Appearance
OrviQ 1.1 Release Notes
Release Date: September 2026
Release Tag: integration/policy-governance-bank-ready
Commit Baseline: d32bcfa403739f2d6bcd8c3782cf6fbd3d4b6ff4
We are pleased to announce the release of OrviQ 1.1, delivering comprehensive Enterprise Policy Governance, the certified Content 2.0 regulatory corpus, operationalization and bi-directional traceability, the self-service Employee Policy Portal, native Security Tool Integrations, and automated Cloud & Identity Discovery.
1. Enterprise Policy Governance & Content 2.0
Authoritative Content 2.0 Corpus
OrviQ 1.1 introduces an institutional-grade governance library designed for regulated financial institutions and global enterprises:
- 110 Unique Governance Instruments: Covering institutional governance charters, statutory policies, supervisory codes, and board terms of reference (
DOC-2026-0001throughDOC-2026-0110). - 518 Structured Sections & 1,058 Atomic Statements: Decomposed into granular, single-obligation governance statements for precise mapping and tracking.
- 25 Pending Substantiation Statements: Identified clauses requiring tenant-specific operational parameterization.
- 5 Certified Domain Packs (190 total memberships):
ORV-PACK-CORE: OrviQ Core Governance Library (103 memberships)ORV-PACK-BANKING: Commercial Banking & Risk Governance Pack (37 memberships)ORV-PACK-SBP: Pakistan / State Bank of Pakistan Governance Pack (38 memberships)ORV-PACK-ISLAMIC: Islamic Banking & Shariah Governance Pack (7 memberships)ORV-PACK-PAYMENTS: Digital Payments & Financial Infrastructure Pack (5 memberships)
Content Library (/governance/packs)
- Browse, inspect, and adopt certified governance packs into the internal Policy Register via
policy_pack.adopt. - Decoupled Lifecycle: Adopted policies become tenant-owned records in status
draft. Disabling thecontent_libraryentitlement prevents new catalog adoptions but preserves all previously adopted policies and operational mappings. - Semantic Doctrine: Adopting Content 2.0 governance packs creates internal draft text; Adoption != compliance.
2. Policy Assessments (Upload & Assess)
- Route:
/governance/assessments(permissions:policy_assessment.run,policy_assessment.review). - Deterministic Pipeline: Upload legacy policy documents (
.pdf,.docx,.txt) or select existing internal versions, extract structured text segments, and compare against immutable target expectation snapshots. - Human-in-the-Loop Adjudication: Review candidate alignments by submitting decisions (
accept,reject,modify,reopen) that transition stored mapping states (manual,ai_suggested,accepted,rejected). - Policy Assessment Lifecycle: Assessments move through canonical states
draft$\rightarrow$extracted$\rightarrow$in_review$\rightarrow$completed. - Policy Coverage Scoring: Deterministically computes stored results (
unassessed,addressed,partially_addressed,missing,not_applicable) and aggregate Policy Coverage %. Coverage measures textual alignment; Coverage != compliance. - Immutable Freezing: Completed assessments freeze evaluated snapshots and route identified deficiencies directly to the Gap Workbench.
3. Policy Gap Workbench
- Route:
/governance/gaps(permissions:policy.read,policy.write). - Deficiency Lifecycle: Deterministic tracking across 8 lifecycle states (
open$\rightarrow$in_remediation$\rightarrow$ready_for_validation$\rightarrow$closed, with branch statesdeferred,accepted_risk,not_applicable,cancelled). - 12 Remediation Pathways: Direct actions including statement amendments, adding sections, drafting new policies, adopting Content 2.0 templates, dispatching engineering action plans (
ACT-), linking operational risks (RSK-), or requesting governed exceptions (EXC-). - Independent Validation Before Closure: Completing a remediation action transitions a gap to
ready_for_validation. Formal gap closure requires independent validation before gap closure; completing a task does not automatically close a deficiency, and Gap closure != compliance determination.
4. Policy Operationalization & Traceability
- Routes: Global view at
/governance/operationalization; scoped view at/governance/policy/:pid/operationalization(permission:policy.operationalize). - Atomic Statement Model: Decomposes policies into atomic units (
PST-YYYY-NNNN), eliminating coarse document-level assertions. - 10 Operational Target Types: Maps statements to Controls (
CTL-), Requirements (REQ-), Evidence Expectations, Risks (RSK-), Owners, Scopes/Assets (SCP-/AST-), Tasks (ACT-), Metrics (IND-), Findings (FND-), and Exceptions (EXC-). - Operationalization Vocabulary: Formal status derivation (
NOT_MAPPED,PARTIALLY_OPERATIONALIZED,OPERATIONALIZED,GAP_IDENTIFIED). - Bi-directional Traceability: Full lineage traversing forward from regulations down to telemetry, and reverse from technical observations up to executive policy. Traceability != compliance/effectiveness.
