Product roadmap
PolicyWatcher includes goal-driven evidence workspaces in addition to static dashboard views. Workspace configuration records the user objective, requested evidence depth and modules that remain unavailable until source requirements are met.
Technical baseline
Ten evidence-backed module checks separate shipped capability from architectural opportunity. References point to the implementation inspected for this snapshot.
Five-step cascade: direct, HTTP/2, Renderer, Wayback and Common Crawl.
The mass scan loop is still sequential; move long-running work behind a durable queue.
scraper.ts · cron/check-all/route.tsStructured output is schema-validated; Beta 42 includes a golden set and AI telemetry.
The model produces the score. Input is capped at 45,000 characters or 22,000 + 22,000, not scored by a deterministic formula.
gemini.ts · geminiPolicySchema.ts · golden-set.v1.jsonSQLite backs 31 Prisma models, including five additive canonical evidence models; AI telemetry and access logs have a 90-day retention policy.
Canonical backfill is not active and PolicyCheckLog has no explicit retention policy.
prisma/schema.prisma · aiTelemetry.tsSigned sessions and roles are present.
Credentials are shared by role, with no individual identity or central revocation; rate state remains in memory.
adminAuth.ts · rateLimit.tsDashboardClient is about 3,181 lines and 125 KB; the public “map” is an impact matrix.
Decompose and measure the bundle; add true geography and regional filtering only where supported by data.
DashboardClient.tsx · ReleaseImpactMap.tsxv1 and v2 are not symmetrical; a persistent outbox and signed delivery headers already exist.
The worker still depends on application invocation. Actual headers use the PolicyWatcher-* prefix.
webhookDelivery.ts · webhookDeliveryData.tsactiveTab enables local selection/page analysis and up to three evidence summaries.
The companion does not display KPI values or a policy score.
browser-extension/popup.jsThe Agent uses HMAC, timestamp and nonce; the Renderer uses Bearer auth with two-secret rotation.
Keep release and readiness evidence bounded and observable across both services.
api/admin/vps-services · vps-agent/agent.mjsJSON and PDF exports include SHA-256 integrity material.
Packets lack a digital signature, complete diff and archive timestamp.
evidencePacket.tsUser templates are English-only; newsroom RSS and JSON Feed already exist.
Unsubscribe is client-confirmed rather than one-click, and bounce suppression is not implemented.
press-kit/feed.xml/route.ts · email templatesPriority pipeline
This ordered pipeline is the committed prioritization lens. The feature radar remains a separate, unprioritized candidate backlog.
- Now
Durable queue for asynchronous workloads
Expected outcomeScraping, webhooks and email run as persistent jobs with retry, backoff, idempotency and a dead-letter queue.
Dependency / gateCompletion and retry metrics are visible; recovery is tested.
- Now
Source-bound RAG and governed scoring
Expected outcomeChunking and source-anchored citations cover every KPI; scoring is deterministic only when presented as such, otherwise explicitly AI-generated.
Dependency / gateGolden-set quality and claim-to-evidence traceability pass review.
- Next
Individual enterprise identity
Expected outcomeOIDC, MFA, session revocation and per-user audit records replace role-shared attribution.
Dependency / gateNo admin action is attributable only to a shared role.
- Next
Modular, measured dashboard
Expected outcomeDashboardClient is decomposed, secondary surfaces are lazy-loaded and bundle changes are measured; geography follows actual data coverage.
Dependency / gateA bundle budget and responsive tests pass before release.
- Next
Hardened webhook egress and scheduling
Expected outcomeDNS pinning and rebinding protection align webhook SSRF policy with acquisition; scheduling no longer depends on app cron.
Dependency / gateRedirect/DNS tests and an independent scheduler healthcheck pass.
- Next
Email deliverability and consent
Expected outcomeProvider events drive bounce/complaint suppression and true RFC 8058 one-click unsubscribe while preserving granular preferences.
Dependency / gateProvider events and the suppression list are auditable.
- Conditional
PostgreSQL and object storage when needed
Expected outcomePersistence moves only when deployment is genuinely multi-instance, with an attachment strategy and tested backup/restore.
Dependency / gateThe operational requirement and a restore drill are documented first.
- Conditional
High-assurance evidence export
Expected outcomePackets include complete diff and archive timestamp; PDF signing and multiple renderers follow stable queue and storage foundations.
Dependency / gateSignature verification and reproducible rendering pass.
Explore the adaptive workspaceOptional product demonstrator, collapsed to keep community signals first.
