UI v2 Rewire Authority Matrix

Status: SUPERSEDED for current UI authority (2026-07-13); historical planning matrix Date: 2026-02-20

This matrix records which pack was authoritative within the historical v2 planning set. For current navigation, routes, roles, and scopes, use the direct source pointers in the directory currency notice.

A) Capability authority

Capability areaAuthoritative pack(s)Superseded packsNotes
Global IA and namingpack-23.md, pack-22.mdpack-21.md and lower for overlapsCanonical roots are Mission Control, Releases, Security, Evidence, Topology, Platform.
Dashboard mission controlpack-22.md, pack-16.mdpack-01.md, pack-04.md, pack-08.md, pack-11.mdPack 22 defines posture framing; Pack 16 keeps detailed signal cards where unchanged.
Releases lifecycle consolidationpack-22.md, pack-12.md, pack-13.md, pack-14.md, pack-17.mdStandalone lifecycle module variants in older packsRuns/deployments/promotions/hotfixes are views under Releases, not roots.
Topology inventory and setuppack-22.md, pack-18.mdPrior placements under Release Control and Platform OpsRegions/env/targets/hosts/agents/workflows/gate profiles belong to Topology.
Security consolidationpack-22.md, pack-19.mdpack-03.md, pack-07.md and split-view variantsFindings + Disposition + SBOM Explorer as consolidated IA.
Evidence and audit chainpack-22.md, pack-20.mdpack-03.md, pack-09.md, pack-11.mdEvidence must be linked from Releases and Security decisions.
Operations runtime posturepack-23.md, pack-15.md, pack-10.mdpack-03.md, pack-06.md, pack-09.md, pack-11.mdOps runs under Platform and owns runtime operability state; agents stay in Topology.
Integrations configurationpack-23.md, pack-10.md, pack-21.mdpack-02.md, pack-05.md, pack-09.mdIntegrations runs under Platform and is limited to external systems/connectors.
Administration governancepack-22.md, pack-21.mdpack-02.md, pack-05.md, pack-09.md, pack-11.mdIdentity/tenant/notification/usage/policy/system remain admin-owned under Platform -> Setup.

B) Explicit higher-pack overrides

DecisionReplaced guidanceCanonical guidance
Root domain namingDashboard, Release Control, Security & Risk, Evidence & Audit, Platform Ops, top-level AdministrationMission Control, Releases, Security, Evidence, Topology, Platform (pack-23.md)
Bundle namingBundle-first labels in packs 12/21UI term is Release Version; bundle semantics remain in data model (pack-22.md)
Lifecycle menu sprawlStandalone Promotions, Deployments, Runs, Hotfixes menusLifecycle surfaces live under Releases list/detail/activity/approvals (pack-22.md)
Region/environment nav placementDeep menu under release-control variantsGlobal context selectors + Topology inventory pages (pack-22.md)
Security navigation splitSeparate VEX, Exceptions, SBOM Graph, SBOM Lake menusConsolidated Disposition Center and SBOM surfaces (pack-22.md)
Feed and VEX source setup placementSecurity-owned advisory sources setup variantsIntegrations-owned feed/source configuration (pack-22.md)
Agent module placementPlatform Ops ownership variantsTopology -> Agents (pack-22.md)

C) Pack lifecycle classification

PackStatus for planningPrimary reason
pack-01.mdSuperseded baselineEarly drafts replaced by higher packs.
pack-02.mdSuperseded baselineEarly settings/admin/integration placement replaced.
pack-03.mdSuperseded baselineEarly security/evidence/ops model replaced.
pack-04.mdSuperseded baselineEarly release control model replaced.
pack-05.mdSuperseded baselineTransitional admin/integration moves replaced.
pack-06.mdSuperseded baselineOps structure replaced by packs 15 and 22.
pack-07.mdSuperseded baselineSecurity model replaced by packs 19 and 22.
pack-08.mdSuperseded baselineHistorical reference only.
pack-09.mdSuperseded baselineSettings migration draft replaced.
pack-10.mdActive partial authorityIntegrations/feeds/airgap detail where not overridden.
pack-11.mdSuperseded baselineReplaced by packs 12-22.
pack-12.mdActive authorityRelease composition deep specification.
pack-13.mdActive authorityPromotion flow baseline for Releases.
pack-14.mdActive authorityRun timeline/checkpoint semantics.
pack-15.mdActive authorityData Integrity operations model.
pack-16.mdActive authorityDashboard signal-level model.
pack-17.mdActive authorityApprovals detail model.
pack-18.mdActive authorityEnvironment/topology detail shell standard.
pack-19.mdActive authoritySecurity decision model details.
pack-20.mdActive authorityEvidence chain structure.
pack-21.mdActive fallback authorityPre-Pack-22 admin/integration organization details where not overridden.
pack-23.mdHighest-precedence authorityPlatform global menu with Ops/Integrations/Setup consolidation and ownership boundaries.
pack-22.mdActive authorityIA consolidation baseline and naming model before Platform delta in Pack 23.

D) Raw pack usage policy

For sprint planning, use raw packs only through this sequence:

  1. Find capability in Section A.
  2. Start with listed authoritative pack(s).
  3. Open superseded packs only for migration context or missing implementation detail.

E) UI RBAC visibility matrix

SurfacePrimary scope gate (any)Fallback/notes
Mission Control rootui.read, release:read, scanner:read, sbom:readRedirect unauthorized users to /console/profile.
Releases rootrelease:read, release:write, release:publishApprovals queue additionally expects approval/governance scopes.
Security rootscanner:read, sbom:read, advisory:read, vex:read, exception:read, findings:read, vuln:viewDisposition and SBOM tabs remain visible only when parent root is visible.
Evidence rootrelease:read, policy:audit, authority:audit.read, signer:read, vex:exportTrust mutation routes stay under Platform -> Setup.
Topology rootrelease:read, orch:read, orch:operate, ui.adminIncludes regions/env, targets/runtimes, and agent fleet.
Platform rootui.admin, orch:read, orch:operate, health:read, notify.viewerCovers ops, integrations, and setup/admin surfaces.
Legacy alias roots (/operations, /integrations, /administration, /platform-ops)Same gate as Platform rootAlias-window only; tracked by legacy_route_hit telemetry.