From 511d78e96dfa9d7a7ce8932f1b315c07a88b0817 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 22:57:36 +0200 Subject: [PATCH 01/12] chore(parity): fold r-glpi packs 1-2 (GLPI source read at 11.0.9) --- openspec/parity/capabilities.json | 55 ++++++++++++++++++------------- 1 file changed, 32 insertions(+), 23 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index a34da246..52669b51 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -163,7 +163,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "yes", "bluedolphin": "yes", - "glpi": "partial", + "glpi": "yes", "topdesk": "partial", "stackiq": "partial", "built": { @@ -181,7 +181,7 @@ "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | docs, intelligence competitor_features#27422 'Fact Sheets & Data Model' (2026-04-12): Flexible data model for applications, processes, IT components", "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository. | docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", - "glpi": "docs, intelligence competitor_features#48900 'Software inventory & catalog' (2026-07-23): Detects installed software and normalises into a software catalog. | docs, intelligence competitor_features#3267 'Software Catalog' (2026-03-28): Manage software licenses and installations | Rated partial because software is an inventoried asset, not a described application.", + "glpi": "source read at 11.0.9: src/Appliance.php:46 class Appliance is GLPI's application itemtype; install/mysql/glpi-empty.sql:8935 glpi_appliances carries name, comment (description), manufacturers_id and states_id (status); src/Appliance.php:350 search option Status; supplier through the Management tab Infocom (install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id) and Contract_Item (src/Appliance.php:99); menu src/Html.php:1300 lists Appliance under Management, served by src/Glpi/Kernel/Listener/RequestListener/LegacyItemtypeRouteListener.php:100. Reached on: Management > Appliances (front/appliance.php).", "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure | Rated partial because software is a CMDB object among assets.", "stackiq": "src/manifest.json:592 Modules page (FacetedCatalogIndexView, schema module) with the library CnIndexPage create form at src/views/FacetedCatalogIndexView.vue:108; lib/Settings/softwarecatalogus_register.json:6777 module schema has name, shortDescription/longDescription and provider (Supplier) but NO status property; status lives on usage (register.json:2654, enum Acquisition..In production) which has no page" } @@ -194,7 +194,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -210,7 +210,8 @@ "note": "Stackiq's 'module' is the whole application, so there is no breakdown of one application into modules. The nearest thing is a suite (product) listing its applications, which answers 'which module belongs to which product' but not the decomposition.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated partial because fact sheets separate Application from IT Component.", - "stackiq": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')" + "stackiq": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')", + "glpi": "source read at 11.0.9: src/Appliance_Item.php:45 links an Appliance to member items; src/autoload/CFG_GLPI.php:562 appliance_types includes Software, Appliance, Database and DatabaseInstance, so an application can be split into software and sub-appliances on its Items tab (src/Appliance.php:98). There is no module entity that belongs to a supplier product: grep -i 'module' src/Software.php src/Appliance.php returns no module concept. Reached on: Management > Appliances > Items tab." } }, { @@ -236,7 +237,7 @@ "featureConfidence": "medium", "note": "A version is created on the Module versions index with its module and date in use, and opens on its own detail page.", "evidence": { - "glpi": "docs, intelligence competitor_features#48900 'Software inventory & catalog' (2026-07-23): Detects installed software and normalises into a software catalog. | Rated partial because installed versions come from inventory.", + "glpi": "source read at 11.0.9: src/SoftwareVersion.php:42 SoftwareVersion child of Software, table install/mysql/glpi-empty.sql:6900 glpi_softwareversions with name, states_id, operatingsystems_id but no release or in-use date; the only date is per installation, install/mysql/glpi-empty.sql:1074 glpi_items_softwareversions.date_install. Reached on: Assets > Software > Versions tab (front/softwareversion.form.php).", "stackiq": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn" } }, @@ -248,7 +249,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -263,7 +264,8 @@ "featureConfidence": "medium", "note": "A three-step wizard bundles existing applications into one suite. Caveat: a row click on the Suites list only toggles selection (the library returns before emitting row-click when selectable, SuitesIndexView.vue:35), so SuiteDetail is not opened from the list, and its data widget includes stale field names (src/manifest.json:683 beschrijvingKort, contactpersoon).", "evidence": { - "stackiq": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)" + "stackiq": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)", + "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:562 appliance_types contains Appliance and Software, so an Appliance can bundle existing appliances and software through src/Appliance_Item.php:45 (table install/mysql/glpi-empty.sql:8979 glpi_appliances_items). There is no notion of offering the bundle as a product to others. Reached on: Management > Appliances > Items tab." } }, { @@ -274,7 +276,7 @@ "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -290,7 +292,8 @@ "note": "A supplier's service over one or more applications is registered on the Services page. There is no 'hosting' service type (technical management is the nearest), and services have no detail page, so a row cannot be opened.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | Rated partial because offering registration covers products; services not named in the reading.", - "stackiq": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)" + "stackiq": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)", + "glpi": "source read at 11.0.9: no supplier service itemtype; services are held as contracts, src/ContractType.php:37 admin dropdown of contract types (for example hosting or support), install/mysql/glpi-empty.sql:1550 glpi_contracts_suppliers ties the contract to a Supplier and install/mysql/glpi-empty.sql:1536 glpi_contracts_items ties it to the Appliance or Software it covers. Reached on: Management > Contracts (front/contract.php), Suppliers tab." } }, { @@ -301,7 +304,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -314,7 +317,8 @@ "providerHow": "read-from-code", "note": "A sector schema exists, but no application, service or organisation can be tagged with a sector and no page lists sectors.", "evidence": { - "stackiq": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395" + "stackiq": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395", + "glpi": "source read at 11.0.9: no government sector concept, grep -i 'sector' over src/*.php and locales/glpi.pot hits only menu sectorization (src/Html.php:1019); the nearest holder is the single-valued Appliance type dropdown install/mysql/glpi-empty.sql:8941 appliancetypes_id, or an admin custom dropdown (install/mysql/glpi-empty.sql:10113 glpi_dropdowns_dropdowndefinitions) used as a field of a custom asset. Multi-valued tagging needs the separate tag plugin (github.com/pluginsGLPI/tag, not read). Reached on: Management > Appliances, Appliance type field." } }, { @@ -325,7 +329,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -341,7 +345,8 @@ "note": "One contact person per application can be set, but there is no separate business owner and technical owner. ModuleDetail's data widget includes 'contactpersoon', a key the schema no longer has, so the contact may not show there.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | Rated partial because surveys go to application owners, so ownership is modelled.", - "stackiq": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')" + "stackiq": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')", + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:8935 glpi_appliances holds users_id and users_id_tech; src/Appliance.php:186 search option User and src/Appliance.php:195 Group (business side), src/Appliance.php:240 'Technician in charge' and the 'Group in charge' option a few lines below (technical side). Reached on: Management > Appliances, form fields User, Group, Technician in charge, Group in charge." } }, { @@ -352,7 +357,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "yes", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -367,7 +372,7 @@ "note": "Stackiq offers no way to add fields. Editing the schema in OpenRegister's own admin UI is possible there, but that is an OpenRegister feature, not a stackiq page.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because flexible fact sheet data model.", - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141835 '11.17 Custom object type management': GLPI 11 ships admin-defined itemtypes with custom fields and capabilities (`src/Glpi/CustomObject/AbstractDefinition.php`, `src/Glpi/Asset/AssetDefinition.php`, `src/Glpi/Asset/CustomFieldDefinition.php`), but the machin | Rated yes because custom asset definitions and custom fields, source-read 2026-09-14.", + "glpi": "source read at 11.0.9: native custom fields exist only for admin defined custom asset types, src/Glpi/Asset/CustomFieldDefinition.php:52 child of AssetDefinition (install/mysql/glpi-empty.sql:10159 glpi_assets_customfielddefinitions keyed on assets_assetdefinitions_id), set up under Setup > Asset definitions (src/Html.php:1330). The core Appliance and Software types take no custom fields in core; that needs the fields plugin, read at pluginsGLPI/fields tag 1.24.5, inc/container.class.php:91 containers with a list of itemtypes. Reached on: Setup > Asset definitions > Custom fields; or plugin Fields.", "stackiq": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json" } }, @@ -379,7 +384,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -394,7 +399,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#27428 'EAM Automation' (2026-04-12): Automated data collection from ServiceNow, Jira, cloud providers | Rated partial because automated collection from ServiceNow, Jira and cloud.", "bluedolphin": "docs, intelligence competitor_features#48971 'Data import (Excel)' (2026-07-23): Bulk import of application/portfolio data.", - "stackiq": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)" + "stackiq": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)", + "glpi": "source read at 11.0.9: core has CSV export only (src/Glpi/Csv/ holds CsvResponse and export classes, no importer) and no spreadsheet import of assets or appliances. Bulk import is the separate datainjection plugin, read at pluginsGLPI/datainjection tag 2.15.11: inc/backendcsv.class.php CSV backend and inc/applianceinjection.class.php:33 PluginDatainjectionApplianceInjection extends Appliance; setup.php:36 requires GLPI 11.0.5 or later. Reached on: plugin Data injection (Tools > Data injection)." } }, { @@ -405,7 +411,7 @@ "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -422,7 +428,8 @@ "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because fact sheet is the per-application page.", - "stackiq": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)" + "stackiq": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)", + "glpi": "source read at 11.0.9: src/Appliance.php:98 onwards defineTabs puts Items, Contracts, Documents, Management (Infocom), Certificates, Domains, Knowledge base, Tickets, Problems, Changes and Impact on the one appliance page; versions sit on the separate Software page (src/SoftwareVersion.php:42), and no compliance tab exists (grep -i 'complian' src/Appliance.php returns nothing). Reached on: Management > Appliances > appliance form tabs." } }, { @@ -433,7 +440,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -448,7 +455,8 @@ "featureConfidence": "low", "note": "Many entries can be selected and deleted together through the library index page. The mass publish and mass lock dialogs exist but hang off a view modal no page opens, and the publish endpoint (lib/Controller/PublicationController.php, PUT /api/publication/...) has no frontend caller.", "evidence": { - "stackiq": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets" + "stackiq": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets", + "glpi": "source read at 11.0.9: every search list offers massive actions, src/MassiveAction.php:666 Update (any field, for example status), src/MassiveAction.php:698 Put in trashbin, src/MassiveAction.php:652 Delete permanently, src/MassiveAction.php:656 Restore. There is no publish state; locking applies to inventory fields only. Reached on: any list, for example Management > Appliances, Actions button." } }, { @@ -459,7 +467,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -472,7 +480,8 @@ "providerHow": "read-from-code", "note": "Only organisations can be merged, with a dry run first, and only by a Nextcloud admin. Applications, services and other entries have no merge.", "evidence": { - "stackiq": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets" + "stackiq": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets", + "glpi": "source read at 11.0.9: src/Software.php:109 'Merging' tab on a recursive software, src/Software.php:926 showMergeCandidates lists same named software, src/Software.php:997 massive action Merge, src/Software.php:1011 private function merge moves versions and licences into the kept entry; dropdowns get Replace, src/CommonDropdown.php:680. Reached on: Assets > Software > Merging tab." } }, { From 913f72f8b01111c1b2863e9d8600461883ba388a Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:00:20 +0200 Subject: [PATCH 02/12] chore(parity): fold r-glpi packs 3-7 and errata --- openspec/parity/capabilities.json | 141 ++++++++++++++++++------------ 1 file changed, 84 insertions(+), 57 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index 52669b51..3273482a 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -492,7 +492,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -507,7 +507,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | docs, intelligence competitor_features#27423 'Survey-Based Data Collection' (2026-04-12): Crowdsource architecture data from application owners", "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders.", - "stackiq": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)" + "stackiq": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)", + "glpi": "source read at 11.0.9: the native form builder (src/Glpi/Form/Form.php:92) only has ITIL destinations, src/Glpi/Form/Destination/ holds FormDestinationTicket, FormDestinationChange and FormDestinationProblem, so a form answer opens a ticket but never confirms or updates an appliance record; the only 'survey' in core is ticket satisfaction (src/Central.php:220). No owner review campaign exists." } }, { @@ -518,7 +519,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -531,7 +532,8 @@ "providerHow": "read-from-code", "note": "No page scores how complete or current an entry is.", "evidence": { - "stackiq": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)" + "stackiq": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)", + "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing; no score of how filled in an item is exists in core." } }, { @@ -542,7 +544,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -555,7 +557,8 @@ "providerHow": "read-from-code", "note": "An admin picks the demo dataset in the setup wizard and it is imported through OpenRegister. Admin-only, which suits an installation task.", "evidence": { - "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp" + "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp", + "glpi": "source read at 11.0.9: grep -ril 'demo data\\|sample data' over src/ templates/ locales/glpi.pot returns nothing and src/Glpi/Console/ has no demo loader; example data exists only as test fixtures under tests/, not shipped as a feature." } }, { @@ -566,7 +569,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -579,7 +582,8 @@ "providerHow": "read-from-code", "note": "Only suites get a step-by-step wizard. Applications and services are added through a plain form, and connections have no page at all.", "evidence": { - "stackiq": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing" + "stackiq": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing", + "glpi": "source read at 11.0.9: grep -ril 'wizard' over src/ templates/ locales/glpi.pot returns nothing for item creation; appliances are added through the plain form only (install/mysql/glpi-empty.sql:8935 glpi_appliances has no is_template column)." } }, { @@ -590,7 +594,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -603,7 +607,8 @@ "providerHow": "read-from-code", "note": "A module version's page lists the third-party components imported from its SBOM.", "evidence": { - "stackiq": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema" + "stackiq": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema", + "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; software versions carry no component list (install/mysql/glpi-empty.sql:6900 glpi_softwareversions)." } }, { @@ -614,7 +619,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -630,7 +635,8 @@ "note": "The application form records on-premises, IaaS, PaaS or SaaS plus hosting location and jurisdiction. There is no field naming the hosting party itself.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | Rated partial because SaaS is tracked as a class of application.", - "stackiq": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)" + "stackiq": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)", + "glpi": "source read at 11.0.9: no hosting model field; the closest holders are the admin editable Environment dropdown on an appliance, src/Appliance.php:277 ApplianceEnvironment search option (install/mysql/glpi-empty.sql:8945 applianceenvironments_id), plus locations_id and the Appliance type dropdown. grep -i 'saas' over src/ finds nothing; 'On-premise' in locales/glpi.pot:12997 is only an icon label. Reached on: Management > Appliances, Environment field." } }, { @@ -641,7 +647,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -657,7 +663,8 @@ "note": "The field for a national provision exists on the connection schema, but with no connection page nobody can fill it in stackiq.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48841 'National provisions (landelijke voorzieningen) linking' (2026-07-23): Records links between applications and national government provisions.", - "stackiq": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection" + "stackiq": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection", + "glpi": "source read at 11.0.9: no national provision concept (grep -ril 'basisregistratie' src/ locales/glpi.pot returns nothing); a provision can be held as another Appliance and linked through an impact relation, install/mysql/glpi-empty.sql:1247 glpi_impactrelations (source item, impacted item, name), with Appliance enabled for impact at src/autoload/CFG_GLPI.php:649. Reached on: Appliance > Impact analysis tab, Add relation." } }, { @@ -668,7 +675,7 @@ "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -684,7 +691,8 @@ "note": "There is no list of connections in the catalogue. The Integrations page lists outside integrations, a different thing.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", - "stackiq": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)" + "stackiq": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)", + "glpi": "source read at 11.0.9: src/ImpactRelation.php:39 ImpactRelation has only prepareInputForAdd and getIDFromInput (src/ImpactRelation.php:47, :107), no search options and no list page; relations are only seen per item in the Impact analysis tab (src/Impact.php:91)." } }, { @@ -695,7 +703,7 @@ "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -711,7 +719,8 @@ "note": "Connections that reference an application should appear among the untyped related objects on its page, but there is no connections section and nothing to open. The dedicated per-application endpoint is API only.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", - "stackiq": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/" + "stackiq": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/", + "glpi": "source read at 11.0.9: src/Impact.php:91 getTabNameForItem adds the 'Impact analysis' tab (src/Impact.php:80) to every impact enabled itemtype, Appliance and Software included (src/autoload/CFG_GLPI.php:649 and :663), with a list view src/Impact.php:270 displayListView of every related item in both directions. Reached on: Management > Appliances > Impact analysis tab." } }, { @@ -739,7 +748,7 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model. | docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", "bluedolphin": "docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models. | docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145369 'C-case-core-38 The graph of what a case is linked to is drawn, and exported.': glpi: Impact graph (Tools, front/impactitem.php, impactcsv.php, src/Impact.php) Lane findings: D-glpi-40. | Rated yes because impact graph, source-read 2026-09-14.", + "glpi": "source read at 11.0.9: src/Impact.php:252 displayGraphView and src/Impact.php:1559 makeDataForCytoscape draw the relation network, with editing tools add asset, add relation, add group at src/Impact.php:1160. Reached on: Appliance > Impact analysis tab, graph view.", "stackiq": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)" } }, @@ -765,7 +774,7 @@ "note": "The only way to see what depends on an application is the generic list of objects that reference it, which OpenRegister's relation index fills. There is no impact view or retirement check.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", - "glpi": "docs, intelligence competitor_features#48902 'CMDB & configuration relations' (2026-07-23): CI relationships and impact analysis.", + "glpi": "source read at 11.0.9: src/Impact.php:49 class Impact 'Impact analysis', src/Impact.php:713 bfs walks the graph by direction and src/Impact.php:612 buildListData lists what is impacted, with ongoing tickets, problems and changes on impacted items (src/Impact.php:313). Reached on: Tools > Impact analysis (src/Html.php:1309) and the item's Impact analysis tab.", "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because relations between assets.", "stackiq": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/" } @@ -778,7 +787,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -791,7 +800,8 @@ "providerHow": "read-from-code", "note": "The type field exists but there is no connection list to filter.", "evidence": { - "stackiq": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter" + "stackiq": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter", + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations has only a free name besides the two endpoints, no connection type (API, file, message), so there is nothing to filter on; the graph settings (src/Impact.php:1167 impact_settings) cover depth and direction." } }, { @@ -802,7 +812,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -816,7 +826,8 @@ "note": "Stackiq has no record for an API an application exposes.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27425 'API Management' (2026-04-12): Catalog and manage APIs across the application landscape", - "stackiq": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label" + "stackiq": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label", + "glpi": "source read at 11.0.9: no API entity in core, grep -ril 'openapi' src/*.php finds no itemtype for exposed APIs; an admin can define an 'API' custom asset type (src/Html.php:1330 Setup > Asset definitions, src/Glpi/Asset/AssetDefinition.php) and attach it to the application as an Appliance item (src/Appliance_Item.php:45) or impact relation (install/mysql/glpi-empty.sql:1247). Reached on: Setup > Asset definitions, then Appliance > Items tab." } }, { @@ -842,7 +853,7 @@ "featureConfidence": "low", "note": "The organisation ArchiMate export carries modules and usages but not connections, so an application's link graph cannot be exported.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145369 'C-case-core-38 The graph of what a case is linked to is drawn, and exported.': glpi: Impact graph (Tools, front/impactitem.php, impactcsv.php, src/Impact.php) Lane findings: D-glpi-40. | Rated yes because impactcsv export, source-read 2026-09-14.", + "glpi": "source read at 11.0.9: front/impactcsv.php streams Glpi\\Csv\\ImpactCsvExport for an item, linked from the impact list view at src/Impact.php:393; the graph Download button src/Impact.php:1165 calls js/impact.js:2528 download, which writes PNG (js/impact.js:2539) or JPEG (js/impact.js:2546). Reached on: Appliance > Impact analysis tab, Download and CSV export.", "stackiq": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*" } }, @@ -854,7 +865,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -867,7 +878,8 @@ "providerHow": "read-from-code", "note": "With integriq installed, an admin sees stackiq's three integrations and their checked status on one page, and Add integration opens integriq. Without integriq the page is hidden, and the checking is integriq's.", "evidence": { - "stackiq": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq" + "stackiq": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq", + "glpi": "source read at 11.0.9: outside integrations are set up on separate Setup pages, not one overview: src/Html.php:1331 Webhook, src/Html.php:1333 OAuthClient and MailCollector, Auth (LDAP, SSO) on src/Html.php:1332; src/Webhook.php:64 Webhook and src/OAuthClient.php:45 OAuthClient each have their own list. Reached on: Setup > Webhooks, Setup > OAuth clients, Setup > Authentication." } }, { @@ -878,7 +890,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -894,7 +906,8 @@ "note": "Works end to end but only a Nextcloud admin can import: the endpoint rejects non-admins and the upload control lives only on the admin settings page.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27459 'ArchiMate & BPMN Support' (2026-04-12): Full ArchiMate and BPMN modeling in one platform | Rated yes because full ArchiMate support; import format not named in the reading.", - "stackiq": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile" + "stackiq": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile", + "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma\\|togaf' over src/ templates/ locales/glpi.pot returns nothing; no model import exists." } }, { @@ -905,7 +918,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "partial", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -922,7 +935,8 @@ "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", - "stackiq": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button" + "stackiq": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button", + "glpi": "source read at 11.0.9: grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing; exports are CSV, PDF and spreadsheet search output (src/Glpi/Csv/) only." } }, { @@ -933,7 +947,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -949,7 +963,8 @@ "note": "Complete logic, but reachable only on the admin settings page; an ordinary organisation user cannot export its own landscape from a stackiq page.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape | docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools | Rated yes because map and export the municipality's landscape.", - "stackiq": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes" + "stackiq": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes", + "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma' over src/ templates/ locales/glpi.pot returns nothing; no GEMMA plotting or per entity model export." } }, { @@ -960,7 +975,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -975,7 +990,8 @@ "featureConfidence": "medium", "note": "There is an endpoint, but its comparison is broken (a missing key against a placeholder string) and no page calls it. The compare_archimate.py/.php scripts in the repo root are developer tools, not a user capability.", "evidence": { - "stackiq": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register" + "stackiq": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register", + "glpi": "source read at 11.0.9: there is no model import or export to round trip, grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing." } }, { @@ -986,7 +1002,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1001,7 +1017,8 @@ "featureConfidence": "medium", "note": "The import runs as one blocking request with a spinner. The cancel endpoint calls a missing method and import progress is never recorded, so neither following nor cancelling works.", "evidence": { - "stackiq": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button" + "stackiq": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button", + "glpi": "source read at 11.0.9: no model import exists (grep -ril 'archimate' src/ returns nothing), so there is no import to follow; the generic progress endpoint src/Glpi/Controller/ProgressController.php serves other long operations." } }, { @@ -1012,7 +1029,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1027,7 +1044,8 @@ "featureConfidence": "low", "note": "You can open a standard's page and read its definition, but reference components and other GEMMA terms have no page and there is no inline definition where they appear.", "evidence": { - "stackiq": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only" + "stackiq": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only", + "glpi": "source read at 11.0.9: grep -ril 'gemma\\|glossary' over src/ templates/ locales/glpi.pot returns nothing; no reference term definitions ship in core." } }, { @@ -1038,7 +1056,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1055,7 +1073,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | docs, intelligence competitor_features#27420 'Business Capability Mapping' (2026-04-12): Map applications to business capabilities and processes", "bluedolphin": "docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", - "stackiq": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies" + "stackiq": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies", + "glpi": "source read at 11.0.9: grep -rli 'business capabilit\\|business process' over src/ and locales/glpi.pot returns nothing; 'Capacity' in src/Glpi/Asset/Capacity.php is a feature toggle for custom assets, not a business capability." } }, { @@ -1066,7 +1085,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1081,7 +1100,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model.", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models.", - "stackiq": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components" + "stackiq": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components", + "glpi": "source read at 11.0.9: the impact graph is an editable diagram, src/Impact.php:1160 add asset, add relation and add group tools, groups stored in install/mysql/glpi-empty.sql:1264 glpi_impactcompounds and node positions in install/mysql/glpi-empty.sql:1276 glpi_impactitems; it draws dependency graphs only, with no architecture notation or views. Reached on: Appliance > Impact analysis tab, graph edit mode." } }, { @@ -1092,7 +1112,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1106,7 +1126,8 @@ "note": "Business processes are not modelled; the only link applications have is to GEMMA reference components.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27464 'Process Mapping' (2026-04-12): Map processes, applications, data, and technology", - "stackiq": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json" + "stackiq": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json", + "glpi": "source read at 11.0.9: grep -rli 'business process' over src/ and locales/glpi.pot returns nothing; no process itemtype to link to applications." } }, { @@ -1117,7 +1138,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1131,7 +1152,8 @@ "note": "Planned usage and planned replacements exist per record, but there is no future-state model and no comparison with today.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27419 'IT Transformation' (2026-04-12): Plan and execute cloud migrations and modernization | Rated partial because transformation planning.", - "stackiq": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape" + "stackiq": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape", + "glpi": "source read at 11.0.9: grep -rli 'future state\\|what-if\\|scenario' over src/*.php returns nothing; the impact graph (src/Impact.php:49) shows only the current relations, with no plateau or target landscape." } }, { @@ -1142,7 +1164,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1156,7 +1178,8 @@ "note": "No report or view lists reference components that no application in your landscape covers.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", - "stackiq": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage" + "stackiq": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage", + "glpi": "source read at 11.0.9: no reference component model to compare against, grep -ril 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; appliances are typed only by the free Appliance type dropdown (install/mysql/glpi-empty.sql:8941)." } }, { @@ -1167,7 +1190,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1181,7 +1204,8 @@ "note": "Nothing drafts diagrams.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48970 'AI-powered diagramming' (2026-07-23): AI assists diagram generation. | docs, intelligence competitor_features#27461 'AI-Powered Diagramming' (2026-04-12): Auto-generate BPMN diagrams with built-in AI", - "stackiq": "no diagram generation in lib/Service or src; no AI integration for diagrams" + "stackiq": "no diagram generation in lib/Service or src; no AI integration for diagrams", + "glpi": "source read at 11.0.9: grep -rli 'openai\\|llm\\|mistral\\|chatgpt\\|artificial intelligence' over src/ templates/ returns nothing; diagrams are drawn by hand in the impact graph (src/Impact.php:1160)." } }, { @@ -1192,7 +1216,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1208,7 +1232,8 @@ "note": "The GEMMA standards imported with the AMEF model are browsable on their own page with a detail view that lists compliance claims.", "evidence": { "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports. | docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", - "stackiq": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)" + "stackiq": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)", + "glpi": "source read at 11.0.9: no standards itemtype, grep -ril 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing and the word standard in src/Appliance.php occurs only in addStandardTab (src/Appliance.php:100)." } }, { @@ -1219,7 +1244,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1234,7 +1259,8 @@ "featureConfidence": "high", "note": "Evidence can be attached as a file, a URL or a Nextcloud Files link on the compliance claim's page.", "evidence": { - "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'" + "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'", + "glpi": "source read at 11.0.9: any document can be attached to an appliance through the Documents tab, src/Appliance.php:100 Document_Item tab and src/Document_Item.php:46, stored in install/mysql/glpi-empty.sql:2585 glpi_documents; there is no compliance claim to attach it to. Reached on: Management > Appliances > Documents tab." } }, { @@ -1245,7 +1271,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1260,7 +1286,8 @@ "featureConfidence": "high", "note": "The matrix separates claims with evidence from claims without, but 'verified' only means evidence is attached: no one reviews or approves the evidence, so a supplier-uploaded document counts as verified.", "evidence": { - "stackiq": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue" + "stackiq": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue", + "glpi": "source read at 11.0.9: no compliance claim model, grep -rli 'complian' over src/Appliance.php src/Software.php returns nothing; nothing to mark verified or claimed (src/Appliance.php:46 fields are inventory and management fields only)." } }, { From f46affcdb7186602fb2715bf5b1a60a813753723 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:12:17 +0200 Subject: [PATCH 03/12] chore(parity): fold r-docs-a (VNG Softwarecatalogus and TOPdesk, public docs read 2026-09-26) and r-glpi packs to 29 --- openspec/parity/capabilities.json | 1251 +++++++++++++++++++---------- 1 file changed, 817 insertions(+), 434 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index 3273482a..bd7d02a3 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -178,11 +178,11 @@ "featureConfidence": "high", "note": "An application with supplier and description can be registered on the Modules page, but the module schema has no status field, and the per-organisation usage that carries a status has no page to create it on. The Modules list also cannot open ModuleDetail: its standalone CnIndexPage (FacetedCatalogIndexView.vue:108-117) binds no @view/@row-click, so the View action is inert.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"klik dan op de knop + achter de beschrijving van het pakket om het pakket toe te voegen aan je omgeving ... Pakketversie ... Referentiecomponenten ... Vul onder Planning bij Status in gebruik in\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus: \"Wanneer Gemeenten en samenwerkingen hun applicatielandschap hebben ingevoerd, wordt deze automatisch geplot op de GEMMA referentiecomponentenkaart\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Voeg pakket toe.", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | docs, intelligence competitor_features#27422 'Fact Sheets & Data Model' (2026-04-12): Flexible data model for applications, processes, IT components", "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository. | docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", "glpi": "source read at 11.0.9: src/Appliance.php:46 class Appliance is GLPI's application itemtype; install/mysql/glpi-empty.sql:8935 glpi_appliances carries name, comment (description), manufacturers_id and states_id (status); src/Appliance.php:350 search option Status; supplier through the Management tab Infocom (install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id) and Contract_Item (src/Appliance.php:99); menu src/Html.php:1300 lists Appliance under Management, served by src/Glpi/Kernel/Listener/RequestListener/LegacyItemtypeRouteListener.php:100. Reached on: Management > Appliances (front/appliance.php).", - "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure | Rated partial because software is a CMDB object among assets.", + "topdesk": "https://docs.topdesk.com/en/migrating-objects-to-asset-management.html: \"In the new Asset Management you design your own template for each type of asset you have\" (read 2026-09-26); https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"Create a new template for software cards\" (read 2026-09-26). Applications are a self-designed asset type, no application model ships. Reached on: Modules > Asset Management > Template Designer / Asset overview > New.", "stackiq": "src/manifest.json:592 Modules page (FacetedCatalogIndexView, schema module) with the library CnIndexPage create form at src/views/FacetedCatalogIndexView.vue:108; lib/Settings/softwarecatalogus_register.json:6777 module schema has name, shortDescription/longDescription and provider (Supplier) but NO status property; status lives on usage (register.json:2654, enum Acquisition..In production) which has no page" } }, @@ -211,6 +211,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated partial because fact sheets separate Application from IT Component.", "stackiq": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')", + "topdesk": "unknown: assets can be linked parent to child, but no application module concept is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the docs model a pakket and its pakketversies only, no module level is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Appliance_Item.php:45 links an Appliance to member items; src/autoload/CFG_GLPI.php:562 appliance_types includes Software, Appliance, Database and DatabaseInstance, so an application can be split into software and sub-appliances on its Items tab (src/Appliance.php:98). There is no module entity that belongs to a supplier product: grep -i 'module' src/Software.php src/Appliance.php returns no module concept. Reached on: Management > Appliances > Items tab." } }, @@ -219,7 +221,7 @@ "area": "landscape", "name": "Record the released versions of a module, with the date each came into use.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", @@ -238,7 +240,9 @@ "note": "A version is created on the Module versions index with its module and date in use, and opens on its own detail page.", "evidence": { "glpi": "source read at 11.0.9: src/SoftwareVersion.php:42 SoftwareVersion child of Software, table install/mysql/glpi-empty.sql:6900 glpi_softwareversions with name, states_id, operatingsystems_id but no release or in-use date; the only date is per installation, install/mysql/glpi-empty.sql:1074 glpi_items_softwareversions.date_install. Reached on: Assets > Software > Versions tab (front/softwareversion.form.php).", - "stackiq": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn" + "stackiq": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn", + "topdesk": "unknown: no version records per application or module are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Titel is de naam van uw productversie ... Status geeft aan of uw product in ontwikkeling, in productie, of teruggetrokken is ... startdata van ontwikkeling, test en distributie\" (read 2026-09-26). Versions are recorded per package (pakketversie), not per module. Reached on: Supplier login > Productportfolio > product > plus (versie toevoegen)." } }, { @@ -265,6 +269,8 @@ "note": "A three-step wizard bundles existing applications into one suite. Caveat: a row click on the Suites list only toggles selection (the library returns before emitting row-click when selectable, SuitesIndexView.vue:35), so SuiteDetail is not opened from the list, and its data widget includes stale field names (src/manifest.json:683 beschrijvingKort, contactpersoon).", "evidence": { "stackiq": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)", + "topdesk": "unknown: no suite bundling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no bundling of packages into a suite is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:562 appliance_types contains Appliance and Software, so an Appliance can bundle existing appliances and software through src/Appliance_Item.php:45 (table install/mysql/glpi-empty.sql:8979 glpi_appliances_items). There is no notion of offering the bundle as a product to others. Reached on: Management > Appliances > Items tab." } }, @@ -277,7 +283,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -291,8 +297,9 @@ "featureConfidence": "medium", "note": "A supplier's service over one or more applications is registered on the Services page. There is no 'hosting' service type (technical management is the nearest), and services have no detail page, so a row cannot be opened.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | Rated partial because offering registration covers products; services not named in the reading.