Workspace configuration
PolicyWatcher retains a guided start for first-time visitors. The selected purpose and evidence depth compose a preview from registered dashboard modules; the choice stays reversible and Source QA remains pinned in every generated stack.
For audit or publication. The UI exposes retrieval path, hashes, timestamps, source drift, and known limitations.
Change summary
A low-noise reading mode focused on policy changes, plain-language summaries, affected rights, and what should be verified at the source.
Review delivered releases and impact evidenceVersion history and the full release-impact map.
Delivered releases
The voted outcomes are now shipped alongside the active Confidence work, with acceptance criteria and publication boundaries kept visible.
AI Discoverability and Citation Readiness
Align visible homepage content, canonical social metadata, structured identity and crawler access around the public evidence boundary.
- Benefit
- Readers, search engines and AI assistants receive the same server-rendered topic, evidence path and citation context.
- Validation
- Live crawler admission, indexing and citation remain external outcomes that require post-deploy verification.
PolicyWatcher Civico
Turn eligible public policy changes into a bounded association pilot watchlist with theme triage, local review states, a Markdown digest and Evidence Collection handoff.
- Benefit
- Italian consumer associations can organize a source-first review scope without creating an account or sending member, consumer or draft data to PolicyWatcher.
- Validation
- The workspace reuses public-evidence gates, keeps working state in the browser and names unavailable or empty conditions; it does not manage complaints, make legal findings or publish decisions.
Managed VPS Renderer releases
Upload a bounded Renderer package from the protected Admin Center, verify it across the browser, Hostinger and VPS Agent, then follow asynchronous install, smoke and rollback state.
- Benefit
- Routine Renderer deltas no longer require manual package staging, extraction or service commands on the VPS.
- Validation
- The Agent accepts only signed bounded uploads, rejects unsafe archives and version mismatches, and reports one observable operation through completion or rollback.
Git-hosted Press Kit distribution
Keep complete checksum-listed editorial packages in the public repository while serving download links from GitHub and excluding nested package archives from Hostinger deployments.
- Benefit
- Editors retain the complete EN and IT downloads while the application release is smaller, faster to transfer and easier to inspect.
- Validation
- The package manifest names GitHub as the provider, the UI labels the external handoff and the release builder rejects nested Press Kit ZIPs.
Resource navigation and retrieval diagnostics
Group the full public resource directory by intent and make shared acquisitions explicit through safe fingerprints, cache modes and renderer/browser coherence.
- Benefit
- Readers scan a shorter navigation structure while operators can distinguish legitimate regional fetches from reused acquisition results.
- Validation
- All footer destinations remain available; focused tests preserve semantic URL differences, redact log labels and verify renderer UA behavior without stealth or WAF bypass.
Administrative mutation hardening
Centralize same-origin provenance, route-specific declared-body limits, JSON enforcement, bounded rate state and safe response metadata for unsafe administrative API methods.
- Benefit
- Administrative mutation routes receive one consistent defense-in-depth boundary without changing public APIs or page CSP and framing behavior.
- Validation
- Focused tests cover accepted same-origin requests, denial paths, body caps, rate state, headers and page CSP; the control is not a pentest or distributed rate limit.
Community Signal Composer UX
Turn candidate interest or a new proposal into a browser-local Need, Evidence, Limits and Review dossier before an explicit GitHub handoff.
- Benefit
- Researchers, citizens, GRC reviewers and builders can prepare a bounded proposal without sending draft contents to PolicyWatcher.
- Validation
- Strict local draft parsing and deterministic issue generation are covered; GitHub permissions, review, acceptance and adoption remain external.
Source Remediation Workbench UX
Connect returned-window priority, safe filtering, bounded issue evidence, responsive layouts and the Detect to Close sequence in one protected workbench.
- Benefit
- Admins and Auditors can identify the next responsible remediation action while mutation controls remain admin-only.
- Validation
- Only Recovered issues can be closed and Resolved issues reopened; closure is not proof of continuous source availability or measured usability improvement.
Renderer production hardening
Require explicit target-domain egress, HTTPS, bounded output and total runtime while separating public liveness from authenticated Chromium readiness and supporting a bounded two-secret rotation overlap.
- Benefit
- Operators can constrain rendered destinations and rotate credentials without exposing readiness detail publicly or accepting arbitrary public targets.
- Validation
- Focused tests cover allowlist parsing, subdomain boundaries, secret overlap, HTTPS enforcement and query-free operational logging; Chromium socket ownership remains an explicit limit.
