Core
Local system of record, SQLite workspace, snapshots, validation, import/export, writer lock, and backup-oriented master JSON.
Project notice hidden.
A local-first compliance uplift tool for PSPF assessment work: author in VS Code, decide the current position, connect strategic choices to delivery actions, then review exposure and forward work in a shareable browser-based Explorer view.
Core is the trusted workspace record. Workshop is the operator decision surface. Assurance tracks assessments, findings, verification queues, and publication readiness. Shop links commercial planning to assurance. Pub keeps people and stakeholder context local. Explorer is the compliance uplift and forward-planning view: it supports defensible status decisions, evidence, mitigation suggestions, and a practical route from assessment outcome to the next work plan. Strategy delivery cues, closed-work history, evidence strength and temporal change help teams decide what needs attention next.
Each surface has a distinct job. Version 1.51 keeps the system local-first, uses the master JSON bundle as the exchange boundary, and makes the route from assessment to strategic delivery easier to inspect.
Local system of record, SQLite workspace, snapshots, validation, import/export, writer lock, and backup-oriented master JSON.
Day-to-day authoring for Requirements, Evidence, Actions, Risks, Directions, ISM mappings, tags, saved views, and posture briefs.
Dedicated assurance surface for assessments, penetration testing workbench, finding queues, verification status, and publication-readiness checks.
Compliance uplift and forward-planning view for reviewers: posture, records, local changes, saved views, Plan Lens, Connected View, exposure and copyable brief output. Explorer helps teams turn assessment results into defensible decisions, mitigation paths, and the next cycle of work rather than simply publishing a static status snapshot.
Commercial planning for suppliers, contracts, spend items, forecast review, and assurance-linked commercial context.
People, role, team, assignment, and stakeholder relationship foundation for local-only staff context, organisation charts, action badges, and responsibility signals. Pub records stay local and do not publish to Explorer bundles.
The useful path is deliberately short: capture, validate, share, and recover. Every step keeps the authoritative policy source separate from local assessment data.
Use Core, Workshop, and Assurance to maintain assessment state, evidence, actions, risks, Directions, ISM mappings, pentest findings, verification queues, and planning context.
Capture the current status, evidence, rationale, and standard mitigation options for each requirement or control. Link the resulting Actions to the Strategy Choice they deliver, keeping each decision defensible and ready to plan.
Open the bundle in Explorer for posture, records, Connected View, saved views, local changes, exposure, trends and a forward work-plan view. Closed Actions remain auditable without crowding the active plan.
The Workshop Cyber Strategy Map turns linked risk into explicit priority. Each strategic choice derives a priority band from the risks it links — so leadership sees which choices matter most, and why, without any extra data entry or cloud service.
Linked risk severity (likelihood × impact) is adjusted by the choice's trend and confidence. The peak adjusted risk sets the choice's priority band. Nothing is persisted — it is a derived read model over existing data.
The ecosystem is a small set of canonical entities that flow through a single local workspace and exit through one validated JSON bundle. These diagrams show the lifecycle, the entity model, and what crosses the publication boundary into Explorer.
Official sources stay separate from your assessment data. A single SQLite workspace is the system of record; one master JSON bundle is the only exchange artefact.
Every record has a stable prefixed ID and a typed link to other records. Domain anchors the assessment; Requirement is the hub; Evidence, Action, Risk, and Direction carry the assurance work.
Every field declares a publication policy. Anything personal or restricted stays local; only labelled references and assurance-relevant context cross to Explorer.
ASM-*) and team membershipStart with the authoritative sources, then install the local tools and open Explorer when you have a bundle to review.
Official PSPF policy and guidance.
authoritativeOfficial mitigation strategy terminology.
published viewLoad a master JSON bundle in a browser.
MarketplaceInstall the local system of record.
MarketplaceInstall the authoring surface.
MarketplaceInstall the assessment and verification surface.
MarketplaceInstall commercial planning support.
MarketplaceInstall people and stakeholder context support.
relatedRelated home-use project with separate development and repository setup.