Docs / ANALYSIS ENGINES
ANALYSIS ENGINES
Policy Engine
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
The Policy Engine decides which findings should block a CI/CD pipeline, which should warn , and which to ignore - based on a federated baseline plus your organization's overrides. It outputs proper CI exit codes and standard-format reports.
Verdicts
Each verdict carries a citation to the rule or standard that produced it (e.g. "NIST SP 800-131A § 8.2") so reviewers can verify the decision.
| Verdict | Meaning | CI behavior |
|---|---|---|
| BLOCK | This finding violates a hard rule. | CI fails (exit 1). |
| WARN | Finding noted, but not blocking. | CI passes with annotation. |
| ALLOW | Finding falls within the policy. | CI passes silently. |
| AUDIT | Finding noted for periodic review. | CI passes; appears in audit summary. |
Built-in Profiles
Profiles are a property of the policy file, not a CLI setting. There is no command to switch or print the active profile - the CLI exposes exactly two policy subcommands, enforce and evaluate . Select a profile by editing the policy file and passing it with --policy .
| Profile | Use case |
|---|---|
| strict | Anything below recommended status raises BLOCK. For greenfield projects + regulated industries. |
| balanced | Default. Deprecated raises BLOCK; acceptable raises WARN; exemptions allowed. |
| legacy | Only disallowed primitives BLOCK; deprecated WARN; for brownfield migrations. |
Scan Modes
# Evaluate a report against the policy, machine-readable korthex policy evaluate --report report.krx --format sarif # Enforce it: exit 1 when the policy is violated korthex policy enforce --report report.krx --fail-on-violation policy enforce takes a report via --report , not a directory, and it has no mode selector: --mode , --base-ref and --baseline do not exist on it. The three scopes above are properties of the policy evaluation, not flags you pass here. To gate a PR on changed files only, use korthex check . --since-ref origin/main ; to gate on new findings only, use korthex check . --baseline <file> . Policy commands require an Enterprise license. Exit codes: 0 clean, 1 violations, 31 report unreadable, 32 no policy loaded, 41 policy file unusable. --threshold is declared but not honoured - set ci_fail_on in the policy file instead.
| Mode | Effect |
|---|---|
| full | Evaluate every finding in the report against policy. |
| changed | Only findings touched by the current diff (best for PR gates). |
| baseline | Only findings new since the saved baseline (best for incremental migration). |
CI Output Formats
Policy enforcement emits in formats CI platforms consume natively:
| Format | Integration |
|---|---|
| SARIF | GitHub Code Scanning, Azure DevOps, GitLab. Findings show up inline on the PR diff. |
| JUnit XML | Generic CI runners. Each violation becomes a failed test case. |
| JSON | Custom integrations and bot workflows. |
| TEXT | Human-readable summary for terminals + Slack notifications. |