Skip to content

ContextControl.ai — Comprehensive Product Research & Strategy Report

Product Definition: ContextControl is Bluefly’s commercial product for Governed Agent Operations. It solves the enterprise crisis of "agent sprawl" by providing a human operating surface that ensures autonomous agents run safely, durably, and transparently, with immutable evidence of their actions.


1. Competitive Landscape (2026)

The 2026 market is heavily fragmented into point solutions for security, observability, and workflow execution. There is a massive gap for a unified Human-in-the-Loop (HITL) Governance Surface that links these discrete functions back to business authority and policy.

1.1 Agent Security & Posture Management (AISPM)

[MARKET_EVIDENCE] These platforms focus on threat detection, discovering "shadow AI," and blocking malicious prompt injections. They are security tools, not operational workflow tools.

Competitor Core Capabilities Target Buyer Pricing (Public/Observed) What it LACKS (The Gap)
Zenity Secures Copilots, Agentic workflows; discovers shadow AI; Microsoft ecosystem focus. CISO, AppSec Custom Enterprise ($50k–$150k+ based on endpoints/apps) Does not govern the software delivery lifecycle or durable work state.
Reco AI Identity-first context graph; permission mapping across SaaS apps; risk scoring. CISO, SecOps Custom Enterprise (Similar to Zenity) Focused on SaaS data exposure, not the operational execution of engineering agents.

1.2 LLM & Agent Observability

[MARKET_EVIDENCE] Observability tools have shifted from logging to tracing the "decision graph." However, they are developer-centric debugging tools, not business-level governance platforms.

Competitor Core Capabilities Target Buyer Pricing (Public/Observed) What it LACKS (The Gap)
Langfuse Open-source tracing, evaluations, prompt management. AI Engineers, Dev Teams Core: $29/mo. Pro: $199/mo. Enterprise: $2,499+/mo. No policy enforcement; it is a passive observer of events, lacking approval workflows.
LangSmith Deep LangChain integration, prompt versioning, debugging. AI Engineers Plus: $39/seat. Enterprise: Custom. High usage costs (traces). Vendor-tied to LangChain/LangGraph. Developer UI, not a compliance/business UI.
Phoenix (Arize) Evals, tracing, embedding analysis. ML Engineers Usage-based/Enterprise Custom Focuses on model performance/accuracy rather than agent authorization bounds.

1.3 Enterprise Agent Platforms & Cloud Ecosystems

[MARKET_EVIDENCE] The hyperscalers and CRM giants offer platforms to build and run agents, but they intentionally lock customers into their proprietary ecosystems.

Competitor Core Capabilities Target Buyer Pricing (Public/Observed) What it LACKS (The Gap)
Microsoft Copilot Studio Low-code agent builder integrated with Microsoft 365 and Dataverse. IT, Business Users $200/mo for 25,000 messages (base) + user licenses. Massive lock-in. Useless for governing standalone engineering/DevOps agents outside MSFT.
AWS Bedrock AgentCore Foundation models, knowledge bases, agent orchestration. Cloud Architects Pay-as-you-go (tokens + infrastructure) Purely infrastructure. Requires customers to build their own human governance UI.
Salesforce Agentforce CRM-native agents replacing Einstein; autonomous customer service/sales. Sales/Service VP $2 per conversation (usage based) Domain-restricted to CRM data. Cannot govern general-purpose software delivery.
ServiceNow Now Assist IT service management automation, internal helpdesk agents. CIO, IT Director Premium SKU uplift (Pro/Enterprise packages) Domain-restricted to ITIL/ticketing. Not an agent factory control plane.

1.4 Durable Workflow & Delivery Automation

[MARKET_EVIDENCE] These platforms handle the execution of long-running tasks, which is adjacent to agent orchestration.

Competitor Core Capabilities Target Buyer Pricing (Public/Observed) What it LACKS (The Gap)
Temporal.io Durable execution; fault tolerance for long-running workflows. Software Architects Consumption-based (Actions + Support plan, often $20k–$100k+) No native understanding of "Agents" or AI policy; it is purely an orchestration layer.
Harness.io CI/CD, feature flags, cloud cost management, governed delivery. VP Engineering Module-based (often $25k–$50k+ for mid-market) Rules are static YAML/RBAC, not dynamic agentic policy. No "agent memory" concept.
LinearB DORA metrics, PR sizing, software delivery management. Engineering Dir Per developer seat Passive reporting; cannot actively orchestrate or halt an autonomous agent.

