From b81b532c1d39c01425ff6200dcd9acc87b6ecd7a Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Fri, 25 Sep 2026 20:21:40 +0200 Subject: [PATCH 1/2] feat(parity): start stackiq's capability matrix (work in progress) 173 rows in 12 areas against five competitor columns, competitor cells from the intelligence database. Stackiq's own column is not read yet. --- openspec/parity/capabilities.json | 2910 +++++++++++++++++++++++++++++ 1 file changed, 2910 insertions(+) create mode 100644 openspec/parity/capabilities.json diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json new file mode 100644 index 000000000..d885fb5e8 --- /dev/null +++ b/openspec/parity/capabilities.json @@ -0,0 +1,2910 @@ +{ + "comparedOn": "2026-09-25", + "category": "Stackiq is a software and application catalogue for public-sector organisations, mapped to the GEMMA reference architecture. It does two jobs in one product: it is the back office and API of a national, public market-transparency catalogue (suppliers publish what they offer, municipalities record what they use and how it connects, everything is plotted on GEMMA reference components), and it gives one organisation a portfolio view of its own landscape (contracts, lifecycle, licences, vulnerabilities, compliance). So it competes first with the VNG GEMMA Softwarecatalogus it is built to succeed (its requirements are the VNG issues in issues.md), second with application portfolio and enterprise architecture tools that municipalities buy for the same landscape (SAP LeanIX, BlueDolphin), and third with the CMDB and IT asset tools that already hold a municipality's software list (GLPI, TOPdesk). It is not a discovery agent, a service desk or a developer portal, and the operations area exists to record that on purpose. Correct this paragraph if the category is wrong: the areas, the phrasing and the columns all follow from it.", + "columnsWhy": "Five competitor columns. VNG GEMMA Softwarecatalogus is the incumbent and the requirement source. SAP LeanIX is the application portfolio management reference and BlueDolphin (ValueBlue) the Dutch ArchiMate-first EA tool sold to municipalities. GLPI is the open-source ITAM and CMDB with the deepest research on file (a source reading by the procest lane on 2026-09-14 on top of the docs pass), and TOPdesk is the service management and CMDB suite most Dutch municipalities already run. Left out: Backstage, Port, Cortex, OpsLevel, Compass and other developer portals (a different buyer and a catalog-info.yaml model); ServiceNow CMDB, Flexera/Snow, BMC Helix and Alfabet (enterprise-priced, and the licence and SAM rows below already carry the ideas they would add); Ardoq, MEGA HOPEX, BiZZdesign, Sparx, Archi and the other EA tools (LeanIX and BlueDolphin stand for the class); i-doit, Snipe-IT, Lansweeper, OCS, Ralph, NetBox, Device42 and CMDBuild (discovery and hardware, where GLPI stands for the open-source class); and Atlas Governance, Kong, Gravitee, Apigee, Postman, SwaggerHub, Stoplight, RapidAPI and Sensus BPM, which are linked to softwarecatalog in the intelligence database but are board, API gateway or process tools and noise for this product.", + "corpus": { + "repo": "ConductionNL/concurrentie-analyse (intelligence database)", + "file": "competitor_features, canonical_features and competitor_apps for app_slug softwarecatalog; stackiq issues.md for the VNG requirements" + }, + "systems": [ + { + "key": "stackiq", + "name": "Stackiq", + "vendor": "Conduction", + "isSelf": true, + "readOn": "2026-09-25" + }, + { + "key": "vng-softwarecatalogus", + "name": "GEMMA Softwarecatalogus", + "vendor": "VNG Realisatie", + "readOn": "2026-07-23", + "evidenceGrade": "docs-only", + "unknownReason": "Not covered by the 20 intelligence rows for this system (a docs pass dated 2026-04-12 and 2026-07-23); the public site was not driven." + }, + { + "key": "sap-leanix", + "name": "SAP LeanIX", + "vendor": "SAP", + "readOn": "2026-07-23", + "evidenceGrade": "docs-only", + "unknownReason": "Not covered by the 24 intelligence rows for this system (docs passes dated 2026-04-12 and 2026-07-23); no trial was opened." + }, + { + "key": "bluedolphin", + "name": "BlueDolphin", + "vendor": "ValueBlue", + "readOn": "2026-07-23", + "evidenceGrade": "docs-only", + "unknownReason": "Not covered by the 22 intelligence rows for this system (docs passes dated 2026-04-12 and 2026-07-23); no trial was opened." + }, + { + "key": "glpi", + "name": "GLPI", + "vendor": "Teclib", + "readOn": "2026-07-23", + "evidenceGrade": "docs-only", + "unknownReason": "Not covered by the GLPI rows read for this product (a docs pass dated 2026-07-23) or by the procest lane's source reading of 2026-09-14, which answered case-management questions." + }, + { + "key": "topdesk", + "name": "TOPdesk", + "vendor": "TOPdesk", + "readOn": "2026-07-23", + "evidenceGrade": "docs-only", + "unknownReason": "Not covered by the 50 intelligence rows for this system (docs passes dated 2026-04-10 to 2026-07-23); the product was not driven." + } + ], + "areas": [ + { + "key": "landscape", + "name": "Application landscape register", + "name_nl": "Applicatielandschap registreren" + }, + { + "key": "connections", + "name": "Integrations and dependencies", + "name_nl": "Koppelingen en afhankelijkheden" + }, + { + "key": "architecture", + "name": "GEMMA and ArchiMate", + "name_nl": "GEMMA en ArchiMate" + }, + { + "key": "compliance", + "name": "Standards, BIO and compliance", + "name_nl": "Standaarden, BIO en compliance" + }, + { + "key": "market", + "name": "Supplier offering and market transparency", + "name_nl": "Aanbod en markttransparantie" + }, + { + "key": "lifecycle", + "name": "Lifecycle, roadmap and rationalisation", + "name_nl": "Levenscyclus, roadmap en rationalisatie" + }, + { + "key": "contracts", + "name": "Contracts, licences and costs", + "name_nl": "Contracten, licenties en kosten" + }, + { + "key": "security", + "name": "Vulnerabilities and software supply chain", + "name_nl": "Kwetsbaarheden en softwareketen" + }, + { + "key": "organisations", + "name": "Organisations, accounts and access", + "name_nl": "Organisaties, accounts en toegang" + }, + { + "key": "sharing", + "name": "Open data, federation and APIs", + "name_nl": "Open data, federatie en API's" + }, + { + "key": "insight", + "name": "Search, dashboards and reports", + "name_nl": "Zoeken, dashboards en rapportages" + }, + { + "key": "operations", + "name": "Discovery and IT operations", + "name_nl": "Discovery en IT-beheer" + } + ], + "providers": [ + { + "key": "stackiq", + "name": "Stackiq", + "kind": "self" + }, + { + "key": "openregister", + "name": "OpenRegister", + "kind": "app" + }, + { + "key": "opencatalogi", + "name": "OpenCatalogi", + "kind": "app" + }, + { + "key": "decidiq", + "name": "Decidiq (app id decidesk)", + "kind": "app" + }, + { + "key": "integriq", + "name": "Integriq (app id openconnector)", + "kind": "app" + }, + { + "key": "portaliq", + "name": "Portaliq", + "kind": "app" + }, + { + "key": "nextcloud", + "name": "Nextcloud", + "kind": "platform" + } + ], + "capabilities": [ + { + "id": "land-register-application", + "area": "landscape", + "name": "Register an application your organisation uses, with its supplier, description and status.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "partial", + "topdesk": "partial", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | docs, intelligence competitor_features#27422 'Fact Sheets & Data Model' (2026-04-12): Flexible data model for applications, processes, IT components", + "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository. | docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", + "glpi": "docs, intelligence competitor_features#48900 'Software inventory & catalog' (2026-07-23): Detects installed software and normalises into a software catalog. | docs, intelligence competitor_features#3267 'Software Catalog' (2026-03-28): Manage software licenses and installations | Rated partial because software is an inventoried asset, not a described application.", + "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure | Rated partial because software is a CMDB object among assets.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-application-modules", + "area": "landscape", + "name": "Break an application into modules and see which module belongs to which product.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated partial because fact sheets separate Application from IT Component.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-module-versions", + "area": "landscape", + "name": "Record the released versions of a module, with the date each came into use.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48900 'Software inventory & catalog' (2026-07-23): Detects installed software and normalises into a software catalog. | Rated partial because installed versions come from inventory.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-usage-record", + "area": "landscape", + "name": "Record that your organisation uses a module, as a usage separate from the product itself.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "partial", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", + "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-suite", + "area": "landscape", + "name": "Bundle several existing applications into one suite that is offered as a single product.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-services", + "area": "landscape", + "name": "Register a service a supplier delivers on top of one or more applications, such as hosting or support.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | Rated partial because offering registration covers products; services not named in the reading.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-sectors", + "area": "landscape", + "name": "Tag applications with the government sectors they are meant for.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-application-owner", + "area": "landscape", + "name": "Name the business owner and the technical owner responsible for an application.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | Rated partial because surveys go to application owners, so ownership is modelled.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-custom-fields", + "area": "landscape", + "name": "Add your own fields to an application without a developer changing the data model.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because flexible fact sheet data model.", + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141835 '11.17 Custom object type management': GLPI 11 ships admin-defined itemtypes with custom fields and capabilities (`src/Glpi/CustomObject/AbstractDefinition.php`, `src/Glpi/Asset/AssetDefinition.php`, `src/Glpi/Asset/CustomFieldDefinition.php`), but the machin | Rated yes because custom asset definitions and custom fields, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-bulk-import", + "area": "landscape", + "name": "Import an existing application list in bulk from a spreadsheet or file.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#27428 'EAM Automation' (2026-04-12): Automated data collection from ServiceNow, Jira, cloud providers | Rated partial because automated collection from ServiceNow, Jira and cloud.", + "bluedolphin": "docs, intelligence competitor_features#48971 'Data import (Excel)' (2026-07-23): Bulk import of application/portfolio data.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-migrate-legacy", + "area": "landscape", + "name": "Bring over what was registered in the previous catalogue so nobody has to type it in again.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-detail-page", + "area": "landscape", + "name": "Open one application and see its versions, usages, contracts and compliance on one page.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because fact sheet is the per-application page.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-bulk-edit", + "area": "landscape", + "name": "Select many catalogue entries at once and publish, lock or delete them together.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-duplicate-merge", + "area": "landscape", + "name": "Merge two catalogue entries that turn out to describe the same thing.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-data-quality-survey", + "area": "landscape", + "name": "Ask application owners through a survey to confirm or correct their entries.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | docs, intelligence competitor_features#27423 'Survey-Based Data Collection' (2026-04-12): Crowdsource architecture data from application owners", + "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-completeness-score", + "area": "landscape", + "name": "See how complete and up to date each application's entry is, as a score.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-demo-data", + "area": "landscape", + "name": "Load a set of example data so a new installation can be tried out straight away.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-guided-wizard", + "area": "landscape", + "name": "Add an application, service or connection through a step-by-step wizard instead of a bare form.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-sbom-components", + "area": "landscape", + "name": "See the third-party components a module version is built from.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "land-hosting-model", + "area": "landscape", + "name": "Record whether an application runs on premises, as SaaS or at a hosting party.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | Rated partial because SaaS is tracked as a class of application.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-register-connection", + "area": "connections", + "name": "Register a connection between two applications, with its direction and the standard it uses.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "yes", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-external-provision", + "area": "connections", + "name": "Record a connection from an application to a national provision such as a basisregistratie.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48841 'National provisions (landelijke voorzieningen) linking' (2026-07-23): Records links between applications and national government provisions.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-list-page", + "area": "connections", + "name": "Browse all connections in the catalogue in one list and open each one.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-per-application", + "area": "connections", + "name": "See every connection an application has, from that application's own page.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-diagram", + "area": "connections", + "name": "See the connections between applications drawn as a diagram.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model. | docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", + "bluedolphin": "docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models. | docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145369 'C-case-core-38 The graph of what a case is linked to is drawn, and exported.': glpi: Impact graph (Tools, front/impactitem.php, impactcsv.php, src/Impact.php) Lane findings: D-glpi-40. | Rated yes because impact graph, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-impact-analysis", + "area": "connections", + "name": "Before changing or retiring an application, see what depends on it.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "yes", + "glpi": "yes", + "topdesk": "partial", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", + "glpi": "docs, intelligence competitor_features#48902 'CMDB & configuration relations' (2026-07-23): CI relationships and impact analysis.", + "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because relations between assets.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-usage-of-connection", + "area": "connections", + "name": "Record that your organisation actually runs a given connection, not only that it exists.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-shared-with-others", + "area": "connections", + "name": "See which connections you run together with other organisations.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-type-filter", + "area": "connections", + "name": "Filter connections by type, such as an API, a file exchange or a message.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-api-catalogue", + "area": "connections", + "name": "Keep the APIs an application exposes in the catalogue next to the application.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#27425 'API Management' (2026-04-12): Catalog and manage APIs across the application landscape", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-export-graph", + "area": "connections", + "name": "Export the graph of what an application is linked to, for use elsewhere.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145369 'C-case-core-38 The graph of what a case is linked to is drawn, and exported.': glpi: Impact graph (Tools, front/impactitem.php, impactcsv.php, src/Impact.php) Lane findings: D-glpi-40. | Rated yes because impactcsv export, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "conn-integration-registry", + "area": "connections", + "name": "Add and check the organisation's outside integrations from one integrations overview.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-refcomp-mapping", + "area": "architecture", + "name": "Place an application on the GEMMA reference components it fulfils.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48835 'Reference component mapping (referentiecomponenten)' (2026-07-23): Maps each registered software product onto GEMMA reference components/domains so functionality is comparable across suppliers. | docs, intelligence competitor_features#27551 'Reference Component Linking' (2026-04-12): Link software to GEMMA reference components", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-gemma-views", + "area": "architecture", + "name": "Open a GEMMA architecture view with your own applications drawn inside it.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | Rated yes because landscape auto-plotted on the reference component map.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-shared-overlay", + "area": "architecture", + "name": "On a GEMMA view, see which applications you share with partner organisations, drawn differently from your own.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-import-amef", + "area": "architecture", + "name": "Import an ArchiMate model file in the Open Group exchange format.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27459 'ArchiMate & BPMN Support' (2026-04-12): Full ArchiMate and BPMN modeling in one platform | Rated yes because full ArchiMate support; import format not named in the reading.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-export-amef", + "area": "architecture", + "name": "Export the catalogue as an ArchiMate file that opens in Archi or another modelling tool.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools", + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-export-org", + "area": "architecture", + "name": "Export one organisation's landscape plotted on GEMMA as its own ArchiMate file.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape | docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools | Rated yes because map and export the municipality's landscape.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-round-trip", + "area": "architecture", + "name": "Check that a model survives import and export without losing elements or relations.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-import-progress", + "area": "architecture", + "name": "Follow a long model import while it runs, and cancel it if needed.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-gemma-api", + "area": "architecture", + "name": "Retrieve the GEMMA architecture itself through an API.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-definitions", + "area": "architecture", + "name": "Read the definition of a GEMMA term in place while working in the catalogue.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-capability-map", + "area": "architecture", + "name": "Map applications to business capabilities or functions and see the map.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | docs, intelligence competitor_features#27420 'Business Capability Mapping' (2026-04-12): Map applications to business capabilities and processes", + "bluedolphin": "docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-modelling", + "area": "architecture", + "name": "Draw and edit architecture models yourself inside the tool.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model.", + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-process-mapping", + "area": "architecture", + "name": "Model business processes and link them to the applications that support them.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27464 'Process Mapping' (2026-04-12): Map processes, applications, data, and technology", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-scenarios", + "area": "architecture", + "name": "Model a future-state landscape and compare it with today's.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#27419 'IT Transformation' (2026-04-12): Plan and execute cloud migrations and modernization | Rated partial because transformation planning.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-gap-analysis", + "area": "architecture", + "name": "Find reference components that no application in your landscape covers.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "arch-ai-diagram", + "area": "architecture", + "name": "Have a diagram drafted for you by an assistant from a description.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48970 'AI-powered diagramming' (2026-07-23): AI assists diagram generation. | docs, intelligence competitor_features#27461 'AI-Powered Diagramming' (2026-04-12): Auto-generate BPMN diagrams with built-in AI", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-standards-register", + "area": "compliance", + "name": "Browse a register of the standards applications are expected to support.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports. | docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-declare-standard", + "area": "compliance", + "name": "Declare that an application supports a specific version of a standard.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-evidence", + "area": "compliance", + "name": "Attach a test report or other evidence to a compliance claim.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-verified-vs-claimed", + "area": "compliance", + "name": "Tell a verified compliance claim apart from one the supplier only asserts.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-matrix", + "area": "compliance", + "name": "See applications against chosen standards in one matrix, cell by cell.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-bulk-sync-standards", + "area": "compliance", + "name": "Bring the standards set of many applications up to date in one action.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-bio-measures", + "area": "compliance", + "name": "Browse the BIO information security measures with their theme and level.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-bio-assessment", + "area": "compliance", + "name": "Record which BIO measures an application meets and which it does not.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-dpia", + "area": "compliance", + "name": "Record whether a data protection impact assessment has been done for an application.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-forum-standaardisatie", + "area": "compliance", + "name": "Check an application against the Forum Standaardisatie comply-or-explain list.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-health-scoring", + "area": "compliance", + "name": "Score the correctness and completeness of the register against a rule set.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "comp-audit-questionnaire", + "area": "compliance", + "name": "Send a compliance questionnaire to a supplier and keep the answers with the application.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders. | Rated partial because questionnaires collect portfolio data.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-supplier-offering", + "area": "market", + "name": "As a supplier, publish the applications and services you offer to government.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | docs, intelligence competitor_features#27555 'Vendor Registration' (2026-04-12): ICT providers register their software offerings", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-offer-accept", + "area": "market", + "name": "As a supplier, accept or decline a usage another organisation has claimed of your product.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-find-software", + "area": "market", + "name": "Find software for a task by filtering the whole market on reference component and standard.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27553 'ICT Market Orientation' (2026-04-12): Find and compare software from registered ICT providers", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-supplier-directory", + "area": "market", + "name": "Browse all organisations that offer applications or services, with search and filters.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-compare-peers", + "area": "market", + "name": "See which software comparable organisations use for the same reference component.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value. | docs, intelligence competitor_features#27552 'Municipality Comparison' (2026-04-12): Compare application landscapes between municipalities", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-who-uses-it", + "area": "market", + "name": "See which organisations use a given application.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-contact-peers", + "area": "market", + "name": "Get in touch with other organisations that use the same product.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27557 'Contact & Collaboration' (2026-04-12): Connect with municipalities using similar products", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-supplier-roadmap", + "area": "market", + "name": "Read a supplier's declared roadmap and planned releases for a product.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48839 'Product roadmap / planning declaration' (2026-07-23): Suppliers declare product planning and release roadmap per product.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-reviews", + "area": "market", + "name": "Write a review with a rating of an application you use.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-review-moderation", + "area": "market", + "name": "Hold a submitted review for moderation before others can read it.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-rating-aggregate", + "area": "market", + "name": "See the average rating and number of reviews of an application.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-contacts-per-product", + "area": "market", + "name": "Name different contact persons per product a supplier offers.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-vendor-master-data", + "area": "market", + "name": "Keep one record per supplier that every product and contract points to.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because Provider fact sheet.", + "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-hide-landscape-from-vendors", + "area": "market", + "name": "Keep your application landscape and connections hidden from suppliers.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "mkt-free-public-service", + "area": "market", + "name": "Use the catalogue free of charge as a municipality or supplier.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "no", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", + "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", + "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-phase", + "area": "lifecycle", + "name": "See which lifecycle phase each application in use is in, such as planned, in use or being phased out.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "partial", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because replacement timelines on assets.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-eol-warning", + "area": "lifecycle", + "name": "Get a warning before an application or version falls out of support.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-eol-feed", + "area": "lifecycle", + "name": "Fill in end-of-support dates automatically from a public end-of-life feed.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | Rated partial because obsolescence tracking; source of dates not named.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-roadmap", + "area": "lifecycle", + "name": "See per organisation which applications are replaced when, on a roadmap.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-planned-replacement", + "area": "lifecycle", + "name": "Record which application is planned to replace another.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-time-classification", + "area": "lifecycle", + "name": "Classify each application as tolerate, invest, migrate or eliminate.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-overlap", + "area": "lifecycle", + "name": "Find applications that overlap because they fulfil the same reference component.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | Rated partial because rationalisation through capability map.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-rationalisation-report", + "area": "lifecycle", + "name": "Open a report of overlapping and ageing software for rationalisation.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R). | docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-version-in-use", + "area": "lifecycle", + "name": "Record which version of an application your organisation currently runs.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-new-version-notice", + "area": "lifecycle", + "name": "Get notified when a supplier publishes a new version of an application you use.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-tech-obsolescence", + "area": "lifecycle", + "name": "Track the lifecycle of the underlying technology, such as a database or framework, not only the application.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-strategy-link", + "area": "lifecycle", + "name": "Link applications to the strategic goals they serve.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#27466 'Strategy Alignment' (2026-04-12): Connect architecture to strategic objectives", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "life-maintenance-window", + "area": "lifecycle", + "name": "Follow planned maintenance announced for an application.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-register", + "area": "contracts", + "name": "Register a contract for a service with its number, type, term and cost.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145509 'C-parties-and-contacts-1 A contract is a record with its own term and costs, linked to the party it binds and the cases raised under it': glpi: Contracts (Management, Contracts, front/contract_item.php, contractcost.php, ticket_contract.php) Lane findings: D-glpi-49.", + "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-expiry-alert", + "area": "contracts", + "name": "Get warned before a contract expires.