Word Contract Evidence Review
Classify an explicitly selected Word clause locally against a fixed taxonomy, display the derived topics and search related public evidence only after a separate acknowledgement.
- Benefit
- Reviewers can reach cited public evidence from a Word clause without transmitting the selected clause to PolicyWatcher.
- Validation
- Network queries contain controlled topic labels only; the source package does not verify, approve or legally assess a contract.
Microsoft, Google and AWS agent packages
Validate a Microsoft 365 Copilot declarative agent, Vertex AI Agent Builder tool or Amazon Quick OpenAPI connector against the same public evidence contract.
- Benefit
- Enterprise users can query PolicyWatcher from an approved agent environment while public evidence remains at the source.
- Validation
- The repository provides source packages and runbooks; it does not deploy, approve, publish or certify them in customer environments.
Cross-cloud Agent Evidence Gateway
Retrieve deterministic capabilities, public change briefs and curated Observatory briefs through one flattened OpenAPI 3.0 contract.
- Benefit
- Agent tools receive timestamps, applied filters, answer context, citations and explicit evidence limits in a consistent form.
- Validation
- Only public evidence and curated references are returned; zero results do not establish absence and private workflows remain on API v2.
Browser-local event feed continuity
Inspect the bounded public change-event window, save or import a strict local checkpoint and explicitly resume forward polling from its opaque cursor.
- Benefit
- Integration developers can rehearse checkpoint, deduplication and resume behavior without registering an endpoint or sending consumer state to PolicyWatcher.
- Validation
- The report detects observable duplicate, overlap, ordering and truncation conditions; it does not claim exhaustive monitoring, delivery confirmation or zero gaps.
Local public-evidence watchlists and shareable collections
Select up to 12 exact public change records, keep a bounded title and review state in localStorage, and share a canonical URL containing public change IDs only.
- Benefit
- Researchers and reviewers can assemble a reproducible scope without creating an account or sending personal workspace state to PolicyWatcher.
- Validation
- Shared links exclude the local title and review states; corrupt or oversized browser state is ignored and the selection remains bounded to public records.
Multi-change evidence briefing
Selected exact-change Evidence Packets are composed into one deterministic collection with per-record identity, source state, screening trace, packet digest and review questions.
- Benefit
- A reviewer can carry a defined multi-record scope into editorial, research or governance work while retaining each original evidence boundary.
- Validation
- The collection is selection-based rather than exhaustive and does not infer a market, legal or compliance conclusion.
Portable generic evidence bundle
One read-only endpoint returns deterministic JSON, Markdown or formula-safe CSV for 1–12 canonical public change IDs.
- Benefit
- Developers can move bounded public evidence into their own review workflow without a vendor-specific connector.
- Validation
- The endpoint accepts IDs and format only; direct Jira, Confluence, Teams or GRC delivery, signed webhooks and write operations remain unimplemented.
Source evidence and continuity ledger
Public evidence files show publication state, sanitized retrieval status, last-check time and versioned public snapshot fingerprints for one change.
- Benefit
- Reviewers can inspect the recorded evidence chain without access to protected Dataset QA operations.
- Validation
- The public view excludes admin notes, raw retrieval failures, credentials and withheld records; retrieval state is not a source-authenticity rating.
Advisory governance mapping
Assessed KPI evidence is mapped to review questions for the EU AI Act, ISO/IEC 42001, NIST AI RMF and OECD AI Principles.
- Benefit
- GRC and legal reviewers receive a structured starting point for specialist framework review.
- Validation
- Mappings state mapped or not assessed, name their source and version, and never issue compliance, conformity or legal verdicts.
Source-anchored score explainability
Stored score reasons can show an exact source passage, snapshot side and related KPI only when the passage matches the recorded snapshot.
- Benefit
- A reviewer can connect a screening reason to available source evidence instead of reading an unsupported explanation in isolation.
- Validation
- Nonmatching candidate quotes are rejected and hidden; historical records without an anchor state that the source passage was not recorded.
Change-bound evidence reports
Each publishable change can produce a two-page PDF and JSON packet with identity, evidence fingerprints, score trace, advisory mappings, review questions and digest.
- Benefit
- Reviewers can download an exact-change dossier without receiving a report for a later change in the same policy.
- Validation
- The packet is a bounded evidence record, not a certification, audit result, legal opinion or compliance assessment.
Shareable evidence views
Copy view writes the public dashboard filters to a versioned canonical URL, while committed filter changes participate in browser history and stale values fail closed.
