# Advanced Legal Pack Quickstart

## Using the Advanced Legal Pack

Log in to Sonatype Lifecycle or Sonatype SBOM Manager and select **Legal** from the navigation menu. Use the _Legal Obligations_ page to manage your legal obligations and attributions.

You can manage your legal obligations and attributions from this page.

The _Applications_ tab contains a list of all applications detected during the last scan. The _Components_ tab contains all components used by every application scanned by the Sonatype IQ Server.

From here, you will be able to manage your legal obligations and attributions via the _Legal Backlog_. The _Legal Backlog_ provides a list of your applications with information on the last scan, application categories, and the components reviewed.

On the _Applications_ tab, you'll see a list of every application known by your IQ Server. Use the _Filter_ button at the top right to narrow your results by organization, application, application category, stage, or review progress. Clicking the _Create Attribution Report_ will create an attribution report for all the applications currently filtered for.

On the _Components_ tab, you'll see a list of every component in every application known by the IQ Server. Like before, use the _Filter_ button at the top right to narrow your results by organization, application, application category, stage, or review progress.

|     |
| --- |
|  |

Selecting an application from the _Applications_ tab takes you to the _Application Legal Details_ page. Here, you will see a list of all components in that application, and view details on their licenses, completed obligations, and review status. This is also where you can create an _Attribution Report_ for just the selected application.

Click on the _Create Attribution Report_ as shown below.

**Note**

The report generation time for _Attribution Reports_ could be longer for a large number of applications or components. We estimate a response time of 1 minute for generation of attribution reports for around 1000 components. For environments using reverse proxy, we recommend increasing the reverse proxy timeout to generate _Attribution Reports_ for a large number of applications or components.

Refer to [License Legal REST API](https://help.sonatype.com/en/license-legal-rest-api.html "License Legal REST API") for more information on _Attribution Report_ templates and other customizations.

|     |
| --- |
|  |

Selecting a component from the _Applications Legal Details_ page or the _Components_ tab of the _Legal Backlog_ takes you to the _Component License Details_ page. The top portion of the screen gives you an overview of your review progress and other license details. The remainder of the screen is where you will review your license obligations, and add or edit copyright statements, notice texts, license texts, and attributions.

|     |
| --- |
|  |

## Example Workflows with the ALP

Most legal teams don’t currently have a tool to support their work and rely on manual processes to manage compliance and licensing. The ALP automates and reduces these manual, time-consuming tasks. See below for some examples:

| Scenario | Lifecycle Workflow | ALP Workflow |
| --- | --- | --- |
| As a **release manager/legal reviewer**, I’m being asked to provide an attribution report meeting the obligations of our OSS dependencies. | 1. Export raw legal data out of Lifecycle as a CSV.<br>2. Spend upwards of 60 hours collecting data for a single application. | 1. Automatically collect the required legal data<br>2. Edit that data, as needed<br>3. Use a form to generate an attribution report |
| As a **legal reviewer**, I’m being asked by a third-party organization to provide extended legal data about components my development teams would like to use for approval. | No Lifecycle workflow. Alternative: Download the component and use Grep, or a third-party tool, to try and collect the data. | 1. Select a component from the list of obligations<br>2. Export the extended legal data |
| As a **legal reviewer**, I would like more information about components with a Non-Declared, See-License, or Non-Standard license detection. | No Lifecycle workflow Alternative: Download the component and use Grep, or a third-party tool, to try and collect the data. | 1. Select a component from the list of obligations<br>2. Check the extended legal data for potential detections that Lifecycle is not able to perform |

## License Obligations

On the left side, each type of legal obligation is color-coded for easy reference. When you click one of these color-coded items, the view automatically scrolls to the corresponding section of the license text on the right. This makes it quick and straightforward to see exactly where each obligation appears in the full license.

## Search results

No results found.