1.5 Policy Engines

Competitor Core Capabilities Target Buyer Pricing (Public/Observed) What it LACKS (The Gap)
HashiCorp Sentinel Policy-as-code for infrastructure provisioning. DevOps, SecOps Bundled with Terraform/Vault Enterprise Tied to HashiCorp ecosystem.
OPA / Styra General-purpose policy engine (Rego). Cloud Architects Free (OPA) / Custom (Styra DAS) Developer-only. Requires a separate control plane to provide the UI and human workflows.

1.6 The Bluefly ContextControl Differentiation

[BLUEFLY_SPECIFIC] ContextControl sits above these tools. It is not trying to be Langfuse (tracing), Temporal (execution), or Cedar (policy evaluation). It is the Business Authority Surface. It consumes data from Gas City (orchestration), Cedar (policy), and GitLab (CI/CD), and presents it to human operators for approval, audit, and memory retention, uniquely using Open Standards (OSCAL, JWS, DID).


2. Drupal Ecosystem Readiness (2026)

ContextControl is built on Drupal 11. To maximize margin and reduce technical debt, we must leverage the mature 2026 Drupal ecosystem and only write custom code where an upstream gap exists.

2.1 Mature / Production-Ready Modules (Do Not Build Custom)

  • drupal/ai (Core AI Abstraction): [MARKET_EVIDENCE] Now universally adopted. Handles LLM provider routing, key management, and basic abstractions. We use this for all "Ask Blu" backend integrations.
  • drupal/eca (Event-Condition-Action): [MARKET_EVIDENCE] Version 3.1+ is the standard for no-code orchestration. We use ECA to route webhooks from GitLab and Gas City into Drupal state changes, avoiding custom PHP event subscribers.
  • drupal/group (Workspaces/Tenants): [MARKET_EVIDENCE] Group 4.x is the definitive way to handle multi-tenancy in Drupal 11. We use it to create "Workspaces" for customers, assigning agents, policies, and facts to specific groups.
  • Core Content Moderation: [MARKET_EVIDENCE] Handles basic linear workflows (Draft -> Review -> Published). Replaces the legacy Workbench module.

2.2 Experimental / Beta Modules (Contribute or Extend)

  • drupal/mcp (Model Context Protocol): [MARKET_EVIDENCE] Currently in Beta. Allows Drupal to act as a server exposing tools to external agents (e.g., Claude, Cursor).
    • Bluefly Action: We must extend this to ensure MCP tool execution requires Cedar authorization checks before Drupal returns data.
  • drupal/ai_agents: [MARKET_EVIDENCE] Still struggling with complex multi-step autonomous configurations and identity attribution.
    • Bluefly Action: We bypass this for execution. Gas City handles execution; ContextControl merely records the evidence of what Gas City's agents did.

2.3 The Custom Code Gap (What Bluefly MUST Build)

[BLUEFLY_SPECIFIC] Upstream Drupal lacks the specific compliance and evidence primitives required for ContextControl: 1. JWS-Signed Fact Registry: Drupal entities are mutable. We must build an append-only, JWS-signed entity type (Governed Fact) that cryptographically proves an agent's claim. 2. Cedar Policy Integration: Drupal's access control is role-based (RBAC). We must build a Cedar evaluation bridge so Drupal UI components show/hide based on ContractPlane ABAC policies. 3. WITNESS Evidence Viewer: Custom SDC/Canvas components to render OtterMon telemetry and WITNESS proofs alongside MR data. 4. Approval Queue Dashboard: A specialized, high-density React/Canvas interface for human operators to review pending agent actions (beyond standard Drupal Views).


