Skip to Content
Welcome to the Novantra documentation.

Sources

The Sources module records the source truth your organization wants to govern: regulators, standards bodies, internal policy owners, laws, circulars, standards, guidance, and their versions.

Sources are tenant-owned. Novantra does not hardcode which authorities, source categories, jurisdictions, or frameworks matter to you. Framework catalogs and integrations can help create records, but your workspace owns the resulting source records and reviews their impact.

When you would reach for this

Use Sources when:

  • A new law, circular, standard, guideline, or internal policy version needs to be tracked.
  • Your team needs an auditable record of where a framework, obligation, control change, or compliance decision came from.
  • An external monitor or integration detects official-source updates and submits them to Novantra.
  • You need to preserve source provenance, dates, trust labels, classification, rights, and import receipts before downstream governance work begins.

Do not use Sources to decide compliance by itself. Applicability, obligations, controls, evidence requirements, posture, work assignments, and exports remain separate governed workflows.

What lives in Sources

Three main source records build on each other:

  1. Authority - the issuer or owner of a source. This can be a regulator, standards body, internal policy owner, customer-defined committee, or any tenant-defined authority.
  2. Source item - the source being tracked, such as a law, circular, standard, guidance document, internal policy, or another tenant-defined source type.
  3. Source version - a specific version or publication instance with dates, status, URL/reference information, provenance, classification, rights posture, and optional hash evidence.

Imports also create import batches and import receipts. These show when source updates were received from public API, catalog, spreadsheet, or manual import paths and which source records were accepted or reused.

What the imports tab means

The Imports tab is read-only. It helps compliance and governance teams verify that an integration or catalog import created a source record and returned a receipt.

An import receipt does not mean the source has been applied to your compliance program. It means Novantra accepted or reused the source record. Your team still reviews applicability and downstream impact.

Typical workflow

  1. Create or import the source authority.
  2. Create or import the source item.
  3. Add the source version with effective dates, status, source URL/reference, and any available provenance.
  4. Review the source in the workspace.
  5. If a newer version replaces an older one, mark the old version as superseded and choose the replacement version. The old record remains visible for history.
  6. Archive a version only when it should no longer be active for future selection, while still preserving audit history.
  7. Decide whether the change affects framework applicability, obligations, controls, evidence, posture, work assignments, exports, or AI indexing.

Keep protected full-text content, secrets, credentials, and private access URLs out of source metadata. Store documents through the approved document or artifact workflows when your organization is allowed to keep the content.

External source monitoring

If your organization monitors official sites or legal feeds outside Novantra, a scoped service account can submit source updates through the public API. See Sources API reference.

Downstream review

Source lifecycle changes can create downstream review signals. For example, a new, archived, or superseded source version may appear in Regulatory Register triage, Compliance Posture signal snapshots, Work Management, or Audit Packages depending on which modules are enabled and how your workspace has configured them.

Last updated on