Dashboard / CanaPoint + ForgeScan

Phase 1 · Version 1.0 · Prepared October 6, 2026

CanaPoint AI Command + ForgeScan

Phase 1 Accelerated Implementation

Active sprint · Release candidate · 10 workdays

A controlled sprint from October 7 through October 20, 2026. The target is a demonstrable, security-reviewed Phase 1 release candidate. It is not a claim of completed FedRAMP authorization, agency PIV onboarding, or full multi-cloud production certification.

/projects/canapoint-forgescan-phase1/

Executive decision

A 10-workday Phase 1 release-candidate sprint is achievable if the team keeps the existing architectures, runs parallel lanes, gates production deployments, and treats a live GovCloud / FIPS deployment as a stretch gate when external accounts or approvals are unavailable.

Calendar
October 7–20, 2026. Wednesday, October 7 is Day 1: baseline and federal identity architecture. Milestone M1 is “baseline sealed.”
Primary repositories
Bjay0727-jay/AI-Governance and Bjay0727-jay/Forge-Scan. No shared database and no forced monorepo.
Success target
One integrated release candidate: identity foundations, hardened bidirectional integration, Trust Graph plus signed AI-BOM, ForgeScan assurance evidence, portable IaC foundations, and release evidence.
Day 0 note
The October 6 plan records ForgeScan PR #231 as ready and not merged. Merging it, confirming main CI, and verifying migrations 044 and 045 is the prerequisite. Merging that PR does not by itself enable OIDC in production.
Production
No production deployment from this portal, a laptop, or an agent session. Promotion stays PR, CI, review, merge, then an authorized promotion.

Tagline from the plan. AI-driven. Security-first. Assurance built in. External claims stay behind observed evidence.

Ten-workday map

Critical path: Day 0 merge of ForgeScan #231, federal identity policy, connector GA, Trust Graph and AI-BOM, integrated mission thread, then exact-SHA certification. ForgeScan assurance work runs in parallel. IaC starts once identity and connector contracts are stable.

Working days only. October 10–11 and October 17–18 are outside the sprint map.
Day Date Theme Exit
1 Wed, Oct 7 Baseline + federal identity architecture M1 baseline sealed. No production OIDC enablement.
2 Thu, Oct 8 Federal identity implementation + connector v2 start M2 identity foundation. Commercial auth unchanged.
3 Fri, Oct 9 Connector GA + secret rotation M3 connector GA candidate. Two-way conformance.
4 Mon, Oct 12 Trust Graph + Assurance Node M4 relationship and fabric core.
5 Tue, Oct 13 AI-BOM + evidence integrity M5 evidence chain. Signed AI-BOM and hash-verified raw evidence.
6 Wed, Oct 14 Web scan safety + live lifecycle M6 ForgeScan functional closeout.
7 Thu, Oct 15 Terraform + federal runtime foundations M7 portable infrastructure. Plan and validate only.
8 Fri, Oct 16 Supply chain + claims + portability proof M8 release assurance.
9 Mon, Oct 19 Integrated mission thread M9 integrated acceptance, including failure injection.
10 Tue, Oct 20 Release-candidate certification M10 Phase 1 RC. GO FOR CONTROLLED BETA, CONDITIONAL GO, or NO-GO.

Workstreams and lanes

Ten-day release-candidate outcomes. Stretch items stay labeled stretch.
Workstream Release-candidate outcome
A · Identity and change control Enterprise OIDC in both products, secure sessions, federal identity policy and CAC/PIV federation architecture, and documented production-promotion controls.
B · Connector GA Versioned CanaPoint envelope with v1 compatibility, per-tenant rotating secrets, correlation, and two-way conformance tests.
C · Trust Graph + AI-BOM Graph relationships over AI assets and a signed, versioned CycloneDX-compatible AI/ML BOM. CanaPoint remains authoritative for the BOM.
D · ForgeScan assurance fabric Assurance Node, SSRF-safe web scanner behind a gate, raw evidence with integrity hashes, live lifecycle proof, and updated capability claims.
E · Federal / IaC foundation Reusable Terraform modules, federal crypto-boundary documentation, tamper-evident audit plan, and one portable non-Cloudflare proof when feasible.
F · Supply chain / claims SBOM and signing, dependency triage, claims register, release evidence pack, and exact-SHA closeout.

Lane 1 · CanaPoint

Federal identity, connector control plane, Trust Graph, AI-BOM, and supply-chain evidence.

Lane 2 · ForgeScan

Close #231, connector receiver, Assurance Node, web-scan safety, evidence retention, and live scan lifecycle.