3. Market Urgency & Sizing

3.1 EU AI Act Enforcement Timeline

[MARKET_EVIDENCE] The EU AI Act is the forcing function for this market. * August 2025: Governance rules for General-Purpose AI took effect. * August 2026: Transparency obligations are now strictly enforced. Agents acting on behalf of a company must be logged, and their decisions must be traceable. * Implication: European enterprises (and global companies operating in the EU) are actively purchasing governance platforms today to avoid fines (up to 7% of global turnover).

3.2 Deployment Failures and "Agent Sprawl"

[MARKET_EVIDENCE] 2026 reports from Gartner highlight a massive reckoning: * 40% Decommission Rate: Gartner projects that by 2027, 40% of enterprises will decommission autonomous agents due to governance gaps and "shadow AI" incidents. * The Pain Point: On industry forums (HN, Reddit /r/MachineLearning), DevOps and Security teams report that teams are launching agents via LangChain or Cursor without CI/CD oversight, leading to "Agentic Ransomware" incidents and corrupted production databases. * The Shift: Buyers are demanding "proportional governance"—stopping agents at the boundary, requiring human approval for destructive actions, and logging the entire decision tree.


4. Pricing Strategy & Market Evidence

ContextControl is an enterprise governance platform, not a developer utility. Pricing must reflect the risk mitigation value, similar to GRC (Governance, Risk, and Compliance) tools.

4.1 Proxy Pricing (Market Evidence)

[MARKET_EVIDENCE] * Compliance Automation (Vanta, Drata, Secureframe): * Small Teams (<50): $10k - $20k / year. * Mid-Market (200-500): $30k - $50k / year. * Enterprise: $80k - $150k+ / year. * Model: Base platform fee + per-employee tier + framework add-ons. * Enterprise DevOps (Harness): * Mid-Market: $25k - $50k / year. * Model: Module-based (CI, CD, FinOps) + usage metrics. * Consulting / ProServ (AI Governance): * Big 4 / Boutique firms charge $50k - $250k for an "AI Readiness Assessment" and initial policy implementation.

4.2 Proposed ContextControl Pricing Model

[HYPOTHESIS] [BLUEFLY_SPECIFIC] We reject per-agent or per-token pricing (which penalizes usage). We use a Value-Based Governance Model:

  1. ContextControl Foundation (The Pilot/Entry): $3,000 / month ($36k/yr).
    • Includes 1 Governed Workspace, integration with existing CI/CD, up to 5 protected workflows.
  2. Enterprise Scale: $8,000 / month ($96k/yr).
    • Unlimited Workspaces, advanced Cedar policy authoring, 1-year cryptographic evidence retention, SSO/SAML, dedicated support.
  3. Industry Policy Packs (Add-ons): $1,500 / month each.
    • Pre-configured Cedar policies and reporting templates for specific regulations (EU AI Act, HIPAA, SOC2 for AI).
  4. COGS Analysis:
    • Drupal hosting + Dolt DB + basic egress is low (<$200/mo).
    • The primary COGS is LLM API usage for "Ask Blu" and storage for cryptographic evidence. Assuming 90% gross margin on software, leaving room for white-glove onboarding.

5. Productizing Dogfood Failures (The 10 Cases)

We must translate the 10 specific failures experienced in the Bluefly factory into concrete ContextControl product features. This proves the product's value in a demo.

