Skip to content

One canonical roadmap, so the work stops drifting between five lanes - #19

Merged
itcmsgr merged 1 commit into
mainfrom
docs/canonical-roadmap
Sep 20, 2026
Merged

itcmsgr merged 1 commit into
mainfrom
docs/canonical-roadmap

Conversation

@itcmsgr

@itcmsgr itcmsgr commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Documentation only. One file, 77 lines added, no code and no gate changes.

The roadmap described the right things but had no spine, so "release work", "report work", "controls", "ARM" and "frameworks" kept competing for the same slot as though only one could proceed. They are three independent tracks and a phase order, and conflating them has cost more time than any of the work itself.

Owner decision, 2026-09-20, recorded as the single authoritative reading:

Phase State
0 Technical preview foundation IMPLEMENTED
1 Reproducible example report now closed — IQ-011
2 W1-D host assurance collection PLANNED
3 Native ISE-* control catalog PLANNED
4 Findings report PLANNED
5 Approved baseline and classified delta PLANNED
6 Platform expansion PLANNED
7 Generic mapping engine FUTURE
8 Mode B — validated open mappings FUTURE
9 Mode C — provider-authorized BYOL FUTURE

Two things this fixes beyond ordering.

The alpha's goal is stated plainly: prove the engine, packaging, deterministic semantics and release process are sound enough to build an assurance layer on. It is not to complete assurance content. Measured against assurance breadth, a technical preview would fail for the wrong reason.

The report is no longer described as absent. Four milestones separate what exists from what does not — R0 evidence report works today, R1 is the reproducible public sample, R2 adds native findings, R3 adds baseline and delta. The reporting engine is not what is missing; the assurance intelligence is.

No duration is frozen. An estimate produced before a single domain has been built is a guess wearing a schedule's clothing, and this repository does not publish confidence the evidence has not earned. The method is recorded instead: build the first two domains, measure the real cost of collector plus fixtures plus criterion plus renderer plus falsification, then re-estimate the rest from observed velocity.

No architecture decision is taken here. An amendment follows implementation evidence, never the reverse.

The roadmap described the right things but had no spine, so "release work",
"report work", "controls", "ARM" and "frameworks" kept competing for the same
slot as though only one could proceed. They are three independent tracks and a
phase order, and conflating them has cost more time than any of the work itself.

Owner decision, 2026-09-20, recorded as the single authoritative reading:

  Phase 0  technical preview foundation            IMPLEMENTED
  Phase 1  reproducible example report             PLANNED, closes IQ-011
  Phase 2  W1-D host assurance collection          PLANNED, ten control domains
  Phase 3  native ISE-* control catalog            PLANNED
  Phase 4  findings report                         PLANNED, first customer-useful output
  Phase 5  approved baseline and classified delta  PLANNED
  Phase 6  platform expansion                      PLANNED
  Phase 7  generic mapping engine                  FUTURE
  Phase 8  Mode B verified open mappings           FUTURE
  Phase 9  Mode C provider-authorized BYOL         FUTURE

Two things this fixes beyond ordering.

The alpha's goal is stated plainly: prove the engine, packaging, deterministic
semantics and release process are sound enough to build an assurance layer on.
It is not to complete assurance content. Measured against assurance breadth the
technical preview would fail for the wrong reason.

And the report is no longer described as absent. Four milestones separate what
exists from what does not: R0 evidence report works today, R1 is a reproducible
public sample, R2 adds native findings, R3 adds baseline and delta. The
reporting engine is not what is missing; the assurance intelligence is.

No duration is frozen. An estimate produced before a single domain has been
built is a guess wearing a schedule's clothing, and this repository does not
publish confidence the evidence has not earned. The method is recorded instead:
build the first two domains, measure the real cost of collector plus fixtures
plus criterion plus renderer plus falsification, then re-estimate the rest from
observed velocity.

No architecture decision is taken here. An amendment follows implementation
evidence, never the reverse.

Implements: D-65, D-66, D-82, D-88
Assisted-by: Claude (drafting from the owner's canonical roadmap)
@itcmsgr
itcmsgr merged commit 1362dcd into main Sep 20, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant