The question regulators and engineers ask in the same breath: where did this number come from?
CoComply harvests evidence from catalogs, query logs, pipeline configs, code, and BI metadata, then stitches it into a single graph — from system of origin to final consumption, with a confidence score on every edge.
Search any element, walk upstream to origin or downstream to consumption, and inspect the evidence behind any hop.
How the graph is built and kept current: harvesting, stitching, confidence scoring, and the human confirmation queue.
Blast-radius assessment — every downstream report, model, and consumer affected before a change ships.
Catalog and metadata service harvesting.
Warehouse query & job logs — the richest as-executed evidence.
ETL and pipeline configurations.
SQL, Python, and legacy codebases.
BI tool models and definitions.
By reconciling multiple independent evidence sources and routing low-confidence links to humans, CoComply delivers end-to-end lineage that satisfies BCBS 239 and model-risk expectations — and never publishes a weak edge silently.