Field Engagement Playbook: Windows and macOS Coverage
Audience: field engineers, sales engineering, and customer-facing operators fielding Windows/macOS coverage questions about the Stella Ops Scanner.
This playbook helps field teams answer Windows and macOS coverage questions accurately — grounding the conversation in shipped capability and design intent, without drifting into speculative promises or date commitments.
1) Current scope (baseline)
- Scanner targets deterministic container-image workflows first (Linux-focused).
- Windows and macOS analyzers are design-tracked and should be discussed as “in discovery/design” unless a specific sprint or feature flag says otherwise.
2) Operator talking points
- Determinism and offline parity are non-negotiable: any Windows/macOS expansion must keep fixtures, ordering, hashing, and Offline Kit flows reproducible.
- Coverage work is split into:
- Scanner analyzers (collection and parsing),
- Policy predicates (trust/verification rules),
- Offline Kit packaging (feeds, certificates, mirrors, and deterministic indexes).
3) Where to point people
- Design briefs:
- Deep dives and research notes:
deep-dives/windows.mddeep-dives/macos.md- Demand capture:
windows-macos-demand.md
- Policy readiness notes:
4) Signal capture workflow
- Capture requirements using the interview template.
- Append a structured summary to the demand log.
- If the signal implies policy or security decisions (signature verification, trust roots, masking/telemetry), update the relevant readiness notes and reference the demand entry.
- Share the updated demand entry with the Scanner and Policy guilds in the next sync.
5) FAQ snippets
- When will Windows/macOS be GA? Demand- and evidence-driven; avoid date promises. Point to the design briefs and deep dives for the current state.
- Can we run scans offline? Offline parity is required; any OS expansion must include an Offline Kit story (feeds, trust roots, deterministic indexes).
- Do we cover Authenticode/notarization? Treat as a policy/security decision captured in the readiness notes, not an implicit feature promise.