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS renewal dates.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-status", + "area": "contracts", + "name": "See each contract's status move from active to expiring to expired on its own.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-approval", + "area": "contracts", + "name": "Only let a contract become active after an approval decision is recorded.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-renewal", + "area": "contracts", + "name": "Raise a renewal of a contract as a decision and see its outcome on the contract.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-per-application", + "area": "contracts", + "name": "See the contracts behind an application from that application's page.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | Rated yes because contracts tracked against assets.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-yearly-cost", + "area": "contracts", + "name": "See what the portfolio costs per year across its contracts.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS cost.", + "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts | docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-licence-model", + "area": "contracts", + "name": "Record the licence model of an application, such as open source, per user or per organisation.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48901 'License management' (2026-07-23): Track license entitlements, compliance and expirations.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-licence-posture", + "area": "contracts", + "name": "See the licence posture of the whole portfolio, such as the share that is open source.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-seat-count", + "area": "contracts", + "name": "Track the number of licences bought against the number in use.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48901 'License management' (2026-07-23): Track license entitlements, compliance and expirations. | docs, intelligence competitor_features#3270 'License Management' (2026-03-28): Track software licenses, compliance, and expiration", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-effective-licence-position", + "area": "contracts", + "name": "Compute entitlement against measured consumption to defend a licence audit.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-budget", + "area": "contracts", + "name": "Charge software costs against a budget with a period.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145790 'C-reporting-1 A budget the case costs are charged against, with a period.': glpi: Budgets (Management, Budgets, front/budget.php) Lane findings: D-glpi-37. | Rated yes because budgets, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-depreciation", + "area": "contracts", + "name": "Depreciate the purchase cost of software over its useful life.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts | Rated partial because TCO tracking.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-documents", + "area": "contracts", + "name": "Keep the signed contract document with the contract record.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ctr-saas-spend", + "area": "contracts", + "name": "See SaaS subscriptions and their spend, including ones bought outside IT.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-vulnerability-register", + "area": "security", + "name": "Register a known vulnerability with its CVE code and severity score.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-affected-versions", + "area": "security", + "name": "Link a vulnerability to the module versions it affects.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-exposure", + "area": "security", + "name": "See which organisations and usages are exposed to a vulnerability.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-vulnerability-alert", + "area": "security", + "name": "Get an alert when a vulnerability is reported for software you use.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-sbom-import", + "area": "security", + "name": "Import a software bill of materials in CycloneDX or SPDX for a version.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-cve-feed", + "area": "security", + "name": "Match the catalogue automatically against a public CVE feed.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-risk-score", + "area": "security", + "name": "Give each application a risk score from its vulnerabilities and support status.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks | Rated partial because technology risk.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-patch-status", + "area": "security", + "name": "See whether the version you run has been patched against a given vulnerability.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "sec-vulnerability-page", + "area": "security", + "name": "Browse all vulnerabilities in one list and open the details of each.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-register", + "area": "organisations", + "name": "Register an organisation, such as a municipality, supplier or cooperation, with its type.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27555 'Vendor Registration' (2026-04-12): ICT providers register their software offerings | docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-self-registration", + "area": "organisations", + "name": "Let a new organisation sign itself up without an account.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-moderation", + "area": "organisations", + "name": "Review a self-registered organisation in a queue before it becomes active.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-status", + "area": "organisations", + "name": "Move an organisation between concept, active and inactive.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-contact-persons", + "area": "organisations", + "name": "Keep the contact persons of an organisation with their roles.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27557 'Contact & Collaboration' (2026-04-12): Connect with municipalities using similar products", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-contact-to-account", + "area": "organisations", + "name": "Turn a contact person into a user account with the right role automatically.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-invite-colleagues", + "area": "organisations", + "name": "Give a colleague access to your organisation's part of the catalogue.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-multi-membership", + "area": "organisations", + "name": "Act for more than one organisation with one account and switch between them.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-cooperation", + "area": "organisations", + "name": "Register a cooperation of organisations and the landscape they share.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-merge", + "area": "organisations", + "name": "Merge two organisations after a municipal reorganisation or takeover, keeping their relations.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-merge-dry-run", + "area": "organisations", + "name": "See what a merge of organisations would change before it is carried out.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#146004 'C-configuration-95 The product shows what an import or a migration will change before it writes.': glpi: Form export and import (Form/ExportController.php, Form/Import/Step1IndexController.php through Step4ExecuteController.php) Lane findings: D-glpi-11. | Rated partial because import previews before writing; not for merges, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-roles", + "area": "organisations", + "name": "Map catalogue roles such as administrator, buyer and civil servant onto user groups.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141837 '11.19 User, role and department administration in the app': `/front/user.form.php`, `/front/profile.form.php` (`src/Profile.php`, `src/ProfileRight.php:46`), `/front/group.form.php`, and the three-way user x profile x entity grant `src/Profile_User.php:320` with a recursive flag | Rated yes because user, profile and entity administration, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-data-segregation", + "area": "organisations", + "name": "Keep each organisation's records visible only to that organisation unless published.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48910 'Multi-entity (tenant) segregation' (2026-07-23): Hierarchical entities for multi-org / multi-department isolation.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-hierarchy", + "area": "organisations", + "name": "Make the first user of an organisation its administrator and manager of later users.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-sso", + "area": "organisations", + "name": "Sign in with the organisation's own identity provider.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48908 'LDAP / SSO' (2026-07-23): Directory authentication and SSO.", + "topdesk": "docs, intelligence competitor_features#48935 'SSO integration' (2026-07-23): SAML / SSO authentication.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-directory-sync", + "area": "organisations", + "name": "Keep users and groups in step with a directory such as LDAP.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48908 'LDAP / SSO' (2026-07-23): Directory authentication and SSO. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141776 '5.11 Contact import and change subscriptions from registries': LDAP import and periodic re-sync of users and groups (`src/AuthLDAP.php`, `/front/ldap.import.php`, `/front/ldap.group.import.php`) with `src/RuleRight.php` mapping directory attributes to profiles; nothing subscribes to", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-password-change", + "area": "organisations", + "name": "Change your own password and see your own account details.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "org-activation-mail", + "area": "organisations", + "name": "Send registration, activation and account mails from templates an administrator can edit.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141830 '11.12 E-mail template library': `src/NotificationTemplate.php` with per-language bodies (`src/NotificationTemplateTranslation.php`), bound to events and delivery modes by `src/Notification_NotificationTemplate.php`, at `/front/notificationtemplate.php` | Rated yes because notification templates, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-public-browse", + "area": "sharing", + "name": "Let anyone browse the published catalogue without signing in.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-publish", + "area": "sharing", + "name": "Publish or withdraw a single catalogue entry as open data.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-open-data-privacy", + "area": "sharing", + "name": "Publish usage as open data without exposing personal contact details.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-federation-announce", + "area": "sharing", + "name": "Announce your catalogue in a shared directory so other catalogues can find it.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-federation-pull", + "area": "sharing", + "name": "Pull published entries from peer catalogues, marked with where they came from.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-federation-peers", + "area": "sharing", + "name": "Add or remove the peer catalogues you exchange with.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-rest-api", + "area": "sharing", + "name": "Read and write catalogue data through a REST API.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48867 'REST & GraphQL API' (2026-07-23): Programmatic access to the workspace graph.", + "bluedolphin": "docs, intelligence competitor_features#48972 'REST API' (2026-07-23): Programmatic integration with other systems.", + "glpi": "docs, intelligence competitor_features#48907 'REST API (HLAPI 2.x)' (2026-07-23): High-level REST API expanding object coverage in GLPI 11.", + "topdesk": "docs, intelligence competitor_features#48933 'REST API' (2026-07-23): Open REST API for integrations.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-public-api", + "area": "sharing", + "name": "Give developers a secure public API over the supplier offering.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "no", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141847 '12.19 Public data API with certificates or API keys': the API is fully authenticated, never public: user tokens plus optional app tokens with IP allow-listing (`apirest.md:62-67`, `src/APIClient.php:42`) and OAuth2 with scopes (`src/Glpi/OAuth/`). No anonymous public datase | Rated no because API is always authenticated, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-api-docs", + "area": "sharing", + "name": "Read generated documentation of the catalogue API.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141846 '12.18 OpenAPI documentation': auto-generated from route attributes: `src/Glpi/Api/HL/OpenAPIGenerator.php` with `src/Glpi/Api/HL/Doc/`, versioned per route (`#[RouteVersion]`, router at `src/Glpi/Api/HL/Router.php:98`); the legacy API is documented i | Rated yes because OpenAPI generator, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-export", + "area": "sharing", + "name": "Export your own catalogue data for use elsewhere.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141818 '10.3 Export list results to CSV or XLSX': `src/Glpi/Search/Output/Csv.php`, `Xlsx.php`, `Ods.php` and `Pdf.php`, mapped at `src/Glpi/Search/SearchEngine.php:108-130` | Rated yes because CSV, XLSX, ODS, PDF export, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-portal", + "area": "sharing", + "name": "Show catalogue content on a shared external portal next to other apps' content.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-ai-assistant", + "area": "sharing", + "name": "Let an AI assistant query and update the catalogue through a tool interface.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-itsm-integration", + "area": "sharing", + "name": "Exchange application data with the organisation's service management tool.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", + "glpi": "unknown", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48866 'Out-of-the-box integrations (ServiceNow, Signavio, SAP)' (2026-07-23): Pre-built connectors sync CMDB, process and ERP data.", + "bluedolphin": "docs, intelligence competitor_features#48973 'TOPdesk integration' (2026-07-23): Connector to TOPdesk asset/service data. | docs, intelligence competitor_features#27465 'TOPdesk Integration' (2026-04-12): Available on TOPdesk Marketplace for IT landscape insights", + "topdesk": "docs, intelligence competitor_features#48934 'Marketplace integrations (Lansweeper, ValueBlue)' (2026-07-23): Pre-built connectors incl. Lansweeper discovery and ValueBlue EA. | docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-webhooks", + "area": "sharing", + "name": "Notify another system automatically when a catalogue entry changes.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "share-self-hosted", + "area": "sharing", + "name": "Run the catalogue on your own infrastructure instead of the vendor's cloud.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "no", + "bluedolphin": "no", + "glpi": "yes", + "topdesk": "partial", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", + "bluedolphin": "docs, intelligence competitor_features#27467 'SaaS Platform' (2026-04-12): Cloud-native SaaS, no installation required", + "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", + "topdesk": "docs, intelligence competitor_features#26346 'SaaS Platform' (2026-04-10): Cloud-hosted SaaS platform with automatic updates | Rated partial because offered as SaaS; on-premises not in the reading.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-faceted-search", + "area": "insight", + "name": "Search the catalogue and narrow the results with facets such as reference component and supplier.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#27553 'ICT Market Orientation' (2026-04-12): Find and compare software from registered ICT providers", + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141806 '9.2 Advanced search with per-case-type fields': the search engine is strong, with ~160 ticket search options (`src/Ticket.php:2670`), nested criteria groups, `AND`/`OR`/`AND NOT`/`OR NOT` (`src/Glpi/Search/SearchEngine.php:551-564`), cross-itemtype meta-criteria, but | Rated yes because search engine with nested criteria, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-saved-view", + "area": "insight", + "name": "Save a filtered view of the catalogue and open it again later.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141807 '9.3 Personal saved searches': `src/SavedSearch.php:52`, `is_private` default 1, personal ordering (`:824`) and a default per itemtype (`src/SavedSearch_User.php:94-115`), at `/front/savedsearch.php` | Rated yes because saved searches, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-dashboard", + "area": "insight", + "name": "Open a dashboard with counts of organisations, applications and contracts.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports. | docs, intelligence competitor_features#27424 'Dashboards & Reports' (2026-04-12): Real-time dashboards for CIO-level reporting", + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141816 '10.1 Configurable KPI dashboards (count, gauge, chart)': `src/Glpi/Dashboard/Grid.php:67` with 20 widget types: pie, donut, half pie/donut, bars, lines, areas, stacked and horizontal variants, big number, multiple numbers, summary numbers, markdown, search result, article list", + "topdesk": "docs, intelligence competitor_features#48936 'Reporting & dashboards' (2026-07-23): Operational reporting and dashboards.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-concept-orgs-widget", + "area": "insight", + "name": "See organisations still waiting in concept on the Nextcloud dashboard.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-reports-page", + "area": "insight", + "name": "Pick a ready-made report from a list and open it.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145791 'C-reporting-2 A canned report the product ships, run without building it.': glpi: Reports (Tools, Reports, front/report.default.php, report.dynamic.php, report.year.php, report.state.php, report.reservation.php, report.contract.php) Lane findings: D-glpi-35. | Rated yes because canned reports, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-custom-report", + "area": "insight", + "name": "Build your own report over the whole portfolio and export it.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141816 '10.1 Configurable KPI dashboards (count, gauge, chart)': `src/Glpi/Dashboard/Grid.php:67` with 20 widget types: pie, donut, half pie/donut, bars, lines, areas, stacked and horizontal variants, big number, multiple numbers, summary numbers, markdown, search result, article list", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-export-list", + "area": "insight", + "name": "Export a filtered list to a spreadsheet.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141818 '10.3 Export list results to CSV or XLSX': `src/Glpi/Search/Output/Csv.php`, `Xlsx.php`, `Ods.php` and `Pdf.php`, mapped at `src/Glpi/Search/SearchEngine.php:108-130` | Rated yes because source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-scheduled-report", + "area": "insight", + "name": "Have a report sent to named people on a schedule.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-audit-trail", + "area": "insight", + "name": "Look back at who changed what in the catalogue, and when.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141820 '10.5 Audit or event log viewer with filters and export': two logs, both searchable and exportable through the search engine: `src/Log.php:48` field-level object history (Historical tab, `src/Ticket.php:887`) and `src/Glpi/Event.php:63` the system/event log at `/front/logs.php` | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141852 '13.9 Audit trail including reads and views': writes are covered thoroughly: `src/Log.php:48` field-level history on every object, `src/Glpi/Event.php:63` the system log including logins (`src/Auth.php:1149-1163`), `src/RuleMatchedLog.php` for rule decisions. Reads | Rated yes because field-level history, source-read 2026-09-14.", + "topdesk": "docs, intelligence competitor_features#26345 'Audit Trail' (2026-04-10): Complete audit trail of all service management actions", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-live-updates", + "area": "insight", + "name": "See a list update by itself when someone else changes an entry.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48969 'Real-time collaboration' (2026-07-23): Multiple stakeholders collaborate on models. | Rated partial because real-time collaboration on models.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-notifications", + "area": "insight", + "name": "Receive in-app notifications about changes that concern you.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141783 '6.8 In-app notifications (bell)': `MODE_AJAX` is a wired delivery mode (`src/Notification_NotificationTemplate.php:55-59`, `getModes()` at `:381-398`, implementation `src/NotificationAjax.php`), rendering as a browser toast rather than a persistent inbox | Rated partial because toast delivery, not an inbox, source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-cost-report", + "area": "insight", + "name": "See a report of software cost per organisation or per domain.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-feature-roadmap", + "area": "insight", + "name": "See in the app which features are available, in beta or coming soon.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-progress", + "area": "insight", + "name": "Follow the progress of a long synchronisation or import.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145875 'C-configuration-20 A long running administrative operation reports its progress.': glpi: Progress on a long operation (src/Glpi/Controller/ProgressController.php, Traits/AsyncOperationProgressControllerTrait.php) Lane findings: D-glpi-29. | Rated yes because source-read 2026-09-14.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ins-kb", + "area": "insight", + "name": "Keep knowledge articles about applications in a searchable knowledge base.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48909 'Knowledge base' (2026-07-23): Built-in KB with FAQ publishing.", + "topdesk": "docs, intelligence competitor_features#48931 'Knowledge base' (2026-07-23): Knowledge management and published articles.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-agent-inventory", + "area": "operations", + "name": "Discover the software installed on workstations and servers automatically with an agent.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48899 'Native inventory (GLPI Agent)' (2026-07-23): Built-in agent (ex-FusionInventory) discovers hardware/software automatically. | docs, intelligence competitor_features#3269 'Inventory' (2026-03-28): Automatic inventory discovery with FusionInventory agent", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-network-discovery", + "area": "operations", + "name": "Discover devices on the network automatically.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48911 'Network / SNMP discovery' (2026-07-23): SNMP network equipment inventory.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-saas-discovery", + "area": "operations", + "name": "Discover SaaS applications in use that nobody registered.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-hardware-assets", + "area": "operations", + "name": "Register hardware such as laptops and servers alongside software.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#3266 'IT Asset Management' (2026-03-28): Track hardware, software, and network assets", + "topdesk": "docs, intelligence competitor_features#27388 'Asset Management' (2026-04-12): Track hardware and software assets, locations, and assignments", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-ci-relations", + "area": "operations", + "name": "Record configuration items and their relations in a CMDB.", + "origin": "competitor", + "vng-softwarecatalogus": "no", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "glpi": "docs, intelligence competitor_features#48902 'CMDB & configuration relations' (2026-07-23): CI relationships and impact analysis.", + "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-reconciliation", + "area": "operations", + "name": "Deduplicate and reconcile records that arrive from several sources.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-tickets", + "area": "operations", + "name": "Log incidents and requests against an application.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48903 'ITIL helpdesk / ticketing' (2026-07-23): Full incident/request ticketing with the assets module.", + "topdesk": "docs, intelligence competitor_features#48927 'Incident / ticket management' (2026-07-23): Core ITSM incident and request handling.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-change", + "area": "operations", + "name": "Run a change on an application through an approval workflow.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#3277 'Change Management' (2026-03-28): ITIL change management with approval workflows", + "topdesk": "docs, intelligence competitor_features#48929 'Change management' (2026-07-23): Structured change workflows with action sequences.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-sla", + "area": "operations", + "name": "Track service level targets for an application or supplier.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48904 'SLA management' (2026-07-23): SLA targets and escalation rules.", + "topdesk": "docs, intelligence competitor_features#48930 'SLA management' (2026-07-23): Service-level target tracking and reporting.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-self-service", + "area": "operations", + "name": "Let end users request software through a self-service portal.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "topdesk": "docs, intelligence competitor_features#48928 'Self-service portal' (2026-07-23): End-user portal for requests and knowledge, reduces direct support load.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-plugins", + "area": "operations", + "name": "Extend the product with plugins installed from a marketplace.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "glpi": "docs, intelligence competitor_features#48906 'Plugin ecosystem' (2026-07-23): Large plugin marketplace (FormCreator, GenericObject, etc.). | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145919 'C-configuration-48 An extension is found, installed, updated and removed from inside the product.': glpi: Marketplace (Setup, Plugins, front/marketplace.php, marketplace.download.php, front/plugin.php) Lane findings: D-glpi-45.", + "topdesk": "docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-mobile", + "area": "operations", + "name": "Use the product from a native mobile app.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "yes", + "stackiq": "unknown", + "evidence": { + "topdesk": "docs, intelligence competitor_features#48937 'Mobile app' (2026-07-23): Native mobile operator app.", + "stackiq": "not checked: the code reading for this row is under way" + } + }, + { + "id": "ops-scheduled-sync", + "area": "operations", + "name": "Run the organisation and contact synchronisation on a schedule and see when it last ran.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "unknown", + "evidence": { + "stackiq": "not checked: the code reading for this row is under way" + } + } + ], + "pending": [] +} From 67f640843254efc34395742d00d782308a7a1ce9 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Fri, 25 Sep 2026 20:40:27 +0200 Subject: [PATCH 2/2] feat(parity): rate stackiq's own column from the code 134 rated rows and 39 pending across 12 areas. Every own rating carries a path and a line, a reachedOn and, on sibling rows, the owning repo. --- openspec/parity/capabilities.json | 3603 +++++++++++++++++++++-------- 1 file changed, 2690 insertions(+), 913 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index d885fb5e8..c797863ad 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -165,14 +165,25 @@ "bluedolphin": "yes", "glpi": "partial", "topdesk": "partial", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:592 Modules page (FacetedCatalogIndexView, schema module) with the library CnIndexPage create form at src/views/FacetedCatalogIndexView.vue:108; lib/Settings/softwarecatalogus_register.json:6777 module schema has name, shortDescription/longDescription and provider (Supplier) but NO status property; status lives on usage (register.json:2654, enum Acquisition..In production) which has no page", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Modules /modules (menu Applications), Add button", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "high", + "note": "An application with supplier and description can be registered on the Modules page, but the module schema has no status field, and the per-organisation usage that carries a status has no page to create it on. The Modules list also cannot open ModuleDetail: its standalone CnIndexPage (FacetedCatalogIndexView.vue:108-117) binds no @view/@row-click, so the View action is inert.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | docs, intelligence competitor_features#27422 'Fact Sheets & Data Model' (2026-04-12): Flexible data model for applications, processes, IT components", "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository. | docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", "glpi": "docs, intelligence competitor_features#48900 'Software inventory & catalog' (2026-07-23): Detects installed software and normalises into a software catalog. | docs, intelligence competitor_features#3267 'Software Catalog' (2026-03-28): Manage software licenses and installations | Rated partial because software is an inventoried asset, not a described application.", "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure | Rated partial because software is a CMDB object among assets.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:592 Modules page (FacetedCatalogIndexView, schema module) with the library CnIndexPage create form at src/views/FacetedCatalogIndexView.vue:108; lib/Settings/softwarecatalogus_register.json:6777 module schema has name, shortDescription/longDescription and provider (Supplier) but NO status property; status lives on usage (register.json:2654, enum Acquisition..In production) which has no page" } }, { @@ -185,10 +196,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Suites /suites and SuiteDetail /suites/:id (Related panel); ModuleDetail Related panel shows suites that include it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "low", + "note": "Stackiq's 'module' is the whole application, so there is no breakdown of one application into modules. The nearest thing is a suite (product) listing its applications, which answers 'which module belongs to which product' but not the decomposition.