53 lines
3.5 KiB
Markdown
53 lines
3.5 KiB
Markdown
# CASAN Edition Feature and Limitation Matrix
|
||
|
||
This matrix is the customer-facing source of truth for edition claims. A check
|
||
means the capability is packaged and has repository evidence; it does not imply
|
||
an enterprise SLA, managed operation, or certification unless explicitly noted.
|
||
|
||
Edition and maturity are independent: edition describes shipped capability;
|
||
CASAN Maturity L1–L5 describes evidence-backed operational adoption.
|
||
|
||
| Capability | Core | DevKit | Platform Preview | Enterprise |
|
||
|---|---:|---:|---:|---:|
|
||
| H1–H7 harness, policy/action gates | Included | Included | Included | Building blocks only |
|
||
| CLI and evidence pack creation/verification | Included | Included | Included | Building blocks only |
|
||
| Project/domain templates and CI adoption guides | — | Included | Included | — |
|
||
| Gitea CI gate template | — | Included | Included | — |
|
||
| Control Panel: runs, governance, security, cost, approvals | — | — | Included | Not a shipped edition |
|
||
| Prompt assurance receipt + latest-run discovery | Included | Included | Included | Building blocks only |
|
||
| Core Local Assurance Viewer (single project, offline, read-only) | Included | Included | Included | Building blocks only |
|
||
| H1–H7 assurance rail + per-run HTML/JSON export | Included | Included | Included | Building blocks only |
|
||
| H6 AgentOps dossier + history + filters + HTML/JSON export | Included | Included | Included | Building blocks only |
|
||
| Clickable local trace deep link; central link when enrolled | Included | Included | Included | Building blocks only |
|
||
| One-command centralized Control Plane launcher | — | — | Included | Not a shipped edition |
|
||
| Async HMAC telemetry delivery with durable local spool | Included | Included | Included | Building blocks only |
|
||
| Evidence Pack Viewer | — | — | Included | Not a shipped edition |
|
||
| Governed chat/operator/codegen MVP | — | — | Included, preview | Not a shipped edition |
|
||
| Gitea webhook evidence publishing | — | — | Not yet available | Not available |
|
||
| Enterprise OIDC/CA/private-network deployment | — | — | Local smoke only | Not available |
|
||
| Vault/KMS enforced, immutable object storage | Harness building blocks | Harness building blocks | Not production packaged | Not available |
|
||
| HA, DR, RPO/RTO, production SLA | — | — | Not available | Not available |
|
||
| External pentest / ISO/SOC/ISMAP claim | — | — | Not available | Not available |
|
||
| Commercial license / support agreement | Required for paid use | Required for paid use | Required for paid use | Future contract only |
|
||
|
||
## Edition rules
|
||
|
||
- **Core** is the first paid-PoC product: use it with the customer’s existing
|
||
AI coding tools and CI. It includes a production-quality single-project
|
||
Local Assurance Viewer without Node/npm or a Platform dependency.
|
||
- **DevKit** adds repeatable adoption material. It does not add a managed
|
||
service or a security certification.
|
||
- **Platform Preview** includes the Control Panel and Evidence Pack Viewer,
|
||
plus centralized multi-project operations, RBAC and approvals. It is not
|
||
production enterprise software. The bundle has a
|
||
`PREVIEW-INCOMPLETE.txt` marker by design.
|
||
- **Enterprise** remains `future` and `package-release.sh enterprise` refuses
|
||
to generate an artifact. Do not advertise it as a purchasable edition.
|
||
|
||
## Claim guardrails
|
||
|
||
Do not claim “enterprise-ready”, “production HA”, “ISMAP compliant”, “APPI
|
||
compliant”, “immutable storage”, “signed evidence”, or “sandboxed codegen”
|
||
unless the corresponding deployment and verification evidence exists for that
|
||
customer environment.
|