Replace implemented column with CMMI maturity level

Drop the boolean implemented/not-implemented state in favor of a
mandatory CMMI maturity level enum (NONE, INITIAL, MANAGED, DEFINED,
QUANTITATIVELY_MANAGED, OPTIMIZING) stored as a Postgres enum type.

The migration backfills existing rows (NOT_IMPLEMENTED → NONE,
IMPLEMENTED → INITIAL), makes the column NOT NULL, and drops the old
implemented column and its enum type.

- maturityLevel is required on CreateControlInput and non-nullable (!)
  in the GraphQL schema
- CLI displays human-readable CMMI labels instead of raw enum tokens
- SOA table and published document use a single Maturity column in
  place of the old Implemented + Maturity columns
- Remove ControlImplementationState type and all implemented references
  across backend, frontend, CLI, MCP, n8n, and E2E tests

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-04-20 20:48:23 +02:00
parent da91afc2a7
commit e1148f812e
32 changed files with 271 additions and 586 deletions

View File

@@ -415,9 +415,8 @@ func (r *mutationResolver) CreateControl(ctx context.Context, input types.Create
Description: input.Description,
SectionTitle: input.SectionTitle,
BestPractice: input.BestPractice,
Implemented: input.Implemented,
NotImplementedJustification: input.NotImplementedJustification,
MaturityLevel: input.MaturityLevel,
NotImplementedJustification: input.NotImplementedJustification,
},
)
if err != nil {
@@ -453,9 +452,8 @@ func (r *mutationResolver) UpdateControl(ctx context.Context, input types.Update
Description: gqlutils.UnwrapOmittable(input.Description),
SectionTitle: input.SectionTitle,
BestPractice: input.BestPractice,
Implemented: input.Implemented,
MaturityLevel: input.MaturityLevel,
NotImplementedJustification: gqlutils.UnwrapOmittable(input.NotImplementedJustification),
MaturityLevel: gqlutils.UnwrapOmittable(input.MaturityLevel),
},
)

View File

@@ -1,17 +1,3 @@
enum ControlImplementationState
@goModel(
model: "go.probo.inc/probo/pkg/coredata.ControlImplementationState"
) {
IMPLEMENTED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.ControlImplementationStateImplemented"
)
NOT_IMPLEMENTED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.ControlImplementationStateNotImplemented"
)
}
enum ControlMaturityLevel
@goModel(model: "go.probo.inc/probo/pkg/coredata.ControlMaturityLevel") {
NONE
@@ -113,9 +99,8 @@ type Control implements Node {
name: String!
description: String
bestPractice: Boolean!
implemented: ControlImplementationState!
notImplementedJustification: String
maturityLevel: ControlMaturityLevel
maturityLevel: ControlMaturityLevel!
regulatory: Boolean! @goField(forceResolver: true)
contractual: Boolean! @goField(forceResolver: true)
riskAssessment: Boolean! @goField(forceResolver: true)
@@ -307,9 +292,8 @@ input CreateControlInput {
name: String!
description: String
bestPractice: Boolean!
implemented: ControlImplementationState!
maturityLevel: ControlMaturityLevel!
notImplementedJustification: String
maturityLevel: ControlMaturityLevel
}
input UpdateControlInput {
@@ -318,9 +302,8 @@ input UpdateControlInput {
name: String
description: String @goField(omittable: true)
bestPractice: Boolean
implemented: ControlImplementationState
maturityLevel: ControlMaturityLevel
notImplementedJustification: String @goField(omittable: true)
maturityLevel: ControlMaturityLevel @goField(omittable: true)
}
input DeleteControlInput {

View File

@@ -75,7 +75,6 @@ func NewControl(control *coredata.Control) *Control {
Name: control.Name,
Description: control.Description,
BestPractice: control.BestPractice,
Implemented: control.Implemented,
NotImplementedJustification: control.NotImplementedJustification,
MaturityLevel: control.MaturityLevel,
CreatedAt: control.CreatedAt,