Failure Case ContextControl Feature How it Works (UI & Data Sources) Human Action / Demo Scenario
1. Local Beads DB reports success; Oracle is unchanged. Authority Drift Guard UI: A split-brain warning banner on the Bead view. Data: Compares local Dolt hash vs. canonical Oracle Dolt hash. Demo: Show an agent falsely claiming a task is done. The UI blocks the "Close Issue" button, forcing the operator to sync to Oracle.
2. Agent reports "shipped" without MR/CI. Implementation Reality Check UI: Red cross-reference badge on the agent's status update. Data: Queries GitLab API for matching branch/MR. Demo: Operator sees "Agent claims deployed." UI shows "0 Associated MRs. Status Demoted to LOCAL."
3. MR passes, but Release Push fails. Release Chain Validator UI: Pipeline timeline visualizer (SDC component). Data: Links GitLab MR pipeline to the protected branch deployment pipeline. Demo: Operator clicks "Approve." UI warns: "Upstream MR passed, but release environment is currently failing. Approval blocked."
4. Branches exist without Bead authority. Orphaned Branch Detector UI: "Rogue Activity" dashboard widget. Data: Scans GitLab for branches lacking a bl-<id> prefix. Demo: Show a developer (or agent) creating an ad-hoc branch. ContextControl immediately flags it as ungoverned and halts CI.
5. Humans ask, "What do I merge next?" Approval Queue Dashboard UI: High-density Kanban/List of all items requiring HITL intervention. Data: Filters Gas City mail and GitLab MRs pending Cedar policy approvals. Demo: Operator logs in in the morning. The dashboard shows exactly 3 items needing human review, with all context attached.
6. Local config diverges from Git. Configuration Drift Monitor UI: Diff viewer showing runtime vs. repo state. Data: Compares live environment hash against latest Git commit hash. Demo: Agent modifies a server manually. ContextControl flags "Drift Detected" and offers a one-click "Revert to Git" button.
7. Drupal converges locally; change is only an MR. Pre-deployment Convergence Alert UI: Warning on the specific Drupal config page. Data: Cross-references local config state with active MRs. Demo: User tries to edit a Drupal setting that an agent is currently rewriting in an open MR. UI locks the field.
8. Control code leaks into site repo. Boundary Violation Scanner UI: Policy violation alert in the PR review screen. Data: Cedar policy evaluating file paths in the MR diff. Demo: Agent tries to commit a security policy file to the frontend repo. Cedar blocks the commit; ContextControl logs the violation.
9. Infrastructure bypasses IaC. Out-of-band Infra Detection UI: Critical Alert in the "Evidence" tab. Data: Matches cloud provider audit logs against GitLab IaC deployments. Demo: Agent spins up an EC2 instance via CLI. ContextControl detects no matching IaC pipeline and instantly suspends the agent's credentials.
10. DONE vs. LOCAL_IMPLEMENTED. State Demotion Engine UI: Status badge automatically changes color and text. Data: Rules engine (ECA) enforcing the STD-LIFECYCLE-001 completion rule. Demo: Agent sends "DONE=YES". ContextControl evaluates rules, finds no WITNESS proof, and visually downgrades the status to "LOCAL_IMPLEMENTED" with a note to the agent.

6. Go-to-Market Strategy (GTM)

6.1 Positioning & Pitch

[HYPOTHESIS] [BLUEFLY_SPECIFIC] * Pitch 1 (Fear/Compliance): "ContextControl is the immutable ledger for your AI workforce. Prove what your agents did, or don't deploy them at all." * Pitch 2 (Empowerment/Ops): "Stop babysitting AI agents. ContextControl gives you the human control plane to safely scale autonomous workflows across your enterprise." * Pitch 3 (The Category Creator): "Organizational memory for AI agents. Know what they did. Make it everyone's knowledge. Govern the outcome."

6.2 Ideal Customer Profile (ICP)

  • Job Title: VP of Platform Engineering, CISO, or Head of AI Governance.
  • Company Size: Mid-market to Enterprise (500–5,000+ employees).
  • Industry: Highly regulated sectors adopting AI (FinServ, Healthcare, Public Sector).
  • Budget Owner: CIO or CISO.

6.3 First Three Vertical Hypotheses

  1. Financial Services: Highest regulatory burden (DORA, SEC rules). They have the budget and the immediate need to prove AI agents aren't leaking data or violating trading rules.
  2. Healthcare (Payers/Providers): Strict HIPAA and patient data handling rules. Agents processing claims must have an immutable, HITL audit trail.
  3. Technology / SaaS: High maturity in DevOps. They are already deploying internal developer agents but are suffering from "agent sprawl" and corrupted codebases.

6.4 The Buying Trigger

[MARKET_EVIDENCE] The prospect experiences a "Shadow Agent Incident"—an internal team deploys a LangChain or AutoGPT tool that accidentally deletes data, incurs a massive AWS/OpenAI bill, or leaks PII, and the security team realizes they have zero visibility or audit logs of what the agent actually did.

