FEEDBACK LOOP — SAST, SCA and quality findings, cloud posture alerts and SOC detections return to PLAN and CODE, and revise the golden pipeline that let them through
Lanes show who or what performs the step. The eight pipeline gates appear as gateways, each tagged with its gate number so it ties back to the operating model tab. Where a shape maps to a control, the panel below offers a link straight to its detail.
From a change being raised to a conformant service running in the cloud, with every security gate shown where it actually sits. Five lanes carry the work: the delivery team, source control, the CI/CD orchestrator, the security tooling, and the cloud platform. Two pools beneath show where the process leaves the pipeline — to the Security Architecture tower for an exception or a risk position, and to the Security Operations tower for detection.
Gateways marked G1 to G8 correspond to the pipeline gates on the operating model tab. Blocking outcomes are shown in red on the flow labels.
Every branch is an AND gate, so a weak child pulls its parent down — which is why a composite box takes the score of its weakest dependency rather than the product of all of them. Select any box for its detail, or hover to highlight what it connects to. Availability figures are an illustrative opening position for a baselining conversation, not an assessment.