Actual capability state

What works, what is degraded, and what is not connected

Every capability is tied to a user journey, state, and latest successful check. Engineering checks and external gates are listed separately below.

Functional readiness

Capabilities that perform a real action

The measure counts only available working capabilities. Catalogues, placeholders, disabled and degraded services do not increase the percentage.

working: 40/50 · verified on this revision: 40%

FUNC80%Functional readiness
40/50working
0degraded
40%verified on this revision

Sources

88%
88%

7/8 working

Capture

83%
83%

5/6 working

EvidenceResearch material whose provenance, time, integrity state and link to an exact source version are preserved.

100%
100%

6/6 working

Analysis

75%
75%

3/4 working

Search

80%
80%

4/5 working

Graph

100%
100%

4/4 working

Maps

67%
67%

2/3 working

Collaboration

33%
33%

1/3 working

Publication

75%
75%

3/4 working

Operations

71%
71%

5/7 working

Sources7/8
CapabilityStatusLast successful check
Kazakhstan Source AtlasA research catalog of potential Kazakhstan sources with their coverage, owner, risk and mandatory admission gates.Open the Atlas and inspect a source card working local-tested
Source guidesOpen a guide and inspect its search boundaries working local-tested
Add an Atlas source to a caseAdd an Atlas card to a protected case, reopen the plan, and export it working local-tested
QazLake exchange ratesCapture rates, open the JSON snapshotAn immutable control copy of an open dataset or page at a defined point in time., and export the case working local-tested · verified on this revision
QazLake source summaryCapture the summary and verify the snapshot digest working local-tested · verified on this revision
QazLake economic indicatorsCapture indicators and open the versioned JSON working local-tested · verified on this revision
QazLake data qualityCapture quality status and open the resulting version working local-tested · verified on this revision
Portfolio integration catalogueInspect adapter state, version, limits, and kill switchA control that immediately disables a connector or risky capability and prevents unauthorized reactivation. catalogue or contract only local-tested
Capture5/6
CapabilityStatusLast successful check
Browser evidence packageEnter a URL, build a package, and reopen it working local-tested
Import a local package into a protected caseUpload an encrypted local package, verify its digest and anchor, and open the protected evidence working local-tested · verified on this revision
Owner public URL captureCapture a URL and open the hashed evidence working local-tested
Owner file ingestAdd a file and open its digest-verified snapshot working local-tested · verified on this revision
Capture NBK rates through QazPipeQueue NBK rates, verify the receipt and artifact digest, and reopen the protected evidence working local-tested · verified on this revision
TenantA security boundary isolating one organization's users, cases, keys and policy from every other organization. network captureCapture an admitted URL inside a tenant case disabled Tenant identity and the execution contour are not connected no successful check yet
Evidence6/6
CapabilityStatusLast successful check
Protected document text derivativeUpload a Kazakh, Russian or English document and open its encrypted text, exact tool version, original digest and page anchors working local-tested · verified on this revision
Protected media metadata and frameUpload owner media and open the encrypted metadata summary, representative frame, perceptual hash and original digest working local-tested
Synthetic case workbenchCreate a case and reopen its evidence and claimAn atomic, verifiable statement linked to evidence, a coverage envelope and separate human assessment dimensions. working local-tested
Protected owner caseAdd multiple evidence items and a claim to one case working local-tested
Protected evidence readerOpen text or JSON and compare the snapshot digest working local-tested
Evidence anchorsAn exact pointer to a fragment of a document, page, image or media item that supports or refutes a conclusion. and provenanceNavigate from a claim to its exact evidence anchor working local-tested
Analysis3/4
CapabilityStatusLast successful check
Synthetic analyzersAnalyze an approved fixture and inspect its findings working local-tested
Science methodsOpen a method cardA versioned record of a method's purpose, inputs, steps, version, limits and failure mode., current control run, dataset provenance, and review log working local-tested · verified on this revision
Owner evidence analysisAnalyze evidence and send the result for review working local-tested · verified on this revision
QazCompute contractInspect the input policy and execution state catalogue or contract only no successful check yet