- Benefit
- Reviewers can share and revisit the same public evidence scope without manually reconstructing each visible filter.
- Validation
- Only public view state is encoded; identity, private evidence and consent state remain excluded, and a future link can still reflect changed source availability.
Coordinated visual evidence drill-down
Heatmap selection commits region and audience together, while radar KPI selection opens original and normalized values with explicit missing and tie outcomes.
- Benefit
- A visual signal now leads directly to its precise context, exact values and interpretation boundary.
- Validation
- Keyboard and mobile paths retain exact-value tables; normalized ordinal values are screening aids, not compliance or performance measurements.
Mobile inquiry reliability
The notification workflow now moves from paste to a local company/policy summary and one verification action, while optional corrections and explainability stay progressively disclosed.
- Benefit
- A person on a phone can submit a useful request without reconstructing hidden links, dates or a multi-field form.
- Validation
- Only successful writes show a registered reference; the admin queue has a visible count and optional minimized email alert, while raw notification content remains browser-local.
Browser Evidence Companion
A minimum-permission Chrome, Edge and Safari companion reads an opened notice only after an explicit gesture, extracts non-personal clues locally, and connects the confirmed signal to PolicyWatcher’s published portfolio evidence.
- Benefit
- People can move from a real notification to a verifiable answer without copying raw personal communications into the platform.
- Validation
- No persistent mailbox access, raw-content transmission, remote code or automated publication; unknown sources still enter the human approval and QA workflow.
Workspace onboarding and navigation
First-time visitors choose an objective and evidence depth, preview the evidence stack, and enter a workspace whose toolbar exposes only the most relevant actions while retaining every command in More.
- Benefit
- The product becomes understandable before the full dashboard density appears, without removing expert capabilities.
- Validation
- Source QA remains visible, preferences stay local, setup is reversible, and the mobile navigation remains focused and safe-area aware.
Notification-to-evidence inquiry
A citizen can paste a plain-text terms/privacy notice, confirm the locally extracted organization and starting policy clues, receive portfolio-wide public evidence, or create a zero-content human-review inquiry that feeds controlled company discovery.
- Benefit
- The path from a real notification email to trustworthy evidence becomes direct without treating marketing copy as proof.
- Validation
- Only publicEvidence records answer immediately; unknown or unverified cases remain queued behind the human source-approval gate.
Objective-based Dashboard Composer
On a first visit, a guided start asks for the user objective and evidence depth, previews a typed stack of real dashboard evidence modules, and saves the selected workspace.
- Benefit
- The selected session purpose determines an evidence stack assembled from existing product modules.
- Validation
- Accepted: generated stacks use registered evidence modules only, remain reversible, and always keep Source QA visible.
Bulk Source Onboarding
Operators can import company and policy candidates, review official-source fit, establish a first private baseline, run the QA gate, and record an explicit publication decision.
- Benefit
- Large source batches move through one durable, auditable workflow instead of ad hoc record creation.
- Validation
- Accepted: duplicate and URL checks run before approval; imports and first baselines remain private until QA passes and an operator publishes them.
Personal Evidence Workspace
Save preferred detail level, visible panels, comparison lenses, and export defaults locally so repeated work feels intentional instead of crowded.
- Benefit
- Power users get density; casual readers get clarity.
- Validation
- Preferences must be local, reversible, and never hide source-quality warnings.
Dataset QA, source suspension, review log, access log, renderer/VPS monitoring, public evidence gate, and quality badges.
First-use objective composer built from registered evidence modules, plus durable five-stage bulk source onboarding with private baselines, QA review, and explicit publication decisions.
Persistent discovery jobs, atomic run claims, safe request parsing, audited candidate reopening, synchronized QA rollback, sensor-free mobile context, and UTC countdown correctness.
Centralized onboarding batch invariants, held-workflow defense in depth, deferred orientation evaluation with cleanup, root mobile overflow containment, and single-source release metadata.
Bilingual notification-to-evidence inquiry with browser-local clue extraction, one-request company discovery, in-context baselines, evidence-provenance KPI QA, audited human handoff, and self-checking Hostinger startup.
Plain-text-first notification intake, explicit clue confirmation, organization/domain conflict handling, portfolio-wide policy verification, and actionable database-unavailable states without transmitting raw message content.
Progressive first-use onboarding, objective-aware quick actions, direct changelog identity, icon-only What Changed entry, focused mobile navigation, and browser-local personalization.
Production Chrome/Edge Manifest V3 extension and Safari-compatible source with temporary tab access, local clue extraction, structured confirmation and portfolio-wide public evidence results.
One-action mobile notification intake, company extraction, persistence-specific receipts, visible admin queue count and privacy-minimized operator alerts.
Human-approved AI model registry, privacy-safe telemetry, validated release ledger and bilingual Evidence Pulse with explicit residual boundaries.
Self-service webhook lifecycle, endpoint proof and secret rotation, persistent alert watchlists, multi-version diff and production integration hardening after the configured pilot.
Community benchmark pack, cross-version evidence lineage, external methodology review and production database hardening.
Impact across business and technical assurance
Select any route to inspect its benefit, evidence basis and named residual risk. Categorical KPI and KRI labels describe release outcomes, not measured performance.
The matrix contains 76 visible work items across 9 domains. Releases run from 3.7.0 through the current 4.0.0 Beta 3 and two future horizons.
Swipe or scroll horizontally to follow the release route. Work-item labels remain fixed.
Feature candidates
Candidate review records the workflow, expected evidence, acceptable limits and the current implementation gap. No popularity or endorsement count is inferred.
Read-only public integration directory
Delivered in 3.9.0 Beta 11: a versioned manifest and localized Observatory registry make the public integration surface inspectable, rate-limited and source-bound.
Entra, Azure API Management and Power Platform
Pilot ready: API v2 validates tenant-bound Entra tokens at the origin, publishes an OpenAPI contract, includes an APIM policy and provides a source-controlled custom connector package.
Cross-cloud public evidence dialogue
Delivered in Beta 28-29: one deterministic Agent Evidence Gateway plus source packages for Microsoft 365 Copilot, Vertex AI Agent Builder and Amazon Quick.
Word Contract Evidence Review
Delivered in Beta 30: locally classify selected clause text and send only displayed controlled topic labels to the public evidence gateway after explicit acknowledgement.
Local public-evidence watchlists and shareable collections
Delivered in 3.9.0 Beta 17: select up to 12 public change IDs, retain title and review states locally, and share an ID-only canonical URL.
Configured signed webhook delivery
Delivered in 3.9.0 Beta 23: deployment-configured HTTPS destinations receive eligible public change events through HMAC-SHA256 signatures, a persistent outbox, per-attempt evidence and bounded retries.
Reviewed framework mapping catalogue
Add versioned reviewer commentary, change history and additional framework topics to the delivered advisory map.
Aggregate source continuity trends
Publish bounded portfolio-level continuity trends across time without exposing raw failures, admin decisions or private remediation details.
Market pulse atlas
A visual atlas of policy movement by sector, jurisdiction, source status, and time period, designed for researchers and journalists.
Multi-change evidence briefing
Delivered in 3.9.0 Beta 17: compose selected exact-change evidence packets into a dated bundle with selection scope and per-record digests.
Persistent alert watchlists
Let authenticated users subscribe to future changes for selected companies, policies, jurisdictions, or governance topics and receive focused updates.
Cross-version explanation trace
Compare source-anchored screening reasons across multiple public changes while retaining the original snapshot side and KPI linkage.
Portable generic evidence bundle
Delivered in 3.9.0 Beta 17: deterministic JSON, Markdown and formula-safe CSV exports for 1–12 canonical public change IDs.
Evidence export to GRC tools
Available in the current build as a vendor-neutral handoff manifest with deterministic work-item IDs, evidence links, digests, review questions and acceptance criteria.
Teams, Copilot, MCP and Graph surfaces
Copilot public-evidence agent source is delivered. Continue with an authenticated Teams route, a federated MCP server and optional Graph indexing over tenant-bound controls.
Microsoft commercial marketplace offer
Start with a discovery listing, then evaluate a transactable SaaS offer after tenant provisioning, entitlements, billing events, consent revocation and support operations exist.
Forensic workbench redesign
Move from crowded navigation to a command-driven, panel-based inspection surface with graph, table, timeline, and evidence modes.
Community benchmark pack
A public set of known policy-source cases used to test retrieval, source-fit checks, source suspension, and dashboard behavior.
Signal criteria
Each request is reviewed for feasibility, source quality, security and claim scope. The ranking informs product prioritization.
Use case
Identify the user, decision and question.
Evidence requirement
Specify the required source, check log, snapshot, region, KPI or export.
Implementation path
Document the implementation path, data requirements and automation limits.
Release lane
Classify the item as a feature release, evidence-method release or research candidate.
Roadmap signal submission
The most useful feedback is specific: the role you have, the decision you need to make, the evidence you trust, and the level of detail you expect.