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated partial because fact sheets separate Application from IT Component.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')" } }, { @@ -201,28 +223,21 @@ "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Module versions /moduleversies (menu), Add + detail /moduleversies/:id; also ModuleDetail md-versions list (src/manifest.json:504, allowCreate false)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "lifecycle-and-end-of-support", + "featureConfidence": "medium", + "note": "A version is created on the Module versions index with its module and date in use, and opens on its own detail page.", "evidence": { "glpi": "docs, intelligence competitor_features#48900 'Software inventory & catalog' (2026-07-23): Detects installed software and normalises into a software catalog. | Rated partial because installed versions come from inventory.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "land-usage-record", - "area": "landscape", - "name": "Record that your organisation uses a module, as a usage separate from the product itself.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "partial", - "bluedolphin": "partial", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", - "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn" } }, { @@ -235,25 +250,47 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Suites /suites (menu), New suite wizard", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "medium", + "note": "A three-step wizard bundles existing applications into one suite. Caveat: a row click on the Suites list only toggles selection (the library returns before emitting row-click when selectable, SuitesIndexView.vue:35), so SuiteDetail is not opened from the list, and its data widget includes stale field names (src/manifest.json:683 beschrijvingKort, contactpersoon).", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)" } }, { "id": "land-services", "area": "landscape", - "name": "Register a service a supplier delivers on top of one or more applications, such as hosting or support.", + "name": "Register a service a supplier delivers on top of applications, such as hosting or support.", "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Services /diensten (menu), Add button", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "medium", + "note": "A supplier's service over one or more applications is registered on the Services page. There is no 'hosting' service type (technical management is the nearest), and services have no detail page, so a row cannot be opened.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | Rated partial because offering registration covers products; services not named in the reading.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)" } }, { @@ -266,9 +303,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "specified", + "evidence": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A sector schema exists, but no application, service or organisation can be tagged with a sector and no page lists sectors.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395" } }, { @@ -281,10 +327,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Modules /modules create/edit form (Contact person field)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "low", + "note": "One contact person per application can be set, but there is no separate business owner and technical owner. ModuleDetail's data widget includes 'contactpersoon', a key the schema no longer has, so the contact may not show there.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | Rated partial because surveys go to application owners, so ownership is modelled.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')" } }, { @@ -297,11 +354,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "Stackiq offers no way to add fields. Editing the schema in OpenRegister's own admin UI is possible there, but that is an OpenRegister feature, not a stackiq page.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because flexible fact sheet data model.", "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141835 '11.17 Custom object type management': GLPI 11 ships admin-defined itemtypes with custom fields and capabilities (`src/Glpi/CustomObject/AbstractDefinition.php`, `src/Glpi/Asset/AssetDefinition.php`, `src/Glpi/Asset/CustomFieldDefinition.php`), but the machin | Rated yes because custom asset definitions and custom fields, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json" } }, { @@ -314,26 +381,20 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "Modules /modules, Import in the index actions (also every type:index page)", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "The generic index page offers a file import (CSV per schema, or a register-wide JSON/Excel) that OpenRegister executes. Nothing stackiq-specific maps a spreadsheet's supplier names to organisation references, so relation columns must already hold identifiers.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27428 'EAM Automation' (2026-04-12): Automated data collection from ServiceNow, Jira, cloud providers | Rated partial because automated collection from ServiceNow, Jira and cloud.", "bluedolphin": "docs, intelligence competitor_features#48971 'Data import (Excel)' (2026-07-23): Bulk import of application/portfolio data.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "land-migrate-legacy", - "area": "landscape", - "name": "Bring over what was registered in the previous catalogue so nobody has to type it in again.", - "origin": "competitor", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)" } }, { @@ -346,11 +407,22 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id, reached from OrganisatieDetail Applications list (src/manifest.json:417 rowRoute ModuleDetail); NOT from the Modules list (FacetedCatalogIndexView.vue:108 binds no @view/@row-click)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "medium", + "note": "The application page shows versions and compliance claims, and usages only as untyped entries in the generic Related panel. Contracts are not shown. The page cannot be opened from the Applications list itself, and its data widget asks for three field names the schema no longer has, so the descriptions do not render.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because fact sheet is the per-application page.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)" } }, { @@ -363,9 +435,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Any index page (e.g. Module versions /moduleversies): select rows, mass delete; publish and lock: nothing reaches them", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "open-data-publishing", + "featureConfidence": "low", + "note": "Many entries can be selected and deleted together through the library index page. The mass publish and mass lock dialogs exist but hang off a view modal no page opens, and the publish endpoint (lib/Controller/PublicationController.php, PUT /api/publication/...) has no frontend caller.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets" } }, { @@ -378,9 +461,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "OrganisatieDetail /organisaties/:id, Merge panel (admins only)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Only organisations can be merged, with a dry run first, and only by a Nextcloud admin. Applications, services and other entries have no merge.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets" } }, { @@ -393,11 +485,20 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Nothing asks owners to confirm or correct their entries.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | docs, intelligence competitor_features#27423 'Survey-Based Data Collection' (2026-04-12): Crowdsource architecture data from application owners", "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)" } }, { @@ -410,9 +511,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No page scores how complete or current an entry is.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)" } }, { @@ -425,9 +535,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "First-run setup wizard (admin), step 'Load example data'", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "An admin picks the demo dataset in the setup wizard and it is imported through OpenRegister. Admin-only, which suits an installation task.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp" } }, { @@ -440,9 +559,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Suites /suites, New suite wizard only", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Only suites get a step-by-step wizard. Applications and services are added through a plain form, and connections have no page at all.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing" } }, { @@ -455,9 +583,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleversieDetail /moduleversies/:id, sidebar tab Components", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A module version's page lists the third-party components imported from its SBOM.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema" } }, { @@ -470,28 +607,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Modules /modules create/edit form; ModuleDetail data widget", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "medium", + "note": "The application form records on-premises, IaaS, PaaS or SaaS plus hosting location and jurisdiction. There is no field naming the hosting party itself.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | Rated partial because SaaS is tracked as a class of application.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "conn-register-connection", - "area": "connections", - "name": "Register a connection between two applications, with its direction and the standard it uses.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "yes", - "bluedolphin": "partial", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", - "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)" } }, { @@ -504,10 +634,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: OpenRegister objects API", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "low", + "note": "The field for a national provision exists on the connection schema, but with no connection page nobody can fill it in stackiq.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48841 'National provisions (landelijke voorzieningen) linking' (2026-07-23): Records links between applications and national government provisions.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection" } }, { @@ -520,10 +661,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "specified", + "evidence": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "medium", + "note": "There is no list of connections in the catalogue. The Integrations page lists outside integrations, a different thing.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)" } }, { @@ -536,10 +688,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id, Related panel (untyped); API /api/koppelingen-gebruik/{uuid}", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "low", + "note": "Connections that reference an application should appear among the untyped related objects on its page, but there is no connections section and nothing to open. The dedicated per-application endpoint is API only.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/" } }, { @@ -552,12 +715,23 @@ "bluedolphin": "yes", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "low", + "note": "No page draws connections. The ArchiMate export can be opened in Archi, but it carries GEMMA views and usages, not the catalogue's connections.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model. | docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", "bluedolphin": "docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models. | docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145369 'C-case-core-38 The graph of what a case is linked to is drawn, and exported.': glpi: Impact graph (Tools, front/impactitem.php, impactcsv.php, src/Impact.php) Lane findings: D-glpi-40. | Rated yes because impact graph, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)" } }, { @@ -570,42 +744,21 @@ "bluedolphin": "yes", "glpi": "yes", "topdesk": "partial", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "ModuleDetail /modules/:id, Related panel", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "The only way to see what depends on an application is the generic list of objects that reference it, which OpenRegister's relation index fills. There is no impact view or retirement check.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", "glpi": "docs, intelligence competitor_features#48902 'CMDB & configuration relations' (2026-07-23): CI relationships and impact analysis.", "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because relations between assets.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "conn-usage-of-connection", - "area": "connections", - "name": "Record that your organisation actually runs a given connection, not only that it exists.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "conn-shared-with-others", - "area": "connections", - "name": "See which connections you run together with other organisations.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/" } }, { @@ -618,9 +771,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "specified", + "evidence": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The type field exists but there is no connection list to filter.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter" } }, { @@ -633,10 +795,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Stackiq has no record for an API an application exposes.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27425 'API Management' (2026-04-12): Catalog and manage APIs across the application landscape", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label" } }, { @@ -649,10 +820,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it (nearest: admin settings ArchiMate organisation export)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "low", + "note": "The organisation ArchiMate export carries modules and usages but not connections, so an application's link graph cannot be exported.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145369 'C-case-core-38 The graph of what a case is linked to is drawn, and exported.': glpi: Impact graph (Tools, front/impactitem.php, impactcsv.php, src/Impact.php) Lane findings: D-glpi-40. | Rated yes because impactcsv export, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*" } }, { @@ -665,57 +847,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "arch-refcomp-mapping", - "area": "architecture", - "name": "Place an application on the GEMMA reference components it fulfils.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48835 'Reference component mapping (referentiecomponenten)' (2026-07-23): Maps each registered software product onto GEMMA reference components/domains so functionality is comparable across suppliers. | docs, intelligence competitor_features#27551 'Reference Component Linking' (2026-04-12): Link software to GEMMA reference components", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "arch-gemma-views", - "area": "architecture", - "name": "Open a GEMMA architecture view with your own applications drawn inside it.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | Rated yes because landscape auto-plotted on the reference component map.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "arch-shared-overlay", - "area": "architecture", - "name": "On a GEMMA view, see which applications you share with partner organisations, drawn differently from your own.", - "origin": "own-code", - "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq", + "owner": "ConductionNL/integriq" + }, + "reachedOn": "Integrations /settings/integrations (settings menu, admin, only when app id 'integriq' is installed)", + "provider": "integriq", + "providerHow": "read-from-code", + "note": "With integriq installed, an admin sees stackiq's three integrations and their checked status on one page, and Add integration opens integriq. Without integriq the page is hidden, and the checking is integriq's.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq" } }, { @@ -728,10 +871,21 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section ArchiMate Import/Export (Nextcloud admin settings, stackiq section)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "high", + "note": "Works end to end but only a Nextcloud admin can import: the endpoint rejects non-admins and the upload control lives only on the admin settings page.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27459 'ArchiMate & BPMN Support' (2026-04-12): Full ArchiMate and BPMN modeling in one platform | Rated yes because full ArchiMate support; import format not named in the reading.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile" } }, { @@ -744,11 +898,22 @@ "bluedolphin": "partial", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section ArchiMate Import/Export, button Export Base", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "high", + "note": "The export produces a downloadable AMEF XML, but only from the admin settings page; organisation admins may call the API but have no page for it.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button" } }, { @@ -761,10 +926,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section ArchiMate Import/Export, organisation select + Organization Export", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "high", + "note": "Complete logic, but reachable only on the admin settings page; an ordinary organisation user cannot export its own landscape from a stackiq page.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape | docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools | Rated yes because map and export the municipality's landscape.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes" } }, { @@ -777,9 +953,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it: src/store/modules/settings.js:1953 testRoundTrip action has no caller", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "medium", + "note": "There is an endpoint, but its comparison is broken (a missing key against a placeholder string) and no page calls it. The compare_archimate.py/.php scripts in the repo root are developer tools, not a user capability.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register" } }, { @@ -792,24 +979,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "arch-gemma-api", - "area": "architecture", - "name": "Retrieve the GEMMA architecture itself through an API.", - "origin": "competitor", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "building", + "evidence": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section ArchiMate Import/Export shows a spinner during import; nothing shows progress or offers cancel", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "medium", + "note": "The import runs as one blocking request with a spinner. The cancel endpoint calls a missing method and import progress is never recorded, so neither following nor cancelling works.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button" } }, { @@ -822,9 +1005,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Standaarden /standaarden and StandaardDetail /standaarden/:id for standards; no page for reference components or other GEMMA terms, and no in-place definition while working", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "low", + "note": "You can open a standard's page and read its definition, but reference components and other GEMMA terms have no page and there is no inline definition where they appear.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only" } }, { @@ -837,11 +1031,22 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Modules /modules facet by reference component (a list, not a map); the map itself only in Archi after the admin org export", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "medium", + "note": "The mapping to GEMMA reference components exists, but there is no map view in stackiq; you only see it as a facet list or in Archi after an admin export.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | docs, intelligence competitor_features#27420 'Business Capability Mapping' (2026-04-12): Map applications to business capabilities and processes", "bluedolphin": "docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies" } }, { @@ -854,11 +1059,20 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Models are imported and exported as ArchiMate files; nothing lets a user draw or edit a model inside stackiq.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model.", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components" } }, { @@ -871,10 +1085,19 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Business processes are not modelled; the only link applications have is to GEMMA reference components.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27464 'Process Mapping' (2026-04-12): Map processes, applications, data, and technology", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json" } }, { @@ -887,10 +1110,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Planned usage and planned replacements exist per record, but there is no future-state model and no comparison with today.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27419 'IT Transformation' (2026-04-12): Plan and execute cloud migrations and modernization | Rated partial because transformation planning.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape" } }, { @@ -903,10 +1135,19 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No report or view lists reference components that no application in your landscape covers.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage" } }, { @@ -919,10 +1160,19 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no diagram generation in lib/Service or src; no AI integration for diagrams", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Nothing drafts diagrams.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48970 'AI-powered diagramming' (2026-07-23): AI assists diagram generation. | docs, intelligence competitor_features#27461 'AI-Powered Diagramming' (2026-04-12): Auto-generate BPMN diagrams with built-in AI", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "no diagram generation in lib/Service or src; no AI integration for diagrams" } }, { @@ -935,26 +1185,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Standaarden /standaarden, menu Standards; detail StandaardDetail /standaarden/:id", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "high", + "note": "The GEMMA standards imported with the AMEF model are browsable on their own page with a detail view that lists compliance claims.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports. | docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "comp-declare-standard", - "area": "compliance", - "name": "Declare that an application supports a specific version of a standard.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)" } }, { @@ -967,9 +1212,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "KompliantieDetail /komplianties/:id, Evidence documents widget; evidence URL/file fields on the compliance form", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "high", + "note": "Evidence can be attached as a file, a URL or a Nextcloud Files link on the compliance claim's page.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'" } }, { @@ -982,9 +1238,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ComplianceMatrix /compliance-matrix (menu Reports & Compliance > Compliance matrix)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "high", + "note": "The matrix separates claims with evidence from claims without, but 'verified' only means evidence is attached: no one reviews or approves the evidence, so a supplier-uploaded document counts as verified.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue" } }, { @@ -997,9 +1264,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json ComplianceMatrix /compliance-matrix custom page -> src/customComponents.js ComplianceMatrixView -> src/views/ComplianceMatrixView.vue (modules x selected standard versions or BIO measures, src/utils/complianceMatrix.js:270 columns)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ComplianceMatrix /compliance-matrix, menu Reports & Compliance > Compliance matrix", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "high", + "note": "A filter-first matrix of applications against chosen standard versions (or BIO measures), cell by cell with verified/claimed/none.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json ComplianceMatrix /compliance-matrix custom page -> src/customComponents.js ComplianceMatrixView -> src/views/ComplianceMatrixView.vue (modules x selected standard versions or BIO measures, src/utils/complianceMatrix.js:270 columns)" } }, { @@ -1012,9 +1290,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:275 POST /api/bulk-sync-standards -> lib/Controller/SettingsController.php:3598 (isAdmin check) -> lib/Service/ModuleComplianceService.php:527 bulkSyncModuleStandards (reads up to 1000 compliancy records and updates module standards); UI src/views/settings/sections/StatisticsOverview.vue:79 button -> src/modals/BulkSyncDialog.vue:321", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings, Statistics overview section, bulk sync button", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "medium", + "note": "One action updates every module's standards from its compliance records, but only a Nextcloud admin can run it and it stops at 1000 compliance records.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/routes.php:275 POST /api/bulk-sync-standards -> lib/Controller/SettingsController.php:3598 (isAdmin check) -> lib/Service/ModuleComplianceService.php:527 bulkSyncModuleStandards (reads up to 1000 compliancy records and updates module standards); UI src/views/settings/sections/StatisticsOverview.vue:79 button -> src/modals/BulkSyncDialog.vue:321" } }, { @@ -1027,9 +1316,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json BioMaatregelen /bio-maatregelen index (columns code,name,thema,bioVersion,bbnNiveau) and BioMaatregelDetail; register property is bbnLevel (lib/Settings/softwarecatalogus_register.json bioMeasure), so the bbnNiveau column is empty; no BIO catalogue is seeded (only 6 demo objects in lib/Settings/stackiq_mock_register.json)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "BioMaatregelen /bio-maatregelen, menu BIO measures; detail BioMaatregelDetail /bio-maatregelen/:id", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "medium", + "note": "The page exists and shows the theme, but the level column is wired to a key that does not exist (bbnNiveau vs bbnLevel; level only shows on the detail page), and the BIO measures are not shipped, so someone has to type them in.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json BioMaatregelen /bio-maatregelen index (columns code,name,thema,bioVersion,bbnNiveau) and BioMaatregelDetail; register property is bbnLevel (lib/Settings/softwarecatalogus_register.json bioMeasure), so the bbnNiveau column is empty; no BIO catalogue is seeded (only 6 demo objects in lib/Settings/stackiq_mock_register.json)" } }, { @@ -1042,9 +1342,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json compliancy.bioMeasure links a module to a BIO measure; src/manifest.json ModuleDetail md-compliance lists claims incl. bioMaatregel column, BioMaatregelDetail bm-compliance lists modules per measure; compliancy has no status/met-not-met field", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Komplianties /komplianties (create a claim with a BIO measure); ComplianceMatrix /compliance-matrix with BIO measures as columns", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "medium", + "note": "You can record that an application meets a BIO measure, but there is no way to record that it does not meet one: the absence of a claim is the only negative, which cannot be told apart from 'not assessed'. The md-compliance column key 'bioMaatregel' also differs from the property bioMeasure.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.bioMeasure links a module to a BIO measure; src/manifest.json ModuleDetail md-compliance lists claims incl. bioMaatregel column, BioMaatregelDetail bm-compliance lists modules per measure; compliancy has no status/met-not-met field" } }, { @@ -1057,9 +1368,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json module.dpiaStatus (enum not required/required/executed), dpiaDate, dpiaNextAssessment, dpiaDocumentRef; src/manifest.json ModuleDetail md-data includes the DPIA fields; Modules /modules quick filter 'Without DPIA (BBN2+)'", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id Application data widget; Modules /modules column dpiaStatus and 'Without DPIA' quick filter", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "low", + "note": "DPIA status, date, next review and document link are fields on the application and shown and filterable on the Applications pages. The scheduled 'dpia-review-overdue' notification is only a register declaration.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Settings/softwarecatalogus_register.json module.dpiaStatus (enum not required/required/executed), dpiaDate, dpiaNextAssessment, dpiaDocumentRef; src/manifest.json ModuleDetail md-data includes the DPIA fields; Modules /modules quick filter 'Without DPIA (BBN2+)'" } }, { @@ -1072,10 +1394,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for forum standaardisatie / pas toe of leg uit / comply-or-explain in lib and src: no hits; standards come only from the GEMMA AMEF import (element gemmaType=standaard)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "There is no list or check for the Forum Standaardisatie comply-or-explain list; only GEMMA standards imported with the model.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for forum standaardisatie / pas toe of leg uit / comply-or-explain in lib and src: no hits; standards come only from the GEMMA AMEF import (element gemmaType=standaard)" } }, { @@ -1088,9 +1419,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for completeness/health score/quality score in lib and src: no hits; lib/Command/ReferencesAuditCommand.php:34 (occ stackiq:references:audit) only audits cross-app uuid references, it is not a scored rule set", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No rule-based score of register correctness or completeness exists on any page.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for completeness/health score/quality score in lib and src: no hits; lib/Command/ReferencesAuditCommand.php:34 (occ stackiq:references:audit) only audits cross-app uuid references, it is not a scored rule set" } }, { @@ -1103,10 +1443,19 @@ "bluedolphin": "partial", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for questionnaire/vragenlijst in lib and src: no hits; no questionnaire schema in lib/Settings/softwarecatalogus_register.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Nothing sends questionnaires to suppliers or stores their answers.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders. | Rated partial because questionnaires collect portfolio data.