Search4/5
CapabilityStatusLast successful check
Synthetic case searchFind case records by query and open a result working local-tested
Atlas filteringFind a source using RU, KK or EN text and transliterationA rule for rendering a name in another script; it aids discovery but does not prove identity., then save the filters in the browser working local-tested
Reproducible owner case searchSearch one case in Russian, Kazakh or transliteration, save the query, and compare its result after the index changes working local-tested · verified on this revision
Tenant multilingual searchSearch tenant cases in Kazakh, Russian, and English disabled organization-identity local-tested · verified on this revision
Shared search, graph and timeline resultSelect a table record and open the same query, digest and selection in graph and timeline working local-tested · verified on this revision
Graph4/4
CapabilityStatusLast successful check
Synthetic evidence graphPropose, accept, or reject a relationship working local-tested
Evidence-anchored entity candidatesPreserve two candidates with matching values, open their evidence anchors, and record a human same-object decision working local-tested · verified on this revision
Evidence-anchored relationship graphPropose a temporally bounded relationship between two objects, open its exact evidence, and record a human decision working local-tested · verified on this revision
Unified case timelineReview source versions, jobs, findings, decisions and exports in one stable order, then open the exact evidence behind a finding working local-tested · verified on this revision
Maps2/3
CapabilityStatusLast successful check
Safe QazGeo regional surfaceOpen a regional layer as a map and table working local-tested
Evidence-linked case placesAdd a place candidate with an evidence anchor, select it in the table, and record a human decision with a disclosure boundary working local-tested · verified on this revision
QazGeo case mapCompare case evidence on a provenance-linked map disabled The QazGeo adapter remains contract-only no successful check yet
Collaboration1/3
CapabilityStatusLast successful check
Synthetic human reviewThe stage where an authorized professional examines evidence, method, limitations and harm risk and records a decision.Record an alternative hypothesis and make a review decision working local-tested
Organizations and rolesUse isolated case workspaces for two organizations disabled organization-identity local-tested · verified on this revision
Team review queueAssign a case to a reviewer and receive a decision disabled organization-identity local-tested · verified on this revision
Publication3/4
CapabilityStatusLast successful check
Synthetic case exportDownload JSON and the print report working local-tested
Encrypted owner exportDownload a case bundle and verify its receipt digest working local-tested
Editorial handoffRecord redactionControlled removal or masking of personal, confidential or potentially harmful material before disclosure. and editorial disclosure decisionsA recorded decision defining which material may be disclosed, to which audience, after what redaction and under which policy version. for an accepted claim, then download the bounded brief working local-tested · verified on this revision
Autonomous publicationPublish material without a human decision disabled The product contract requires a human decision no successful check yet
Operations5/7
CapabilityStatusLast successful check
Public runtime healthVerify readiness and exact release identity working local-tested
Functional readiness registryInspect ten readiness categories and their latest checks working local-tested
Owner action dashboardInspect cases, tasks, reviews, exports, and errors on one protected page working local-tested · verified on this revision
Owner durable operation queueQueue a task and reopen its evidence and receipt after a worker restart working local-tested · verified on this revision
Integration observabilityInspect health, latency, and error class for every adapter working local-tested · verified on this revision
Database recovery drillRestore a local snapshot and verify integrity catalogue or contract only no successful check yet
Production monitoring and alertingReceive a failure alert before a user report not connected No formal runtime owner or alerting contour is assigned no successful check yet

Readiness

Verified
24local checks passed
8external owner gates
11adapters disabled

Synthetic local contour only

local-engineering-pass · production=false · private-data=false

VerifiedLOCAL-1

Evidence SpineThe connected chain from source to conclusion that preserves versions, exact anchors, limitations, transformations and human decisions. and strict persisted contracts

  • schemas
  • tests/test_domain_models.py
  • tests/test_service_workflow.py
VerifiedLOCAL-2

