ADR-033: PDI-Immune ServiceNow Identity — Versioned Natural Keys + Server-Enforced Deletion Policy
Make ServiceNow entity identity PDI-independent (versioned typed natural keys) and move deletion protection to a server-enforced per-tenant policy, so a curated demo tenant survives any PDI change with zero manual steps. Executed on dev 2026-07-24 (manifest 25bfda55…) and independently re-verified 2026-07-27; 91 legacy entities re-keyed, 10-entity protected floor intact, zero active-graph dangling references.
Canonical Resource Identity for Path-Scoped Execution Evidence
Why SecurityV0's current resource identity model cannot support deterministic path-scoped execution evidence attribution, and a proposal to introduce a first-class canonical resource_key on both entities and evidence records.
Combined Platform Pipeline Architecture
Merges W1.1 (persistent authority paths + path-level findings) with Phase 4 (platform-side graph computation, import-by-type ingestion)
Cross-Connector Graph Stitching Architecture
Deterministic stitching pipeline that merges cross-connector identities and re-materializes authority paths spanning connector boundaries.
Implementation Plan: Scan Safety, Data Loss Prevention & Connector Observability
Plan to harden scan safety (no automatic large soft-removals from a single suspect scan) and add connector observability after a fresh scan removed all 5 authority paths for the default tenant on 2026-02-26.
Processing Pipeline Architecture
Defines the batch processing pipeline from connector submission through findings and evidence packs
Reconciled Roadmap — Automation-First MVP + Post-MVP Architecture
Final reconciled roadmap comparing three analysis versions (2026-02-10, codex, combined), taking the best from each
Vision vs. Delivered — Deep Gap Analysis & Architecture Evolution Plan
Comprehensive comparison of MVP1 PRD product vision against current platform delivery, identifying structural gaps in UI automation focus, graph visualization, ingestion architecture, and business-...