Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
64 commits
Select commit Hold shift + click to select a range
584f0ed
chore(release): 0.2.3-unstable.20260912202721
github-actions[bot] Sep 12, 2026
d8f63b3
Merge pull request #1025 from ConductionNL/release/v0.2.3-unstable.20…
rubenvdlinde Sep 13, 2026
e7b8cd7
chore(sync): carry beta back into development
github-actions[bot] Sep 13, 2026
e78ec44
Merge pull request #1029 from ConductionNL/sync/beta-to-development-2…
rubenvdlinde Sep 13, 2026
a8a66d0
feat(integrations): show stackiq's connections through integriq's reg…
rubenvdlinde Sep 14, 2026
7828663
fix(tests): format the connection-registry files and read info.xml as…
rubenvdlinde Sep 16, 2026
60142ce
fix(tests): initialise connectionReports on the reflection-built cont…
rubenvdlinde Sep 16, 2026
45f4d2a
fix(schemas): drop a stray licence key so the module schema imports a…
rubenvdlinde Sep 16, 2026
f66ddcf
feat(connections): federation and EOL sync read Switched off, and the…
rubenvdlinde Sep 16, 2026
07352a4
fix(e2e): find connection rows by their cell, not by an anchored row …
rubenvdlinde Sep 16, 2026
24ebea1
chore(deps-dev): bump eslint from 10.9.1 to 10.10.0 (#1047)
dependabot[bot] Sep 18, 2026
f5f9e30
chore(deps): bump zod from 4.5.4 to 4.6.5 (#1046)
dependabot[bot] Sep 18, 2026
6aa6292
chore(deps): bump gridstack from 13.2.0 to 13.3.0 (#1045)
dependabot[bot] Sep 18, 2026
0d5bf06
chore(deps): bump dexie from 4.4.5 to 4.4.6 (#1041)
dependabot[bot] Sep 18, 2026
9a70ea2
fix(routes): two entries shared a route name, so one route never regi…
rubenvdlinde Sep 19, 2026
da5c86a
chore(deps): move nextcloud-vue back to the 2.x line
rubenvdlinde Sep 22, 2026
c9760e0
Merge pull request #1070 from ConductionNL/chore/nextcloud-vue-back-t…
rubenvdlinde Sep 23, 2026
b81b532
feat(parity): start stackiq's capability matrix (work in progress)
rubenvdlinde Sep 25, 2026
67f6408
feat(parity): rate stackiq's own column from the code
rubenvdlinde Sep 25, 2026
38b9938
Merge pull request #1072 from ConductionNL/feat/parity-capability-matrix
rubenvdlinde Sep 25, 2026
22466d6
fix(parity): apply cross-lane corrections to the capability matrix
rubenvdlinde Sep 26, 2026
b8e7db0
Merge pull request #1088 from ConductionNL/fix/parity-cross-lane-corr…
rubenvdlinde Sep 26, 2026
511d78e
chore(parity): fold r-glpi packs 1-2 (GLPI source read at 11.0.9)
rubenvdlinde Sep 26, 2026
913f72f
chore(parity): fold r-glpi packs 3-7 and errata
rubenvdlinde Sep 26, 2026
f46affc
chore(parity): fold r-docs-a (VNG Softwarecatalogus and TOPdesk, publ…
rubenvdlinde Sep 26, 2026
cca6e68
chore(parity): apply r-glpi errata, land-demo-data no to partial
rubenvdlinde Sep 26, 2026
ca32289
chore(parity): record the GLPI 11.0.9 lab drive on 26 cells
rubenvdlinde Sep 26, 2026
5c52326
chore(parity): glpi driven at 11.0.9, VNG and TOPdesk read 2026-09-26…
rubenvdlinde Sep 26, 2026
2540bde
feat(parity): 31 demand rows mined from tenders, feature requests, ro…
rubenvdlinde Sep 26, 2026
5e4f50b
chore(parity): back-fill VNG and TOPdesk on the 31 demand rows
rubenvdlinde Sep 26, 2026
69ef74e
chore(parity): back-fill GLPI on the demand rows from source at 11.0.9
rubenvdlinde Sep 26, 2026
4d6fb66
feat(parity): LeanIX and BlueDolphin read 2026-09-26, 11 more demand …
rubenvdlinde Sep 26, 2026
1a807f8
chore(parity): batch-2 back-fill VNG and TOPdesk
rubenvdlinde Sep 26, 2026
e331962
chore(parity): batch-2 back-fill GLPI
rubenvdlinde Sep 26, 2026
86c5c6a
Merge pull request #1090 from ConductionNL/parity/wave5-competitor-so…
rubenvdlinde Sep 26, 2026
49e65cb
chore(deps): move @conduction/nextcloud-vue to 2.57.1 (Dexie loads on…
rubenvdlinde Sep 27, 2026
9a5ece6
docs(openspec): OpenSpec pass batch 1, landscape and connections chan…
rubenvdlinde Sep 27, 2026
e2d38aa
docs(openspec): OpenSpec pass batch 2, architecture and lifecycle cha…
rubenvdlinde Sep 27, 2026
a0afae7
docs(openspec): OpenSpec pass batch 3, contracts, insight, operations…
rubenvdlinde Sep 27, 2026