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: facet \"Ondersteunde technologie: On-premise, Dienst - Software as a Service (SAAS)\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: \"Onder het tabblad Technologie selecteer je de onderliggende technieken van het pakket. Veelal Saas of on-premise\" (read 2026-09-26). Hosting as SaaS is a property of a package version, no separate service record (hosting, support) is documented. Reached on: Alle pakketversies > filter Ondersteunde technologie.", "stackiq": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)", + "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"Services you offer may rely on services of external suppliers. These services are called underpinning services. TOPdesk allows you to link your services to supplier services\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity), Operational Activity, Knowledge Item, Problem, and Service cards, you can link multiple assets in one go\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > Service card > Links > Assets.", "glpi": "source read at 11.0.9: no supplier service itemtype; services are held as contracts, src/ContractType.php:37 admin dropdown of contract types (for example hosting or support), install/mysql/glpi-empty.sql:1550 glpi_contracts_suppliers ties the contract to a Supplier and install/mysql/glpi-empty.sql:1536 glpi_contracts_items ties it to the Appliance or Software it covers. Reached on: Management > Contracts (front/contract.php), Suppliers tab." } }, @@ -301,7 +308,7 @@ "area": "landscape", "name": "Tag applications with the government sectors they are meant for.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", @@ -318,6 +325,8 @@ "note": "A sector schema exists, but no application, service or organisation can be tagged with a sector and no page lists sectors.", "evidence": { "stackiq": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395", + "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: facets \"Domein\" (Bestuur, Fysieke leefomgeving, Sociaal domein, ...) and \"Doelgroep\" (Gemeente, Generiek, Inwoners en ondernemers, Ketenpartners) (read 2026-09-26). Domains are municipal policy domains, the catalogue serves municipalities only, not other government sectors. Reached on: Alle pakketversies > filters Domein, Doelgroep.", "glpi": "source read at 11.0.9: no government sector concept, grep -i 'sector' over src/*.php and locales/glpi.pot hits only menu sectorization (src/Html.php:1019); the nearest holder is the single-valued Appliance type dropdown install/mysql/glpi-empty.sql:8941 appliancetypes_id, or an admin custom dropdown (install/mysql/glpi-empty.sql:10113 glpi_dropdowns_dropdowndefinitions) used as a field of a custom asset. Multi-valued tagging needs the separate tag plugin (github.com/pluginsGLPI/tag, not read). Reached on: Management > Appliances, Appliance type field." } }, @@ -330,7 +339,7 @@ "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -346,6 +355,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | Rated partial because surveys go to application owners, so ownership is modelled.", "stackiq": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')", + "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"Assignment widget : assigns locations and persons to the asset\" (read 2026-09-26). No separate business and technical owner roles are described. Reached on: Asset card > Assignment widget.", + "vng-softwarecatalogus": "unknown: the landscape entry fields listed (pakketversie, referentiecomponenten, technologie, status) include no business or technical owner; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30355 (read 2026-09-26)", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:8935 glpi_appliances holds users_id and users_id_tech; src/Appliance.php:186 search option User and src/Appliance.php:195 Group (business side), src/Appliance.php:240 'Technician in charge' and the 'Group in charge' option a few lines below (technical side). Reached on: Management > Appliances, form fields User, Group, Technician in charge, Group in charge." } }, @@ -358,7 +369,7 @@ "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "no", "built": { "state": "none", @@ -373,7 +384,9 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because flexible fact sheet data model.", "glpi": "source read at 11.0.9: native custom fields exist only for admin defined custom asset types, src/Glpi/Asset/CustomFieldDefinition.php:52 child of AssetDefinition (install/mysql/glpi-empty.sql:10159 glpi_assets_customfielddefinitions keyed on assets_assetdefinitions_id), set up under Setup > Asset definitions (src/Html.php:1330). The core Appliance and Software types take no custom fields in core; that needs the fields plugin, read at pluginsGLPI/fields tag 1.24.5, inc/container.class.php:91 containers with a list of itemtypes. Reached on: Setup > Asset definitions > Custom fields; or plugin Fields.", - "stackiq": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json" + "stackiq": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json", + "topdesk": "https://docs.topdesk.com/en/creating-new-fields.html: \"Whether it is a contact person, a purchase price, or a reminder date ... Use fields in a fieldset or dataset widget to register any useful information about an asset\" (read 2026-09-26). Reached on: Asset Management > Template Designer > Fields.", + "vng-softwarecatalogus": "unknown: no user-defined fields are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -381,11 +394,11 @@ "area": "landscape", "name": "Import an existing application list in bulk from a spreadsheet or file.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "no", "sap-leanix": "partial", "bluedolphin": "yes", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -400,6 +413,8 @@ "sap-leanix": "docs, intelligence competitor_features#27428 'EAM Automation' (2026-04-12): Automated data collection from ServiceNow, Jira, cloud providers | Rated partial because automated collection from ServiceNow, Jira and cloud.", "bluedolphin": "docs, intelligence competitor_features#48971 'Data import (Excel)' (2026-07-23): Bulk import of application/portfolio data.", "stackiq": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)", + "topdesk": "https://docs.topdesk.com/en/generate-import-file.html: \"Importing assets speeds up this task ... export an asset template to XLSX format\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-new-import.html: \"You can use a file (CSV or XLSX), connect with an MS SQL database or import from Microsoft Intune , or Lansweeper\" (read 2026-09-26). Reached on: Settings > Import settings > Asset Management imports.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"Een import vanuit die tools naar de Softwarecatalogus zodat 2-richtingverkeer mogelijk wordt voor actualisatie, is vooralsnog niet voorhanden\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/19703: inventory goes in a spreadsheet, then \"Kies met de + toets het pakket dat opgevoerd moet worden\", one package at a time (read 2026-09-26)", "glpi": "source read at 11.0.9: core has CSV export only (src/Glpi/Csv/ holds CsvResponse and export classes, no importer) and no spreadsheet import of assets or appliances. Bulk import is the separate datainjection plugin, read at pluginsGLPI/datainjection tag 2.15.11: inc/backendcsv.class.php CSV backend and inc/applianceinjection.class.php:33 PluginDatainjectionApplianceInjection extends Appliance; setup.php:36 requires GLPI 11.0.5 or later. Reached on: plugin Data injection (Tools > Data injection)." } }, @@ -412,7 +427,7 @@ "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -426,9 +441,10 @@ "featureConfidence": "medium", "note": "The application page shows versions and compliance claims, and usages only as untyped entries in the generic Related panel. Contracts are not shown. The page cannot be opened from the Applications list itself, and its data widget asks for three field names the schema no longer has, so the descriptions do not render.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakket/archi: package page shows versions with status and start dates, \"Pakket geschikt voor (GEMMA 2) Ingevuld door (28)\", and per version the mandatory and recommended standards with support, compliancy and testrapport (read 2026-09-26). No contracts on the page. Reached on: Alle pakketten > package name.", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because fact sheet is the per-application page.", "stackiq": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)", + "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: twelve widgets incl. \"History\", \"Relationships\", \"Relationship grid\", \"Documents\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: assets linked to calls, changes, services (read 2026-09-26). Versions and compliance are not part of it. Reached on: Asset card.", "glpi": "source read at 11.0.9: src/Appliance.php:98 onwards defineTabs puts Items, Contracts, Documents, Management (Infocom), Certificates, Domains, Knowledge base, Tickets, Problems, Changes and Impact on the one appliance page; versions sit on the separate Software page (src/SoftwareVersion.php:42), and no compliance tab exists (grep -i 'complian' src/Appliance.php returns nothing). Reached on: Management > Appliances > appliance form tabs." } }, @@ -441,7 +457,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -456,6 +472,8 @@ "note": "Many entries can be selected and deleted together through the library index page. The mass publish and mass lock dialogs exist but hang off a view modal no page opens, and the publish endpoint (lib/Controller/PublicationController.php, PUT /api/publication/...) has no frontend caller.", "evidence": { "stackiq": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets", + "topdesk": "https://docs.topdesk.com/en/editing-assets-in-bulk.html: \"select multiple assets by ticking their boxes ... You can use bulk edit for updating up to 500 assets\" (read 2026-09-26); editable are assignments, drop-down, date, number, text and checkbox fields. Bulk publish or delete is not described. Reached on: Asset Management > Asset overview > select > bulk edit.", + "vng-softwarecatalogus": "unknown: no multi-select publish, lock or delete is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "glpi": "source read at 11.0.9: every search list offers massive actions, src/MassiveAction.php:666 Update (any field, for example status), src/MassiveAction.php:698 Put in trashbin, src/MassiveAction.php:652 Delete permanently, src/MassiveAction.php:656 Restore. There is no publish state; locking applies to inventory fields only. Reached on: any list, for example Management > Appliances, Actions button." } }, @@ -468,7 +486,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "no", "stackiq": "partial", "built": { "state": "built", @@ -481,6 +499,8 @@ "note": "Only organisations can be merged, with a dry run first, and only by a Nextcloud admin. Applications, services and other entries have no merge.", "evidence": { "stackiq": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets", + "topdesk": "https://docs.topdesk.com/en/migration-status.html: \"You cannot merge the two cards into one card\" (read 2026-09-26); https://tip.topdesk.com/c/239-ai-cmdb-monitoring-: roadmap card in column \"Under consideration\", \"AI can continuously scan your configuration database for duplicate records ... and surfaces them for review\" (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no merge of entries is described; the news page only mentions a pseudo-supplier \"Open Source Pakketten\" created against duplicate spellings; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/nieuws (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Software.php:109 'Merging' tab on a recursive software, src/Software.php:926 showMergeCandidates lists same named software, src/Software.php:997 massive action Merge, src/Software.php:1011 private function merge moves versions and licences into the kept entry; dropdowns get Replace, src/CommonDropdown.php:680. Reached on: Assets > Software > Merging tab." } }, @@ -489,7 +509,7 @@ "area": "landscape", "name": "Ask application owners through a survey to confirm or correct their entries.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "no", @@ -508,6 +528,8 @@ "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | docs, intelligence competitor_features#27423 'Survey-Based Data Collection' (2026-04-12): Crowdsource architecture data from application owners", "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders.", "stackiq": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)", + "topdesk": "unknown: Survey Management runs general surveys (and \"will reach end of life ... November 2026\"), not confirmation of entries by owners; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C7: \"Leveranciers krijgen ook periodiek notificatiemails met een aantal automatische controles en de Te corrigeren fouten staan ook op het dashboard van ingelogde leveranciers\" (read 2026-09-26); https://www.softwarecatalogus.nl/suggesties_overnemen: suppliers send suggestions that municipalities accept or decline (read 2026-09-26). No survey to application owners.", "glpi": "source read at 11.0.9: the native form builder (src/Glpi/Form/Form.php:92) only has ITIL destinations, src/Glpi/Form/Destination/ holds FormDestinationTicket, FormDestinationChange and FormDestinationProblem, so a form answer opens a ticket but never confirms or updates an appliance record; the only 'survey' in core is ticket satisfaction (src/Central.php:220). No owner review campaign exists." } }, @@ -516,7 +538,7 @@ "area": "landscape", "name": "See how complete and up to date each application's entry is, as a score.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "no", @@ -533,7 +555,9 @@ "note": "No page scores how complete or current an entry is.", "evidence": { "stackiq": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)", - "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing; no score of how filled in an item is exists in core." + "topdesk": "unknown: the only readiness score described is the AI readiness score for the knowledge base; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/voortgang-verbeteren: \"Met het aantal sterren (*) wordt een indicatie van volledigheid van ingevulde gegevens aangegeven\", criteria include referentiecomponenten filled, statuses, koppelingen and \"Datum laatste wijziging is recenter dan 3 maanden geleden\" (read 2026-09-26). Scored per organisation, not per application entry. Reached on: Homepage block Voortgang gemeenten; organisation page header.", + "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing; no score of how filled in an item is exists in core. The item form tabs (src/Appliance.php:98 onwards) show no score." } }, { @@ -558,6 +582,8 @@ "note": "An admin picks the demo dataset in the setup wizard and it is imported through OpenRegister. Admin-only, which suits an installation task.", "evidence": { "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp", + "topdesk": "unknown: no example data set is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the catalogue is one hosted service; no loadable example data set is described (a \"VNG Realisatie Demo\" supplier appears in the live data); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'demo data\\|sample data' over src/ templates/ locales/glpi.pot returns nothing and src/Glpi/Console/ has no demo loader; example data exists only as test fixtures under tests/, not shipped as a feature." } }, @@ -583,6 +609,8 @@ "note": "Only suites get a step-by-step wizard. Applications and services are added through a plain form, and connections have no page at all.", "evidence": { "stackiq": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing", + "topdesk": "unknown: wizards exist for imports and migration, not for adding an application; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the manuals describe forms (\"Hierna opent een formulier\"), no step-by-step wizard; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30355 (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'wizard' over src/ templates/ locales/glpi.pot returns nothing for item creation; appliances are added through the plain form only (install/mysql/glpi-empty.sql:8935 glpi_appliances has no is_template column)." } }, @@ -608,6 +636,8 @@ "note": "A module version's page lists the third-party components imported from its SBOM.", "evidence": { "stackiq": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema", + "topdesk": "unknown: no software components per version are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no third-party component list per version is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; software versions carry no component list (install/mysql/glpi-empty.sql:6900 glpi_softwareversions)." } }, @@ -616,7 +646,7 @@ "area": "landscape", "name": "Record whether an application runs on premises, as SaaS or at a hosting party.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", @@ -636,6 +666,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | Rated partial because SaaS is tracked as a class of application.", "stackiq": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)", + "topdesk": "unknown: only possible as a self-defined field; no hosting model is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Indien een leverancier zowel SaaS als On premise ondersteunt, kan je aangeven welke van deze twee varianten gebruikt wordt binnen de gemeente\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen > tabblad Technologie.", "glpi": "source read at 11.0.9: no hosting model field; the closest holders are the admin editable Environment dropdown on an appliance, src/Appliance.php:277 ApplianceEnvironment search option (install/mysql/glpi-empty.sql:8945 applianceenvironments_id), plus locations_id and the Appliance type dropdown. grep -i 'saas' over src/ finds nothing; 'On-premise' in locales/glpi.pot:12997 is only an icon label. Reached on: Management > Appliances, Environment field." } }, @@ -662,8 +694,9 @@ "featureConfidence": "low", "note": "The field for a national provision exists on the connection schema, but with no connection page nobody can fill it in stackiq.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48841 'National provisions (landelijke voorzieningen) linking' (2026-07-23): Records links between applications and national government provisions.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"De richting van het berichtenverkeer, de landelijke voorziening waarmee gekoppeld is/wordt, in dit geval GGK\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus: \"kunnen koppelingen tussen applicaties onderling en met Landelijke Voorzieningen vastgelegd worden\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > koppeling toevoegen.", "stackiq": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection", + "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "glpi": "source read at 11.0.9: no national provision concept (grep -ril 'basisregistratie' src/ locales/glpi.pot returns nothing); a provision can be held as another Appliance and linked through an impact relation, install/mysql/glpi-empty.sql:1247 glpi_impactrelations (source item, impacted item, name), with Appliance enabled for impact at src/autoload/CFG_GLPI.php:649. Reached on: Appliance > Impact analysis tab, Add relation." } }, @@ -672,7 +705,7 @@ "area": "connections", "name": "Browse all connections in the catalogue in one list and open each one.", "origin": "own-code", - "vng-softwarecatalogus": "partial", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "no", @@ -690,8 +723,9 @@ "featureConfidence": "medium", "note": "There is no list of connections in the catalogue. The Integrations page lists outside integrations, a different thing.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle koppelingen ... staan de koppelingen van alle gemeenten en samenwerkingsverbanden ... Door te klikken op het icoontje rechts van een koppeling, krijg je nog enige detail informatie\" (read 2026-09-26). Reached on: Inlogmenu > Alle koppelingen (logged-in municipal users).", "stackiq": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)", + "topdesk": "unknown: relations are shown per asset and in a graphical overview; a list of all relations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "glpi": "source read at 11.0.9: src/ImpactRelation.php:39 ImpactRelation has only prepareInputForAdd and getIDFromInput (src/ImpactRelation.php:47, :107), no search options and no list page; relations are only seen per item in the Impact analysis tab (src/Impact.php:91)." } }, @@ -704,7 +738,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -718,8 +752,9 @@ "featureConfidence": "low", "note": "Connections that reference an application should appear among the untyped related objects on its page, but there is no connections section and nothing to open. The dedicated per-application endpoint is API only.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Mijn pakketoverzicht ... Onder het eerste tabblad zitten de pakketten en onder het tweede tabblad de koppelingen\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: \"Door op een applicatienaam in het Models venster te klikken, zie je in de Visualiser alle koppelingen tussen die applicatie met andere applicaties\" (in Archi after export) (read 2026-09-26). No per-application connection view inside the catalogue is described. Reached on: Mijn softwarecatalogus > Koppelingen.", "stackiq": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/", + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"Links between assets are created and managed via the Relationships widget. For current relationships with other assets, the widget shows the template's icon, the Asset ID\" (read 2026-09-26). Generic asset relations, not interfaces. Reached on: Asset card > Relationships widget.", "glpi": "source read at 11.0.9: src/Impact.php:91 getTabNameForItem adds the 'Impact analysis' tab (src/Impact.php:80) to every impact enabled itemtype, Appliance and Software included (src/autoload/CFG_GLPI.php:649 and :663), with a list view src/Impact.php:270 displayListView of every related item in both directions. Reached on: Management > Appliances > Impact analysis tab." } }, @@ -728,11 +763,11 @@ "area": "connections", "name": "See the connections between applications drawn as a diagram.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "no", "built": { "state": "none", @@ -749,7 +784,9 @@ "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model. | docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", "bluedolphin": "docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models. | docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", "glpi": "source read at 11.0.9: src/Impact.php:252 displayGraphView and src/Impact.php:1559 makeDataForCytoscape draw the relation network, with editing tools add asset, add relation, add group at src/Impact.php:1160. Reached on: Appliance > Impact analysis tab, graph view.", - "stackiq": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)" + "stackiq": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)", + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"After you define the relationship between assets, you can use the graphical overview to see a visual representation of their relationship\" (read 2026-09-26). Reached on: Asset card > graphical overview.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30890: \"Tekenen van een view met koppelingen ... Een koppeling is gemodelleerd als een Archimate flow relatie\" (read 2026-09-26). Diagrams are drawn in Archi after an AMEFF export, not in the catalogue." } }, { @@ -757,7 +794,7 @@ "area": "connections", "name": "Before changing or retiring an application, see what depends on it.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "yes", "glpi": "yes", @@ -775,8 +812,9 @@ "evidence": { "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", "glpi": "source read at 11.0.9: src/Impact.php:49 class Impact 'Impact analysis', src/Impact.php:713 bfs walks the graph by direction and src/Impact.php:612 buildListData lists what is impacted, with ongoing tickets, problems and changes on impacted items (src/Impact.php:313). Reached on: Tools > Impact analysis (src/Html.php:1309) and the item's Impact analysis tab.", - "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because relations between assets.", - "stackiq": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/" + "topdesk": "https://docs.topdesk.com/en/managing-disruptions-in-your-asset-management-process.html: \"you want to know how far the reach of the disruption is ... the operational/impacted status for assets ... Status impacts are also only shown in the graphical overview when a link type is used\" (read 2026-09-26). Disruption impact, not a pre-change dependency analysis. Reached on: Asset card > General widget > Determine status automatically.", + "stackiq": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Pakketversies die niet meer in gebruik zijn, kunnen verwijderd worden waarbij feedback gegeven wordt over de koppelingen die ook automatisch verwijderd zullen worden\" (read 2026-09-26). Only on delete, no dependency analysis." } }, { @@ -801,6 +839,8 @@ "note": "The type field exists but there is no connection list to filter.", "evidence": { "stackiq": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter", + "topdesk": "unknown: custom link types exist, but filtering relations by type is not described; https://tip.topdesk.com/c/90-graphical-overview-improvements is still under consideration; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: connections carry a standard and \"het soort overdracht\" (upload naar portaal, webservices), but the docs do not name a type filter on the connection list; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo (read 2026-09-26)", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations has only a free name besides the two endpoints, no connection type (API, file, message), so there is nothing to filter on; the graph settings (src/Impact.php:1167 impact_settings) cover depth and direction." } }, @@ -827,6 +867,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#27425 'API Management' (2026-04-12): Catalog and manage APIs across the application landscape", "stackiq": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label", + "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no register of APIs an application exposes is described; standards are declared instead; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "glpi": "source read at 11.0.9: no API entity in core, grep -ril 'openapi' src/*.php finds no itemtype for exposed APIs; an admin can define an 'API' custom asset type (src/Html.php:1330 Setup > Asset definitions, src/Glpi/Asset/AssetDefinition.php) and attach it to the application as an Appliance item (src/Appliance_Item.php:45) or impact relation (install/mysql/glpi-empty.sql:1247). Reached on: Setup > Asset definitions, then Appliance > Items tab." } }, @@ -835,7 +877,7 @@ "area": "connections", "name": "Export the graph of what an application is linked to, for use elsewhere.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", @@ -854,7 +896,9 @@ "note": "The organisation ArchiMate export carries modules and usages but not connections, so an application's link graph cannot be exported.", "evidence": { "glpi": "source read at 11.0.9: front/impactcsv.php streams Glpi\\Csv\\ImpactCsvExport for an item, linked from the impact list view at src/Impact.php:393; the graph Download button src/Impact.php:1165 calls js/impact.js:2528 download, which writes PNG (js/impact.js:2539) or JPEG (js/impact.js:2546). Reached on: Appliance > Impact analysis tab, Download and CSV export.", - "stackiq": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*" + "stackiq": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*", + "topdesk": "unknown: exporting the relation graph is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: \"Pakketten én koppelingen worden in 1 model geëxporteerd ... AMEFF-export\" (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Mijn koppelingen: Knop [Exporteren] op tabblad Koppelingen\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten or Koppelingen > Exporteren > AMEFF-export." } }, { @@ -866,7 +910,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -879,6 +923,8 @@ "note": "With integriq installed, an admin sees stackiq's three integrations and their checked status on one page, and Add integration opens integriq. Without integriq the page is hidden, and the checking is integriq's.", "evidence": { "stackiq": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq", + "topdesk": "https://docs.topdesk.com/en/connections.html: \"TOPdesk offers a storage space for usernames, passwords, and authentication tokens used in automated actions ... Better overview: Observe when specific credentials are applied\" (read 2026-09-26); https://docs.topdesk.com/en/using-the-automated-actions-overview.html: \"contains all asset actions, webhooks, scheduled actions ... The last execution status\" (read 2026-09-26). Reached on: Settings > Connections; Action Management > Automated Actions.", + "vng-softwarecatalogus": "unknown: no overview of the catalogue's own outside integrations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "glpi": "source read at 11.0.9: outside integrations are set up on separate Setup pages, not one overview: src/Html.php:1331 Webhook, src/Html.php:1333 OAuthClient and MailCollector, Auth (LDAP, SSO) on src/Html.php:1332; src/Webhook.php:64 Webhook and src/OAuthClient.php:45 OAuthClient each have their own list. Reached on: Setup > Webhooks, Setup > OAuth clients, Setup > Authentication." } }, @@ -907,7 +953,9 @@ "evidence": { "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27459 'ArchiMate & BPMN Support' (2026-04-12): Full ArchiMate and BPMN modeling in one platform | Rated yes because full ArchiMate support; import format not named in the reading.", "stackiq": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile", - "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma\\|togaf' over src/ templates/ locales/glpi.pot returns nothing; no model import exists." + "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: only export to AMEFF is documented; importing an ArchiMate file into the catalogue is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma\\|togaf' over src/ templates/ locales/glpi.pot returns nothing; no model import exists. Import paths in core are inventory (src/Glpi/Inventory/Inventory.php:106) and form import (src/Glpi/Controller/Form/Import/), neither for models." } }, { @@ -933,10 +981,11 @@ "featureConfidence": "high", "note": "The export produces a downloadable AMEF XML, but only from the admin settings page; organisation admins may call the API but have no page for it.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: \"De softwarecatalogus ondersteund een koppeling met architectuurtools. Dit wordt gedaan via de exportfunctionaliteit van een ArchiMate Exchange Format-bestand ... Archi (Open Source), Bizzdesign, Mavim, Sparx, Dragon1 en Value Blue\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Exporteren > AMEFF-export.", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", "stackiq": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button", - "glpi": "source read at 11.0.9: grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing; exports are CSV, PDF and spreadsheet search output (src/Glpi/Csv/) only." + "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing; exports are CSV, PDF and spreadsheet search output (src/Glpi/Csv/) only. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43 and the spreadsheet siblings." } }, { @@ -962,9 +1011,10 @@ "featureConfidence": "high", "note": "Complete logic, but reachable only on the admin settings page; an ordinary organisation user cannot export its own landscape from a stackiq page.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape | docs, intelligence competitor_features#27554 'ArchiMate Export' (2026-04-12): Export to ArchiMate format for use in architecture tools | Rated yes because map and export the municipality's landscape.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: export file named \"GEMMA_Softwarecatalogus__ameff_model\" (read 2026-09-26); https://www.softwarecatalogus.nl/Archi_modellen_samenvoegen: \"De export van de Softwarecatalogus bevat de GEMMA en alle pakketten en koppelingen van de gemeente\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: \"GEMMA views met daarop geplot de pakketten van de gemeente\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Exporteren > AMEFF-export.", "stackiq": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes", - "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma' over src/ templates/ locales/glpi.pot returns nothing; no GEMMA plotting or per entity model export." + "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma' over src/ templates/ locales/glpi.pot returns nothing; no GEMMA plotting or per entity model export. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43, no model file." } }, { @@ -991,7 +1041,9 @@ "note": "There is an endpoint, but its comparison is broken (a missing key against a placeholder string) and no page calls it. The compare_archimate.py/.php scripts in the repo root are developer tools, not a user capability.", "evidence": { "stackiq": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register", - "glpi": "source read at 11.0.9: there is no model import or export to round trip, grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing." + "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the merge guide checks the result inside Archi via its status log; the catalogue itself offers no round-trip check; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Archi_modellen_samenvoegen (read 2026-09-26)", + "glpi": "source read at 11.0.9: there is no model import or export to round trip, grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43, no model file." } }, { @@ -1018,7 +1070,9 @@ "note": "The import runs as one blocking request with a spinner. The cancel endpoint calls a missing method and import progress is never recorded, so neither following nor cancelling works.", "evidence": { "stackiq": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button", - "glpi": "source read at 11.0.9: no model import exists (grep -ril 'archimate' src/ returns nothing), so there is no import to follow; the generic progress endpoint src/Glpi/Controller/ProgressController.php serves other long operations." + "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no model import is documented; for export only \"Er verschijnt een venster met de melding dat de export gegenereerd wordt\"; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools (read 2026-09-26)", + "glpi": "source read at 11.0.9: no model import exists (grep -ril 'archimate' src/ returns nothing), so there is no import to follow; the generic progress endpoint src/Glpi/Controller/ProgressController.php serves other long operations. The progress route is src/Glpi/Controller/ProgressController.php:50 /progress/check/{key}, used by the installer (src/Glpi/Controller/InstallController.php:57)." } }, { @@ -1026,7 +1080,7 @@ "area": "architecture", "name": "Read the definition of a GEMMA term in place while working in the catalogue.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "no", @@ -1045,7 +1099,9 @@ "note": "You can open a standard's page and read its definition, but reference components and other GEMMA terms have no page and there is no inline definition where they appear.", "evidence": { "stackiq": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only", - "glpi": "source read at 11.0.9: grep -ril 'gemma\\|glossary' over src/ templates/ locales/glpi.pot returns nothing; no reference term definitions ship in core." + "topdesk": "unknown: GEMMA is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/lexicon: lexicon of catalogue terms (Addendum, Referentiecomponent, Standaard, SaaS); terms in page text link to it (read 2026-09-26); https://www.softwarecatalogus.nl/node/13683: \"Alle referentiecomponenten ... de toelichting bij de referentiecomponenten\" (read 2026-09-26). Reached on: Lexicon; Alle referentiecomponenten.", + "glpi": "source read at 11.0.9: grep -ril 'gemma\\|glossary' over src/ templates/ locales/glpi.pot returns nothing; no reference term definitions ship in core. The knowledge base (src/KnowbaseItem.php:57) is the only place definitions could be written by hand." } }, { @@ -1053,7 +1109,7 @@ "area": "architecture", "name": "Map applications to business capabilities or functions and see the map.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "no", @@ -1074,7 +1130,9 @@ "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | docs, intelligence competitor_features#27420 'Business Capability Mapping' (2026-04-12): Map applications to business capabilities and processes", "bluedolphin": "docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", "stackiq": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies", - "glpi": "source read at 11.0.9: grep -rli 'business capabilit\\|business process' over src/ and locales/glpi.pot returns nothing; 'Capacity' in src/Glpi/Asset/Capacity.php is a feature toggle for custom assets, not a business capability." + "topdesk": "unknown: no capability or function map is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: view \"RD02 Bedrijfsfuncties ruimtelijk domein met referentiecomponenten\" with the municipality's packages plotted (read 2026-09-26). Mapping runs through fixed GEMMA reference components and business functions, not the organisation's own capability model. Reached on: Mijn softwarecatalogus > Pakketten > kaart kiezen > Toon kaart.", + "glpi": "source read at 11.0.9: grep -rli 'business capabilit\\|business process' over src/ and locales/glpi.pot returns nothing; 'Capacity' in src/Glpi/Asset/Capacity.php is a feature toggle for custom assets, not a business capability. src/Glpi/Asset/Capacity.php:39 is the custom asset capacity class." } }, { @@ -1101,6 +1159,8 @@ "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model.", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models.", "stackiq": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components", + "topdesk": "unknown: no architecture modelling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the docs send users to Archi or other tools for modelling; drawing inside the catalogue is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30890 (read 2026-09-26)", "glpi": "source read at 11.0.9: the impact graph is an editable diagram, src/Impact.php:1160 add asset, add relation and add group tools, groups stored in install/mysql/glpi-empty.sql:1264 glpi_impactcompounds and node positions in install/mysql/glpi-empty.sql:1276 glpi_impactitems; it draws dependency graphs only, with no architecture notation or views. Reached on: Appliance > Impact analysis tab, graph edit mode." } }, @@ -1127,7 +1187,9 @@ "evidence": { "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27464 'Process Mapping' (2026-04-12): Map processes, applications, data, and technology", "stackiq": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json", - "glpi": "source read at 11.0.9: grep -rli 'business process' over src/ and locales/glpi.pot returns nothing; no process itemtype to link to applications." + "topdesk": "unknown: no process modelling linked to applications is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no process modelling is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'business process' over src/ and locales/glpi.pot returns nothing; no process itemtype to link to applications. Appliance tabs (src/Appliance.php:98 onwards) link no process." } }, { @@ -1135,7 +1197,7 @@ "area": "architecture", "name": "Model a future-state landscape and compare it with today's.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", @@ -1153,6 +1215,8 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#27419 'IT Transformation' (2026-04-12): Plan and execute cloud migrations and modernization | Rated partial because transformation planning.", "stackiq": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape", + "topdesk": "unknown: Long-Term Planning scenarios are for maintenance planning and the module \"will reach end of life ... November 2026\"; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"geplande harmonisaties ... met een status gepland met bijbehorende datum. Zo kan ook het uiteindelijke doel-landschap in 1 overzicht inzichtelijk worden gemaakt\" (read 2026-09-26). No side-by-side comparison of today and target. Reached on: Mijn softwarecatalogus (samenwerking) > Pakketten > status Gepland.", "glpi": "source read at 11.0.9: grep -rli 'future state\\|what-if\\|scenario' over src/*.php returns nothing; the impact graph (src/Impact.php:49) shows only the current relations, with no plateau or target landscape." } }, @@ -1161,7 +1225,7 @@ "area": "architecture", "name": "Find reference components that no application in your landscape covers.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "yes", "glpi": "no", @@ -1179,6 +1243,8 @@ "evidence": { "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", "stackiq": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage", + "topdesk": "unknown: GEMMA reference components are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tile \"Pakketten met meer mogelijkheden: U heeft in uw pakketoverzicht pakketten die geschikt zijn voor referentiecomponenten waarbij u nog geen pakket heeft opgevoerd\" (read 2026-09-26). It lists uncovered components only where an owned package could fill them. Reached on: Dashboard tile Pakketten met meer mogelijkheden.", "glpi": "source read at 11.0.9: no reference component model to compare against, grep -ril 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; appliances are typed only by the free Appliance type dropdown (install/mysql/glpi-empty.sql:8941)." } }, @@ -1205,6 +1271,8 @@ "evidence": { "bluedolphin": "docs, intelligence competitor_features#48970 'AI-powered diagramming' (2026-07-23): AI assists diagram generation. | docs, intelligence competitor_features#27461 'AI-Powered Diagramming' (2026-04-12): Auto-generate BPMN diagrams with built-in AI", "stackiq": "no diagram generation in lib/Service or src; no AI integration for diagrams", + "topdesk": "unknown: the AI features cover tickets and knowledge, not diagrams; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no assistant is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'openai\\|llm\\|mistral\\|chatgpt\\|artificial intelligence' over src/ templates/ returns nothing; diagrams are drawn by hand in the impact graph (src/Impact.php:1160)." } }, @@ -1231,8 +1299,9 @@ "featureConfidence": "high", "note": "The GEMMA standards imported with the AMEF model are browsable on their own page with a detail view that lists compliance claims.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports. | docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle standaarden: Dit overzicht is een opsomming van alle standaarden waaraan pakketten mogelijk moeten voldoen. Alle standaarden hebben een toelichting en indien aanwezig een toelichting op het compliancy-instrument\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle standaarden.", "stackiq": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "glpi": "source read at 11.0.9: no standards itemtype, grep -ril 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing and the word standard in src/Appliance.php occurs only in addStandardTab (src/Appliance.php:100)." } }, @@ -1241,7 +1310,7 @@ "area": "compliance", "name": "Attach a test report or other evidence to a compliance claim.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", @@ -1260,6 +1329,8 @@ "note": "Evidence can be attached as a file, a URL or a Nextcloud Files link on the compliance claim's page.", "evidence": { "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Door de vakje achter de standaard aan te vinken voor Ondersteuning(gepland) en Compliancy, wordt de optie om een testrapport of auditrapport op te voeren geopend\" (read 2026-09-26). Reached on: Supplier login > productversie > Voeg extra standaarden toe.", "glpi": "source read at 11.0.9: any document can be attached to an appliance through the Documents tab, src/Appliance.php:100 Document_Item tab and src/Document_Item.php:46, stored in install/mysql/glpi-empty.sql:2585 glpi_documents; there is no compliance claim to attach it to. Reached on: Management > Appliances > Documents tab." } }, @@ -1268,7 +1339,7 @@ "area": "compliance", "name": "Tell a verified compliance claim apart from one the supplier only asserts.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "no", @@ -1287,6 +1358,8 @@ "note": "The matrix separates claims with evidence from claims without, but 'verified' only means evidence is attached: no one reviews or approves the evidence, so a supplier-uploaded document counts as verified.", "evidence": { "stackiq": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C8: \"Gepubliceerde testrapporten voor een aantal standaarden die in de compliancy-monitor staan, worden sinds eind 2016 door VNG Realisatie gecontroleerd en daarna op status goedgekeurd of afgekeurd gezet\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facet \"Standaard met testrapport: Toon alleen pakketversies met compliancy aangetoond in een testrapport\" (read 2026-09-26). Reached on: Alle pakketversies > filter Standaard met testrapport; Compliancy monitor.", "glpi": "source read at 11.0.9: no compliance claim model, grep -rli 'complian' over src/Appliance.php src/Software.php returns nothing; nothing to mark verified or claimed (src/Appliance.php:46 fields are inventory and management fields only)." } }, @@ -1295,10 +1368,10 @@ "area": "compliance", "name": "See applications against chosen standards in one matrix, cell by cell.