Files
probo/pkg/server/api/trust/v1/graphql/trust_center.graphql
Sacha Al Himdani c635492f75 SOA as document: replace export with publish workflow
Statements of Applicability are no longer exported as one-off PDFs.
Instead, each SOA owns a persistent document that accumulates versions
over time, following the same publish/approve lifecycle as authored
documents.

Publishing without approvers publishes immediately; publishing with
approvers creates a draft pending approval via the existing quorum
system. SOAs can also store default approvers that are pre-populated in
the publish dialog.

The SOA is removed from the snapshot system — applicability statements
are now queried directly (snapshot_id IS NULL) rather than through
snapshot copies.

A standalone migration script (cmd/migrate-soa-snapshots-to-documents)
converts existing SOA snapshots into documents with proper ProseMirror
content, preserving version history and approval decisions.

Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
2026-04-16 00:01:13 +02:00

425 lines
10 KiB
GraphQL

type TrustCenter implements Node {
id: ID!
active: Boolean!
slug: String!
logoFileUrl: String @goField(forceResolver: true)
darkLogoFileUrl: String @goField(forceResolver: true)
nonDisclosureAgreement: NonDisclosureAgreement @goField(forceResolver: true)
viewerSubscription: MailingListSubscriber @goField(forceResolver: true)
organization: Organization! @goField(forceResolver: true)
documents(
first: Int
after: CursorKey
last: Int
before: CursorKey
): DocumentConnection! @goField(forceResolver: true)
audits(
first: Int
after: CursorKey
last: Int
before: CursorKey
): AuditConnection! @goField(forceResolver: true)
subprocessors(
first: Int
after: CursorKey
last: Int
before: CursorKey
): SubprocessorConnection! @goField(forceResolver: true)
references(
first: Int
after: CursorKey
last: Int
before: CursorKey
): TrustCenterReferenceConnection! @goField(forceResolver: true)
trustCenterFiles(
first: Int
after: CursorKey
last: Int
before: CursorKey
): TrustCenterFileConnection! @goField(forceResolver: true)
complianceFrameworks(
first: Int
after: CursorKey
last: Int
before: CursorKey
): ComplianceFrameworkConnection! @goField(forceResolver: true)
externalUrls(
first: Int
after: CursorKey
last: Int
before: CursorKey
): ComplianceExternalURLConnection! @goField(forceResolver: true)
updates(
first: Int
after: CursorKey
last: Int
before: CursorKey
): MailingListUpdateConnection! @goField(forceResolver: true)
}
enum DocumentType
@goModel(model: "go.probo.inc/probo/pkg/coredata.DocumentType") {
OTHER @goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeOther")
GOVERNANCE
@goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeGovernance")
POLICY @goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypePolicy")
PROCEDURE
@goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeProcedure")
PLAN @goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypePlan")
REGISTER
@goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeRegister")
RECORD @goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeRecord")
REPORT @goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeReport")
TEMPLATE
@goEnum(value: "go.probo.inc/probo/pkg/coredata.DocumentTypeTemplate")
STATEMENT_OF_APPLICABILITY
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.DocumentTypeStatementOfApplicability"
)
}
type Document implements Node @nda {
id: ID!
title: String!
documentType: DocumentType!
isUserAuthorized: Boolean! @goField(forceResolver: true)
access: DocumentAccess @goField(forceResolver: true)
}
type DocumentConnection @nda {
edges: [DocumentEdge!]!
pageInfo: PageInfo!
}
type DocumentEdge @nda {
cursor: CursorKey!
node: Document!
}
type Framework implements Node @nda {
id: ID!
name: String!
lightLogoURL: String @goField(forceResolver: true)
darkLogoURL: String @goField(forceResolver: true)
}
type Report implements Node @nda {
id: ID!
filename: String!
isUserAuthorized: Boolean! @goField(forceResolver: true)
access: DocumentAccess @goField(forceResolver: true)
}
type Audit implements Node @nda {
id: ID!
name: String
framework: Framework! @goField(forceResolver: true)
report: Report @goField(forceResolver: true)
}
type AuditConnection @nda {
edges: [AuditEdge!]!
pageInfo: PageInfo!
}
type AuditEdge @nda {
cursor: CursorKey!
node: Audit!
}
type ComplianceFramework implements Node
@goModel(
model: "go.probo.inc/probo/pkg/server/api/trust/v1/types.ComplianceFramework"
) {
id: ID!
framework: Framework! @goField(forceResolver: true)
}
type ComplianceFrameworkConnection
@goModel(
model: "go.probo.inc/probo/pkg/server/api/trust/v1/types.ComplianceFrameworkConnection"
) {
edges: [ComplianceFrameworkEdge!]!
pageInfo: PageInfo!
}
type ComplianceFrameworkEdge
@goModel(
model: "go.probo.inc/probo/pkg/server/api/trust/v1/types.ComplianceFrameworkEdge"
) {
cursor: CursorKey!
node: ComplianceFramework!
}
enum SubprocessorCategory
@goModel(model: "go.probo.inc/probo/pkg/coredata.VendorCategory") {
ANALYTICS
@goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryAnalytics")
CLOUD_MONITORING
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryCloudMonitoring"
)
CLOUD_PROVIDER
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryCloudProvider"
)
COLLABORATION
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryCollaboration"