d22033a
docs(parity): set 5 sibling rows from the OpenSpec pass (#1143)
rubenvdlinde Sep 28, 2026
7ca2cc0
docs(parity): corrections round 8, 7 rows re-read against their issue…
rubenvdlinde Sep 28, 2026
cab7bc3
fix(settings): read the saved organisation admin groups back (#1136) …
rubenvdlinde Sep 28, 2026
d4566ec
fix(views): read a single view with OpenRegister's checks on, and sco…
rubenvdlinde Sep 28, 2026
1103ab8
fix(roles): map the English organisation types to role groups (#1137)…
rubenvdlinde Sep 28, 2026
c04511f
fix(progress): keep operation progress in the distributed cache, read…
rubenvdlinde Sep 28, 2026
2666a36
fix(register): lifecycle states of four schemas use the enum values (…
rubenvdlinde Sep 28, 2026
f11a407
fix(facets): the domain facet reads the element's declared domein pro…
rubenvdlinde Sep 28, 2026
a0dd1b2
fix(archimate): remove the round-trip test endpoint any signed-in use…
rubenvdlinde Sep 28, 2026
1bca4d7
fix(sync): the organisation contact sync job honours its enabled swit…
rubenvdlinde Sep 28, 2026
52559fc
fix(merge): a merged-away supplier's applications and services move t…
rubenvdlinde Sep 28, 2026
ac51298
fix(openspec): drop the empty delta headers from org-archimate-export…
rubenvdlinde Sep 28, 2026
855dca2
test(openspec): match delta headers case-insensitively, as openspec d…
rubenvdlinde Sep 28, 2026
252dd05
fix(a11y): the selected objects list honours reduced motion for move …
rubenvdlinde Sep 29, 2026
d19bbc4
docs(parity): decide the 25 open stackiq rows, specify the import pro…
rubenvdlinde Sep 29, 2026
d9b52f6
feat(archimate): follow a running ArchiMate import and cancel it (#1175)
rubenvdlinde Sep 29, 2026
72754a7
feat(applications): open an application from the list and see its usa…
rubenvdlinde Sep 29, 2026
c6ebcd3
feat(connections): browse and open connections, and see them on the a…
rubenvdlinde Sep 29, 2026
dcb6403
test(connections): seed the contacts uid from a crypto UUID, not the …
rubenvdlinde Sep 29, 2026
1edd2ba
fix(organisations): the concept organisations widget lists draft orga…
rubenvdlinde Sep 29, 2026
ba60bb1
feat(contracts): record licences bought and in use, and see where use…
rubenvdlinde Sep 29, 2026
f280e80
feat(ai-systems): register the AI systems you use and see the high-ri…
rubenvdlinde Sep 29, 2026
a4a28c4
feat(usages): record the applications your organisation uses, with ve…
rubenvdlinde Sep 29, 2026
100db8c
feat(maintenance): follow planned maintenance on the applications you…
rubenvdlinde Sep 29, 2026
f262512
feat(portfolio): score the applications you use on value, fit and ris…
rubenvdlinde Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
9 changes: 8 additions & 1 deletion .github/workflows/code-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -158,7 +158,14 @@ jobs:
# object API directly (tests/e2e/workflows/_fixtures.ts), so testing
# against `main` measures a different backend than the one this app is
# written for. Pinned to `development` to match.
additional-apps: '[{"repo":"ConductionNL/openregister","app":"openregister","ref":"development"}]'
#
# integriq is here because the Integrations page reads integriq's
# `app_connection` rows (adopt-connection-registry). Without it the page
# shows the missing-dependency screen and
# `tests/e2e/workflows/integrations-page.spec.ts` fails on every run.
# `app` is `integriq`, verified in its appinfo/info.xml on `development`
# on 2026-09-14.
additional-apps: '[{"repo":"ConductionNL/openregister","app":"openregister","ref":"development"},{"repo":"ConductionNL/integriq","app":"integriq","ref":"development"}]'
# Newman disabled: tests/magic-mapper-import.postman_collection.json was
# written against a dev env with URL rewriting + a fixed disk layout — it
# hits bare paths like `/configurations` and uploads files from
Expand Down
2 changes: 1 addition & 1 deletion appinfo/info.xml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Vrij en open source onder de EUPL-licentie.