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for questionnaire/vragenlijst in lib and src: no hits; no questionnaire schema in lib/Settings/softwarecatalogus_register.json" } }, { @@ -1119,25 +1468,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:592 Modules and :647 Diensten are FacetedCatalogIndexView over schema module/catalogService (CnIndexPage, showAdd default true); lib/Settings/softwarecatalogus_register.json:6779 module has provider + publicationDate (visible on form) and public read when publicationDate <= now or registeredBy Supplier", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules and Services /diensten (main menu), create via the index Add form", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "medium", + "note": "A supplier in aanbod-beheerder creates modules and services on the index pages and publishes them by setting publicationDate in the form. The dedicated publish endpoint (PUT /api/publication/...) is not called by any page (src/utils/openDataProjection.js has no importer).", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | docs, intelligence competitor_features#27555 'Vendor Registration' (2026-04-12): ICT providers register their software offerings", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "mkt-offer-accept", - "area": "market", - "name": "As a supplier, accept or decline a usage another organisation has claimed of your product.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:592 Modules and :647 Diensten are FacetedCatalogIndexView over schema module/catalogService (CnIndexPage, showAdd default true); lib/Settings/softwarecatalogus_register.json:6779 module has provider + publicationDate (visible on form) and public read when publicationDate <= now or registeredBy Supplier" } }, { @@ -1150,10 +1495,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "lib/Service/FacetService.php:109 DIMENSIONS referenceComponent, standard, applicationService, domain for schemas module and catalogService (:102); src/views/FacetedCatalogIndexView.vue:108 CnFacetSidebar narrows CnIndexPage; route GET /api/facets/{schema} called from src/services/facets.js", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules and Services /diensten, GEMMA facet sidebar", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "medium", + "note": "Live facet counts on reference component and standard narrow the module and service lists. Scope is whatever the RBAC read rules let the viewer see (published entries are public).", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27553 'ICT Market Orientation' (2026-04-12): Find and compare software from registered ICT providers", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS referenceComponent, standard, applicationService, domain for schemas module and catalogService (:102); src/views/FacetedCatalogIndexView.vue:108 CnFacetSidebar narrows CnIndexPage; route GET /api/facets/{schema} called from src/services/facets.js" } }, { @@ -1166,41 +1522,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "mkt-compare-peers", - "area": "market", - "name": "See which software comparable organisations use for the same reference component.", - "origin": "competitor", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value. | docs, intelligence competitor_features#27552 'Municipality Comparison' (2026-04-12): Compare application landscapes between municipalities", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "mkt-who-uses-it", - "area": "market", - "name": "See which organisations use a given application.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisations /organisaties (main menu)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The Organisations index lists organisations with search, a type facet and a status filter. There is no filter for 'offers at least one product'; type Supplier is the proxy.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)" } }, { @@ -1213,10 +1546,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "Looked in src/components, src/views and lib/Controller for any contact or messaging between organisations sharing a module: none. Usage read rules (register :3137) hide other organisations' usages from municipalities.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Nothing lets an organisation find or contact other organisations using the same product.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27557 'Contact & Collaboration' (2026-04-12): Connect with municipalities using similar products", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Looked in src/components, src/views and lib/Controller for any contact or messaging between organisations sharing a module: none. Usage read rules (register :3137) hide other organisations' usages from municipalities." } }, { @@ -1229,10 +1571,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register :7651 moduleVersion with status enum in development/in use/end of support/withdrawn and dateInDevelopment/dateInUse/dateEndSupport, read public; src/manifest.json:915 Moduleversies index + ModuleversieDetail", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Module versions /moduleversies (main menu)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "maintenance-and-supplier-roadmap", + "featureConfidence": "medium", + "note": "A supplier can register a future version with status 'in development' and planned dates, which reads as a crude release plan. There is no roadmap view or declared roadmap; the overlay marks maintenance-and-supplier-roadmap as 'soon'.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48839 'Product roadmap / planning declaration' (2026-07-23): Suppliers declare product planning and release roadmap per product.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register :7651 moduleVersion with status enum in development/in use/end of support/withdrawn and dateInDevelopment/dateInUse/dateEndSupport, read public; src/manifest.json:915 Moduleversies index + ModuleversieDetail" } }, { @@ -1245,24 +1598,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "mkt-review-moderation", - "area": "market", - "name": "Hold a submitted review for moderation before others can read it.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:514 ModuleDetail bodyWidget ReviewsPanel; src/components/reviews/ReviewsPanel.vue:63 opens SubmitReviewModal; POST /api/reviews -> lib/Service/ReviewService.php:232 stamps author and forces status pending; rating 1..10 in software-review schema (:3961)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id, Reviews panel 'write a review'", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "reviews", + "featureConfidence": "high", + "note": "Logged-in users write a rated review from the application page. Services have no detail page, so only applications can be reviewed there.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:514 ModuleDetail bodyWidget ReviewsPanel; src/components/reviews/ReviewsPanel.vue:63 opens SubmitReviewModal; POST /api/reviews -> lib/Service/ReviewService.php:232 stamps author and forces status pending; rating 1..10 in software-review schema (:3961)" } }, { @@ -1275,9 +1624,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "lib/Service/ReviewAggregateService.php:51 approved-only average + count; GET /api/reviews/aggregate (PublicPage) called from src/utils/reviewAggregate.js imported by src/components/reviews/ReviewsPanel.vue", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id, Reviews panel", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "reviews", + "featureConfidence": "high", + "note": "The application page shows the approved-only average and count. Services have no detail page, so the aggregate is not shown for them.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/ReviewAggregateService.php:51 approved-only average + count; GET /api/reviews/aggregate (PublicPage) called from src/utils/reviewAggregate.js imported by src/components/reviews/ReviewsPanel.vue" } }, { @@ -1290,9 +1650,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register :6856 module.contactPerson -> contactPerson with x-relation-filter organization = @object.provider; catalogService and suite also carry contactPerson; src/manifest.json:500 ModuleDetail md-data include lists 'contactpersoon', 'beschrijvingKort', 'beschrijvingLang', which are not module properties (renamed to contactPerson/shortDescription/longDescription)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules create/edit form; not shown on ModuleDetail /modules/:id", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Each product can point at its own contact person of the supplier through the form. The application page's data widget names the old Dutch keys, so the product's contact person (and its descriptions) do not show there; the same stale keys are on SuiteDetail (src/manifest.json:683).", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register :6856 module.contactPerson -> contactPerson with x-relation-filter organization = @object.provider; catalogService and suite also carry contactPerson; src/manifest.json:500 ModuleDetail md-data include lists 'contactpersoon', 'beschrijvingKort', 'beschrijvingLang', which are not module properties (renamed to contactPerson/shortDescription/longDescription)" } }, { @@ -1305,221 +1674,204 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "register :2022 organization (one record, type Supplier); module.provider (:6921) and catalogService.provider (:3762) are $ref organization; catalogContract points at service (+usage), register :3252; OrganisatieDetail src/manifest.json:403 lists the supplier's services and applications", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisations /organisaties and OrganisatieDetail /organisaties/:id (services and applications lists)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "One organisation record is the supplier; products reference it and the detail page lists them. A contract reaches the supplier only through its service, not by its own field.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because Provider fact sheet.", "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "mkt-hide-landscape-from-vendors", - "area": "market", - "name": "Keep your application landscape and connections hidden from suppliers.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "mkt-free-public-service", - "area": "market", - "name": "Use the catalogue free of charge as a municipality or supplier.", - "origin": "competitor", - "vng-softwarecatalogus": "yes", - "sap-leanix": "no", - "bluedolphin": "unknown", - "glpi": "yes", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", - "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", - "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register :2022 organization (one record, type Supplier); module.provider (:6921) and catalogService.provider (:3762) are $ref organization; catalogContract points at service (+usage), register :3252; OrganisatieDetail src/manifest.json:403 lists the supplier's services and applications" } }, { "id": "life-phase", "area": "lifecycle", - "name": "See which lifecycle phase each application in use is in, such as planned, in use or being phased out.", + "name": "See the lifecycle phase of each application in use: planned, in use or being phased out.", "origin": "own-code", "vng-softwarecatalogus": "no", "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "partial", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json LifecycleRoadmap /portfolio-roadmap custom page -> src/views/LifecycleRoadmapView.vue:55 groups the selected organisation's usages by phase, derived from usage dates by src/utils/lifecyclePhase.js derivePhase (:408); usage.status enum Acquisition/Planned/In production/To be phased out/Phased out in lib/Settings/softwarecatalogus_register.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "LifecycleRoadmap /portfolio-roadmap, menu Portfolio roadmap", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "portfolio-roadmap", + "featureConfidence": "high", + "note": "Pick an organisation and its applications in use are grouped by derived lifecycle phase. The usage records themselves cannot be created or edited on any stackiq page (see life-planned-replacement).", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because replacement timelines on assets.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json LifecycleRoadmap /portfolio-roadmap custom page -> src/views/LifecycleRoadmapView.vue:55 groups the selected organisation's usages by phase, derived from usage dates by src/utils/lifecyclePhase.js derivePhase (:408); usage.status enum Acquisition/Planned/In production/To be phased out/Phased out in lib/Settings/softwarecatalogus_register.json" } }, { - "id": "life-eol-warning", + "id": "life-roadmap", "area": "lifecycle", - "name": "Get a warning before an application or version falls out of support.", + "name": "See per organisation which applications are replaced when, on a roadmap.", "origin": "own-code", "vng-softwarecatalogus": "no", "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/views/LifecycleRoadmapView.vue:28 organisation select, :55 phase groups, :96-110 phase-out date, planned replacement and link to the replacing module (:400 plannedReplacement, :423 plannedReplacementDate), ordered by nearest urgency (:428)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "LifecycleRoadmap /portfolio-roadmap, menu Portfolio roadmap", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "portfolio-roadmap", + "featureConfidence": "high", + "note": "Per organisation it shows which applications are phased out or replaced and when; it is a grouped list ordered by urgency rather than a timeline chart.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", - "stackiq": "not checked: the code reading for this row is under way" + "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "stackiq": "src/views/LifecycleRoadmapView.vue:28 organisation select, :55 phase groups, :96-110 phase-out date, planned replacement and link to the replacing module (:400 plannedReplacement, :423 plannedReplacementDate), ordered by nearest urgency (:428)" } }, { - "id": "life-eol-feed", + "id": "life-overlap", "area": "lifecycle", - "name": "Fill in end-of-support dates automatically from a public end-of-life feed.", + "name": "Find applications that overlap because they fulfil the same reference component.", "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for overlap/redundant in lib and src finds only code comments and the Reports card description (src/manifest.json:1031 'Overlapping and ageing software'); lib/Service/PortfolioReportService.php computes TIME quadrants, EOL exposure, cloud share and cost, no grouping by reference component; the /modules facet counts modules per reference component across the whole catalogue, not your landscape", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Nothing finds applications in your landscape that fulfil the same reference component; the Reports card promises 'overlapping' software but the report does not compute it.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | Rated partial because obsolescence tracking; source of dates not named.", - "stackiq": "not checked: the code reading for this row is under way" + "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | Rated partial because rationalisation through capability map.", + "stackiq": "grep for overlap/redundant in lib and src finds only code comments and the Reports card description (src/manifest.json:1031 'Overlapping and ageing software'); lib/Service/PortfolioReportService.php computes TIME quadrants, EOL exposure, cloud share and cost, no grouping by reference component; the /modules facet counts modules per reference component across the whole catalogue, not your landscape" } }, { - "id": "life-roadmap", + "id": "life-rationalisation-report", "area": "lifecycle", - "name": "See per organisation which applications are replaced when, on a roadmap.", + "name": "Open a report of overlapping and ageing software for rationalisation.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:303 GET /api/portfolio-report -> lib/Controller/PortfolioReportController.php -> lib/Service/PortfolioReportService.php + PortfolioReportDerivation.php; UI src/views/organisaties/PortfolioReport.vue (TIME chart :112, quadrant summary :126 with EOL exposure/cloud/cost, rows :176, CSV export :50)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "PortfolioReport /portfolio-report, from Reports /reports card 'Portfolio rationalization' (footer menu Reports)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The report covers ageing software (EOL exposure) with TIME quadrants, cost and a CSV export, but not overlap, even though its card says 'overlapping and ageing'.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", - "stackiq": "not checked: the code reading for this row is under way" + "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R). | docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", + "stackiq": "appinfo/routes.php:303 GET /api/portfolio-report -> lib/Controller/PortfolioReportController.php -> lib/Service/PortfolioReportService.php + PortfolioReportDerivation.php; UI src/views/organisaties/PortfolioReport.vue (TIME chart :112, quadrant summary :126 with EOL exposure/cloud/cost, rows :176, CSV export :50)" } }, { - "id": "life-planned-replacement", + "id": "life-version-in-use", "area": "lifecycle", - "name": "Record which application is planned to replace another.", + "name": "Record which version of an application your organisation currently runs.", "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json usage.moduleVersion ($ref moduleVersion); read by src/views/LifecycleRoadmapView.vue:397 for EOL state; ModuleversieDetail mv-related shows related usages; no usage create/edit page in src/manifest.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "used on LifecycleRoadmap /portfolio-roadmap and ModuleversieDetail /moduleversies/:id; nothing in stackiq records it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "lifecycle-and-end-of-support", + "featureConfidence": "low", + "note": "The version an organisation runs is a field on its usage and drives the EOL badges, but no stackiq page lets the organisation set or change it.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Settings/softwarecatalogus_register.json usage.moduleVersion ($ref moduleVersion); read by src/views/LifecycleRoadmapView.vue:397 for EOL state; ModuleversieDetail mv-related shows related usages; no usage create/edit page in src/manifest.json" } }, { - "id": "life-time-classification", + "id": "life-new-version-notice", "area": "lifecycle", - "name": "Classify each application as tolerate, invest, migrate or eliminate.", + "name": "Get notified when a supplier publishes a new version of an application you use.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "yes", + "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "specified", + "evidence": "lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications module-version-published (trigger created, recipients object-acl manage + group software-catalog-admins); no notification code in lib (no INotificationManager use)", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "nothing reaches it for a using organisation", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "notifications", + "featureConfidence": "medium", + "note": "The only rule is a register declaration, and it addresses the version's own managers and catalogue admins, not the organisations that use the application, so even if OpenRegister dispatches it a user of the application is not told.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications module-version-published (trigger created, recipients object-acl manage + group software-catalog-admins); no notification code in lib (no INotificationManager use)" } }, { - "id": "life-overlap", + "id": "life-tech-obsolescence", "area": "lifecycle", - "name": "Find applications that overlap because they fulfil the same reference component.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "partial", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | Rated partial because rationalisation through capability map.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "life-rationalisation-report", - "area": "lifecycle", - "name": "Open a report of overlapping and ageing software for rationalisation.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "yes", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R). | docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "life-version-in-use", - "area": "lifecycle", - "name": "Record which version of an application your organisation currently runs.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "life-new-version-notice", - "area": "lifecycle", - "name": "Get notified when a supplier publishes a new version of an application you use.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "life-tech-obsolescence", - "area": "lifecycle", - "name": "Track the lifecycle of the underlying technology, such as a database or framework, not only the application.", + "name": "Track the lifecycle of underlying technology, such as a database or framework, not only applications.", "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "lib/Settings/softwarecatalogus_register.json sbomComponent has name/version/purl/licenses/type/hashes/bomRef/vexCveIds, no lifecycle or EOL field; the EOL feed (lib/Service/EolSyncService.php:290) only stamps versions of modules with eolProductSlug; no relation from an application to the platform it runs on", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "You could register a database as its own 'System software' module and feed its EOL, but nothing ties it to the applications that depend on it; SBOM components carry no lifecycle.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Settings/softwarecatalogus_register.json sbomComponent has name/version/purl/licenses/type/hashes/bomRef/vexCveIds, no lifecycle or EOL field; the EOL feed (lib/Service/EolSyncService.php:290) only stamps versions of modules with eolProductSlug; no relation from an application to the platform it runs on" } }, { @@ -1532,10 +1884,19 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no goal/strategy schema among the 20 in lib/Settings/softwarecatalogus_register.json; grep for strateg/doel in src/manifest.json: none", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Strategic goals are not modelled.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#27466 'Strategy Alignment' (2026-04-12): Connect architecture to strategic objectives", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "no goal/strategy schema among the 20 in lib/Settings/softwarecatalogus_register.json; grep for strateg/doel in src/manifest.json: none" } }, { @@ -1548,44 +1909,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ctr-register", - "area": "contracts", - "name": "Register a contract for a service with its number, type, term and cost.", - "origin": "own-code", - "vng-softwarecatalogus": "no", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "yes", - "topdesk": "yes", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145509 'C-parties-and-contacts-1 A contract is a record with its own term and costs, linked to the party it binds and the cases raised under it': glpi: Contracts (Management, Contracts, front/contract_item.php, contractcost.php, ticket_contract.php) Lane findings: D-glpi-49.", - "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ctr-expiry-alert", - "area": "contracts", - "name": "Get warned before a contract expires.", - "origin": "own-code", - "vng-softwarecatalogus": "no", - "sap-leanix": "partial", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "specified", + "evidence": "openspec/features.overlay.json maintenance-and-supplier-roadmap status 'soon'; no maintenance schema in lib/Settings/softwarecatalogus_register.json and no page in src/manifest.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "maintenance-and-supplier-roadmap", + "featureConfidence": "high", + "note": "Listed as 'soon' in the feature overlay; nothing is built.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS renewal dates.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "openspec/features.overlay.json maintenance-and-supplier-roadmap status 'soon'; no maintenance schema in lib/Settings/softwarecatalogus_register.json and no page in src/manifest.json" } }, { @@ -1598,24 +1935,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ctr-approval", - "area": "contracts", - "name": "Only let a contract become active after an approval decision is recorded.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/ContractStatusService.php:77 shouldExpire and :114 expirePastContracts set Active -> Expired when endDate < now; lib/BackgroundJob/ContractStatusJob.php:57 daily, registered in appinfo/info.xml:99", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Contracts /contracten status column and quick filters", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "contract-administration", + "featureConfidence": "high", + "note": "A daily job moves Active contracts past their end date to Expired on its own. There is no 'expiring' state in the enum, so the middle step of the row does not exist.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/ContractStatusService.php:77 shouldExpire and :114 expirePastContracts set Active -> Expired when endDate < now; lib/BackgroundJob/ContractStatusJob.php:57 daily, registered in appinfo/info.xml:99" } }, { @@ -1628,9 +1961,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/components/contracts/ContractApprovalPanel.vue:183 canSubmitRenewal for status Expired; POST /api/contracts/{uuid}/approval/renewal -> ContractApprovalService.php:254 with decisionType contract-renewal; lib/EventListener/DecisionConcludedListener.php projects the outcome (approvalState, status Active) via DECISION_CONCLUDED_EVENTS registered in lib/AppInfo/Application.php:830", + "owner": "ConductionNL/decidiq", + "ownerNote": "reader wrote: ConductionNL/stackiq + ConductionNL/decidiq" + }, + "reachedOn": "ContractDetail /contracten/:id, Approval panel 'Submit renewal' and approval state", + "provider": "decidiq", + "providerHow": "read-from-code", + "feature": "contract-renewal-approval", + "featureConfidence": "high", + "note": "An expired contract can be raised for renewal as a decidiq decision and the outcome shows on the contract's approval panel. It needs the decidiq app installed; without it the panel hides the action.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/contracts/ContractApprovalPanel.vue:183 canSubmitRenewal for status Expired; POST /api/contracts/{uuid}/approval/renewal -> ContractApprovalService.php:254 with decisionType contract-renewal; lib/EventListener/DecisionConcludedListener.php projects the outcome (approvalState, status Active) via DECISION_CONCLUDED_EVENTS registered in lib/AppInfo/Application.php:830" } }, { @@ -1643,10 +1988,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "contract-administration", + "featureConfidence": "medium", + "note": "The application page has no contracts list, and a contract links to a usage and a service rather than the application, so there is no path from an application to its contracts in the UI.", "evidence": { "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | Rated yes because contracts tracked against assets.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it" } }, { @@ -1659,11 +2015,22 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "lib/Service/PortfolioReportDerivation.php:163 annualisedCost (Monthly x12, Annually x1, One-off separate); lib/Service/PortfolioReportService.php:337 sumContractCost per quadrant; src/views/organisaties/PortfolioReport.vue:167 and :248 show annualised cost; src/utils/contractCost.js:111 totalAnnualisedCost used by src/views/LicensePostureView.vue per vendor", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Reports /reports -> Portfolio rationalization /portfolio-report; License posture /license-posture per-vendor rollup", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "contract-administration", + "featureConfidence": "high", + "note": "The portfolio report sums annualised contract cost per organisation and TIME quadrant, and the license posture page per vendor. The Dashboard only counts contracts.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS cost.", "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts | docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/PortfolioReportDerivation.php:163 annualisedCost (Monthly x12, Annually x1, One-off separate); lib/Service/PortfolioReportService.php:337 sumContractCost per quadrant; src/views/organisaties/PortfolioReport.vue:167 and :248 show annualised cost; src/utils/contractCost.js:111 totalAnnualisedCost used by src/views/LicensePostureView.vue per vendor" } }, { @@ -1676,10 +2043,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register :6937 module.licentietype enum Closed source/Open source and module.licence (five open-source licence names); catalogContract.contractType enum SLA/Licence/Maintenance (:3341)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules form and ModuleDetail /modules/:id data widget", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "license-and-seat-tracking", + "featureConfidence": "medium", + "note": "An application records open versus closed source and which open-source licence. There is no licence metric such as per user, per organisation or per seat.", "evidence": { "glpi": "docs, intelligence competitor_features#48901 'License management' (2026-07-23): Track license entitlements, compliance and expirations.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register :6937 module.licentietype enum Closed source/Open source and module.licence (five open-source licence names); catalogContract.contractType enum SLA/Licence/Maintenance (:3341)" } }, { @@ -1692,9 +2070,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/views/LicensePostureView.vue:11 open-source vs closed-source share weighted by in-production usage, :64 per-vendor rollup, per-organisation open-source-first report; derived in src/utils/licensePosture.js", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "License posture /license-posture (main menu)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The page shows the open-source share of the running portfolio with per-vendor and per-organisation breakdowns, computed at read time.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/LicensePostureView.vue:11 open-source vs closed-source share weighted by in-production usage, :64 per-vendor rollup, per-organisation open-source-first report; derived in src/utils/licensePosture.js" } }, { @@ -1707,10 +2094,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for seat/licence count across lib/, src/ and the register finds no seat or quantity field on catalogContract (:3252), module or usage", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "license-and-seat-tracking", + "featureConfidence": "high", + "note": "No field records licences bought or in use. The overlay lists license-and-seat-tracking as 'soon'.", "evidence": { "glpi": "docs, intelligence competitor_features#48901 'License management' (2026-07-23): Track license entitlements, compliance and expirations. | docs, intelligence competitor_features#3270 'License Management' (2026-03-28): Track software licenses, compliance, and expiration", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for seat/licence count across lib/, src/ and the register finds no seat or quantity field on catalogContract (:3252), module or usage" } }, { @@ -1723,9 +2121,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No entitlement or consumption fields exist (see ctr-seat-count); no service computes a licence position in lib/Service/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Without seat or consumption data there is nothing to compute an effective licence position from.