server re-checks it on every call regardless of what the form allowed you to select.