**Ondersteuning:** Voor ondersteuning, neem contact op via support@conduction.nl. Voor een Service Level Agreement (SLA), neem contact op via sales@conduction.nl.
]]></description>
<version>0.2.2-unstable.20260910105110</version>
<version>0.2.3-unstable.20260912202721</version>
<licence>EUPL-1.2</licence>
<author mail="info@conduction.nl" homepage="https://www.conduction.nl/">Conduction</author>
<namespace>Stackiq</namespace>
Expand Down
9 changes: 6 additions & 3 deletions appinfo/routes.php
Original file line number Diff line number Diff line change
Expand Up @@ -104,8 +104,6 @@
['name' => 'settings#killArchiMateImport', 'url' => '/api/archimate/import/kill', 'verb' => 'POST'], // deprecated
['name' => 'settings#clearArchiMateExportStatus', 'url' => '/api/archimate/status/export/clear', 'verb' => 'POST'],

['name' => 'settings#testArchiMateRoundTrip', 'url' => '/api/archimate/test-round-trip', 'verb' => 'POST'],

// User Groups management routes
['name' => 'settings#getGenericUserGroups', 'url' => '/api/settings/user-groups/generic', 'verb' => 'GET'],
['name' => 'settings#setGenericUserGroups', 'url' => '/api/settings/user-groups/generic', 'verb' => 'POST'],
Expand All @@ -126,7 +124,12 @@
// ArchiMate focused endpoints
['name' => 'settings#getArchiMateConfig', 'url' => '/api/archimate/config', 'verb' => 'GET'],
['name' => 'settings#updateArchiMateConfig', 'url' => '/api/archimate/config', 'verb' => 'POST'],
['name' => 'settings#getArchiMateConfig', 'url' => '/api/archimate/status', 'verb' => 'GET'],
// A route name carries no URL, so without a 'postfix' this entry and the
// GET '/api/archimate/config' one above register under the same name and
// only the last declared survives. This one won on line order, which left
// the config read a 404 and made the store's polling endpoint depend on
// nothing but the order of these two lines.
['name' => 'settings#getArchiMateConfig', 'url' => '/api/archimate/status', 'verb' => 'GET', 'postfix' => 'Status'],

