Why this board exists
298 issues are open and they do not all weigh the same. This board says in what order the work gets done so that a sellable GRC is ready in January 2027, with its three promises proven:
Trust : tenant isolation, auth, data integrity and the audit trail hold up to a regulated buyer's security questionnaire.
The engine : one canonical model, the chain Requirement → Control → Test → Evidence, and scores that the formula can explain.
Killer workflow B, Evidence Fabric : evidence that stays current, time-bound acceptance decisions, and a sealed audit pack.
Everything else (auto-draft, governed AI, ecosystem, no-code builders, marketplace, predictive AI) is after the launch . The scope decision is D-054 in docs/DECISIONS.md (PR #817 ).
Source: the direction audit of 2026-09-25 (code, backlog and GRC coverage).
Board rules
The order is binding. A sprint does not start while a P0 from the sprint before is still open.
A sprint issue is status:ready before its sprint starts. Otherwise it is refined in the sprint before; the refinement deadlines are on each issue.
Priority conventions (D-003, dual labelling): the wave-family priority:P0 means blocks the launch ; the Constitution-family priority:P0-critical means production broken or exposed .
Dates : two-week sprints from Monday 28 September. The GA date is to be confirmed by the owner (D-054) ; the proposal is the week of 18 January 2027 .
Sprint 1 — Trust P0 (28 Sep → 9 Oct)
Goal: no known defect lets anyone cross a tenant boundary, bypass an auth factor, or store a false score.
Sprint 2 — trust-v1 complete, CI green (12 → 23 Oct)
Goal: CI shows real results, self-hosting installs a known schema, and no screen claims something false.
feat(notifications): implement a proper notification system (replace NoOpNotifier) #757 — real notifications (replaces NoOpNotifier); prerequisite for feat(risk): residual-risk acceptance expires — mandatory end date, reminder, automatic re-assessment #811
fix(analytics): financial dashboards and trends are returning dummy data #756 — hard-coded 0.0 values in analytics (deceptive UI)
fix(users): POST /users answers 500, so the E2E seed cannot provision analyst or auditor #590 — POST /users returns 500; creates a membership, after security(users): /users/:id status, role and delete act on the global account, not on the caller's membership #807 · duplicate E2E seed cannot create the analyst and auditor personas (POST /users → 500), so their journeys never run #660
fix(e2e): the suite trips the product's own credential throttle — 31 of 62 failures are 429s #588 — E2E trips the throttle; production limits unchanged · duplicate [OR-P0-18] Make E2E authentication tests parallel-safe without weakening production rate limits #352
security(auth): sign-up with an address that already has an account — say so, offer sign-in and reset, alert the owner #686 · fix(auth): “sign out other devices” signs the caller out too (refresh cookie path) #727 · Real-time stream never renews an expired session — live updates stop on an idle page until the user clicks #701 · fix(risk): the risk timeline attributes every change to the risk's creator #793 — end of the auth / session / timeline backlog
Entitlement levels are declared, advertised, and enforced nowhere #613 + fix(entitlements): PRICING.md annonce cinq capacites payantes que le code napplique pas #783 — entitlements declared but never enforced; PRICING.md
Self-hosted instances run on an unspecified schema: the SQL migrations are not in the backend image #611 · Self-hosted deployments must not resolve to PlanFree (D-040) #612 — self-host: migrations in the image, not PlanFree
ci(security): Security Scanning is red on master for three untracked reasons — gofmt, gosec SARIF, deprecated CodeQL v2 #818 · DAST gate never runs: security.yml uses the rejected actions/upload-artifact@v3 #649 · ci(security): the license compliance job has never run, and would pass on anything #774 — Security Scanning red on master (gofmt, gosec SARIF, CodeQL v2, DAST, licences)
fix(ci): Frontend Design Tokens is red on master — alpha-classes manifest is stale, and it hides the visual suite #715 · chore(frontend): lint:ceiling fails on a clean master — stale no-irregular-whitespace count #627 · ci(api): the committed openapi.generated.ts has drifted ~1,000 lines from docs/openapi.yaml, and nothing checks it #814 — other red, silent or unchecked CI gates
chore(deps): remove react-leaflet (Hippocratic-2.1) and replace the no-op license-check job (D-017) #457 — react-leaflet (Hippocratic licence)
Sprint 3 — The engine (26 Oct → 6 Nov)
Goal: the model the Evidence Fabric is built on is decided and in code.
