Add implemented state and justification to controls

Introduce `implemented` enum (IMPLEMENTED/NOT_IMPLEMENTED) and
`not_implemented_justification` (nullable text) fields on the Control
entity across all API surfaces (GraphQL, MCP, CLI), database, frontend,
and SOA export.

The database stores implementation state as a PostgreSQL enum
`control_implementation_state`. Controls default to IMPLEMENTED during
migration. The SOA list and PDF export show implementation status
alongside applicability, with "-" for non-applicable controls.
Justification columns are renamed for clarity: "Justification for
non-applicability" and "Justification for non-implementation".

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-03-16 19:24:34 +01:00
parent d8670d2412
commit cf1dadc0b5
25 changed files with 663 additions and 233 deletions

View File

@@ -65,6 +65,12 @@ var (
}
return "no"
},
"derefString": func(s *string) string {
if s == nil {
return ""
}
return *s
},
"boolToYesNoDash": func(b *bool) string {
if b == nil {
return "-"
@@ -312,15 +318,17 @@ type (
}
ControlData struct {
FrameworkName string
SectionTitle string
Name string
Applicability *bool
Justification *string
BestPractice *bool
Regulatory *bool
Contractual *bool
RiskAssessment *bool
FrameworkName string
SectionTitle string
Name string
Applicability *bool
Justification *string
BestPractice *bool
Implemented *string
NotImplementedJustification *string
Regulatory *bool
Contractual *bool
RiskAssessment *bool
}
)