// Email focused endpoints
['name' => 'settings#getEmailConfig', 'url' => '/api/email/config', 'verb' => 'GET'],
Expand Down
2 changes: 1 addition & 1 deletion composer.json
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@
"phpmetrics:violations": "./vendor/bin/phpmetrics --violations-xml=phpmetrics/violations.xml lib/",
"psalm": "if [ -f vendor/bin/psalm ]; then ./vendor/bin/psalm --threads=1 --no-cache --memory-limit=2G; else echo 'Psalm not installed, skipping...'; fi",
"phpstan": "if [ -f vendor/bin/phpstan ]; then ./vendor/bin/phpstan analyse --memory-limit=1G; else echo 'PHPStan not installed, skipping...'; fi",
"test:unit": "phpunit tests -c tests/phpunit.xml --colors=always --fail-on-warning --fail-on-risky",
"test:unit": "phpunit -c phpunit-unit.xml --colors=always --fail-on-warning --fail-on-risky",
"test:all": "if [ ! -f vendor/bin/phpunit ]; then echo 'SKIPPED: phpunit not installed - run composer install'; elif [ ! -f ../../lib/base.php ]; then echo 'SKIPPED: tests/bootstrap.php requires a Nextcloud server tree (../../lib/base.php not found) - run from inside a Nextcloud checkout or in CI'; else ./vendor/bin/phpunit --colors=always; fi",
"check": "E=0; for CMD in lint phpcs psalm test:unit; do echo; echo \"=== $CMD ===\"; composer $CMD || E=1; done; echo; if [ $E -eq 0 ]; then echo \"ALL CHECKS PASSED\"; else echo \"SOME CHECKS FAILED (see above)\"; fi; exit $E",
"check:full": "E=0; for CMD in lint phpcs psalm phpstan test:all; do echo; echo \"=== $CMD ===\"; composer $CMD || E=1; done; echo; if [ $E -eq 0 ]; then echo \"ALL CHECKS PASSED\"; else echo \"SOME CHECKS FAILED (see above)\"; fi; exit $E",
Expand Down
45 changes: 45 additions & 0 deletions docs/features/ai-systems.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# AI systems

An AI system is an AI agent, an AI model or an AI feature that your organisation uses. You register it next to the application it runs in, classify it under the EU AI Act, and keep the documents the act asks for.

Specification: [`openspec/specs/ai-system-inventory/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/ai-system-inventory/spec.md).

## Registering an AI system

Open **Applications** in the navigation menu, then **AI systems**, and click **Add**. Fill in:

- **Name** and **Description**.
- **Kind**: an AI agent acts on its own, an AI model is a trained model, an AI feature is part of an application.
- **Application**: the application it runs in or supports.
- **Supplier** and **Purpose**: who supplies it and what it decides, recommends or produces.

The page of the application shows its AI systems in the **AI systems** section.

## Classifying it under the AI Act

Each AI system records:

- **AI Act risk category**: prohibited, high risk, limited risk, minimal risk, or not yet assessed. A new system starts as not yet assessed.
- **Role under the AI Act**: provider or deployer.
- **Last assessed on** and the **Algorithm register entry**, the link to the system in the Dutch algorithm register.

The category is your organisation's own classification. Stackiq records it; it does not decide it.

## Evidence

Attach documents to the AI system under **Documents** and tag each one: FRIA (fundamental rights impact assessment), Technical documentation, Human oversight or Logging. The **AI Act evidence** panel on the page lists the four tags and shows which have a document.

Fill in **Fundamental rights impact assessment** with a reference to the FRIA. A high-risk AI system without one:

- reads **FRIA missing** in the list,
- shows a warning on its page,
- and appears under the **High risk without FRIA** filter above the list.

The other filters above the list select one risk category each.

Screenshots follow once the feature runs on the demo instance.
29 changes: 29 additions & 0 deletions docs/features/application-page.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# The application page

One page per application shows what the catalogue knows about it: its data, the organisations that use it, its versions, its compliance claims and the contracts behind it.

Specification: [`openspec/specs/application-page/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/application-page/spec.md).

## Opening the page

Open **Applications** from the navigation menu and click a row, or use the **View** action on it. The page opens at `/modules/<id>`. The page also opens from an organisation's list of applications.

## What the page shows

- **Application**: the name, the short and long description, the website, the supplier, the supplier's contact person for this product, and the hosting, licence, BBN and DPIA fields.
- **Documentation**: files attached to the application.
- **Vendor and services**: the supplier and the services and connections linked to the application.
- **Application versions**: every registered version with its status. A row opens the version.
- **Usages**: every organisation that registered a usage of the application, with the version it uses and the status of that usage. You see the usages you may read: a municipality sees its own, a supplier sees the usages of its products.
- **Compliance claims**: the standards and BIO measures the application claims, with the evidence. A row opens the claim.
- **Contracts**: every contract on a usage of the application, and every contract on a service that offers it, each listed once, with its number, type, end date and status. A row opens the contract. You see only the contracts you may read.
- **Reviews**: ratings and reviews of the application.

