06 — UI & Reporting Architecture
Web UI architecture for SecurityV0 — page specifications for 9-type entity model, component architecture, data fetching patterns, evidence pack rendering, execution chain views, and export capabili...
Web UI architecture for SecurityV0 — page specifications for 9-type entity model, component architecture, data fetching patterns, evidence pack rendering, execution chain views, and export capabili...
Sprint priority #2 plan: surface drift signals in a governance-conditions card (Status / Condition / Evidence) at both authority-path and cluster levels, extending the G3 backend with the Notion-spec card format.
Plan to wire execution evidence end-to-end: surface stored execution_evidence nodes via API + UI drilldown, and convert dangling ServiceNow execution refs into first-class evidence entities.
Consolidated implementation plan for Exposure Aggregation APIs (G1), Remediation Content Generation (G2), and Scope Drift UX (G3)
Canonical definitions for SecurityV0 domain terminology — NHI, execution chains, entity types (identity, workload, connection, credential, owner), relationship types (RUNS_AS, CALLS, INVOKES, USES,...
W1 Gap 2 plan: replace static one-size-fits-all remediation strings in evidence packs with context-aware content that names entities, roles, resources, sensitivity levels, and source systems.
Primary test scenario demonstrating orphaned ownership detection
W1 Gap 3 plan: enrich the scope-drift Finding Detail page so it tells the 'so what' story (which roles were added, what they grant, what changed) rather than only stating drift occurred.