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No entitlement or consumption fields exist (see ctr-seat-count); no service computes a licence position in lib/Service/" } }, { @@ -1738,10 +2145,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Contracts carry a cost and a period, but there is no budget to charge them against.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145790 'C-reporting-1 A budget the case costs are charged against, with a period.': glpi: Budgets (Management, Budgets, front/budget.php) Lane findings: D-glpi-37. | Rated yes because budgets, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)" } }, { @@ -1754,10 +2170,19 @@ "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "grep for depreciation/afschrijving finds nothing in lib/, src/ or the register", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No purchase value, useful life or depreciation is recorded or computed.", "evidence": { "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts | Rated partial because TCO tracking.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "grep for depreciation/afschrijving finds nothing in lib/, src/ or the register" } }, { @@ -1770,9 +2195,21 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:567 ContractDetail ct-files integration 'files' (Documents panel); catalogContract.documentReference text field (register :3252)", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq (page), files via ConductionNL/openregister + Nextcloud Files" + }, + "reachedOn": "ContractDetail /contracten/:id, Documents panel", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "contract-administration", + "featureConfidence": "medium", + "note": "The contract page has a Documents files panel for the signed contract, plus a document reference field.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:567 ContractDetail ct-files integration 'files' (Documents panel); catalogContract.documentReference text field (register :3252)" } }, { @@ -1785,10 +2222,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "usage.cloudDienstverleningsmodel (register :3050) plus contract cost; lib/Service/PortfolioReportService.php:302 per-usage annualised cost and cloud-transition share; src/views/organisaties/PortfolioReport.vue:166 cloudTransitionLabel per row", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Reports /reports -> Portfolio rationalization /portfolio-report", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The portfolio report shows each application in use with its cloud model and annualised cost, which lets you pick out SaaS spend. There is no SaaS subscription list and nothing discovers purchases made outside IT.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "usage.cloudDienstverleningsmodel (register :3050) plus contract cost; lib/Service/PortfolioReportService.php:302 per-usage annualised cost and cloud-transition share; src/views/organisaties/PortfolioReport.vue:166 cloudTransitionLabel per row" } }, { @@ -1801,10 +2247,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/views/KwetsbaarhedenView.vue:378 reportVulnerability opens the generic ObjectModal for 'vulnerability'; register.json:1619 vulnerability schema with cveCode (pattern CVE-yyyy-n, :1679) and cvssScore 0-10", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Vulnerabilities /kwetsbaarheden (menu), Report vulnerability", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A vulnerability is registered with CVE code and CVSS score, and a severity band is derived from the score.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/KwetsbaarhedenView.vue:378 reportVulnerability opens the generic ObjectModal for 'vulnerability'; register.json:1619 vulnerability schema with cveCode (pattern CVE-yyyy-n, :1679) and cvssScore 0-10" } }, { @@ -1817,39 +2272,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "sec-exposure", - "area": "security", - "name": "See which organisations and usages are exposed to a vulnerability.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "sec-vulnerability-alert", - "area": "security", - "name": "Get an alert when a vulnerability is reported for software you use.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:1701 vulnerability.modules links to module (applications), not moduleVersion; version level only via read-time SBOM match (src/utils/sbomVulnerabilityMatch.js, sbomComponent.vexCveIds register.json:8024) on the ModuleversieDetail Components tab", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Vulnerabilities /kwetsbaarheden form (Affected applications); ModuleversieDetail Components tab shows matches", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A vulnerability links to applications, not to specific versions. Per-version affectedness only shows as a computed match against a version's imported SBOM.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:1701 vulnerability.modules links to module (applications), not moduleVersion; version level only via read-time SBOM match (src/utils/sbomVulnerabilityMatch.js, sbomComponent.vexCveIds register.json:8024) on the ModuleversieDetail Components tab" } }, { @@ -1862,9 +2296,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/components/sbom/SbomComponentsPanel.vue:53-90 upload control (.json) -> POST /api/moduleversies/{uuid}/sbom (appinfo/routes.php:92) -> lib/Controller/SbomController.php:129 importSbom -> lib/Service/SbomParserService.php:77 parse (CycloneDX JSON) and :127 parseSpdx (SPDX 2.x JSON)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleversieDetail /moduleversies/:id, sidebar tab Components, upload", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "An SBOM in CycloneDX JSON or SPDX 2.x JSON can be uploaded for a version. XML and tag-value formats are not accepted.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/sbom/SbomComponentsPanel.vue:53-90 upload control (.json) -> POST /api/moduleversies/{uuid}/sbom (appinfo/routes.php:92) -> lib/Controller/SbomController.php:129 importSbom -> lib/Service/SbomParserService.php:77 parse (CycloneDX JSON) and :127 parseSpdx (SPDX 2.x JSON)" } }, { @@ -1877,9 +2320,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "decided-no", + "evidence": "src/utils/sbomVulnerabilityMatch.js header: 'no HTTP request to an external advisory feed is ever made'; lib/Service/EolSyncService.php syncs endoflife.date support dates, not CVEs", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Matching is deliberately local, against vulnerabilities typed into the catalogue. No public CVE feed is read.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/utils/sbomVulnerabilityMatch.js header: 'no HTTP request to an external advisory feed is ever made'; lib/Service/EolSyncService.php syncs endoflife.date support dates, not CVEs" } }, { @@ -1892,10 +2344,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "src/utils/vulnerabilitySeverity.js derives a severity band per vulnerability from CVSS; no per-application risk score in lib/ or src/ (searched risk)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Only individual vulnerabilities get a severity band. No application gets a combined score from its vulnerabilities and support status.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks | Rated partial because technology risk.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/utils/vulnerabilitySeverity.js derives a severity band per vulnerability from CVSS; no per-application risk score in lib/ or src/ (searched risk)" } }, { @@ -1908,9 +2369,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "register.json:1619 vulnerability has no fixed-in version field; src/utils/vulnerabilityExposure.js computeExposure carries the deployed moduleVersion per usage but nothing compares it to a fix", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The exposure row shows which version is deployed, but no record says which version fixes the vulnerability, so patch status cannot be seen.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register.json:1619 vulnerability has no fixed-in version field; src/utils/vulnerabilityExposure.js computeExposure carries the deployed moduleVersion per usage but nothing compares it to a fix" } }, { @@ -1923,9 +2393,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:969 Kwetsbaarheden custom page -> src/views/KwetsbaarhedenView.vue table with severity tabs; row click openDetail (:417) opens the record in the generic ObjectModal", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Vulnerabilities /kwetsbaarheden (menu)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "All vulnerabilities are listed with severity filters and each opens in the record form. The separate KwetsbaarheidDetail page is not what a row opens.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:969 Kwetsbaarheden custom page -> src/views/KwetsbaarhedenView.vue table with severity tabs; row click openDetail (:417) opens the record in the generic ObjectModal" } }, { @@ -1938,25 +2417,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:386 Organisaties type:index over schema organization (Add form); register :2022 organization.type enum Municipality/Supplier/Collaboration/Community, required contactsUid + type", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisations /organisaties (main menu), Add form; walkthrough step create-organisatie", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Organisations are created on the index with their type. The required contactsUid is a Nextcloud Contacts UID the form asks for as text, which is awkward but does not block the capability.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27555 'Vendor Registration' (2026-04-12): ICT providers register their software offerings | docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "org-self-registration", - "area": "organisations", - "name": "Let a new organisation sign itself up without an account.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization (Add form); register :2022 organization.type enum Municipality/Supplier/Collaboration/Community, required contactsUid + type" } }, { @@ -1969,9 +2442,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/views/settings/StackiqSettings.vue:92 ModerationQueue (type organisation) -> src/utils/adminApi.js -> GET /api/moderation/pending, POST /api/moderation/{uuid}/approve|reject; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; lib/Service/ModerationService.php:230 approval sets registrationStatus active and stamps publicationDate (:173)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section 'Registration moderation' (Nextcloud admin settings, stackiq)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "self-registration-with-moderation", + "featureConfidence": "high", + "note": "An admin reviews pending self-registrations and approves or rejects them. Approval sets registrationStatus and publication, but leaves the separate status field at Draft, which is what user provisioning waits for (see org-status).", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/settings/StackiqSettings.vue:92 ModerationQueue (type organisation) -> src/utils/adminApi.js -> GET /api/moderation/pending, POST /api/moderation/{uuid}/approve|reject; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; lib/Service/ModerationService.php:230 approval sets registrationStatus active and stamps publicationDate (:173)" } }, { @@ -1984,9 +2468,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "building", + "evidence": "register organization.status enum Draft/Active/Inactive is visible:false (:2022); src/manifest.json:403 OrganisatieDetail overrides status editable:false; src/modals/object/ChangeOrganisatieStatusDialog.vue:211 is never opened (no setDialog('changeOrganisatieStatus') in src); src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters status 'concept' and :129 writes 'actief', neither an enum value", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it (Organisations /organisaties can only filter by status)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No working path moves an organisation between Draft, Active and Inactive: the field is hidden on the form and locked on the detail page, the status dialog is orphaned, and the Nextcloud dashboard widget still uses the old Dutch values so it lists nothing and would write an invalid value.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "register organization.status enum Draft/Active/Inactive is visible:false (:2022); src/manifest.json:403 OrganisatieDetail overrides status editable:false; src/modals/object/ChangeOrganisatieStatusDialog.vue:211 is never opened (no setDialog('changeOrganisatieStatus') in src); src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters status 'concept' and :129 writes 'actief', neither an enum value" } }, { @@ -1999,25 +2492,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:418 OrganisatieDetail org-contactpersonen object-list (role, roles) with rowRoute ContactpersoonDetail; register :1788 contactPerson (contactsUid, role, organization, roles enum of catalogue roles)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "OrganisatieDetail /organisaties/:id 'Contact persons' list -> ContactpersoonDetail /contactpersonen/:id", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Contact persons are listed on the organisation with their function and roles. The Contactpersonen index page exists but has no menu entry.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27557 'Contact & Collaboration' (2026-04-12): Connect with municipalities using similar products", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "org-contact-to-account", - "area": "organisations", - "name": "Turn a contact person into a user account with the right role automatically.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:418 OrganisatieDetail org-contactpersonen object-list (role, roles) with rowRoute ContactpersoonDetail; register :1788 contactPerson (contactsUid, role, organization, roles enum of catalogue roles)" } }, { @@ -2030,9 +2517,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/components/organisations/OrganisationSwitcher.vue:48 'Manage members' (isBeheerder) opens src/modals/GrantOrganisationAccessModal.vue; POST /api/organisations/{uuid}/members -> lib/Controller/OrganisationMembersController.php:108 authorizeBeheerder then OpenRegister joinOrganisation (:123)", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq + ConductionNL/openregister" + }, + "reachedOn": "App header OrganisationSwitcher (src/App.vue:55) -> Manage members", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "A beheerder of the organisation grants an existing Nextcloud user access to it from the header switcher; membership is stored by OpenRegister. It adds existing users; it does not send an invitation to a new person.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/organisations/OrganisationSwitcher.vue:48 'Manage members' (isBeheerder) opens src/modals/GrantOrganisationAccessModal.vue; POST /api/organisations/{uuid}/members -> lib/Controller/OrganisationMembersController.php:108 authorizeBeheerder then OpenRegister joinOrganisation (:123)" } }, { @@ -2045,25 +2542,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "org-cooperation", - "area": "organisations", - "name": "Register a cooperation of organisations and the landscape they share.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/components/organisations/OrganisationSwitcher.vue:197 POST /apps/openregister/api/organisations/{uuid}/set-active; mounted in src/App.vue:55", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq + ConductionNL/openregister" + }, + "reachedOn": "App header OrganisationSwitcher on every page", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "A user who belongs to several organisations switches the active one from the header; OpenRegister holds the memberships.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/organisations/OrganisationSwitcher.vue:197 POST /apps/openregister/api/organisations/{uuid}/set-active; mounted in src/App.vue:55" } }, { @@ -2076,9 +2567,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail; POST /api/organisaties/{uuid}/merge -> lib/Controller/MergeController.php:142 isAdmin; lib/Service/MergeOrganisatieService.php:111 re-points usage.consumer/participants, contactPerson.organization, connection.provider and @self.organisation of catalogContract/compliancy; module.provider and catalogService.provider are not re-pointed", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "OrganisatieDetail /organisaties/:id, merge panel (admin only)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "An admin can merge a municipality into another and its usages, contacts and contracts follow. A supplier takeover leaves the source's applications and services pointing at the tombstoned supplier, because module and service provider fields are not in the relation map.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail; POST /api/organisaties/{uuid}/merge -> lib/Controller/MergeController.php:142 isAdmin; lib/Service/MergeOrganisatieService.php:111 re-points usage.consumer/participants, contactPerson.organization, connection.provider and @self.organisation of catalogContract/compliancy; module.provider and catalogService.provider are not re-pointed" } }, { @@ -2091,10 +2591,19 @@ "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/components/organisations/OrganisationMergePanel.vue:324 organisatieStore.dryRunMerge shows dryRunCounts before execute; POST /api/organisaties/{uuid}/merge/dry-run -> lib/Service/MergeOrganisatieService.php:160 dryRun", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "OrganisatieDetail /organisaties/:id, merge panel (admin only)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The merge panel shows per-type counts of what would be re-pointed before the admin confirms. It inherits the merge's blind spot: module and service provider links are not counted because they are not moved.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#146004 'C-configuration-95 The product shows what an import or a migration will change before it writes.': glpi: Form export and import (Form/ExportController.php, Form/Import/Step1IndexController.php through Step4ExecuteController.php) Lane findings: D-glpi-11. | Rated partial because import previews before writing; not for merges, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/organisations/OrganisationMergePanel.vue:324 organisatieStore.dryRunMerge shows dryRunCounts before execute; POST /api/organisaties/{uuid}/merge/dry-run -> lib/Service/MergeOrganisatieService.php:160 dryRun" } }, { @@ -2107,41 +2616,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/views/settings/StackiqSettings.vue:80 UserGroupsConfiguration -> GET/POST /api/user-groups/config (src/store/modules/settings.js:830); lib/Controller/SettingsController.php:3379; lib/Service/Stackiq/GroupHandler.php:103 generic groups, :167 fixed role groups (aanbod-beheerder, gebruik-beheerder, ...), group choice by organisation type (:471)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section 'User groups'", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "An admin configures which groups count as generic users, organisation admins and super users. The catalogue roles themselves map to fixed, hard-coded group names and by organisation type, so an admin cannot map e.g. 'buyer' onto a group of their choice.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141837 '11.19 User, role and department administration in the app': `/front/user.form.php`, `/front/profile.form.php` (`src/Profile.php`, `src/ProfileRight.php:46`), `/front/group.form.php`, and the three-way user x profile x entity grant `src/Profile_User.php:320` with a recursive flag | Rated yes because user, profile and entity administration, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "org-data-segregation", - "area": "organisations", - "name": "Keep each organisation's records visible only to that organisation unless published.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "yes", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "glpi": "docs, intelligence competitor_features#48910 'Multi-entity (tenant) segregation' (2026-07-23): Hierarchical entities for multi-org / multi-department isolation.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "org-hierarchy", - "area": "organisations", - "name": "Make the first user of an organisation its administrator and manager of later users.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/settings/StackiqSettings.vue:80 UserGroupsConfiguration -> GET/POST /api/user-groups/config (src/store/modules/settings.js:830); lib/Controller/SettingsController.php:3379; lib/Service/Stackiq/GroupHandler.php:103 generic groups, :167 fixed role groups (aanbod-beheerder, gebruik-beheerder, ...), group choice by organisation type (:471)" } }, { @@ -2154,11 +2641,20 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No OIDC/SAML code in lib/ or src/; stackiq creates local Nextcloud users with a password (lib/Service/Stackiq/ContactPersonHandler.php:292)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it in stackiq; Nextcloud's own user_oidc/user_saml apps would apply platform-wide", + "provider": "nextcloud", + "providerHow": "read-from-code", + "note": "Stackiq does nothing for single sign-on. A Nextcloud admin can add an identity provider app, but that is the platform, not a stackiq page.", "evidence": { "glpi": "docs, intelligence competitor_features#48908 'LDAP / SSO' (2026-07-23): Directory authentication and SSO.", "topdesk": "docs, intelligence competitor_features#48935 'SSO integration' (2026-07-23): SAML / SSO authentication.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No OIDC/SAML code in lib/ or src/; stackiq creates local Nextcloud users with a password (lib/Service/Stackiq/ContactPersonHandler.php:292)" } }, { @@ -2171,10 +2667,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it in stackiq; Nextcloud's user_ldap would apply platform-wide", + "provider": "nextcloud", + "providerHow": "read-from-code", + "note": "Stackiq has no directory sync for users or groups. Nextcloud's LDAP app could do it platform-wide, outside stackiq.", "evidence": { "glpi": "docs, intelligence competitor_features#48908 'LDAP / SSO' (2026-07-23): Directory authentication and SSO. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141776 '5.11 Contact import and change subscriptions from registries': LDAP import and periodic re-sync of users and groups (`src/AuthLDAP.php`, `/front/ldap.import.php`, `/front/ldap.group.import.php`) with `src/RuleRight.php` mapping directory attributes to profiles; nothing subscribes to", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/" } }, { @@ -2187,9 +2692,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/components/ContactpersonenList.vue:115 'Change Password' opens src/dialogs/ChangePasswordDialog.vue -> POST /api/contactpersonen/change-password -> lib/Controller/ContactpersonenController.php:718, self-reset allowed at :753; GET /api/me (:1578) used only by src/App.vue and OrganisationSwitcher", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisations /organisaties card -> contact persons view -> Change Password on your own row", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A user can change their own password from their contact row in the organisation card, which is hard to find. There is no 'my account' page in stackiq; /api/me feeds only the organisation switcher. Nextcloud's personal settings do both natively.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/components/ContactpersonenList.vue:115 'Change Password' opens src/dialogs/ChangePasswordDialog.vue -> POST /api/contactpersonen/change-password -> lib/Controller/ContactpersonenController.php:718, self-reset allowed at :753; GET /api/me (:1578) used only by src/App.vue and OrganisationSwitcher" } }, { @@ -2202,26 +2716,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/SymfonyEmailService.php:466 registration, :553 activation, :641 user creation mails from templates; src/views/settings/sections/EmailConfiguration.vue:902 saveTemplate is a stub that logs 'not yet implemented in the backend' and still shows success; backend POST /api/email/templates/{templateName} (lib/Controller/SettingsController.php:2194) has no caller in src/; lib/Settings/connections.json email adapter reports the 'null' transport as simulated", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section 'Email configuration', Templates tab (save does not persist)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The mails are sent from templates, but the admin template editor's Save button does not call the backend and reports success anyway, so an administrator cannot edit a template from the UI. The transport defaults to 'null', which sends nothing until configured.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141830 '11.12 E-mail template library': `src/NotificationTemplate.php` with per-language bodies (`src/NotificationTemplateTranslation.php`), bound to events and delivery modes by `src/Notification_NotificationTemplate.php`, at `/front/notificationtemplate.php` | Rated yes because notification templates, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "share-public-browse", - "area": "sharing", - "name": "Let anyone browse the published catalogue without signing in.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/SymfonyEmailService.php:466 registration, :553 activation, :641 user creation mails from templates; src/views/settings/sections/EmailConfiguration.vue:902 saveTemplate is a stub that logs 'not yet implemented in the backend' and still shows success; backend POST /api/email/templates/{templateName} (lib/Controller/SettingsController.php:2194) has no caller in src/; lib/Settings/connections.json email adapter reports the 'null' transport as simulated" } }, { @@ -2234,9 +2741,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/PublicationController.php:87 publish/depublish (routes.php:208-209, PUT/DELETE /api/publication/{objectType}/{uuid}) with an IDOR guard; lib/Service/PublicationService.php:51 publishable types catalogService, module, connection, organization. No src/ caller of /api/publication (only a comment in src/utils/openDataProjection.js). The publish buttons in src/modals/object/ViewObject.vue:4854 are unreachable: Modals.vue renders ViewObject only for modal 'viewOrganisatie'/'viewContactpersoon', which nothing sets. Workaround: publicationDate/depublicationDate are visible, editable fields on module/catalogService/organization/connection (lib/Settings/softwarecatalogus_register.json:6777 schema).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only for the publish action: PUT /api/publication/{objectType}/{uuid}/publish, no stackiq page calls it; a user can only set the publicationDate field by hand in the edit form on Applications /modules or Services /diensten", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "open-data-publishing", + "featureConfidence": "high", + "note": "The dedicated publish/withdraw endpoint is complete and guarded but no page calls it, and the old modal publish buttons are dead code. The only UI path is typing a publication or depublication date into the generic edit form.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Controller/PublicationController.php:87 publish/depublish (routes.php:208-209, PUT/DELETE /api/publication/{objectType}/{uuid}) with an IDOR guard; lib/Service/PublicationService.php:51 publishable types catalogService, module, connection, organization. No src/ caller of /api/publication (only a comment in src/utils/openDataProjection.js). The publish buttons in src/modals/object/ViewObject.vue:4854 are unreachable: Modals.vue renders ViewObject only for modal 'viewOrganisatie'/'viewContactpersoon', which nothing sets. Workaround: publicationDate/depublicationDate are visible, editable fields on module/catalogService/organization/connection (lib/Settings/softwarecatalogus_register.json:6777 schema)." } }, { @@ -2249,9 +2767,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "building", + "evidence": "src/utils/openDataProjection.js:36 STRIPPED_FIELDS (PII projection) is imported by nothing in src/ and has no PHP counterpart (grep 'projection' in lib/ finds none). Usage schema read rule lib/Settings/softwarecatalogus_register.json:3150 has no public group; lib/Controller/GebruikController.php:102 returns an empty result to anonymous callers.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "open-data-publishing", + "featureConfidence": "high", + "note": "Usage (gebruik) is not published as open data at all: anonymous callers get an empty envelope and the usage schema has no public read rule. The PII-stripping projection exists only as an unused, unit-tested JS util.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/utils/openDataProjection.js:36 STRIPPED_FIELDS (PII projection) is imported by nothing in src/ and has no PHP counterpart (grep 'projection' in lib/ finds none). Usage schema read rule lib/Settings/softwarecatalogus_register.json:3150 has no public group; lib/Controller/GebruikController.php:102 returns an empty result to anonymous callers." } }, { @@ -2264,9 +2793,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/Federation/FederationService.php:215 announce() calls OpenCatalogi BroadcastService->broadcast(directory URL); only caller is lib/BackgroundJob/FederationSyncJob.php:73. Off by default: lib/Service/Federation/FederationConfig.php:56 federation_enabled=false; lib/Settings/connections.json lists federation as switch-only via occ. isAvailable() is class_exists('OCA\\\\OpenCatalogi\\\\Service\\\\DirectoryService') (FederationService.php:95).", + "owner": "ConductionNL/opencatalogi" + }, + "reachedOn": "admin settings section Catalog federation shows status only; announce runs only from the background job after an admin sets federation_enabled with occ", + "provider": "opencatalogi", + "providerHow": "read-from-code", + "feature": "federation-between-catalogues", + "featureConfidence": "high", + "note": "The announce hop is a real call into OpenCatalogi, but it is off by default, can only be switched on with occ, has no announce button, and needs OpenCatalogi installed.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/Federation/FederationService.php:215 announce() calls OpenCatalogi BroadcastService->broadcast(directory URL); only caller is lib/BackgroundJob/FederationSyncJob.php:73. Off by default: lib/Service/Federation/FederationConfig.php:56 federation_enabled=false; lib/Settings/connections.json lists federation as switch-only via occ. isAvailable() is class_exists('OCA\\\\OpenCatalogi\\\\Service\\\\DirectoryService') (FederationService.php:95)." } }, { @@ -2279,9 +2819,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "built", + "evidence": "lib/Service/Federation/FederationService.php:434 fetchPeerCatalog() calls OpenCatalogi DirectoryService->getDirectory(['url' => $peerUrl]); OpenCatalogi's getDirectory (opencatalogi lib/Service/DirectoryService.php:2409, also on origin/development) reads only filters/limit/offset/include-federated and ignores 'url', so it returns this instance's own directory listings, not the peer's published entries. Provenance marking itself is built: lib/Service/Federation/FederationMerger.php:239 stamps _source.instance. Mirrors are written into the organization schema (FederationService.php:56 PEER_MIRROR_TYPE). No src/ code reads _source, so no page shows where an entry came from.", + "owner": "ConductionNL/opencatalogi" + }, + "reachedOn": "admin settings section Catalog federation, Pull now button (src/views/settings/sections/FederationSettings.vue:332)", + "provider": "opencatalogi", + "providerHow": "read-from-code", + "feature": "federation-between-catalogues", + "featureConfidence": "high", + "note": "The pull does not fetch the peer: the peer URL is passed as a parameter OpenCatalogi ignores, so what gets mirrored is the local directory listing. Provenance is stamped on mirrors but no page displays it. Federation is also off by default.