Lane 1 · CanaPoint
Federal identity, connector control plane, Trust Graph, AI-BOM, and supply-chain evidence.
Dashboard / CanaPoint + ForgeScan
Phase 1 · Version 1.0 · Prepared October 6, 2026
Phase 1 Accelerated Implementation
Active sprint · Release candidate · 10 workdays
A controlled sprint from October 7 through October 20, 2026. The target is a demonstrable, security-reviewed Phase 1 release candidate. It is not a claim of completed FedRAMP authorization, agency PIV onboarding, or full multi-cloud production certification.
/projects/canapoint-forgescan-phase1/
A 10-workday Phase 1 release-candidate sprint is achievable if the team keeps the existing architectures, runs parallel lanes, gates production deployments, and treats a live GovCloud / FIPS deployment as a stretch gate when external accounts or approvals are unavailable.
Tagline from the plan. AI-driven. Security-first. Assurance built in. External claims stay behind observed evidence.
Critical path: Day 0 merge of ForgeScan #231, federal identity policy, connector GA, Trust Graph and AI-BOM, integrated mission thread, then exact-SHA certification. ForgeScan assurance work runs in parallel. IaC starts once identity and connector contracts are stable.
| Day | Date | Theme | Exit |
|---|---|---|---|
| 1 | Wed, Oct 7 | Baseline + federal identity architecture | M1 baseline sealed. No production OIDC enablement. |
| 2 | Thu, Oct 8 | Federal identity implementation + connector v2 start | M2 identity foundation. Commercial auth unchanged. |
| 3 | Fri, Oct 9 | Connector GA + secret rotation | M3 connector GA candidate. Two-way conformance. |
| 4 | Mon, Oct 12 | Trust Graph + Assurance Node | M4 relationship and fabric core. |
| 5 | Tue, Oct 13 | AI-BOM + evidence integrity | M5 evidence chain. Signed AI-BOM and hash-verified raw evidence. |
| 6 | Wed, Oct 14 | Web scan safety + live lifecycle | M6 ForgeScan functional closeout. |
| 7 | Thu, Oct 15 | Terraform + federal runtime foundations | M7 portable infrastructure. Plan and validate only. |
| 8 | Fri, Oct 16 | Supply chain + claims + portability proof | M8 release assurance. |
| 9 | Mon, Oct 19 | Integrated mission thread | M9 integrated acceptance, including failure injection. |
| 10 | Tue, Oct 20 | Release-candidate certification | M10 Phase 1 RC. GO FOR CONTROLLED BETA, CONDITIONAL GO, or NO-GO. |
| Workstream | Release-candidate outcome |
|---|---|
| A · Identity and change control | Enterprise OIDC in both products, secure sessions, federal identity policy and CAC/PIV federation architecture, and documented production-promotion controls. |
| B · Connector GA | Versioned CanaPoint envelope with v1 compatibility, per-tenant rotating secrets, correlation, and two-way conformance tests. |
| C · Trust Graph + AI-BOM | Graph relationships over AI assets and a signed, versioned CycloneDX-compatible AI/ML BOM. CanaPoint remains authoritative for the BOM. |
| D · ForgeScan assurance fabric | Assurance Node, SSRF-safe web scanner behind a gate, raw evidence with integrity hashes, live lifecycle proof, and updated capability claims. |
| E · Federal / IaC foundation | Reusable Terraform modules, federal crypto-boundary documentation, tamper-evident audit plan, and one portable non-Cloudflare proof when feasible. |
| F · Supply chain / claims | SBOM and signing, dependency triage, claims register, release evidence pack, and exact-SHA closeout. |
Federal identity, connector control plane, Trust Graph, AI-BOM, and supply-chain evidence.
Close #231, connector receiver, Assurance Node, web-scan safety, evidence retention, and live scan lifecycle.
Platform/IaC after Day 3. Security and QA review exact SHAs and do not approve their own implementation path.
Merge Phase 1A.2B. Federal identity policy. Connector v2 and per-tenant secret rotation. Trust Graph MVP. Signed AI-BOM. Assurance Node. R2 evidence retention. Gated SSRF-safe crawler. D1 lifecycle proof. SBOM, claims, and release evidence. Terraform skeleton with CI validation.
Live AWS GovCloud or customer-managed Linux deployment. Broader Postgres adapter proof. External tamper-evident audit sink. Live enterprise PIV/CAC test. Production-like connector soak.
Formal FedRAMP authorization, agency PIV/CAC onboarding, full datastore migration, air-gap productization, full Helm/Kubernetes, SCIM, SAML, and third-party compliance certification.
Stop dependent merges on a tenant-isolation failure, a connector that accepts the wrong tenant or a bad signature or a replay, evidence hash mismatch, or a CI gate weakened to pass. If web scanning can reach a blocked network or metadata target, keep that feature disabled. If GovCloud is unavailable, deliver a validated reference plan and mark the live proof pending. That absence does not stop the core sprint.
| ID | Blocker | Target | Expected status |
|---|---|---|---|
| P0-1 | Enterprise / federal identity | Day 2 | Partial until live IdP evidence |
| P0-2 | SSRF-safe web crawler | Day 6 | Resolve |
| P0-3 | Tamper-evident audit | Day 7 | Resolve or accept |
| P0-4 | Capability / claim gaps | Day 8 | Resolve |
| P0-5 | Connector shared secret | Day 3 | Resolve |
| P0-6 | FIPS posture | Days 7–10 | Partial / stretch |
| P0-7 | Production approval | Day 10 | Risk accept / partial |
| P0-8 | Supply-chain findings | Day 8 | Resolve or accept residual |
| P0-9 | ForgeScan live D1 lifecycle | Day 6 | Resolve |
| P0-10 | Raw scan evidence retention | Day 5 | Resolve |
Classification on Day 10. GO FOR CONTROLLED BETA, CONDITIONAL GO, or NO-GO. Coding stops except for release-blocking defects after SHA freeze.
Frozen SHAs, migration lists, test summaries, CI results, SBOM and AI-BOM verification, connector conformance, ForgeScan lifecycle and SSRF reports, Trust Graph evidence, Assurance Node proof, federal identity notes with any pending PIV/CAC called out, the P0 register, the claims register, and rollback runbooks.