Specifications

How AI Security Planner turns a few planning assumptions into a consistent roadmap, saves work, and produces reports and exports.

How a plan moves through the product
InputsPlanning assumptions

Dates, organization size, delivery capacity, existing foundations, and a source-backed program.

PlanDependency-aware scheduling

Fixed rules sequence effort against capacity, dependencies, progress, and saved date changes.

OutputsRoadmap, report, and exports

Every view reads the same saved program; sharing creates a separate read-only snapshot.

What runs where

Editable work is saved to the signed-in account or selected organization. Only an explicit Share action creates a separate, expiring read-only copy.

Planning runs in the browser

Planning, forecasting, reporting, import, export, and PowerPoint generation run on the current device; authorized saved state is written to the signed-in account or selected organization workspace.

Sharing is deliberate

The share service stores only the bounded, expiring, read-only snapshot created when a user chooses Share.

No artificial-intelligence processing

Results come from fixed program data and repeatable rules. The product sends no prompt, model request, research request, or automated translation.

How plans are built

Source-backed program packages and one scheduling method produce a roadmap that can be inspected and repeated.

Source-backed program packages

Five fixed programs, one custom program, and legacy Endpoint compatibility provide stable sources, effort, dependencies, roles, outcomes, and finish conditions.

Repeatable scheduling

Dependency order, capacity, effort, priority, saved dates, and progress drive every forecast without hidden optimization.

Cross-program portfolio

Portfolio derives schedule position, progress, blockers, critical paths, target dates, and next actions from saved programs without copying or mutating them.

One saved program, every view

Overview, List, Kanban, Gantt, PERT, Burndown, Burnup, inspectors, and reports all read the same active program.

How work is saved and moved

Programs remain separate in their account or organization workspace, while explicit files provide user-controlled backup and transfer.

Separate saved programs

The current account or organization workspace stores one independent execution for each program and preserves the last valid revision if a save fails.

Protection from stale sessions

Revision checks stop an older session from replacing newer organization work and identify the changed record before another write.

User-controlled files

JSON export includes the complete checked project and a checksum. CSV and Markdown exports neutralize active spreadsheet or markup content.

How reports stay consistent

Reports and visual exports use the same saved program and never change it.

Saved comparison points

A reporting snapshot preserves the exact inputs, progress, saved dates, notes, program package, and report content used for the next comparison.

Editable PowerPoint

The exporter creates one branded 16:9 slide with editable text, the exact logo, stable geometry, and source notes.

Complete roadmap images

Gantt and PERT PNG exports include the complete chart rather than only the visible scroll position.

How delegated access is enforced

Provider access is limited by the signed-in provider role, an active organization delegation, and the selected organization.

Every provider action needs two grants

The provider role and the organization delegation must both allow an action. A missing, revoked, or mismatched delegation denies access.

Organization authority stays with the organization

Provider roles cannot manage organization members, approve organization decisions, change provider access, change the organization profile, or delete the organization.

The server enforces the boundary

Authorization checks the provider, organization, delegation status, delegated role, and requested action. Hiding a control in the interface is not treated as authorization.

What must pass before release

Automated tests protect repeatable behavior; browser, accessibility, language, and deployment checks complete the release evidence.

Automated product checks

Acceptance tests cover creation, editing, saving, import and export, reporting, roadmap views, PowerPoint output, and recovery.

Accessibility target

The release target is WCAG 2.2 Level AA with keyboard, focus, semantics, contrast, reflow, zoom, touch, and screen-reader evidence.

Manual release checks

Seven locale packages, Arabic right-to-left behavior, supported browsers, manual accessibility evidence, deployment headers, and exact production mapping remain release gates.