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/Federation/FederationService.php:434 fetchPeerCatalog() calls OpenCatalogi DirectoryService->getDirectory(['url' => $peerUrl]); OpenCatalogi's getDirectory (opencatalogi lib/Service/DirectoryService.php:2409, also on origin/development) reads only filters/limit/offset/include-federated and ignores 'url', so it returns this instance's own directory listings, not the peer's published entries. Provenance marking itself is built: lib/Service/Federation/FederationMerger.php:239 stamps _source.instance. Mirrors are written into the organization schema (FederationService.php:56 PEER_MIRROR_TYPE). No src/ code reads _source, so no page shows where an entry came from." } }, { @@ -2294,9 +2845,20 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/FederationController.php:86 addPeer / removePeer (routes.php:246-247), #[AuthorizedAdminSetting(StackiqAdmin)]; lib/Service/Federation/FederationService.php:157/191 with an SSRF host guard; UI src/views/settings/sections/FederationSettings.vue:283 (POST) and :307 (DELETE), mounted from src/views/settings/StackiqSettings.vue:114.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section Catalog federation (Nextcloud admin settings > Stackiq)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "federation-between-catalogues", + "featureConfidence": "high", + "note": "Adding and removing peers works end to end, but only for a Nextcloud admin in the admin settings, and the peers are only used by a pull that currently fetches the wrong data (see share-federation-pull).", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Controller/FederationController.php:86 addPeer / removePeer (routes.php:246-247), #[AuthorizedAdminSetting(StackiqAdmin)]; lib/Service/Federation/FederationService.php:157/191 with an SSRF host guard; UI src/views/settings/sections/FederationSettings.vue:283 (POST) and :307 (DELETE), mounted from src/views/settings/StackiqSettings.vue:114." } }, { @@ -2309,29 +2871,22 @@ "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "Every catalogue entity is an OpenRegister object (src/manifest.json pages read register @resolve:voorzieningen_register), so OpenRegister's /apps/openregister/api/objects/{register}/{schema} CRUD applies, gated by the schema authorization rules (lib/Settings/softwarecatalogus_register.json:6777 module and others). Stackiq adds its own routed endpoints in appinfo/routes.php (e.g. :202 /api/aanbod, :255-261 /api/aangeboden-gebruik, :298 /api/gebruik, :303 /api/portfolio-report).", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "API: /apps/openregister/api/objects plus stackiq /api/*; the stackiq pages themselves use the same API", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "Read and write through a REST API is live through OpenRegister, with stackiq's own role-scoped endpoints on top.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48867 'REST & GraphQL API' (2026-07-23): Programmatic access to the workspace graph.", "bluedolphin": "docs, intelligence competitor_features#48972 'REST API' (2026-07-23): Programmatic integration with other systems.", "glpi": "docs, intelligence competitor_features#48907 'REST API (HLAPI 2.x)' (2026-07-23): High-level REST API expanding object coverage in GLPI 11.", "topdesk": "docs, intelligence competitor_features#48933 'REST API' (2026-07-23): Open REST API for integrations.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "share-public-api", - "area": "sharing", - "name": "Give developers a secure public API over the supplier offering.", - "origin": "competitor", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "no", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141847 '12.19 Public data API with certificates or API keys': the API is fully authenticated, never public: user tokens plus optional app tokens with IP allow-listing (`apirest.md:62-67`, `src/APIClient.php:42`) and OAuth2 with scopes (`src/Glpi/OAuth/`). No anonymous public datase | Rated no because API is always authenticated, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Every catalogue entity is an OpenRegister object (src/manifest.json pages read register @resolve:voorzieningen_register), so OpenRegister's /apps/openregister/api/objects/{register}/{schema} CRUD applies, gated by the schema authorization rules (lib/Settings/softwarecatalogus_register.json:6777 module and others). Stackiq adds its own routed endpoints in appinfo/routes.php (e.g. :202 /api/aanbod, :255-261 /api/aangeboden-gebruik, :298 /api/gebruik, :303 /api/portfolio-report)." } }, { @@ -2344,10 +2899,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261), both login-only. Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: GET /api/views/docs and /api/aangeboden-gebruik/docs; docs site https://stackiq.conduction.nl (Documentation footer link)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The generated OpenAPI file is empty. What exists is hand-written: two JSON doc endpoints and markdown pages. OpenRegister may generate an OAS per register, but stackiq does not surface it.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141846 '12.18 OpenAPI documentation': auto-generated from route attributes: `src/Glpi/Api/HL/OpenAPIGenerator.php` with `src/Glpi/Api/HL/Doc/`, versioned per route (`#[RouteVersion]`, router at `src/Glpi/Api/HL/Router.php:98`); the legacy API is documented i | Rated yes because OpenAPI generator, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261), both login-only. Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint." } }, { @@ -2360,41 +2924,22 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section ArchiMate Import/Export; Portfolio rationalization /portfolio-report (Export CSV, one organisation at a time)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "medium", + "note": "A full ArchiMate export exists but is only reached from admin settings. The one export on a user page is the portfolio report CSV, and the catalogue list pages offer no export.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141818 '10.3 Export list results to CSV or XLSX': `src/Glpi/Search/Output/Csv.php`, `Xlsx.php`, `Ods.php` and `Pdf.php`, mapped at `src/Glpi/Search/SearchEngine.php:108-130` | Rated yes because CSV, XLSX, ODS, PDF export, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "share-portal", - "area": "sharing", - "name": "Show catalogue content on a shared external portal next to other apps' content.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "share-ai-assistant", - "area": "sharing", - "name": "Let an AI assistant query and update the catalogue through a tool interface.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json)." } }, { @@ -2407,46 +2952,49 @@ "bluedolphin": "yes", "glpi": "unknown", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No ITSM connector: lib/Settings/connections.json lists only email, federation and eol-feed; grep for topdesk/servicenow/itsm in lib/ and src/ finds nothing.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No integration with a service management tool exists.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48866 'Out-of-the-box integrations (ServiceNow, Signavio, SAP)' (2026-07-23): Pre-built connectors sync CMDB, process and ERP data.", "bluedolphin": "docs, intelligence competitor_features#48973 'TOPdesk integration' (2026-07-23): Connector to TOPdesk asset/service data. | docs, intelligence competitor_features#27465 'TOPdesk Integration' (2026-04-12): Available on TOPdesk Marketplace for IT landscape insights", "topdesk": "docs, intelligence competitor_features#48934 'Marketplace integrations (Lansweeper, ValueBlue)' (2026-07-23): Pre-built connectors incl. Lansweeper discovery and ValueBlue EA. | docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No ITSM connector: lib/Settings/connections.json lists only email, federation and eol-feed; grep for topdesk/servicenow/itsm in lib/ and src/ finds nothing." } }, { - "id": "share-webhooks", + "id": "share-self-hosted", "area": "sharing", - "name": "Notify another system automatically when a catalogue entry changes.", + "name": "Run the catalogue on your own infrastructure instead of the vendor's cloud.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "share-self-hosted", - "area": "sharing", - "name": "Run the catalogue on your own infrastructure instead of the vendor's cloud.", - "origin": "competitor", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "no", - "bluedolphin": "no", - "glpi": "yes", - "topdesk": "partial", - "stackiq": "unknown", + "sap-leanix": "no", + "bluedolphin": "no", + "glpi": "yes", + "topdesk": "partial", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "appinfo/info.xml: a Nextcloud app (id stackiq, EUPL-1.2) installed on the customer's own Nextcloud with OpenRegister; stackiq-compose.yaml at repo root for a local stack.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "the whole app runs on the customer's own Nextcloud", + "provider": "nextcloud", + "providerHow": "read-from-code", + "note": "As a Nextcloud app it runs on whatever infrastructure hosts the Nextcloud instance.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", "bluedolphin": "docs, intelligence competitor_features#27467 'SaaS Platform' (2026-04-12): Cloud-native SaaS, no installation required", "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", "topdesk": "docs, intelligence competitor_features#26346 'SaaS Platform' (2026-04-10): Cloud-hosted SaaS platform with automatic updates | Rated partial because offered as SaaS; on-premises not in the reading.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "appinfo/info.xml: a Nextcloud app (id stackiq, EUPL-1.2) installed on the customer's own Nextcloud with OpenRegister; stackiq-compose.yaml at repo root for a local stack." } }, { @@ -2459,11 +3007,22 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/FacetService.php:109 DIMENSIONS = referenceComponent, standard, applicationService, domain (GET /api/facets/{schema}, routes.php:195); src/views/FacetedCatalogIndexView.vue renders CnFacetSidebar with these plus search, on the Applications and Services pages. Supplier is only a column (src/manifest.json Modules config columns 'provider'), not a facet, although the module schema marks provider facetable.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules and Services /diensten (FacetedCatalogIndexView)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "low", + "note": "Search plus reference-component, standard, application-service and domain facets work. Supplier is not offered as a facet, which is half of the row's example.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27553 'ICT Market Orientation' (2026-04-12): Find and compare software from registered ICT providers", "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141806 '9.2 Advanced search with per-case-type fields': the search engine is strong, with ~160 ticket search options (`src/Ticket.php:2670`), nested criteria groups, `AND`/`OR`/`AND NOT`/`OR NOT` (`src/Glpi/Search/SearchEngine.php:551-564`), cross-itemtype meta-criteria, but | Rated yes because search engine with nested criteria, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS = referenceComponent, standard, applicationService, domain (GET /api/facets/{schema}, routes.php:195); src/views/FacetedCatalogIndexView.vue renders CnFacetSidebar with these plus search, on the Applications and Services pages. Supplier is only a column (src/manifest.json Modules config columns 'provider'), not a facet, although the module schema marks provider facetable." } }, { @@ -2476,10 +3035,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules and Services /diensten, Saved views menu", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A user can save the facet and search selection as a named view and reopen it. Storage is OpenRegister's views API. It covers only those two pages.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141807 '9.3 Personal saved searches': `src/SavedSearch.php:52`, `is_private` default 1, personal ordering (`:824`) and a default per itemtype (`src/SavedSearch_User.php:94-115`), at `/front/savedsearch.php` | Rated yes because saved searches, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back." } }, { @@ -2492,12 +3060,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:72 Dashboard page with stat widgets kpi-organisations, kpi-modules, kpi-services, kpi-contracts (source metric count on organization/module/catalogService/catalogContract) plus catalog-panels.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Dashboard / (first menu entry)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The dashboard shows counts of organisations, applications, services and contracts. The counts are computed by OpenRegister through the library stat widget.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports. | docs, intelligence competitor_features#27424 'Dashboards & Reports' (2026-04-12): Real-time dashboards for CIO-level reporting", "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141816 '10.1 Configurable KPI dashboards (count, gauge, chart)': `src/Glpi/Dashboard/Grid.php:67` with 20 widget types: pie, donut, half pie/donut, bars, lines, areas, stacked and horizontal variants, big number, multiple numbers, summary numbers, markdown, search result, article list", "topdesk": "docs, intelligence competitor_features#48936 'Reporting & dashboards' (2026-07-23): Operational reporting and dashboards.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:72 Dashboard page with stat widgets kpi-organisations, kpi-modules, kpi-services, kpi-contracts (source metric count on organization/module/catalogService/catalogContract) plus catalog-panels." } }, { @@ -2510,9 +3087,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "built", + "evidence": "lib/Dashboard/ConceptOrganisatiesWidget.php registered at lib/AppInfo/Application.php:760; src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters organisations on status === 'concept', but the status enum is Draft/Active/Inactive/merged (lib/Settings/softwarecatalogus_register.json:2321) after lib/Repair/RenameDutchCatalogValues.php:76 renamed 'Concept' to 'Draft'. Accept writes status 'actief' (:129), which is not in the enum either.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Nextcloud dashboard widget 'Concept organisaties'", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The widget is registered and loads, but it filters on a status value the data no longer holds, so it always lists nothing. Its accept button would write an invalid status.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Dashboard/ConceptOrganisatiesWidget.php registered at lib/AppInfo/Application.php:760; src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters organisations on status === 'concept', but the status enum is Draft/Active/Inactive/merged (lib/Settings/softwarecatalogus_register.json:2321) after lib/Repair/RenameDutchCatalogValues.php:76 renamed 'Concept' to 'Draft'. Accept writes status 'actief' (:129), which is not in the enum either." } }, { @@ -2525,10 +3111,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Reports /reports (footer menu), one card to Portfolio rationalization /portfolio-report", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The report picker exists and opens a working report. The list holds exactly one report.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145791 'C-reporting-2 A canned report the product ships, run without building it.': glpi: Reports (Tools, Reports, front/report.default.php, report.dynamic.php, report.year.php, report.state.php, report.reservation.php, report.contract.php) Lane findings: D-glpi-35. | Rated yes because canned reports, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303)." } }, { @@ -2541,11 +3136,22 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No report builder in src/ or lib/. The only report is the fixed Gartner TIME portfolio report (lib/Controller/PortfolioReportController.php, CSV at :105). The overlay lists portfolio-reporting as status 'soon'.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "portfolio-reporting", + "featureConfidence": "high", + "note": "Users cannot build their own report. The one fixed portfolio report can be exported as CSV, but it is not configurable.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141816 '10.1 Configurable KPI dashboards (count, gauge, chart)': `src/Glpi/Dashboard/Grid.php:67` with 20 widget types: pie, donut, half pie/donut, bars, lines, areas, stacked and horizontal variants, big number, multiple numbers, summary numbers, markdown, search result, article list", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No report builder in src/ or lib/. The only report is the fixed Gartner TIME portfolio report (lib/Controller/PortfolioReportController.php, CSV at :105). The overlay lists portfolio-reporting as status 'soon'." } }, { @@ -2558,10 +3164,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Portfolio rationalization /portfolio-report, Export CSV", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "portfolio-reporting", + "featureConfidence": "low", + "note": "One fixed report exports to CSV for a selected organisation. The filtered catalogue lists cannot be exported.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141818 '10.3 Export list results to CSV or XLSX': `src/Glpi/Search/Output/Csv.php`, `Xlsx.php`, `Ods.php` and `Pdf.php`, mapped at `src/Glpi/Search/SearchEngine.php:108-130` | Rated yes because source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export." } }, { @@ -2574,58 +3191,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ins-audit-trail", - "area": "insight", - "name": "Look back at who changed what in the catalogue, and when.", - "origin": "competitor", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "yes", - "topdesk": "yes", - "stackiq": "unknown", - "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141820 '10.5 Audit or event log viewer with filters and export': two logs, both searchable and exportable through the search engine: `src/Log.php:48` field-level object history (Historical tab, `src/Ticket.php:887`) and `src/Glpi/Event.php:63` the system/event log at `/front/logs.php` | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141852 '13.9 Audit trail including reads and views': writes are covered thoroughly: `src/Log.php:48` field-level history on every object, `src/Glpi/Event.php:63` the system log including logins (`src/Auth.php:1149-1163`), `src/RuleMatchedLog.php` for rule decisions. Reads | Rated yes because field-level history, source-read 2026-09-14.", - "topdesk": "docs, intelligence competitor_features#26345 'Audit Trail' (2026-04-10): Complete audit trail of all service management actions", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ins-live-updates", - "area": "insight", - "name": "See a list update by itself when someone else changes an entry.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "partial", - "glpi": "unknown", - "topdesk": "unknown", - "stackiq": "unknown", - "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48969 'Real-time collaboration' (2026-07-23): Multiple stakeholders collaborate on models. | Rated partial because real-time collaboration on models.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ins-notifications", - "area": "insight", - "name": "Receive in-app notifications about changes that concern you.", - "origin": "own-code", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "partial", - "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No scheduled report or report mail job: lib/BackgroundJob/ holds only ContractStatusJob, EolSyncJob, FederationSyncJob and OrganizationContactSyncJob; grep for report scheduling in lib/ and src/ finds nothing.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Reports cannot be scheduled or sent to people.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141783 '6.8 In-app notifications (bell)': `MODE_AJAX` is a wired delivery mode (`src/Notification_NotificationTemplate.php:55-59`, `getModes()` at `:381-398`, implementation `src/NotificationAjax.php`), rendering as a browser toast rather than a persistent inbox | Rated partial because toast delivery, not an inbox, source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No scheduled report or report mail job: lib/BackgroundJob/ holds only ContractStatusJob, EolSyncJob, FederationSyncJob and OrganizationContactSyncJob; grep for report scheduling in lib/ and src/ finds nothing." } }, { @@ -2638,10 +3215,21 @@ "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/views/LicensePostureView.vue:84 per-vendor rollup with annual cost from contracts (src/utils/licensePosture.js perVendorRollup); src/views/organisaties/PortfolioReport.vue:143 annualised and one-off cost per TIME quadrant for one selected organisation (lib/Service/PortfolioReportService.php via GET /api/portfolio-report).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "License posture /license-posture (per vendor); Portfolio rationalization /portfolio-report (per selected organisation)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "contract-administration", + "featureConfidence": "medium", + "note": "Cost is reported per vendor and, within the portfolio report, for one organisation at a time. There is no cross-organisation or per-domain cost report.", "evidence": { "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/views/LicensePostureView.vue:84 per-vendor rollup with annual cost from contracts (src/utils/licensePosture.js perVendorRollup); src/views/organisaties/PortfolioReport.vue:143 annualised and one-off cost per TIME quadrant for one selected organisation (lib/Service/PortfolioReportService.php via GET /api/portfolio-report)." } }, { @@ -2654,9 +3242,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "src/manifest.json:1048 FeaturesRoadmap page (type roadmap, line 1050), footer menu entry FeaturesRoadmapMenu; content from openspec/features.overlay.json statuses stable/beta/soon.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Features & roadmap /features-roadmap (footer menu)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The page lists features with their status. Note that the overlay feeding it is a self-description and may be stale in the app's favour.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "src/manifest.json:1048 FeaturesRoadmap page (type roadmap, line 1050), footer menu entry FeaturesRoadmapMenu; content from openspec/features.overlay.json statuses stable/beta/soon." } }, { @@ -2669,10 +3266,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/SettingsController.php:1289 getProgress and :1360 streamProgress (routes.php:119-120) serve lib/Service/ProgressTracker.php, used only by lib/Service/MergeOrganisatieService.php; no src/ caller of /api/progress. The admin ArchiMate import shows a spinner then the final objects-processed count (src/views/settings/sections/ArchiMateImportExport.vue:103). Organisation sync shows a status block with last sync time and organisations to process (src/views/settings/sections/OrganizationSynchronization.vue:211).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings sections Organization Synchronization and ArchiMate Import/Export (status and result only); progress endpoints API only", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A progress API exists but no page reads it. Admins see a sync status and final import results, not the progress of a running job.", "evidence": { "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145875 'C-configuration-20 A long running administrative operation reports its progress.': glpi: Progress on a long operation (src/Glpi/Controller/ProgressController.php, Traits/AsyncOperationProgressControllerTrait.php) Lane findings: D-glpi-29. | Rated yes because source-read 2026-09-14.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/Controller/SettingsController.php:1289 getProgress and :1360 streamProgress (routes.php:119-120) serve lib/Service/ProgressTracker.php, used only by lib/Service/MergeOrganisatieService.php; no src/ caller of /api/progress. The admin ArchiMate import shows a spinner then the final objects-processed count (src/views/settings/sections/ArchiMateImportExport.vue:103). Organisation sync shows a status block with last sync time and organisations to process (src/views/settings/sections/OrganizationSynchronization.vue:211)." } }, { @@ -2685,11 +3291,20 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "There is no knowledge base. Files can be attached to an application, but that is not searchable articles.", "evidence": { "glpi": "docs, intelligence competitor_features#48909 'Knowledge base' (2026-07-23): Built-in KB with FAQ publishing.", "topdesk": "docs, intelligence competitor_features#48931 'Knowledge base' (2026-07-23): Knowledge management and published articles.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel." } }, { @@ -2702,10 +3317,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No discovery agent or agent-ingest endpoint in lib/ or appinfo/routes.php. The nearest capability is SBOM import per module version (lib/Controller/SbomController.php:129), which records components of a known release, not installed software.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Stackiq is a catalogue, and nothing discovers installed software.", "evidence": { "glpi": "docs, intelligence competitor_features#48899 'Native inventory (GLPI Agent)' (2026-07-23): Built-in agent (ex-FusionInventory) discovers hardware/software automatically. | docs, intelligence competitor_features#3269 'Inventory' (2026-03-28): Automatic inventory discovery with FusionInventory agent", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No discovery agent or agent-ingest endpoint in lib/ or appinfo/routes.php. The nearest capability is SBOM import per module version (lib/Controller/SbomController.php:129), which records components of a known release, not installed software." } }, { @@ -2718,10 +3342,19 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No network scanning code in lib/ or routes (appinfo/routes.php).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No device discovery.", "evidence": { "glpi": "docs, intelligence competitor_features#48911 'Network / SNMP discovery' (2026-07-23): SNMP network equipment inventory.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No network scanning code in lib/ or routes (appinfo/routes.php)." } }, { @@ -2734,10 +3367,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No SaaS or SSO-log discovery code in lib/; lib/Settings/connections.json has no such source.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No discovery of unregistered SaaS use.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No SaaS or SSO-log discovery code in lib/; lib/Settings/connections.json has no such source." } }, { @@ -2750,11 +3392,20 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No hardware schema in lib/Settings/softwarecatalogus_register.json (schemas are software, organisation, contract and GEMMA model types only).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Only software is registered, not hardware.", "evidence": { "glpi": "docs, intelligence competitor_features#3266 'IT Asset Management' (2026-03-28): Track hardware, software, and network assets", "topdesk": "docs, intelligence competitor_features#27388 'Asset Management' (2026-04-12): Track hardware and software assets, locations, and assignments", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No hardware schema in lib/Settings/softwarecatalogus_register.json (schemas are software, organisation, contract and GEMMA model types only)." } }, { @@ -2767,12 +3418,21 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "Applications (module lib/Settings/softwarecatalogus_register.json:6777), versions (moduleVersion :7649), suites (suite :1135) and application-to-application connections (connection :3563) with relations; ModuleDetail and SuiteDetail show a Related panel. No manifest page has register+schema 'connection' or 'usage', so connections are not listed or created on their own page.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Applications /modules/:id and Suites /suites/:id Related panels; no page for connections", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The landscape and its relations are recorded as catalogue objects, not as a CMDB with CI classes. Connections (koppelingen) have no index or detail page of their own.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", "glpi": "docs, intelligence competitor_features#48902 'CMDB & configuration relations' (2026-07-23): CI relationships and impact analysis.", "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Applications (module lib/Settings/softwarecatalogus_register.json:6777), versions (moduleVersion :7649), suites (suite :1135) and application-to-application connections (connection :3563) with relations; ModuleDetail and SuiteDetail show a Related panel. No manifest page has register+schema 'connection' or 'usage', so connections are not listed or created on their own page." } }, { @@ -2785,9 +3445,18 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "Organisation merge: src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail, calling /api/organisaties/{uuid}/merge/dry-run and /merge (src/store/modules/organisatie.js:486/524, lib/Controller/MergeController.php:106, admin-only body guard). Federation mirrors are reconciled per peer by lib/Service/Federation/FederationMerger.php.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisation /organisaties/:id, Merge organisation panel (admin only)", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "An admin can merge duplicate organisations with a dry run. Nothing deduplicates applications or reconciles records arriving from several sources.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "Organisation merge: src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail, calling /api/organisaties/{uuid}/merge/dry-run and /merge (src/store/modules/organisatie.js:486/524, lib/Controller/MergeController.php:106, admin-only body guard). Federation mirrors are reconciled per peer by lib/Service/Federation/FederationMerger.php." } }, { @@ -2800,11 +3469,20 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "No ticketing.", "evidence": { "glpi": "docs, intelligence competitor_features#48903 'ITIL helpdesk / ticketing' (2026-07-23): Full incident/request ticketing with the assets module.", "topdesk": "docs, intelligence competitor_features#48927 'Incident / ticket management' (2026-07-23): Core ITSM incident and request handling.