Compliance center sidebar link returns 404 error

What does this MR do and why?

The Compliance Center sidebar link (Secure > Compliance Center) navigates users to /-/compliance_center, which returns a 404 error on any new project or group with no compliance framework configured. This is a broken client journey — a user following a primary navigation item in the GitLab UI hits a dead end with no guidance, no empty state, and no recovery path.


Steps to reproduce

  1. Create a new group on GitLab.com
  2. Create a new project within that group
  3. Navigate to Secure > Compliance Center from the left sidebar
  4. Result: 404 Not Found at /<group>/<project>/-/compliance_center

Expected vs actual behavior

Expected Actual
URL /-/security/compliance_dashboard/standards_adherence /-/compliance_center
Page Compliance Center dashboard or empty state 404 error
User guidance Clear prompt to set up a framework None

Impact

  • Affects 100% of new projects and groups on first visit
  • Disproportionately impacts demos, evaluations, and PoC environments — the highest-value user touchpoints
  • Users and SAs assume misconfiguration on their end, degrading trust in the Compliance feature before it has even been evaluated
  • The 404 is silent — no error message, no call-to-action, no documentation link

Root cause

The sidebar menu item points to /-/compliance_center instead of /-/security/compliance_dashboard/standards_adherence. There is also no route guard or redirect in place, and no empty state rendered when no compliance framework is associated with the project.


Engineering actions required

This MR is a short-term documentation mitigation. The underlying route bug must be fixed in the application code to fully resolve the broken user journey:

  • Fix the sidebar route — update the Compliance Center sidebar link to point to /-/security/compliance_dashboard/standards_adherence
  • Add a route guard or redirect — ensure /-/compliance_center redirects to the correct path instead of returning 404
  • Add an empty state — when no framework is configured, render an actionable empty state with a prompt to import or create a framework, rather than a 404

Files changed

  • doc/user/compliance/compliance_center/compliance_frameworks_report.md
    • Fixed navigation steps to reflect group-level access
    • Added NOTE admonition with correct URL pattern
  • doc/user/compliance/compliance_center/compliance_projects_report.md
    • Restored correct prerequisite (Security Manager or Owner role)
    • Fixed navigation steps to reflect group-level access
    • Added NOTE admonition with correct URL pattern

Author's checklist

Edited by Shashank Chinchli

Merge request reports

Loading
Loading