docs: order the roadmap by what reaches somebody else's SIEM - #99
Merged
Conversation
The roadmap listed the dashboard once, as a bullet in "Later", with no reason attached. That reads as an oversight rather than a decision, and an oversight is something the next reader helpfully corrects. Three separate strategy documents this month each arrived at "demote the dashboard" as a finding, which is what happens when a decision is only implied by ordering. So the ordering is now stated. `Next` is sorted by one test: does this make the sensor land in a SIEM somebody else already runs. That puts the Splunk TA listing and per-host identity above the OTel ingest work, because the TA works and has tests and is still a directory you copy onto a search head by hand. Both of those needed an issue to satisfy this file's own second rule. Per-host identity had one. Splunk certification had none anywhere, so it has one now: enterprise #8, filed after checking that nothing in that repo has been near AppInspect. The dashboard gets a named section at the bottom instead of a stray bullet, with the reason and the limit. It is a local inspection surface for one machine, the SIEM is the console, and a triage queue here would be the second-best version of something the customer already bought. It also says the part that stops this reading as abandonment: it builds in CI, and the Next 16 migration went in because dependency alerts had to close, not because a screen needed adding. The Sigma pack is not on the roadmap because it shipped in #98. It is in CHANGELOG.md, per the first rule at the top of the file. The Dependabot row is gone for the same reason, the queue being empty. Status table refreshed: 1125 tests, and the detection row now says the rules are exported as Sigma, which is a claim a reader can check against docs/integrations/sigma/ rather than take. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The roadmap listed the dashboard once, as a bullet in
Later, with no reason attached. That reads as an oversight rather than a decision, and an oversight is something the next reader helpfully corrects.Three separate strategy documents this month each arrived at "demote the dashboard" as a finding. That is what happens when a decision is only implied by ordering. So the ordering is now stated.
Nextis sorted by one testDoes this make the sensor land in a SIEM somebody else already runs?
The Splunk TA works and has tests. It is also still a directory you copy onto a search head by hand, which is a different conversation from a listing a security team can find on their own.
Two items needed an issue
This file's second rule is that every item names a number somebody else can read. Per-host identity already had enterprise #1. Splunk certification had none anywhere, so it has one now: enterprise #8, filed after checking that nothing in that repo has been near AppInspect. The TA's README and
app.confboth disclaim certification today, correctly, and those disclaimers come out on the day a listing is live and not before.The dashboard gets a section, not a stray bullet
### The dashboard, last on purpose, at the bottom, collecting #27, #26 and #95 under a reason: it is a local inspection surface for the machine the sensor runs on, the SIEM is the console, and a triage queue built here would be the second-best version of a feature the customer already bought.It also says the part that stops this reading as abandonment. It builds in CI, and the Next 16 migration went in because dependency alerts had to close, not because a screen needed adding. That is the level of attention it gets.
What is deliberately not here
The Sigma pack, because it shipped in #98 yesterday. It is in
CHANGELOG.mdinstead, per the first rule at the top of this file: shipped work leaves the roadmap or the roadmap becomes a second, worse changelog. The Dependabot row is gone for the same reason, the queue being empty.Status table refreshed to 1125 tests, and the detection row now says the rules are exported as Sigma, which is a claim a reader can check against
docs/integrations/sigma/rather than take.Not touched
No file under
apps/orchestrator/agentmetry/core/audit/. The ruleset fingerprint is56ad3de1ad8533cfbefore and after, and the dogfood clock stays at 2 of 4 with week 3 closing 2026-08-28.🤖 Generated with Claude Code