Documentation

Use AI Security Planner to create a program, keep the roadmap current, report progress, and back up or share the result.

Alerts: charts and source basis

Charts compare the advisories in the selected scope. Selecting a bar narrows the alert table; source and planning actions remain explicit.

Alerts by program

Counts cover the complete retained API selection within the current filters. One publisher item is counted once across revisions. Separate publishers remain distinct even when CVEs overlap. An advisory can match several programs, so program totals cannot be added into a distinct portfolio total. Bars use the existing Critical / high, Medium, and Other / not rated urgency groups. The chart marks completeness as unconfirmed if the API does not provide its coverage receipt.

Material risk changes

The chart compares distinct Critical / high Alerts first recorded in the selected period with the immediately preceding equal period for each exact organization and program. Known exploited is an evidence-backed subset. Delivery status, schedule position, and optional organization-supplied program-wide asset value provide decision context. Alert volume is a review signal, not proof of exposure, exploitation, loss, control failure, security effectiveness, or return on investment. Asset values are never summed across currencies.

Shared remediation opportunities

A cohort appears when either at least two distinct Critical / high Alerts or one Critical / high Alert across multiple authorized organization or site targets maps to the same milestone in one program. Every qualifying cohort is ranked by Alert count in descending order in both the summary and inspector. A cohort indicates an opportunity to coordinate review; it does not prove that one change resolves every Alert.

Alerts over time

The selectable 24-hour, 7-day, 30-day, and 90-day chart counts all distinct relevant Alerts at the hour or day their stable publisher identity was first recorded, stacked as Critical / high, Medium, and Other / not rated. Segment details include the current review lifecycle mix and Known Exploited subset. Later revisions do not backfill publisher dates or rewrite the original entry. Source interruptions and retention can leave earlier counts incomplete.

Export PNG

Export PNG prepares an image of the selected chart; Download PNG saves it. Alert chart exports include the displayed values, legends, current scope, date, and any unavailable-data notice. Exporting does not change alerts, milestones, or tasks.

Start a program

Choose one program, set broad delivery assumptions, and preserve the generated baseline.

  1. Open New Program.

    Use Plan a program, the My Work empty state, or the New program command. Every start action opens the same application route.

  2. Choose or import.

    Select one current program or import a complete validated JSON program. Import is the only file action on the creation route.

  3. Set the planning basis.

    Enter the start and target dates, organization-size band, delivery capacity, and any established foundations.

  4. Generate the roadmap.

    The fixed catalog and rules calculate milestones, dependencies, forecast dates, and critical path before Overview opens.

Planning method

Versioned catalogs and deterministic rules turn declared assumptions into one inspectable planning baseline.

  1. Declare broad inputs.

    A program starts with its catalog, start and target dates, organization-size band, allocated delivery capacity, established foundations, and any program-specific eligibility or operating-context fields.

  2. Build the baseline.

    The selected source-backed catalog supplies stable work identifiers, outcomes, completion conditions, effort, lead roles, priority, and dependencies. The planning-rules version schedules that work in dependency order against available capacity.

  3. Record execution.

    Saved progress, actual dates, user-set dates, blockers, decisions, tasks, and subtasks reforecast unfinished work without rewriting the catalog or original generated dates.

  4. Report the current state.

    Overview, List, Kanban, Gantt, PERT, Agile views, and the executive report derive from the same saved program. A reporting snapshot preserves an exact comparison point.

  5. Keep the boundary visible.

    Matching inputs, catalog version, planning-rules version, and saved state produce the same baseline and forecast. Results support planning; they do not assess controls, prove effectiveness, certify compliance, or replace qualified review.

Inputs, results, and review

Use only the bounded information needed for planning, then review every output before acting on it.

Accepted planning information

Use broad dates, capacity assumptions, foundation choices, bounded operational context, and concise execution notes. Do not enter credentials, secrets, regulated records, detailed architecture, security evidence, or other sensitive source material.

Generated and saved results

The product produces a roadmap, linked planning views, deterministic reports, PNG and PowerPoint output, and user-controlled JSON, CSV, and Markdown files.

Import boundary

JSON import checks type, size, schema, checksum, and the complete program before showing a summary. Replacement happens only after confirmation and never changes an unrelated program.

Human review

Check applicability, source scope, assumptions, dates, ownership, recommendations, sensitive status, and exported content before committing people, budget, technology, or time.

Review the portfolio and roadmap

Portfolio compares active programs. Each program view keeps the underlying milestone identity intact.

Portfolio

Compare schedule position, execution progress, blockers, critical paths, target dates, and next actions across active programs. Open one program when a detail needs action.

Overview

Review schedule position, progress, blockers, now, next, at risk, and the visible plan basis.

List and Kanban

Scan the complete work hierarchy in List or move milestones through delivery states in Kanban.

Gantt

Review calendar alignment, dependency routes, critical work, tasks, and nested subtasks. The complete view can be exported as PNG.

PERT

Inspect the complete dependency graph and critical path. The full graph can also be exported as PNG.

Update dates and work

User-owned dates and execution records can change without erasing the generated reference plan.

Update a milestone

Select a milestone, review its useful facts, then use the single Update milestone action for status, owner, dates, blockers, decisions, and notes.