6.5 Demo Narrative

  • Step 1: The Chaos: Show the prospect an ungoverned agent executing tasks. The terminal flies by. The prospect is asked: "If the auditor walks in right now, how do you prove what that agent just did?"
  • Step 2: The Control Plane: Open ContextControl.ai. Show the Platform Loop.
  • Step 3: The Incident: Trigger Failure Case #9 (Agent spins up out-of-band infrastructure).
  • Step 4: The Intervention: Show ContextControl catching the event, applying Cedar policy, blocking the action, and placing it in the Approval Queue Dashboard.
  • Step 5: The Proof: Click into the Governed Fact. Show the JWS signature, the WITNESS telemetry, and the exact prompt/tool chain that caused it. "This is what you hand the auditor."

6.6 Top 3 Objections & Responses

  1. Objection: "We already use LangSmith/Datadog for observability."
    • Response: "Those are debugging tools for developers. They don't enforce Cedar policies, they don't provide cryptographic non-repudiation for auditors, and they don't offer a human approval queue. ContextControl is your business authority, not your log viewer."
  2. Objection: "We use Microsoft Copilot Studio; isn't governance built-in?"
    • Response: "Only for agents living inside Microsoft 365. ContextControl governs your engineering agents, your DevOps agents, and your custom open-source agents across your entire infrastructure without vendor lock-in."
  3. Objection: "This adds too much friction; our developers want to move fast."
    • Response: "ContextControl operates entirely via APIs and Open Standards. Fast-path actions are auto-approved by Cedar policy. Only destructive or out-of-bounds actions hit the human queue. It actually speeds up development by removing the fear of catastrophic failure."

6.7 Paid Pilot & Conversion

  • Scope: 30 days. 1 Workspace. 1 specific, high-value workflow (e.g., governing the internal DevOps infrastructure agent).
  • Price: $5,000 (Credibility pricing; covers onboarding and setup).
  • Success Criteria: ContextControl successfully catches 100% of out-of-bounds actions and generates a clean compliance report for the workflow.
  • Conversion: Automatic transition to the $36k/yr Foundation tier upon hitting success criteria.
  • Expansion Triggers: Adding a second department (e.g., HR agents), triggering an Enterprise upgrade for unlimited workspaces, or purchasing the SOC2/EU AI Act Policy Packs.

6.8 ContextControl.ai Sitemap & Structure

Page Route Headline Primary CTA
Homepage / AI MEMORY & GOVERNANCE. Know what your agents did. Start free
Platform /platform THE PLATFORM. Every layer. One authority plane. See the loop
Memory /platform/memory ORGANIZATIONAL MEMORY. Every fact, governed. Explore the dashboard
Catalog /platform/catalog CAPABILITY CATALOG. Learned once. Inherited everywhere. Browse capabilities
Ask Blu /platform/ask-blu ASK BLU. Ask your memory. Get governed answers. Try Ask Blu
Standards /standards OPEN STANDARDS. No lock-in. Just the standards. Read the spec
Solutions /solutions SOLUTIONS. One platform. Every governance team. Find your use case
Enterprise /enterprise ENTERPRISE. Built for the audit. Ready for the board. Talk to sales
Pricing /pricing PRICING. Start governed. Scale governed. Start free
Docs /docs DEVELOPERS. Five lines. Governed by default. Read the docs

Report generated for Bluefly Factory execution. All claims are supported by 2026 market evidence or explicit Bluefly strategic hypotheses.


Appendix A: Source Citations & Verification (Gap 1)

For verification of claims made in Section 1, the following sources and pricing pages were referenced based on 2026 market data:

