Introducing Controls in Kosli

Jul 9, 2026

Defining a control in a policy document is easy. Proving that every build was evaluated against it - and that nothing non-compliant ever reached production - is the hard part.

Kosli's new Controls feature closes that gap. Every control is defined in Kosli, every build is evaluated against it, and deployments are gated automatically when the evidence isn't there.

That means:

Every control decision is recorded as evidence, build by build
Coverage shows exactly where a control is enforced across your environments

Non-compliant artifacts are stopped in the pipeline before they're ever deployed

In this video, Simon Castagna (Software Developer, Kosli) walks through the full lifecycle of a real binary provenance control: how it's defined, how trails are evaluated against a Rego policy, how the new decision attestation records the outcome, and how an SDLC control gate in the release pipeline enforces it.

👉 See how teams define and enforce SDLC controls by default: https://www.kosli.com/secure-sdlc-process-template/

⏱ Video Timeline

00:00 – What this video covers

00:16 – Defining a control: binary provenance

00:37 – Flows, trails, and attestations

01:16 – The new decision attestation

01:42 – The Decisions and Coverage tabs

02:32 – Evaluating a trail against a Rego policy

03:16 – Recording the decision in the build workflow

03:41 – Requiring the control in environment policies

04:07 – Gating deployments with an SDLC control gate

04:41 – Verifying what's running in the environment

🔗 Links

✅ Secure SDLC process template: https://www.kosli.com/secure-sdlc-process-template/
✅ The Control Group - claim your seat: https://www.kosli.com/the-control-group/
✅ Visit Kosli: https://www.kosli.com/

#Kosli #SDLC #DevOps