Legal and Compliance Workflows
Note: Changes to licenses, copyrights, or notices apply at the organization level, i.e., the new license/copyright/notice will show up on the library in every project/application in which it exists.
Overview
As a Legal Compliance Manager, you may want to easily identify applications and projects with the most critical licensing risks and investigate areas where licenses are unidentified, to ensure the organization’s compliance with licensing requirements efficiently and effectively.
Notable Features
SBOM/Attribution Side Panel
A side panel for SBOM and attribution data allows users to view and navigate detailed legal and compliance information efficiently.License Side Panel
A dedicated side panel for license-related details to improve accessibility and clarity.Comments
Users can add, view, and manage comments within the legal workflow, ensuring efficient collaboration and tracking.
Getting it done
The Legal section is available on the left-pane menu in the context of an Application or a Project:

Three pages are available to you within the Legal section:
OS Inventory - SBOM and Attribution data.
Proprietary - Proprietary licenses only.
Commercial - Commercial licenses only.
The OS Inventory Table
The OS Inventory table provides a comprehensive view of libraries and their associated licenses, copyrights, and dependencies, for efficient management of the open-source inventory.

OS Inventory Columns
Library – Displays the library name. Note that if a library has multiple licenses, they will be grouped together and displayed in the relevant line under the Licenses column.
Project – Displays the project name when viewed at the application level.
Violations - Displays the number of violations related to the library in question.
License Risk – Displays the license risk icon, reflecting the risk category (Low, Medium, High, Unknown, Requires Review) and score.
Licenses – Displays associated licenses.
Direct Libraries – Displays the number of direct libraries associated with this library.
Hovering over the value will spawn a tooltip displaying the names of direct libraries and including a link to open the side panel on the Impact Analysis tab.If the library is direct only, it will be denoted using
-
.If the library is both direct and transitive, its name will be displayed (again) in the tooltip.
Copyrights – Displays available copyrights, with an override option.
Notices – Displays available notices, with an override option.
Language – Displays the programming language of the library.
Dependency – Displays the dependency type (Direct, Transitive, Direct/Transitive).
Author - Displays the library’s author’s name. Hidden by default.
Library Location - Displays the library location path. Hidden by default.
When multiple locations exist, one is displayed in the table while the rest are displayed in the tooltip.

OS Inventory Actions
Multi-Select – Allows users to select multiple libraries using checkboxes.
Assign Licenses – Clicking this action opens the side panel on the License tab.
Assign Copyrights – Clicking this action opens the side panel on the Copyrights tab.
Mark as Proprietary – Not available as a bulk action.
Mark as Commercial – Not available as a bulk action.
Create Report - Clicking the Create Report button (
) at the far right allows you to generate both Dependencies Attribution and Dependencies SBOM reports from this page.
Export to CSV - Clicking the Export to CSV button (
) will export the data to a .CSV file. Note that copyrights and notices are exported as text.