Compliance center sidebar link returns 404 error
What does this MR do and why?
The Compliance Center sidebar link (Secure > Compliance Center) navigates users to /-/compliance_center, which returns a 404 error on any new project or group with no compliance framework configured. This is a broken client journey — a user following a primary navigation item in the GitLab UI hits a dead end with no guidance, no empty state, and no recovery path.
Steps to reproduce
- Create a new group on GitLab.com
- Create a new project within that group
- Navigate to Secure > Compliance Center from the left sidebar
- Result:
404 Not Foundat/<group>/<project>/-/compliance_center
Expected vs actual behavior
| Expected | Actual | |
|---|---|---|
| URL | /-/security/compliance_dashboard/standards_adherence |
/-/compliance_center |
| Page | Compliance Center dashboard or empty state | 404 error |
| User guidance | Clear prompt to set up a framework | None |
Impact
- Affects 100% of new projects and groups on first visit
- Disproportionately impacts demos, evaluations, and PoC environments — the highest-value user touchpoints
- Users and SAs assume misconfiguration on their end, degrading trust in the Compliance feature before it has even been evaluated
- The 404 is silent — no error message, no call-to-action, no documentation link
Root cause
The sidebar menu item points to /-/compliance_center instead of /-/security/compliance_dashboard/standards_adherence. There is also no route guard or redirect in place, and no empty state rendered when no compliance framework is associated with the project.
Engineering actions required
This MR is a short-term documentation mitigation. The underlying route bug must be fixed in the application code to fully resolve the broken user journey:
- Fix the sidebar route — update the Compliance Center sidebar link to point to
/-/security/compliance_dashboard/standards_adherence - Add a route guard or redirect — ensure
/-/compliance_centerredirects to the correct path instead of returning 404 - Add an empty state — when no framework is configured, render an actionable empty state with a prompt to import or create a framework, rather than a 404
Files changed
doc/user/compliance/compliance_center/compliance_frameworks_report.md- Fixed navigation steps to reflect group-level access
- Added
NOTEadmonition with correct URL pattern
doc/user/compliance/compliance_center/compliance_projects_report.md- Restored correct prerequisite (Security Manager or Owner role)
- Fixed navigation steps to reflect group-level access
- Added
NOTEadmonition with correct URL pattern
Author's checklist
- Follow the Documentation process.
- Follow the Documentation guidelines.
- Follow the Style Guide.
- Requested review from the Technical Writer assigned to the
group::compliancestage/group.