## Why a contract shows up here

A contract in stackiq belongs to a usage and a service, not to the application directly. The page follows both links: a contract appears when its usage is a usage of this application, or when its service offers this application.
38 changes: 38 additions & 0 deletions docs/features/applications-in-use.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# Applications in use

An application in use records that your organisation uses an application: which version it runs, where it stands in its lifecycle, and who owns it on the business side and on the technical side. The portfolio views, the lifecycle roadmap and the end-of-support warnings all start from these records.

Specification: [`openspec/specs/application-usage-pages/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/application-usage-pages/spec.md).

## Adding an application to your landscape

Open the application's page under **Applications** and click **Add to our landscape** in the usages section. The application is already filled in. Pick:

- **Consumer**: your organisation.
- **Version**: the version you run. The list only offers versions of this application.
- **Status**: Acquisition, Planned, In production, To be phased out or Phased out.
- **Business owner** and **Technical owner**: contact persons of your organisation.

## Browsing what you use

Open **Applications** in the navigation menu, then **Applications in use**. The list shows each application with its version, status, owners and TIME classification. The tabs above the list filter on status. Your organisation's page lists the same records under **Applications in use**.

## Moving through the lifecycle

Open an application in use. The actions at the top follow its status:

- **Plan** moves Acquisition to Planned.
- **Go live** moves Planned to In production.
- **Phase out** moves In production to To be phased out.
- **Retire** moves To be phased out to Phased out.

Every change is kept in the **History** tab.

## Who sees the owners

The owners are contact persons of the organisation that uses the application. A supplier can read the usages of its own products, but it cannot open the contact persons of its customers.
32 changes: 32 additions & 0 deletions docs/features/connections.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# Connections

A connection records that one application exchanges data with another application, or with a national provision such as a basisregistratie: over which transport, in which direction, and in which state.

Specification: [`openspec/specs/catalogue-connection-pages/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/catalogue-connection-pages/spec.md).

## The connections list

Open **Applications** in the navigation menu, then **Connections**. The list at `/koppelingen` shows every connection you may read, with its type, its status, both applications, the national provision and the direction.

- The chips above the list filter on status: in use, in development, end of support and withdrawn.
- The filter menu in the table header filters on type (for example api or file transfer), status and direction.
- Click a row to open the connection.

You see the connections of your own organisation, and the connections that are published.

## A connection's page

The page shows the connection's data, both applications, the national provision and the intermediary application if there is one, the lifecycle dates, attached documents, and its history.

The actions at the top move a connection through its lifecycle: release (in development to in use), sunset (in use to end of support) and withdraw (to withdrawn).

When you record a connection to a national provision, the picker lists the GEMMA elements of type Buitengemeentelijke voorziening.

## Connections on the application page

The page of an application has two lists: **Connections from this application**, where it is application A, and **Connections to this application**, where it is application B. Each row opens the connection, and View all opens the connections list filtered on that application.
39 changes: 39 additions & 0 deletions docs/features/licence-seats.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# Licence seats

A licence contract records how the licence is measured and how many licences were bought and are in use. Stackiq sets the two numbers against each other on the contract and on the License posture page, so you see where use runs over what was bought.

Specification: [`openspec/specs/licence-seats/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/licence-seats/spec.md).

## Recording the licence on a contract

Open a contract and edit it. Three fields describe the licence:

- **Licence metric**: per named user, per concurrent user, per device, per inhabitant, per organisation, or other.
- **Licences bought**: the number the contract pays for.
- **Licences in use**: the number in use today.

All three are optional. A count cannot be negative.

## The licences panel on a contract

The contract page shows a **Licences** panel with the metric, both counts, a bar of in use against bought, and one of these states:

- **Within licence**: in use is at or below bought.
- **Over licence by N**: in use is N above bought. The bar turns red.
- **Unknown**: one of the counts is empty.
- **Not counted**: the metric is per organisation or other, so there is nothing to count and no bar.

The panel also shows the date the contract was last changed, so you can judge how current the count is.

## The Seats section on the License posture page

Open **License posture** in the navigation menu. The **Seats** section has one row per contract with a counted metric and a number of licences bought. Each row names the application, the organisation, the metric, bought, in use and the state. Contracts over their licence come first, the furthest over at the top.

You see the contracts you may read; the section uses the same access rules as the rest of the page.