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1313,7 +1386,10 @@ "featureConfidence": "high", "note": "A filter-first matrix of applications against chosen standard versions (or BIO measures), cell by cell with verified/claimed/none.", "evidence": { - "stackiq": "src/manifest.json ComplianceMatrix /compliance-matrix custom page -> src/customComponents.js ComplianceMatrixView -> src/views/ComplianceMatrixView.vue (modules x selected standard versions or BIO measures, src/utils/complianceMatrix.js:270 columns)" + "stackiq": "src/manifest.json ComplianceMatrix /compliance-matrix custom page -> src/customComponents.js ComplianceMatrixView -> src/views/ComplianceMatrixView.vue (modules x selected standard versions or BIO measures, src/utils/complianceMatrix.js:270 columns)", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/compliancy_monitor: per standard (e.g. \"Betalen en invorderen services 1.0\") a table of Leverancier, Pakketversie, Compliancy \"Ok\" or \"Niet ok\" (read 2026-09-26). Fixed per standard, not a matrix of chosen applications against chosen standards. Reached on: Homepage > Compliancy monitor.", + "glpi": "source read at 11.0.9: there are no standards in core (grep -rli 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing), so no application by standard matrix; search output (src/Glpi/Search/Output/Spreadsheet.php) only tabulates item fields. The spreadsheet output is src/Glpi/Search/Output/Csv.php:38 and siblings." } }, { @@ -1324,7 +1400,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1339,7 +1415,10 @@ "featureConfidence": "medium", "note": "One action updates every module's standards from its compliance records, but only a Nextcloud admin can run it and it stops at 1000 compliance records.", "evidence": { - "stackiq": "appinfo/routes.php:275 POST /api/bulk-sync-standards -> lib/Controller/SettingsController.php:3598 (isAdmin check) -> lib/Service/ModuleComplianceService.php:527 bulkSyncModuleStandards (reads up to 1000 compliancy records and updates module standards); UI src/views/settings/sections/StatisticsOverview.vue:79 button -> src/modals/BulkSyncDialog.vue:321" + "stackiq": "appinfo/routes.php:275 POST /api/bulk-sync-standards -> lib/Controller/SettingsController.php:3598 (isAdmin check) -> lib/Service/ModuleComplianceService.php:527 bulkSyncModuleStandards (reads up to 1000 compliancy records and updates module standards); UI src/views/settings/sections/StatisticsOverview.vue:79 button -> src/modals/BulkSyncDialog.vue:321", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: only per-version copying is described (\"opvoer van een nieuwe versies mogelijk als kopie van een op te geven vorige versie\"); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no standards model exists (see comp-standards-register); massive actions (src/MassiveAction.php:666 Update) update item fields only." } }, { @@ -1350,7 +1429,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1365,7 +1444,10 @@ "featureConfidence": "medium", "note": "The page exists and shows the theme, but the level column is wired to a key that does not exist (bbnNiveau vs bbnLevel; level only shows on the detail page), and the BIO measures are not shipped, so someone has to type them in.", "evidence": { - "stackiq": "src/manifest.json BioMaatregelen /bio-maatregelen index (columns code,name,thema,bioVersion,bbnNiveau) and BioMaatregelDetail; register property is bbnLevel (lib/Settings/softwarecatalogus_register.json bioMeasure), so the bbnNiveau column is empty; no BIO catalogue is seeded (only 6 demo objects in lib/Settings/stackiq_mock_register.json)" + "stackiq": "src/manifest.json BioMaatregelen /bio-maatregelen index (columns code,name,thema,bioVersion,bbnNiveau) and BioMaatregelDetail; register property is bbnLevel (lib/Settings/softwarecatalogus_register.json bioMeasure), so the bbnNiveau column is empty; no BIO catalogue is seeded (only 6 demo objects in lib/Settings/stackiq_mock_register.json)", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: BIO measures are not in the catalogue docs; BBN views live on GEMMA Online per the news page; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/nieuws (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'iso 27001\\|27002' and grep -rwi 'bio' over src/ locales/glpi.pot return nothing; no security measure catalogue ships (menus at src/Html.php:1295 onwards list none)." } }, { @@ -1376,7 +1458,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1391,7 +1473,10 @@ "featureConfidence": "medium", "note": "You can record that an application meets a BIO measure, but there is no way to record that it does not meet one: the absence of a claim is the only negative, which cannot be told apart from 'not assessed'. The md-compliance column key 'bioMaatregel' also differs from the property bioMeasure.", "evidence": { - "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.bioMeasure links a module to a BIO measure; src/manifest.json ModuleDetail md-compliance lists claims incl. bioMaatregel column, BioMaatregelDetail bm-compliance lists modules per measure; compliancy has no status/met-not-met field" + "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.bioMeasure links a module to a BIO measure; src/manifest.json ModuleDetail md-compliance lists claims incl. bioMaatregel column, BioMaatregelDetail bm-compliance lists modules per measure; compliancy has no status/met-not-met field", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no BIO assessment per application is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no measure catalogue and no assessment itemtype; grep -rli 'iso 27001\\|27002' over src/ locales/glpi.pot returns nothing and Appliance tabs (src/Appliance.php:98 onwards) hold no assessment." } }, { @@ -1402,7 +1487,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1417,7 +1502,10 @@ "featureConfidence": "low", "note": "DPIA status, date, next review and document link are fields on the application and shown and filterable on the Applications pages. The scheduled 'dpia-review-overdue' notification is only a register declaration.", "evidence": { - "stackiq": "lib/Settings/softwarecatalogus_register.json module.dpiaStatus (enum not required/required/executed), dpiaDate, dpiaNextAssessment, dpiaDocumentRef; src/manifest.json ModuleDetail md-data includes the DPIA fields; Modules /modules quick filter 'Without DPIA (BBN2+)'" + "stackiq": "lib/Settings/softwarecatalogus_register.json module.dpiaStatus (enum not required/required/executed), dpiaDate, dpiaNextAssessment, dpiaDocumentRef; src/manifest.json ModuleDetail md-data includes the DPIA fields; Modules /modules quick filter 'Without DPIA (BBN2+)'", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no DPIA field is described; the VWO addendum is a supplier-level processing agreement; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/leveranciers (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'dpia\\|impact assessment\\|gdpr' over src/ returns nothing, locales/glpi.pot:12792 'gdpr-tools' is only an icon name. The GDPR records plugin yild/gdprropa read at tag 1.0.3 has 'PIA required' and 'PIA status' (inc/record.class.php:459, :468) but declares GLPI 10 only, setup.php:56 max 10.99.99, so it does not run on 11.0.9." } }, { @@ -1425,10 +1513,10 @@ "area": "compliance", "name": "Check an application against the Forum Standaardisatie comply-or-explain list.", "origin": "competitor", - "vng-softwarecatalogus": "yes", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1441,8 +1529,10 @@ "providerHow": "read-from-code", "note": "There is no list or check for the Forum Standaardisatie comply-or-explain list; only GEMMA standards imported with the model.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27556 'Standards Mapping' (2026-04-12): Map software to Forum Standaardisatie standards", - "stackiq": "grep for forum standaardisatie / pas toe of leg uit / comply-or-explain in lib and src: no hits; standards come only from the GEMMA AMEF import (element gemmaType=standaard)" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/inkoopondersteuning%20standaarden: \"De verplichte standaarden zijn: ... de open standaarden die onder het pas-toe-of-leg-uit regime van de overheid binnen het werkingsgebied vallen\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: package version shows \"Verplichte standaarden ... Ondersteuning Compliancy Testrapport\" (read 2026-09-26). Comply-or-explain standards are mixed into the mandatory set, not shown as their own list. Reached on: Package page > Standaarden; Inkoopondersteuning.", + "stackiq": "grep for forum standaardisatie / pas toe of leg uit / comply-or-explain in lib and src: no hits; standards come only from the GEMMA AMEF import (element gemmaType=standaard)", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'standaard\\|forum standaardisatie\\|comply' over src/ locales/glpi.pot returns nothing relevant; no comply or explain list in core (Setup menu src/Html.php:1330 onwards)." } }, { @@ -1450,10 +1540,10 @@ "area": "compliance", "name": "Score the correctness and completeness of the register against a rule set.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1466,7 +1556,10 @@ "providerHow": "read-from-code", "note": "No rule-based score of register correctness or completeness exists on any page.", "evidence": { - "stackiq": "grep for completeness/health score/quality score in lib and src: no hits; lib/Command/ReferencesAuditCommand.php:34 (occ stackiq:references:audit) only audits cross-app uuid references, it is not a scored rule set" + "stackiq": "grep for completeness/health score/quality score in lib and src: no hits; lib/Command/ReferencesAuditCommand.php:34 (occ stackiq:references:audit) only audits cross-app uuid references, it is not a scored rule set", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C7: automatic checks and \"Te corrigeren fouten ... Bijvoorbeeld over het ontbreken van pakketversies, of tegenstrijdigheid in de status van een pakketversie en vermelde datum distributie\" (read 2026-09-26); https://www.softwarecatalogus.nl/voortgang-verbeteren: star criteria for completeness (read 2026-09-26). Reached on: Supplier dashboard Te corrigeren fouten; Voortgang sterren.", + "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing and no rule set scores register quality; the rules engine (src/Glpi/Rules/, src/RuleCollection.php) assigns and imports data, it does not score it. The rules engine base is src/RuleCollection.php:48." } }, { @@ -1477,7 +1570,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "partial", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1491,7 +1584,10 @@ "note": "Nothing sends questionnaires to suppliers or stores their answers.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders. | Rated partial because questionnaires collect portfolio data.", - "stackiq": "grep for questionnaire/vragenlijst in lib and src: no hits; no questionnaire schema in lib/Settings/softwarecatalogus_register.json" + "stackiq": "grep for questionnaire/vragenlijst in lib and src: no hits; no questionnaire schema in lib/Settings/softwarecatalogus_register.json", + "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no questionnaire to suppliers is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: native forms (src/Glpi/Form/Form.php:92) are filled by logged in or helpdesk users and only produce tickets, changes or problems (src/Glpi/Form/Destination/FormDestinationTicket.php:47); nothing sends a questionnaire to a supplier or stores answers on an appliance." } }, { @@ -1502,7 +1598,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1517,8 +1613,10 @@ "featureConfidence": "medium", "note": "A supplier in aanbod-beheerder creates modules and services on the index pages and publishes them by setting publicationDate in the form. The dedicated publish endpoint (PUT /api/publication/...) is not called by any page (src/utils/openDataProjection.js has no importer).", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48838 'Supplier product offering (aanbod) registration' (2026-07-23): ICT suppliers publish their product offering for the municipal market with global functionality descriptions. | docs, intelligence competitor_features#27555 'Vendor Registration' (2026-04-12): ICT providers register their software offerings", - "stackiq": "src/manifest.json:592 Modules and :647 Diensten are FacetedCatalogIndexView over schema module/catalogService (CnIndexPage, showAdd default true); lib/Settings/softwarecatalogus_register.json:6779 module has provider + publicationDate (visible on form) and public read when publicationDate <= now or registeredBy Supplier" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Deze handleiding is bedoeld voor de leveranciers en legt uit hoe de leveranciers hun productportfolio kunnen aanvullen en beheren ... voeg pakket toe\" (read 2026-09-26). Reached on: Supplier login > Productportfolio.", + "stackiq": "src/manifest.json:592 Modules and :647 Diensten are FacetedCatalogIndexView over schema module/catalogService (CnIndexPage, showAdd default true); lib/Settings/softwarecatalogus_register.json:6779 module has provider + publicationDate (visible on form) and public read when publicationDate <= now or registeredBy Supplier", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: suppliers are records kept by the buying organisation, install/mysql/glpi-empty.sql:7067 glpi_suppliers, with no supplier login or offering page; profiles (src/Profile.php) cover internal users and the self-service helpdesk only." } }, { @@ -1529,7 +1627,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1544,8 +1642,10 @@ "featureConfidence": "medium", "note": "Live facet counts on reference component and standard narrow the module and service lists. Scope is whatever the RBAC read rules let the viewer see (published entries are public).", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27553 'ICT Market Orientation' (2026-04-12): Find and compare software from registered ICT providers", - "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS referenceComponent, standard, applicationService, domain for schemas module and catalogService (:102); src/views/FacetedCatalogIndexView.vue:108 CnFacetSidebar narrows CnIndexPage; route GET /api/facets/{schema} called from src/services/facets.js" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Ik ben op zoek naar een nieuw pakket voor referentiecomponent voor BAG-administratie\" and standards filters combine (read 2026-09-26); https://www.softwarecatalogus.nl/pakketten: facets Referentiecomponent and Standaard (read 2026-09-26). Reached on: Alle pakketten > filters.", + "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS referenceComponent, standard, applicationService, domain for schemas module and catalogService (:102); src/views/FacetedCatalogIndexView.vue:108 CnFacetSidebar narrows CnIndexPage; route GET /api/facets/{schema} called from src/services/facets.js", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: search covers only the organisation's own records (src/Glpi/Search/SearchEngine.php); there is no market wide catalogue and no reference component or standard to filter on (grep -ril 'gemma\\|reference component' src/ returns nothing). The marketplace (src/Glpi/Marketplace/) lists GLPI plugins, not software for a task. The search engine is src/Glpi/Search/SearchEngine.php:101; the marketplace is src/Glpi/Marketplace/Controller.php:64." } }, { @@ -1553,10 +1653,10 @@ "area": "market", "name": "Browse all organisations that offer applications or services, with search and filters.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1569,7 +1669,10 @@ "providerHow": "read-from-code", "note": "The Organisations index lists organisations with search, a type facet and a status filter. There is no filter for 'offers at least one product'; type Supplier is the proxy.", "evidence": { - "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)" + "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/leveranciers: \"Leveranciers ... Zoek in leveranciers ... 354 resultaten gevonden\", filter \"Met ondertekend addendum\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle leveranciers.", + "glpi": "source read at 11.0.9: src/Supplier.php:46 Supplier list under Management (src/Html.php:1298) with search, filters and a supplier type (install/mysql/glpi-empty.sql:7072 suppliertypes_id), but it holds only the suppliers this organisation entered, not all organisations offering to government. Reached on: Management > Suppliers (front/supplier.php)." } }, { @@ -1580,7 +1683,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1593,8 +1696,10 @@ "providerHow": "read-from-code", "note": "Nothing lets an organisation find or contact other organisations using the same product.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27557 'Contact & Collaboration' (2026-04-12): Connect with municipalities using similar products", - "stackiq": "Looked in src/components, src/views and lib/Controller for any contact or messaging between organisations sharing a module: none. Usage read rules (register :3137) hide other organisations' usages from municipalities." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle gemeenten ... inclusief contactgegevens van gemeenten ... U kunt contact onderhouden met deze gemeenten\" (read 2026-09-26). Reached on: Inlogmenu > Alle gemeenten.", + "stackiq": "Looked in src/components, src/views and lib/Controller for any contact or messaging between organisations sharing a module: none. Usage read rules (register :3137) hide other organisations' usages from municipalities.", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: each GLPI instance holds one organisation's data (entities are internal subdivisions, src/Entity.php), so there is no view of other organisations using the same product; grep -rli 'peer' src/*.php matches only relation and network code such as src/CommonDBConnexity.php, no peer organisation feature." } }, { @@ -1605,7 +1710,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1620,8 +1725,10 @@ "featureConfidence": "medium", "note": "A supplier can register a future version with status 'in development' and planned dates, which reads as a crude release plan. There is no roadmap view or declared roadmap; the overlay marks maintenance-and-supplier-roadmap as 'soon'.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48839 'Product roadmap / planning declaration' (2026-07-23): Suppliers declare product planning and release roadmap per product.", - "stackiq": "register :7651 moduleVersion with status enum in development/in use/end of support/withdrawn and dateInDevelopment/dateInUse/dateEndSupport, read public; src/manifest.json:915 Moduleversies index + ModuleversieDetail" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle pakketversies en planningen ... gelijk zichtbaar de planning van de diverse pakketversies\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facet \"Status planning ... Filter op in ontwikkeling en zie de distributie planningsdata\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle pakketversies en planningen.", + "stackiq": "register :7651 moduleVersion with status enum in development/in use/end of support/withdrawn and dateInDevelopment/dateInUse/dateEndSupport, read public; src/manifest.json:915 Moduleversies index + ModuleversieDetail", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: suppliers (install/mysql/glpi-empty.sql:7067 glpi_suppliers) carry address and contact fields only, and software versions (install/mysql/glpi-empty.sql:6900) carry no planned release date; grep -rli 'roadmap' src/*.php returns nothing." } }, { @@ -1632,7 +1739,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1647,7 +1754,10 @@ "featureConfidence": "high", "note": "Logged-in users write a rated review from the application page. Services have no detail page, so only applications can be reviewed there.", "evidence": { - "stackiq": "src/manifest.json:514 ModuleDetail bodyWidget ReviewsPanel; src/components/reviews/ReviewsPanel.vue:63 opens SubmitReviewModal; POST /api/reviews -> lib/Service/ReviewService.php:232 stamps author and forces status pending; rating 1..10 in software-review schema (:3961)" + "stackiq": "src/manifest.json:514 ModuleDetail bodyWidget ReviewsPanel; src/components/reviews/ReviewsPanel.vue:63 opens SubmitReviewModal; POST /api/reviews -> lib/Service/ReviewService.php:232 stamps author and forces status pending; rating 1..10 in software-review schema (:3961)", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no reviews are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no product review model; satisfaction surveys rate ticket handling only (src/CommonITILSatisfaction.php) and knowledge base comments (src/KnowbaseItem_Comment.php) carry no rating. Ticket satisfaction is src/CommonITILSatisfaction.php:43 and knowledge base comments src/KnowbaseItem_Comment.php:43." } }, { @@ -1658,7 +1768,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1673,7 +1783,10 @@ "featureConfidence": "high", "note": "The application page shows the approved-only average and count. Services have no detail page, so the aggregate is not shown for them.", "evidence": { - "stackiq": "lib/Service/ReviewAggregateService.php:51 approved-only average + count; GET /api/reviews/aggregate (PublicPage) called from src/utils/reviewAggregate.js imported by src/components/reviews/ReviewsPanel.vue" + "stackiq": "lib/Service/ReviewAggregateService.php:51 approved-only average + count; GET /api/reviews/aggregate (PublicPage) called from src/utils/reviewAggregate.js imported by src/components/reviews/ReviewsPanel.vue", + "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no ratings are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: with no product reviews there is no average rating; the only averages are ticket satisfaction statistics (src/CommonITILSatisfaction.php). Ticket satisfaction is src/CommonITILSatisfaction.php:43." } }, { @@ -1684,7 +1797,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1697,7 +1810,10 @@ "providerHow": "read-from-code", "note": "Each product can point at its own contact person of the supplier through the form. The application page's data widget names the old Dutch keys, so the product's contact person (and its descriptions) do not show there; the same stale keys are on SuiteDetail (src/manifest.json:683).", "evidence": { - "stackiq": "register :6856 module.contactPerson -> contactPerson with x-relation-filter organization = @object.provider; catalogService and suite also carry contactPerson; src/manifest.json:500 ModuleDetail md-data include lists 'contactpersoon', 'beschrijvingKort', 'beschrijvingLang', which are not module properties (renamed to contactPerson/shortDescription/longDescription)" + "stackiq": "register :6856 module.contactPerson -> contactPerson with x-relation-filter organization = @object.provider; catalogService and suite also carry contactPerson; src/manifest.json:500 ModuleDetail md-data include lists 'contactpersoon', 'beschrijvingKort', 'beschrijvingLang', which are not module properties (renamed to contactPerson/shortDescription/longDescription)", + "topdesk": "unknown: supplier contacts are registered per supplier (\"Registering a supplier contact\"); contacts per product are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the docs name one contact per supplier (\"Bij elke leverancier is een contactpersoon opgevoerd\"); whether a product can carry its own is not stated; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30402 (read 2026-09-26)", + "glpi": "source read at 11.0.9: contacts link to a supplier as a whole, src/Contact_Supplier.php:39 (install/mysql/glpi-empty.sql:1429 glpi_contacts_suppliers), not to a product; per application there is only the free text contact field on an appliance (src/Appliance.php:214) and the user or technician in charge. Reached on: Management > Suppliers > Contacts tab; Appliance contact field." } }, { @@ -1705,10 +1821,10 @@ "area": "market", "name": "Keep one record per supplier that every product and contract points to.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "yes", "stackiq": "yes", "built": { @@ -1722,8 +1838,10 @@ "note": "One organisation record is the supplier; products reference it and the detail page lists them. A contract reaches the supplier only through its service, not by its own field.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because Provider fact sheet.", - "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", - "stackiq": "register :2022 organization (one record, type Supplier); module.provider (:6921) and catalogService.provider (:3762) are $ref organization; catalogContract points at service (+usage), register :3252; OrganisatieDetail src/manifest.json:403 lists the supplier's services and applications" + "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier ... The Supplier Card has been created\" and \"Registering a supplier contact\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Create a new preliminary contract or preliminary supplier contract\" (read 2026-09-26). Reached on: Supporting Files > New > Supplier.", + "stackiq": "register :2022 organization (one record, type Supplier); module.provider (:6921) and catalogService.provider (:3762) are $ref organization; catalogContract points at service (+usage), register :3252; OrganisatieDetail src/manifest.json:403 lists the supplier's services and applications", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"De verbinding met de leveranciersgegevens garandeert juiste schrijfwijzes van leveranciers- en pakketnamen en juiste versienummering\" (read 2026-09-26); https://www.softwarecatalogus.nl/leveranciers: one record per supplier with contact and addenda (read 2026-09-26). There are no contracts to point to it. Reached on: Alle leveranciers > supplier page.", + "glpi": "source read at 11.0.9: one Supplier record (src/Supplier.php:46, install/mysql/glpi-empty.sql:7067) is referenced by contracts through install/mysql/glpi-empty.sql:1550 glpi_contracts_suppliers and by the financial record of any item through install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id. Reached on: Management > Suppliers." } }, { @@ -1731,10 +1849,10 @@ "area": "lifecycle", "name": "See the lifecycle phase of each application in use: planned, in use or being phased out.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "yes", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "partial", "stackiq": "yes", "built": { @@ -1749,10 +1867,11 @@ "featureConfidence": "high", "note": "Pick an organisation and its applications in use are grouped by derived lifecycle phase. The usage records themselves cannot be created or edited on any stackiq page (see life-planned-replacement).", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A1: \"Bij de oude versie kan de status gewijzigd worden in uit-te-faseren / uitgefaseerd\" (read 2026-09-26); https://www.softwarecatalogus.nl/voortgang-verbeteren: \"pakketversies hebben de status Gepland óf Uit te faseren\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: \"Vul onder Planning bij Status in gebruik in\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Planning Status.", "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", - "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | Rated partial because replacement timelines on assets.", - "stackiq": "src/manifest.json LifecycleRoadmap /portfolio-roadmap custom page -> src/views/LifecycleRoadmapView.vue:55 groups the selected organisation's usages by phase, derived from usage dates by src/utils/lifecyclePhase.js derivePhase (:408); usage.status enum Acquisition/Planned/In production/To be phased out/Phased out in lib/Settings/softwarecatalogus_register.json" + "topdesk": "https://docs.topdesk.com/en/managing-disruptions-in-your-asset-management-process.html: built-in \"operational/impacted status for assets\" (read 2026-09-26); lifecycle phases need a self-defined drop-down field (https://docs.topdesk.com/en/creating-new-fields.html). No planned, in use, phase-out model ships. Reached on: Asset card > General widget.", + "stackiq": "src/manifest.json LifecycleRoadmap /portfolio-roadmap custom page -> src/views/LifecycleRoadmapView.vue:55 groups the selected organisation's usages by phase, derived from usage dates by src/utils/lifecyclePhase.js derivePhase (:408); usage.status enum Acquisition/Planned/In production/To be phased out/Phased out in lib/Settings/softwarecatalogus_register.json", + "glpi": "source read at 11.0.9: appliances carry a status, install/mysql/glpi-empty.sql:8950 glpi_appliances.states_id and src/Appliance.php:350 search option Status, whose values are an admin defined tree dropdown src/State.php:45 (install/mysql/glpi-empty.sql:7027 glpi_states), so phases such as planned, in use and being phased out are set up and filtered on. Reached on: Management > Appliances, Status field; Setup > Dropdowns > Statuses of items." } }, { @@ -1760,10 +1879,10 @@ "area": "lifecycle", "name": "See per organisation which applications are replaced when, on a roadmap.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -1778,9 +1897,11 @@ "featureConfidence": "high", "note": "Per organisation it shows which applications are phased out or replaced and when; it is a grouped list ordered by urgency rather than a timeline chart.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"de uit te faseren applicaties van die status worden voorzien inclusief datum. Zo ontstaat inzicht in het totale huidige- en doel-landschap in 1 overzicht\" (read 2026-09-26). Dates per status, no roadmap view described. Reached on: Mijn softwarecatalogus > Pakketten > Planning.", "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", - "stackiq": "src/views/LifecycleRoadmapView.vue:28 organisation select, :55 phase groups, :96-110 phase-out date, planned replacement and link to the replacing module (:400 plannedReplacement, :423 plannedReplacementDate), ordered by nearest urgency (:428)" + "stackiq": "src/views/LifecycleRoadmapView.vue:28 organisation select, :55 phase groups, :96-110 phase-out date, planned replacement and link to the replacing module (:400 plannedReplacement, :423 plannedReplacementDate), ordered by nearest urgency (:428)", + "topdesk": "unknown: no replacement roadmap is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: replacements can be planned as projects linked to the appliance, src/Appliance.php:108 Item_Project tab (src/Item_Project.php:45) and src/Project.php:50 Project with Kanban; the Gantt view is the separate gantt plugin (src/Project.php:599 checks isActivated('gantt')). No per organisation application roadmap view exists. Reached on: Tools > Projects, Appliance > Projects tab." } }, { @@ -1788,10 +1909,10 @@ "area": "lifecycle", "name": "Find applications that overlap because they fulfil the same reference component.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1805,7 +1926,10 @@ "note": "Nothing finds applications in your landscape that fulfil the same reference component; the Reports card promises 'overlapping' software but the report does not compute it.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | Rated partial because rationalisation through capability map.", - "stackiq": "grep for overlap/redundant in lib and src finds only code comments and the Reports card description (src/manifest.json:1031 'Overlapping and ageing software'); lib/Service/PortfolioReportService.php computes TIME quadrants, EOL exposure, cloud share and cost, no grouping by reference component; the /modules facet counts modules per reference component across the whole catalogue, not your landscape" + "stackiq": "grep for overlap/redundant in lib and src finds only code comments and the Reports card description (src/manifest.json:1031 'Overlapping and ageing software'); lib/Service/PortfolioReportService.php computes TIME quadrants, EOL exposure, cloud share and cost, no grouping by reference component; the /modules facet counts modules per reference component across the whole catalogue, not your landscape", + "topdesk": "unknown: no functional classification to detect overlap is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tile \"Referentiecomponenten met meerdere pakketten: Deze tegel signaleert dat er meer dan 1 pakket(versie) bij eenzelfde referentiecomponent in productie is\" (read 2026-09-26). Reached on: Dashboard tile Referentiecomponenten met meerdere pakketten.", + "glpi": "source read at 11.0.9: no reference component model to detect overlap on, grep -rli 'reference component\\|gemma' over src/ locales/glpi.pot returns nothing; appliances only carry a free type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." } }, { @@ -1813,10 +1937,10 @@ "area": "lifecycle", "name": "Open a report of overlapping and ageing software for rationalisation.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1830,7 +1954,10 @@ "note": "The report covers ageing software (EOL exposure) with TIME quadrants, cost and a CSV export, but not overlap, even though its card says 'overlapping and ageing'.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R). | docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", - "stackiq": "appinfo/routes.php:303 GET /api/portfolio-report -> lib/Controller/PortfolioReportController.php -> lib/Service/PortfolioReportService.php + PortfolioReportDerivation.php; UI src/views/organisaties/PortfolioReport.vue (TIME chart :112, quadrant summary :126 with EOL exposure/cloud/cost, rows :176, CSV export :50)" + "stackiq": "appinfo/routes.php:303 GET /api/portfolio-report -> lib/Controller/PortfolioReportController.php -> lib/Service/PortfolioReportService.php + PortfolioReportDerivation.php; UI src/views/organisaties/PortfolioReport.vue (TIME chart :112, quadrant summary :126 with EOL exposure/cloud/cost, rows :176, CSV export :50)", + "topdesk": "unknown: no rationalisation report is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Referentiecomponenten met meerdere pakketten ... per referentiecomponent aan welke pakketversies daaraan gekoppeld zijn\" (read 2026-09-26). Overlap only, ageing not covered. Reached on: Dashboard tile.", + "glpi": "source read at 11.0.9: the built in report list src/Report.php:77 to src/Report.php:111 holds default, by contract, by year, financial, network, loan and status reports; none covers overlapping or ageing software." } }, { @@ -1838,10 +1965,10 @@ "area": "lifecycle", "name": "Record which version of an application your organisation currently runs.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -1856,7 +1983,10 @@ "featureConfidence": "low", "note": "The version an organisation runs is a field on its usage and drives the EOL badges, but no stackiq page lets the organisation set or change it.", "evidence": { - "stackiq": "lib/Settings/softwarecatalogus_register.json usage.moduleVersion ($ref moduleVersion); read by src/views/LifecycleRoadmapView.vue:397 for EOL state; ModuleversieDetail mv-related shows related usages; no usage create/edit page in src/manifest.json" + "stackiq": "lib/Settings/softwarecatalogus_register.json usage.moduleVersion ($ref moduleVersion); read by src/views/LifecycleRoadmapView.vue:397 for EOL state; ModuleversieDetail mv-related shows related usages; no usage create/edit page in src/manifest.json", + "topdesk": "unknown: versions in use are only possible as a self-defined field; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Pakketversie - selecteer de versie die in gebruik is\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", + "glpi": "source read at 11.0.9: src/Item_SoftwareVersion.php:39 records which software version is installed on which item (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions with date_install at :1074), filled by hand or by native inventory, and listed on the Software Installations tab (src/Software.php:129). Reached on: Assets > Software > Installations tab." } }, { @@ -1864,10 +1994,10 @@ "area": "lifecycle", "name": "Get notified when a supplier publishes a new version of an application you use.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1882,7 +2012,10 @@ "featureConfidence": "medium", "note": "The only rule is a register declaration, and it addresses the version's own managers and catalogue admins, not the organisations that use the application, so even if OpenRegister dispatches it a user of the application is not told.", "evidence": { - "stackiq": "lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications module-version-published (trigger created, recipients object-acl manage + group software-catalog-admins); no notification code in lib (no INotificationManager use)" + "stackiq": "lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications module-version-published (trigger created, recipients object-acl manage + group software-catalog-admins); no notification code in lib (no INotificationManager use)", + "topdesk": "unknown: no supplier version feed is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/suggesties_overnemen: \"Wanneer een leverancier een pakketversie registreert kan deze een suggestie versturen naar de gemeenten en samenwerkingen die dit pakket afnemen\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C2: \"Via de notificatiefunctie krijgt u een signaal zodra het versienummer is toegevoegd\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Suggesties; Inbox.", + "glpi": "source read at 11.0.9: GLPI has no feed of supplier releases; software versions appear only when entered or inventoried (src/SoftwareVersion.php:42), and notification events for software are licence expiry only (src/NotificationTargetSoftwareLicense.php)." } }, { @@ -1893,7 +2026,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1907,7 +2040,10 @@ "note": "You could register a database as its own 'System software' module and feed its EOL, but nothing ties it to the applications that depend on it; SBOM components carry no lifecycle.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", - "stackiq": "lib/Settings/softwarecatalogus_register.json sbomComponent has name/version/purl/licenses/type/hashes/bomRef/vexCveIds, no lifecycle or EOL field; the EOL feed (lib/Service/EolSyncService.php:290) only stamps versions of modules with eolProductSlug; no relation from an application to the platform it runs on" + "stackiq": "lib/Settings/softwarecatalogus_register.json sbomComponent has name/version/purl/licenses/type/hashes/bomRef/vexCveIds, no lifecycle or EOL field; the EOL feed (lib/Service/EolSyncService.php:290) only stamps versions of modules with eolProductSlug; no relation from an application to the platform it runs on", + "topdesk": "unknown: no technology lifecycle is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: technologies per version are recorded (\"Pakketversie is beschikbaar voor één of meerdere technologien; databases, OS, SAAS\") but no lifecycle for them is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "glpi": "source read at 11.0.9: underlying technology is held as items (database instances src/DatabaseInstance.php, operating systems, software) and each can carry a financial record with warranty and decommission date, install/mysql/glpi-empty.sql:3282 glpi_infocoms.decommission_date; there is no end of support date or lifecycle feed (grep -i 'end_of_support' install/mysql/glpi-empty.sql returns nothing). Reached on: any item > Management tab (Infocom)." } }, { @@ -1918,7 +2054,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -1932,7 +2068,10 @@ "note": "Strategic goals are not modelled.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#27466 'Strategy Alignment' (2026-04-12): Connect architecture to strategic objectives", - "stackiq": "no goal/strategy schema among the 20 in lib/Settings/softwarecatalogus_register.json; grep for strateg/doel in src/manifest.json: none" + "stackiq": "no goal/strategy schema among the 20 in lib/Settings/softwarecatalogus_register.json; grep for strateg/doel in src/manifest.json: none", + "topdesk": "unknown: no strategic goals are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no strategic goals are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -i 'strategic\\|goal\\|objective' over src/Appliance.php and src/Project.php returns nothing; no goal itemtype exists and the Appliance tabs (src/Appliance.php:98 onwards) link items, contracts, documents, tickets and projects only." } }, { @@ -1943,8 +2082,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "yes", "stackiq": "no", "built": { "state": "specified", @@ -1958,7 +2097,10 @@ "featureConfidence": "high", "note": "Listed as 'soon' in the feature overlay; nothing is built.", "evidence": { - "stackiq": "openspec/features.overlay.json maintenance-and-supplier-roadmap status 'soon'; no maintenance schema in lib/Settings/softwarecatalogus_register.json and no page in src/manifest.json" + "stackiq": "openspec/features.overlay.json maintenance-and-supplier-roadmap status 'soon'; no maintenance schema in lib/Settings/softwarecatalogus_register.json and no page in src/manifest.json", + "topdesk": "https://docs.topdesk.com/en/operations-management.html: \"In TOPdesk you can easily schedule operational activities in the user-friendly planner. If you wish to schedule a recurring activity, you can use a series\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: assets can be linked to \"Operational Activity\" cards (read 2026-09-26). Reached on: Modules > Operations Management > Planner.", + "vng-softwarecatalogus": "unknown: no maintenance announcements are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no maintenance window on an item ('Maintenance mode' in locales/glpi.pot:7534 is GLPI's own downtime switch); planned work is a change linked to the appliance, src/Appliance.php:107 Change_Item tab, with planned tasks carrying begin and end (install/mysql/glpi-empty.sql:792 glpi_changetasks, :799 begin, :800 end) shown in the planning. Reached on: Appliance > Changes tab; Assistance > Planning." } }, { @@ -1969,8 +2111,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "built", @@ -1984,7 +2126,10 @@ "featureConfidence": "high", "note": "A daily job moves Active contracts past their end date to Expired on its own. There is no 'expiring' state in the enum, so the middle step of the row does not exist.", "evidence": { - "stackiq": "lib/Service/ContractStatusService.php:77 shouldExpire and :114 expirePastContracts set Active -> Expired when endDate < now; lib/BackgroundJob/ContractStatusJob.php:57 daily, registered in appinfo/info.xml:99" + "stackiq": "lib/Service/ContractStatusService.php:77 shouldExpire and :114 expirePastContracts set Active -> Expired when endDate < now; lib/BackgroundJob/ContractStatusJob.php:57 daily, registered in appinfo/info.xml:99", + "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Status: Configurable drop-down showing the contract's lifecycle status, e.g. draft, active ... Reminder date\" (read 2026-09-26); https://docs.topdesk.com/en/terminating-a-contract.html: \"The contract will terminate once the end date passes\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: contract status is a manual dropdown (install/mysql/glpi-empty.sql:1512 glpi_contracts.states_id); expiry is computed, src/Contract.php:654 virtual 'Expiration' column from begin date, duration and renewal, and src/Contract.php:1092 cronContract sends end and notice alerts, but the status itself never moves by itself. Reached on: Management > Contracts list, Expiration column." } }, { @@ -1995,8 +2140,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -2011,7 +2156,10 @@ "featureConfidence": "high", "note": "An expired contract can be raised for renewal as a decidiq decision and the outcome shows on the contract's approval panel. It needs the decidiq app installed; without it the panel hides the action.", "evidence": { - "stackiq": "src/components/contracts/ContractApprovalPanel.vue:183 canSubmitRenewal for status Expired; POST /api/contracts/{uuid}/approval/renewal -> ContractApprovalService.php:254 with decisionType contract-renewal; lib/EventListener/DecisionConcludedListener.php projects the outcome (approvalState, status Active) via DECISION_CONCLUDED_EVENTS registered in lib/AppInfo/Application.php:830" + "stackiq": "src/components/contracts/ContractApprovalPanel.vue:183 canSubmitRenewal for status Expired; POST /api/contracts/{uuid}/approval/renewal -> ContractApprovalService.php:254 with decisionType contract-renewal; lib/EventListener/DecisionConcludedListener.php projects the outcome (approvalState, status Active) via DECISION_CONCLUDED_EVENTS registered in lib/AppInfo/Application.php:830", + "topdesk": "https://docs.topdesk.com/en/extending-a-contract.html: \"Under Create , select Extend contract ... The contract is now a preliminary contract ... Click Validate Contract\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Sequence Number ... goes up by 1 each time the contract is extended ... so you can trace the contract's extension history\" (read 2026-09-26). Reached on: Contract card > Create > Extend contract.