Specifications
How AI Security Planner turns a few planning assumptions into a consistent roadmap, saves work, and produces reports and exports.
Dates, organization size, delivery capacity, existing foundations, and a source-backed program.
Fixed rules sequence effort against capacity, dependencies, progress, and saved date changes.
Every view reads the same saved program; sharing creates a separate read-only snapshot.
What runs where
Editable work is saved to the signed-in account or selected organization. Only an explicit Share action creates a separate, expiring read-only copy.
Planning runs in the browser
Planning, forecasting, reporting, import, export, and PowerPoint generation run on the current device; authorized saved state is written to the signed-in account or selected organization workspace.
Sharing is deliberate
The share service stores only the bounded, expiring, read-only snapshot created when a user chooses Share.
No artificial-intelligence processing
Results come from fixed program data and repeatable rules. The product sends no prompt, model request, research request, or automated translation.
How plans are built
Source-backed program packages and one scheduling method produce a roadmap that can be inspected and repeated.
Source-backed program packages
Five fixed programs, one custom program, and legacy Endpoint compatibility provide stable sources, effort, dependencies, roles, outcomes, and finish conditions.
Repeatable scheduling
Dependency order, capacity, effort, priority, saved dates, and progress drive every forecast without hidden optimization.
Cross-program portfolio
Portfolio derives schedule position, progress, blockers, critical paths, target dates, and next actions from saved programs without copying or mutating them.
One saved program, every view
Overview, List, Kanban, Gantt, PERT, Burndown, Burnup, inspectors, and reports all read the same active program.
How work is saved and moved
Programs remain separate in their account or organization workspace, while explicit files provide user-controlled backup and transfer.
Separate saved programs
The current account or organization workspace stores one independent execution for each program and preserves the last valid revision if a save fails.
Protection from stale sessions
Revision checks stop an older session from replacing newer organization work and identify the changed record before another write.
User-controlled files
JSON export includes the complete checked project and a checksum. CSV and Markdown exports neutralize active spreadsheet or markup content.
How reports stay consistent
Reports and visual exports use the same saved program and never change it.
Saved comparison points
A reporting snapshot preserves the exact inputs, progress, saved dates, notes, program package, and report content used for the next comparison.
Editable PowerPoint
The exporter creates one branded 16:9 slide with editable text, the exact logo, stable geometry, and source notes.
Complete roadmap images
Gantt and PERT PNG exports include the complete chart rather than only the visible scroll position.
How delegated access is enforced
Provider access is limited by the signed-in provider role, an active organization delegation, and the selected organization.
Every provider action needs two grants
The provider role and the organization delegation must both allow an action. A missing, revoked, or mismatched delegation denies access.
Organization authority stays with the organization
Provider roles cannot manage organization members, approve organization decisions, change provider access, change the organization profile, or delete the organization.
The server enforces the boundary
Authorization checks the provider, organization, delegation status, delegated role, and requested action. Hiding a control in the interface is not treated as authorization.
What must pass before release
Automated tests protect repeatable behavior; browser, accessibility, language, and deployment checks complete the release evidence.
Automated product checks
Acceptance tests cover creation, editing, saving, import and export, reporting, roadmap views, PowerPoint output, and recovery.
Accessibility target
The release target is WCAG 2.2 Level AA with keyboard, focus, semantics, contrast, reflow, zoom, touch, and screen-reader evidence.
Manual release checks
Seven locale packages, Arabic right-to-left behavior, supported browsers, manual accessibility evidence, deployment headers, and exact production mapping remain release gates.