Manage tasks and subtasks

Add, rename, complete, reopen, or delete tasks and subtasks in the same milestone update. The saved hierarchy appears across roadmap views and exports.

Record progress

Save completion, actual dates, blockers, decision categories, and a bounded plain-text note for the reporting date.

Resolve conflicts

The interface identifies target and dependency conflicts. A user-set date remains explicit rather than being silently corrected.

Prepare a report

The report converts saved execution state into concise, deterministic decision support.

Review the preview

Confirm forecast status, priority work, consequences, ownership, due date, next action, and plan basis.

Save a comparison baseline

A reporting snapshot is immutable. The next report compares against that exact saved state.

Export PowerPoint

Download a branded, editable 16:9 PowerPoint slide. The same report state produces the same executive facts without changing saved work.

Keep the boundary visible

The report states that execution progress does not measure security effectiveness or control performance.

Share and back up a program

Share and Export are separate actions on each saved program.

Create a read-only link

Share saves an immutable snapshot with an unguessable address, separate revocation key, and 30-day expiry.

Choose how to share

Copy the link, open another app, copy a plain-text summary, or download Markdown from the same Share dialog.

Revoke access

The browser keeps the revocation key locally so the owner can disable the current link before it expires.

Export local files

Export separately provides complete JSON, spreadsheet-ready CSV, readable Markdown, and an editable PowerPoint when reporting is supported.

Data, storage, recovery, and product feedback

Editable work remains organization-owned. Browser preferences, Share, minimized product-use events, first-party feedback, and the optional SurveyMonkey follow-up are separate data flows.

Saved work

Programs and execution state are stored in the signed-in account or selected organization workspace and remain available only to the authorized account or organization members.

Conflicting sessions

Revision checks stop an older browser session from overwriting newer saved work. The application offers a reload path when the organization record changes.

Invalid data

An invalid organization record fails safely instead of being silently replaced. Invalid imports do not change saved work.

Settings

Appearance and navigation preferences persist on this device. Account planning defaults and authorized organization overrides are account-backed. Defaults never alter an existing program.

Share snapshots

A deliberate Share action sends a sanitized immutable snapshot to bounded server storage. It expires after 30 days and can be revoked with a separate key kept in the creating browser profile.

Anonymous product-use events

Defined route, creation-stage, completion, export, and bounded error or recovery events use one random tab-session identifier. Creation attempts use a second short-lived random identifier. The event service stores only SHA-256 digests, fixed categories, and timestamps. The product-use table excludes program content, entered values, titles, saved identifiers, filenames, messages, query strings, IP addresses, and user-agent strings.

Optional first-party feedback

After an explicit program cancellation, the user can submit one fixed reason and, for Other, an optional detail of up to 180 characters. After a program is first recorded complete, the user can submit a 0–10 recommendation score. Those first-party responses contain a fixed program-family label and random tab-session digest, but no saved program title or identifier. Cancellation details never appear on Usage.

Optional detailed follow-up

After a successfully submitted score of 9 or 10, the user may open a separate SurveyMonkey survey about benefits, effort, useful capabilities, estimated time saved, and an optional quotation. The parameter-free link sends no NPS score or program data from AI Security Planner. Anything entered in that survey is submitted directly to SurveyMonkey under its service controls.

Collection choices and retention

Global Privacy Control and Do Not Track suppress passive product-use events. First-party feedback is sent only after Submit, and a five-minute cleanup cycle deletes its raw rows once they are older than 90 days. SurveyMonkey retention is separate. Usage publishes only owner-reviewed fixed aggregates and quotes with explicit quote permission; those approved public values are versioned with the product.

Public beta and measurement limits

Availability, organization storage, browser preferences, planning output, and aggregate usage each have explicit limits.

Public beta availability

The public beta can change, pause, or end and is not promised to be uninterrupted or error-free.

Browser storage

Clearing site data, changing browser profile, or losing the device can remove interface preferences and local share-revocation keys, but it does not delete organization programs. Validated JSON export remains a user-controlled backup path.

Planning limits

Forecasts are deterministic planning outputs, not delivery commitments, control tests, posture scores, professional advice, or proof of security effectiveness.

Aggregate limits

A tab session is not a person or unique visitor, and repeated or automated valid events can affect counts. A completed milestone or program means the product recorded that planning state; it does not prove control effectiveness. Recommendation scores and SurveyMonkey follow-up answers are optional self-reports, so response volume appears with the results.

Release status

Supported-browser, accessibility, localization, scale, security, exact-revision, and production-deployment evidence remain launch gates until each is closed.

Provider and organization responsibilities

Use this reference to distinguish delegated provider access from organization authority.

Provider and organization responsibility assignments
ResponsibilityProviderOrganization
Manage the provider team and service configurationProvider owner or administratorNo access
Approve, change, or revoke provider accessRequest or acknowledgeOrganization owner or administrator approves
Manage organization members and final decision authorityNo accessOrganization owner or administrator
Change the organization's identity and profileNo accessOrganization owner or administrator
Configure sites and site capacityDelegated service administratorOrganization owner or administrator
Plan and update program executionDelegated service administrator or editorOrganization owner, administrator, or editor
Approve schedule decisions and date changesPrepare a recommendation; cannot approveOrganization owner or administrator
Delete the organizationNo accessOrganization owner only