Compliance Workflow Templates
Pre-built workflow patterns for common regulated use cases. Each template demonstrates how Boruna’s evidence bundle, capability policy, and approval gate features satisfy specific compliance requirements.
| Template | Standard | Key Feature |
|---|---|---|
soc2_audit_workflow | SOC 2 | Hash-chained evidence bundle as tamper-evident audit trail |
hipaa_data_pipeline | HIPAA | PHI redaction before evidence bundle write |
financial_review_pipeline | SOX / dual-control | Multi-approver approval gates with immutable sign-off record |
How to use
- Copy the template to your project
- Replace synthetic data with real capability calls (e.g.,
net.fetchfor live system data) - Run with
--recordto produce a verifiable evidence bundle:boruna workflow run examples/compliance/soc2_audit_workflow --policy allow-all --record boruna evidence verify <bundle-dir> - The verified bundle is your compliance artifact
Customisation
Each template README describes which steps to modify for your environment.
Real integrations typically replace the gather_* or receive_* first step
with a capability call to fetch live data.