)
CUSTOMER_SUPPORT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryCustomerSupport"
)
DATA_STORAGE_AND_PROCESSING
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryDataStorageAndProcessing"
)
DOCUMENT_MANAGEMENT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryDocumentManagement"
)
EMPLOYEE_MANAGEMENT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryEmployeeManagement"
)
ENGINEERING
@goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryEngineering")
FINANCE
@goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryFinance")
IDENTITY_PROVIDER
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryIdentityProvider"
)
IT @goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryIT")
MARKETING
@goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryMarketing")
OFFICE_OPERATIONS
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryOfficeOperations"
)
OTHER @goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryOther")
PASSWORD_MANAGEMENT
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryPasswordManagement"
)
PRODUCT_AND_DESIGN
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryProductAndDesign"
)
PROFESSIONAL_SERVICES
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryProfessionalServices"
)
RECRUITING
@goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategoryRecruiting")
SALES @goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategorySales")
SECURITY
@goEnum(value: "go.probo.inc/probo/pkg/coredata.VendorCategorySecurity")
VERSION_CONTROL
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.VendorCategoryVersionControl"
)
}
type Subprocessor implements Node @nda {
id: ID!
name: String!
description: String
category: SubprocessorCategory!
websiteUrl: String
privacyPolicyUrl: String
countries: [CountryCode!]!
}
type SubprocessorConnection
@goModel(
model: "go.probo.inc/probo/pkg/server/api/trust/v1/types.SubprocessorConnection"
) @nda {
edges: [SubprocessorEdge!]!
pageInfo: PageInfo!
totalCount: Int! @goField(forceResolver: true)
}
type SubprocessorEdge @nda {
cursor: CursorKey!
node: Subprocessor!
}
type TrustCenterReference implements Node @nda {
id: ID!
name: String!
description: String
websiteUrl: String!
logoUrl: String! @goField(forceResolver: true)
}
type TrustCenterReferenceConnection @nda {
edges: [TrustCenterReferenceEdge!]!
pageInfo: PageInfo!
}
type TrustCenterReferenceEdge @nda {
cursor: CursorKey!
node: TrustCenterReference!
}
type TrustCenterFile implements Node @nda {
id: ID!
name: String!
category: String!
isUserAuthorized: Boolean! @goField(forceResolver: true)
access: DocumentAccess @goField(forceResolver: true)
}
type TrustCenterFileConnection @nda {
edges: [TrustCenterFileEdge!]!
pageInfo: PageInfo!
}
type TrustCenterFileEdge @nda {
cursor: CursorKey!
node: TrustCenterFile!
}
type ComplianceExternalURL implements Node {
id: ID!
name: String!
url: String!
rank: Int!
}
type ComplianceExternalURLConnection {
edges: [ComplianceExternalURLEdge!]!
pageInfo: PageInfo!
}
type ComplianceExternalURLEdge {
cursor: CursorKey!
node: ComplianceExternalURL!
}
type TrustCenterAccess implements Node {
id: ID!
email: EmailAddr!
name: String!
createdAt: Datetime!
updatedAt: Datetime!
}
enum DocumentAccessStatus
@goModel(
model: "go.probo.inc/probo/pkg/coredata.TrustCenterDocumentAccessStatus"
) {
REQUESTED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.TrustCenterDocumentAccessStatusRequested"
)
GRANTED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.TrustCenterDocumentAccessStatusGranted"
)
REJECTED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.TrustCenterDocumentAccessStatusRejected"
)
REVOKED
@goEnum(
value: "go.probo.inc/probo/pkg/coredata.TrustCenterDocumentAccessStatusRevoked"
)
}
type DocumentAccess implements Node {
id: ID!
status: DocumentAccessStatus!
}
extend type Mutation {
requestAllAccesses: RequestAccessesPayload! @session(required: PRESENT) @nda
exportDocumentPDF(input: ExportDocumentPDFInput!): ExportDocumentPDFPayload!
@session(required: OPTIONAL) @nda
exportReportPDF(input: ExportReportPDFInput!): ExportReportPDFPayload!
@session(required: OPTIONAL) @nda
exportTrustCenterFile(
input: ExportTrustCenterFileInput!
): ExportTrustCenterFilePayload! @session(required: OPTIONAL) @nda
requestDocumentAccess(
input: RequestDocumentAccessInput!
): RequestDocumentAccessPayload! @session(required: PRESENT) @nda
requestReportAccess(
input: RequestReportAccessInput!
): RequestReportAccessPayload! @session(required: PRESENT) @nda
requestTrustCenterFileAccess(
input: RequestTrustCenterFileAccessInput!
): RequestFileAccessPayload! @session(required: PRESENT) @nda
}
type RequestDocumentAccessPayload {
document: Document
}
type RequestReportAccessPayload {
audit: Audit
}
type RequestFileAccessPayload {
file: TrustCenterFile
}
type RequestAccessesPayload {
trustCenterAccess: TrustCenterAccess!
}
input ExportDocumentPDFInput {
documentId: ID!
}
input ExportReportPDFInput {
reportId: ID!
}
input RequestDocumentAccessInput {
documentId: ID!
}
input RequestReportAccessInput {
reportId: ID!
}
input RequestTrustCenterFileAccessInput {
trustCenterFileId: ID!
}
input ExportTrustCenterFileInput {
trustCenterFileId: ID!
}
type ExportDocumentPDFPayload {
data: String!
}
type ExportReportPDFPayload {
data: String!
}
type ExportTrustCenterFilePayload {
data: String!
}