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: src/Contract.php:60 to :62 renewal kinds never, tacit and express, with the renewal computation in the alert cron (src/Contract.php:1293); there is no renewal decision record or outcome, only the contract's renewal setting and an optional approval through a change. Reached on: Management > Contracts, Renewal field." } }, { @@ -2023,7 +2171,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "no", "built": { "state": "none", @@ -2037,8 +2185,10 @@ "featureConfidence": "medium", "note": "The application page has no contracts list, and a contract links to a usage and a service rather than the application, so there is no path from an application to its contracts in the UI.", "evidence": { - "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | Rated yes because contracts tracked against assets.", - "stackiq": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it" + "glpi": "source read at 11.0.9: src/Appliance.php:99 and src/Software.php:131 add the Contract_Item tab (src/Contract_Item.php:43, install/mysql/glpi-empty.sql:1536 glpi_contracts_items) listing every contract of the application. Reached on: Management > Appliances > Contracts tab.", + "stackiq": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it", + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: assets link to \"Service cards\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"On the Services tab, link the services that apply to this contract\" (read 2026-09-26). Contract to asset runs through the service. Reached on: Contract > Services tab > Service > Links > Assets.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" } }, { @@ -2050,7 +2200,7 @@ "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "yes", "built": { "state": "built", @@ -2065,8 +2215,10 @@ "note": "The portfolio report sums annualised contract cost per organisation and TIME quadrant, and the license posture page per vendor. The Dashboard only counts contracts.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS cost.", - "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts | docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets.", - "stackiq": "lib/Service/PortfolioReportDerivation.php:163 annualisedCost (Monthly x12, Annually x1, One-off separate); lib/Service/PortfolioReportService.php:337 sumContractCost per quadrant; src/views/organisaties/PortfolioReport.vue:167 and :248 show annualised cost; src/utils/contractCost.js:111 totalAnnualisedCost used by src/views/LicensePostureView.vue per vendor" + "glpi": "source read at 11.0.9: contract costs have a period and a budget, install/mysql/glpi-empty.sql:1458 glpi_contractcosts with begin_date, end_date, cost and budgets_id; the contract list sums them in the 'Total cost' column (src/Contract.php:773) and a budget with a period shows spend per entity and type (src/Budget.php:537 showValuesByEntity). Reached on: Management > Contracts (Total cost column); Management > Budgets.", + "stackiq": "lib/Service/PortfolioReportDerivation.php:163 annualisedCost (Monthly x12, Annually x1, One-off separate); lib/Service/PortfolioReportService.php:337 sumContractCost per quadrant; src/views/organisaties/PortfolioReport.vue:167 and :248 show annualised cost; src/utils/contractCost.js:111 totalAnnualisedCost used by src/views/LicensePostureView.vue per vendor", + "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Costs (Services) ... Total internal cost, based on the service levels linked\" (read 2026-09-26); https://docs.topdesk.com/en/obtain-insights-with-asset-type-report.html: \"do you need an overview of the total costs of new assets? Use the Asset Type Report\" (read 2026-09-26). Reached on: Contract card > Financial; Asset Type Report.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" } }, { @@ -2074,7 +2226,7 @@ "area": "contracts", "name": "Record the licence model of an application, such as open source, per user or per organisation.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", @@ -2092,8 +2244,10 @@ "featureConfidence": "medium", "note": "An application records open versus closed source and which open-source licence. There is no licence metric such as per user, per organisation or per seat.", "evidence": { - "glpi": "docs, intelligence competitor_features#48901 'License management' (2026-07-23): Track license entitlements, compliance and expirations.", - "stackiq": "register :6937 module.licentietype enum Closed source/Open source and module.licence (five open-source licence names); catalogContract.contractType enum SLA/Licence/Maintenance (:3341)" + "glpi": "source read at 11.0.9: each licence has a type, install/mysql/glpi-empty.sql:6775 glpi_softwarelicenses.softwarelicensetypes_id, an admin editable dropdown seeded with types such as OEM (install/empty_data.php:9294). Reached on: Management > Licenses (front/softwarelicense.php), Type field.", + "stackiq": "register :6937 module.licentietype enum Closed source/Open source and module.licence (five open-source licence names); catalogContract.contractType enum SLA/Licence/Maintenance (:3341)", + "topdesk": "unknown: licence cards hold number, code, purchase and expiration date; a licence model is only possible as a self-defined field; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/nieuws: \"is er de leverancier Open Source Pakketten aangemaakt. Onder deze leverancier staat nu een aantal veelgebruikte open source pakketten geregistreerd\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: Archi listed under supplier \"Open Source pakketten\", version \"Open source\" (read 2026-09-26). Other licence models are not recorded. Reached on: Alle pakketten > Leverancier Open Source pakketten." } }, { @@ -2104,7 +2258,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2117,7 +2271,10 @@ "providerHow": "read-from-code", "note": "The page shows the open-source share of the running portfolio with per-vendor and per-organisation breakdowns, computed at read time.", "evidence": { - "stackiq": "src/views/LicensePostureView.vue:11 open-source vs closed-source share weighted by in-production usage, :64 per-vendor rollup, per-organisation open-source-first report; derived in src/utils/licensePosture.js" + "stackiq": "src/views/LicensePostureView.vue:11 open-source vs closed-source share weighted by in-production usage, :64 per-vendor rollup, per-organisation open-source-first report; derived in src/utils/licensePosture.js", + "topdesk": "unknown: no portfolio licence posture is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: licences can be listed and filtered by type in search (install/mysql/glpi-empty.sql:6775 softwarelicensetypes_id), but the dashboard's per type charts cover asset types and Software only (src/Glpi/Dashboard/Grid.php:1452), not licences, and no portfolio share view exists. Reached on: Management > Licenses, filtered by type." } }, { @@ -2129,7 +2286,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "no", "built": { "state": "none", @@ -2143,8 +2300,10 @@ "featureConfidence": "high", "note": "No field records licences bought or in use. The overlay lists license-and-seat-tracking as 'soon'.", "evidence": { - "glpi": "docs, intelligence competitor_features#48901 'License management' (2026-07-23): Track license entitlements, compliance and expirations. | docs, intelligence competitor_features#3270 'License Management' (2026-03-28): Track software licenses, compliance, and expiration", - "stackiq": "grep for seat/licence count across lib/, src/ and the register finds no seat or quantity field on catalogContract (:3252), module or usage" + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:6774 glpi_softwarelicenses.number is the bought quantity; src/SoftwareLicense.php:158 computeValidityIndicator compares it with assigned items (Item_SoftwareLicense::countForLicense) and flags over use in red (src/SoftwareLicense.php:1030), with allow_overquota at install/mysql/glpi-empty.sql:6797. Reached on: Assets > Software > Licenses tab.", + "stackiq": "grep for seat/licence count across lib/, src/ and the register finds no seat or quantity field on catalogContract (:3252), module or usage", + "topdesk": "https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"add fields to fill the number of licences you have purchased and still have left ... the Relationship grid widget on the software cards will display details about the licences\" (read 2026-09-26). Reached on: Asset Management > software card > Relationship grid.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" } }, { @@ -2155,8 +2314,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "partial", "stackiq": "no", "built": { "state": "none", @@ -2168,7 +2327,10 @@ "providerHow": "read-from-code", "note": "Without seat or consumption data there is nothing to compute an effective licence position from.", "evidence": { - "stackiq": "No entitlement or consumption fields exist (see ctr-seat-count); no service computes a licence position in lib/Service/" + "stackiq": "No entitlement or consumption fields exist (see ctr-seat-count); no service computes a licence position in lib/Service/", + "topdesk": "https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"Knowing which software tools are used by whom ... the legal implications of using a tool without being licensed\" (read 2026-09-26). Entitlement against linked users, no measured consumption. Reached on: Asset Management > licence cards.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: entitlement is compared with licence assignments (src/SoftwareLicense.php:158 computeValidityIndicator), while measured installations are counted separately (src/Item_SoftwareVersion.php:39); core has no computed effective licence position report reconciling the two for an audit. Reached on: Assets > Software > Licenses and Installations tabs." } }, { @@ -2180,7 +2342,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "no", "built": { "state": "none", @@ -2192,8 +2354,10 @@ "providerHow": "read-from-code", "note": "Contracts carry a cost and a period, but there is no budget to charge them against.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145790 'C-reporting-1 A budget the case costs are charged against, with a period.': glpi: Budgets (Management, Budgets, front/budget.php) Lane findings: D-glpi-37. | Rated yes because budgets, source-read 2026-09-14.", - "stackiq": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)" + "glpi": "source read at 11.0.9: src/Budget.php:46 Budget with a period and value (install/mysql/glpi-empty.sql:306 begin_date, :307 end_date, :308 value); contract costs (install/mysql/glpi-empty.sql:1466 budgets_id) and financial records (src/Infocom.php:599 budgets_id check) are charged to it. Reached on: Management > Budgets.", + "stackiq": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)", + "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Budget holder: Cost-accounting owner of the contract\" and \"Applicable to ... Budget holder\" (read 2026-09-26). No budget with a period is described. Reached on: Contract card > Financial.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" } }, { @@ -2204,7 +2368,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "partial", + "glpi": "yes", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2217,8 +2381,10 @@ "providerHow": "read-from-code", "note": "No purchase value, useful life or depreciation is recorded or computed.", "evidence": { - "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts | Rated partial because TCO tracking.", - "stackiq": "grep for depreciation/afschrijving finds nothing in lib/, src/ or the register" + "glpi": "source read at 11.0.9: the financial record of any item, licences included (src/SoftwareLicense.php:245 Infocom tab), carries depreciation type, duration and coefficient (install/mysql/glpi-empty.sql:3269 sink_time, :3270 sink_type, :3271 sink_coeff); src/Infocom.php:872 Linear and degressive types and src/Infocom.php:1085 linearAmortise compute the table. Reached on: Management > Licenses > Management tab.", + "stackiq": "grep for depreciation/afschrijving finds nothing in lib/, src/ or the register", + "topdesk": "unknown: depreciation is not mentioned (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" } }, { @@ -2229,8 +2395,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "yes", + "topdesk": "partial", "stackiq": "yes", "built": { "state": "built", @@ -2245,7 +2411,10 @@ "featureConfidence": "medium", "note": "The contract page has a Documents files panel for the signed contract, plus a document reference field.", "evidence": { - "stackiq": "src/manifest.json:567 ContractDetail ct-files integration 'files' (Documents panel); catalogContract.documentReference text field (register :3252)" + "stackiq": "src/manifest.json:567 ContractDetail ct-files integration 'files' (Documents panel); catalogContract.documentReference text field (register :3252)", + "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"You can view the contracts in a variety of formats, including PDF\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Archive Number (Free text) Reference to a physical or external archived copy of the contract document\" (read 2026-09-26). Reached on: Contract card.", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: src/Contract.php:126 adds the Documents tab (Document_Item) to every contract, storing the signed file in install/mysql/glpi-empty.sql:2585 glpi_documents. Reached on: Management > Contracts > Documents tab." } }, { @@ -2256,7 +2425,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -2270,7 +2439,10 @@ "note": "The portfolio report shows each application in use with its cloud model and annualised cost, which lets you pick out SaaS spend. There is no SaaS subscription list and nothing discovers purchases made outside IT.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates", - "stackiq": "usage.cloudDienstverleningsmodel (register :3050) plus contract cost; lib/Service/PortfolioReportService.php:302 per-usage annualised cost and cloud-transition share; src/views/organisaties/PortfolioReport.vue:166 cloudTransitionLabel per row" + "stackiq": "usage.cloudDienstverleningsmodel (register :3050) plus contract cost; lib/Service/PortfolioReportService.php:302 per-usage annualised cost and cloud-transition share; src/views/organisaties/PortfolioReport.vue:166 cloudTransitionLabel per row", + "topdesk": "unknown: no SaaS spend tracking is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -i 'saas' over src/ returns nothing; spend is only what is entered on contracts and financial records (install/mysql/glpi-empty.sql:1458 glpi_contractcosts), with no discovery of subscriptions bought outside IT." } }, { @@ -2278,10 +2450,10 @@ "area": "security", "name": "Register a known vulnerability with its CVE code and severity score.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2294,8 +2466,10 @@ "providerHow": "read-from-code", "note": "A vulnerability is registered with CVE code and CVSS score, and a severity band is derived from the score.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "stackiq": "src/views/KwetsbaarhedenView.vue:378 reportVulnerability opens the generic ObjectModal for 'vulnerability'; register.json:1619 vulnerability schema with cveCode (pattern CVE-yyyy-n, :1679) and cvssScore 0-10" + "vng-softwarecatalogus": "unknown: no vulnerability register is described; the docs do not state its absence either (the IBD-foto export only hands CPE identifiers to the IBD); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Hoe%20maak%20je%20een%20ICT-foto%20voor%20de%20IBD%3F (read 2026-09-26)", + "stackiq": "src/views/KwetsbaarhedenView.vue:378 reportVulnerability opens the generic ObjectModal for 'vulnerability'; register.json:1619 vulnerability schema with cveCode (pattern CVE-yyyy-n, :1679) and cvssScore 0-10", + "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'cve\\|vulnerab\\|cvss' over src/ templates/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74 (a PHP version warning) and a session comment at src/Session.php:1085; no vulnerability itemtype exists." } }, { @@ -2306,7 +2480,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -2319,7 +2493,10 @@ "providerHow": "read-from-code", "note": "A vulnerability links to applications, not to specific versions. Per-version affectedness only shows as a computed match against a version's imported SBOM.", "evidence": { - "stackiq": "register.json:1701 vulnerability.modules links to module (applications), not moduleVersion; version level only via read-time SBOM match (src/utils/sbomVulnerabilityMatch.js, sbomComponent.vexCveIds register.json:8024) on the ModuleversieDetail Components tab" + "stackiq": "register.json:1701 vulnerability.modules links to module (applications), not moduleVersion; version level only via read-time SBOM match (src/utils/sbomVulnerabilityMatch.js, sbomComponent.vexCveIds register.json:8024) on the ModuleversieDetail Components tab", + "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no vulnerability model (see src/Glpi/System/Requirement/PhpSupportedVersion.php:74 as the only 'vulnerabilities' hit), so nothing links to software versions (install/mysql/glpi-empty.sql:6900)." } }, { @@ -2330,7 +2507,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2343,7 +2520,10 @@ "providerHow": "read-from-code", "note": "An SBOM in CycloneDX JSON or SPDX 2.x JSON can be uploaded for a version. XML and tag-value formats are not accepted.", "evidence": { - "stackiq": "src/components/sbom/SbomComponentsPanel.vue:53-90 upload control (.json) -> POST /api/moduleversies/{uuid}/sbom (appinfo/routes.php:92) -> lib/Controller/SbomController.php:129 importSbom -> lib/Service/SbomParserService.php:77 parse (CycloneDX JSON) and :127 parseSpdx (SPDX 2.x JSON)" + "stackiq": "src/components/sbom/SbomComponentsPanel.vue:53-90 upload control (.json) -> POST /api/moduleversies/{uuid}/sbom (appinfo/routes.php:92) -> lib/Controller/SbomController.php:129 importSbom -> lib/Service/SbomParserService.php:77 parse (CycloneDX JSON) and :127 parseSpdx (SPDX 2.x JSON)", + "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; inventory import (src/Glpi/Inventory/) takes glpi-agent JSON only. Inventory import is src/Glpi/Inventory/Inventory.php:106." } }, { @@ -2354,7 +2534,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2367,7 +2547,10 @@ "providerHow": "read-from-code", "note": "Matching is deliberately local, against vulnerabilities typed into the catalogue. No public CVE feed is read.", "evidence": { - "stackiq": "src/utils/sbomVulnerabilityMatch.js header: 'no HTTP request to an external advisory feed is ever made'; lib/Service/EolSyncService.php syncs endoflife.date support dates, not CVEs" + "stackiq": "src/utils/sbomVulnerabilityMatch.js header: 'no HTTP request to an external advisory feed is ever made'; lib/Service/EolSyncService.php syncs endoflife.date support dates, not CVEs", + "topdesk": "unknown: no CVE matching is described; the roadmap card https://tip.topdesk.com/c/186-automated-asset-scanning-tool (under consideration) mentions monitoring \"security vulnerabilities\" as a future idea; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the catalogue does not match CVEs itself; its \"IBD-foto\" export lists supplier, product and CPE so the IBD can do so; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Hoe%20maak%20je%20een%20ICT-foto%20voor%20de%20IBD%3F (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'cve' over src/ templates/ finds no feed matching (only src/Glpi/System/Requirement/PhpSupportedVersion.php:74 text); no pluginsGLPI cve repository exists (git ls-remote https://github.com/pluginsGLPI/cve: repository not found)." } }, { @@ -2378,7 +2561,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2392,7 +2575,10 @@ "note": "Only individual vulnerabilities get a severity band. No application gets a combined score from its vulnerabilities and support status.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks | Rated partial because technology risk.", - "stackiq": "src/utils/vulnerabilitySeverity.js derives a severity band per vulnerability from CVSS; no per-application risk score in lib/ or src/ (searched risk)" + "stackiq": "src/utils/vulnerabilitySeverity.js derives a severity band per vulnerability from CVSS; no per-application risk score in lib/ or src/ (searched risk)", + "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: with no vulnerability data (only hit src/Glpi/System/Requirement/PhpSupportedVersion.php:74) and no support status field on software (install/mysql/glpi-empty.sql:6856 glpi_softwares), no risk score is computed; grep -i 'risk' over src/Appliance.php src/Software.php returns nothing." } }, { @@ -2403,7 +2589,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2416,7 +2602,10 @@ "providerHow": "read-from-code", "note": "The exposure row shows which version is deployed, but no record says which version fixes the vulnerability, so patch status cannot be seen.", "evidence": { - "stackiq": "register.json:1619 vulnerability has no fixed-in version field; src/utils/vulnerabilityExposure.js computeExposure carries the deployed moduleVersion per usage but nothing compares it to a fix" + "stackiq": "register.json:1619 vulnerability has no fixed-in version field; src/utils/vulnerabilityExposure.js computeExposure carries the deployed moduleVersion per usage but nothing compares it to a fix", + "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: installed versions are known (src/Item_SoftwareVersion.php:39) but no vulnerability or fixed in version exists to compare against (grep -rli 'cve' src/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74)." } }, { @@ -2427,7 +2616,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2440,7 +2629,10 @@ "providerHow": "read-from-code", "note": "All vulnerabilities are listed with severity filters and each opens in the record form. The separate KwetsbaarheidDetail page is not what a row opens.", "evidence": { - "stackiq": "src/manifest.json:969 Kwetsbaarheden custom page -> src/views/KwetsbaarhedenView.vue table with severity tabs; row click openDetail (:417) opens the record in the generic ObjectModal" + "stackiq": "src/manifest.json:969 Kwetsbaarheden custom page -> src/views/KwetsbaarhedenView.vue table with severity tabs; row click openDetail (:417) opens the record in the generic ObjectModal", + "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no vulnerability itemtype and no such entry in any menu (src/Html.php:1295 to :1334 list Management, Tools, Administration and Setup types)." } }, { @@ -2451,8 +2643,8 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -2464,8 +2656,10 @@ "providerHow": "read-from-code", "note": "Organisations are created on the index with their type. The required contactsUid is a Nextcloud Contacts UID the form asks for as text, which is awkward but does not block the capability.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27555 'Vendor Registration' (2026-04-12): ICT providers register their software offerings | docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", - "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization (Add form); register :2022 organization.type enum Municipality/Supplier/Collaboration/Community, required contactsUid + type" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Als leverancier kunt u zich aanmelden door de volgende gegevens te sturen naar softwarecatalogus@vng.nl\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C4 roles for gemeente and samenwerking accounts (read 2026-09-26); organisation types gemeente, samenwerking, leverancier. Reached on: Registration via VNG helpdesk.", + "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization (Add form); register :2022 organization.type enum Municipality/Supplier/Collaboration/Community, required contactsUid + type", + "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier ... In the Tasks block, specify whether first or second line incidents, or services or changes, may be assigned to the supplier\" (read 2026-09-26); branches are registered as Branch cards (https://docs.topdesk.com/en/drop-down-lists-settings.html \"the Person and Branch cards\"). Reached on: Supporting Files > New > Supplier / Branch.", + "glpi": "source read at 11.0.9: external organisations are suppliers with a type dropdown (src/Supplier.php:46, install/mysql/glpi-empty.sql:7072 suppliertypes_id); the organisation's own units are entities (src/Entity.php:58). There is no generic organisation register covering municipalities or cooperations. Reached on: Management > Suppliers; Administration > Entities." } }, { @@ -2473,10 +2667,10 @@ "area": "organisations", "name": "Review a self-registered organisation in a queue before it becomes active.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2491,7 +2685,10 @@ "featureConfidence": "high", "note": "An admin reviews pending self-registrations and approves or rejects them. Approval sets registrationStatus and publication, but leaves the separate status field at Draft, which is what user provisioning waits for (see org-status).", "evidence": { - "stackiq": "src/views/settings/StackiqSettings.vue:92 ModerationQueue (type organisation) -> src/utils/adminApi.js -> GET /api/moderation/pending, POST /api/moderation/{uuid}/approve|reject; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; lib/Service/ModerationService.php:230 approval sets registrationStatus active and stamps publicationDate (:173)" + "stackiq": "src/views/settings/StackiqSettings.vue:92 ModerationQueue (type organisation) -> src/utils/adminApi.js -> GET /api/moderation/pending, POST /api/moderation/{uuid}/approve|reject; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; lib/Service/ModerationService.php:230 approval sets registrationStatus active and stamps publicationDate (:173)", + "topdesk": "unknown: no review queue for organisations is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Om te kunnen deelnemen aan de softwarecatalogus controleren wij of de leverancier voldoet aan de richtlijnen van de softwarecatalogus\" (read 2026-09-26). Manual review by e-mail, no queue described.", + "glpi": "source read at 11.0.9: suppliers are created by staff (src/Supplier.php:75 sets is_active on a new record) and there is no self registration or approval queue for organisations; grep -i 'moderat' over src/Supplier.php src/Entity.php returns nothing." } }, { @@ -2502,7 +2699,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2515,7 +2712,10 @@ "providerHow": "read-from-code", "note": "No working path moves an organisation between Draft, Active and Inactive: the field is hidden on the form and locked on the detail page, the status dialog is orphaned, and the Nextcloud dashboard widget still uses the old Dutch values so it lists nothing and would write an invalid value.", "evidence": { - "stackiq": "register organization.status enum Draft/Active/Inactive is visible:false (:2022); src/manifest.json:403 OrganisatieDetail overrides status editable:false; src/modals/object/ChangeOrganisatieStatusDialog.vue:211 is never opened (no setDialog('changeOrganisatieStatus') in src); src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters status 'concept' and :129 writes 'actief', neither an enum value" + "stackiq": "register organization.status enum Draft/Active/Inactive is visible:false (:2022); src/manifest.json:403 OrganisatieDetail overrides status editable:false; src/modals/object/ChangeOrganisatieStatusDialog.vue:211 is never opened (no setDialog('changeOrganisatieStatus') in src); src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters status 'concept' and :129 writes 'actief', neither an enum value", + "topdesk": "unknown: cards can be archived; concept, active, inactive states for organisations are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: suppliers carry a \"heeft geldig convenant\" flag and may be removed, but no concept, active, inactive status is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/leveranciers (read 2026-09-26)", + "glpi": "source read at 11.0.9: a supplier is active or inactive, src/Supplier.php:365 is_active search option (install/mysql/glpi-empty.sql:7087 glpi_suppliers.is_active); there is no concept state. Reached on: Management > Suppliers, Active field." } }, { @@ -2526,8 +2726,8 @@ "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "yes", + "topdesk": "partial", "stackiq": "yes", "built": { "state": "built", @@ -2539,8 +2739,10 @@ "providerHow": "read-from-code", "note": "Contact persons are listed on the organisation with their function and roles. The Contactpersonen index page exists but has no menu entry.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27557 'Contact & Collaboration' (2026-04-12): Connect with municipalities using similar products", - "stackiq": "src/manifest.json:418 OrganisatieDetail org-contactpersonen object-list (role, roles) with rowRoute ContactpersoonDetail; register :1788 contactPerson (contactsUid, role, organization, roles enum of catalogue roles)" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30402: \"Bij elke leverancier is een contactpersoon opgevoerd. Deze persoon is verantwoordelijk voor de inhoud\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E4 contact details of municipalities (read 2026-09-26). One contact, no roles. Reached on: Supplier page header.", + "stackiq": "src/manifest.json:418 OrganisatieDetail org-contactpersonen object-list (role, roles) with rowRoute ContactpersoonDetail; register :1788 contactPerson (contactsUid, role, organization, roles enum of catalogue roles)", + "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier contact ... The Supplier card where the contact person is active must be registered first\" (read 2026-09-26). Roles per contact are not described. Reached on: Supporting Files > New > Supplier Contact.", + "glpi": "source read at 11.0.9: contacts (src/Contact.php:45, install/mysql/glpi-empty.sql:1390 glpi_contacts) carry a contact type and a title (:1402 contacttypes_id, :1405 usertitles_id) and are linked to suppliers through src/Contact_Supplier.php:39. Reached on: Management > Contacts; Supplier > Contacts tab." } }, { @@ -2548,11 +2750,11 @@ "area": "organisations", "name": "Give a colleague access to your organisation's part of the catalogue.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "yes", + "topdesk": "partial", "stackiq": "yes", "built": { "state": "built", @@ -2565,7 +2767,10 @@ "providerHow": "read-from-code", "note": "A beheerder of the organisation grants an existing Nextcloud user access to it from the header switcher; membership is stored by OpenRegister. It adds existing users; it does not send an invitation to a new person.", "evidence": { - "stackiq": "src/components/organisations/OrganisationSwitcher.vue:48 'Manage members' (isBeheerder) opens src/modals/GrantOrganisationAccessModal.vue; POST /api/organisations/{uuid}/members -> lib/Controller/OrganisationMembersController.php:108 authorizeBeheerder then OpenRegister joinOrganisation (:123)" + "stackiq": "src/components/organisations/OrganisationSwitcher.vue:48 'Manage members' (isBeheerder) opens src/modals/GrantOrganisationAccessModal.vue; POST /api/organisations/{uuid}/members -> lib/Controller/OrganisationMembersController.php:108 authorizeBeheerder then OpenRegister joinOrganisation (:123)", + "topdesk": "https://docs.topdesk.com/en/step-2, operator-import-with-a-linked-person.html: \"Create new operators via import\" (read 2026-09-26); permissions via permission groups (https://docs.topdesk.com/en/automated-actions.html). Administrators create accounts; no invitation flow. Reached on: Supporting Files > Operators.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/gebruikersbeheer: \"Beheerders van gemeenten, samenwerkingen of leveranciers kunnen voor collega's een account aanmaken ... ontvangt deze nieuwe gebruiker een e-mail met daarin de inloginstructies\" (read 2026-09-26). Reached on: Menu > Gebruikersbeheer > Gebruiker toevoegen.", + "glpi": "source read at 11.0.9: an administrator gives a user a profile on an entity, install/mysql/glpi-empty.sql:5917 glpi_profiles_users with profiles_id and entities_id, set on the user's Authorizations tab or automatically by authorisation rules (src/RuleRight.php:297 profiles_id action, :273 entities_id action). There is no emailed invitation link. Reached on: Administration > Users > Authorizations tab." } }, { @@ -2573,10 +2778,10 @@ "area": "organisations", "name": "Act for more than one organisation with one account and switch between them.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2590,7 +2795,10 @@ "providerHow": "read-from-code", "note": "A user who belongs to several organisations switches the active one from the header; OpenRegister holds the memberships.", "evidence": { - "stackiq": "src/components/organisations/OrganisationSwitcher.vue:197 POST /apps/openregister/api/organisations/{uuid}/set-active; mounted in src/App.vue:55" + "stackiq": "src/components/organisations/OrganisationSwitcher.vue:197 POST /apps/openregister/api/organisations/{uuid}/set-active; mounted in src/App.vue:55", + "topdesk": "unknown: one account acting for several organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4: \"Een account kan ook beide rollen gekregen hebben. In het inlogmenu kan dan van rol gewisseld worden ... Gecombineerde rollen kunnen alleen door VNG Realisatie aangemaakt worden\" (read 2026-09-26). Reached on: Inlogmenu > rol wisselen.", + "glpi": "source read at 11.0.9: one user can hold several profile and entity pairs (install/mysql/glpi-empty.sql:5917 glpi_profiles_users) and switch between them in the session, src/Session.php:461 changeActiveEntities and src/Session.php:592 changeProfile. Reached on: user menu, entity and profile selector." } }, { @@ -2601,7 +2809,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -2614,7 +2822,10 @@ "providerHow": "read-from-code", "note": "An admin can merge a municipality into another and its usages, contacts and contracts follow. A supplier takeover leaves the source's applications and services pointing at the tombstoned supplier, because module and service provider fields are not in the relation map.", "evidence": { - "stackiq": "src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail; POST /api/organisaties/{uuid}/merge -> lib/Controller/MergeController.php:142 isAdmin; lib/Service/MergeOrganisatieService.php:111 re-points usage.consumer/participants, contactPerson.organization, connection.provider and @self.organisation of catalogContract/compliancy; module.provider and catalogService.provider are not re-pointed" + "stackiq": "src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail; POST /api/organisaties/{uuid}/merge -> lib/Controller/MergeController.php:142 isAdmin; lib/Service/MergeOrganisatieService.php:111 re-points usage.consumer/participants, contactPerson.organization, connection.provider and @self.organisation of catalogContract/compliancy; module.provider and catalogService.provider are not re-pointed", + "topdesk": "unknown: merging organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: entities cannot be merged, src/Entity.php:202 forbids the dropdown merge action for Entity; records can be moved into another entity with src/Transfer.php:50 Transfer (massive action add_transfer_list, src/MassiveAction.php:598), keeping or cleaning linked items per transfer options. Reached on: Administration > Entities; list Actions > Add to transfer list." } }, { @@ -2625,7 +2836,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "partial", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -2638,8 +2849,10 @@ "providerHow": "read-from-code", "note": "The merge panel shows per-type counts of what would be re-pointed before the admin confirms. It inherits the merge's blind spot: module and service provider links are not counted because they are not moved.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#146004 'C-configuration-95 The product shows what an import or a migration will change before it writes.': glpi: Form export and import (Form/ExportController.php, Form/Import/Step1IndexController.php through Step4ExecuteController.php) Lane findings: D-glpi-11. | Rated partial because import previews before writing; not for merges, source-read 2026-09-14.", - "stackiq": "src/components/organisations/OrganisationMergePanel.vue:324 organisatieStore.dryRunMerge shows dryRunCounts before execute; POST /api/organisaties/{uuid}/merge/dry-run -> lib/Service/MergeOrganisatieService.php:160 dryRun" + "glpi": "source read at 11.0.9: with no merge (src/Entity.php:202 forbids merge for Entity) there is nothing to preview; the transfer (src/Transfer.php:50) runs directly without a what would change report.", + "stackiq": "src/components/organisations/OrganisationMergePanel.vue:324 organisatieStore.dryRunMerge shows dryRunCounts before execute; POST /api/organisaties/{uuid}/merge/dry-run -> lib/Service/MergeOrganisatieService.php:160 dryRun", + "topdesk": "unknown: merging organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -2647,11 +2860,11 @@ "area": "organisations", "name": "Map catalogue roles such as administrator, buyer and civil servant onto user groups.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "built", @@ -2663,8 +2876,10 @@ "providerHow": "read-from-code", "note": "An admin configures which groups count as generic users, organisation admins and super users. The catalogue roles themselves map to fixed, hard-coded group names and by organisation type, so an admin cannot map e.g. 'buyer' onto a group of their choice.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141837 '11.19 User, role and department administration in the app': `/front/user.form.php`, `/front/profile.form.php` (`src/Profile.php`, `src/ProfileRight.php:46`), `/front/group.form.php`, and the three-way user x profile x entity grant `src/Profile_User.php:320` with a recursive flag | Rated yes because user, profile and entity administration, source-read 2026-09-14.", - "stackiq": "src/views/settings/StackiqSettings.vue:80 UserGroupsConfiguration -> GET/POST /api/user-groups/config (src/store/modules/settings.js:830); lib/Controller/SettingsController.php:3379; lib/Service/Stackiq/GroupHandler.php:103 generic groups, :167 fixed role groups (aanbod-beheerder, gebruik-beheerder, ...), group choice by organisation type (:471)" + "glpi": "source read at 11.0.9: roles are profiles with per right settings (src/Profile.php:55), mapped onto groups and directory attributes by authorisation rules, src/RuleRight.php:236 group criterion and src/RuleRight.php:297 profile action. Reached on: Administration > Profiles; Administration > Rules > Authorizations assignment rules.", + "stackiq": "src/views/settings/StackiqSettings.vue:80 UserGroupsConfiguration -> GET/POST /api/user-groups/config (src/store/modules/settings.js:830); lib/Controller/SettingsController.php:3379; lib/Service/Stackiq/GroupHandler.php:103 generic groups, :167 fixed role groups (aanbod-beheerder, gebruik-beheerder, ...), group choice by organisation type (:471)", + "topdesk": "https://docs.topdesk.com/en/automated-actions.html: \"Assign these permissions via Supporting Files > Permission Groups > [Permission Group]\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: permission tables per module (read 2026-09-26). Reached on: Supporting Files > Permission Groups.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4 roles gemeentebeheerder, raadpleger, samenwerkingsbeheerder; \"Er is géén rol voor het raadplegen van een samenwerking\" (read 2026-09-26). Fixed roles, no mapping onto groups. Reached on: Gebruikersbeheer." } }, { @@ -2688,9 +2903,10 @@ "providerHow": "read-from-code", "note": "Stackiq does nothing for single sign-on. A Nextcloud admin can add an identity provider app, but that is the platform, not a stackiq page.", "evidence": { - "glpi": "docs, intelligence competitor_features#48908 'LDAP / SSO' (2026-07-23): Directory authentication and SSO.", - "topdesk": "docs, intelligence competitor_features#48935 'SSO integration' (2026-07-23): SAML / SSO authentication.", - "stackiq": "No OIDC/SAML code in lib/ or src/; stackiq creates local Nextcloud users with a password (lib/Service/Stackiq/ContactPersonHandler.php:292)" + "glpi": "source read at 11.0.9: src/Auth.php:106 EXTERNAL (web server provided identity, for example a SAML or OIDC module in front of GLPI), src/Auth.php:107 CAS with phpCAS::client at src/Auth.php:557, and src/Auth.php:108 X509 certificates, next to LDAP at src/Auth.php:105. Reached on: Setup > Authentication > Other authentication methods.", + "topdesk": "https://docs.topdesk.com/en/automatic-login-methods.html: \"Single Sign-on via SAML requirements TOPdesk uses OpenSAML 3 for authentication. You can connect all common IdP solutions which support SAML 2.0\" (read 2026-09-26). Reached on: Settings > Login Settings.", + "stackiq": "No OIDC/SAML code in lib/ or src/; stackiq creates local Nextcloud users with a password (lib/Service/Stackiq/ContactPersonHandler.php:292)", + "vng-softwarecatalogus": "unknown: login is by username and password (\"Vul uw GEMMA Softwarecatalogus-gebruikersnaam in\"); no identity provider sign-in is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/user/login (read 2026-09-26)" } }, { @@ -2702,7 +2918,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "no", "built": { "state": "none", @@ -2714,8 +2930,10 @@ "providerHow": "read-from-code", "note": "Stackiq has no directory sync for users or groups. Nextcloud's LDAP app could do it platform-wide, outside stackiq.", "evidence": { - "glpi": "docs, intelligence competitor_features#48908 'LDAP / SSO' (2026-07-23): Directory authentication and SSO. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141776 '5.11 Contact import and change subscriptions from registries': LDAP import and periodic re-sync of users and groups (`src/AuthLDAP.php`, `/front/ldap.import.php`, `/front/ldap.group.import.php`) with `src/RuleRight.php` mapping directory attributes to profiles; nothing subscribes to", - "stackiq": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/" + "glpi": "source read at 11.0.9: src/AuthLDAP.php:59 LDAP directories with user import and group import (src/AuthLDAP.php:2816 ldapImportGroup), and the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users (alias ldap:sync at :80). Reached on: Administration > Users > LDAP directory link; Setup > Authentication > LDAP directories.", + "stackiq": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/", + "topdesk": "https://docs.topdesk.com/en/manual-login-with-ldap.html: \"This is also required if you want to import persons from your AD via Supporting files import\" (read 2026-09-26); https://tip.topdesk.com/c/242-support-scim-when-importing-users-from-entra-id-to-topdesk: roadmap card in column \"Launched\", \"Support SCIM when importing users from Entra ID to TOPdesk\" (read 2026-09-26). Reached on: Settings > Import settings > Supporting Files imports.", + "vng-softwarecatalogus": "unknown: no directory sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -2723,11 +2941,11 @@ "area": "organisations", "name": "Change your own password and see your own account details.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "yes", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "built", @@ -2739,7 +2957,10 @@ "providerHow": "read-from-code", "note": "A user can change their own password from their contact row in the organisation card, which is hard to find. There is no 'my account' page in stackiq; /api/me feeds only the organisation switcher. Nextcloud's personal settings do both natively.", "evidence": { - "stackiq": "src/components/ContactpersonenList.vue:115 'Change Password' opens src/dialogs/ChangePasswordDialog.vue -> POST /api/contactpersonen/change-password -> lib/Controller/ContactpersonenController.php:718, self-reset allowed at :753; GET /api/me (:1578) used only by src/App.vue and OrganisationSwitcher" + "stackiq": "src/components/ContactpersonenList.vue:115 'Change Password' opens src/dialogs/ChangePasswordDialog.vue -> POST /api/contactpersonen/change-password -> lib/Controller/ContactpersonenController.php:718, self-reset allowed at :753; GET /api/me (:1578) used only by src/App.vue and OrganisationSwitcher", + "topdesk": "https://docs.topdesk.com/en/editing-your-personal-profile.html: \"Click on Personal Profile . In the General and Private section, you can edit your personal information. In the Change password section, you can change your password\" (read 2026-09-26). Reached on: Profile picture > Personal Profile.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/wachtwoord-vergeten: \"Op het inlogscherm ... staat een link om een nieuw wachtwoord aan te vragen\" (read 2026-09-26). Reset by mail; viewing own account details is not described. Reached on: Inloggen > Vraag een nieuw wachtwoord aan.", + "glpi": "source read at 11.0.9: front/preference.php renders the user's own form through src/User.php:3105 showMyForm (template pages/admin/user/user.html.twig), whose preference variant shows a 'Change password' button to front/updatepassword.php at templates/pages/admin/user/user.html.twig:277 to :279; the new password form is templates/password_form.html.twig:79." } }, { @@ -2763,8 +2984,10 @@ "providerHow": "read-from-code", "note": "The mails are sent from templates, but the admin template editor's Save button does not call the backend and reports success anyway, so an administrator cannot edit a template from the UI. The transport defaults to 'null', which sends nothing until configured.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141830 '11.12 E-mail template library': `src/NotificationTemplate.php` with per-language bodies (`src/NotificationTemplateTranslation.php`), bound to events and delivery modes by `src/Notification_NotificationTemplate.php`, at `/front/notificationtemplate.php` | Rated yes because notification templates, source-read 2026-09-14.", - "stackiq": "lib/Service/SymfonyEmailService.php:466 registration, :553 activation, :641 user creation mails from templates; src/views/settings/sections/EmailConfiguration.vue:902 saveTemplate is a stub that logs 'not yet implemented in the backend' and still shows success; backend POST /api/email/templates/{templateName} (lib/Controller/SettingsController.php:2194) has no caller in src/; lib/Settings/connections.json email adapter reports the 'null' transport as simulated" + "glpi": "source read at 11.0.9: src/NotificationTargetUser.php:44 user events passwordexpires, passwordforget and passwordinit; their text lives in admin editable templates, src/NotificationTemplate.php:47 and translations src/NotificationTemplateTranslation.php:42, seeded at install/empty_data.php:3212 (passwordinit) and :5640. Reached on: Setup > Notifications > Notification templates.", + "stackiq": "lib/Service/SymfonyEmailService.php:466 registration, :553 activation, :641 user creation mails from templates; src/views/settings/sections/EmailConfiguration.vue:902 saveTemplate is a stub that logs 'not yet implemented in the backend' and still shows success; backend POST /api/email/templates/{templateName} (lib/Controller/SettingsController.php:2194) has no caller in src/; lib/Settings/connections.json email adapter reports the 'null' transport as simulated", + "topdesk": "unknown: email designs are editable for automated actions, but account activation mails are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: new users receive a login mail, but administrator-editable templates are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)" } }, { @@ -2775,7 +2998,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -2790,7 +3013,10 @@ "featureConfidence": "high", "note": "The dedicated publish/withdraw endpoint is complete and guarded but no page calls it, and the old modal publish buttons are dead code. The only UI path is typing a publication or depublication date into the generic edit form.", "evidence": { - "stackiq": "lib/Controller/PublicationController.php:87 publish/depublish (routes.php:208-209, PUT/DELETE /api/publication/{objectType}/{uuid}) with an IDOR guard; lib/Service/PublicationService.php:51 publishable types catalogService, module, connection, organization. No src/ caller of /api/publication (only a comment in src/utils/openDataProjection.js). The publish buttons in src/modals/object/ViewObject.vue:4854 are unreachable: Modals.vue renders ViewObject only for modal 'viewOrganisatie'/'viewContactpersoon', which nothing sets. Workaround: publicationDate/depublicationDate are visible, editable fields on module/catalogService/organization/connection (lib/Settings/softwarecatalogus_register.json:6777 schema)." + "stackiq": "lib/Controller/PublicationController.php:87 publish/depublish (routes.php:208-209, PUT/DELETE /api/publication/{objectType}/{uuid}) with an IDOR guard; lib/Service/PublicationService.php:51 publishable types catalogService, module, connection, organization. No src/ caller of /api/publication (only a comment in src/utils/openDataProjection.js). The publish buttons in src/modals/object/ViewObject.vue:4854 are unreachable: Modals.vue renders ViewObject only for modal 'viewOrganisatie'/'viewContactpersoon', which nothing sets. Workaround: publicationDate/depublicationDate are visible, editable fields on module/catalogService/organization/connection (lib/Settings/softwarecatalogus_register.json:6777 schema).", + "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: supplier data is public by default and municipal data is never public; publishing or withdrawing one entry is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'open data\\|opendata' over src/ locales/glpi.pot returns nothing; items have no publish state, the closest is is_helpdesk_visible (install/mysql/glpi-empty.sql:8956 on glpi_appliances), which only shows the item to helpdesk users of the same instance." } }, { @@ -2798,10 +3024,10 @@ "area": "sharing", "name": "Publish usage as open data without exposing personal contact details.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2816,7 +3042,10 @@ "featureConfidence": "high", "note": "Usage (gebruik) is not published as open data at all: anonymous callers get an empty envelope and the usage schema has no public read rule. The PII-stripping projection exists only as an unused, unit-tested JS util.", "evidence": { - "stackiq": "src/utils/openDataProjection.js:36 STRIPPED_FIELDS (PII projection) is imported by nothing in src/ and has no PHP counterpart (grep 'projection' in lib/ finds none). Usage schema read rule lib/Settings/softwarecatalogus_register.json:3150 has no public group; lib/Controller/GebruikController.php:102 returns an empty result to anonymous callers." + "stackiq": "src/utils/openDataProjection.js:36 STRIPPED_FIELDS (PII projection) is imported by nothing in src/ and has no PHP counterpart (grep 'projection' in lib/ finds none). Usage schema read rule lib/Settings/softwarecatalogus_register.json:3150 has no public group; lib/Controller/GebruikController.php:102 returns an empty result to anonymous callers.", + "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Beschikbare%20downloads: public CSV downloads of packages, versions and compliance (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: \"Ingevuld door (28) Aantal gemeenten met een versie van het pakket in productie\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C5 contact details \"alleen als contactgegevens voor andere ingelogde gebruikers\" (read 2026-09-26). Reached on: Beschikbare downloads; package page.", + "glpi": "source read at 11.0.9: no open data publication exists (grep -rli 'open data' src/ returns nothing); anonymisation settings cover ticket actors only (install/mysql/glpi-empty.sql:2824 anonymize_support_agents on entities)." } }, { @@ -2827,7 +3056,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -2842,7 +3071,10 @@ "featureConfidence": "high", "note": "The announce hop is a real call into OpenCatalogi, but it is off by default, can only be switched on with occ, has no announce button, and needs OpenCatalogi installed.", "evidence": { - "stackiq": "lib/Service/Federation/FederationService.php:215 announce() calls OpenCatalogi BroadcastService->broadcast(directory URL); only caller is lib/BackgroundJob/FederationSyncJob.php:73. Off by default: lib/Service/Federation/FederationConfig.php:56 federation_enabled=false; lib/Settings/connections.json lists federation as switch-only via occ. isAvailable() is class_exists('OCA\\\\OpenCatalogi\\\\Service\\\\DirectoryService') (FederationService.php:95)." + "stackiq": "lib/Service/Federation/FederationService.php:215 announce() calls OpenCatalogi BroadcastService->broadcast(directory URL); only caller is lib/BackgroundJob/FederationSyncJob.php:73. Off by default: lib/Service/Federation/FederationConfig.php:56 federation_enabled=false; lib/Settings/connections.json lists federation as switch-only via occ. isAvailable() is class_exists('OCA\\\\OpenCatalogi\\\\Service\\\\DirectoryService') (FederationService.php:95).", + "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'federat\\|activitypub' over src/ returns nothing; every instance is standalone and the only outbound registration is the plugin marketplace client (src/Glpi/Marketplace/). The marketplace client is src/Glpi/Marketplace/Controller.php:64." } }, { @@ -2853,7 +3085,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -2868,7 +3100,10 @@ "featureConfidence": "high", "note": "The pull does not fetch the peer: the peer URL is passed as a parameter OpenCatalogi ignores, so what gets mirrored is the local directory listing. Provenance is stamped on mirrors but no page displays it. Federation is also off by default.", "evidence": { - "stackiq": "lib/Service/Federation/FederationService.php:434 fetchPeerCatalog() calls OpenCatalogi DirectoryService->getDirectory(['url' => $peerUrl]); OpenCatalogi's getDirectory (opencatalogi lib/Service/DirectoryService.php:2409, also on origin/development) reads only filters/limit/offset/include-federated and ignores 'url', so it returns this instance's own directory listings, not the peer's published entries. Provenance marking itself is built: lib/Service/Federation/FederationMerger.php:239 stamps _source.instance. Mirrors are written into the organization schema (FederationService.php:56 PEER_MIRROR_TYPE). No src/ code reads _source, so no page shows where an entry came from." + "stackiq": "lib/Service/Federation/FederationService.php:434 fetchPeerCatalog() calls OpenCatalogi DirectoryService->getDirectory(['url' => $peerUrl]); OpenCatalogi's getDirectory (opencatalogi lib/Service/DirectoryService.php:2409, also on origin/development) reads only filters/limit/offset/include-federated and ignores 'url', so it returns this instance's own directory listings, not the peer's published entries. Provenance marking itself is built: lib/Service/Federation/FederationMerger.php:239 stamps _source.instance. Mirrors are written into the organization schema (FederationService.php:56 PEER_MIRROR_TYPE). No src/ code reads _source, so no page shows where an entry came from.", + "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'federat' over src/ returns nothing; data enters only through the UI, the APIs (src/Glpi/Api/APIRest.php:60, src/Glpi/Api/HL/Router.php) and inventory, never from peer catalogues." } }, { @@ -2879,7 +3114,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -2894,7 +3129,10 @@ "featureConfidence": "high", "note": "Adding and removing peers works end to end, but only for a Nextcloud admin in the admin settings, and the peers are only used by a pull that currently fetches the wrong data (see share-federation-pull).", "evidence": { - "stackiq": "lib/Controller/FederationController.php:86 addPeer / removePeer (routes.php:246-247), #[AuthorizedAdminSetting(StackiqAdmin)]; lib/Service/Federation/FederationService.php:157/191 with an SSRF host guard; UI src/views/settings/sections/FederationSettings.vue:283 (POST) and :307 (DELETE), mounted from src/views/settings/StackiqSettings.vue:114." + "stackiq": "lib/Controller/FederationController.php:86 addPeer / removePeer (routes.php:246-247), #[AuthorizedAdminSetting(StackiqAdmin)]; lib/Service/Federation/FederationService.php:157/191 with an SSRF host guard; UI src/views/settings/sections/FederationSettings.vue:283 (POST) and :307 (DELETE), mounted from src/views/settings/StackiqSettings.vue:114.", + "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'federat' over src/ returns nothing; there is no peer list in the Setup menu (src/Html.php:1330 onwards)." } }, { @@ -2920,9 +3158,10 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48867 'REST & GraphQL API' (2026-07-23): Programmatic access to the workspace graph.", "bluedolphin": "docs, intelligence competitor_features#48972 'REST API' (2026-07-23): Programmatic integration with other systems.", - "glpi": "docs, intelligence competitor_features#48907 'REST API (HLAPI 2.x)' (2026-07-23): High-level REST API expanding object coverage in GLPI 11.", - "topdesk": "docs, intelligence competitor_features#48933 'REST API' (2026-07-23): Open REST API for integrations.", - "stackiq": "Every catalogue entity is an OpenRegister object (src/manifest.json pages read register @resolve:voorzieningen_register), so OpenRegister's /apps/openregister/api/objects/{register}/{schema} CRUD applies, gated by the schema authorization rules (lib/Settings/softwarecatalogus_register.json:6777 module and others). Stackiq adds its own routed endpoints in appinfo/routes.php (e.g. :202 /api/aanbod, :255-261 /api/aangeboden-gebruik, :298 /api/gebruik, :303 /api/portfolio-report)." + "glpi": "source read at 11.0.9: legacy REST API src/Glpi/Api/APIRest.php:60 (documented in apirest.md) and the v2 high level API, src/Glpi/Api/HL/Controller/AssetController.php:149 /Assets with GET list (:2825), GET item (:2839) and POST create (:2988), Appliance and Software included (src/Glpi/Api/HL/Controller/AssetController.php:39, :133). Reached on: /apirest.php and /api.php/v2.", + "topdesk": "https://docs.topdesk.com/en/required-knowledge.html: \"basic knowledge of REST API requests (see developers.topdesk.com )\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: \"API access > REST API : this permission is necessary for operator cards that are used for accessing the TOPdesk API\" (read 2026-09-26). Reached on: developers.topdesk.com.", + "stackiq": "Every catalogue entity is an OpenRegister object (src/manifest.json pages read register @resolve:voorzieningen_register), so OpenRegister's /apps/openregister/api/objects/{register}/{schema} CRUD applies, gated by the schema authorization rules (lib/Settings/softwarecatalogus_register.json:6777 module and others). Stackiq adds its own routed endpoints in appinfo/routes.php (e.g. :202 /api/aanbod, :255-261 /api/aangeboden-gebruik, :298 /api/gebruik, :303 /api/portfolio-report).", + "vng-softwarecatalogus": "unknown: https://www.softwarecatalogus.nl/api answers only \"Services Endpoint api has been setup successfully.\" and no API is documented; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api (read 2026-09-26)" } }, { @@ -2934,7 +3173,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "built", @@ -2947,8 +3186,10 @@ "providerHow": "read-from-code", "note": "The generated OpenAPI file is empty. What exists is hand-written: two JSON doc endpoints and markdown pages. OpenRegister may generate an OAS per register, but stackiq does not surface it.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141846 '12.18 OpenAPI documentation': auto-generated from route attributes: `src/Glpi/Api/HL/OpenAPIGenerator.php` with `src/Glpi/Api/HL/Doc/`, versioned per route (`#[RouteVersion]`, router at `src/Glpi/Api/HL/Router.php:98`); the legacy API is documented i | Rated yes because OpenAPI generator, source-read 2026-09-14.", - "stackiq": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261). The views docs endpoint is login-only; the aangeboden-gebruik docs endpoint is @PublicPage (AangebodenGebruikController.php:860), so anyone can read it (corrected 2026-09-26). Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint." + "glpi": "source read at 11.0.9: src/Glpi/Api/HL/Controller/CoreController.php:322 route /doc serves a Swagger UI 'GLPI API Documentation' (:329 to :331) over the spec built by src/Glpi/Api/HL/OpenAPIGenerator.php. Reached on: /api.php/doc.", + "stackiq": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261). The views docs endpoint is login-only; the aangeboden-gebruik docs endpoint is @PublicPage (AangebodenGebruikController.php:860), so anyone can read it (corrected 2026-09-26). Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint.", + "topdesk": "https://developers.topdesk.com/: TOPdesk API reference site, linked from the docs as \"TOPdesk API documentation\" (read 2026-09-26); https://docs.topdesk.com/en/generate-a-document.html: \"see FreeMarker and the TOPdesk API documentation\" (read 2026-09-26). Reached on: developers.topdesk.com.", + "vng-softwarecatalogus": "unknown: no API documentation for the current catalogue was found; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" } }, { @@ -2960,7 +3201,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "built", @@ -2974,9 +3215,10 @@ "featureConfidence": "medium", "note": "A full ArchiMate export exists but is only reached from admin settings. The one export on a user page is the portfolio report CSV, and the catalogue list pages offer no export.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27550 'Application Landscape Mapping' (2026-04-12): Map and export municipality application landscape", - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141818 '10.3 Export list results to CSV or XLSX': `src/Glpi/Search/Output/Csv.php`, `Xlsx.php`, `Ods.php` and `Pdf.php`, mapped at `src/Glpi/Search/SearchEngine.php:108-130` | Rated yes because CSV, XLSX, ODS, PDF export, source-read 2026-09-14.", - "stackiq": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json)." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"De publieke informatie is ook beschikbaar als download van exportbestanden ... Mijn pakketten, Mijn koppelingen: Knop [Exporteren]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Exporteren; Beschikbare downloads.", + "glpi": "source read at 11.0.9: every search list exports to CSV, PDF, ODS and XLSX through src/Glpi/Search/Output/Csv.php, Pdf.php, Ods.php and Xlsx.php, plus impact CSV (front/impactcsv.php) and the APIs (src/Glpi/Api/HL/Controller/AssetController.php:2825). Reached on: any list, Export menu.", + "stackiq": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json).", + "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: tile actions \"Export to .CSV Export to Excel\" (read 2026-09-26); https://docs.topdesk.com/en/create-odata-reports-for-asset-management.html: \"generate reports by using the TOPdesk OData feed ... Microsoft Power BI, or Microsoft Excel\" (read 2026-09-26). Reached on: Asset dashboard; OData feed." } }, { @@ -2984,10 +3226,10 @@ "area": "sharing", "name": "Exchange application data with the organisation's service management tool.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "yes", - "glpi": "unknown", + "glpi": "yes", "topdesk": "yes", "stackiq": "no", "built": { @@ -3002,8 +3244,10 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48866 'Out-of-the-box integrations (ServiceNow, Signavio, SAP)' (2026-07-23): Pre-built connectors sync CMDB, process and ERP data.", "bluedolphin": "docs, intelligence competitor_features#48973 'TOPdesk integration' (2026-07-23): Connector to TOPdesk asset/service data. | docs, intelligence competitor_features#27465 'TOPdesk Integration' (2026-04-12): Available on TOPdesk Marketplace for IT landscape insights", - "topdesk": "docs, intelligence competitor_features#48934 'Marketplace integrations (Lansweeper, ValueBlue)' (2026-07-23): Pre-built connectors incl. Lansweeper discovery and ValueBlue EA. | docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", - "stackiq": "No ITSM connector: lib/Settings/connections.json lists only email, federation and eol-feed; grep for topdesk/servicenow/itsm in lib/ and src/ finds nothing." + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"Go to Links > Assets . Click Link asset\" (read 2026-09-26) on calls and changes; TOPdesk is itself the service management tool. Reached on: Call card > Links > Assets.", + "stackiq": "No ITSM connector: lib/Settings/connections.json lists only email, federation and eol-feed; grep for topdesk/servicenow/itsm in lib/ and src/ finds nothing.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"Met de exportfunctie kunt u de gegevens in andere tools synchroon houden ... We verwachten in 2019 een pilot met Topdesk ... Een import vanuit die tools naar de Softwarecatalogus ... is vooralsnog niet voorhanden\" (read 2026-09-26); https://www.softwarecatalogus.nl/RID%20de%20Liemers: RID de Liemers signals updates through its TOPdesk change process by hand (read 2026-09-26)", + "glpi": "source read at 11.0.9: GLPI is itself the service management tool, so application records are used directly by tickets, problems and changes, src/Appliance.php:105 onwards Item_Ticket, Item_Problem and Change_Item tabs; the menu src/Html.php:1283 Assistance holds Ticket, Problem and Change. Reached on: Appliance > Tickets, Problems, Changes tabs." } }, { @@ -3015,7 +3259,7 @@ "sap-leanix": "no", "bluedolphin": "no", "glpi": "yes", - "topdesk": "partial", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -3029,9 +3273,10 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", "bluedolphin": "docs, intelligence competitor_features#27467 'SaaS Platform' (2026-04-12): Cloud-native SaaS, no installation required", - "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", - "topdesk": "docs, intelligence competitor_features#26346 'SaaS Platform' (2026-04-10): Cloud-hosted SaaS platform with automatic updates | Rated partial because offered as SaaS; on-premises not in the reading.", - "stackiq": "appinfo/info.xml: a Nextcloud app (id stackiq, EUPL-1.2) installed on the customer's own Nextcloud with OpenRegister; stackiq-compose.yaml at repo root for a local stack." + "glpi": "source read at 11.0.9: GPL 3 source distributed for installation on own servers (LICENSE, INSTALL.md, install/mysql/glpi-empty.sql schema and the web installer src/Glpi/Controller/InstallController.php). The version is src/autoload/constants.php:43 GLPI_VERSION 11.0.9, the installer controller src/Glpi/Controller/InstallController.php:57, the licence LICENSE:1 GNU GPL version 3.", + "topdesk": "https://docs.topdesk.com/VA2026R3/index.html: \"TOPdesk Virtual Appliance documentation\", releases VA 2023 R2 to VA 2026 R3 (read 2026-09-26); https://tip.topdesk.com/c/255-va-release-q4-2026: roadmap card in column \"Planned\", \"VA Release Q4 2026\" in section \"On premise - VA releases\" (read 2026-09-26). Reached on: Virtual Appliance.", + "stackiq": "appinfo/info.xml: a Nextcloud app (id stackiq, EUPL-1.2) installed on the customer's own Nextcloud with OpenRegister; stackiq-compose.yaml at repo root for a local stack.", + "vng-softwarecatalogus": "unknown: the catalogue is run by VNG Realisatie; self-hosting is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3039,11 +3284,11 @@ "area": "insight", "name": "Search the catalogue and narrow the results with facets such as reference component and supplier.", "origin": "own-code", - "vng-softwarecatalogus": "partial", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -3057,9 +3302,10 @@ "featureConfidence": "low", "note": "Search plus reference-component, standard, application-service and domain facets work. Supplier is not offered as a facet, which is half of the row's example.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#27553 'ICT Market Orientation' (2026-04-12): Find and compare software from registered ICT providers", - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141806 '9.2 Advanced search with per-case-type fields': the search engine is strong, with ~160 ticket search options (`src/Ticket.php:2670`), nested criteria groups, `AND`/`OR`/`AND NOT`/`OR NOT` (`src/Glpi/Search/SearchEngine.php:551-564`), cross-itemtype meta-criteria, but | Rated yes because search engine with nested criteria, source-read 2026-09-14.", - "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS = referenceComponent, standard, applicationService, domain (GET /api/facets/{schema}, routes.php:195); src/views/FacetedCatalogIndexView.vue renders CnFacetSidebar with these plus search, on the Applications and Services pages. Supplier is only a column (src/manifest.json Modules config columns 'provider'), not a facet, although the module schema marks provider facetable." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Aan de linkerkant staan zogenaamde filter mogelijkheden. Deze werken ook in combinatie ... Achter de te zetten filters staat een getal\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facets Leverancier, Standaard, Referentiecomponent, Status planning, Domein, Doelgroep, Bedrijfsfunctie (read 2026-09-26). Reached on: Alle pakketten / Alle pakketversies.", + "glpi": "source read at 11.0.9: every list has a criteria builder, src/Glpi/Search/Input/QueryBuilder.php:72 showGenericSearch, over all search options, for example manufacturer on appliances (src/Appliance.php:229 region, glpi_manufacturers) and status (src/Appliance.php:350); there are no counted facets and no reference component to filter on. Reached on: Management > Appliances, search criteria.", + "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS = referenceComponent, standard, applicationService, domain (GET /api/facets/{schema}, routes.php:195); src/views/FacetedCatalogIndexView.vue renders CnFacetSidebar with these plus search, on the Applications and Services pages. Supplier is only a column (src/manifest.json Modules config columns 'provider'), not a facet, although the module schema marks provider facetable.", + "topdesk": "https://docs.topdesk.com/en/the-asset-management-module-page.html: \"Asset overview : view all your assets in a filterable list\" (read 2026-09-26). Facets with counts are not described. Reached on: Asset Management > Asset overview." } }, { @@ -3071,7 +3317,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -3083,8 +3329,10 @@ "providerHow": "read-from-code", "note": "A user can save the facet and search selection as a named view and reopen it. Storage is OpenRegister's views API. It covers only those two pages.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141807 '9.3 Personal saved searches': `src/SavedSearch.php:52`, `is_private` default 1, personal ordering (`:824`) and a default per itemtype (`src/SavedSearch_User.php:94-115`), at `/front/savedsearch.php` | Rated yes because saved searches, source-read 2026-09-14.", - "stackiq": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back." + "glpi": "source read at 11.0.9: src/SavedSearch.php:52 SavedSearch, private or shared, listed under Tools > Saved searches (src/Html.php:1309) with optional alerts (front/savedsearch_alert.form.php). Reached on: Tools > Saved searches (front/savedsearch.php).", + "stackiq": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back.", + "topdesk": "https://tip.topdesk.com/c/83-share-saved-overviews-with-operators-and-operator-groups: roadmap card in column \"Launched\", \"User is able to share saved overviews with operators and operator groups - Rename the saved overview\" (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: only VNG-defined \"Marktscans-voorgedefinieerde filters\" are described; users saving their own view is not; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Marktscans (read 2026-09-26)" } }, { @@ -3092,7 +3340,7 @@ "area": "insight", "name": "Open a dashboard with counts of organisations, applications and contracts.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", @@ -3109,9 +3357,10 @@ "note": "The dashboard shows counts of organisations, applications, services and contracts. The counts are computed by OpenRegister through the library stat widget.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports. | docs, intelligence competitor_features#27424 'Dashboards & Reports' (2026-04-12): Real-time dashboards for CIO-level reporting", - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141816 '10.1 Configurable KPI dashboards (count, gauge, chart)': `src/Glpi/Dashboard/Grid.php:67` with 20 widget types: pie, donut, half pie/donut, bars, lines, areas, stacked and horizontal variants, big number, multiple numbers, summary numbers, markdown, search result, article list", - "topdesk": "docs, intelligence competitor_features#48936 'Reporting & dashboards' (2026-07-23): Operational reporting and dashboards.", - "stackiq": "src/manifest.json:72 Dashboard page with stat widgets kpi-organisations, kpi-modules, kpi-services, kpi-contracts (source metric count on organization/module/catalogService/catalogContract) plus catalog-panels." + "glpi": "source read at 11.0.9: src/Glpi/Dashboard/Grid.php:1400 adds a 'Number of %s' card for every menu itemtype, so suppliers, appliances, software and contracts are counted (menu types src/Html.php:1298 to :1300); dashboards are stored by src/Glpi/Dashboard/Dashboard.php:66 and shown on the central page (src/Central.php:135). Reached on: Home > Dashboard; Assets > Dashboard.", + "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"open the Asset dashboard to see statistics and visualised information regarding your registered assets\" (read 2026-09-26); https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub\" (read 2026-09-26). Reached on: Asset Management > Asset dashboard.", + "stackiq": "src/manifest.json:72 Dashboard page with stat widgets kpi-organisations, kpi-modules, kpi-services, kpi-contracts (source metric count on organization/module/catalogService/catalogContract) plus catalog-panels.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tiles for logged-in municipalities (read 2026-09-26); https://www.softwarecatalogus.nl/: \"Voortgang gemeenten Aantal gemeenten per voortgangscategorie ... Aantal ingelogde gemeenten in 2026: 69\" (read 2026-09-26). No contracts. Reached on: Dashboard; homepage." } }, { @@ -3122,7 +3371,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -3135,7 +3384,10 @@ "providerHow": "read-from-code", "note": "The widget is registered and loads, but it filters on a status value the data no longer holds, so it always lists nothing. Its accept button would write an invalid status.", "evidence": { - "stackiq": "lib/Dashboard/ConceptOrganisatiesWidget.php registered at lib/AppInfo/Application.php:760; src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters organisations on status === 'concept', but the status enum is Draft/Active/Inactive/merged (lib/Settings/softwarecatalogus_register.json:2321) after lib/Repair/RenameDutchCatalogValues.php:76 renamed 'Concept' to 'Draft'. Accept writes status 'actief' (:129), which is not in the enum either." + "stackiq": "lib/Dashboard/ConceptOrganisatiesWidget.php registered at lib/AppInfo/Application.php:760; src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters organisations on status === 'concept', but the status enum is Draft/Active/Inactive/merged (lib/Settings/softwarecatalogus_register.json:2321) after lib/Repair/RenameDutchCatalogValues.php:76 renamed 'Concept' to 'Draft'. Accept writes status 'actief' (:129), which is not in the enum either.", + "topdesk": "unknown: not a Nextcloud app; no such widget applies; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: the catalogue is not a Nextcloud app; no such widget applies; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: GLPI is not a Nextcloud app and has no concept organisation state (suppliers only have is_active, install/mysql/glpi-empty.sql:7087), so no such widget exists in its own dashboards (src/Glpi/Dashboard/Grid.php:67)." } }, { @@ -3143,11 +3395,11 @@ "area": "insight", "name": "Pick a ready-made report from a list and open it.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "yes", "built": { "state": "built", @@ -3159,8 +3411,10 @@ "providerHow": "read-from-code", "note": "The report picker exists and opens a working report. The list holds exactly one report.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145791 'C-reporting-2 A canned report the product ships, run without building it.': glpi: Reports (Tools, Reports, front/report.default.php, report.dynamic.php, report.year.php, report.state.php, report.reservation.php, report.contract.php) Lane findings: D-glpi-35. | Rated yes because canned reports, source-read 2026-09-14.", - "stackiq": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303)." + "glpi": "source read at 11.0.9: src/Report.php:52 Report builds a pick list of ready made reports, src/Report.php:77 default, :81 by contract, :85 by year, :87 financial information, :110 status, chosen from 'Select the report you want to generate' (src/Report.php:143). Reached on: Tools > Reports (front/report.php).", + "stackiq": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303).", + "topdesk": "https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub ... So far, you could find dashboards and reports in different places\" (read 2026-09-26); https://tip.topdesk.com/c/20-reporting-hub: roadmap card in column \"Launched\", \"Reporting Hub\" (read 2026-09-26). Reached on: TOPdesk menu > Reporting Hub.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/rapportages: \"Regelmatig worden er rapportages gemaakt over het gebruik van de Softwarecatalogus\" (read 2026-09-26); compliancy monitor and digital accessibility monitor pages. Reached on: Rapportages; Compliancy monitor." } }, { @@ -3172,7 +3426,7 @@ "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "no", "built": { "state": "none", @@ -3187,8 +3441,10 @@ "note": "Users cannot build their own report. The one fixed portfolio report can be exported as CSV, but it is not configurable.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141816 '10.1 Configurable KPI dashboards (count, gauge, chart)': `src/Glpi/Dashboard/Grid.php:67` with 20 widget types: pie, donut, half pie/donut, bars, lines, areas, stacked and horizontal variants, big number, multiple numbers, summary numbers, markdown, search result, article list", - "stackiq": "No report builder in src/ or lib/. The only report is the fixed Gartner TIME portfolio report (lib/Controller/PortfolioReportController.php, CSV at :105). The overlay lists portfolio-reporting as status 'soon'." + "glpi": "source read at 11.0.9: any itemtype list takes arbitrary criteria (src/Glpi/Search/Input/QueryBuilder.php:72), selectable columns, and exports to CSV, PDF, ODS or XLSX (src/Glpi/Search/Output/Xlsx.php); the result can be saved (src/SavedSearch.php:52) and charted on a dashboard (src/Glpi/Dashboard/Grid.php:67). Reached on: any list with criteria, column selection and export.", + "stackiq": "No report builder in src/ or lib/. The only report is the fixed Gartner TIME portfolio report (lib/Controller/PortfolioReportController.php, CSV at :105). The overlay lists portfolio-reporting as status 'soon'.", + "topdesk": "https://docs.topdesk.com/en/reporting.html: \"The Report Wizard is not available for the Asset Management module. Further reporting can be done with the Asset Type Report or the OData feed\" (read 2026-09-26). Reached on: Asset Type Report; OData.", + "vng-softwarecatalogus": "unknown: only CSV exports for use in a spreadsheet are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" } }, { @@ -3196,11 +3452,11 @@ "area": "insight", "name": "Export a filtered list to a spreadsheet.", "origin": "competitor", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "built", @@ -3214,8 +3470,10 @@ "featureConfidence": "low", "note": "One fixed report exports to CSV for a selected organisation. The filtered catalogue lists cannot be exported.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141818 '10.3 Export list results to CSV or XLSX': `src/Glpi/Search/Output/Csv.php`, `Xlsx.php`, `Ods.php` and `Pdf.php`, mapped at `src/Glpi/Search/SearchEngine.php:108-130` | Rated yes because source-read 2026-09-14.", - "stackiq": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export." + "glpi": "source read at 11.0.9: src/Glpi/Search/Output/Csv.php, Ods.php, Xlsx.php and Pdf.php export the filtered list; the output format selector is rendered by src/Html.php:4219 Dropdown::showOutputFormat. Reached on: any filtered list, Export.", + "stackiq": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export.", + "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"Export to .CSV Export to Excel\" (read 2026-09-26). Reached on: Asset dashboard tile menu.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: \"Export to CSV\" on the filtered package-version list (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Ook beschikbaar via knop [Export to csv] op pagina Alle pakketten\" (read 2026-09-26). Reached on: Alle pakketversies > Export to CSV." } }, { @@ -3226,8 +3484,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "yes", "stackiq": "no", "built": { "state": "none", @@ -3239,7 +3497,10 @@ "providerHow": "read-from-code", "note": "Reports cannot be scheduled or sent to people.", "evidence": { - "stackiq": "No scheduled report or report mail job: lib/BackgroundJob/ holds only ContractStatusJob, EolSyncJob, FederationSyncJob and OrganizationContactSyncJob; grep for report scheduling in lib/ and src/ finds nothing." + "stackiq": "No scheduled report or report mail job: lib/BackgroundJob/ holds only ContractStatusJob, EolSyncJob, FederationSyncJob and OrganizationContactSyncJob; grep for report scheduling in lib/ and src/ finds nothing.", + "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"Reports & Selections > Schedule reports with my own authorizations : the operator can schedule reports to be regularly saved or sent to contact persons\" (read 2026-09-26). Reached on: Reports & Selections.", + "vng-softwarecatalogus": "unknown: no scheduled reports are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: saved search alerts, src/SavedSearch_Alert.php:45 with count conditions (src/SavedSearch_Alert.php:53 to :58) and a frequency, run by src/SavedSearch_Alert.php:307 cronSavedSearchesAlerts and sent through the notification system to configured recipients; they notify on a result count rather than sending the report itself. Reached on: Tools > Saved searches > Alerts tab." } }, { @@ -3251,7 +3512,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -3265,8 +3526,10 @@ "featureConfidence": "medium", "note": "Cost is reported per vendor and, within the portfolio report, for one organisation at a time. There is no cross-organisation or per-domain cost report.", "evidence": { - "glpi": "docs, intelligence competitor_features#3271 'Financial Management' (2026-03-28): TCO tracking with procurement and contracts", - "stackiq": "src/views/LicensePostureView.vue:84 per-vendor rollup with annual cost from contracts (src/utils/licensePosture.js perVendorRollup); src/views/organisaties/PortfolioReport.vue:143 annualised and one-off cost per TIME quadrant for one selected organisation (lib/Service/PortfolioReportService.php via GET /api/portfolio-report)." + "glpi": "source read at 11.0.9: src/Budget.php:537 showValuesByEntity shows spend per entity and item type for a budget, and src/Report.php:89 'Other financial and administrative information (licenses, cartridges, consumables)' (front/report.infocom.conso.php); there is no cost per domain or reference component view. Reached on: Management > Budgets > budget tabs; Tools > Reports.", + "stackiq": "src/views/LicensePostureView.vue:84 per-vendor rollup with annual cost from contracts (src/utils/licensePosture.js perVendorRollup); src/views/organisaties/PortfolioReport.vue:143 annualised and one-off cost per TIME quadrant for one selected organisation (lib/Service/PortfolioReportService.php via GET /api/portfolio-report).", + "topdesk": "https://docs.topdesk.com/en/obtain-insights-with-asset-type-report.html: \"do you need an overview of the total costs of new assets?\" (read 2026-09-26); call cost fields in https://docs.topdesk.com/en/fields-for-call-management-reports.html. Reached on: Asset Type Report.", + "vng-softwarecatalogus": "unknown: costs are not recorded; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3277,8 +3540,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "no", + "topdesk": "partial", "stackiq": "yes", "built": { "state": "built", @@ -3290,7 +3553,10 @@ "providerHow": "read-from-code", "note": "The page lists features with their status. Note that the overlay feeding it is a self-description and may be stale in the app's favour.", "evidence": { - "stackiq": "src/manifest.json:1048 FeaturesRoadmap page (type roadmap, line 1050), footer menu entry FeaturesRoadmapMenu; content from openspec/features.overlay.json statuses stable/beta/soon." + "stackiq": "src/manifest.json:1048 FeaturesRoadmap page (type roadmap, line 1050), footer menu entry FeaturesRoadmapMenu; content from openspec/features.overlay.json statuses stable/beta/soon.", + "topdesk": "https://docs.topdesk.com/en/topdesk-labs.html: \"As a SaaS user, you can turn on the labs features you are curious about through Functional Settings > Labs\" (read 2026-09-26); https://docs.topdesk.com/en/ai-features.html: \"On your settings page, you can find an overview of all the AI features currently available in your environment\" (read 2026-09-26). Coming-soon items live on the external roadmap, not in the app. Reached on: Functional Settings > Labs.", + "vng-softwarecatalogus": "unknown: FAQ E14 points to a homepage block \"Binnenkort in de Softwarecatalogus\", but today's homepage shows no such block; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/ (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'coming soon' over src/ templates/ returns no in app feature status page; src/Glpi/Features/ holds item traits (for example src/Glpi/Features/Kanban.php), not feature flags. src/Glpi/Features/Kanban.php:45 is a trait, typical of that directory." } }, { @@ -3314,8 +3580,10 @@ "providerHow": "read-from-code", "note": "A progress API exists but no page reads it. Admins see a sync status and final import results, not the progress of a running job.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145875 'C-configuration-20 A long running administrative operation reports its progress.': glpi: Progress on a long operation (src/Glpi/Controller/ProgressController.php, Traits/AsyncOperationProgressControllerTrait.php) Lane findings: D-glpi-29. | Rated yes because source-read 2026-09-14.", - "stackiq": "lib/Controller/SettingsController.php:1289 getProgress and :1360 streamProgress (routes.php:119-120) serve lib/Service/ProgressTracker.php, used only by lib/Service/MergeOrganisatieService.php; no src/ caller of /api/progress. The admin ArchiMate import shows a spinner then the final objects-processed count (src/views/settings/sections/ArchiMateImportExport.vue:103). Organisation sync shows a status block with last sync time and organisations to process (src/views/settings/sections/OrganizationSynchronization.vue:211)." + "glpi": "source read at 11.0.9: massive actions over many records show a progress bar, src/MassiveAction.php:1294 displayProgressBar; the LDAP synchronisation command shows one per user batch, src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:382; long web operations report through src/Glpi/Controller/ProgressController.php:50 /progress/check/{key}. Inventory imports run per agent request without a progress view. Reached on: massive action screen; CLI ldap:sync.", + "stackiq": "lib/Controller/SettingsController.php:1289 getProgress and :1360 streamProgress (routes.php:119-120) serve lib/Service/ProgressTracker.php, used only by lib/Service/MergeOrganisatieService.php; no src/ caller of /api/progress. The admin ArchiMate import shows a spinner then the final objects-processed count (src/views/settings/sections/ArchiMateImportExport.vue:103). Organisation sync shows a status block with last sync time and organisations to process (src/views/settings/sections/OrganizationSynchronization.vue:211).", + "topdesk": "unknown: import errors can be downloaded as logs; following progress of a running import is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no progress display for sync or import is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3339,9 +3607,10 @@ "providerHow": "read-from-code", "note": "There is no knowledge base. Files can be attached to an application, but that is not searchable articles.", "evidence": { - "glpi": "docs, intelligence competitor_features#48909 'Knowledge base' (2026-07-23): Built-in KB with FAQ publishing.", - "topdesk": "docs, intelligence competitor_features#48931 'Knowledge base' (2026-07-23): Knowledge management and published articles.", - "stackiq": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel." + "glpi": "source read at 11.0.9: src/KnowbaseItem.php:57 knowledge base articles with categories and visibility, linked to items through src/KnowbaseItem_Item.php:45 and shown on the appliance Knowledge base tab (src/Appliance.php:104); menu src/Html.php:1307. Reached on: Tools > Knowledge base (front/knowbaseitem.php).", + "topdesk": "https://docs.topdesk.com/en/knowledge-management.html: \"The Knowledge Base is set up and managed by your organization's knowledge managers. Every operator is able to use information from the Knowledge Base\" (read 2026-09-26). Reached on: Modules > Knowledge Management.", + "stackiq": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel.", + "vng-softwarecatalogus": "unknown: the FAQ and manuals are site help, no knowledge base about applications is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3353,7 +3622,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "no", "built": { "state": "none", @@ -3365,8 +3634,10 @@ "providerHow": "read-from-code", "note": "Stackiq is a catalogue, and nothing discovers installed software.", "evidence": { - "glpi": "docs, intelligence competitor_features#48899 'Native inventory (GLPI Agent)' (2026-07-23): Built-in agent (ex-FusionInventory) discovers hardware/software automatically. | docs, intelligence competitor_features#3269 'Inventory' (2026-03-28): Automatic inventory discovery with FusionInventory agent", - "stackiq": "No discovery agent or agent-ingest endpoint in lib/ or appinfo/routes.php. The nearest capability is SBOM import per module version (lib/Controller/SbomController.php:129), which records components of a known release, not installed software." + "glpi": "source read at 11.0.9: native inventory receives glpi-agent submissions at src/Glpi/Controller/InventoryController.php:61 /Inventory (legacy :62 /front/inventory.php), processed by src/Glpi/Inventory/Inventory.php:106 with src/Glpi/Inventory/Asset/Software.php creating software and installations. The agent is the separate glpi-project/glpi-agent repository. Reached on: Administration > Inventory; Assets > Software.", + "stackiq": "No discovery agent or agent-ingest endpoint in lib/ or appinfo/routes.php. The nearest capability is SBOM import per module version (lib/Controller/SbomController.php:129), which records components of a known release, not installed software.", + "topdesk": "https://docs.topdesk.com/en/taking-inventory-with-configuration-management.html: \"TOPsis will scan the workstations in your network and import the data into TOPdesk\" (read 2026-09-26) (old Configuration Management); https://docs.topdesk.com/en/migration-status.html: \"For network scanning purposes, we advise you to use other solutions that are available via the TOPdesk Marketplace: Lansweeper integration Microsoft Endpoint Manager integration\" (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3378,7 +3649,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "no", "built": { "state": "none", @@ -3390,8 +3661,10 @@ "providerHow": "read-from-code", "note": "No device discovery.", "evidence": { - "glpi": "docs, intelligence competitor_features#48911 'Network / SNMP discovery' (2026-07-23): SNMP network equipment inventory.", - "stackiq": "No network scanning code in lib/ or routes (appinfo/routes.php)." + "glpi": "source read at 11.0.9: src/Glpi/Inventory/Request.php:97 NETDISCOVERY_ACTION calls src/Glpi/Inventory/Request.php:237 networkDiscovery, importing devices found by the agent's network discovery; scheduling discovery tasks from the server goes through the HANDLE_NETDISCOVERY_TASK hook (src/Glpi/Inventory/Request.php:448), which the separate glpiinventory plugin implements. Reached on: Administration > Inventory; Assets > Network devices.", + "stackiq": "No network scanning code in lib/ or routes (appinfo/routes.php).", + "topdesk": "https://docs.topdesk.com/en/creating-a-new-import.html: \"Connecting to Lansweeper as Asset Management import source\" (read 2026-09-26); https://tip.topdesk.com/c/186-automated-asset-scanning-tool: roadmap card in column \"Under consideration\", \"The asset discovery tool constantly monitors the entire network for new devices\" (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3402,7 +3675,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "no", "built": { @@ -3416,7 +3689,10 @@ "note": "No discovery of unregistered SaaS use.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model.", - "stackiq": "No SaaS or SSO-log discovery code in lib/; lib/Settings/connections.json has no such source." + "stackiq": "No SaaS or SSO-log discovery code in lib/; lib/Settings/connections.json has no such source.", + "topdesk": "unknown: SaaS discovery is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: inventory handlers under src/Glpi/Inventory/Asset/ (Software.php, Process.php, VirtualMachine.php and others) read what the agent sees on devices; grep -i 'saas' over src/ returns nothing, so cloud subscriptions nobody registered are not discovered. The software handler is src/Glpi/Inventory/Asset/Software.php:56." } }, { @@ -3440,9 +3716,10 @@ "providerHow": "read-from-code", "note": "Only software is registered, not hardware.", "evidence": { - "glpi": "docs, intelligence competitor_features#3266 'IT Asset Management' (2026-03-28): Track hardware, software, and network assets", - "topdesk": "docs, intelligence competitor_features#27388 'Asset Management' (2026-04-12): Track hardware and software assets, locations, and assignments", - "stackiq": "No hardware schema in lib/Settings/softwarecatalogus_register.json (schemas are software, organisation, contract and GEMMA model types only)." + "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:208 asset_types lists Computer, Monitor, NetworkEquipment and the other hardware types managed next to software, under the Assets menu. Reached on: Assets > Computers, Monitors, Network devices.", + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"Think of a router that provides a computer with access to your network, or a printer\" (read 2026-09-26); any asset type via templates. Reached on: Asset Management.", + "stackiq": "No hardware schema in lib/Settings/softwarecatalogus_register.json (schemas are software, organisation, contract and GEMMA model types only).", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3466,9 +3743,9 @@ "providerHow": "read-from-code", "note": "The landscape and its relations are recorded as catalogue objects, not as a CMDB with CI classes. Connections (koppelingen) have no index or detail page of their own.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "glpi": "docs, intelligence competitor_features#48902 'CMDB & configuration relations' (2026-07-23): CI relationships and impact analysis.", - "topdesk": "docs, intelligence competitor_features#48926 'Asset Management / CMDB' (2026-07-23): Register assets, users, relations and replacement timelines in one overview. | docs, intelligence competitor_features#27387 'CMDB / Configuration Management' (2026-04-12): Configuration database for registering IT objects like laptops, software, infrastructure", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"Dubbel beheer (én in de Softwarecatalogus én in de CMDB) ... Een CMDB die separaat wordt bijgehouden\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/19703: \"Zolang de CMDB niet gekoppeld is aan de Softwarecatalogus\" (read 2026-09-26). The docs treat the CMDB as a separate tool.", + "glpi": "source read at 11.0.9: configuration items are the asset types (src/autoload/CFG_GLPI.php:208) plus appliances, with relations recorded as appliance membership (src/Appliance_Item.php:45), impact relations (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and network port links. Reached on: Assets menu; item > Impact analysis tab.", + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"You register these functionalities as custom link types, and these link types are shown in the graphical overview of assets\" (read 2026-09-26). Reached on: Asset card > Relationships widget.", "stackiq": "Applications (module lib/Settings/softwarecatalogus_register.json:6777), versions (moduleVersion :7649), suites (suite :1135) and application-to-application connections (connection :3563) with relations; ModuleDetail and SuiteDetail show a Related panel. No manifest page has register+schema 'connection' or 'usage', so connections are not listed or created on their own page." } }, @@ -3480,7 +3757,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3493,7 +3770,10 @@ "providerHow": "read-from-code", "note": "An admin can merge duplicate organisations with a dry run. Nothing deduplicates applications or reconciles records arriving from several sources.", "evidence": { - "stackiq": "Organisation merge: src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail, calling /api/organisaties/{uuid}/merge/dry-run and /merge (src/store/modules/organisatie.js:486/524, lib/Controller/MergeController.php:106, admin-only body guard). Federation mirrors are reconciled per peer by lib/Service/Federation/FederationMerger.php." + "stackiq": "Organisation merge: src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail, calling /api/organisaties/{uuid}/merge/dry-run and /merge (src/store/modules/organisatie.js:486/524, lib/Controller/MergeController.php:106, admin-only body guard). Federation mirrors are reconciled per peer by lib/Service/Federation/FederationMerger.php.", + "topdesk": "unknown: deduplication across sources is not described; https://tip.topdesk.com/c/239-ai-cmdb-monitoring- (duplicates) is under consideration; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: src/RuleImportAsset.php:46 import and link rules decide whether an incoming inventory record matches an existing asset (by serial, UUID, MAC and similar) or creates one; src/RuleDictionnarySoftware.php:44 normalises software names and publishers from different sources; duplicates can be merged afterwards (src/Software.php:1011). Reached on: Administration > Rules > Rules for import and link equipments; Dictionaries." } }, { @@ -3517,9 +3797,10 @@ "providerHow": "read-from-code", "note": "No ticketing.", "evidence": { - "glpi": "docs, intelligence competitor_features#48903 'ITIL helpdesk / ticketing' (2026-07-23): Full incident/request ticketing with the assets module.", - "topdesk": "docs, intelligence competitor_features#48927 'Incident / ticket management' (2026-07-23): Core ITSM incident and request handling.", - "stackiq": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php." + "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:301 ticket_types includes Appliance (line 305), so tickets link to an application through src/Item_Ticket.php:41, shown on the appliance Tickets tab (src/Appliance.php:105). Reached on: Assistance > Tickets; Appliance > Tickets tab.", + "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity) ... cards, you can link multiple assets\" (read 2026-09-26). Reached on: Call card > Links > Assets.", + "stackiq": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php.", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3543,9 +3824,10 @@ "providerHow": "read-from-code", "note": "Contracts go through an approval, but changes to an application do not.", "evidence": { - "glpi": "docs, intelligence competitor_features#3277 'Change Management' (2026-03-28): ITIL change management with approval workflows", - "topdesk": "docs, intelligence competitor_features#48929 'Change management' (2026-07-23): Structured change workflows with action sequences.", - "stackiq": "No change-request workflow for applications. The only approval flow is for contracts: src/components/contracts/ContractApprovalPanel.vue on ContractDetail via /api/contracts/{uuid}/approval (routes.php:35-37), delegated to decidiq." + "glpi": "source read at 11.0.9: changes link to the appliance (src/Appliance.php:107 Change_Item tab) and go through approvals, src/ChangeValidation.php:39 ChangeValidation extends CommonITILValidation. Reached on: Assistance > Changes; Appliance > Changes tab.", + "topdesk": "https://docs.topdesk.com/en/requesting-a-change.html: \"A Preliminary Request for Change can only be dealt with as a Request for Change after it is authorized\" (read 2026-09-26). Reached on: Modules > Change Management.", + "stackiq": "No change-request workflow for applications. The only approval flow is for contracts: src/components/contracts/ContractApprovalPanel.vue on ContractDetail via /api/contracts/{uuid}/approval (routes.php:35-37), delegated to decidiq.", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3569,9 +3851,10 @@ "providerHow": "read-from-code", "note": "A contract can be typed as SLA, but no service level targets are recorded or tracked.", "evidence": { - "glpi": "docs, intelligence competitor_features#48904 'SLA management' (2026-07-23): SLA targets and escalation rules.", - "topdesk": "docs, intelligence competitor_features#48930 'SLA management' (2026-07-23): Service-level target tracking and reporting.", - "stackiq": "catalogContract.contractType enum includes 'SLA' (lib/Settings/softwarecatalogus_register.json:3344) as a label only; no service-level target, measurement or breach fields in any schema." + "glpi": "source read at 11.0.9: src/SLM.php:42 service level management with src/SLA.php:44 SLA and OLA targets on tickets (install/mysql/glpi-empty.sql:7304 glpi_tickets.slas_id_ttr), assigned by business rules (src/RuleCommonITILObject.php:73) that can key on the linked appliance (src/RuleCommonITILObject.php:305 assign_appliance). Reached on: Setup > Service levels.", + "topdesk": "https://docs.topdesk.com/en/track-when-you-respond-to-calls, response-times.html: \"you register and track how quickly your operators need to respond ... you need a Contract Management and SLM license\" (read 2026-09-26). Reached on: Contract Management and SLM.", + "stackiq": "catalogContract.contractType enum includes 'SLA' (lib/Settings/softwarecatalogus_register.json:3344) as a label only; no service-level target, measurement or breach fields in any schema.", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" } }, { @@ -3582,7 +3865,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "yes", "stackiq": "no", "built": { @@ -3595,8 +3878,10 @@ "providerHow": "read-from-code", "note": "End users cannot request software.", "evidence": { - "topdesk": "docs, intelligence competitor_features#48928 'Self-service portal' (2026-07-23): End-user portal for requests and knowledge, reduces direct support load.", - "stackiq": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls." + "topdesk": "https://docs.topdesk.com/en/mobile-access-to-the-self-service-portal.html: \"The SSP layout is suited to be displayed in a mobile interface\" (read 2026-09-26); https://tip.topdesk.com/c/86-webshop-is-connected-with-asset-management: roadmap card in column \"Building\", \"End-user can order items which are in Asset Management\" (read 2026-09-26); pricing lists \"Self-Service Portal\" and \"Webshop\". Reached on: Self-Service Portal.", + "stackiq": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls.", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: the 11.0 service catalog src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45 lists native forms for self service users (menu src/Html.php:1283), and a form question can offer software items to pick, src/Glpi/Form/QuestionType/QuestionTypeItem.php:180 Software::class, creating a ticket from the answer. Reached on: Self service > Service catalog." } }, { @@ -3607,7 +3892,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "yes", "stackiq": "no", "built": { @@ -3620,8 +3905,10 @@ "providerHow": "read-from-code", "note": "There is no native mobile app.", "evidence": { - "topdesk": "docs, intelligence competitor_features#48937 'Mobile app' (2026-07-23): Native mobile operator app.", - "stackiq": "No mobile app or mobile-specific surface in the repo; the app is the Nextcloud web UI (src/manifest.json)." + "topdesk": "https://docs.topdesk.com/en/installing-the-topdesk-mobile-store-application.html: \"Scan the QR code to download the app from the Play store\" (read 2026-09-26). Reached on: TOPdesk Mobile app.", + "stackiq": "No mobile app or mobile-specific surface in the repo; the app is the Nextcloud web UI (src/manifest.json).", + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'android\\|ios app\\|mobile app' over src/ templates/ returns nothing; the repository ships only the responsive web interface (templates/) and APIs (src/Glpi/Api/HL/Controller/CoreController.php:322 docs), no native mobile client." } }, { @@ -3632,8 +3919,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -3647,7 +3934,10 @@ "featureConfidence": "medium", "note": "The sync runs on a schedule and its last run time is shown, but only an admin can see and configure it, which is the rule for partial.", "evidence": { - "stackiq": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674)." + "stackiq": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674).", + "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"when tracking imports/Exchange exports via system events ... on a schedule\" (read 2026-09-26); https://tip.topdesk.com/c/116-support-for-importing-persons-and-operators-directly-from-local-active-directory: roadmap card in column \"Launched\", person import from AD (read 2026-09-26). Reached on: Settings > Import settings.", + "vng-softwarecatalogus": "unknown: only \"De kaart wordt dagelijks bijgewerkt\" is stated; no organisation or contact sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/17042 (read 2026-09-26)", + "glpi": "source read at 11.0.9: automatic actions are scheduled and show their last run, src/CronTask.php:59 with install/mysql/glpi-empty.sql:1610 glpi_crontasks.lastrun, but LDAP user and group synchronisation is not one of them (grep -i ldap over the cron seed in install/empty_data.php:438 finds none); it is the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users, which must be scheduled by the system cron. Organisation (supplier) records have no sync at all. Reached on: Setup > Automatic actions; CLI bin/console ldap:sync." } } ], @@ -3660,7 +3950,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "partial", "bluedolphin": "partial", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3675,10 +3965,12 @@ "featureConfidence": "high", "note": "The usage schema models this separation properly, but no stackiq page creates or edits a usage: the ObjectModal accepts type 'usage' (src/modals/Modals.vue:38) yet nothing opens it. Usages are only read by the roadmap, compliance matrix and vulnerability views.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: municipality adds the supplier's package and version to its own landscape (\"om het pakket toe te voegen aan je omgeving\") (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E1 \"Leveranciers onderhouden de gegevens van hun producten ... Gemeenten en Samenwerkingen onderhouden de gegevens van het eigen applicatieportfolio\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten.", "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", - "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/" + "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", + "topdesk": "unknown: one organisation per environment; a separate usage record is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: use is recorded as installations separate from the software product, src/Item_SoftwareVersion.php:39 (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions) per device, and licence assignments per item or user; there is no usage record of a module by an organisation as such. Reached on: Assets > Software > Installations tab." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend create usage (gebruik) records through /api/aangeboden-gebruik or the OpenRegister objects API, and is that frontend part of what stackiq ships?" }, @@ -3690,7 +3982,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "no", "built": { @@ -3703,7 +3995,10 @@ "providerHow": "read-from-code", "note": "There is no importer for the previous VNG Softwarecatalogus's registrations. The repair steps only rename stackiq's own earlier data, and the ArchiMate import brings in the GEMMA model, not organisations' entries.", "evidence": { - "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets" + "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", + "topdesk": "unknown: no import from the VNG Softwarecatalogus is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: this is the previous catalogue itself; no import of an earlier registration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: data from earlier GLPI versions is carried over by src/Update.php:172 doUpdates with the chain in install/migrations/ (update_0.85.x_to_0.90.0.php up to the 11.0 steps); data from another catalogue needs the separate datainjection plugin (pluginsGLPI/datainjection tag 2.15.11, inc/backendcsv.class.php). Reached on: web installer update; plugin Data injection." }, "pendingQuestion": "Is the data from the previous VNG Softwarecatalogus meant to be brought over by a one-off migration outside this repo (for example an OpenRegister register import of an export file)?" }, @@ -3715,8 +4010,8 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "yes", "bluedolphin": "partial", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -3730,10 +4025,12 @@ "featureConfidence": "medium", "note": "The connection model with direction and standard is complete, and the demo data ships six, but no stackiq page creates or edits one.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48842 'Application-to-application connection registry (koppelingen)' (2026-07-23): Records interfaces/connections between registered applications.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Selecteer vervolgens de betreffende pakketversie. De richting van het berichtenverkeer ... Selecteer vervolgens de betreffende standaard en versie\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > toevoegen.", "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", - "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it" + "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", + "topdesk": "https://docs.topdesk.com/en/hierarchy-of-relationships.html: \"When assets are linked with a link type , one of the assets often supplies a certain feature to another asset. The supplying asset therefore is the parent asset\" (read 2026-09-26). Direction via parent and child; no standard per relation. Reached on: Asset card > Relationships widget.", + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations stores a directed link from a source item to an impacted item with a name, added via src/Impact.php:1161 'Add relation'; there is no field for the standard or protocol used. Reached on: Appliance > Impact analysis tab, Add relation." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend register koppelingen through the OpenRegister objects API, and does it count as part of stackiq?" }, @@ -3742,10 +4039,10 @@ "area": "connections", "name": "Record that your organisation actually runs a given connection, not only that it exists.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3760,7 +4057,10 @@ "featureConfidence": "medium", "note": "The model records which connections a usage runs, but neither usages nor connections have a page.", "evidence": { - "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller" + "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", + "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Geef bij status in productie of gepland aan\"; connections are registered in the organisation's own landscape (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen.", + "glpi": "source read at 11.0.9: an impact relation (install/mysql/glpi-empty.sql:1247) is a single fact in one instance; there is no separate usage record saying the organisation runs it, and grep -n 'usage' src/ImpactRelation.php returns nothing." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend let an organisation record the connections it runs, through /api/koppelingen-gebruik or the objects API?" }, @@ -3769,10 +4069,10 @@ "area": "connections", "name": "See which connections you run together with other organisations.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3787,7 +4087,10 @@ "featureConfidence": "medium", "note": "Shared usage (with the connections it carries) is answerable through the API, but no stackiq page shows it.", "evidence": { - "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/" + "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", + "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A10: \"Een Samenwerking geeft aan welke gemeenten gebruik maken van een betreffende koppeling. Die gemeentenamen worden getoond\" (read 2026-09-26). Reached on: Alle koppelingen.", + "glpi": "source read at 11.0.9: relations live inside one instance (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and entities are subdivisions of one organisation (src/Entity.php:58); no cross organisation sharing of connections exists (grep -rli 'federat' src/ returns nothing)." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend show shared connections from /api/aangeboden-gebruik/deelnemers?" }, @@ -3799,7 +4102,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3814,8 +4117,10 @@ "featureConfidence": "high", "note": "The mapping is stored and can be filtered on, but no stackiq screen writes it: the module field is hideOnForm and the usage schema has no index or edit page; writes come through ArchiMate import, the OpenRegister objects API or the external VNG frontend.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48835 'Reference component mapping (referentiecomponenten)' (2026-07-23): Maps each registered software product onto GEMMA reference components/domains so functionality is comparable across suppliers. | docs, intelligence competitor_features#27551 'Reference Component Linking' (2026-04-12): Link software to GEMMA reference components", - "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Referentiecomponenten aangegeven door leverancier ... Toegevoegde referentiecomponenten\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", + "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; the only classification of an appliance is its type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." }, "pendingQuestion": "Does the Modules page's CnIndexPage create/edit dialog in nextcloud-vue 2.55.1 render module.referenceComponents (hideOnForm:true, items.$ref element in the AMEF register) as a working multiselect of reference components? nextcloud-vue's fieldsFromSchema (src/utils/schema.js:529) does not check hideOnForm." }, @@ -3827,7 +4132,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3842,8 +4147,10 @@ "featureConfidence": "medium", "note": "No stackiq page renders a GEMMA view. The enriched view data is served for an external frontend, and the org export draws applications into view copies that open in Archi.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48836 'Municipal application landscape registration' (2026-07-23): Municipalities register which software packages they use; auto-plotted on the GEMMA reference component map. | Rated yes because landscape auto-plotted on the reference component map.", - "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart.", + "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'gemma\\|archimate' over src/ templates/ locales/glpi.pot returns nothing; the only diagram is the impact graph (src/Impact.php:252 displayGraphView)." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend render /api/views/{id} with include_gebruik, and is that frontend in scope for stackiq's column?" }, @@ -3855,7 +4162,7 @@ "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3870,8 +4177,10 @@ "featureConfidence": "high", "note": "The API separates shared usage from own usage and names the source organisation, but nothing in stackiq draws it; in the ArchiMate export shared applications get the same style as own ones, so they are not drawn differently.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", - "stackiq": "lib/Service/ViewService.php:1187 getDeelnamesGebruikData + :924 tags shared usage with _type='deelnames' and _sourceOrganization; lib/Service/ArchiMateExportService.php:3005 org export gives every nested application the same green fillColor, deelnames only get their own folder (:3086)" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: cooperation packages: \"kies bij Organisaties welke gemeenten ... de betreffende applicatie gebruiken ... Het pakket verschijnt dan ook alleen op de lijst en kaart van de samenwerking en niet bij de gemeenten\" (read 2026-09-26). Drawing shared apart from own is not described. Reached on: Samenwerking > Pakketten > Organisaties.", + "stackiq": "lib/Service/ViewService.php:1187 getDeelnamesGebruikData + :924 tags shared usage with _type='deelnames' and _sourceOrganization; lib/Service/ArchiMateExportService.php:3005 org export gives every nested application the same green fillColor, deelnames only get their own folder (:3086)", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: no GEMMA views (grep -rli 'gemma' src/ returns nothing) and no partner sharing; the impact graph (src/Impact.php:1559 makeDataForCytoscape) draws one instance's items only." }, "pendingQuestion": "Does the external VNG frontend draw deelnames nodes differently from own usage on a GEMMA view?" }, @@ -3883,7 +4192,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -3898,7 +4207,10 @@ "featureConfidence": "low", "note": "A pure API row: the views endpoint is routed, authorised for logged-in users and returns the imported GEMMA views; elements come through OpenRegister's generic objects API.", "evidence": { - "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/docs, /api/views/{viewId} -> lib/Controller/ViewController.php:82,218 (@NoAdminRequired) -> lib/Service/ViewService.php:108,166 read views from the AMEF register; GEMMA elements are element objects in the AMEF register, readable through the OpenRegister objects API" + "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/docs, /api/views/{viewId} -> lib/Controller/ViewController.php:82,218 (@NoAdminRequired) -> lib/Service/ViewService.php:108,166 read views from the AMEF register; GEMMA elements are element objects in the AMEF register, readable through the OpenRegister objects API", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no API over GEMMA in the catalogue is documented; GEMMA overviews are copied from GEMMA Online tables; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api (read 2026-09-26)", + "glpi": "source read at 11.0.9: the v2 API controllers (src/Glpi/Api/HL/Controller/, for example AssetController.php:149 /Assets) expose GLPI itemtypes only; grep -rli 'gemma' src/ returns nothing." }, "pendingQuestion": "Is the view API reachable without a Nextcloud login (no #[PublicPage] on ViewController), and does the row require public access?" }, @@ -3910,7 +4222,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3925,8 +4237,10 @@ "featureConfidence": "high", "note": "A compliance record can be created on the Compliance index, but the standard-version relation points at element objects that live in the AMEF register while the page works on the voorzieningen register, so the version picker may not resolve; the free-text standardGemma field is the fallback. Not offered from the application page itself.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48840 'Standards support declaration' (2026-07-23): Suppliers declare which standards (StUF, ZGW/Zaakgericht APIs, etc.) a product supports.", - "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.standardVersion ($ref element, queryParams gemmaType=standaardversie) + compliancy.module + compliancy.standardGemma (string); src/manifest.json Komplianties /komplianties index on the voorzieningen register; ModuleDetail md-compliance object-list has allowCreate:false; module.standardVersions is hideOnForm" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"via de optie Voeg extra standaarden toe de gewenste standaard te selecteren ... Ondersteuning(gepland) en Compliancy\" (read 2026-09-26). Reached on: Supplier login > productversie > standaarden.", + "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.standardVersion ($ref element, queryParams gemmaType=standaardversie) + compliancy.module + compliancy.standardGemma (string); src/manifest.json Komplianties /komplianties index on the voorzieningen register; ModuleDetail md-compliance object-list has allowCreate:false; module.standardVersions is hideOnForm", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: no standards model (grep -rli 'standaard' src/ locales/glpi.pot returns nothing); software versions (install/mysql/glpi-empty.sql:6900) carry no supported standard." }, "pendingQuestion": "On /komplianties, does the create form's standardVersion select (items $ref element, which lives only in the AMEF register) list standard versions, or does it resolve against the voorzieningen register and come back empty/404 as the Standaarden page did before its register fix?" }, @@ -3938,7 +4252,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3953,7 +4267,10 @@ "featureConfidence": "high", "note": "The accept/decline logic is complete and authorised, but nothing in src/ calls it, so only the external VNG frontend or a script can use it. There is also no stackiq page for usage (gebruik) records at all.", "evidence": { - "stackiq": "lib/Controller/AanbodController.php:200 acceptAanbod and :303 denyAanbod, lib/Service/AanbodService.php:289 checks the active organisation is aanbieder or afnemer then re-owns the object; routes appinfo/routes.php PUT /api/aanbod/{uuid}/accept, DELETE /api/aanbod/{uuid}/deny; also /api/aangeboden-gebruik/{id}/set-self and /deny" + "stackiq": "lib/Controller/AanbodController.php:200 acceptAanbod and :303 denyAanbod, lib/Service/AanbodService.php:289 checks the active organisation is aanbieder or afnemer then re-owns the object; routes appinfo/routes.php PUT /api/aanbod/{uuid}/accept, DELETE /api/aanbod/{uuid}/deny; also /api/aangeboden-gebruik/{id}/set-self and /deny", + "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: suppliers see \"Mijn gemeenten\" (who registered their packages) but accepting or declining a usage is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: suppliers have no login or role (install/mysql/glpi-empty.sql:7067 glpi_suppliers is a plain record; profiles in src/Profile.php:55 are for users), so no supplier can accept or decline a claimed usage." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend (not in this repo) call PUT /api/aanbod/{uuid}/accept and /api/aangeboden-gebruik/{id}/set-self, and is that frontend part of what we ship?" }, @@ -3965,7 +4282,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -3980,8 +4297,10 @@ "featureConfidence": "high", "note": "The shared-usage enrichment on GEMMA views exists server-side but no stackiq page renders it, so a user cannot see peers' software per reference component in this app.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value. | docs, intelligence competitor_features#27552 'Municipality Comparison' (2026-04-12): Compare application landscapes between municipalities", - "stackiq": "lib/Controller/ViewController.php (routes GET /api/views, /api/views/{viewId}) enriches GEMMA views with shared usage (deelnames); src/store/modules/view.js:89 calls it but no component imports that store" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle gemeenten helpt bijvoorbeeld in het verkrijgen van inzicht welke gemeenten dezelfde pakketten gebruiken ... Ook met betrekking tot een bepaald beleidsthema, referentiecomponent of standaard\" (read 2026-09-26). Reached on: Inlogmenu > Alle gemeenten / Alle pakketoverzichten.", + "stackiq": "lib/Controller/ViewController.php (routes GET /api/views, /api/views/{viewId}) enriches GEMMA views with shared usage (deelnames); src/store/modules/view.js:89 calls it but no component imports that store", + "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: no reference components (grep -rli 'reference component' src/ returns nothing) and no data from comparable organisations, since each instance is standalone (src/Entity.php:58 entities are internal)." }, "pendingQuestion": "Does the external VNG frontend render /api/views with the deelnames enrichment, and does that count as a stackiq page?" }, @@ -3993,7 +4312,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4008,8 +4327,10 @@ "featureConfidence": "medium", "note": "There is no usage page and no 'used by' list on the application page. A supplier may see usages of its own product through the generic related panel, other roles see only their own usages; the per-product usage endpoints have no caller in src/.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48837 'Cross-municipality software comparison' (2026-07-23): Municipalities compare used software and connections with peer gemeenten; core network-effect value.", - "stackiq": "register :2656 usage (consumer, module); usage read rule lets aanbod-beheerder read usages where provider = own organisation (:3137); ModuleDetail md-related widget src/manifest.json:491; GET /api/koppelingen-gebruik/{uuid} and /api/gebruik in lib/Controller/AangebodenGebruikController.php, lib/Controller/GebruikController.php" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Marktscans: \"kunnen ingelogde gemeenten of samenwerkingen zien bij welke collega-gemeenten betreffende pakketversie in het applicatielandschap staat (klik daarvoor op het getal boven Ingevuld door)\" (read 2026-09-26). Reached on: Package page > Ingevuld door.", + "stackiq": "register :2656 usage (consumer, module); usage read rule lets aanbod-beheerder read usages where provider = own organisation (:3137); ModuleDetail md-related widget src/manifest.json:491; GET /api/koppelingen-gebruik/{uuid} and /api/gebruik in lib/Controller/AangebodenGebruikController.php, lib/Controller/GebruikController.php", + "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: within one instance the version Summary tab shows installations per entity, src/Item_SoftwareVersion.php:850 showForVersionByEntity, and the installation list carries the entity column (src/Item_SoftwareVersion.php:484); organisations outside the instance are not visible. Reached on: Assets > Software > version > Summary tab." }, "pendingQuestion": "Does the generic 'related' widget on ModuleDetail list usage objects that point at the module (inverse relation), and for which roles?" }, @@ -4021,7 +4342,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4036,7 +4357,10 @@ "featureConfidence": "high", "note": "The ReviewsPanel path holds reviews as pending and an admin approves them in settings. But the generic Reviews index /reviews shows pending reviews to every catalogue group and its Add form writes software-review through OpenRegister directly, where status (enum incl. approved) is a visible form field, so moderation can be bypassed.", "evidence": { - "stackiq": "lib/Service/ReviewService.php:232 forces pending; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; src/views/settings/StackiqSettings.vue:98 ModerationQueue type=software-review via src/utils/adminApi.js; lib/Settings/register.d/catalog-ratings.json public read only matches status approved but every catalogue group reads all reviews and may create them" + "stackiq": "lib/Service/ReviewService.php:232 forces pending; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; src/views/settings/StackiqSettings.vue:98 ModerationQueue type=software-review via src/utils/adminApi.js; lib/Settings/register.d/catalog-ratings.json public read only matches status approved but every catalogue group reads all reviews and may create them", + "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no reviews are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: there are no product reviews (see mkt-reviews); the only moderation is knowledge base publication by rights on src/KnowbaseItem.php:57, unrelated to reviews." }, "pendingQuestion": "Does the installed OpenRegister let a catalogue user create a software-review with status=approved through /reviews (the generic create), bypassing ReviewService?" }, @@ -4045,10 +4369,10 @@ "area": "market", "name": "Keep your application landscape and connections hidden from suppliers.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4062,7 +4386,10 @@ "providerHow": "read-from-code", "note": "The register declares organisation-scoped reads, so a supplier sees only usages of its own products and published connections. This rests on the installed OpenRegister executing the declared match rules.", "evidence": { - "stackiq": "register usage authorization (:3137) reads scoped to _organisation or consumer; aanbod-beheerder also reads usages where provider = own organisation; connection read (:3855) public when published and by provider; openspec/specs/vendor-visibility-rbac" + "stackiq": "register usage authorization (:3137) reads scoped to _organisation or consumer; aanbod-beheerder also reads usages where provider = own organisation; connection read (:3855) public when published and by provider; openspec/specs/vendor-visibility-rbac", + "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E2: \"Leveranciers kunnen alleen hun eigen applicatieversies die in gebruik zijn bij gemeenten en samenwerkingen zien ... overigens ziet de leverancier geen status-informatie. Die is vertrouwelijk\" (read 2026-09-26)", + "glpi": "source read at 11.0.9: suppliers are records without accounts (install/mysql/glpi-empty.sql:7067 glpi_suppliers) and all data is visible only through the profiles and entities assigned to users (install/mysql/glpi-empty.sql:5917 glpi_profiles_users), so a supplier sees nothing unless given an account. Reached on: Administration > Profiles." }, "pendingQuestion": "Does the installed OpenRegister enforce the declared authorization.read match rules (e.g. {group: aanbod-beheerder, match: {provider: $organisation}}) on usage and connection reads?" }, @@ -4071,11 +4398,11 @@ "area": "market", "name": "Use the catalogue free of charge as a municipality or supplier.", "origin": "competitor", - "vng-softwarecatalogus": "yes", + "vng-softwarecatalogus": "unknown", "sap-leanix": "no", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "no", "stackiq": "partial", "built": { "state": "built", @@ -4088,10 +4415,11 @@ "providerHow": "read-from-code", "note": "The software is free and published entries are publicly readable, but the repo ships no hosted public catalogue; the public-facing frontend is the external VNG one.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", + "vng-softwarecatalogus": "unknown: public browsing is open (\"Iedereen kan de softwarecatalogus raadplegen\", FAQ E6) but no page states the use is free of charge; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden (read 2026-09-26)", "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", - "glpi": "docs, intelligence competitor_features#48912 '100% open source (GPL)' (2026-07-23): Fully GPL; no license fees, broad device coverage.", - "stackiq": "LICENSE (EUPL-1.2) and appinfo/info.xml: the app is free open source; catalogService and organization carry public read rules for published entries; module's public read also admits every object with registeredBy Supplier, a rule with no publication-date or status condition (lib/Settings/softwarecatalogus_register.json:7322-7327, corrected 2026-09-26); public intake POST /api/intake/register" + "glpi": "source read at 11.0.9: LICENSE:1 GNU General Public License version 3, so any municipality or supplier can run it without licence fees; there is no free hosted public service, the paid cloud is GLPI Network by Teclib. Reached on: self hosted install.", + "stackiq": "LICENSE (EUPL-1.2) and appinfo/info.xml: the app is free open source; catalogService and organization carry public read rules for published entries; module's public read also admits every object with registeredBy Supplier, a rule with no publication-date or status condition (lib/Settings/softwarecatalogus_register.json:7322-7327, corrected 2026-09-26); public intake POST /api/intake/register", + "topdesk": "https://www.topdesk.com/en/pricing/: \"Essential ... £51 Per agent/month\", \"Engaged ... £72\", \"Excellent ... £101\" (read 2026-09-26)" }, "pendingQuestion": "Is a hosted, free-of-charge stackiq instance offered to municipalities and suppliers (the competitor offer is a public service, not software)?" }, @@ -4100,11 +4428,11 @@ "area": "lifecycle", "name": "Get a warning before an application or version falls out of support.