As a compliance analyst I want the scanner to pull controls from the breakpilot-compliance Qdrant RAG (300k+ atomic controls, ~400 laws) and use
them as tools so that findings map to real regulatory controls and new
findings are revealed.
Part of #186. Implements the #136ControlsProvider seam.
Acceptance criteria
A ControlsProvider backed by the breakpilot-compliance Qdrant RAG,
queryable by framework / jurisdiction / context.
Retrieved controls exposed as tools/checks that can surface additional
findings and map existing findings → controls.
Pluggable (built-in OSCAL default when the tenant lacks the RAG).
**As a** compliance analyst **I want** the scanner to pull controls from the
**breakpilot-compliance Qdrant RAG** (300k+ atomic controls, ~400 laws) and use
them as tools **so that** findings map to real regulatory controls and new
findings are revealed.
Part of #186. Implements the #136 `ControlsProvider` seam.
## Acceptance criteria
- [ ] A `ControlsProvider` backed by the breakpilot-compliance Qdrant RAG,
queryable by framework / jurisdiction / context.
- [ ] Retrieved controls exposed as tools/checks that can surface additional
findings and map existing findings → controls.
- [ ] Pluggable (built-in OSCAL default when the tenant lacks the RAG).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
As a compliance analyst I want the scanner to pull controls from the
breakpilot-compliance Qdrant RAG (300k+ atomic controls, ~400 laws) and use
them as tools so that findings map to real regulatory controls and new
findings are revealed.
Part of #186. Implements the #136
ControlsProviderseam.Acceptance criteria
ControlsProviderbacked by the breakpilot-compliance Qdrant RAG,queryable by framework / jurisdiction / context.
findings and map existing findings → controls.