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php." } }, { @@ -2817,11 +3495,20 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No change-request workflow for applications. The only approval flow is for contracts: src/components/contracts/ContractApprovalPanel.vue on ContractDetail via /api/contracts/{uuid}/approval (routes.php:35-37), delegated to decidiq.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "Contracts go through an approval, but changes to an application do not.", "evidence": { "glpi": "docs, intelligence competitor_features#3277 'Change Management' (2026-03-28): ITIL change management with approval workflows", "topdesk": "docs, intelligence competitor_features#48929 'Change management' (2026-07-23): Structured change workflows with action sequences.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No change-request workflow for applications. The only approval flow is for contracts: src/components/contracts/ContractApprovalPanel.vue on ContractDetail via /api/contracts/{uuid}/approval (routes.php:35-37), delegated to decidiq." } }, { @@ -2834,11 +3521,20 @@ "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "catalogContract.contractType enum includes 'SLA' (lib/Settings/softwarecatalogus_register.json:3344) as a label only; no service-level target, measurement or breach fields in any schema.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "A contract can be typed as SLA, but no service level targets are recorded or tracked.", "evidence": { "glpi": "docs, intelligence competitor_features#48904 'SLA management' (2026-07-23): SLA targets and escalation rules.", "topdesk": "docs, intelligence competitor_features#48930 'SLA management' (2026-07-23): Service-level target tracking and reporting.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "catalogContract.contractType enum includes 'SLA' (lib/Settings/softwarecatalogus_register.json:3344) as a label only; no service-level target, measurement or breach fields in any schema." } }, { @@ -2851,27 +3547,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls.", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "End users cannot request software.", "evidence": { "topdesk": "docs, intelligence competitor_features#48928 'Self-service portal' (2026-07-23): End-user portal for requests and knowledge, reduces direct support load.", - "stackiq": "not checked: the code reading for this row is under way" - } - }, - { - "id": "ops-plugins", - "area": "operations", - "name": "Extend the product with plugins installed from a marketplace.", - "origin": "competitor", - "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", - "glpi": "yes", - "topdesk": "yes", - "stackiq": "unknown", - "evidence": { - "glpi": "docs, intelligence competitor_features#48906 'Plugin ecosystem' (2026-07-23): Large plugin marketplace (FormCreator, GenericObject, etc.). | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145919 'C-configuration-48 An extension is found, installed, updated and removed from inside the product.': glpi: Marketplace (Setup, Plugins, front/marketplace.php, marketplace.download.php, front/plugin.php) Lane findings: D-glpi-45.", - "topdesk": "docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls." } }, { @@ -2884,10 +3572,19 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "yes", - "stackiq": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "No mobile app or mobile-specific surface in the repo; the app is the Nextcloud web UI (src/manifest.json).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "nextcloud", + "providerHow": "read-from-code", + "note": "There is no native mobile app.", "evidence": { "topdesk": "docs, intelligence competitor_features#48937 'Mobile app' (2026-07-23): Native mobile operator app.", - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "No mobile app or mobile-specific surface in the repo; the app is the Nextcloud web UI (src/manifest.json)." } }, { @@ -2900,11 +3597,1091 @@ "bluedolphin": "unknown", "glpi": "unknown", "topdesk": "unknown", - "stackiq": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674).", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings sections Cronjob configuration and Organization Synchronization", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "automatic-user-provisioning", + "featureConfidence": "medium", + "note": "The sync runs on a schedule and its last run time is shown, but only an admin can see and configure it, which is the rule for partial.", "evidence": { - "stackiq": "not checked: the code reading for this row is under way" + "stackiq": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674)." } } ], - "pending": [] + "pending": [ + { + "id": "land-usage-record", + "area": "landscape", + "name": "Record that your organisation uses a module, as a usage separate from the product itself.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "partial", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: /api/aangeboden-gebruik/*, /api/gebruik and OpenRegister objects API; read-only on Portfolio roadmap /portfolio-roadmap", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "high", + "note": "The usage schema models this separation properly, but no stackiq page creates or edits a usage: the ObjectModal accepts type 'usage' (src/modals/Modals.vue:38) yet nothing opens it. Usages are only read by the roadmap, compliance matrix and vulnerability views.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", + "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", + "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/" + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend create usage (gebruik) records through /api/aangeboden-gebruik or the OpenRegister objects API, and is that frontend part of what stackiq ships?" + }, + { + "id": "land-migrate-legacy", + "area": "landscape", + "name": "Bring over what was registered in the previous catalogue, so nobody types it again.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "There is no importer for the previous VNG Softwarecatalogus's registrations. The repair steps only rename stackiq's own earlier data, and the ArchiMate import brings in the GEMMA model, not organisations' entries.", + "evidence": { + "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets" + }, + "pendingQuestion": "Is the data from the previous VNG Softwarecatalogus meant to be brought over by a one-off migration outside this repo (for example an OpenRegister register import of an export file)?" + }, + { + "id": "conn-register-connection", + "area": "connections", + "name": "Register a connection between two applications, with its direction and the standard it uses.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "yes", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: OpenRegister objects API; no stackiq page", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "medium", + "note": "The connection model with direction and standard is complete, and the demo data ships six, but no stackiq page creates or edits one.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", + "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it" + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend register koppelingen through the OpenRegister objects API, and does it count as part of stackiq?" + }, + { + "id": "conn-usage-of-connection", + "area": "connections", + "name": "Record that your organisation actually runs a given connection, not only that it exists.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "medium", + "note": "The model records which connections a usage runs, but neither usages nor connections have a page.", + "evidence": { + "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller" + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend let an organisation record the connections it runs, through /api/koppelingen-gebruik or the objects API?" + }, + { + "id": "conn-shared-with-others", + "area": "connections", + "name": "See which connections you run together with other organisations.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: /api/aangeboden-gebruik/deelnemers", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "shared-usage-on-gemma-views", + "featureConfidence": "medium", + "note": "Shared usage (with the connections it carries) is answerable through the API, but no stackiq page shows it.", + "evidence": { + "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/" + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend show shared connections from /api/aangeboden-gebruik/deelnemers?" + }, + { + "id": "arch-refcomp-mapping", + "area": "architecture", + "name": "Place an application on the GEMMA reference components it fulfils.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Modules /modules (FacetedCatalogIndexView) filters by reference component (read only); no stackiq page sets the mapping: module form hides it (hideOnForm), usage has no page", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "high", + "note": "The mapping is stored and can be filtered on, but no stackiq screen writes it: the module field is hideOnForm and the usage schema has no index or edit page; writes come through ArchiMate import, the OpenRegister objects API or the external VNG frontend.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48835 'Reference component mapping (referentiecomponenten)' (2026-07-23): Maps each registered software product onto GEMMA reference components/domains so functionality is comparable across suppliers. | docs, intelligence competitor_features#27551 'Reference Component Linking' (2026-04-12): Link software to GEMMA reference components", + "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules" + }, + "pendingQuestion": "Does the Modules page's CnIndexPage create/edit dialog in nextcloud-vue 2.55.1 render module.referenceComponents (hideOnForm:true, items.$ref element in the AMEF register) as a working multiselect of reference components? nextcloud-vue's fieldsFromSchema (src/utils/schema.js:529) does not check hideOnForm." + }, + { + "id": "arch-gemma-views", + "area": "architecture", + "name": "Open a GEMMA architecture view with your own applications drawn inside it.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: GET /api/views (src/store/modules/view.js:89 defines a store but nothing imports useViewStore); the drawn view is only visible in Archi after 'Organization Export' on admin settings section ArchiMate Import/Export", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "medium", + "note": "No stackiq page renders a GEMMA view. The enriched view data is served for an external frontend, and the org export draws applications into view copies that open in Archi.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | Rated yes because landscape auto-plotted on the reference component map.", + "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export" + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend render /api/views/{id} with include_gebruik, and is that frontend in scope for stackiq's column?" + }, + { + "id": "arch-shared-overlay", + "area": "architecture", + "name": "On a GEMMA view, see the applications you share with partners, drawn apart from your own.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/ViewService.php:1187 getDeelnamesGebruikData + :924 tags shared usage with _type='deelnames' and _sourceOrganization; lib/Service/ArchiMateExportService.php:3005 org export gives every nested application the same green fillColor, deelnames only get their own folder (:3086)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: GET /api/views/{viewId}?include_deelnames_gebruik=true; org ArchiMate export from admin settings section ArchiMate Import/Export (Deelnames checkbox)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "shared-usage-on-gemma-views", + "featureConfidence": "high", + "note": "The API separates shared usage from own usage and names the source organisation, but nothing in stackiq draws it; in the ArchiMate export shared applications get the same style as own ones, so they are not drawn differently.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", + "stackiq": "lib/Service/ViewService.php:1187 getDeelnamesGebruikData + :924 tags shared usage with _type='deelnames' and _sourceOrganization; lib/Service/ArchiMateExportService.php:3005 org export gives every nested application the same green fillColor, deelnames only get their own folder (:3086)" + }, + "pendingQuestion": "Does the external VNG frontend draw deelnames nodes differently from own usage on a GEMMA view?" + }, + { + "id": "arch-gemma-api", + "area": "architecture", + "name": "Retrieve the GEMMA architecture itself through an API.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:185-187 GET /api/views, /api/views/docs, /api/views/{viewId} -> lib/Controller/ViewController.php:82,218 (@NoAdminRequired) -> lib/Service/ViewService.php:108,166 read views from the AMEF register; GEMMA elements are element objects in the AMEF register, readable through the OpenRegister objects API", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: GET /api/views and /api/views/{viewId} (authenticated), plus OpenRegister /api/objects on the AMEF register for elements", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "low", + "note": "A pure API row: the views endpoint is routed, authorised for logged-in users and returns the imported GEMMA views; elements come through OpenRegister's generic objects API.", + "evidence": { + "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/docs, /api/views/{viewId} -> lib/Controller/ViewController.php:82,218 (@NoAdminRequired) -> lib/Service/ViewService.php:108,166 read views from the AMEF register; GEMMA elements are element objects in the AMEF register, readable through the OpenRegister objects API" + }, + "pendingQuestion": "Is the view API reachable without a Nextcloud login (no #[PublicPage] on ViewController), and does the row require public access?" + }, + { + "id": "comp-declare-standard", + "area": "compliance", + "name": "Declare that an application supports a specific version of a standard.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json compliancy.standardVersion ($ref element, queryParams gemmaType=standaardversie) + compliancy.module + compliancy.standardGemma (string); src/manifest.json Komplianties /komplianties index on the voorzieningen register; ModuleDetail md-compliance object-list has allowCreate:false; module.standardVersions is hideOnForm", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Komplianties /komplianties (menu Reports & Compliance > Compliance), generic create form", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "standards-compliance", + "featureConfidence": "high", + "note": "A compliance record can be created on the Compliance index, but the standard-version relation points at element objects that live in the AMEF register while the page works on the voorzieningen register, so the version picker may not resolve; the free-text standardGemma field is the fallback. Not offered from the application page itself.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports.", + "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.standardVersion ($ref element, queryParams gemmaType=standaardversie) + compliancy.module + compliancy.standardGemma (string); src/manifest.json Komplianties /komplianties index on the voorzieningen register; ModuleDetail md-compliance object-list has allowCreate:false; module.standardVersions is hideOnForm" + }, + "pendingQuestion": "On /komplianties, does the create form's standardVersion select (items $ref element, which lives only in the AMEF register) list standard versions, or does it resolve against the voorzieningen register and come back empty/404 as the Standaarden page did before its register fix?" + }, + { + "id": "mkt-offer-accept", + "area": "market", + "name": "As a supplier, accept or decline a usage another organisation has claimed of your product.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/AanbodController.php:200 acceptAanbod and :303 denyAanbod, lib/Service/AanbodService.php:289 checks the active organisation is aanbieder or afnemer then re-owns the object; routes appinfo/routes.php PUT /api/aanbod/{uuid}/accept, DELETE /api/aanbod/{uuid}/deny; also /api/aangeboden-gebruik/{id}/set-self and /deny", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: /api/aanbod and /api/aangeboden-gebruik, no stackiq page calls them (grep of src finds no caller)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "high", + "note": "The accept/decline logic is complete and authorised, but nothing in src/ calls it, so only the external VNG frontend or a script can use it. There is also no stackiq page for usage (gebruik) records at all.", + "evidence": { + "stackiq": "lib/Controller/AanbodController.php:200 acceptAanbod and :303 denyAanbod, lib/Service/AanbodService.php:289 checks the active organisation is aanbieder or afnemer then re-owns the object; routes appinfo/routes.php PUT /api/aanbod/{uuid}/accept, DELETE /api/aanbod/{uuid}/deny; also /api/aangeboden-gebruik/{id}/set-self and /deny" + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend (not in this repo) call PUT /api/aanbod/{uuid}/accept and /api/aangeboden-gebruik/{id}/set-self, and is that frontend part of what we ship?" + }, + { + "id": "mkt-compare-peers", + "area": "market", + "name": "See which software comparable organisations use for the same reference component.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/ViewController.php (routes GET /api/views, /api/views/{viewId}) enriches GEMMA views with shared usage (deelnames); src/store/modules/view.js:89 calls it but no component imports that store", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: GET /api/views, the only caller is src/store/modules/view.js which no mounted component uses", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "shared-usage-on-gemma-views", + "featureConfidence": "high", + "note": "The shared-usage enrichment on GEMMA views exists server-side but no stackiq page renders it, so a user cannot see peers' software per reference component in this app.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value. | docs, intelligence competitor_features#27552 'Municipality Comparison' (2026-04-12): Compare application landscapes between municipalities", + "stackiq": "lib/Controller/ViewController.php (routes GET /api/views, /api/views/{viewId}) enriches GEMMA views with shared usage (deelnames); src/store/modules/view.js:89 calls it but no component imports that store" + }, + "pendingQuestion": "Does the external VNG frontend render /api/views with the deelnames enrichment, and does that count as a stackiq page?" + }, + { + "id": "mkt-who-uses-it", + "area": "market", + "name": "See which organisations use a given application.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register :2656 usage (consumer, module); usage read rule lets aanbod-beheerder read usages where provider = own organisation (:3137); ModuleDetail md-related widget src/manifest.json:491; GET /api/koppelingen-gebruik/{uuid} and /api/gebruik in lib/Controller/AangebodenGebruikController.php, lib/Controller/GebruikController.php", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id 'Vendor & services' related panel (supplier only, via RBAC); otherwise API only: /api/koppelingen-gebruik, /api/gebruik", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "medium", + "note": "There is no usage page and no 'used by' list on the application page. A supplier may see usages of its own product through the generic related panel, other roles see only their own usages; the per-product usage endpoints have no caller in src/.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value.", + "stackiq": "register :2656 usage (consumer, module); usage read rule lets aanbod-beheerder read usages where provider = own organisation (:3137); ModuleDetail md-related widget src/manifest.json:491; GET /api/koppelingen-gebruik/{uuid} and /api/gebruik in lib/Controller/AangebodenGebruikController.php, lib/Controller/GebruikController.php" + }, + "pendingQuestion": "Does the generic 'related' widget on ModuleDetail list usage objects that point at the module (inverse relation), and for which roles?" + }, + { + "id": "mkt-review-moderation", + "area": "market", + "name": "Hold a submitted review for moderation before others can read it.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/ReviewService.php:232 forces pending; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; src/views/settings/StackiqSettings.vue:98 ModerationQueue type=software-review via src/utils/adminApi.js; lib/Settings/register.d/catalog-ratings.json public read only matches status approved but every catalogue group reads all reviews and may create them", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "admin settings section 'Review moderation'; the Reviews /reviews index also lists reviews", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "reviews", + "featureConfidence": "high", + "note": "The ReviewsPanel path holds reviews as pending and an admin approves them in settings. But the generic Reviews index /reviews shows pending reviews to every catalogue group and its Add form writes software-review through OpenRegister directly, where status (enum incl. approved) is a visible form field, so moderation can be bypassed.", + "evidence": { + "stackiq": "lib/Service/ReviewService.php:232 forces pending; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; src/views/settings/StackiqSettings.vue:98 ModerationQueue type=software-review via src/utils/adminApi.js; lib/Settings/register.d/catalog-ratings.json public read only matches status approved but every catalogue group reads all reviews and may create them" + }, + "pendingQuestion": "Does the installed OpenRegister let a catalogue user create a software-review with status=approved through /reviews (the generic create), bypassing ReviewService?" + }, + { + "id": "mkt-hide-landscape-from-vendors", + "area": "market", + "name": "Keep your application landscape and connections hidden from suppliers.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register usage authorization (:3137) reads scoped to _organisation or consumer; aanbod-beheerder also reads usages where provider = own organisation; connection read (:3855) public when published and by provider; openspec/specs/vendor-visibility-rbac", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq (rules), executed by ConductionNL/openregister" + }, + "reachedOn": "no page: enforced by OpenRegister RBAC on every read", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "The register declares organisation-scoped reads, so a supplier sees only usages of its own products and published connections. This rests on the installed OpenRegister executing the declared match rules.", + "evidence": { + "stackiq": "register usage authorization (:3137) reads scoped to _organisation or consumer; aanbod-beheerder also reads usages where provider = own organisation; connection read (:3855) public when published and by provider; openspec/specs/vendor-visibility-rbac" + }, + "pendingQuestion": "Does the installed OpenRegister enforce the declared authorization.read match rules (e.g. {group: aanbod-beheerder, match: {provider: $organisation}}) on usage and connection reads?" + }, + { + "id": "mkt-free-public-service", + "area": "market", + "name": "Use the catalogue free of charge as a municipality or supplier.", + "origin": "competitor", + "vng-softwarecatalogus": "yes", + "sap-leanix": "no", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "LICENSE (EUPL-1.2) and appinfo/info.xml: the app is free open source; module/catalogService/organization carry public read rules for published entries; public intake POST /api/intake/register", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "no page: a property of the app and its licence", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The software is free and published entries are publicly readable, but the repo ships no hosted public catalogue; the public-facing frontend is the external VNG one.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", + "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", + "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", + "stackiq": "LICENSE (EUPL-1.2) and appinfo/info.xml: the app is free open source; module/catalogService/organization carry public read rules for published entries; public intake POST /api/intake/register" + }, + "pendingQuestion": "Is a hosted, free-of-charge stackiq instance offered to municipalities and suppliers (the competitor offer is a public service, not software)?" + }, + { + "id": "life-eol-warning", + "area": "lifecycle", + "name": "Get a warning before an application or version falls out of support.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/views/LifecycleRoadmapView.vue:73-86 EOL passed/approaching/withdrawn badges with EOL_WINDOW_DAYS=180 (:143); lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications eol-approaching (scheduled, dateEndSupport withinNext P180D, recipients software-catalog-admins + object-acl manage) is a declaration only; no notification code in lib (no INotificationManager use)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "LifecycleRoadmap /portfolio-roadmap badges; push warning only if OpenRegister executes the declared rule", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "lifecycle-and-end-of-support", + "featureConfidence": "high", + "note": "You see an 'approaching end of support' badge when you open the roadmap. A pushed warning rests only on a register declaration, and that rule addresses catalogue admins and the version's managers, not the organisations using the application.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", + "stackiq": "src/views/LifecycleRoadmapView.vue:73-86 EOL passed/approaching/withdrawn badges with EOL_WINDOW_DAYS=180 (:143); lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications eol-approaching (scheduled, dateEndSupport withinNext P180D, recipients software-catalog-admins + object-acl manage) is a declaration only; no notification code in lib (no INotificationManager use)" + }, + "pendingQuestion": "Does the installed OpenRegister dispatch the scheduled x-openregister-notifications rule 'eol-approaching' on moduleVersion, and to whom?" + }, + { + "id": "life-eol-feed", + "area": "lifecycle", + "name": "Fill in end-of-support dates automatically from a public end-of-life feed.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/BackgroundJob/EolSyncJob.php (registered appinfo/info.xml:101) + appinfo/routes.php:292-295 /api/eol-sync/* -> lib/Service/EolSyncService.php:145 run() reads eol_cycle objects via OpenRegister ObjectService (:328), stamps dateEndSupport on module versions via EolMatcherService; enabled defaults to false (lib/Service/SettingsService.php:7211); lib/Settings/connections.json eol-feed is a switch, off until enabled; the cycles are fetched by integriq's endoflife-date source", + "owner": "ConductionNL/integriq" + }, + "reachedOn": "admin settings section End-of-life feed sync (src/views/settings/sections/EolSyncSettings.vue); results visible on ModuleversieDetail and LifecycleRoadmap", + "provider": "integriq", + "providerHow": "read-from-code", + "feature": "lifecycle-and-end-of-support", + "featureConfidence": "high", + "note": "The matcher is complete, but it is off by default, only an admin can switch it on, each module needs an eolProductSlug, and the feed data only exists when integriq's endoflife.date source is provisioned.", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | Rated partial because obsolescence tracking; source of dates not named.", + "stackiq": "lib/BackgroundJob/EolSyncJob.php (registered appinfo/info.xml:101) + appinfo/routes.php:292-295 /api/eol-sync/* -> lib/Service/EolSyncService.php:145 run() reads eol_cycle objects via OpenRegister ObjectService (:328), stamps dateEndSupport on module versions via EolMatcherService; enabled defaults to false (lib/Service/SettingsService.php:7211); lib/Settings/connections.json eol-feed is a switch, off until enabled; the cycles are fetched by integriq's endoflife-date source" + }, + "pendingQuestion": "Is integriq's endoflife-date source (eol_product/eol_cycle register) provisioned on a default install, so that switching the sync on actually finds cycles?" + }, + { + "id": "life-planned-replacement", + "area": "lifecycle", + "name": "Record which application is planned to replace another.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json usage.plannedReplacement ($ref module) + plannedReplacementDate; read by src/views/LifecycleRoadmapView.vue:400; no usage page in src/manifest.json and navigationStore.setModal('usage') is never called (src/modals/Modals.vue:38 lists usage but nothing opens it)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "shown on LifecycleRoadmap /portfolio-roadmap; nothing in stackiq records it (OpenRegister objects API or the external VNG frontend only)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "portfolio-roadmap", + "featureConfidence": "high", + "note": "The planned replacement is stored per usage and displayed on the roadmap, but no stackiq page lets you record it.", + "evidence": { + "stackiq": "lib/Settings/softwarecatalogus_register.json usage.plannedReplacement ($ref module) + plannedReplacementDate; read by src/views/LifecycleRoadmapView.vue:400; no usage page in src/manifest.json and navigationStore.setModal('usage') is never called (src/modals/Modals.vue:38 lists usage but nothing opens it)" + }, + "pendingQuestion": "Is the external VNG Softwarecatalogus frontend (which writes usage objects) counted as part of stackiq for this row?" + }, + { + "id": "life-time-classification", + "area": "lifecycle", + "name": "Classify each application as tolerate, invest, migrate or eliminate.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "yes", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json usage.timeClassification enum Tolerate/Invest/Migrate/Eliminate + timeRationale + timeReviewDate; read by lib/Service/PortfolioReportService.php and rendered in src/views/organisaties/PortfolioReport.vue:112 quadrant chart; src/modals/object/ObjectModal.vue:178 has the enum select but is never opened for usage", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "PortfolioReport /portfolio-report (via Reports /reports card) shows the classification; no stackiq page sets it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The TIME classification is stored and reported per quadrant, but there is no page in stackiq where a user classifies an application.", + "evidence": { + "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "stackiq": "lib/Settings/softwarecatalogus_register.json usage.timeClassification enum Tolerate/Invest/Migrate/Eliminate + timeRationale + timeReviewDate; read by lib/Service/PortfolioReportService.php and rendered in src/views/organisaties/PortfolioReport.vue:112 quadrant chart; src/modals/object/ObjectModal.vue:178 has the enum select but is never opened for usage" + }, + "pendingQuestion": "Is the external VNG frontend or OpenRegister's generic object editor the intended place to set timeClassification, and does it count here?" + }, + { + "id": "ctr-register", + "area": "contracts", + "name": "Register a contract for a service with its number, type, term and cost.