Lanes 3 and 4

Platform/IaC after Day 3. Security and QA review exact SHAs and do not approve their own implementation path.

Must, stretch, and deferred

Must

Merge Phase 1A.2B. Federal identity policy. Connector v2 and per-tenant secret rotation. Trust Graph MVP. Signed AI-BOM. Assurance Node. R2 evidence retention. Gated SSRF-safe crawler. D1 lifecycle proof. SBOM, claims, and release evidence. Terraform skeleton with CI validation.

Stretch

Live AWS GovCloud or customer-managed Linux deployment. Broader Postgres adapter proof. External tamper-evident audit sink. Live enterprise PIV/CAC test. Production-like connector soak.

Deferred

Formal FedRAMP authorization, agency PIV/CAC onboarding, full datastore migration, air-gap productization, full Helm/Kubernetes, SCIM, SAML, and third-party compliance certification.

Guardrails

  • No shared database among CanaPoint AI Command, ForgeScan, and ForgeComply. No product is a runtime dependency of another for basic operation.
  • CanaPoint is authoritative for AI governance and decision context. ForgeScan is authoritative for observed technical state, scanner infrastructure, raw findings, and raw evidence.
  • Unknown identity, tenant, subject, invalid signature, stale or replayed event, malformed target, and unsupported crypto fail closed.
  • Browser credentials do not return to localStorage or sessionStorage. Scanner nodes remain machine identities.
  • Refactor in place. No broad rewrite and no production change that bypasses human security review.
  • Federal features do not claim CAC/PIV, AAL, FICAM, FIPS, or FedRAMP compliance without implementation and evidence.
  • Claims use explicit states: Verified, Partial, Preview, Architected, Blocked, Deferred. A new external claim is not Verified until the register points at observed evidence.
  • Every security-sensitive change is implementation first, independent review second, human merge third. Cursor agents do not auto-merge.

Stop conditions

Stop dependent merges on a tenant-isolation failure, a connector that accepts the wrong tenant or a bad signature or a replay, evidence hash mismatch, or a CI gate weakened to pass. If web scanning can reach a blocked network or metadata target, keep that feature disabled. If GovCloud is unavailable, deliver a validated reference plan and mark the live proof pending. That absence does not stop the core sprint.

P0 closure targets

Expected status is the 10-day target from the October 6 plan, not a claim that the item is already closed.
ID Blocker Target Expected status
P0-1 Enterprise / federal identity Day 2 Partial until live IdP evidence
P0-2 SSRF-safe web crawler Day 6 Resolve
P0-3 Tamper-evident audit Day 7 Resolve or accept
P0-4 Capability / claim gaps Day 8 Resolve
P0-5 Connector shared secret Day 3 Resolve
P0-6 FIPS posture Days 7–10 Partial / stretch
P0-7 Production approval Day 10 Risk accept / partial
P0-8 Supply-chain findings Day 8 Resolve or accept residual
P0-9 ForgeScan live D1 lifecycle Day 6 Resolve
P0-10 Raw scan evidence retention Day 5 Resolve

Day 10 exit criteria

  • Must-scope items are complete or explicitly moved to a named risk with an owner and evidence.
  • P0-2, P0-5, P0-8, P0-9, and P0-10 are resolved. P0-1, P0-3, P0-6, and P0-7 have evidence-backed classifications.
  • Connector v2 passes two-way conformance and stays compatible with current v1 consumers.
  • A representative AI system has a tenant-scoped Trust Graph and a signed, versioned AI-BOM.
  • ForgeScan models Assurance Nodes, stores hash-verifiable raw evidence, and passes the approved live scan lifecycle.
  • Web scanning is either safely gated or remains disabled with P0-2 visibly open.
  • Terraform validates. A portable node proof or a validated federal reference plan is captured.
  • SBOM, provenance, and the claims register match the candidate. The golden mission thread and failure injection are complete.
  • Independent exact-SHA review and full CI are green.
  • Production deployment remains a separate authorized decision.

Classification on Day 10. GO FOR CONTROLLED BETA, CONDITIONAL GO, or NO-GO. Coding stops except for release-blocking defects after SHA freeze.

Evidence pack

Frozen SHAs, migration lists, test summaries, CI results, SBOM and AI-BOM verification, connector conformance, ForgeScan lifecycle and SSRF reports, Trust Graph evidence, Assurance Node proof, federal identity notes with any pending PIV/CAC called out, the P0 register, the claims register, and rollback runbooks.

Back to dashboard AI Governance