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "partial", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -4118,9 +4446,11 @@ "featureConfidence": "high", "note": "You see an 'approaching end of support' badge when you open the roadmap. A pushed warning rests only on a register declaration, and that rule addresses catalogue admins and the version's managers, not the organisations using the application.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "vng-softwarecatalogus": "unknown: suppliers set a status \"Einde ondersteuning\" and municipalities are notified of supplier changes, but an advance warning before support ends is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/pakketversies (read 2026-09-26)", "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", - "stackiq": "src/views/LifecycleRoadmapView.vue:73-86 EOL passed/approaching/withdrawn badges with EOL_WINDOW_DAYS=180 (:143); lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications eol-approaching (scheduled, dateEndSupport withinNext P180D, recipients software-catalog-admins + object-acl manage) is a declaration only; no notification code in lib (no INotificationManager use)" + "stackiq": "src/views/LifecycleRoadmapView.vue:73-86 EOL passed/approaching/withdrawn badges with EOL_WINDOW_DAYS=180 (:143); lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications eol-approaching (scheduled, dateEndSupport withinNext P180D, recipients software-catalog-admins + object-acl manage) is a declaration only; no notification code in lib (no INotificationManager use)", + "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"…when a card date will be reached within a particular period of time\" (read 2026-09-26). Works on any date field, e.g. a self-defined end-of-support date; no built-in end-of-support. Reached on: Action Management > events.", + "glpi": "source read at 11.0.9: alerts exist for dates GLPI stores, licence expiry (src/NotificationTargetSoftwareLicense.php:46 'Alarms on expired licenses'), contract end and notice (src/NotificationTargetContract.php:47) and warranty expiry (src/Infocom.php:651 cronInfocom); no end of support date exists on an application or version (install/mysql/glpi-empty.sql:6900 glpi_softwareversions). Reached on: Setup > Notifications; Setup > Automatic actions." }, "pendingQuestion": "Does the installed OpenRegister dispatch the scheduled x-openregister-notifications rule 'eol-approaching' on moduleVersion, and to whom?" }, @@ -4132,7 +4462,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4148,7 +4478,10 @@ "note": "The matcher is complete, but it is off by default, only an admin can switch it on, each module needs an eolProductSlug, and the feed data only exists when integriq's endoflife.date source is provisioned.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | Rated partial because obsolescence tracking; source of dates not named.", - "stackiq": "lib/BackgroundJob/EolSyncJob.php (registered appinfo/info.xml:101) + appinfo/routes.php:292-295 /api/eol-sync/* -> lib/Service/EolSyncService.php:145 run() reads eol_cycle objects via OpenRegister ObjectService (:328), stamps dateEndSupport on module versions via EolMatcherService; enabled defaults to false (lib/Service/SettingsService.php:7211); lib/Settings/connections.json eol-feed is a switch, off until enabled; the cycles are fetched by integriq's endoflife-date source" + "stackiq": "lib/BackgroundJob/EolSyncJob.php (registered appinfo/info.xml:101) + appinfo/routes.php:292-295 /api/eol-sync/* -> lib/Service/EolSyncService.php:145 run() reads eol_cycle objects via OpenRegister ObjectService (:328), stamps dateEndSupport on module versions via EolMatcherService; enabled defaults to false (lib/Service/SettingsService.php:7211); lib/Settings/connections.json eol-feed is a switch, off until enabled; the cycles are fetched by integriq's endoflife-date source", + "topdesk": "unknown: no end-of-life feed is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: end-of-support comes from supplier input; no public feed is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -i 'end_of_support\\|endoflife' over install/mysql/glpi-empty.sql and src/ returns nothing; no external lifecycle feed is read (the only outbound catalogues are the plugin marketplace, src/Glpi/Marketplace/). The marketplace client, the only outbound catalogue, is src/Glpi/Marketplace/Controller.php:64." }, "pendingQuestion": "Is integriq's endoflife-date source (eol_product/eol_cycle register) provisioned on a default install, so that switching the sync on actually finds cycles?" }, @@ -4157,10 +4490,10 @@ "area": "lifecycle", "name": "Record which application is planned to replace another.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4175,7 +4508,10 @@ "featureConfidence": "high", "note": "The planned replacement is stored per usage and displayed on the roadmap, but no stackiq page lets you record it.", "evidence": { - "stackiq": "lib/Settings/softwarecatalogus_register.json usage.plannedReplacement ($ref module) + plannedReplacementDate; read by src/views/LifecycleRoadmapView.vue:400; no usage page in src/manifest.json and navigationStore.setModal('usage') is never called (src/modals/Modals.vue:38 lists usage but nothing opens it)" + "stackiq": "lib/Settings/softwarecatalogus_register.json usage.plannedReplacement ($ref module) + plannedReplacementDate; read by src/views/LifecycleRoadmapView.vue:400; no usage page in src/manifest.json and navigationStore.setModal('usage') is never called (src/modals/Modals.vue:38 lists usage but nothing opens it)", + "topdesk": "unknown: no replacement link is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"geplande harmonisaties ... status gepland met bijbehorende datum ... de uit te faseren applicaties van die status worden voorzien inclusief datum\" (read 2026-09-26). No explicit replaces link. Reached on: Mijn softwarecatalogus > Pakketten > Planning.", + "glpi": "source read at 11.0.9: a software can be flagged as an 'Upgrade from' another software, templates/pages/assets/software.html.twig:46 to :50 (is_update with softwares_id, install/mysql/glpi-empty.sql:6864 and :6865); this records succession after the fact, with no planned replacement link for appliances. Reached on: Assets > Software form, Upgrade from." }, "pendingQuestion": "Is the external VNG Softwarecatalogus frontend (which writes usage objects) counted as part of stackiq for this row?" }, @@ -4187,7 +4523,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4201,7 +4537,10 @@ "note": "The TIME classification is stored and reported per quadrant, but there is no page in stackiq where a user classifies an application.", "evidence": { "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", - "stackiq": "lib/Settings/softwarecatalogus_register.json usage.timeClassification enum Tolerate/Invest/Migrate/Eliminate + timeRationale + timeReviewDate; read by lib/Service/PortfolioReportService.php and rendered in src/views/organisaties/PortfolioReport.vue:112 quadrant chart; src/modals/object/ObjectModal.vue:178 has the enum select but is never opened for usage" + "stackiq": "lib/Settings/softwarecatalogus_register.json usage.timeClassification enum Tolerate/Invest/Migrate/Eliminate + timeRationale + timeReviewDate; read by lib/Service/PortfolioReportService.php and rendered in src/views/organisaties/PortfolioReport.vue:112 quadrant chart; src/modals/object/ObjectModal.vue:178 has the enum select but is never opened for usage", + "topdesk": "unknown: no TIME classification is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no TIME classification is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'tolerate\\|eliminate' over src/ locales/glpi.pot returns nothing; a TIME class can only be held in a repurposed single choice dropdown such as the appliance status (install/mysql/glpi-empty.sql:8950 states_id, values from src/State.php:45) or type (install/mysql/glpi-empty.sql:8941). Reached on: Management > Appliances, Status or Type field." }, "pendingQuestion": "Is the external VNG frontend or OpenRegister's generic object editor the intended place to set timeClassification, and does it count here?" }, @@ -4210,7 +4549,7 @@ "area": "contracts", "name": "Register a contract for a service with its number, type, term and cost.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", @@ -4228,9 +4567,9 @@ "featureConfidence": "high", "note": "All the fields are on the contract form, but a contract requires a usage (gebruik) record and no stackiq page can create one, so on a fresh install the form cannot be completed without data from elsewhere (demo data, API, external frontend).", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", - "glpi": "docs, intelligence competitor_features#48905 'Financial & contract management' (2026-07-23): Purchase, contract, warranty and budget tracking against assets. | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145509 'C-parties-and-contacts-1 A contract is a record with its own term and costs, linked to the party it binds and the cases raised under it': glpi: Contracts (Management, Contracts, front/contract_item.php, contractcost.php, ticket_contract.php) Lane findings: D-glpi-49.", - "topdesk": "docs, intelligence competitor_features#48932 'Contract & vendor management' (2026-07-23): Track supplier contracts and operational agreements.", + "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; their absence is not stated either; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1483 glpi_contracts with name, num (contract number), contracttypes_id, begin_date, duration, notice and renewal, and costs in install/mysql/glpi-empty.sql:1458 glpi_contractcosts. Reached on: Management > Contracts.", + "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Contract Number (mandatory) ... Type ... Start Date (mandatory) ... End Date (mandatory) ... Costs (Services)\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > New.", "stackiq": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)" }, "pendingQuestion": "Does the installed OpenRegister accept a catalogContract without the required usage (schema hardValidation false), and can the related-object picker create a usage inline?" @@ -4240,11 +4579,11 @@ "area": "contracts", "name": "Get warned before a contract expires.", "origin": "own-code", - "vng-softwarecatalogus": "no", + "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "yes", + "topdesk": "yes", "stackiq": "no", "built": { "state": "specified", @@ -4259,9 +4598,11 @@ "featureConfidence": "high", "note": "The only expiry warning is a declared OpenRegister notification whose filter value 'Actief' never matches the English status 'Active', so even if OpenRegister dispatches it, no contract qualifies. No page shows contracts that are about to expire.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48846 'No lifecycle / contract / vulnerability tracking' (2026-07-23): GAP: registry only -- no EOL, contract, vulnerability or CMDB asset lifecycle management.", + "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS renewal dates.", - "stackiq": "lib/Settings/softwarecatalogus_register.json:3255 x-openregister-notifications contract-expiry filters status equals 'Actief' but the status enum is Active/Expired/In negotiation (:3428), and the subject uses {{contractNummer}}/{{eindDatum}} while fields are contractNumber/endDate; Contracten quick filter 'Expiring / expired' filters status Expired only (src/manifest.json:527)" + "stackiq": "lib/Settings/softwarecatalogus_register.json:3255 x-openregister-notifications contract-expiry filters status equals 'Actief' but the status enum is Active/Expired/In negotiation (:3428), and the subject uses {{contractNummer}}/{{eindDatum}} while fields are contractNumber/endDate; Contracten quick filter 'Expiring / expired' filters status Expired only (src/manifest.json:527)", + "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"To prevent the accidental extension of unwanted contracts, TOPdesk warns you when contracts are about to expire\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Reminder date Date on which an operator should be reminded about the contract, e.g. ahead of expiry\" (read 2026-09-26). Reached on: Contract card > Reminder date.", + "glpi": "source read at 11.0.9: src/Contract.php:1092 cronContract computes end and notice dates and sends the events of src/NotificationTargetContract.php:47 (end of contract, notice, periodicity, periodicity notice); install/mysql/glpi-empty.sql:1508 glpi_contracts.alert sets which alerts apply. Reached on: Management > Contracts, Email alarms field; Setup > Notifications." }, "pendingQuestion": "Does the installed OpenRegister dispatch scheduled x-openregister-notifications, and does it compare the filter value case/locale-insensitively (it cannot map 'Actief' to 'Active')?" }, @@ -4273,8 +4614,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "no", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -4289,7 +4630,10 @@ "featureConfidence": "high", "note": "The approval path through decidiq works and only an approved outcome sets Active. Nothing stops a user from creating or editing a contract with status Active directly in the generic form, so 'only after an approval' is not enforced.", "evidence": { - "stackiq": "lib/Service/ContractApprovalService.php:254 submitForApproval dispatches OCA\\Decidiq\\Event\\DecisionRequestedEvent (fail-closed), :412 projectOutcome sets status Active only on approved; src/manifest.json:579 ContractApprovalPanel on ContractDetail; but register :3428 status enum incl. Active is an editable form field and approvalState (register.d/contracts-to-decidesk.json) is not readOnly; the declared x-openregister-lifecycle uses Dutch states 'In onderhandeling'/'Actief' that match no enum value" + "stackiq": "lib/Service/ContractApprovalService.php:254 submitForApproval dispatches OCA\\Decidiq\\Event\\DecisionRequestedEvent (fail-closed), :412 projectOutcome sets status Active only on approved; src/manifest.json:579 ContractApprovalPanel on ContractDetail; but register :3428 status enum incl. Active is an editable form field and approvalState (register.d/contracts-to-decidesk.json) is not readOnly; the declared x-openregister-lifecycle uses Dutch states 'In onderhandeling'/'Actief' that match no enum value", + "topdesk": "https://docs.topdesk.com/en/registering-and-validating-contracts.html: \"Create a new Preliminary Contract card ... Validate the contract. You have created an active contract\" (read 2026-09-26). A validation step, no recorded approval decision. Reached on: Contract card > Validate Contract.", + "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -n 'alidation' src/Contract.php returns nothing and no ContractValidation class exists; approvals exist only for ITIL objects (src/ChangeValidation.php:39), and the contract status is a free dropdown (install/mysql/glpi-empty.sql:1512 states_id)." }, "pendingQuestion": "Does the installed OpenRegister enforce x-openregister-lifecycle transitions on catalogContract.status, given its states are Dutch ('Actief') and the enum is English ('Active')?" }, @@ -4301,7 +4645,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4314,7 +4658,10 @@ "providerHow": "read-from-code", "note": "The list shows how many in-production usages are exposed to each vulnerability. The per-organisation exposure lives on a detail tab the list does not open, so a user sees the count but not reliably who is exposed.", "evidence": { - "stackiq": "src/utils/vulnerabilityExposure.js:54 in-production join vulnerability.modules -> usage.module -> usage.consumer; count shown in the list (src/views/KwetsbaarhedenView.vue:111); per-organisation rows in VulnerabilityExposurePanel on KwetsbaarheidDetail tab (src/manifest.json:997), but a list row opens the edit modal, not the detail page (KwetsbaarhedenView.vue:417)" + "stackiq": "src/utils/vulnerabilityExposure.js:54 in-production join vulnerability.modules -> usage.module -> usage.consumer; count shown in the list (src/views/KwetsbaarhedenView.vue:111); per-organisation rows in VulnerabilityExposurePanel on KwetsbaarheidDetail tab (src/manifest.json:997), but a list row opens the edit modal, not the detail page (KwetsbaarhedenView.vue:417)", + "topdesk": "unknown: vulnerabilities are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no vulnerability data exists (grep -rli 'cve' src/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74), so exposure cannot be derived even though installations per entity are known (src/Item_SoftwareVersion.php:850)." }, "pendingQuestion": "Is KwetsbaarheidDetail reachable from any page, for example by clicking a vulnerability in ModuleDetail's Related panel?" }, @@ -4326,7 +4673,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4341,7 +4688,10 @@ "featureConfidence": "high", "note": "The alert is declared, not code in stackiq, and it goes to catalogue admins and the record's managers, not to the organisations that use the affected software.", "evidence": { - "stackiq": "register.json:1622 x-openregister-notifications 'vulnerability-reported' on vulnerability, trigger created, channels nc-notification + email, recipients group software-catalog-admins and object-acl manage (a declaration only)" + "stackiq": "register.json:1622 x-openregister-notifications 'vulnerability-reported' on vulnerability, trigger created, channels nc-notification + email, recipients group software-catalog-admins and object-acl manage (a declaration only)", + "topdesk": "unknown: vulnerabilities are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no vulnerability functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no vulnerability events among notification targets; software notifications are licence expiry only (src/NotificationTargetSoftwareLicense.php:46)." }, "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications 'vulnerability-reported' rule on the vulnerability schema, and can recipients be the consumers of the affected modules?" }, @@ -4350,10 +4700,10 @@ "area": "organisations", "name": "Let a new organisation sign itself up without an account.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4368,7 +4718,10 @@ "featureConfidence": "high", "note": "The anonymous sign-up endpoint is complete and lands in moderation, but stackiq has no sign-up form. The schema also grants 'public' create on organization, so an anonymous generic OpenRegister create could skip the intake's pending stamp.", "evidence": { - "stackiq": "lib/Controller/IntakeController.php:74 PublicPage + AnonRateLimit(5/h) on POST /api/intake/register; lib/Service/IntakeService.php:146 forces registrationStatus pending, publicationDate null; no caller in src/. Separately, organization authorization.create includes 'public' (register :2467)" + "stackiq": "lib/Controller/IntakeController.php:74 PublicPage + AnonRateLimit(5/h) on POST /api/intake/register; lib/Service/IntakeService.php:146 forces registrationStatus pending, publicationDate null; no caller in src/. Separately, organization authorization.create includes 'public' (register :2467)", + "topdesk": "unknown: organisations signing themselves up is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Als leverancier kunt u zich aanmelden door de volgende gegevens te sturen naar softwarecatalogus@vng.nl\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-gemeente-aanmelden: cooperations without an account \"vraag deze dan aan door een mail te sturen\" (read 2026-09-26). Sign-up by e-mail, no online form.", + "glpi": "source read at 11.0.9: suppliers are created by staff only (src/Supplier.php:75 sets is_active on add from the staff form) and there is no public sign up page among front/ pages (front/lostpassword.php and front/initpassword.php are the only anonymous account pages)." }, "pendingQuestion": "Does the external VNG frontend post to /api/intake/register, and does OpenRegister's generic public create on organization let an anonymous caller set registrationStatus/status/publicationDate directly?" }, @@ -4380,8 +4733,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "no", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -4395,7 +4748,10 @@ "featureConfidence": "high", "note": "Conversion and role-based group assignment exist, manual and automatic on create for active organisations. Both read an email field the contact schema no longer has, so a contact created through the current form (contactsUid only) fails with 'No email address found' unless it carries legacy data.", "evidence": { - "stackiq": "lib/Controller/ContactpersonenController.php:393 convertToUser -> lib/Service/Stackiq/ContactPersonHandler.php:292 createUserAccount reads objectData['email'] (:299); automatic path lib/EventListener/StackiqEventListener.php -> lib/Service/ContactpersoonService.php:128 also reads contactData['email']; contactPerson schema (:1788) declares no email (identity moved to Nextcloud Contacts via contactsUid); UI: src/components/ContactpersonenList.vue:97 'Convert to User' inside OrganisatieCard" + "stackiq": "lib/Controller/ContactpersonenController.php:393 convertToUser -> lib/Service/Stackiq/ContactPersonHandler.php:292 createUserAccount reads objectData['email'] (:299); automatic path lib/EventListener/StackiqEventListener.php -> lib/Service/ContactpersoonService.php:128 also reads contactData['email']; contactPerson schema (:1788) declares no email (identity moved to Nextcloud Contacts via contactsUid); UI: src/components/ContactpersonenList.vue:97 'Convert to User' inside OrganisatieCard", + "topdesk": "https://docs.topdesk.com/en/step-2, operator-import-with-a-linked-person.html: \"To create operators with a person card linked via the Supporting Files import\" (read 2026-09-26); https://docs.topdesk.com/en/assigning-or-editing-self-service-portal-login-data.html: \"select the TOPdesk field Has access to Self-Service Portal and map it\" (read 2026-09-26). Reached on: Supporting Files imports.", + "vng-softwarecatalogus": "unknown: no conversion of contact persons into accounts is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)", + "glpi": "source read at 11.0.9: contacts (src/Contact.php:45) and users are separate itemtypes with no conversion action; user accounts come from manual creation, LDAP import (src/AuthLDAP.php:59) or authorisation rules (src/RuleRight.php:297 profile action)." }, "pendingQuestion": "Does a contactPerson created via the current form reach createUserAccount with an email (e.g. resolved from Nextcloud Contacts by contactsUid somewhere I did not find), or does conversion fail for every post-migration contact?" }, @@ -4407,7 +4763,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4422,8 +4778,10 @@ "featureConfidence": "medium", "note": "A cooperation can be registered with its participant organisations. The landscape it shares is only exposed through the deelnemers API and the unrendered view enrichment; no page shows it, and there is no usage page to record it.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48844 'Municipal cooperation / shared-service management' (2026-07-23): Manages gemeente-samenwerking (shared service centres) registering a joint landscape.", - "stackiq": "register organization.type 'Collaboration' + participants/deelnames (:2236); usage.participants (:2718); shared landscape endpoint GET /api/aangeboden-gebruik/deelnemers (lib/Controller/AangebodenGebruikController.php) has no caller in src/" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"Handleiding beheer gemeente-samenwerking ... Samenwerkingsverbanden die als doel hebben om de applicatielandschappen van de aangesloten gemeenten te harmoniseren\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: cooperation selects the member municipalities per package (read 2026-09-26). Reached on: Samenwerking account > Pakketten.", + "stackiq": "register organization.type 'Collaboration' + participants/deelnames (:2236); usage.participants (:2718); shared landscape endpoint GET /api/aangeboden-gebruik/deelnemers (lib/Controller/AangebodenGebruikController.php) has no caller in src/", + "topdesk": "unknown: cooperations of organisations are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: entities form a tree (src/Entity.php:58 extends CommonTreeDropdown) and records flagged recursive are shared with all child entities (src/Appliance.php:325 is_recursive), so a parent entity can hold a landscape shared by several subordinate units; there is no cooperation of independent organisations. Reached on: Administration > Entities; Appliance Child entities field." }, "pendingQuestion": "Does the external VNG frontend show a cooperation's shared landscape from /api/aangeboden-gebruik/deelnemers?" }, @@ -4432,11 +4790,11 @@ "area": "organisations", "name": "Keep each organisation's records visible only to that organisation unless published.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "specified", @@ -4449,8 +4807,10 @@ "providerHow": "read-from-code", "note": "Organisation-scoped reads are declared per schema and the custom endpoints add their own guards. Whether generic pages are actually segregated depends on OpenRegister executing those match rules.", "evidence": { - "glpi": "docs, intelligence competitor_features#48910 'Multi-entity (tenant) segregation' (2026-07-23): Hierarchical entities for multi-org / multi-department isolation.", - "stackiq": "register authorization.read rules with {match: {_organisation: $organisation}} on catalogContract (:3474), contactPerson (:1788), usage (:3137), connection (:3855); public reads only for published entries; lib/Controller/ContactpersonenController.php:293 org guard on the custom endpoint" + "glpi": "source read at 11.0.9: every query on entity scoped items is restricted to the user's active entities, src/DbUtils.php:920 getEntitiesRestrictCriteria; records carry entities_id and is_recursive (install/mysql/glpi-empty.sql:8937 and :8938 on glpi_appliances), so an entity's records stay invisible to other entities unless shared down the tree. Reached on: entity selector in the header.", + "stackiq": "register authorization.read rules with {match: {_organisation: $organisation}} on catalogContract (:3474), contactPerson (:1788), usage (:3137), connection (:3855); public reads only for published entries; lib/Controller/ContactpersonenController.php:293 org guard on the custom endpoint", + "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"To restrict access to specific data, link the operator to branch, operator, or category filters\" (read 2026-09-26). Reached on: Operator card > filters.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Alle gegevens ingevoerd door de gemeenten en samenwerkingen zijn alleen zichtbaar voor gemeentelijke raadplegers en beheerders\"; E2 \"Ingelogde gemeenten en samenwerkingsverbanden kunnen de applicatielandschappen en koppelingen van collega-gemeenten ... bekijken\" (read 2026-09-26)" }, "pendingQuestion": "Does the installed OpenRegister evaluate authorization.read match rules with $organisation on the generic object list and detail endpoints the stackiq pages use?" }, @@ -4459,10 +4819,10 @@ "area": "organisations", "name": "Make the first user of an organisation its administrator and manager of later users.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4477,7 +4837,10 @@ "featureConfidence": "medium", "note": "The first user of an organisation becomes its admin and later users get that admin as manager. It rides on the contact-to-account path, which reads an email field the current contact schema lacks, so it only fires for contacts that carry one.", "evidence": { - "stackiq": "lib/Service/Stackiq/ContactPersonHandler.php:646 first contact of an organisation gets the organisation-admin groups; lib/Service/Stackiq/HierarchyHandler.php:79 ensureOrganizationBeheerder and :130 setupManagerRelationships make later users report to the primary beheerder" + "stackiq": "lib/Service/Stackiq/ContactPersonHandler.php:646 first contact of an organisation gets the organisation-admin groups; lib/Service/Stackiq/HierarchyHandler.php:79 ensureOrganizationBeheerder and :130 setupManagerRelationships make later users report to the primary beheerder", + "topdesk": "unknown: first-user administrator rules are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/17042: \"Vanuit de gemeente is minimaal één gebruiker aangewezen als beheerder. Deze gebruiker kan nieuwe accounts aanmaken voor collega's\" (read 2026-09-26). Reached on: Gebruikersbeheer.", + "glpi": "source read at 11.0.9: an administrator can delegate user management per entity with a profile holding user rights, and GLPI stops a delegate from granting a profile stronger than their own, src/Profile.php:744 currentUserHaveMoreRightThan and src/Profile.php:679 getUnderActiveProfileRestrictCriteria; nothing makes the first user of an organisation its administrator automatically. Reached on: Administration > Users > Authorizations tab." }, "pendingQuestion": "Same as org-contact-to-account: does conversion get an email for a post-migration contact?" }, @@ -4489,7 +4852,7 @@ "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4504,8 +4867,10 @@ "featureConfidence": "medium", "note": "Anonymous browsing rests on RBAC read rules declared in the register and executed by OpenRegister; stackiq ships no public page, and the browsing surface is the external VNG Softwarecatalogus frontend, which is not in this repo. Note the module rule also exposes every registeredBy=Supplier module regardless of publication date.", "evidence": { - "vng-softwarecatalogus": "docs, intelligence competitor_features#48845 'Public open-access catalog' (2026-07-23): Catalog is publicly browsable; free to use for municipalities and suppliers.", - "stackiq": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public on publicationDate<=$now (and, separately, on registeredBy=Supplier); lib/Settings/softwarecatalogus_register.json:1559 catalogService same; suite read is plain 'public' (lib/Settings/softwarecatalogus_register.json:1270). No stackiq route is #[PublicPage] except intake/review aggregate/gebruik (lib/Controller/GebruikController.php:102 returns an empty envelope to anonymous callers). The app's pages are all behind Nextcloud login (appinfo/routes.php:313 SPA catch-all)." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Iedereen kan de softwarecatalogus raadplegen ... De gegevens ingevoerd door de leveranciers zijn openbaar\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketten: package list readable without login (read 2026-09-26). Reached on: Alle pakketten.", + "stackiq": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public on publicationDate<=$now (and, separately, on registeredBy=Supplier); lib/Settings/softwarecatalogus_register.json:1559 catalogService same; suite read is plain 'public' (lib/Settings/softwarecatalogus_register.json:1270). No stackiq route is #[PublicPage] except intake/review aggregate/gebruik (lib/Controller/GebruikController.php:102 returns an empty envelope to anonymous callers). The app's pages are all behind Nextcloud login (appinfo/routes.php:313 SPA catch-all).", + "topdesk": "unknown: the Self-Service Portal requires a login per the SSP login settings; public browsing of assets is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: the only anonymous content is the public FAQ, gated by use_public_faq (src/KnowbaseItem.php:131, src/Document.php:717); asset, appliance and software lists all require a session (src/Glpi/Controller/GenericListController.php checks canView)." }, "pendingQuestion": "Does the installed OpenRegister honour the {group: public, match: {publicationDate: {$lte: $now}}} read rule on module/catalogService for an anonymous GET /apps/openregister/api/objects, and which public frontend (the external VNG Softwarecatalogus site) is the intended browse surface?" }, @@ -4530,8 +4895,10 @@ "providerHow": "read-from-code", "note": "There is no dedicated developer-facing public API: public access to the offering is whatever OpenRegister executes from the declared read rules, and stackiq's own offering endpoint requires login.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141847 '12.19 Public data API with certificates or API keys': the API is fully authenticated, never public: user tokens plus optional app tokens with IP allow-listing (`apirest.md:62-67`, `src/APIClient.php:42`) and OAuth2 with scopes (`src/Glpi/OAuth/`). No anonymous public datase | Rated no because API is always authenticated, source-read 2026-09-14.", - "stackiq": "Anonymous read of the supplier offering depends on declared rules: lib/Settings/softwarecatalogus_register.json:7307 module read includes public on publicationDate<=$now and on registeredBy=Supplier; lib/Settings/softwarecatalogus_register.json:1559 catalogService public on publicationDate. Stackiq's own offering endpoint lib/Controller/AanbodController.php (routes.php:202) is authenticated-only (@NoAdminRequired + in-body guard). Rate limit only on GebruikController (#[AnonRateLimit])." + "glpi": "source read at 11.0.9: the v2 API routes without authentication are only the index, documentation and getting started pages, src/Glpi/Api/HL/Controller/CoreController.php:301, :322, :397, :407; all data routes require OAuth or session auth, and there is no supplier offering to expose.", + "stackiq": "Anonymous read of the supplier offering depends on declared rules: lib/Settings/softwarecatalogus_register.json:7307 module read includes public on publicationDate<=$now and on registeredBy=Supplier; lib/Settings/softwarecatalogus_register.json:1559 catalogService public on publicationDate. Stackiq's own offering endpoint lib/Controller/AanbodController.php (routes.php:202) is authenticated-only (@NoAdminRequired + in-body guard). Rate limit only on GebruikController (#[AnonRateLimit]).", + "topdesk": "unknown: the REST API requires an operator or API account; a public API is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no public API is documented; public data is offered as CSV downloads; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" }, "pendingQuestion": "Does the installed OpenRegister execute the module/catalogService public read rules for anonymous API callers, and is any API key or rate limit applied to that public surface?" }, @@ -4543,7 +4910,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4556,7 +4923,10 @@ "providerHow": "read-from-code", "note": "The contribution is declarative and read-only, and it covers only an organisation's own records for portal subjects. It shows nothing publicly, and the create/accept actions are deferred per its own docblock.", "evidence": { - "stackiq": "lib/Portal/PortalContributionProvider.php:130 getContribution() declares read-only, organisation-scoped collections (catalogService, usage, catalogContract, compliancy) for the vendor-org and participant-org audiences. Portaliq discovers it by FQCN from the Stackiq in appinfo/info.xml (portaliq lib/Contribution/PortalProviderLocator.php:49/77). No info.xml dependency; inert without portaliq." + "stackiq": "lib/Portal/PortalContributionProvider.php:130 getContribution() declares read-only, organisation-scoped collections (catalogService, usage, catalogContract, compliancy) for the vendor-org and participant-org audiences. Portaliq discovers it by FQCN from the Stackiq in appinfo/info.xml (portaliq lib/Contribution/PortalProviderLocator.php:49/77). No info.xml dependency; inert without portaliq.", + "topdesk": "unknown: no shared external portal is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no external portal integration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: no embeddable widget or external portal integration for catalogue content; the self service interface (src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45) is GLPI's own helpdesk portal and grep -rli 'iframe embed\\|oembed' over src/ returns nothing." }, "pendingQuestion": "Does the installed portaliq render stackiq's contribution (its PortalProviderLocator iterating installed apps), and is that portal live for any stackiq customer?" }, @@ -4568,8 +4938,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "no", + "topdesk": "no", "stackiq": "partial", "built": { "state": "none", @@ -4581,7 +4951,10 @@ "providerHow": "read-from-code", "note": "Stackiq has nothing of its own here. An AI client could only reach catalogue objects through OpenRegister's generic MCP server, if it covers the voorzieningen register.", "evidence": { - "stackiq": "No MCP, tool-provider, TaskProcessing or ContextChat code in stackiq lib/ or src/ (grep 'mcp|ToolProvider|assistant|TaskProcessing|ContextChat' in lib/ finds nothing). OpenRegister ships a generic MCP endpoint (openregister appinfo/routes.php:1969 /api/mcp/v1/discover and the JSON-RPC endpoint) over all registers." + "stackiq": "No MCP, tool-provider, TaskProcessing or ContextChat code in stackiq lib/ or src/ (grep 'mcp|ToolProvider|assistant|TaskProcessing|ContextChat' in lib/ finds nothing). OpenRegister ships a generic MCP endpoint (openregister appinfo/routes.php:1969 /api/mcp/v1/discover and the JSON-RPC endpoint) over all registers.", + "topdesk": "https://tip.topdesk.com/c/200-ai-mcp-based-service-: roadmap card in column \"Building\", \"Model Context Protocol (MCP-based service) allows secure, controlled connectivity between your TOPdesk environment and LLM-powered assistants\" (read 2026-09-26); the shipped TOPdesk Robin works inside tickets (https://docs.topdesk.com/en/td-robin-for-operators.html).", + "vng-softwarecatalogus": "unknown: no assistant or tool interface is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'mcp\\|model context\\|openai\\|llm' over src/ returns nothing; AI tool access would go through the generic v2 API (src/Glpi/Api/HL/Controller/AssetController.php:149) with no tool interface of its own." }, "pendingQuestion": "Does OpenRegister's MCP server expose the voorzieningen register's objects (module, catalogService, organization) for read and write to an AI client with a stackiq user's rights?" }, @@ -4593,8 +4966,8 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", - "topdesk": "unknown", + "glpi": "yes", + "topdesk": "yes", "stackiq": "partial", "built": { "state": "none", @@ -4606,7 +4979,10 @@ "providerHow": "read-from-code", "note": "Change notification to another system is possible only through OpenRegister machinery: its webhooks UI, or a flow authored on stackiq's Flows page. Stackiq itself sends nothing.", "evidence": { - "stackiq": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909)." + "stackiq": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909).", + "topdesk": "https://docs.topdesk.com/en/let-your-topdesk-talk-to-other-applications.html: \"Send a request from TOPdesk to another program ... This way you can create an integration with almost any software that has an API\" (read 2026-09-26) triggered by card events (https://docs.topdesk.com/en/events-that-trigger-actions.html). Reached on: Action Management > action sequences.", + "vng-softwarecatalogus": "unknown: notifications go to people by mail and inbox, no system webhooks are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: src/Webhook.php:64 Webhook sends HTTP calls on new, update and delete events (src/Webhook.php:311 getDefaultEventsList) for management itemtypes including Appliance, Budget, Contact and others (src/Webhook.php:398). Reached on: Setup > Webhooks (src/Html.php:1331)." }, "pendingQuestion": "Can a flow created on stackiq's Flows page be triggered by object.updated on a catalogue schema and make an outbound HTTP call to an external system?" }, @@ -4633,9 +5009,10 @@ "featureConfidence": "high", "note": "Per-record history is shown on 11 detail pages, backed by OpenRegister's audit trail. There is no catalogue-wide view of who changed what, and the overlay itself lists audit-trail-view as 'soon'.