Workflows

Organizational discovery

Add accountable business context, organize evidence sources, resolve contradictions, and publish a versioned context snapshot.

Scanners can observe code, cloud resources, delivery paths, and findings. They cannot safely decide which assets the business considers critical, which data is sensitive, who owns a boundary, or which compliance programs apply. Organizational discovery adds that accountable context without weakening evidence provenance.

How discovery becomes truth

  1. A workspace Analyst, Admin, or Owner starts the discovery profile.
  2. Hyperoru asks the highest-value unanswered question first.
  3. Declared answers become confirmed, immutable field revisions.
  4. Reconciled evidence may propose cloud or technology context, but never confirms it.
  5. Conflicting claims remain visible until a person chooses or corrects the value.
  6. Confirmed fields and source-graph relationships publish into a new workspace context snapshot.

One architecture model

Discovery does not create another system graph. Confirmed context is an input to the existing Hyperoru workspace context and canonical architecture model.

Context fields

The profile covers technology, cloud, infrastructure as code, data sensitivity, critical assets, entrypoints, data stores, important flows, trust boundaries, compensating controls, compliance programs, and ownership.

Each current value exposes:

  • its source and source reference;
  • confidence and observation time;
  • confirmation state;
  • sensitivity and architectural impact;
  • version and evidence identifiers;
  • complete correction and supersession history.

Sensitive values are redacted for Viewer and Developer roles. Evidence-inferred sensitive or high-impact values always require explicit confirmation.

Source groups and dependencies

Registered repositories, uploads, cloud collections, delivery systems, and MCP evidence can be assigned to source groups such as Checkout, Payments, Identity, or Data Platform. A group records its owner, criticality, and trust boundary.

Dependencies connect two groups with an explicit relationship type, evidence identifiers, data classification, and boundary-crossing status. Archiving a group or dependency is reversible and retains its history.

Suggestions and contradictions

Evidence suggestions are fingerprinted against the material evidence revision. Rejecting one suppresses the same idea while evidence remains unchanged. Materially new evidence may resurface it for review.

When a new claim disagrees with the current value, Hyperoru creates a contradiction instead of hiding one side. A declared correction resolves the contradiction by creating a new revision; prior revisions remain inspectable.

Publication gate

Publishing is available only when every required field is confirmed and no contradiction remains open. The resulting context snapshot contains confirmed fields, active source groups, assigned active sources, and confirmed dependencies. It can be replayed by later audits and safely rolled back without deleting discovery history.

Use the generated Discovery API reference for the exact field, group, source, dependency, suggestion, and publication contracts.