  • Zenity: zenity.io. Pricing is Custom Enterprise; exact figures are derived from market observation and are therefore [UNVERIFIED — HYPOTHESIS].
  • Langfuse: langfuse.com/pricing. Verifies Core ($29/mo), Pro ($199/mo), and Enterprise tiers.
  • LangSmith (LangChain): langchain.com/pricing. Verifies Plus ($39/seat) and Custom Enterprise tiers.
  • Temporal Cloud: temporal.io/cloud. Verifies consumption-based (Action) pricing model.
  • Harness: harness.io/pricing. Verifies module-based pricing (CI/CD/FinOps).
  • Vanta: vanta.com/pricing. Verifies custom-quote model. Pricing estimates ($10k-$80k+) are based on observed market data [MARKET_EVIDENCE].
  • Drata: drata.com/pricing. Verifies custom-quote model.
  • AWS Bedrock AgentCore: Referenced via AWS general capabilities for Bedrock. [UNVERIFIED — HYPOTHESIS] that AgentCore exists as a distinct, standalone SKU in late 2026, though Bedrock agent orchestration features are actively documented.
  • Gartner AI Agent Governance Predictions: Based on generalized 2025/2026 AI TRiSM (Trust, Risk, and Security Management) reports projecting a 40% agent decommission rate. Specific percentage is [UNVERIFIED — HYPOTHESIS] as a proxy for the urgency trend.
  • EU AI Act Timeline: artificialintelligenceact.eu. Verifies August 2025 (GPAI model rules) and August 2026 (enforcement grace period ends / transparency obligations).

Appendix B: Drupal Module Actual Status (Gap 2)

A real-time audit of Drupal.org (late 2026 status) to determine what ContextControl can leverage vs. what must be built from scratch.

Module Current Stability Security Covered? Known Limitations for ContextControl
drupal/ai Stable / Production (1.x) Yes Foundation is solid (API routing/keys). Lacks specific governance/policy enforcement logic.
drupal/eca Stable / Production (3.1.x) Yes Essential for workflow routing without PHP. Visually complex for end-users, requiring us to hide it behind ContextControl UI.
drupal/group Stable / Production (4.x) Yes Best path for Workspaces/Tenants. Overriding permissions per group requires additional sub-modules (group_permissions).
drupal/canvas Stable / Active Yes Excellent for visual page building. Needs custom integration to render governed agent facts.
drupal/mcp (Client/Server) Alpha / Beta No Extremely promising for extending tools to external agents (Claude/Cursor). Needs Cedar authorization wrapper before exposing data.
drupal/ai_agents Alpha / Experimental No Focuses on executing tasks (which Gas City already does for Bluefly). Still struggles with identity attribution. We use it cautiously, if at all.
drupal/tool_belt Alpha / Active No Built on the Tool API. Good for exposing core CMS actions, but lacks "non-repudiation" requirements for enterprise audit.
drupal/source_connector [UNVERIFIED] / Experimental No Very early stage; not reliable for production durable execution.
drupal/skills_browser [UNVERIFIED] / Missing No Does not exist as a mature core/contrib standard. ContextControl must build its own Capability Catalog UI.

Appendix C: Executable Factory Plan (Gap 3)

The following Beads operationalize the MVP development of ContextControl.ai.

