Skip to content

Drupal Module Ownership Matrix

One record per contrib module Bluefly has evaluated. This is the persistent answer to "which Drupal module owns this capability, and has it already been evaluated?" It is reference knowledge: current, maintained, revalidated on each adoption or retirement through contrib-module-adoption.md.

Rules of the matrix:

  • LAST_VERIFIED is the date of the evidence, not today. A record whose date predates the decision you are about to make must be revalidated first.
  • Every fact below is REPORTED from the linked audit unless marked otherwise. Fields the audit did not support are NOT_ESTABLISHED; nothing here is inferred about compatibility or security.
  • D11_COMPATIBILITY and SECURITY_COVERAGE: Y / N as the audit stated; SECURITY_COVERAGE=Y means a stable release covered by the Drupal security team.
  • NET_OWNERSHIP_EFFECT: SN strongly negative (removes Bluefly ownership), N negative, 0 neutral, P positive (adds ownership).
  • DISPOSITION vocabulary: ADOPT, ADOPT_WHEN_NEEDED, EVALUATE, DO_NOT_USE, REPLACE_BLUEFLY, KEEP_BLUEFLY, CONTRIBUTE_UPSTREAM; KEEP marks a contrib module already owning its capability on the audited site. NEEDS_DECISION marks an open operator decision.
  • Site-specific facts (CURRENT_BLUEFLY_USE) describe bluefly.io at LAST_VERIFIED. They are evidence of the pattern, not a rule for other sites.
  • Version numbers are dated facts carried from the audit; do not copy them into a normative standard.

Evidence for every record: ledger/audits/2026-09-20-bluefly-io-drupal-module-ownership-audit.md (EVIDENCE= cites the audit's domain row). Provenance of the underlying observation: bluefly.io repository, branch chore/bluefly-9yp-ownership-audit, commit bc18aa8c, file .agents/plans/active/bluefly-9yp/OWNERSHIP_AUDIT_2026-09-20.md; that project-local file remains the execution receipt, the ledger entry is the curated record, and this matrix is the current reference.


A. Agent-readable content

markdownify

MODULE=markdownify
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.2.0 stable; core-only dependency; 1,321 reported sites
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=HTML-to-Markdown representation of content for LLM/agent consumption; pairs with llms_txt (Drupal CMS llm_support pattern)
CURRENT_BLUEFLY_USE=not installed; llms_txt enabled; ai.html_to_markdown setting exists
CURRENT_BLUEFLY_OWNER=none yet; "llms content projections" planned in rebuild docs; duadp ships a static llms-full.txt
OVERLAPPING_BLUEFLY_PACKAGES=duadp (static llms-full.txt); the planned custom projection has no package yet
DISPOSITION=ADOPT
WHAT_IT_REPLACES=any custom Markdown / agent-content endpoint (pre-empts it before it is written)
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row A

B. AI administration

ai_dashboard

MODULE=ai_dashboard
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.3 stable; 5,697 reported sites
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=Drupal AI administrative dashboard; with ai_metering (cost/quota) and ai_logging / ai_observability (status)
CURRENT_BLUEFLY_USE=enabled
CURRENT_BLUEFLY_OWNER=four Bluefly dashboards: ai_agents_ossa/ai_agents_dashboard (+_monitoring), agentic_canvas_blocks blocks (agent_dashboard, platform_health, ai_cost_summary), ai_agents_agui_analytics, agentic_canvas theme controllers
OVERLAPPING_BLUEFLY_PACKAGES=ai_agents_ossa, agentic_canvas_blocks, ai_agents_agui, agentic_canvas (theme)
DISPOSITION=REPLACE_BLUEFLY
WHAT_IT_REPLACES=all four Bluefly dashboards; ai_metering owns cost/quota; ai_logging / ai_observability own status
NET_OWNERSHIP_EFFECT=SN
EVIDENCE=audit section 1, row B

C. SEO and URL governance

metatag

MODULE=metatag
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=2.2.0 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=page and entity metadata owner
CURRENT_BLUEFLY_USE=enabled; 7 defaults; 3 submodules
CURRENT_BLUEFLY_OWNER=none (contrib owns)
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP
WHAT_IT_REPLACES=nothing (already the owner)
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row C

token

MODULE=token
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.17 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=token replacement used by pathauto and metatag
CURRENT_BLUEFLY_USE=enabled
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row C

redirect

MODULE=redirect
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.13 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=URL redirects; redirect map owner for migrations
CURRENT_BLUEFLY_USE=enabled; 35 redirects
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row C

metatag_ai

MODULE=metatag_ai
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=2.0.5 stable; uses drupal/ai
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=AI-assisted meta generation through the Drupal AI provider abstraction
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=ADOPT_WHEN_NEEDED
WHAT_IT_REPLACES=nothing today; becomes the owner of "meta generation" once real content exists
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row C

ai_seo

MODULE=ai_seo
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.1.3 stable; uses drupal/ai; 797 reported sites
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=AI SEO analysis
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none (no custom SEO analyser exists)
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=ADOPT_WHEN_NEEDED
WHAT_IT_REPLACES=nothing today; owner for "analysis"; 76 nodes did not justify it at audit time
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row C
MODULE=ai_seo_link_advisor
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.1.1 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=AI link analysis
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; overlaps ai_seo link analysis; would be a third AI-SEO module
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row C

D. Editorial AI

ai_content_suggestions

MODULE=ai_content_suggestions
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.5.0 stable; requires field_widget_actions (dependency fix tracked as bead 9yp.20.8)
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=title, summary, taxonomy, readability and moderation suggestions
CURRENT_BLUEFLY_USE=enabled
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP
WHAT_IT_REPLACES=nothing; owner of editorial suggestions
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row D

ai_ckeditor

MODULE=ai_ckeditor (drupal/ai submodule)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=ships with drupal/ai 1.5 (audit); baseline guidance in drupal-ai-architecture.md prefers stable 1.4 over 1.5 RC
D11_COMPATIBILITY=NOT_ESTABLISHED (inherits drupal/ai; audit did not state)
SECURITY_COVERAGE=NOT_ESTABLISHED (inherits drupal/ai; audit did not state)
CAPABILITIES=CKEditor AI interaction
CURRENT_BLUEFLY_USE=enabled
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP
WHAT_IT_REPLACES=nothing; owner of CKEditor interaction
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row D

ckeditor_ai_agent

MODULE=ckeditor_ai_agent
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=2.0.0 stable; uses drupal/ai; 143 reported sites
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=CKEditor AI plugin
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; ai_ckeditor already owns CKEditor interaction
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row D

aicontentfiller

MODULE=aicontentfiller
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.x-dev; no release
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=AI content filling
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; ai_content_suggestions plus AI automators cover the need
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row D

ai_vocabulary

MODULE=ai_vocabulary
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.2; hard-requires ai_provider_openai
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=Y
CAPABILITIES=AI vocabulary/term generation
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; provider coupling violates the Drupal AI provider abstraction; ai_content_suggestions plus the ai_agents taxonomy agent own it
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row D

ai_validations

MODULE=ai_validations
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.3.0; requires field_validation
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=AI-driven field validation
CURRENT_BLUEFLY_USE=installed, not enabled
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=EVALUATE (drop from composer until a validation need exists)
WHAT_IT_REPLACES=nothing today
NET_OWNERSHIP_EFFECT=N (removing it drops one dependency)
EVIDENCE=audit section 1, row D

chirp_ai_moderation

MODULE=chirp_ai_moderation
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=alpha; requires chirp
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=AI moderation for chirp comments
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; no comments or chirp on the audited site
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row D

E. Media

ai_image_alt_text

MODULE=ai_image_alt_text
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.2 stable; part of the Drupal CMS AI recipe
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=AI-assisted alt text (editorial review still required)
CURRENT_BLUEFLY_USE=installed, not enabled; 0 media entities at audit time
CURRENT_BLUEFLY_OWNER=none (no private alt-text code exists)
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=ADOPT_WHEN_NEEDED (enable when media exists)
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row E

ai_media_image

MODULE=ai_media_image
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=alpha
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=text-to-image media generation
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; no text-to-image requirement
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row E

crop

MODULE=crop (+ focal_point)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=2.6 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=crop and focal-point data for image styles
CURRENT_BLUEFLY_USE=enabled; 1 crop type
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row E

media_directories

MODULE=media_directories
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=3.0.0-rc1; no D11 stable; requires canvas, entity_browser and others
D11_COMPATIBILITY=NOT_ESTABLISHED (no stable D11 release reported)
SECURITY_COVERAGE=NOT_ESTABLISHED
CAPABILITIES=media library folder organisation
CURRENT_BLUEFLY_USE=not installed; 0 media
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=EVALUATE (later, once media exists)
WHAT_IT_REPLACES=nothing today
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row E

svg_image

MODULE=svg_image
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=3.2.4 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=SVG support for image fields
CURRENT_BLUEFLY_USE=enabled alongside svg_image_field, svg_image_field_media_bundle, svg_formatter, svg_image_responsive (five modules for one concern)
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP svg_image; DO_NOT_USE the three to four duplicates after checking field instances
WHAT_IT_REPLACES=the duplicate SVG modules
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row E

F. Workflow and tools

modeler_api

MODULE=modeler_api
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.1.7 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=workflow/model abstraction; ModelOwner plugin contract
CURRENT_BLUEFLY_USE=enabled (+ bpmn_io)
CURRENT_BLUEFLY_OWNER=Bluefly ModelOwner plugins: cedar_policy_modeler, api_normalization_modeler, duadp_discovery_modeler
OVERLAPPING_BLUEFLY_PACKAGES=cedar_policy, api_normalization, duadp (as plugin providers, which is the correct shape)
DISPOSITION=KEEP
WHAT_IT_REPLACES=any proprietary model serialization (delete it); ModelOwner plugins are the correct integration
NET_OWNERSHIP_EFFECT=0 / N
EVIDENCE=audit section 1, row F

tool

MODULE=tool (Tool API)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.0-beta9; beta explicitly accepted as foundational
D11_COMPATIBILITY=NOT_ESTABLISHED (audit did not state; drupal-ai-architecture.md reports Drupal ^10.5 or ^11)
SECURITY_COVERAGE=N (not covered; accepted with that knowledge)
CAPABILITIES=single typed executable-capability registry
CURRENT_BLUEFLY_USE=enabled; 11 tool* modules; 102 tools (api_normalization 31, tool_belt 44, canvas_tools 21, ai_automators 6)
CURRENT_BLUEFLY_OWNER=api_normalization (31 Tool plugins) plus other Bluefly plugin providers
OVERLAPPING_BLUEFLY_PACKAGES=api_normalization (own tool_api_adapter plugin manager, to delete); contractplane_client (parallel Mcp / jsonrpc / rest / AiFunctionCall paths, to collapse)
DISPOSITION=KEEP
WHAT_IT_REPLACES=every competing Bluefly tool registry
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row F

eca

MODULE=eca
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=3.1 installed
D11_COMPATIBILITY=NOT_ESTABLISHED (audit did not state; drupal-ai-architecture.md reports ECA 3.1.8 for Drupal ^11.3)
SECURITY_COVERAGE=Y
CAPABILITIES=event-driven workflow owner (internal)
CURRENT_BLUEFLY_USE=10 models, all from Drupal CMS
CURRENT_BLUEFLY_OWNER=api_normalization (23 ECA plugins); cedar_policy and contractplane_client ECA plugins
OVERLAPPING_BLUEFLY_PACKAGES=api_normalization, cedar_policy, contractplane_client (as plugin providers)
DISPOSITION=KEEP
WHAT_IT_REPLACES=custom event subscribers, orchestration services, queue glue where configuration-expressible
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row F

G. Content UX

entity

MODULE=entity (contrib)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.8 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=entity API extensions
CURRENT_BLUEFLY_USE=enabled; no enabled module depends on it
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE (uninstall on the audited site)
WHAT_IT_REPLACES=nothing; orphan dependency
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row G

auto_entitylabel

MODULE=auto_entitylabel
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=3.4 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=automatic entity labels from tokens
CURRENT_BLUEFLY_USE=installed, not enabled
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE now (drop from composer; re-add if podcast/resource titles need it)
WHAT_IT_REPLACES=nothing today
NET_OWNERSHIP_EFFECT=N (one dependency removed)
EVIDENCE=audit section 1, row G

entity_usage

MODULE=entity_usage
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=5.0.0 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=entity reference usage tracking and orphan reporting
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=hand-scripted orphan-reference audit (MR !133 qa scripts)
OVERLAPPING_BLUEFLY_PACKAGES=none (scripts, not a package)
DISPOSITION=ADOPT
WHAT_IT_REPLACES=manual reference/orphan audit scripts with a Drupal-owned report
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row G

allowed_formats

MODULE=allowed_formats
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=3.0.1; functionality moved to Drupal core
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=Y
CAPABILITIES=restrict text formats per field
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; core owns it
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row G

smart_trim

MODULE=smart_trim
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=2.3.1 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=trimmed text formatter
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; teasers use summary fields
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row G

H. Views and navigation

better_exposed_filters

MODULE=better_exposed_filters
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=7.1.3 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=exposed filter widgets for Views
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none (no custom filter forms exist)
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=ADOPT_WHEN_NEEDED (insights/search filters)
WHAT_IT_REPLACES=nothing today
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row H

views_bulk_operations

MODULE=views_bulk_operations
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=4.4.8 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=bulk actions on Views results
CURRENT_BLUEFLY_USE=enabled; 0 views use it
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE (uninstall on the audited site)
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row H
MODULE=menu_block
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.14 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=configurable menu blocks
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=theme hardcodes navigation (bead 9yp.7.6)
OVERLAPPING_BLUEFLY_PACKAGES=bluefly_theme (hardcoded nav)
DISPOSITION=DO_NOT_USE now
WHAT_IT_REPLACES=nothing until the theme renders regions; cannot fix a template that ignores regions
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row H
MODULE=menu_link_attributes
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.7 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=attributes on menu links
CURRENT_BLUEFLY_USE=enabled; 3 attributes configured; 0 links use it
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE (uninstall on the audited site)
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row H

I. Migration

migrate_plus

MODULE=migrate_plus (+ migrate_tools)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=6.0.10 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=configuration-entity migrations, migration groups, JSON/XML/URL source plugins on top of core Migrate
CURRENT_BLUEFLY_USE=enabled; 0 migrations
CURRENT_BLUEFLY_OWNER=P0 migration done with seed scripts (beads 9yp.2.2 / 2.3); a private external_migration module was planned
OVERLAPPING_BLUEFLY_PACKAGES=planned external_migration (not created); seed scripts
DISPOSITION=ADOPT (as configuration: migration_group plus migrations from the live JSON:API)
WHAT_IT_REPLACES=seed scripts and the planned private migration module; Migration Factory must use this
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row I

J. Identity

externalauth

MODULE=externalauth
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=2.0.13 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=external authentication mapping (with openid_connect)
CURRENT_BLUEFLY_USE=enabled; openid_connect 1 client; 2 users; no SSO active
CURRENT_BLUEFLY_OWNER=none (Keycloak planned per AGENTS)
OVERLAPPING_BLUEFLY_PACKAGES=none; do not confuse with OSSA identity or DUADP discovery
DISPOSITION=KEEP config-only / ADOPT_WHEN_NEEDED
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row J

K. Operations

redis

MODULE=redis
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.11 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=Redis cache backend
CURRENT_BLUEFLY_USE=installed, not enabled; cache = DatabaseBackend; memcache enabled but unconfigured; DDEV redis sidecar exists
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=ADOPT (environment configuration); uninstall memcache
WHAT_IT_REPLACES=dead cache glue; the second cache stack
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row K

mailsystem

MODULE=mailsystem (+ sendgrid_integration)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=4.5
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=Y
CAPABILITIES=mail system routing
CURRENT_BLUEFLY_USE=enabled; symfony_mailer_lite in composer, unused
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=KEEP one path (NEEDS_DECISION: sendgrid via mailsystem vs symfony_mailer_lite); drop the other from composer
WHAT_IT_REPLACES=the unused parallel mail path
NET_OWNERSHIP_EFFECT=N (one dependency removed); credential rotation pending
EVIDENCE=audit section 1, row K

ai_usage_limits

MODULE=ai_usage_limits
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=alpha
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=AI usage quotas
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; ai_metering (enabled) already enforces quotas
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row K

ai_watchdog_analyst

MODULE=ai_watchdog_analyst
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.2
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=AI analysis of watchdog logs
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=EVALUATE (no ownership removed)
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row K

L. Providers

ai_provider_ollama

MODULE=ai_provider_ollama
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.2.0-rc3; not stable
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=NOT_ESTABLISHED
CAPABILITIES=Ollama provider for Drupal AI
CURRENT_BLUEFLY_USE=not installed; anthropic, openai, litellm, huggingface providers enabled
CURRENT_BLUEFLY_OWNER=none; never write Ollama client code
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=ADOPT_WHEN_NEEDED
WHAT_IT_REPLACES=nothing; Drupal AI owns providers; LiteLLM (gate G3) is the intended proxy, after which direct providers can go
NET_OWNERSHIP_EFFECT=0
EVIDENCE=audit section 1, row L

M. Miscellaneous

module_filter

MODULE=module_filter
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=6.0.0 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=module page filtering
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; core module page filters
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row M

geocoder

MODULE=geocoder
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=4.37 stable
D11_COMPATIBILITY=Y
SECURITY_COVERAGE=Y
CAPABILITIES=address geocoding
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing; no address or geo requirement
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row M

ai_experience_wizard

MODULE=ai_experience_wizard
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=alpha
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered)
CAPABILITIES=NOT_ESTABLISHED
CURRENT_BLUEFLY_USE=not installed
CURRENT_BLUEFLY_OWNER=none
OVERLAPPING_BLUEFLY_PACKAGES=none
DISPOSITION=DO_NOT_USE
WHAT_IT_REPLACES=nothing
NET_OWNERSHIP_EFFECT=NOT_ESTABLISHED
EVIDENCE=audit section 1, row M

ai_context

MODULE=ai_context (Context Control Center)
LAST_VERIFIED=2026-09-20
UPSTREAM_STATUS=1.0.0-beta4; beta explicitly accepted as the ContextControl substrate
D11_COMPATIBILITY=NOT_ESTABLISHED
SECURITY_COVERAGE=N (not covered; accepted with that knowledge)
CAPABILITIES=generic context providers, scoring, caching, scopes, ai_context_item entity, token budgets
CURRENT_BLUEFLY_USE=enabled; 10 config objects; 3 items
CURRENT_BLUEFLY_OWNER=kb_cache (ai_context_ccc, ContextMemoryProvider and ContextScoring plugins, agent_memory item type); duadp_ai_context; skills_browser scopes
OVERLAPPING_BLUEFLY_PACKAGES=kb_cache, duadp, skills_browser
DISPOSITION=KEEP upstream; SHRINK Bluefly to governance-only extensions (Cedar-gated writes, DUADP attestation, GAID)
WHAT_IT_REPLACES=generic Bluefly context providers, scoring and caching
NET_OWNERSHIP_EFFECT=N
EVIDENCE=audit section 1, row M; Playbooks/drupal/DRUPAL-AI-CONTEXT-PLAYBOOK.md section 7

Modules found on the audited site beyond the 43 evaluated

These were not in the evaluation list but were observed installed or enabled on bluefly.io and dispositioned. Same fields; same LAST_VERIFIED.

MODULE UPSTREAM_STATUS D11 SEC CURRENT_BLUEFLY_USE DISPOSITION WHAT_IT_REPLACES / WHY NET EVIDENCE
yoast_seo 2.x-dev, dev only NOT_ESTABLISHED NOT_ESTABLISHED enabled; 2 field instances; 0 populated DO_NOT_USE (uninstall, remove 2 fields) duplicates metatag; dev release N audit row C (found)
seo_checklist + checklistapi stable NOT_ESTABLISHED Y enabled DO_NOT_USE (uninstall) checklist UI, no capability N audit row C (found)
google_tag + ga4_google_analytics + matomo (+ google_analytics in composer) NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED all enabled NEEDS_DECISION: one analytics owner (Drupal CMS ships google_tag) three trackers for one concern N audit row C (found)
flowdrop (12 submodules) NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled; 0 pipelines; 2 config objects (api_normalization_flowdrop, cedar_policy_flowdrop) DO_NOT_USE on this site (uninstall) ECA owns internal workflow; no consumer N (−12 modules) audit row F (found)
orchestration (3) + maestro (composer) NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled, 0 config / not enabled (contractplane_orchestration, cedar_policy_orchestration) DO_NOT_USE on this site (uninstall; maestro out of composer) external bridge only when a bridge exists N audit row F (found)
feeds + api_normalization_feeds / _tamper NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled; 0 feeds DO_NOT_USE on this site no consumer N audit row I (found)
monitoring (74 cfg) + ultimate_cron (44 cfg) NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled; nothing consumes sensors; root cause of config-export churn (bead 9yp.3.6) DO_NOT_USE on this site (uninstall) core automated_cron and status report N (−118 config objects) audit row K (found)
memcache NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled but unconfigured DO_NOT_USE (uninstall; redis adopted) second cache stack N audit row K
svg_image_field, svg_image_field_media_bundle, svg_formatter, svg_image_responsive NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled DO_NOT_USE after checking field instances duplicates of svg_image N audit row E
mcp (deprecated) NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED enabled DO_NOT_USE (uninstall) superseded by mcp_server + Tool API bridge N audit section 3, action 5
bootstrap_barrio, features, config_update, symfony_mailer_lite (one of the mail paths) NOT_ESTABLISHED NOT_ESTABLISHED NOT_ESTABLISHED in composer DO_NOT_USE (remove from composer) no consumer N audit section 3, action 8

Reading the matrix

  • The audit tallied MODULES_AUDITED=43 · installed=15 · enabled=12 · ADOPT_NOW=4 · ADOPT_WHEN_NEEDED=7 · EVALUATE=3 · DO_NOT_USE=16 and named 12 modules under "KEEP-already-owning" while reporting the count as 9. Recounting the 43 records above gives DO_NOT_USE=17 and KEEP=12 (INFERRED from the rows; the audit's own totals are REPORTED). Treat the per-record disposition, not the tally, as authoritative.
  • Nothing in this matrix authorises composer require or drush en. Adoption and retirement go through contrib-module-adoption.md, which appends or updates the record here.
  • Modules not present here have not been evaluated. Evaluate them with drupal-standard.md section 13 and the rubric in DRUPAL-CONTRIB-FIRST-EVALUATION-PLAYBOOK.md, then add the record.