Add implemented state and justification to controls

Introduce `implemented` enum (IMPLEMENTED/NOT_IMPLEMENTED) and
`not_implemented_justification` (nullable text) fields on the Control
entity across all API surfaces (GraphQL, MCP, CLI), database, frontend,
and SOA export.

The database stores implementation state as a PostgreSQL enum
`control_implementation_state`. Controls default to IMPLEMENTED during
migration. The SOA list and PDF export show implementation status
alongside applicability, with "-" for non-applicable controls.
Justification columns are renamed for clarity: "Justification for
non-applicability" and "Justification for non-implementation".

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-03-16 19:24:34 +01:00
parent d8670d2412
commit cf1dadc0b5
25 changed files with 663 additions and 233 deletions

View File

@@ -30,15 +30,17 @@ import (
type (
Control struct {
ID gid.GID `db:"id"`
OrganizationID gid.GID `db:"organization_id"`
SectionTitle string `db:"section_title"`
FrameworkID gid.GID `db:"framework_id"`
Name string `db:"name"`
Description *string `db:"description"`
BestPractice bool `db:"best_practice"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
ID gid.GID `db:"id"`
OrganizationID gid.GID `db:"organization_id"`
SectionTitle string `db:"section_title"`
FrameworkID gid.GID `db:"framework_id"`
Name string `db:"name"`
Description *string `db:"description"`
BestPractice bool `db:"best_practice"`
Implemented ControlImplementationState `db:"implemented"`
NotImplementedJustification *string `db:"not_implemented_justification"`
CreatedAt time.Time `db:"created_at"`
UpdatedAt time.Time `db:"updated_at"`
}
Controls []*Control
@@ -131,6 +133,8 @@ WITH ctrl AS (
c.name,
c.description,
c.best_practice,
c.implemented,
c.not_implemented_justification,
c.created_at,
c.updated_at,
c.search_vector
@@ -149,6 +153,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -240,6 +246,8 @@ WITH ctrl AS (
c.name,
c.description,
c.best_practice,
c.implemented,
c.not_implemented_justification,
c.created_at,
c.updated_at,
c.search_vector
@@ -258,6 +266,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -355,6 +365,8 @@ WITH ctrl AS (
c.name,
c.description,
c.best_practice,
c.implemented,
c.not_implemented_justification,
c.created_at,
c.updated_at,
c.search_vector
@@ -379,6 +391,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -458,6 +472,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -552,6 +568,8 @@ WITH ctrl AS (
c.name,
c.description,
c.best_practice,
c.implemented,
c.not_implemented_justification,
c.created_at,
c.updated_at,
c.search_vector
@@ -570,6 +588,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -616,6 +636,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -664,6 +686,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -712,6 +736,8 @@ INSERT INTO
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
)
@@ -724,22 +750,26 @@ VALUES (
@name,
@description,
@best_practice,
@implemented,
@not_implemented_justification,
@created_at,
@updated_at
);
`
args := pgx.StrictNamedArgs{
"tenant_id": scope.GetTenantID(),
"control_id": c.ID,
"organization_id": c.OrganizationID,
"framework_id": c.FrameworkID,
"section_title": c.SectionTitle,
"name": c.Name,
"description": c.Description,
"best_practice": c.BestPractice,
"created_at": c.CreatedAt,
"updated_at": c.UpdatedAt,
"tenant_id": scope.GetTenantID(),
"control_id": c.ID,
"organization_id": c.OrganizationID,
"framework_id": c.FrameworkID,
"section_title": c.SectionTitle,
"name": c.Name,
"description": c.Description,
"best_practice": c.BestPractice,
"implemented": c.Implemented,
"not_implemented_justification": c.NotImplementedJustification,
"created_at": c.CreatedAt,
"updated_at": c.UpdatedAt,
}
_, err := conn.Exec(ctx, q, args)
@@ -789,6 +819,8 @@ UPDATE controls SET
description = @description,
section_title = @section_title,
best_practice = @best_practice,
implemented = @implemented,
not_implemented_justification = @not_implemented_justification,
updated_at = @updated_at
WHERE %s
AND id = @control_id
@@ -796,12 +828,14 @@ WHERE %s
q = fmt.Sprintf(q, scope.SQLFragment())
args := pgx.StrictNamedArgs{
"control_id": c.ID,
"name": c.Name,
"description": c.Description,
"section_title": c.SectionTitle,
"best_practice": c.BestPractice,
"updated_at": c.UpdatedAt,
"control_id": c.ID,
"name": c.Name,
"description": c.Description,
"section_title": c.SectionTitle,
"best_practice": c.BestPractice,
"implemented": c.Implemented,
"not_implemented_justification": c.NotImplementedJustification,
"updated_at": c.UpdatedAt,
}
maps.Copy(args, scope.SQLArguments())
@@ -839,6 +873,8 @@ WITH ctrl AS (
c.name,
c.description,
c.best_practice,
c.implemented,
c.not_implemented_justification,
c.created_at,
c.updated_at,
c.search_vector
@@ -857,6 +893,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM
@@ -906,6 +944,8 @@ WITH ctrl AS (
c.name,
c.description,
c.best_practice,
c.implemented,
c.not_implemented_justification,
c.created_at,
c.updated_at,
c.search_vector
@@ -924,6 +964,8 @@ SELECT
name,
description,
best_practice,
implemented,
not_implemented_justification,
created_at,
updated_at
FROM

View File

@@ -0,0 +1,66 @@
// Copyright (c) 2025 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
package coredata
import (
"database/sql/driver"
"fmt"
)
type (
ControlImplementationState string
)
const (
ControlImplementationStateImplemented ControlImplementationState = "IMPLEMENTED"
ControlImplementationStateNotImplemented ControlImplementationState = "NOT_IMPLEMENTED"
)
func (s ControlImplementationState) IsValid() bool {
switch s {
case ControlImplementationStateImplemented, ControlImplementationStateNotImplemented:
return true
}
return false
}
func (s ControlImplementationState) String() string {
return string(s)
}
func (s ControlImplementationState) MarshalText() ([]byte, error) {
return []byte(s.String()), nil
}
func (s *ControlImplementationState) UnmarshalText(data []byte) error {
val := ControlImplementationState(data)
if !val.IsValid() {
return fmt.Errorf("invalid ControlImplementationState value: %q", string(data))
}
*s = val
return nil
}
func (s *ControlImplementationState) Scan(value any) error {
val, ok := value.(string)
if !ok {
return fmt.Errorf("invalid scan source for ControlImplementationState, expected string got %T", value)
}
return s.UnmarshalText([]byte(val))
}
func (s ControlImplementationState) Value() (driver.Value, error) {
return s.String(), nil
}

View File

@@ -0,0 +1,5 @@
-- Add implemented state and not_implemented_justification columns to controls table
CREATE TYPE control_implementation_state AS ENUM ('IMPLEMENTED', 'NOT_IMPLEMENTED');
ALTER TABLE controls ADD COLUMN implemented control_implementation_state NOT NULL DEFAULT 'IMPLEMENTED';
ALTER TABLE controls ADD COLUMN not_implemented_justification text;
ALTER TABLE controls ALTER COLUMN implemented DROP DEFAULT;