Skip to main content

Documentation coverage map

This map covers every discovered backend top-level internal package, every executable, every agent package, and all canonical schema families at the source baseline. It is a maintenance inventory, not a claim that planned components are implemented.

Backend owners

Package / ownerCanonical guide
cmdbackend/services
ingest, agentidentityingestion/gateway
brokerevent-pipeline/streaming
event, protocolcontracts/event-model
analysis, detectiondetection/overview
detectionstatearchitecture/state-correctness
rulefiledetection/rules
ruleset, sigmadetection/rulesets
alert, alertfile, alertstorecorrelation/alerts
incidentcorrelation/incidents
inventory, inventorystoreinventory/overview
vulnerability, advisoryfeed, advisorystore, osvvulnerability-management/overview
clickhouse, postgres, eventstore, detectionstorestorage/ownership
authz, policyfilesecurity/authentication
agent, pki, devpkisecurity/enrollment
controlapi/overview
huntapi/hunting
platformobservability/health

Executables

advisory-importer, advisory-writer, alert-writer, analysis-engine, backbone-migrator, control-api, control-migrator, detection-writer, event-writer, ingest-gateway, inventory-projector, query-api, store-migrator. Each is described in service responsibilities and has a configuration reference.

Agent packages

PackageGuide
runtimeAgent runtime
modulesAgent collectors
configAgent configuration
identityAgent identity
pkiAgent keys
protocolAgent compatibility
secretsAgent diagnostics
platform/filesAgent identity
platform/privilegesAgent privileges
platform/dumpsAgent diagnostics

Remaining domains

All twelve schema families appear in contracts. All 28 backend ADRs appear under Architecture → Decisions. Every SQL migration is included in the storage reference. Runtime metric declarations appear in metrics.

Installation, Docker/deployment, PKI, threat modeling, data ownership, configuration, troubleshooting, tests, CI, contribution, and status each have explicit sections. Native agent packaging, heartbeat, secure updates, SCA/FIM/process/network collectors, vulnerability matching, and V2 frontend architecture are documented as targets. No unsupported operational command is supplied to fill those gaps.