Governance in WeProject.ai
Capabilities
Decision log
Decisions are recorded with their rationale and remain readable later.
Audit trail
Changes to project records are recorded with who made them and when.
Project access control
Access is controlled per project and per role.
Standards and compliance
Requirements can be assessed against named standards.
Evidence
- Declared in apps/data-domain/seed-data/product-capabilities.json
- Resolved by apps/data-domain/scripts/check-alignment-registry.mjs
- Implemented in apps/frontend/src/views/EnhancedRequirements.tsx
- Implemented in apps/frontend/src/views/Baselines.tsx
- Implemented in apps/frontend/src/views/Decompositions.tsx
- Implemented in apps/frontend/src/views/Budgets.tsx
- Implemented in apps/frontend/src/views/AuditLog.tsx
- Implemented in apps/backend/services/ExportService.js
Security
Running with no outbound connection
The model provider is a configuration choice · Reference data ships with the deployment, not copied into each app · The data stores are yours
Identity and access
One session, verified by every product · Multi-factor authentication · Revocation is checked when a session is used, not only when it is issued · Redirects are allowlisted · Permission resolves on role AND calling application
How the software is kept honest
Dependency vulnerabilities fail the build · A measured quality position, published with its coverage · The marketing claims on this site are gated