View File

@@ -1473,12 +1473,6 @@ func (r *Resolver) AddControlTool(ctx context.Context, req *mcp.CallToolRequest,
svc := r.ProboService(ctx, input.FrameworkID)
var maturityLevel *coredata.ControlMaturityLevel
if input.MaturityLevel != nil {
v := coredata.ControlMaturityLevel(*input.MaturityLevel)
maturityLevel = &v
}
control, err := svc.Controls.Create(
ctx,
probo.CreateControlRequest{
@@ -1487,9 +1481,8 @@ func (r *Resolver) AddControlTool(ctx context.Context, req *mcp.CallToolRequest,
Description: input.Description,
SectionTitle: input.SectionTitle,
BestPractice: input.BestPractice,
Implemented: coredata.ControlImplementationState(input.Implemented),
MaturityLevel: coredata.ControlMaturityLevel(input.MaturityLevel),
NotImplementedJustification: input.NotImplementedJustification,
MaturityLevel: maturityLevel,
},
)
if err != nil {
@@ -1506,20 +1499,10 @@ func (r *Resolver) UpdateControlTool(ctx context.Context, req *mcp.CallToolReque
svc := r.ProboService(ctx, input.ID)
var implemented *coredata.ControlImplementationState
if input.Implemented != nil {
v := coredata.ControlImplementationState(*input.Implemented)
implemented = &v
}
var maturityLevel **coredata.ControlMaturityLevel
if rawMaturity := UnwrapOmittable(input.MaturityLevel); rawMaturity != nil {
var inner *coredata.ControlMaturityLevel
if *rawMaturity != nil {
v := coredata.ControlMaturityLevel(**rawMaturity)
inner = &v
}
maturityLevel = &inner
var maturityLevel *coredata.ControlMaturityLevel
if input.MaturityLevel != nil {
v := coredata.ControlMaturityLevel(*input.MaturityLevel)
maturityLevel = &v
}
control, err := svc.Controls.Update(
@@ -1530,9 +1513,8 @@ func (r *Resolver) UpdateControlTool(ctx context.Context, req *mcp.CallToolReque
Description: UnwrapOmittable(input.Description),
SectionTitle: input.SectionTitle,
BestPractice: input.BestPractice,
Implemented: implemented,
NotImplementedJustification: UnwrapOmittable(input.NotImplementedJustification),
MaturityLevel: maturityLevel,
NotImplementedJustification: UnwrapOmittable(input.NotImplementedJustification),
},
)
if err != nil {

View File

@@ -4212,7 +4212,7 @@ components:
- section_title
- name
- best_practice
- implemented
- maturity_level
- created_at
- updated_at
properties:
@@ -4239,23 +4239,16 @@ components:
best_practice:
type: boolean
description: Whether control is a best practice
implemented:
maturity_level:
type: string
enum: [IMPLEMENTED, NOT_IMPLEMENTED]
description: Control implementation state
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlImplementationState
enum: [NONE, INITIAL, MANAGED, DEFINED, QUANTITATIVELY_MANAGED, OPTIMIZING]
description: CMMI 0-5 maturity level of the control
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlMaturityLevel
not_implemented_justification:
type:
- string
- "null"
description: Justification for non-implementation
maturity_level:
type:
- string
- "null"
enum: [NONE, INITIAL, MANAGED, DEFINED, QUANTITATIVELY_MANAGED, OPTIMIZING, null]
description: CMMI 0-5 maturity level of the control
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlMaturityLevel
created_at:
type: string
format: date-time
@@ -4330,7 +4323,7 @@ components:
- section_title
- name
- best_practice
- implemented
- maturity_level
properties:
organization_id:
$ref: "#/components/schemas/GID"
@@ -4350,23 +4343,16 @@ components:
best_practice:
type: boolean
description: Whether control is a best practice
implemented:
maturity_level:
type: string
enum: [IMPLEMENTED, NOT_IMPLEMENTED]
description: Control implementation state
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlImplementationState
enum: [NONE, INITIAL, MANAGED, DEFINED, QUANTITATIVELY_MANAGED, OPTIMIZING]
description: CMMI 0-5 maturity level of the control
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlMaturityLevel
not_implemented_justification:
type:
- string
- "null"
description: Justification for non-implementation
maturity_level:
type:
- string
- "null"
enum: [NONE, INITIAL, MANAGED, DEFINED, QUANTITATIVELY_MANAGED, OPTIMIZING, null]
description: CMMI 0-5 maturity level of the control
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlMaturityLevel
AddControlOutput:
type: object
@@ -4397,21 +4383,15 @@ components:
best_practice:
type: boolean
description: Whether control is a best practice
implemented:
maturity_level:
type: string
enum: [IMPLEMENTED, NOT_IMPLEMENTED]
description: Control implementation state
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlImplementationState
enum: [NONE, INITIAL, MANAGED, DEFINED, QUANTITATIVELY_MANAGED, OPTIMIZING]
description: CMMI 0-5 maturity level of the control
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlMaturityLevel
not_implemented_justification:
type: ["string", "null"]
description: Justification for non-implementation
go.probo.inc/mcpgen/omittable: true
maturity_level:
type: ["string", "null"]
enum: [NONE, INITIAL, MANAGED, DEFINED, QUANTITATIVELY_MANAGED, OPTIMIZING, null]
description: CMMI 0-5 maturity level of the control
go.probo.inc/mcpgen/type: go.probo.inc/probo/pkg/coredata.ControlMaturityLevel
go.probo.inc/mcpgen/omittable: true
UpdateControlOutput:
type: object

View File

@@ -19,12 +19,6 @@ import (
)
func NewControl(c *coredata.Control) *Control {
var maturityLevel *string
if c.MaturityLevel != nil {
s := string(*c.MaturityLevel)
maturityLevel = &s
}
return &Control{
ID: c.ID,
OrganizationID: c.OrganizationID,
@@ -33,9 +27,8 @@ func NewControl(c *coredata.Control) *Control {
Name: c.Name,
Description: c.Description,
BestPractice: c.BestPractice,
Implemented: ControlImplemented(c.Implemented),
NotImplementedJustification: c.NotImplementedJustification,
MaturityLevel: maturityLevel,
MaturityLevel: ControlMaturityLevel(c.MaturityLevel),
CreatedAt: c.CreatedAt,
UpdatedAt: c.UpdatedAt,
}