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Contracts /contracten (main menu), Add form", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "contract-administration", + "featureConfidence": "high", + "note": "All the fields are on the contract form, but a contract requires a usage (gebruik) record and no stackiq page can create one, so on a fresh install the form cannot be completed without data from elsewhere (demo data, API, external frontend).", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145509 'C-parties-and-contacts-1 A contract is a record with its own term and costs, linked to the party it binds and the cases raised under it': glpi: Contracts (Management, Contracts, front/contract_item.php, contractcost.php, ticket_contract.php) Lane findings: D-glpi-49.", + "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", + "stackiq": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)" + }, + "pendingQuestion": "Does the installed OpenRegister accept a catalogContract without the required usage (schema hardValidation false), and can the related-object picker create a usage inline?" + }, + { + "id": "ctr-expiry-alert", + "area": "contracts", + "name": "Get warned before a contract expires.", + "origin": "own-code", + "vng-softwarecatalogus": "no", + "sap-leanix": "partial", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "no", + "built": { + "state": "specified", + "evidence": "lib/Settings/softwarecatalogus_register.json:3255 x-openregister-notifications contract-expiry filters status equals 'Actief' but the status enum is Active/Expired/In negotiation (:3428), and the subject uses {{contractNummer}}/{{eindDatum}} while fields are contractNumber/endDate; Contracten quick filter 'Expiring / expired' filters status Expired only (src/manifest.json:527)", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq (declaration), dispatch by ConductionNL/openregister" + }, + "reachedOn": "nothing reaches it", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "notifications", + "featureConfidence": "high", + "note": "The only expiry warning is a declared OpenRegister notification whose filter value 'Actief' never matches the English status 'Active', so even if OpenRegister dispatches it, no contract qualifies. No page shows contracts that are about to expire.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS renewal dates.", + "stackiq": "lib/Settings/softwarecatalogus_register.json:3255 x-openregister-notifications contract-expiry filters status equals 'Actief' but the status enum is Active/Expired/In negotiation (:3428), and the subject uses {{contractNummer}}/{{eindDatum}} while fields are contractNumber/endDate; Contracten quick filter 'Expiring / expired' filters status Expired only (src/manifest.json:527)" + }, + "pendingQuestion": "Does the installed OpenRegister dispatch scheduled x-openregister-notifications, and does it compare the filter value case/locale-insensitively (it cannot map 'Actief' to 'Active')?" + }, + { + "id": "ctr-approval", + "area": "contracts", + "name": "Only let a contract become active after an approval decision is recorded.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/ContractApprovalService.php:254 submitForApproval dispatches OCA\\Decidiq\\Event\\DecisionRequestedEvent (fail-closed), :412 projectOutcome sets status Active only on approved; src/manifest.json:579 ContractApprovalPanel on ContractDetail; but register :3428 status enum incl. Active is an editable form field and approvalState (register.d/contracts-to-decidesk.json) is not readOnly; the declared x-openregister-lifecycle uses Dutch states 'In onderhandeling'/'Actief' that match no enum value", + "owner": "ConductionNL/decidiq", + "ownerNote": "reader wrote: ConductionNL/stackiq + ConductionNL/decidiq" + }, + "reachedOn": "ContractDetail /contracten/:id, Approval panel 'Submit for approval' (needs decidiq installed)", + "provider": "decidiq", + "providerHow": "read-from-code", + "feature": "contract-renewal-approval", + "featureConfidence": "high", + "note": "The approval path through decidiq works and only an approved outcome sets Active. Nothing stops a user from creating or editing a contract with status Active directly in the generic form, so 'only after an approval' is not enforced.", + "evidence": { + "stackiq": "lib/Service/ContractApprovalService.php:254 submitForApproval dispatches OCA\\Decidiq\\Event\\DecisionRequestedEvent (fail-closed), :412 projectOutcome sets status Active only on approved; src/manifest.json:579 ContractApprovalPanel on ContractDetail; but register :3428 status enum incl. Active is an editable form field and approvalState (register.d/contracts-to-decidesk.json) is not readOnly; the declared x-openregister-lifecycle uses Dutch states 'In onderhandeling'/'Actief' that match no enum value" + }, + "pendingQuestion": "Does the installed OpenRegister enforce x-openregister-lifecycle transitions on catalogContract.status, given its states are Dutch ('Actief') and the enum is English ('Active')?" + }, + { + "id": "sec-exposure", + "area": "security", + "name": "See which organisations and usages are exposed to a vulnerability.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/utils/vulnerabilityExposure.js:54 in-production join vulnerability.modules -> usage.module -> usage.consumer; count shown in the list (src/views/KwetsbaarhedenView.vue:111); per-organisation rows in VulnerabilityExposurePanel on KwetsbaarheidDetail tab (src/manifest.json:997), but a list row opens the edit modal, not the detail page (KwetsbaarhedenView.vue:417)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Vulnerabilities /kwetsbaarheden, Exposed usages column; KwetsbaarheidDetail /kwetsbaarheden/:id Exposure tab has no confirmed entry point", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "The list shows how many in-production usages are exposed to each vulnerability. The per-organisation exposure lives on a detail tab the list does not open, so a user sees the count but not reliably who is exposed.", + "evidence": { + "stackiq": "src/utils/vulnerabilityExposure.js:54 in-production join vulnerability.modules -> usage.module -> usage.consumer; count shown in the list (src/views/KwetsbaarhedenView.vue:111); per-organisation rows in VulnerabilityExposurePanel on KwetsbaarheidDetail tab (src/manifest.json:997), but a list row opens the edit modal, not the detail page (KwetsbaarhedenView.vue:417)" + }, + "pendingQuestion": "Is KwetsbaarheidDetail reachable from any page, for example by clicking a vulnerability in ModuleDetail's Related panel?" + }, + { + "id": "sec-vulnerability-alert", + "area": "security", + "name": "Get an alert when a vulnerability is reported for software you use.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "specified", + "evidence": "register.json:1622 x-openregister-notifications 'vulnerability-reported' on vulnerability, trigger created, channels nc-notification + email, recipients group software-catalog-admins and object-acl manage (a declaration only)", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "Declaration in the register; fires on create from Vulnerabilities /kwetsbaarheden", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "notifications", + "featureConfidence": "high", + "note": "The alert is declared, not code in stackiq, and it goes to catalogue admins and the record's managers, not to the organisations that use the affected software.", + "evidence": { + "stackiq": "register.json:1622 x-openregister-notifications 'vulnerability-reported' on vulnerability, trigger created, channels nc-notification + email, recipients group software-catalog-admins and object-acl manage (a declaration only)" + }, + "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications 'vulnerability-reported' rule on the vulnerability schema, and can recipients be the consumers of the affected modules?" + }, + { + "id": "org-self-registration", + "area": "organisations", + "name": "Let a new organisation sign itself up without an account.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/IntakeController.php:74 PublicPage + AnonRateLimit(5/h) on POST /api/intake/register; lib/Service/IntakeService.php:146 forces registrationStatus pending, publicationDate null; no caller in src/. Separately, organization authorization.create includes 'public' (register :2467)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: POST /api/intake/register, no stackiq page calls it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "self-registration-with-moderation", + "featureConfidence": "high", + "note": "The anonymous sign-up endpoint is complete and lands in moderation, but stackiq has no sign-up form. The schema also grants 'public' create on organization, so an anonymous generic OpenRegister create could skip the intake's pending stamp.", + "evidence": { + "stackiq": "lib/Controller/IntakeController.php:74 PublicPage + AnonRateLimit(5/h) on POST /api/intake/register; lib/Service/IntakeService.php:146 forces registrationStatus pending, publicationDate null; no caller in src/. Separately, organization authorization.create includes 'public' (register :2467)" + }, + "pendingQuestion": "Does the external VNG frontend post to /api/intake/register, and does OpenRegister's generic public create on organization let an anonymous caller set registrationStatus/status/publicationDate directly?" + }, + { + "id": "org-contact-to-account", + "area": "organisations", + "name": "Turn a contact person into a user account with the right role automatically.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Controller/ContactpersonenController.php:393 convertToUser -> lib/Service/Stackiq/ContactPersonHandler.php:292 createUserAccount reads objectData['email'] (:299); automatic path lib/EventListener/StackiqEventListener.php -> lib/Service/ContactpersoonService.php:128 also reads contactData['email']; contactPerson schema (:1788) declares no email (identity moved to Nextcloud Contacts via contactsUid); UI: src/components/ContactpersonenList.vue:97 'Convert to User' inside OrganisatieCard", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisations /organisaties card -> 'Bekijk contactpersonen' toggle -> Convert to User (org admins)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "automatic-user-provisioning", + "featureConfidence": "high", + "note": "Conversion and role-based group assignment exist, manual and automatic on create for active organisations. Both read an email field the contact schema no longer has, so a contact created through the current form (contactsUid only) fails with 'No email address found' unless it carries legacy data.", + "evidence": { + "stackiq": "lib/Controller/ContactpersonenController.php:393 convertToUser -> lib/Service/Stackiq/ContactPersonHandler.php:292 createUserAccount reads objectData['email'] (:299); automatic path lib/EventListener/StackiqEventListener.php -> lib/Service/ContactpersoonService.php:128 also reads contactData['email']; contactPerson schema (:1788) declares no email (identity moved to Nextcloud Contacts via contactsUid); UI: src/components/ContactpersonenList.vue:97 'Convert to User' inside OrganisatieCard" + }, + "pendingQuestion": "Does a contactPerson created via the current form reach createUserAccount with an email (e.g. resolved from Nextcloud Contacts by contactsUid somewhere I did not find), or does conversion fail for every post-migration contact?" + }, + { + "id": "org-cooperation", + "area": "organisations", + "name": "Register a cooperation of organisations and the landscape they share.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register organization.type 'Collaboration' + participants/deelnames (:2236); usage.participants (:2718); shared landscape endpoint GET /api/aangeboden-gebruik/deelnemers (lib/Controller/AangebodenGebruikController.php) has no caller in src/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Organisations /organisaties form (type Collaboration, participants); shared landscape API only", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "shared-usage-on-gemma-views", + "featureConfidence": "medium", + "note": "A cooperation can be registered with its participant organisations. The landscape it shares is only exposed through the deelnemers API and the unrendered view enrichment; no page shows it, and there is no usage page to record it.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", + "stackiq": "register organization.type 'Collaboration' + participants/deelnames (:2236); usage.participants (:2718); shared landscape endpoint GET /api/aangeboden-gebruik/deelnemers (lib/Controller/AangebodenGebruikController.php) has no caller in src/" + }, + "pendingQuestion": "Does the external VNG frontend show a cooperation's shared landscape from /api/aangeboden-gebruik/deelnemers?" + }, + { + "id": "org-data-segregation", + "area": "organisations", + "name": "Keep each organisation's records visible only to that organisation unless published.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "specified", + "evidence": "register authorization.read rules with {match: {_organisation: $organisation}} on catalogContract (:3474), contactPerson (:1788), usage (:3137), connection (:3855); public reads only for published entries; lib/Controller/ContactpersonenController.php:293 org guard on the custom endpoint", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/stackiq (rules), executed by ConductionNL/openregister" + }, + "reachedOn": "no page: enforced by OpenRegister RBAC/multitenancy on every list and detail page", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "Organisation-scoped reads are declared per schema and the custom endpoints add their own guards. Whether generic pages are actually segregated depends on OpenRegister executing those match rules.", + "evidence": { + "glpi": "docs, intelligence competitor_features#48910 'Multi-entity (tenant) segregation' (2026-07-23): Hierarchical entities for multi-org / multi-department isolation.", + "stackiq": "register authorization.read rules with {match: {_organisation: $organisation}} on catalogContract (:3474), contactPerson (:1788), usage (:3137), connection (:3855); public reads only for published entries; lib/Controller/ContactpersonenController.php:293 org guard on the custom endpoint" + }, + "pendingQuestion": "Does the installed OpenRegister evaluate authorization.read match rules with $organisation on the generic object list and detail endpoints the stackiq pages use?" + }, + { + "id": "org-hierarchy", + "area": "organisations", + "name": "Make the first user of an organisation its administrator and manager of later users.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Service/Stackiq/ContactPersonHandler.php:646 first contact of an organisation gets the organisation-admin groups; lib/Service/Stackiq/HierarchyHandler.php:79 ensureOrganizationBeheerder and :130 setupManagerRelationships make later users report to the primary beheerder", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "no page: runs when a contact is converted to a user (see org-contact-to-account)", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "automatic-user-provisioning", + "featureConfidence": "medium", + "note": "The first user of an organisation becomes its admin and later users get that admin as manager. It rides on the contact-to-account path, which reads an email field the current contact schema lacks, so it only fires for contacts that carry one.", + "evidence": { + "stackiq": "lib/Service/Stackiq/ContactPersonHandler.php:646 first contact of an organisation gets the organisation-admin groups; lib/Service/Stackiq/HierarchyHandler.php:79 ensureOrganizationBeheerder and :130 setupManagerRelationships make later users report to the primary beheerder" + }, + "pendingQuestion": "Same as org-contact-to-account: does conversion get an email for a post-migration contact?" + }, + { + "id": "share-public-browse", + "area": "sharing", + "name": "Let anyone browse the published catalogue without signing in.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public on publicationDate<=$now (and, separately, on registeredBy=Supplier); lib/Settings/softwarecatalogus_register.json:1559 catalogService same; suite read is plain 'public' (lib/Settings/softwarecatalogus_register.json:1270). No stackiq route is #[PublicPage] except intake/review aggregate/gebruik (lib/Controller/GebruikController.php:102 returns an empty envelope to anonymous callers). The app's pages are all behind Nextcloud login (appinfo/routes.php:313 SPA catch-all).", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "API only: anonymous reads go through OpenRegister's objects API; no stackiq page is reachable without signing in", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "open-data-publishing", + "featureConfidence": "medium", + "note": "Anonymous browsing rests on RBAC read rules declared in the register and executed by OpenRegister; stackiq ships no public page, and the browsing surface is the external VNG Softwarecatalogus frontend, which is not in this repo. Note the module rule also exposes every registeredBy=Supplier module regardless of publication date.", + "evidence": { + "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", + "stackiq": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public on publicationDate<=$now (and, separately, on registeredBy=Supplier); lib/Settings/softwarecatalogus_register.json:1559 catalogService same; suite read is plain 'public' (lib/Settings/softwarecatalogus_register.json:1270). No stackiq route is #[PublicPage] except intake/review aggregate/gebruik (lib/Controller/GebruikController.php:102 returns an empty envelope to anonymous callers). The app's pages are all behind Nextcloud login (appinfo/routes.php:313 SPA catch-all)." + }, + "pendingQuestion": "Does the installed OpenRegister honour the {group: public, match: {publicationDate: {$lte: $now}}} read rule on module/catalogService for an anonymous GET /apps/openregister/api/objects, and which public frontend (the external VNG Softwarecatalogus site) is the intended browse surface?" + }, + { + "id": "share-public-api", + "area": "sharing", + "name": "Give developers a secure public API over the supplier offering.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "no", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "Anonymous read of the supplier offering depends on declared rules: lib/Settings/softwarecatalogus_register.json:7307 module read includes public on publicationDate<=$now and on registeredBy=Supplier; lib/Settings/softwarecatalogus_register.json:1559 catalogService public on publicationDate. Stackiq's own offering endpoint lib/Controller/AanbodController.php (routes.php:202) is authenticated-only (@NoAdminRequired + in-body guard). Rate limit only on GebruikController (#[AnonRateLimit]).", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "API only: OpenRegister objects API for anonymous reads; no stackiq page", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "There is no dedicated developer-facing public API: public access to the offering is whatever OpenRegister executes from the declared read rules, and stackiq's own offering endpoint requires login.", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141847 '12.19 Public data API with certificates or API keys': the API is fully authenticated, never public: user tokens plus optional app tokens with IP allow-listing (`apirest.md:62-67`, `src/APIClient.php:42`) and OAuth2 with scopes (`src/Glpi/OAuth/`). No anonymous public datase | Rated no because API is always authenticated, source-read 2026-09-14.", + "stackiq": "Anonymous read of the supplier offering depends on declared rules: lib/Settings/softwarecatalogus_register.json:7307 module read includes public on publicationDate<=$now and on registeredBy=Supplier; lib/Settings/softwarecatalogus_register.json:1559 catalogService public on publicationDate. Stackiq's own offering endpoint lib/Controller/AanbodController.php (routes.php:202) is authenticated-only (@NoAdminRequired + in-body guard). Rate limit only on GebruikController (#[AnonRateLimit])." + }, + "pendingQuestion": "Does the installed OpenRegister execute the module/catalogService public read rules for anonymous API callers, and is any API key or rate limit applied to that public surface?" + }, + { + "id": "share-portal", + "area": "sharing", + "name": "Show catalogue content on a shared external portal next to other apps' content.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Portal/PortalContributionProvider.php:130 getContribution() declares read-only, organisation-scoped collections (catalogService, usage, catalogContract, compliancy) for the vendor-org and participant-org audiences. Portaliq discovers it by FQCN from the Stackiq in appinfo/info.xml (portaliq lib/Contribution/PortalProviderLocator.php:49/77). No info.xml dependency; inert without portaliq.", + "owner": "ConductionNL/portaliq" + }, + "reachedOn": "Portaliq external portal (not a stackiq page), only for signed-in portal subjects of a supplier or participant organisation", + "provider": "portaliq", + "providerHow": "read-from-code", + "note": "The contribution is declarative and read-only, and it covers only an organisation's own records for portal subjects. It shows nothing publicly, and the create/accept actions are deferred per its own docblock.", + "evidence": { + "stackiq": "lib/Portal/PortalContributionProvider.php:130 getContribution() declares read-only, organisation-scoped collections (catalogService, usage, catalogContract, compliancy) for the vendor-org and participant-org audiences. Portaliq discovers it by FQCN from the Stackiq in appinfo/info.xml (portaliq lib/Contribution/PortalProviderLocator.php:49/77). No info.xml dependency; inert without portaliq." + }, + "pendingQuestion": "Does the installed portaliq render stackiq's contribution (its PortalProviderLocator iterating installed apps), and is that portal live for any stackiq customer?" + }, + { + "id": "share-ai-assistant", + "area": "sharing", + "name": "Let an AI assistant query and update the catalogue through a tool interface.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "none", + "evidence": "No MCP, tool-provider, TaskProcessing or ContextChat code in stackiq lib/ or src/ (grep 'mcp|ToolProvider|assistant|TaskProcessing|ContextChat' in lib/ finds nothing). OpenRegister ships a generic MCP endpoint (openregister appinfo/routes.php:1969 /api/mcp/v1/discover and the JSON-RPC endpoint) over all registers.", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "nothing in stackiq reaches it; only OpenRegister's generic MCP endpoint", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "Stackiq has nothing of its own here. An AI client could only reach catalogue objects through OpenRegister's generic MCP server, if it covers the voorzieningen register.", + "evidence": { + "stackiq": "No MCP, tool-provider, TaskProcessing or ContextChat code in stackiq lib/ or src/ (grep 'mcp|ToolProvider|assistant|TaskProcessing|ContextChat' in lib/ finds nothing). OpenRegister ships a generic MCP endpoint (openregister appinfo/routes.php:1969 /api/mcp/v1/discover and the JSON-RPC endpoint) over all registers." + }, + "pendingQuestion": "Does OpenRegister's MCP server expose the voorzieningen register's objects (module, catalogService, organization) for read and write to an AI client with a stackiq user's rights?" + }, + { + "id": "share-webhooks", + "area": "sharing", + "name": "Notify another system automatically when a catalogue entry changes.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "none", + "evidence": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909).", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "Flows /flows (settings section of the app navigation); webhooks only in OpenRegister's own admin UI", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "Change notification to another system is possible only through OpenRegister machinery: its webhooks UI, or a flow authored on stackiq's Flows page. Stackiq itself sends nothing.", + "evidence": { + "stackiq": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909)." + }, + "pendingQuestion": "Can a flow created on stackiq's Flows page be triggered by object.updated on a catalogue schema and make an outbound HTTP call to an external system?" + }, + { + "id": "ins-audit-trail", + "area": "insight", + "name": "Look back at who changed what in the catalogue, and when.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object.", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "History sidebar tab on the detail pages, e.g. Organisation /organisaties/:id", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "audit-trail-view", + "featureConfidence": "high", + "note": "Per-record history is shown on 11 detail pages, backed by OpenRegister's audit trail. There is no catalogue-wide view of who changed what, and the overlay itself lists audit-trail-view as 'soon'.", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141820 '10.5 Audit or event log viewer with filters and export': two logs, both searchable and exportable through the search engine: `src/Log.php:48` field-level object history (Historical tab, `src/Ticket.php:887`) and `src/Glpi/Event.php:63` the system/event log at `/front/logs.php` | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141852 '13.9 Audit trail including reads and views': writes are covered thoroughly: `src/Log.php:48` field-level history on every object, `src/Glpi/Event.php:63` the system log including logins (`src/Auth.php:1149-1163`), `src/RuleMatchedLog.php` for rule decisions. Reads | Rated yes because field-level history, source-read 2026-09-14.", + "topdesk": "docs, intelligence competitor_features#26345 'Audit Trail' (2026-04-10): Complete audit trail of all service management actions", + "stackiq": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object." + }, + "pendingQuestion": "Is OpenRegister's audit trail enabled for the voorzieningen register on a default install, so the History tab shows entries?" + }, + { + "id": "ins-live-updates", + "area": "insight", + "name": "See a list update by itself when someone else changes an entry.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "partial", + "glpi": "unknown", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/composables/useLiveCollections.js:40 subscribes via the library's useObjectSubscription; used in src/views/KwetsbaarhedenView.vue:197, LicensePostureView.vue:209, LifecycleRoadmapView.vue:184, ComplianceMatrixView.vue:326, PortfolioReport.vue:323. The standard index pages (Contracts, Organisations and others) rely on whatever the library's CnIndexPage does.", + "owner": "ConductionNL/openregister", + "ownerNote": "reader wrote: ConductionNL/nextcloud-vue" + }, + "reachedOn": "Vulnerabilities /kwetsbaarheden, License posture /license-posture, Portfolio roadmap /portfolio-roadmap, Compliance matrix /compliance-matrix, Portfolio rationalization /portfolio-report", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "Five custom pages subscribe to collection events and refetch on a change. Whether the event ever arrives depends on OpenRegister and the push transport, which this repo cannot show.", + "evidence": { + "bluedolphin": "docs, intelligence competitor_features#48969 'Real-time collaboration' (2026-07-23): Multiple stakeholders collaborate on models. | Rated partial because real-time collaboration on models.", + "stackiq": "src/composables/useLiveCollections.js:40 subscribes via the library's useObjectSubscription; used in src/views/KwetsbaarhedenView.vue:197, LicensePostureView.vue:209, LifecycleRoadmapView.vue:184, ComplianceMatrixView.vue:326, PortfolioReport.vue:323. The standard index pages (Contracts, Organisations and others) rely on whatever the library's CnIndexPage does." + }, + "pendingQuestion": "Does the installed OpenRegister publish or-collection-{register}-{schema} events over a transport (notify_push or SSE) that the nc-vue liveUpdatesPlugin receives, so these pages update without a reload?" + }, + { + "id": "ins-notifications", + "area": "insight", + "name": "Receive in-app notifications about changes that concern you.", + "origin": "own-code", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "specified", + "evidence": "Only declarations: x-openregister-notifications on vulnerability (lib/Settings/softwarecatalogus_register.json:1622), usage (:2662), catalogContract (:3253), software-review (:3962), module (:6781), moduleVersion (:7652). Stackiq has no INotifier or notification code of its own (grep in lib/). The contract-expiry rule filters status equals 'Actief' (lib/Settings/softwarecatalogus_register.json:3255) while the enum is Active/Expired/In negotiation, so it can never match.", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "Nextcloud notifications bell, if OpenRegister dispatches the declared rules; no stackiq page", + "provider": "openregister", + "providerHow": "read-from-code", + "feature": "notifications", + "featureConfidence": "high", + "note": "Every notification rests on a declaration OpenRegister must execute. At least one rule (contract expiry) filters on a stale Dutch status value and would never fire, and its subject template uses fields (contractNummer, eindDatum) the schema no longer has.", + "evidence": { + "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141783 '6.8 In-app notifications (bell)': `MODE_AJAX` is a wired delivery mode (`src/Notification_NotificationTemplate.php:55-59`, `getModes()` at `:381-398`, implementation `src/NotificationAjax.php`), rendering as a browser toast rather than a persistent inbox | Rated partial because toast delivery, not an inbox, source-read 2026-09-14.", + "stackiq": "Only declarations: x-openregister-notifications on vulnerability (lib/Settings/softwarecatalogus_register.json:1622), usage (:2662), catalogContract (:3253), software-review (:3962), module (:6781), moduleVersion (:7652). Stackiq has no INotifier or notification code of its own (grep in lib/). The contract-expiry rule filters status equals 'Actief' (lib/Settings/softwarecatalogus_register.json:3255) while the enum is Active/Expired/In negotiation, so it can never match." + }, + "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications rules on vulnerability, software-review, moduleVersion and the scheduled rules on catalogContract/usage/module, as Nextcloud notifications to the listed recipients?" + }, + { + "id": "ops-plugins", + "area": "operations", + "name": "Extend the product with plugins installed from a marketplace.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "yes", + "topdesk": "yes", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items.", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "Store /store (footer menu)", + "provider": "openregister", + "providerHow": "read-from-code", + "note": "The store installs configuration sets and flows, not code plugins, and it depends on a registry being configured.", + "evidence": { + "glpi": "docs, intelligence competitor_features#48906 'Plugin ecosystem' (2026-07-23): Large plugin marketplace (FormCreator, GenericObject, etc.). | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145919 'C-configuration-48 An extension is found, installed, updated and removed from inside the product.': glpi: Marketplace (Setup, Plugins, front/marketplace.php, marketplace.download.php, front/plugin.php) Lane findings: D-glpi-45.", + "topdesk": "docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", + "stackiq": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items." + }, + "pendingQuestion": "Is a store registry configured on a default install, and are any stackiq configuration sets published to it?" + } + ] }