ADR-015: Python as Connector SDK Language
Python as the primary language for connectors in sv0-connectors
Python as the primary language for connectors in sv0-connectors
Plan to update architecture docs (01-data-model.md, 03-database.md, 05-connectors.md, glossary.md) with Round 3-5 decisions
Plan to consolidate duplicated Azure functionality across the entra-servicenow and azure-foundry connectors (ARM RBAC role resolution, scope parsing, Entra Graph SP lookups, credential type detection) into a shared package.
Unified strategy for moving SecurityV0 from manual scans to autonomous operations with built-in cross-validation, observability, and an Azure VM hosting lane — ahead of the MediaPro pilot.
Implementation cycle plan for shipping SecurityV0 AWS integration across sv0-connectors, sv0-platform, and documentation, based on the March AWS research and competitive analysis.
Per-tenant connector instances, scoped scans, scan history, scheduling — the control plane that replaces today's manual connector invocations.
Interface contract for SecurityV0 connectors following Extract→Transform→Diff→Load pattern
How connectors actually run inside the SecurityV0 platform — VM topology, credential delivery chain (1Password → Key Vault → Managed Identity → VM env → broker → subprocess), scheduler/driver path, tenant isolation invariants, and failure topology. Complements 05-connectors.md (interface contract) with the runtime/infra view.
Detailed phased plan to create a new core SecurityV0 repository from updated architecture docs, incorporating P0/P1 evidence-grade decisions and lessons from the graph-mongo draft
Survey of how enterprise security platforms (Wiz, Orca, Datadog) onboard customer cloud + SaaS environments without long-lived shared secrets, paired with foundational cloud-provider federation patterns (AWS cross-account + external-ID, AWS IAM Roles Anywhere, AWS OIDC, Azure multi-tenant app + admin consent, Azure WIF, GCP WIF, GitHub App). Drives a per-connector credential-strategy recommendation for SecurityV0.
Honest per-connector accounting of how SecurityV0 derives execution counts, where those numbers match ground truth, and where they don't.
Integration reference and test scenarios for SecurityV0 source systems
Jira integration reference for SecurityV0 — Microsoft + Jira NHI access chain discovery
Where and how to integrate LLM models into SecurityV0 — connector classification, platform narratives, architectural model choices, and deterministic fallback strategy.
Research on Microsoft + Jira NHI access chains for MediaPro prospect technical evaluation
End-to-end implementation plan combining connector control, multi-account AWS, cross-connector graph stitching, and MediaPro Lab 2 demo — the architecture work that closes the half-stitched-graph problem and gates the early-May MediaPro pilot.
Static repo cross-check of current sv0-platform and sv0-connectors implementation against docs/architecture. Identifies aligned docs, stale docs, and undocumented shipped capabilities.
SecurityV0 infrastructure strategy: AWS credits, connector automation, AWS Organization account structure, budget protection, demo lab environments, and phased migration plan from Hetzner.
System-level architecture defining services, data flow, deployment topology, and security boundaries
ServiceNow connector authentication guide — OAuth 2.0 Client Credentials (recommended) and API key options with tradeoffs
Bridge document between what connectors discover and what the platform stores and evaluates. Read this before setting up a dev environment, debugging connector output, or explaining the system to a non-developer.
Wiz integration strategy analysis — connector breadth, code access question, NHI gaps, and SV0 competitive positioning recommendations.