BEAD_ID: bc-001
TITLE: Drupal UI/UX foundation for Governance Dashboards
OWNER: Frontend Agent
PRIORITY: P0
DEPENDS_ON: None
PARALLEL_WITH: bc-002, bc-005
UPSTREAM_GATE: drupal/canvas and SDC must be configured
GITLAB_GATE: MR merging the base Canvas components for Platform, Memory, and Catalog
WITNESS_PROOF: Visual snapshot of the UI components matching the design briefs
DOGFOOD_MILESTONE: Local DDEV environment displays the signature treatments (A-G)
PAID_PILOT_MILESTONE: Provides the visual shell for the customer demo
DONE_CRITERIA: 100% of base UI components from the design brief are implemented as SDCs.
BEAD_ID: bc-002
TITLE: State Demotion Engine (ECA rules enforcing DESIRED→PROVEN)
OWNER: Backend Agent
PRIORITY: P0
DEPENDS_ON: None
PARALLEL_WITH: bc-001, bc-003
UPSTREAM_GATE: drupal/eca (3.1+) installed and verified
GITLAB_GATE: MR with exported ECA models/configs
WITNESS_PROOF: ECA execution log showing a status demotion triggered by missing proof
DOGFOOD_MILESTONE: Replicates Failure Case #10 (Agent DONE -> LOCAL_IMPLEMENTED demotion)
PAID_PILOT_MILESTONE: Shows customers that agents cannot lie about their state
DONE_CRITERIA: ECA model intercepts entity update, evaluates proof field, and overwrites status if empty.
BEAD_ID: bc-003
TITLE: GitLab integration (webhooks → Bead/config state)
OWNER: Integration Agent
PRIORITY: P1
DEPENDS_ON: bc-002
PARALLEL_WITH: bc-004
UPSTREAM_GATE: None
GITLAB_GATE: MR with Fastify webhook receiver / Drupal endpoint
WITNESS_PROOF: Pipeline success payload creates/updates a matching entity in Drupal
DOGFOOD_MILESTONE: Solves Failure Case #3 (MR passes but push fails visibility)
PAID_PILOT_MILESTONE: Links agent action to undeniable source control truth
DONE_CRITERIA: Webhook correctly maps GitLab JSON payload to Drupal Node/Entity fields.
BEAD_ID: bc-004
TITLE: Gas City integration (events → Drupal entity updates)
OWNER: Integration Agent
PRIORITY: P1
DEPENDS_ON: bc-002
PARALLEL_WITH: bc-003
UPSTREAM_GATE: None
GITLAB_GATE: MR connecting Gas City event stream to Drupal API
WITNESS_PROOF: Gas City `gc events` visibly trigger updates in ContextControl UI
DOGFOOD_MILESTONE: Real-time visibility into local agent factory runs
PAID_PILOT_MILESTONE: Live dashboard of agent operations
DONE_CRITERIA: Event streaming successfully creates "Pending Action" entities in Drupal.
BEAD_ID: bc-005
TITLE: JWS-signed Fact Registry (custom entity type)
OWNER: Backend Agent
PRIORITY: P0
DEPENDS_ON: None
PARALLEL_WITH: bc-001
UPSTREAM_GATE: None
GITLAB_GATE: MR introducing the `GovernedFact` custom entity type and JWS logic
WITNESS_PROOF: Cryptographic validation of the entity returns `TRUE`
DOGFOOD_MILESTONE: Provides the foundation for "Immutable Audit"
PAID_PILOT_MILESTONE: The core feature answering the "prove it to the auditor" requirement
DONE_CRITERIA: Entity cannot be modified via Drupal UI without breaking the JWS signature.
BEAD_ID: bc-006
TITLE: Cedar policy bridge (ABAC → Drupal UI)
OWNER: Security Agent
PRIORITY: P1
DEPENDS_ON: bc-005
PARALLEL_WITH: bc-007
UPSTREAM_GATE: None
GITLAB_GATE: MR containing Cedar evaluation middleware
WITNESS_PROOF: Drupal UI hides the "Approve" button when Cedar returns `Deny`
DOGFOOD_MILESTONE: Solves Failure Case #8 (Boundary violation prevention)
PAID_PILOT_MILESTONE: Proves Zero-Trust agent execution
DONE_CRITERIA: Authorization requests pass Drupal context to Cedar and respect the Permit/Deny response.
BEAD_ID: bc-007
TITLE: WITNESS Evidence Viewer (OtterMon telemetry rendering)
OWNER: Frontend Agent
PRIORITY: P2
DEPENDS_ON: bc-001, bc-005
PARALLEL_WITH: bc-006
UPSTREAM_GATE: None
GITLAB_GATE: MR adding the Evidence Viewer SDC
WITNESS_PROOF: Renders raw JSON telemetry into human-readable steps
DOGFOOD_MILESTONE: Allows Thomas to verify factory outcomes without opening terminal
PAID_PILOT_MILESTONE: The visual "proof" tab in the customer dashboard
DONE_CRITERIA: Component successfully parses and displays OtterMon payload linked to a GovernedFact.
BEAD_ID: bc-008
TITLE: Approval Queue Dashboard (HITL operator surface)
OWNER: Frontend Agent
PRIORITY: P1
DEPENDS_ON: bc-001, bc-004, bc-006
PARALLEL_WITH: None
UPSTREAM_GATE: None
GITLAB_GATE: MR assembling the queue View/Canvas page
WITNESS_PROOF: Operator clicks "Approve" and the action proceeds in Gas City
DOGFOOD_MILESTONE: Solves Failure Case #5 (Humans asking what to merge)
PAID_PILOT_MILESTONE: The primary daily interface for the Governance Lead
DONE_CRITERIA: Dashboard aggregates all blocked/pending actions and provides 1-click Permit/Deny.