Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

You are reading the development version (master). For the latest release (v3.7.0) see the stable docs.

Compliance Workflow Templates

Pre-built workflow patterns for common regulated use cases. Each template demonstrates how Boruna’s evidence bundle, capability policy, and approval gate features satisfy specific compliance requirements.

TemplateStandardKey Feature
soc2_audit_workflowSOC 2Hash-chained evidence bundle as tamper-evident audit trail
hipaa_data_pipelineHIPAAPHI redaction before evidence bundle write
financial_review_pipelineSOX / dual-controlMulti-approver approval gates with immutable sign-off record

How to use

  1. Copy the template to your project
  2. Replace synthetic data with real capability calls (e.g., net.fetch for live system data)
  3. Run with --record to produce a verifiable evidence bundle:
    boruna workflow run examples/compliance/soc2_audit_workflow --policy allow-all --record
    boruna evidence verify <bundle-dir>
    
  4. The verified bundle is your compliance artifact

Customisation

Each template README describes which steps to modify for your environment. Real integrations typically replace the gather_* or receive_* first step with a capability call to fetch live data.