spec(domain): OpenRisk Canonical Model v1 — 17 entities, one envelope, one relationship vocabulary #541 — ADR, canonical model, GRC slice (refine by 10 Oct; D-030: no code before the ADR)
feat(compliance): model the full chain — Requirement → Control → Implementation → Test → Evidence #553 — Requirement → Control → Implementation → Test → Evidence (refine by 17 Oct)
[OR-P0-10] Replace post-commit event append with a true transactional outbox #344 — transactional outbox (a commitment of D-004)
[OR-P0-14] Ensure risk.created always carries aggregate identity and is emitted live #348 — risk.created carries its identity
debt(arch): handlers query database.DB directly — ratchet it to zero and add a structural tenant-filter guard #808 — database.DB ratchet in handlers + structural tenant guard (D-055)
feat(risks): the risk bulk endpoint has no impact preview and takes its action from the body #599 · Financial coverage count always fails: raw SQL reads risks.sle_xaf, GORM builds risks.slexaf #712 — bulk risk impact preview; financial coverage
[EPIC] TPRM v1 — vendor register, public questionnaires, vendor score, reminders, vendor→asset→risk #214 — finish TPRM v1 (in progress) · the owner closes feat(tprm): vendor score from weighted answers, separate from Risk.Score #671 and feat(tprm): public questionnaire page for vendors, no account required #674 (already on master)
Sprint 4 — Evidence Fabric (9 → 20 Nov)
Goal: a control's status is computed from its evidence, and every acceptance has an end date.
chore(evidence): retire the legacy control_evidences table now that the evidence library is the only register #813 — one evidence register (after D-056)
feat(evidence): Evidence Fabric record — collector, observation period, hash, chain of custody, freshness #554 — Evidence Fabric record: hash, custody, observation period (refine by 31 Oct)
feat(compliance): control status computed live from evidence freshness and exceptions #555 — control status computed from evidence freshness
feat(risk): residual-risk acceptance expires — mandatory end date, reminder, automatic re-assessment #811 — time-bound risk acceptance, automatic re-assessment
feat(content): control-level depth for NIST 800-53 r5, NIS2 and DORA — and lock every catalogue count in a test #809 — control-level NIST 800-53 / NIS2 / DORA (+ D-057 for CIS / PCI)
feat(content): three ready-to-run framework packs with pre-wired mappings and one-click import #556 — one-click framework packs with their mappings
Sprint 5 — Ready for the auditor, a clean interface (23 Nov → 4 Dec)
Sprint 6 — Launch gate (7 → 18 Dec)
W8-01 — Complete cybersecurity hardening and tenant-isolation release gate #229 — hardening and tenant-isolation release gate
W8-04 — Pass the WCAG 2.1 AA, responsive, and keyboard-first release gate #232 — WCAG AA / keyboard / responsive (see also [OR-P0-05] Complete WCAG 2.2 AA validation with axe, keyboard navigation and screen readers #339 )
[OR-P0-06] Establish realistic enterprise-scale performance and capacity benchmarks #340 — enterprise-scale performance (see also W8-03 — Validate enterprise-scale performance and data-volume behavior #231 )
docs(ops): restauration testee et chronometree, RTO/RPO chiffres #488 — restore tested and timed, RTO/RPO in figures (see also W5-06 — Backup, disaster recovery, and evidence immutability for compliance data #320 )
[OR-P0-12] Validate production alert rules by firing them against a real Prometheus/Alertmanager stack #346 — alerts proven by firing them on a real Prometheus
[OR-P0-15] Validate migration 0060 against populated production-like databases #349 — migration 0060 on a populated database (in progress)
W8-05 — Establish the launch validation suite and live-proof release checklist #233 — launch validation suite
[OR-P1-62] Rewrite README as an evidence-based product and architecture document #405 · W8-08 — User and API documentation platform #316 · fix(marketing): verifier les claims du site OpenDefender contre le produit #781 · docs(trust): auto-evaluation d'OpenDefender par OpenRisk, publiee #490 — evidence-based README, docs, verified claims, published self-assessment
Buffer (21 Dec → 1 Jan) — slippage only, no new scope
Freeze and RC (4 → 15 Jan 2027)
Parallel owner track (not code)
After the launch (explicitly out of scope)
Release 1.3 — Risk Auto-Draft : [EPIC] Killer workflow A — Signal → Risk → Action → Evidence, closed loop #536 , feat(ingest): POST /v1/signals and POST /v1/findings — the inlet the closed loop needs #544 → feat(workflow): closed-loop verification — rescan, evidence, recompute, propose closure #552 , feat(risk): Key Risk Indicators with thresholds tied to risk appetite — a breach drafts a risk signal #812 (KRIs), W7-06 — Risk appetite and tolerance configuration per business unit #319 (appetite)
Release 1.5 — Governed AI : [EPIC] Governed AI — reasoning layer, guardrails, decision record #538 and its children
Release 1.6 — Ecosystem : [EPIC] IT-native surface — CLI, decision API, OSCAL interchange #540 , feat(cli): the openrisk CLI — scan, findings, risks, controls, evidence #564 , feat(api): decision surface — /v1/evaluate, /v1/risk-proposals, /v1/actions #565 , feat(oscal): OSCAL-native import and export with a proven round-trip #566 (OSCAL)
Content by market : feat(content): regulatory catalogues for the declared target markets — Canada, Morocco, Belgium, France #810 (Canada, Morocco, Belgium, France), after chore(content): responsable du contenu reglementaire et cadence de veille #493 and chore(gtm): recruter 3 organisations pilotes #494
Vision (no dedicated milestone; proposed for tier:5-deferred in D-054): no-code builders [OR-P1-51] Build no-code Risk Type Builder #385 → [OR-P1-55] Build no-code Dashboard Builder #389 · marketplace and SDK [OR-P1-56] Create OpenRisk Extension SDK #390 → [OR-P1-59] Implement extension permission sandbox #393 · predictive AI [OR-P2-01] Implement Predictive Risk Forecasting #394 → [OR-P2-08] Build Risk-to-Financial-Impact Executive Model #401 · Wave 2/3/5 features W2-01 — Operationalize CTI ingestion, enrichment, and emerging-risk correlation #202 → W5-03 — Deliver Sensitive Data Discovery and Data Risk scoring #221 · BCP W5-01 — Deliver Business Continuity and Disaster Recovery management #219 (duplicate [OR-P1-64] Implement Business Continuity and Operational Resilience Management #408 )
Measured starting point (2026-09-25, master 6a8c964 )
Why this board exists
298 issues are open and they do not all weigh the same. This board says in what order the work gets done so that a sellable GRC is ready in January 2027, with its three promises proven:
Everything else (auto-draft, governed AI, ecosystem, no-code builders, marketplace, predictive AI) is after the launch. The scope decision is D-054 in
docs/DECISIONS.md(PR #817).Source: the direction audit of 2026-09-25 (code, backlog and GRC coverage).