Screenshots of the panel and the section follow once the feature runs on the demo instance.
35 changes: 35 additions & 0 deletions docs/features/maintenance-and-roadmap.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# Maintenance and roadmap

Suppliers announce planned maintenance on their applications and publish where each application is heading. Organisations that use an application see the maintenance on their dashboard and on the application's page, and read the roadmap before they plan an upgrade.

Specification: [`openspec/specs/maintenance-and-supplier-roadmap/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/maintenance-and-supplier-roadmap/spec.md).

## Announcing maintenance

Open your application's page under **Applications** and click **Announce maintenance** in the **Planned maintenance** section. Fill in:

- **Title** and **Description**: what happens and what users should do.
- **Version**: only when the maintenance concerns one version.
- **Starts at** and **Ends at**.
- **Impact**: No impact, Degraded or Unavailable.

A new window starts as Planned. From its page you move it to In progress, Completed or Cancelled.

## Who is told

When you announce a window, stackiq looks up every organisation that uses the application and the business owner and technical owner of each usage. Those owners get a Nextcloud notification, and a reminder the day before the window starts while it is still planned. Owners are set on the usage, under **Applications in use**; a usage without owners still shows the window on its organisation's dashboard.

## Following maintenance

The dashboard lists **Planned maintenance** on the applications your organisation uses in the next 30 days, with the time window and the impact. Each application's page lists all its planned maintenance.

## The roadmap

A supplier writes the direction of an application in the **Roadmap** field of the application. The application's page shows it with the application's versions on a timeline, the planned versions first. A version is placed on its go-live date, or on the date development started when it has no go-live date yet.

Under **Module versions**, the **Planned releases** tab lists the versions still in development, with the date development started. A supplier releases a planned version from its page with **Release**.
44 changes: 44 additions & 0 deletions docs/features/portfolio-value-assessment.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
<!--
- SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl>
- SPDX-License-Identifier: EUPL-1.2
-->

# Value assessment

An information manager scores each application the organisation uses on business value, technical fit and risk. The scores sit next to the cost stackiq already adds up from contracts, and they point to a TIME class. The TIME class the organisation records stays the decision: the scores back it up or question it, they never change it.

Specification: [`openspec/specs/application-value-assessment/spec.md`](https://github.com/ConductionNL/stackiq/blob/development/openspec/specs/application-value-assessment/spec.md).

## Scoring an application

Open the application under **Applications in use** and edit it. Fill in:

- **Business value**: how much the organisation depends on it, from 1 (little) to 5 (critical).
- **Technical fit**: how well it fits the architecture and the standards the organisation follows, from 1 (poor) to 5 (good).
- **Risk**: the risk the organisation sees in running it, from 1 (low) to 5 (high).
- **Scored on**: the date you set the scores.

When you save, stackiq fills in **Suggested TIME classification**:

| Business value | Technical fit | Suggested class |
|---|---|---|
| 3 or more | 3 or more | Invest |
| 3 or more | below 3 | Migrate |
| below 3 | 3 or more | Tolerate |
| below 3 | below 3 | Eliminate |

While either score is missing there is no suggestion. The **Value assessment** section of the page shows the scores, the recorded TIME class and the suggestion side by side.

## Risk signals

Below the data of the page, **Risk signals** shows what backs a risk score: whether the version you run is past its end of support (or withdrawn), and how many known vulnerabilities are linked to the application. You set the risk score yourself; the signals only inform it.

## The portfolio report

The portfolio report (**Reports**, then **Portfolio rationalization**) adds, for the organisation you select:

- **Business value against technical fit**: one circle per scored application, its size the annualised cost. The circle's colour is the suggested class; a dark ring marks a recorded class that differs from the scores. Applications without both scores are counted below the chart.
- Two columns in the table: **Suggested by scores** and **Value / fit / risk**.
- The switch **Recorded class differs from scores**, which lists only the applications whose recorded class and suggestion disagree.

The CSV export carries the columns businessValue, technicalFit, riskScore, scoredOn, suggestedTimeClassification and timeMismatch.
2 changes: 1 addition & 1 deletion eslint-suppressions.json
Original file line number Diff line number Diff line change
Expand Up @@ -388,7 +388,7 @@
},
"src/store/modules/settings.js": {
"no-console": {
"count": 18
"count": 17
},
"no-unused-vars": {
"count": 8
Expand Down
Loading
Loading