Policy & Control Explorer
Built-in, workflow- and agent-agnostic governance, as a Pack → Policy → Control tree. A policy is the thin enforcement layer that binds a set of controls; controls no policy binds sit under “without a governing policy” so the full catalog stays reachable. Each control carries a scope — a workflow or agent becomes subject to it when it falls under that scope — plus its framework citations, the enforcing check, and its evidence status (the findings raised against it by in-scope agents). Coverage is a facet of the same graph; counts are computed on read, never authored.