Board rules
status:readybefore its sprint starts. Otherwise it is refined in the sprint before; the refinement deadlines are on each issue.priority:P0means blocks the launch; the Constitution-familypriority:P0-criticalmeans production broken or exposed.Sprint 1 — Trust P0 (28 Sep → 9 Oct)
Goal: no known defect lets anyone cross a tenant boundary, bypass an auth factor, or store a false score.
/users/:idacts on the global account (P0, tenant isolation)/assetsreturns 403 on reloadevents:readmissing from the catalogue · duplicate bug(rbac): events:read is granted by every business role but missing from PermissionCatalog #576Sprint 2 — trust-v1 complete, CI green (12 → 23 Oct)
Goal: CI shows real results, self-hosting installs a known schema, and no screen claims something false.
NoOpNotifier); prerequisite for feat(risk): residual-risk acceptance expires — mandatory end date, reminder, automatic re-assessment #811POST /usersreturns 500; creates a membership, after security(users): /users/:id status, role and delete act on the global account, not on the caller's membership #807 · duplicate E2E seed cannot create the analyst and auditor personas (POST /users → 500), so their journeys never run #660Sprint 3 — The engine (26 Oct → 6 Nov)
Goal: the model the Evidence Fabric is built on is decided and in code.
risk.createdcarries its identitydatabase.DBratchet in handlers + structural tenant guard (D-055)Sprint 4 — Evidence Fabric (9 → 20 Nov)
Goal: a control's status is computed from its evidence, and every acceptance has an end date.
Sprint 5 — Ready for the auditor, a clean interface (23 Nov → 4 Dec)
--accentfails contrast on filled surfaces (2.66–2.81) #724 — unreachable controls, a11y, contrastopenapi.yamlSprint 6 — Launch gate (7 → 18 Dec)
Buffer (21 Dec → 1 Jan) — slippage only, no new scope
Freeze and RC (4 → 15 Jan 2027)
/shipgreen on an-rcrelease (SBOM, SHA256SUMS: claim C-007)/verify-claims: noMOCKEDorABSENTclaim on a public surfaceParallel owner track (not code)
Signed-off-by(DCO), then merge. It records D-054 → D-057.After the launch (explicitly out of scope)
tier:5-deferredin D-054): no-code builders [OR-P1-51] Build no-code Risk Type Builder #385 → [OR-P1-55] Build no-code Dashboard Builder #389 · marketplace and SDK [OR-P1-56] Create OpenRisk Extension SDK #390 → [OR-P1-59] Implement extension permission sandbox #393 · predictive AI [OR-P2-01] Implement Predictive Risk Forecasting #394 → [OR-P2-08] Build Risk-to-Financial-Impact Executive Model #401 · Wave 2/3/5 features W2-01 — Operationalize CTI ingestion, enrichment, and emerging-risk correlation #202 → W5-03 — Deliver Sensitive Data Discovery and Data Risk scoring #221 · BCP W5-01 — Deliver Business Continuity and Disaster Recovery management #219 (duplicate [OR-P1-64] Implement Business Continuity and Operational Resilience Management #408)Measured starting point (2026-09-25,
master6a8c964)go build ./...exit 0 ·go test ./...no FAIL (no Postgres) ·npm run type-checkexit 0master(5 jobs: DAST gate never runs: security.yml uses the rejected actions/upload-artifact@v3 #649, ci(security): the license compliance job has never run, and would pass on anything #774, ci(security): Security Scanning is red on master for three untracked reasons — gofmt, gosec SARIF, deprecated CodeQL v2 #818)database.DBcalls ininternal/handler(the ratchet of debt(arch): handlers query database.DB directly — ratchet it to zero and add a structural tenant-filter guard #808 starts here)