Skip to content

docs: order the roadmap by what reaches somebody else's SIEM - #99

Merged
blitzcrieg1 merged 1 commit into
masterfrom
docs/roadmap-sensor-ordering
Aug 23, 2026
Merged

docs: order the roadmap by what reaches somebody else's SIEM#99
blitzcrieg1 merged 1 commit into
masterfrom
docs/roadmap-sensor-ordering

Conversation

@blitzcrieg1

Copy link
Copy Markdown
Owner

The roadmap listed the dashboard once, as a bullet in Later, with no reason attached. That reads as an oversight rather than a decision, and an oversight is something the next reader helpfully corrects.

Three separate strategy documents this month each arrived at "demote the dashboard" as a finding. That is what happens when a decision is only implied by ordering. So the ordering is now stated.

Next is sorted by one test

Does this make the sensor land in a SIEM somebody else already runs?

Was Is
OTel ingest, tool response sizes, per-project scoping, corpus, taxonomy, OTLP export Splunk TA listing, per-host identity, OTel ingest, OTLP export, then the rest

The Splunk TA works and has tests. It is also still a directory you copy onto a search head by hand, which is a different conversation from a listing a security team can find on their own.

Two items needed an issue

This file's second rule is that every item names a number somebody else can read. Per-host identity already had enterprise #1. Splunk certification had none anywhere, so it has one now: enterprise #8, filed after checking that nothing in that repo has been near AppInspect. The TA's README and app.conf both disclaim certification today, correctly, and those disclaimers come out on the day a listing is live and not before.

The dashboard gets a section, not a stray bullet

### The dashboard, last on purpose, at the bottom, collecting #27, #26 and #95 under a reason: it is a local inspection surface for the machine the sensor runs on, the SIEM is the console, and a triage queue built here would be the second-best version of a feature the customer already bought.

It also says the part that stops this reading as abandonment. It builds in CI, and the Next 16 migration went in because dependency alerts had to close, not because a screen needed adding. That is the level of attention it gets.

What is deliberately not here

The Sigma pack, because it shipped in #98 yesterday. It is in CHANGELOG.md instead, per the first rule at the top of this file: shipped work leaves the roadmap or the roadmap becomes a second, worse changelog. The Dependabot row is gone for the same reason, the queue being empty.

Status table refreshed to 1125 tests, and the detection row now says the rules are exported as Sigma, which is a claim a reader can check against docs/integrations/sigma/ rather than take.

Not touched

No file under apps/orchestrator/agentmetry/core/audit/. The ruleset fingerprint is 56ad3de1ad8533cf before and after, and the dogfood clock stays at 2 of 4 with week 3 closing 2026-08-28.

🤖 Generated with Claude Code

The roadmap listed the dashboard once, as a bullet in "Later", with no
reason attached. That reads as an oversight rather than a decision, and
an oversight is something the next reader helpfully corrects. Three
separate strategy documents this month each arrived at "demote the
dashboard" as a finding, which is what happens when a decision is only
implied by ordering.

So the ordering is now stated. `Next` is sorted by one test: does this
make the sensor land in a SIEM somebody else already runs. That puts the
Splunk TA listing and per-host identity above the OTel ingest work,
because the TA works and has tests and is still a directory you copy onto
a search head by hand.

Both of those needed an issue to satisfy this file's own second rule.
Per-host identity had one. Splunk certification had none anywhere, so it
has one now: enterprise #8, filed after checking that nothing in that
repo has been near AppInspect.

The dashboard gets a named section at the bottom instead of a stray
bullet, with the reason and the limit. It is a local inspection surface
for one machine, the SIEM is the console, and a triage queue here would
be the second-best version of something the customer already bought. It
also says the part that stops this reading as abandonment: it builds in
CI, and the Next 16 migration went in because dependency alerts had to
close, not because a screen needed adding.

The Sigma pack is not on the roadmap because it shipped in #98. It is in
CHANGELOG.md, per the first rule at the top of the file. The Dependabot
row is gone for the same reason, the queue being empty.

Status table refreshed: 1125 tests, and the detection row now says the
rules are exported as Sigma, which is a claim a reader can check against
docs/integrations/sigma/ rather than take.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@blitzcrieg1
blitzcrieg1 merged commit a0a6cd0 into master Aug 23, 2026
9 checks passed
@blitzcrieg1
blitzcrieg1 deleted the docs/roadmap-sensor-ordering branch August 23, 2026 10:11
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 23, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant