Skip to main content

Tool

Gemara

An activity-centred GRC model with typed, linkable governance artifacts across definition, activity and measurement layers.

gemara.openssf.org

Where it helps

  • Govern Sensitive Activities

    Places sensitive activities between policy and evaluation so governance evaluates what actors are about to do.

  • Build a Governance Twin

    Provides layered governance semantics and logs that a twin can bind to real resources and activities.

  • Governance is Version Controlled

    Publishes machine-readable schemas so catalogues, policies and logs can live as versioned artefacts.

  • Governance Is Composable

    Supports mappings and layered artefacts so teams compose shared baselines without forking everything.

  • Context In, Decisions Out

    Ties structured evaluation and enforcement logs to explicit requirement and plan ids.

  • Continuous Governance

    Measurement layers (evaluation, enforcement, audit) map continuous posture onto durable records.

  • Evidence by Default

    Evaluation, enforcement and audit logs are first-class evidence artefacts rather than screenshots.