Publication gates

Use publication gates to confirm evidence, scope, privacy and legal boundaries before enabling public reports, PDF export or external sharing.

Business owners, developers and reviewers

Feature availability

Product, package, provider and deployment boundaries for this page.

Available from
Current documentation
Deployment modes
cloud

Before checking gates

Use this page before a private report becomes a public link, printable view, PDF export or external client handoff. Publication gates protect customers from sharing incomplete evidence, unsupported scope, unsafe screenshots or wording that overstates what WebRiskOps proves. Publication is not a manual approval queue. The product should show the blocked reason and the next automated action: fix evidence, review scope, redact data, complete false-positive review or keep the report private.

Check publication gates

Follow the path `Reports → Private report → Quality gates → Publication state → Public report or export`.

  1. Open /reports/{report} after issue evidence and false-positive review are complete. Result: the private report shows publication state, quality gate summary and any blocked reason.
  2. Read each Quality gate before using public sharing, print or PDF actions. Result: evidence, scope, confidence, redaction and legal-boundary blockers are visible.
  3. Open blocked gate details when Can publish is No or the state is Blocked. Result: the reason code shows what to fix or review before sharing.
  4. Resolve missing evidence, unsupported scope, low confidence or false-positive review before publishing. Result: public output does not include incomplete or unsupported claims.
  5. Confirm public report wording and legal boundary before sharing externally. Result: report copy explains evidence limits without claiming certification or a compliance guarantee.
  6. Continue only when gates show Ready for publish. Result: public report links, print and PDF actions use customer-safe report data.

Gate states and next actions

Use the gate state to decide what can safely happen next.

  • Ready for publish means public report, print and PDF actions may be used for the current report state.
  • Blocked means at least one required evidence, scope, privacy or legal-boundary gate failed and sharing must stay private.
  • Draft private report means the report exists for internal review but public output is not enabled yet.
  • Published means the public tokenized report is available; review expiry and sharing settings before sending the link.
  • Disabled public sharing means the report can remain published internally while public access is intentionally off.

Blocked publication states

Resolve blocked gates in the private workflow before sharing outside the workspace.

  • Evidence incomplete means continue to [Evidence, screenshots and artifacts](/docs/reports/evidence-screenshots-and-artifacts) and fix missing proof before publication.
  • False-positive review required means continue to [False-positive review](/docs/reports/false-positive-review) and keep uncertain findings private.
  • Unsupported scope means do not publish claims about pages, domains or authenticated surfaces outside the accepted scan scope.
  • Privacy or secret risk means use [Privacy redaction](/docs/projects/privacy-redaction) before public report, print or PDF output.
  • Legal boundary missing means use [Legal boundary wording](/docs/reports/legal-boundary-wording) before sharing reports that customers may read as certification or legal advice.

Continue to public reports

Continue to [Public reports](/docs/reports/public-reports) only when the gates are ready. Use [PDF and print export](/docs/reports/pdf-and-print-export) for export behavior, and keep blocked reports private until the exact gate reason is resolved.

Related documentation

Was this page helpful?

Feedback goes into the product documentation review queue.