Skip to content

How it works

How a RuleCerta audit works

Predictable, inspectable, and safe for production environments.

  1. 1. Connect an environment

    A workspace can hold several environments — production, test, or one per client. Each environment keeps its own read-only connector credentials, connection status, and audit history so tenant data stays isolated.

  2. 2. Verify the connection

    Before an audit runs, the connection is tested and read access confirmed. Connector credentials are stored encrypted on the server, write-only from the browser, and are never returned to the client UI.

  3. 3. Collect the minimum data

    We request only the configuration required for the audit — workflow rules with their triggers, events, conditions and actions. Least data, least privilege.

  4. 4. Freeze a snapshot

    Each completed audit is stored as an immutable snapshot: environment, rule versions, engine version, coverage, and findings. Historical audits are not rewritten in place.

  5. 5. Analyse deterministically

    Available now: versioned structural rules look for enabled workflows without actions or trigger signals, duplicate names, duplicate content, and unmapped-field coverage context. Coming later: high similarity, shared fields, conflicting target values, overlapping conditions, and cascading potential.

  6. 6. Review, export, repeat

    Findings, relationship map and comparison in the app; a branded PDF for stakeholders; and a history you can diff against the next audit.

Honest audit status

An audit is never shown as complete when it is not. Statuses are explicit. Automatic restoration of a paid audit entitlement after a RuleCerta-side failure is planned with billing — it is not operating today.

Failed
Partial
Completed with warnings
Complete