Tenant and case isolation with purpose-bound roles

  • app/context.py
  • app/storage.py
  • tests/test_storage.py
VerifiedLOCAL-3

Hash-chained auditA log where every event is linked to the previous event hash, making later undisclosed alteration detectable. and tamper detection

  • app/storage.py
  • tests/test_storage.py
VerifiedLOCAL-4

No-network capture target and DNS policy

  • app/capture_policy.py
  • science/benchmarks/capture-policy-hostile-v1.json
  • tests/test_capture_policy.py
VerifiedLOCAL-5

Idempotent durable operation lifecycle

  • schemas/operation-job-v1.schema.json
  • schemas/run-receipt-v1.schema.json
  • app/services/hub.py
  • app/runner.py
  • tests/test_jobs.py
  • tests/test_runner.py
VerifiedLOCAL-6

Tenant-local multilingual reference search

  • app/search.py
  • science/benchmarks/local-search-multilingual-v1.json
  • tests/test_search.py
VerifiedLOCAL-7

Database and immutable-vault recovery rehearsal

  • app/storage.py
  • app/vault.py
  • scripts/verify_pilot.py
  • tests/test_recovery.py
VerifiedLOCAL-8

Encrypted private case portability

  • app/bundles.py
  • tests/test_bundle.py
VerifiedLOCAL-9

Typed portfolio adapter admission: QazPipe approved and ten candidates fail-closed

  • reference/adapters/portfolio-adapters.v2.json
  • reference/adapters/adapter-contract-kit.v1.json
  • app/adapters.py
  • app/adapter_runtime.py
  • app/external_adapters.py
  • tests/test_adapters.py
  • tests/test_external_adapters.py
VerifiedLOCAL-10

Reproducible Science benchmarkA test set with expected answers that measures a reference implementation, not real-world quality. and method registry

  • science/methods
  • science/benchmarks
  • app/benchmarks.py
  • scripts/verify_benchmarks.py
VerifiedLOCAL-11

Dependency locks SBOMA machine-readable inventory of software components, versions and provenance included in a specific product build. and clean-tree release gate

  • requirements.lock
  • requirements-dev.lock
  • artifacts/openapi.json
  • artifacts/sbom.spdx.json
  • scripts/verify_release.py
VerifiedLOCAL-12

Static fail-closed container profile without runtime claim

  • Dockerfile
  • docker-compose.yml
  • .dockerignore
  • tests/test_deployment_contract.py
VerifiedLOCAL-13

Strict multilingual glossary and accessible first-occurrence definitions

  • reference/glossary/osint-glossary.v1.json
  • app/glossary.py
  • tests/test_glossary.py
VerifiedLOCAL-14

Complete read-only synthetic Investigation Workbench

  • app/workbench.py
  • templates/workbench_case.html
  • tests/test_workbench.py
VerifiedLOCAL-15

Content, persona, responsive and accessibility acceptance contract

  • docs/PERSONA_ACCEPTANCE.md
  • docs/CONTENT_OPERATING_SYSTEM.md
  • reference/content/content-registry.v1.json
  • reference/content/route-persona-ledger.v1.json
  • scripts/verify_ui.py
  • tests/test_content_surface.py
VerifiedLOCAL-16

Dense evidence triage, explicit comparison, evidence-bound graph and reviewer workflow

  • app/workbench.py
  • app/operator_session.py
  • templates/workbench.html
  • tests/test_workbench.py
VerifiedLOCAL-17

Aggregate-only QazGeo and QazShield-to-candidate contract rehearsals

  • app/qazgeo_safe.py
  • app/qazstack_contracts.py
  • templates/tools.html
  • tests/test_qazgeo_safe.py
  • tests/test_qazstack_contracts.py
VerifiedLOCAL-18

Backend-neutral stores and PostgreSQL 17 transactional source of truth

  • app/storage_contracts.py
  • app/postgres_store.py
  • migrations/versions/0001_postgres_v1.py
  • tests/integration/test_production_data_plane.py
VerifiedLOCAL-19

