Skip to Content
Welcome to the Novantra documentation.
GuidesGovernanceModulesContinuous Assurance

Continuous Assurance

Continuous Assurance is the workspace module for recording measured assurance over governed sources. It helps teams move from periodic declarations to source-linked evidence, freshness checks, reviewable signals, and approved assurance snapshots.

Use it when a control, policy, obligation, service, supplier, AI system, or operational process needs evidence that can be traced to a source owner without copying raw operational data into the assurance workspace.

What Continuous Assurance Owns

  • Assurance source records that reference manual, connector, file-feed, event-feed, gateway, or source-owner inputs.
  • Evidence rules and freshness or threshold policy snapshots.
  • Collection runs and sanitized collection posture.
  • Normalized observations and measurement records.
  • Assurance signals that can be reviewed or handed off to work, risk, finding, exception, incident, or lifecycle owners.
  • Approved assurance snapshots for audit packages, readiness packs, monitoring, or assurance exchange.

Continuous Assurance does not own connector credentials, source-system jobs, DMS documents, extracted text, vectors, AI prompts, governed indicator truth, governed monitoring truth, posture scoring, audit-package generation, or external reviewer access.

User Journey

  1. Open Governance > Continuous Assurance.
  2. Create an assurance source that points to a source-owner ref, connector ref, manual structured feed, or gateway source.
  3. Define evidence rules that describe what must be measured and how freshness is assessed.
  4. Record collection runs and observations from the source owner or manual evidence process.
  5. Record measurements and review assurance signals.
  6. Approve a sanitized assurance snapshot for downstream use.
  7. Use audit packages, work management, compliance posture, enterprise readiness, regulated monitoring, or assurance exchange to consume the source-owned descriptors.

Decision Receipts

Approved, published, superseded, and retired assurance snapshots hand off sanitized decision receipts to Governance Trace.

The receipt binds the snapshot decision to the snapshot ref, actor/reviewer/ approver refs, outcome, capability state, evidence state, and integrity state. It records whether scope, posture, signal, evidence-freshness, and publication policy snapshots exist, but it does not copy those snapshot payloads into the receipt.

Snapshot Safety

Snapshots are summaries, not raw evidence dumps. They must not include raw documents, source text, prompts, provider responses, embeddings, vectors, storage paths, secrets, credentials, or protected source text.

When a source cannot be measured or prepared, use capability states such as evidence-required, reference-only, policy-blocked, provider-not-configured, deployment-dependent, no-AI profile, or not-configured.

AI Boundary

AI may help explain signals or draft reviewer notes when a deployment profile allows it. Continuous Assurance itself does not execute AI, store prompts, own embeddings, or perform vector retrieval.

AI knowledge preparation and semantic retrieval stay with the content-extraction and AI context owners. This module records the assurance posture and safe refs that those owners can later support.

Cloud And On-Prem

Cloud and on-prem expose the same Continuous Assurance behavior. Provider, connector, AI, and deployment differences must appear as capability states or source-owner evidence refs, not as hidden product gaps.

Do Not Use This Module To Claim

  • A live connector adapter or scheduled collector is running.
  • Raw source documents, logs, prompts, vectors, or provider payloads are disclosed.
  • AI has made a final compliance decision.
  • A breach, legal finding, SLA, certification, or residency claim is automatically proven.
  • Public /api/v1 assurance APIs or external reviewer sessions are available.

Those outcomes require source-owner evidence or separately promoted implementation specs.

Last updated on