Australian PSPF assurance tooling

Local records. Shareable assurance.

A local-first compliance uplift tool for PSPF assessment work: author in VS Code, decide the current position, connect strategic choices to delivery actions, then review exposure and forward work in a shareable browser-based Explorer view.

Core is the trusted workspace record. Workshop is the operator decision surface. Assurance tracks assessments, findings, verification queues, and publication readiness. Shop links commercial planning to assurance. Pub keeps people and stakeholder context local. Explorer is the compliance uplift and forward-planning view: it supports defensible status decisions, evidence, mitigation suggestions, and a practical route from assessment outcome to the next work plan. Strategy delivery cues, closed-work history, evidence strength and temporal change help teams decide what needs attention next.

Recommended start path: Install Core and Workshop first. Then export a master bundle and open it in Explorer for reviewer-facing analysis. Pub records (people, teams, assignments) stay local and are not published to Explorer bundles.
1.60.0UX judgement-support: basis, consequence, blockers, trajectory, change, supplier verdict
1.15.0schema / bundle / API axes
6active product surfaces
0cloud database dependency
Official sourcesPSPF, ISM, Essential Eight
Core + WorkshopLocal authoring and validation
Assurance + Shop + PubAssessment, commercial, and people context
ExplorerPortable review bundle
Posture brief Master JSON Connected View Saved views Backup JSON

Products

Each surface has a distinct job. Version 1.51 keeps the system local-first, uses the master JSON bundle as the exchange boundary, and makes the route from assessment to strategic delivery easier to inspect.

C

Core

Marketplace

Local system of record, SQLite workspace, snapshots, validation, import/export, writer lock, and backup-oriented master JSON.

VS Code extensiontobyharvey.pspf-corelocal-only
Install Core →
W

Workshop

Marketplace

Day-to-day authoring for Requirements, Evidence, Actions, Risks, Directions, ISM mappings, tags, saved views, and posture briefs.

VS Code extensiontobyharvey.pspf-workshopdepends on Core
Install Workshop →
A

Assurance

Marketplace

Dedicated assurance surface for assessments, penetration testing workbench, finding queues, verification status, and publication-readiness checks.

VS Code extensiontobyharvey.pspf-assurancedepends on Core
Install Assurance →
E

Explorer

web

Compliance uplift and forward-planning view for reviewers: posture, records, local changes, saved views, Plan Lens, Connected View, exposure and copyable brief output. Explorer helps teams turn assessment results into defensible decisions, mitigation paths, and the next cycle of work rather than simply publishing a static status snapshot.

browser viewreads JSON bundleno server store
Open Explorer →
S

Shop

Marketplace

Commercial planning for suppliers, contracts, spend items, forecast review, and assurance-linked commercial context.

VS Code extensiontobyharvey.pspf-shopdepends on Core
Install Shop →
P

Pub

Marketplace

People, role, team, assignment, and stakeholder relationship foundation for local-only staff context, organisation charts, action badges, and responsibility signals. Pub records stay local and do not publish to Explorer bundles.

VS Code extensiontobyharvey.pspf-pubdepends on Core
Install Pub →

Workflow

The useful path is deliberately short: capture, validate, share, and recover. Every step keeps the authoritative policy source separate from local assessment data.

Step 1

Capture locally

Use Core, Workshop, and Assurance to maintain assessment state, evidence, actions, risks, Directions, ISM mappings, pentest findings, verification queues, and planning context.

Step 2

Decide and mitigate

Capture the current status, evidence, rationale, and standard mitigation options for each requirement or control. Link the resulting Actions to the Strategy Choice they deliver, keeping each decision defensible and ready to plan.

Step 3

Review and plan in Explorer

Open the bundle in Explorer for posture, records, Connected View, saved views, local changes, exposure, trends and a forward work-plan view. Closed Actions remain auditable without crowding the active plan.

Strategy: risk → priority → choice

The Workshop Cyber Strategy Map turns linked risk into explicit priority. Each strategic choice derives a priority band from the risks it links — so leadership sees which choices matter most, and why, without any extra data entry or cloud service.

Risk drives priority; priority drives choices

Linked risk severity (likelihood × impact) is adjusted by the choice's trend and confidence. The peak adjusted risk sets the choice's priority band. Nothing is persisted — it is a derived read model over existing data.

Linked risks Priority scoring Strategic choice Risk severity likelihood × impact Choice signals trend & confidence Peak adjusted score severity + trend + confidence most pressing linked risk wins Critical ≥ 28 High ≥ 20 Medium ≥ 10 Low ≥ 1 Choice focus top blockers + rationale

How it works

The ecosystem is a small set of canonical entities that flow through a single local workspace and exit through one validated JSON bundle. These diagrams show the lifecycle, the entity model, and what crosses the publication boundary into Explorer.

Data flow lifecycle

Official sources stay separate from your assessment data. A single SQLite workspace is the system of record; one master JSON bundle is the only exchange artefact.

Authoritative sources Local workspace (your machine) Publication PSPF policy requirement statements ISM OSCAL snapshot controls, mappings Essential Eight maturity reference read-only reference → Core workspace SQLite system of record Domain · Requirement · Evidence Action · Risk · Direction · Link Workshop authoring & assessment Assurance findings · verification Shop suppliers · contracts · spend Pub people · roles · assignments Validate & snapshot writer lock · schema · redaction publication boundary → Master JSON bundle manifest + entities + links schemaVersion · bundleVersion redacted by default Explorer (browser) posture · records · Connected View backup restore (validated review path)

Entity model

Every record has a stable prefixed ID and a typed link to other records. Domain anchors the assessment; Requirement is the hub; Evidence, Action, Risk, and Direction carry the assurance work.

Requirement REQ-* assessment status · effectiveness Domain DOM-* policy grouping ISM control ISM-* from OSCAL snapshot Evidence EVD-* freshness · verification Action ACT-* status · priority Risk RSK-* treatment status Direction DIR-* scope · cadence Shop · commercial Supplier SUP-* Contract CON-* Spend SPD-* linked to Requirement / Action for assurance context Pub · workforce (local only) Person PER-* Team TEM-* Role ROL-* Assignment (ASM-*) — never crosses to Explorer Assurance · local work queues Assessment local surface Verification readiness queue Tag · Link tagged-with · derived-from · supports groups maps supports addresses raised-by governed-by assigned-to (local)

Publication boundary

Every field declares a publication policy. Anything personal or restricted stays local; only labelled references and assurance-relevant context cross to Explorer.

Crosses to Explorer

  • Domain, Requirement, Evidence summaries, Action status, Risk and Direction records
  • ISM mappings and Essential Eight references
  • Supplier and contract identifiers used as assurance context
  • Assessment and verification status suitable for publication review
  • Tags, saved views, and link relationships
  • Posture brief content (already redacted)

Stays local (never exported)

  • Person names, emails, and any personal contact data
  • Assignment records (ASM-*) and team membership
  • Restricted-field values and non-public free text
  • Raw penetration testing notes, exploit detail, and internal verification working material
  • Internal-only notes flagged as sensitive
  • Workspace SQLite file and snapshot history