5. Horizon Regulatory & Content Change Impact
- Route:
/governance/change-impact(permissions:change_impact.assess,change_impact.approve). - Change Event Intake (
CHG-): Ingests regulatory circulars and Content 2.0 version updates. - Automated Candidate Discovery: Identifies potentially affected downstream policies, statements, controls, and risks.
- Maker-Checker Segregation of Duties: Assessor formulates impact determinations (
review_required,no_impact,impact_confirmed); independent reviewer approves (assessor_id != reviewer_id). - Non-Destructive Triage: Regulatory changes alert and queue reviews; they never silently alter published policy text or downgrade compliance determinations without human governance.
6. Governed Policy Exceptions
- Route:
/governance/exceptions(permissions:exception.create,exception.approve). - Time-Bound Deviations (
EXC-): Governs temporary deviations with mandatory compensating control evaluations and renewal cadences. - Two-Tier Status Model: Distinguishes raw persisted database states (
draft,requested,in_review,approved,active,rejected,cancelled,closed) from dynamic derived UI badges (DRAFT,SUBMITTED,UNDER_REVIEW,APPROVED,ACTIVE,DUE_FOR_REVIEW,EXPIRING,EXPIRED,CLOSED,REJECTED,CANCELLED). - Non-Satisfaction Invariant: An active policy exception acknowledges an accepted temporary deviation; it never modifies source policy text, never closes policy gaps, and never marks controls effective.
7. Employee Policy Portal ("My Policies")
- Route:
/my-policies(permission:policy.attest). - Self-Service Experience: Purpose-built reading surface for staff members to review assigned corporate policies.
- Version-Pinned Attestation: Employees read and acknowledge the exact published version pinned to their campaign.
- Reading Verification: Opening a policy logs an immutable
opened_attimestamp; opened != acknowledged. - First-Class Declinations: Employees may submit Acknowledge or Decline with a mandatory reason note, providing valuable operational feedback to compliance teams.
- Attestation Doctrine: Attestations provide legal evidence of awareness; Attestation != control effectiveness/compliance.
8. Integration Architecture & Security Tool Telemetry
Integration Catalogue (/integrations/catalogue)
- Read-only directory providing transparent disclosure of 22 catalogued integrations:
- 20 Available Integrations: Operational integrations using declared methods in code (including
native,push,csv):- Security Scanners: Tenable Security Center, Tenable Nessus, Titania Nipper, Qualys VMDR, Prowler
- Cloud & Infrastructure: Microsoft Entra ID, Microsoft Azure, AWS
- Collaboration & Notifications: Slack, Microsoft Teams, Email (SMTP), Webhook, In-App Notifications
- ITSM & Issue Tracking: Jira Software, ServiceNow
- Identity & Workforce: Okta, Google Workspace
- Evidence & Document Storage: Google Drive, Microsoft OneDrive, Amazon S3
- 2 Planned Integrations: Splunk and Microsoft Sentinel (catalogue-only entries in current release; method: push; not operational).
- 20 Available Integrations: Operational integrations using declared methods in code (including
- Entitlement:
integrations_catalogue.
Security Tool Integrations (/integrations/security-tools)
- Native API collectors and file report parsers (
.nessus, Tenable CSV, Titania Nipper XML/CSV/JSON). - Maker-checker import confirmation (
integration.import/integration.confirm). - Entitlement:
integrations_security_tools(ships dark when disabled).
Cloud & Identity Discovery (/integrations/discovery)
- Automated inventory and configuration check ingestion from Microsoft Entra ID, Microsoft Azure, AWS, and Prowler.
- Entitlement:
cloud_discovery(ships dark when disabled).
Scanner & Discovery Provenance into Assets and Findings
- Discovered Assets (
AST-): Discovered hosts and resources flow into the Asset Inventory with sensor ID and discovery timestamps, subject to human review (asset.discovery_review). - Scanner Findings (
SFN-YYYY-NNNN): Ingested vulnerabilities and configuration deviations create technical scanner findings (SFN-) with immutable scanner metadata (source_scanner,scanner_rule_id, CVSS vectors). Through governed triage and promotion, an SFN is promoted to a formal compliance finding (FND-YYYY-NNNN) for action plan remediation or risk acceptance ($\text{SFN} \longrightarrow \text{governed triage/promotion} \longrightarrow \text{FND}$).
9. Platform Entitlements Summary
| Entitlement Key | Description | Ship-Dark Behavior |
|---|---|---|
policy_governance | Core Policy Register, lifecycle, operationalization, assessments, and gaps | Standard navigation gate |
content_library | Access to Content 2.0 catalog and adoption engine | Access gate; adopted policies remain intact if disabled |
content_pack_core | Access to OrviQ Core Governance Library | Granular pack gate |
content_pack_banking | Access to Commercial Banking & Risk Governance Pack | Granular pack gate |
integrations_security_tools | Native scanner connections and report imports | Ships dark when disabled |
cloud_discovery | Automated cloud resource & identity discovery | Ships dark when disabled |
integrations_catalogue | Read-only directory of 22 integrations | Entitlement gated |
api_access | Administrative API keys and inbound/outbound webhooks | Settings gate |