Immutable S3 catalog tenant keys and re-authorized Meilisearch projection

  • app/s3_vault.py
  • app/key_provider.py
  • app/search_index.py
  • app/search_worker.py
  • tests/test_data_plane_adapters.py
VerifiedLOCAL-20

Count digest audit-head object-checksum migration and isolated restore contract

  • scripts/migrate_sqlite_to_postgres.py
  • scripts/create_migration_fixture.py
  • .github/workflows/ci.yml
  • docs/runbooks/INTERNAL_PILOT_RECOVERY.md
VerifiedLOCAL-21

Generated capability contract binds routes roles navigation readiness and release

  • app/capability_registry.py
  • app/routers/auth.py
  • app/routers/operator.py
  • app/routers/cases.py
  • tests/test_osint_v4_contracts.py
VerifiedLOCAL-22

Visitor and five-role Playwright acceptance from 320 to 1920 pixels

  • tests/browser/test_studio_browser.py
  • .github/workflows/ci.yml
VerifiedLOCAL-23

Dedicated runtime backup retentionThe approved time and conditions before material is deleted, archived or placed on legal hold. metrics alerts and runbooks

  • deploy/internal-pilot/docker-compose.runtime.yml
  • deploy/internal-pilot/prometheus-alerts.yml
  • app/backup_worker.py
  • app/retention_worker.py
  • app/metrics.py
  • tests/test_internal_pilot_release.py
VerifiedLOCAL-24

Immutable environment capacity links and six-job CI release controls

  • scripts/validate_internal_pilot_environment.py
  • scripts/check_release_capacity.py
  • scripts/reconcile_runtime_links.py
  • tests/test_deployment_contract.py
  • .github/workflows/ci.yml

Owner required

external owner gates

Owner requiredEXTERNAL-1

License legal privacy and source terms

Portfolio owner plus Legal and DPO

Required closure evidence

Selected project and data licenses, approved legal register, DPIAA prior assessment of risks that personal-data processing creates for people and the measures used to reduce those risks. and connector-specific source admission.

Owner requiredEXTERNAL-2

Production QDEV OIDC credentials role mapping revocation and recovery

Identity owner plus Security

Required closure evidence

Registered qosint.net callback, production client credentials, five-role smoke, revocation and recovery drill.

Owner requiredEXTERNAL-3

Managed KZ evidence and backup S3 policies and tenant keys

Security plus Storage owner

Required closure evidence

KZ hosting attestation, distinct evidence and backup buckets, least-privilege policy, object checksum, signed-download and tenant-key isolation evidence.

Owner requiredEXTERNAL-4

Dedicated runtime capacity and edge private link

Runtime owner plus Edge owner

Required closure evidence

Named 8 vCPU 16 GiB 200 GiB NVMe host, at least 15 percent free, private tunnel proof and no production CI runner.

Owner requiredEXTERNAL-5

Hosted CI security and parser isolation

Security plus CI owner

Required closure evidence

All six required CI jobs green, dependency and secret audit, IDOR OIDC CSRF SSRFA vulnerability class where an attacker causes a server to request an internal, local or otherwise forbidden address. upload tests and parser isolation review.

Owner requiredEXTERNAL-6

Backup restore search rebuild and rollback rehearsal

Storage owner plus Operations

Required closure evidence

Fresh pre-release backup, RPO at most 15 minutes, RTO at most 4 hours, Meilisearch rebuild within 60 minutes and current rollback link receipt.

Owner requiredEXTERNAL-7

Named pilot users operations ownership training and incident tabletop

Product plus Partners plus Security

Required closure evidence

At most five named users, runtime owner, on-call contact, role training, offboarding rehearsal and incident action log.

Owner requiredEXTERNAL-8

Maintenance window final migration edge switch and public proof

Product owner plus Release owner

Required closure evidence

Approved window, exact 691 842 17 53 migration receipt, immutable 0.4.0 image and manifest, edge switch, OIDC smoke and desktop mobile public verification.