Roadmap

The host monitoring loop works.

The recovery programme replaced component-level claims with tested operator journeys. Broader monitoring still follows evidence, not labels.

WP01R–WP02R · Honest baseline and protocol — complete

Claims were reconciled and the bounded atomic collector protocol was frozen.

WP03R–WP04R · Sampling and secure pairing — complete

The supplied binary samples Linux resources and exchanges a short-lived one-use token for private post-scoped configuration.

WP05R–WP06R · Service and reliable delivery — complete

Hardened systemd lifecycle, persistent sequence state, bounded buffering, ordered acknowledgement and backoff are implemented.

WP07R · Explicit collector health — complete

Healthy, stale, offline, skewed, rejected, partial, revoked and never-connected are durable operational states.

WP08R · Complete host journey — complete

Guided host creation, starter rules, pairing confirmation, survey navigation and a separate-process restart gate now prove the ordinary loop.

WP09R · Operable rules and alerts — complete

Authenticated operators can list rules and enable or disable them independently while alert evaluation remains deterministic and restart-safe.

WP10R · Observable notification delivery — complete

Secret-free route status shows pending, retrying, and delivered work from the durable notification queue.

WP11R · Incident ownership — complete

Assignment, notes, creation, and transitions retain the authenticated operator identity in the durable timeline.

WP12R · Navigable evidence — complete

Authorised operators can resolve an exact log or change citation to its complete bounded record and post context.

WP13R · Durable read-only devices — complete

Post-linked SNMPv3 profiles retain address, username, device kind, and bounded read-only OIDs; authentication secrets remain transient.

WP14R · Evidence-grounded investigation — complete

Investigations can assemble at most 20 recent post records automatically, and every provider citation is verified against the conversation post.

WP15R · Inspectable typed actions — complete

Bounded records expose typed parameters, requester, independent approver, lifecycle state, timestamps, and verification result; arbitrary commands remain absent.

WP16R · Operable fleet trust — complete

Peer status exposes trust state, revocation, and bounded inbox/outbox counts while each node remains independently useful.

WP17R · Release and deployment evidence — complete

Deterministic six-target artifacts, checksums, installer download, preserved-state upgrade/rollback, and explicit Caddy/nginx secure-cookie deployment are locally gated.

WP18R · Hardening and recovery — complete

Normal/race/vet/fuzz, release, host, stopped-backup recovery, corruption, and bounded resource-soak gates are composed and locally green.

Development candidate, not public release

Real macOS/Windows execution, scheduled checks, richer management UI, fleet partition evidence, online backups, extended capacity work, and external security review remain explicit limitations.