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141820 '10.5 Audit or event log viewer with filters and export': two logs, both searchable and exportable through the search engine: `src/Log.php:48` field-level object history (Historical tab, `src/Ticket.php:887`) and `src/Glpi/Event.php:63` the system/event log at `/front/logs.php` | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141852 '13.9 Audit trail including reads and views': writes are covered thoroughly: `src/Log.php:48` field-level history on every object, `src/Glpi/Event.php:63` the system log including logins (`src/Auth.php:1149-1163`), `src/RuleMatchedLog.php` for rule decisions. Reads | Rated yes because field-level history, source-read 2026-09-14.", - "topdesk": "docs, intelligence competitor_features#26345 'Audit Trail' (2026-04-10): Complete audit trail of all service management actions", - "stackiq": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object." + "glpi": "source read at 11.0.9: src/Appliance.php:58 dohistory is true and src/Appliance.php:112 adds the Historical tab (src/Log.php:48 Log), recording who changed which field and when. Reached on: Management > Appliances > Historical tab.", + "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"History widget : shows both present and past changes that have been made to an asset\" (read 2026-09-26); https://docs.topdesk.com/en/cards-in-call-management.html: \"Audit trail tab Previous events while processing this call\" (read 2026-09-26). Reached on: Asset card > History widget.", + "stackiq": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object.", + "vng-softwarecatalogus": "unknown: only a \"Laatst gewijzigd\" date on supplier pages and a mutation date in exports are shown; who changed what is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)" }, "pendingQuestion": "Is OpenRegister's audit trail enabled for the voorzieningen register on a default install, so the History tab shows entries?" }, @@ -4647,7 +5024,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "partial", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown", "stackiq": "partial", "built": { @@ -4662,7 +5039,10 @@ "note": "Five custom pages subscribe to collection events and refetch on a change. Whether the event ever arrives depends on OpenRegister and the push transport, which this repo cannot show.", "evidence": { "bluedolphin": "docs, intelligence competitor_features#48969 'Real-time collaboration' (2026-07-23): Multiple stakeholders collaborate on models. | Rated partial because real-time collaboration on models.", - "stackiq": "src/composables/useLiveCollections.js:40 subscribes via the library's useObjectSubscription; used in src/views/KwetsbaarhedenView.vue:197, LicensePostureView.vue:209, LifecycleRoadmapView.vue:184, ComplianceMatrixView.vue:326, PortfolioReport.vue:323. The standard index pages (Contracts, Organisations and others) rely on whatever the library's CnIndexPage does." + "stackiq": "src/composables/useLiveCollections.js:40 subscribes via the library's useObjectSubscription; used in src/views/KwetsbaarhedenView.vue:197, LicensePostureView.vue:209, LifecycleRoadmapView.vue:184, ComplianceMatrixView.vue:326, PortfolioReport.vue:323. The standard index pages (Contracts, Organisations and others) rely on whatever the library's CnIndexPage does.", + "topdesk": "unknown: live list updates are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: no live list updates are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'websocket\\|EventSource' over src/ finds only src/Glpi/Api/HL/Controller/NotificationController.php:303 'websocket: Not used by GLPI core'; lists refresh on reload only." }, "pendingQuestion": "Does the installed OpenRegister publish or-collection-{register}-{schema} events over a transport (notify_push or SSE) that the nc-vue liveUpdatesPlugin receives, so these pages update without a reload?" }, @@ -4671,11 +5051,11 @@ "area": "insight", "name": "Receive in-app notifications about changes that concern you.", "origin": "own-code", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "partial", - "topdesk": "unknown", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "specified", @@ -4689,8 +5069,10 @@ "featureConfidence": "high", "note": "Every notification rests on a declaration OpenRegister must execute. At least one rule (contract expiry) filters on a stale Dutch status value and would never fire, and its subject template uses fields (contractNummer, eindDatum) the schema no longer has.", "evidence": { - "glpi": "source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#141783 '6.8 In-app notifications (bell)': `MODE_AJAX` is a wired delivery mode (`src/Notification_NotificationTemplate.php:55-59`, `getModes()` at `:381-398`, implementation `src/NotificationAjax.php`), rendering as a browser toast rather than a persistent inbox | Rated partial because toast delivery, not an inbox, source-read 2026-09-14.", - "stackiq": "Only declarations: x-openregister-notifications on vulnerability (lib/Settings/softwarecatalogus_register.json:1622), usage (:2662), catalogContract (:3253), software-review (:3962), module (:6781), moduleVersion (:7652). Stackiq has no INotifier or notification code of its own (grep in lib/). The contract-expiry rule filters status equals 'Actief' (lib/Settings/softwarecatalogus_register.json:3255) while the enum is Active/Expired/In negotiation, so it can never match." + "glpi": "source read at 11.0.9: besides mail there is a browser notification mode, src/NotificationAjax.php:42 and src/Notification_NotificationTemplate.php:56 MODE_AJAX, but it only carries events that notification targets define (tickets, changes, contracts, licences, saved search alerts and similar); changes to an appliance raise no notification event. Reached on: Setup > Notifications > Browser followups configuration.", + "stackiq": "Only declarations: x-openregister-notifications on vulnerability (lib/Settings/softwarecatalogus_register.json:1622), usage (:2662), catalogContract (:3253), software-review (:3962), module (:6781), moduleVersion (:7652). Stackiq has no INotifier or notification code of its own (grep in lib/). The contract-expiry rule filters status equals 'Actief' (lib/Settings/softwarecatalogus_register.json:3255) while the enum is Active/Expired/In negotiation, so it can never match.", + "topdesk": "https://docs.topdesk.com/en/topdesk-mobile.html: \"change your notification settings\" in the mobile app (read 2026-09-26); https://docs.topdesk.com/en/action-management.html: \"specific mobile alerts for operators\" (read 2026-09-26). Mostly email and mobile alerts, no in-app inbox described. Reached on: TOPdesk Mobile; Action Management.", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Gemeenten, samenwerkingen, en leveranciers hebben nu rechtsboven bij het inlogmenu een inbox-symbool met daarbij het aantal nieuwe berichten\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E17 \"De softwarecatalogus bevat een notificatievoorziening en een inbox voor gemeenten en samenwerkingen\" (read 2026-09-26). Reached on: Inlogmenu > Inbox." }, "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications rules on vulnerability, software-review, moduleVersion and the scheduled rules on catalogContract/usage/module, as Nextcloud notifications to the listed recipients?" }, @@ -4703,7 +5085,7 @@ "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "yes", - "topdesk": "yes", + "topdesk": "partial", "stackiq": "partial", "built": { "state": "built", @@ -4715,9 +5097,10 @@ "providerHow": "read-from-code", "note": "The store installs configuration sets and flows, not code plugins, and it depends on a registry being configured.", "evidence": { - "glpi": "docs, intelligence competitor_features#48906 'Plugin ecosystem' (2026-07-23): Large plugin marketplace (FormCreator, GenericObject, etc.). | source read of GLPI by the procest lane on 2026-09-14, intelligence competitor_features#145919 'C-configuration-48 An extension is found, installed, updated and removed from inside the product.': glpi: Marketplace (Setup, Plugins, front/marketplace.php, marketplace.download.php, front/plugin.php) Lane findings: D-glpi-45.", - "topdesk": "docs, intelligence competitor_features#27391 'Marketplace Integrations' (2026-04-12): TOPdesk Marketplace with third-party integrations including Lansweeper, BlueDolphin", - "stackiq": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items." + "glpi": "source read at 11.0.9: src/Glpi/Marketplace/View.php:53 marketplace view at front/marketplace.php (src/Glpi/Marketplace/View.php:103) and src/Glpi/Marketplace/Controller.php:64 download and install of plugins; src/Glpi/Marketplace/View.php:185 notes that a registration, at least a free one, is required. Reached on: Setup > Plugins > Marketplace.", + "topdesk": "https://marketplace.topdesk.com/: \"Showing all 133 results\" of integrations (read 2026-09-26); https://docs.topdesk.com/en/exporting-and-importing.html: \"import an action sequence example from the TOPdesk Marketplace\" (read 2026-09-26). Integrations and action-sequence templates, not installable plugins. Reached on: TOPdesk Marketplace.", + "stackiq": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items.", + "vng-softwarecatalogus": "unknown: no plugins are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" }, "pendingQuestion": "Is a store registry configured on a default install, and are any stackiq configuration sets published to it?" } From cca6e68453b94279ad4de3af5a1f5765589eb3e6 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:17:05 +0200 Subject: [PATCH 04/12] chore(parity): apply r-glpi errata, land-demo-data no to partial --- openspec/parity/capabilities.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index bd7d02a3..324cf2d2 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -568,7 +568,7 @@ "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "no", + "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", "built": { @@ -584,7 +584,7 @@ "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp", "topdesk": "unknown: no example data set is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue is one hosted service; no loadable example data set is described (a \"VNG Realisatie Demo\" supplier appears in the live data); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", - "glpi": "source read at 11.0.9: grep -ril 'demo data\\|sample data' over src/ templates/ locales/glpi.pot returns nothing and src/Glpi/Console/ has no demo loader; example data exists only as test fixtures under tests/, not shipped as a feature." + "glpi": "source read at 11.0.9: on a clean install dashboards render placeholder figures from src/Glpi/Dashboard/FakeProvider.php:65 FakeProvider, with the banner 'You are viewing demonstration data.' and a 'Disable demonstration' button (src/Glpi/Dashboard/Grid.php:427, :428, :448); CHANGELOG.md 11.0.0 lists it. No example records (applications, contracts, suppliers) are loaded; the console entry point src/Glpi/Console/Application.php:66 has no demo data command. Reached on: Home > Dashboard on a fresh install." } }, { From ca32289bd40a139501e5a765d1f13ee9fe82d1c0 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:19:50 +0200 Subject: [PATCH 05/12] chore(parity): record the GLPI 11.0.9 lab drive on 26 cells --- openspec/parity/capabilities.json | 121 +++++++++++++++++------------- 1 file changed, 68 insertions(+), 53 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index 324cf2d2..d1b800b3 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -179,9 +179,9 @@ "note": "An application with supplier and description can be registered on the Modules page, but the module schema has no status field, and the per-organisation usage that carries a status has no page to create it on. The Modules list also cannot open ModuleDetail: its standalone CnIndexPage (FacetedCatalogIndexView.vue:108-117) binds no @view/@row-click, so the View action is inert.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"klik dan op de knop + achter de beschrijving van het pakket om het pakket toe te voegen aan je omgeving ... Pakketversie ... Referentiecomponenten ... Vul onder Planning bij Status in gebruik in\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus: \"Wanneer Gemeenten en samenwerkingen hun applicatielandschap hebben ingevoerd, wordt deze automatisch geplot op de GEMMA referentiecomponentenkaart\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Voeg pakket toe.", - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | docs, intelligence competitor_features#27422 'Fact Sheets & Data Model' (2026-04-12): Flexible data model for applications, processes, IT components", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Applications are software systems or programs that process or analyze business data'; application fact sheet with description and lifecycle, supplier via 'provider -> IT component -> application relation' (https://help.sap.com/docs/leanix/ea/provider-modeling-guidelines) (read 2026-09-26). Reached on: Inventory > Application fact sheet.", "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository. | docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", - "glpi": "source read at 11.0.9: src/Appliance.php:46 class Appliance is GLPI's application itemtype; install/mysql/glpi-empty.sql:8935 glpi_appliances carries name, comment (description), manufacturers_id and states_id (status); src/Appliance.php:350 search option Status; supplier through the Management tab Infocom (install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id) and Contract_Item (src/Appliance.php:99); menu src/Html.php:1300 lists Appliance under Management, served by src/Glpi/Kernel/Listener/RequestListener/LegacyItemtypeRouteListener.php:100. Reached on: Management > Appliances (front/appliance.php).", + "glpi": "source read at 11.0.9: src/Appliance.php:46 class Appliance is GLPI's application itemtype; install/mysql/glpi-empty.sql:8935 glpi_appliances carries name, comment (description), manufacturers_id and states_id (status); src/Appliance.php:350 search option Status; supplier through the Management tab Infocom (install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id) and Contract_Item (src/Appliance.php:99); menu src/Html.php:1300 lists Appliance under Management, served by src/Glpi/Kernel/Listener/RequestListener/LegacyItemtypeRouteListener.php:100. Reached on: Management > Appliances (front/appliance.php). Driven on the lab at 11.0.9 (2026-09-26): created the appliance \"Zaaksysteem lab\" with a description through /front/appliance.form.php; it appears in the Appliances list and CSV export.", "topdesk": "https://docs.topdesk.com/en/migrating-objects-to-asset-management.html: \"In the new Asset Management you design your own template for each type of asset you have\" (read 2026-09-26); https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"Create a new template for software cards\" (read 2026-09-26). Applications are a self-designed asset type, no application model ships. Reached on: Modules > Asset Management > Template Designer / Asset overview > New.", "stackiq": "src/manifest.json:592 Modules page (FacetedCatalogIndexView, schema module) with the library CnIndexPage create form at src/views/FacetedCatalogIndexView.vue:108; lib/Settings/softwarecatalogus_register.json:6777 module schema has name, shortDescription/longDescription and provider (Supplier) but NO status property; status lives on usage (register.json:2654, enum Acquisition..In production) which has no page" } @@ -192,7 +192,7 @@ "name": "Break an application into modules and see which module belongs to which product.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -209,7 +209,7 @@ "featureConfidence": "low", "note": "Stackiq's 'module' is the whole application, so there is no breakdown of one application into modules. The nearest thing is a suite (product) listing its applications, which answers 'which module belongs to which product' but not the decomposition.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated partial because fact sheets separate Application from IT Component.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Applications often consist of multiple entities or modules within a common ecosystem or platform', modeled as parent/child hierarchy, e.g. Adobe Photoshop as child of Adobe Creative Cloud (read 2026-09-26). Reached on: Application fact sheet > parent/child relations.", "stackiq": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')", "topdesk": "unknown: assets can be linked parent to child, but no application module concept is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the docs model a pakket and its pakketversies only, no module level is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", @@ -222,7 +222,7 @@ "name": "Record the released versions of a module, with the date each came into use.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -242,7 +242,8 @@ "glpi": "source read at 11.0.9: src/SoftwareVersion.php:42 SoftwareVersion child of Software, table install/mysql/glpi-empty.sql:6900 glpi_softwareversions with name, states_id, operatingsystems_id but no release or in-use date; the only date is per installation, install/mysql/glpi-empty.sql:1074 glpi_items_softwareversions.date_install. Reached on: Assets > Software > Versions tab (front/softwareversion.form.php).", "stackiq": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn", "topdesk": "unknown: no version records per application or module are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Titel is de naam van uw productversie ... Status geeft aan of uw product in ontwikkeling, in productie, of teruggetrokken is ... startdata van ontwikkeling, test en distributie\" (read 2026-09-26). Versions are recorded per package (pakketversie), not per module. Reached on: Supplier login > Productportfolio > product > plus (versie toevoegen)." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Titel is de naam van uw productversie ... Status geeft aan of uw product in ontwikkeling, in productie, of teruggetrokken is ... startdata van ontwikkeling, test en distributie\" (read 2026-09-26). Versions are recorded per package (pakketversie), not per module. Reached on: Supplier login > Productportfolio > product > plus (versie toevoegen).", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'if versioning is relevant ... you can capture it in the Release field of the application fact sheets'; each fact sheet carries lifecycle phase dates, but the guide says 'versioning for applications doesn't add significant value' (read 2026-09-26). Reached on: Application fact sheet > Name and Description > Release." } }, { @@ -251,7 +252,7 @@ "name": "Bundle several existing applications into one suite that is offered as a single product.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -271,6 +272,7 @@ "stackiq": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)", "topdesk": "unknown: no suite bundling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no bundling of packages into a suite is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Adobe Creative Cloud is a suite that bundles various applications ... It is modeled as the parent entity'; a platform fact sheet can group applications. Modeled for the buyer's own inventory, not as a product offered to others (read 2026-09-26). Reached on: Application fact sheet hierarchy, Platform fact sheet.", "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:562 appliance_types contains Appliance and Software, so an Appliance can bundle existing appliances and software through src/Appliance_Item.php:45 (table install/mysql/glpi-empty.sql:8979 glpi_appliances_items). There is no notion of offering the bundle as a product to others. Reached on: Management > Appliances > Items tab." } }, @@ -280,7 +282,7 @@ "name": "Register a service a supplier delivers on top of applications, such as hosting or support.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "yes", @@ -300,6 +302,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: facet \"Ondersteunde technologie: On-premise, Dienst - Software as a Service (SAAS)\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: \"Onder het tabblad Technologie selecteer je de onderliggende technieken van het pakket. Veelal Saas of on-premise\" (read 2026-09-26). Hosting as SaaS is a property of a package version, no separate service record (hosting, support) is documented. Reached on: Alle pakketversies > filter Ondersteunde technologie.", "stackiq": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"Services you offer may rely on services of external suppliers. These services are called underpinning services. TOPdesk allows you to link your services to supplier services\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity), Operational Activity, Knowledge Item, Problem, and Service cards, you can link multiple assets in one go\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > Service card > Links > Assets.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-component-modeling-guidelines: IT component subtype 'Service : Services refer to the provisioning of services related to IT components (usually provided by a 3rd party) ... Examples: Maintenance/Support Service ... Hosting Service'; linked to providers (read 2026-09-26). Reached on: Inventory > IT Component fact sheet, subtype Service.", "glpi": "source read at 11.0.9: no supplier service itemtype; services are held as contracts, src/ContractType.php:37 admin dropdown of contract types (for example hosting or support), install/mysql/glpi-empty.sql:1550 glpi_contracts_suppliers ties the contract to a Supplier and install/mysql/glpi-empty.sql:1536 glpi_contracts_items ties it to the Appliance or Software it covers. Reached on: Management > Contracts (front/contract.php), Suppliers tab." } }, @@ -309,7 +312,7 @@ "name": "Tag applications with the government sectors they are meant for.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -327,6 +330,7 @@ "stackiq": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395", "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: facets \"Domein\" (Bestuur, Fysieke leefomgeving, Sociaal domein, ...) and \"Doelgroep\" (Gemeente, Generiek, Inwoners en ondernemers, Ketenpartners) (read 2026-09-26). Domains are municipal policy domains, the catalogue serves municipalities only, not other government sectors. Reached on: Alle pakketversies > filters Domein, Doelgroep.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/tags-and-custom-fields: tags and tag groups for 'quick, high-level classification', filterable and usable as reporting views; no predefined government sector list is documented (read 2026-09-26). Reached on: Fact sheet > Tags.", "glpi": "source read at 11.0.9: no government sector concept, grep -i 'sector' over src/*.php and locales/glpi.pot hits only menu sectorization (src/Html.php:1019); the nearest holder is the single-valued Appliance type dropdown install/mysql/glpi-empty.sql:8941 appliancetypes_id, or an admin custom dropdown (install/mysql/glpi-empty.sql:10113 glpi_dropdowns_dropdowndefinitions) used as a field of a custom asset. Multi-valued tagging needs the separate tag plugin (github.com/pluginsGLPI/tag, not read). Reached on: Management > Appliances, Appliance type field." } }, @@ -336,7 +340,7 @@ "name": "Name the business owner and the technical owner responsible for an application.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -353,11 +357,11 @@ "featureConfidence": "low", "note": "One contact person per application can be set, but there is no separate business owner and technical owner. ModuleDetail's data widget includes 'contactpersoon', a key the schema no longer has, so the contact may not show there.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | Rated partial because surveys go to application owners, so ownership is modelled.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/subscription-roles: 'Define roles that map to your organization's positions, such as application owner', with subscription types 'Responsible, Accountable, Observer' per fact sheet (read 2026-09-26). Reached on: Fact sheet > Subscriptions; Administration > Subscription Roles.", "stackiq": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')", "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"Assignment widget : assigns locations and persons to the asset\" (read 2026-09-26). No separate business and technical owner roles are described. Reached on: Asset card > Assignment widget.", "vng-softwarecatalogus": "unknown: the landscape entry fields listed (pakketversie, referentiecomponenten, technologie, status) include no business or technical owner; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30355 (read 2026-09-26)", - "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:8935 glpi_appliances holds users_id and users_id_tech; src/Appliance.php:186 search option User and src/Appliance.php:195 Group (business side), src/Appliance.php:240 'Technician in charge' and the 'Group in charge' option a few lines below (technical side). Reached on: Management > Appliances, form fields User, Group, Technician in charge, Group in charge." + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:8935 glpi_appliances holds users_id and users_id_tech; src/Appliance.php:186 search option User and src/Appliance.php:195 Group (business side), src/Appliance.php:240 'Technician in charge' and the 'Group in charge' option a few lines below (technical side). Reached on: Management > Appliances, form fields User, Group, Technician in charge, Group in charge. Driven on the lab at 11.0.9 (2026-09-26): the saved appliance holds users_id and users_id_tech (glpi_appliances row 1), shown as User and Technician in charge." } }, { @@ -382,8 +386,8 @@ "providerHow": "read-from-code", "note": "Stackiq offers no way to add fields. Editing the schema in OpenRegister's own admin UI is possible there, but that is an OpenRegister feature, not a stackiq page.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because flexible fact sheet data model.", - "glpi": "source read at 11.0.9: native custom fields exist only for admin defined custom asset types, src/Glpi/Asset/CustomFieldDefinition.php:52 child of AssetDefinition (install/mysql/glpi-empty.sql:10159 glpi_assets_customfielddefinitions keyed on assets_assetdefinitions_id), set up under Setup > Asset definitions (src/Html.php:1330). The core Appliance and Software types take no custom fields in core; that needs the fields plugin, read at pluginsGLPI/fields tag 1.24.5, inc/container.class.php:91 containers with a list of itemtypes. Reached on: Setup > Asset definitions > Custom fields; or plugin Fields.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/fact-sheet-fields: 'Adding a Custom Field ... To add a custom field, follow these steps'; https://help.sap.com/docs/leanix/ea/tags-and-custom-fields: custom fields as text, dates, numbers, set in the meta model configuration by an admin (read 2026-09-26). Reached on: Administration > Meta Model Configuration > Fact Sheet Fields.", + "glpi": "source read at 11.0.9: native custom fields exist only for admin defined custom asset types, src/Glpi/Asset/CustomFieldDefinition.php:52 child of AssetDefinition (install/mysql/glpi-empty.sql:10159 glpi_assets_customfielddefinitions keyed on assets_assetdefinitions_id), set up under Setup > Asset definitions (src/Html.php:1330). The core Appliance and Software types take no custom fields in core; that needs the fields plugin, read at pluginsGLPI/fields tag 1.24.5, inc/container.class.php:91 containers with a list of itemtypes. Reached on: Setup > Asset definitions > Custom fields; or plugin Fields. Driven on the lab at 11.0.9 (2026-09-26): Setup > Asset definitions (/front/asset/assetdefinition.php) is where custom asset types and their fields are defined; appliances themselves take no custom fields in core.", "stackiq": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json", "topdesk": "https://docs.topdesk.com/en/creating-new-fields.html: \"Whether it is a contact person, a purchase price, or a reminder date ... Use fields in a fieldset or dataset widget to register any useful information about an asset\" (read 2026-09-26). Reached on: Asset Management > Template Designer > Fields.", "vng-softwarecatalogus": "unknown: no user-defined fields are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" @@ -395,7 +399,7 @@ "name": "Import an existing application list in bulk from a spreadsheet or file.", "origin": "competitor", "vng-softwarecatalogus": "no", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "partial", "topdesk": "yes", @@ -410,7 +414,7 @@ "providerHow": "read-from-code", "note": "The generic index page offers a file import (CSV per schema, or a register-wide JSON/Excel) that OpenRegister executes. Nothing stackiq-specific maps a spreadsheet's supplier names to organisation references, so relation columns must already hold identifiers.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#27428 'EAM Automation' (2026-04-12): Automated data collection from ServiceNow, Jira, cloud providers | Rated partial because automated collection from ServiceNow, Jira and cloud.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-fact-sheet-data-through-excel-file and https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: 'using the import option, you can update multiple fact sheets in bulk' via Excel export and import (read 2026-09-26). Reached on: Inventory > Import (Excel).", "bluedolphin": "docs, intelligence competitor_features#48971 'Data import (Excel)' (2026-07-23): Bulk import of application/portfolio data.", "stackiq": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)", "topdesk": "https://docs.topdesk.com/en/generate-import-file.html: \"Importing assets speeds up this task ... export an asset template to XLSX format\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-new-import.html: \"You can use a file (CSV or XLSX), connect with an MS SQL database or import from Microsoft Intune , or Lansweeper\" (read 2026-09-26). Reached on: Settings > Import settings > Asset Management imports.", @@ -442,7 +446,7 @@ "note": "The application page shows versions and compliance claims, and usages only as untyped entries in the generic Related panel. Contracts are not shown. The page cannot be opened from the Applications list itself, and its data widget asks for three field names the schema no longer has, so the descriptions do not render.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakket/archi: package page shows versions with status and start dates, \"Pakket geschikt voor (GEMMA 2) Ingevuld door (28)\", and per version the mandatory and recommended standards with support, compliancy and testrapport (read 2026-09-26). No contracts on the page. Reached on: Alle pakketten > package name.", - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because fact sheet is the per-application page.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines and https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: the application fact sheet holds lifecycle, relations to IT components, organizations, interfaces, cost on relations, and a Relations Explorer on one fact sheet (read 2026-09-26). Reached on: Inventory > Application fact sheet.", "stackiq": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)", "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: twelve widgets incl. \"History\", \"Relationships\", \"Relationship grid\", \"Documents\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: assets linked to calls, changes, services (read 2026-09-26). Versions and compliance are not part of it. Reached on: Asset card.", "glpi": "source read at 11.0.9: src/Appliance.php:98 onwards defineTabs puts Items, Contracts, Documents, Management (Infocom), Certificates, Domains, Knowledge base, Tickets, Problems, Changes and Impact on the one appliance page; versions sit on the separate Software page (src/SoftwareVersion.php:42), and no compliance tab exists (grep -i 'complian' src/Appliance.php returns nothing). Reached on: Management > Appliances > appliance form tabs." @@ -454,7 +458,7 @@ "name": "Select many catalogue entries at once and publish, lock or delete them together.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -474,7 +478,8 @@ "stackiq": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets", "topdesk": "https://docs.topdesk.com/en/editing-assets-in-bulk.html: \"select multiple assets by ticking their boxes ... You can use bulk edit for updating up to 500 assets\" (read 2026-09-26); editable are assignments, drop-down, date, number, text and checkbox fields. Bulk publish or delete is not described. Reached on: Asset Management > Asset overview > select > bulk edit.", "vng-softwarecatalogus": "unknown: no multi-select publish, lock or delete is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "glpi": "source read at 11.0.9: every search list offers massive actions, src/MassiveAction.php:666 Update (any field, for example status), src/MassiveAction.php:698 Put in trashbin, src/MassiveAction.php:652 Delete permanently, src/MassiveAction.php:656 Restore. There is no publish state; locking applies to inventory fields only. Reached on: any list, for example Management > Appliances, Actions button." + "sap-leanix": "https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: 'switch to table view in the inventory, you can perform inline editing across multiple fact sheets'; https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets: 'Archiving Fact Sheets in Bulk' through an Excel action column. No publish or lock action is documented (read 2026-09-26). Reached on: Inventory > Table view; Excel import with action column.", + "glpi": "source read at 11.0.9: every search list offers massive actions, src/MassiveAction.php:666 Update (any field, for example status), src/MassiveAction.php:698 Put in trashbin, src/MassiveAction.php:652 Delete permanently, src/MassiveAction.php:656 Restore. There is no publish state; locking applies to inventory fields only. Reached on: any list, for example Management > Appliances, Actions button. Driven on the lab at 11.0.9 (2026-09-26): the Appliances list carries the massive actions control." } }, { @@ -501,6 +506,7 @@ "stackiq": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets", "topdesk": "https://docs.topdesk.com/en/migration-status.html: \"You cannot merge the two cards into one card\" (read 2026-09-26); https://tip.topdesk.com/c/239-ai-cmdb-monitoring-: roadmap card in column \"Under consideration\", \"AI can continuously scan your configuration database for duplicate records ... and surfaces them for review\" (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no merge of entries is described; the news page only mentions a pseudo-supplier \"Open Source Pakketten\" created against duplicate spellings; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/nieuws (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea (all 663 EA pages grepped for merge); duplicates are handled by archiving (https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets 'removing outdated or duplicate fact sheets'), no merge of two fact sheets is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Software.php:109 'Merging' tab on a recursive software, src/Software.php:926 showMergeCandidates lists same named software, src/Software.php:997 massive action Merge, src/Software.php:1011 private function merge moves versions and licences into the kept entry; dropdowns get Replace, src/CommonDropdown.php:680. Reached on: Assets > Software > Merging tab." } }, @@ -525,7 +531,7 @@ "providerHow": "read-from-code", "note": "Nothing asks owners to confirm or correct their entries.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48865 'Survey campaigns for data collection' (2026-07-23): Crowd-sources data quality via targeted surveys to app owners. | docs, intelligence competitor_features#27423 'Survey-Based Data Collection' (2026-04-12): Crowdsource architecture data from application owners", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/reviewing-responses: 'Review and approve survey responses before they are saved to fact sheets'; https://help.sap.com/docs/leanix/ea/application-modernization-collect-data: 'Create a new survey to get key information from application or business owners' (read 2026-09-26). Reached on: Surveys.", "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders.", "stackiq": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)", "topdesk": "unknown: Survey Management runs general surveys (and \"will reach end of life ... November 2026\"), not confirmation of entries by owners; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", @@ -539,7 +545,7 @@ "name": "See how complete and up to date each application's entry is, as a score.", "origin": "competitor", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -557,6 +563,7 @@ "stackiq": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)", "topdesk": "unknown: the only readiness score described is the AI readiness score for the knowledge base; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/voortgang-verbeteren: \"Met het aantal sterren (*) wordt een indicatie van volledigheid van ingevulde gegevens aangegeven\", criteria include referentiecomponenten filled, statuses, koppelingen and \"Datum laatste wijziging is recenter dan 3 maanden geleden\" (read 2026-09-26). Scored per organisation, not per application entry. Reached on: Homepage block Voortgang gemeenten; organisation page header.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/fact-sheet-completeness: 'The fact sheet completion score measures how much of the required data has been filled out for a fact sheet ... You can view the fact sheet completion score in the fact sheet's header' (read 2026-09-26). Reached on: Fact sheet header > completion score.", "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing; no score of how filled in an item is exists in core. The item form tabs (src/Appliance.php:98 onwards) show no score." } }, @@ -584,7 +591,8 @@ "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp", "topdesk": "unknown: no example data set is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue is one hosted service; no loadable example data set is described (a \"VNG Realisatie Demo\" supplier appears in the live data); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", - "glpi": "source read at 11.0.9: on a clean install dashboards render placeholder figures from src/Glpi/Dashboard/FakeProvider.php:65 FakeProvider, with the banner 'You are viewing demonstration data.' and a 'Disable demonstration' button (src/Glpi/Dashboard/Grid.php:427, :428, :448); CHANGELOG.md 11.0.0 lists it. No example records (applications, contracts, suppliers) are loaded; the console entry point src/Glpi/Console/Application.php:66 has no demo data command. Reached on: Home > Dashboard on a fresh install." + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; demo and sandbox workspaces are mentioned (https://help.sap.com/docs/leanix/ea/automations 'Demo and sandbox workspaces allow up to 10,000 automations per month') but loading an example data set into a workspace is not described (read 2026-09-26)", + "glpi": "source read at 11.0.9: on a clean install dashboards render placeholder figures from src/Glpi/Dashboard/FakeProvider.php:65 FakeProvider, with the banner 'You are viewing demonstration data.' and a 'Disable demonstration' button (src/Glpi/Dashboard/Grid.php:427, :428, :448); CHANGELOG.md 11.0.0 lists it. No example records (applications, contracts, suppliers) are loaded; the console entry point src/Glpi/Console/Application.php:66 has no demo data command. Reached on: Home > Dashboard on a fresh install. Driven on the lab at 11.0.9 (2026-09-26): glpi_configs.is_demo_dashboards is 1 on the fresh install, so the dashboard cards come from FakeProvider until an administrator disables the demonstration." } }, { @@ -611,6 +619,7 @@ "stackiq": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing", "topdesk": "unknown: wizards exist for imports and migration, not for adding an application; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the manuals describe forms (\"Hierna opent een formulier\"), no step-by-step wizard; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30355 (read 2026-09-26)", + "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/creating-fact-sheets describes creating a fact sheet in the inventory with reference catalog suggestions and duplicate hints, not a step by step wizard; wizards are documented only for KPI and integration mapping configuration (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'wizard' over src/ templates/ locales/glpi.pot returns nothing for item creation; appliances are added through the plain form only (install/mysql/glpi-empty.sql:8935 glpi_appliances has no is_template column)." } }, @@ -620,7 +629,7 @@ "name": "See the third-party components a module version is built from.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -638,6 +647,7 @@ "stackiq": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema", "topdesk": "unknown: no software components per version are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no third-party component list per version is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/uploading-sboms-from-fact-sheets: 'Upload SBOM files directly from a microservice fact sheet'; https://help.sap.com/docs/leanix/ea/tech-stack-discovery-from-sboms: 'the system automatically analyzes the SBOM components and builds a structured view of your technology stack'. Part of SAP LeanIX Technology Risk and Compliance (read 2026-09-26). Reached on: Microservice fact sheet > SBOM (Technology Risk and Compliance).", "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; software versions carry no component list (install/mysql/glpi-empty.sql:6900 glpi_softwareversions)." } }, @@ -647,7 +657,7 @@ "name": "Record whether an application runs on premises, as SaaS or at a hosting party.", "origin": "competitor", "vng-softwarecatalogus": "yes", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -664,7 +674,7 @@ "featureConfidence": "medium", "note": "The application form records on-premises, IaaS, PaaS or SaaS plus hosting location and jurisdiction. There is no field naming the hosting party itself.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | Rated partial because SaaS is tracked as a class of application.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/applications-in-reference-catalog lists application fields 'Hosting Type' and 'Hosting Description'; https://help.sap.com/docs/leanix/ea/configuring-kpis filters applications on 'Hosting Type = \"Cloud\"'; IT component subtypes SaaS, IaaS, PaaS, Hardware (read 2026-09-26). Reached on: Application fact sheet > Hosting Type.", "stackiq": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)", "topdesk": "unknown: only possible as a self-defined field; no hosting model is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Indien een leverancier zowel SaaS als On premise ondersteunt, kan je aangeven welke van deze twee varianten gebruikt wordt binnen de gemeente\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen > tabblad Technologie.", @@ -677,7 +687,7 @@ "name": "Record a connection from an application to a national provision such as a basisregistratie.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -697,6 +707,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"De richting van het berichtenverkeer, de landelijke voorziening waarmee gekoppeld is/wordt, in dit geval GGK\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus: \"kunnen koppelingen tussen applicaties onderling en met Landelijke Voorzieningen vastgelegd worden\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > koppeling toevoegen.", "stackiq": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection", "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Modeling External Applications ... applications of business partners, service providers, authorities', linked 'through an interface to analyze dependencies'. Generic external application modeling, no catalogue of national provisions such as basisregistraties (read 2026-09-26). Reached on: Application fact sheet (external) + Interface fact sheet.", "glpi": "source read at 11.0.9: no national provision concept (grep -ril 'basisregistratie' src/ locales/glpi.pot returns nothing); a provision can be held as another Appliance and linked through an impact relation, install/mysql/glpi-empty.sql:1247 glpi_impactrelations (source item, impacted item, name), with Appliance enabled for impact at src/autoload/CFG_GLPI.php:649. Reached on: Appliance > Impact analysis tab, Add relation." } }, @@ -706,7 +717,7 @@ "name": "Browse all connections in the catalogue in one list and open each one.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -726,7 +737,8 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle koppelingen ... staan de koppelingen van alle gemeenten en samenwerkingsverbanden ... Door te klikken op het icoontje rechts van een koppeling, krijg je nog enige detail informatie\" (read 2026-09-26). Reached on: Inlogmenu > Alle koppelingen (logged-in municipal users).", "stackiq": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)", "topdesk": "unknown: relations are shown per asset and in a graphical overview; a list of all relations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "glpi": "source read at 11.0.9: src/ImpactRelation.php:39 ImpactRelation has only prepareInputForAdd and getIDFromInput (src/ImpactRelation.php:47, :107), no search options and no list page; relations are only seen per item in the Impact analysis tab (src/Impact.php:91)." + "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: 'Interfaces are connections between applications that illustrate how data exchange occurs', each a fact sheet listed in the inventory by fact sheet type (read 2026-09-26). Reached on: Inventory > filter fact sheet type Interface.", + "glpi": "source read at 11.0.9: src/ImpactRelation.php:39 ImpactRelation has only prepareInputForAdd and getIDFromInput (src/ImpactRelation.php:47, :107), no search options and no list page; relations are only seen per item in the Impact analysis tab (src/Impact.php:91). Driven on the lab at 11.0.9 (2026-09-26): /front/impactrelation.php opens by URL only (no menu entry) as a generic list whose only criterion and column is ID, so relations cannot be browsed by endpoint; rating unchanged." } }, { @@ -735,7 +747,7 @@ "name": "See every connection an application has, from that application's own page.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -755,7 +767,8 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Mijn pakketoverzicht ... Onder het eerste tabblad zitten de pakketten en onder het tweede tabblad de koppelingen\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: \"Door op een applicatienaam in het Models venster te klikken, zie je in de Visualiser alle koppelingen tussen die applicatie met andere applicaties\" (in Archi after export) (read 2026-09-26). No per-application connection view inside the catalogue is described. Reached on: Mijn softwarecatalogus > Koppelingen.", "stackiq": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"Links between assets are created and managed via the Relationships widget. For current relationships with other assets, the widget shows the template's icon, the Asset ID\" (read 2026-09-26). Generic asset relations, not interfaces. Reached on: Asset card > Relationships widget.", - "glpi": "source read at 11.0.9: src/Impact.php:91 getTabNameForItem adds the 'Impact analysis' tab (src/Impact.php:80) to every impact enabled itemtype, Appliance and Software included (src/autoload/CFG_GLPI.php:649 and :663), with a list view src/Impact.php:270 displayListView of every related item in both directions. Reached on: Management > Appliances > Impact analysis tab." + "sap-leanix": "https://help.sap.com/docs/leanix/ea/circle-map-report: the Interface Circle Map 'helps you track changes and updates in application dependencies', and https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: relations incl. interfaces shown on the fact sheet and in the Relations Explorer (read 2026-09-26). Reached on: Application fact sheet > Relations (Provided and Consumed Interfaces).", + "glpi": "source read at 11.0.9: src/Impact.php:91 getTabNameForItem adds the 'Impact analysis' tab (src/Impact.php:80) to every impact enabled itemtype, Appliance and Software included (src/autoload/CFG_GLPI.php:649 and :663), with a list view src/Impact.php:270 displayListView of every related item in both directions. Reached on: Management > Appliances > Impact analysis tab. Driven on the lab at 11.0.9 (2026-09-26): the appliance page carries an Impact analysis tab with Add assets for every impact enabled item type." } }, { @@ -781,9 +794,9 @@ "featureConfidence": "low", "note": "No page draws connections. The ArchiMate export can be opened in Archi, but it carries GEMMA views and usages, not the catalogue's connections.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model. | docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/data-flow: data flow diagrams help 'understand how applications are connected, identify dependencies, and trace data movement between systems' (read 2026-09-26). Reached on: Diagrams > Data Flow Diagram.", "bluedolphin": "docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models. | docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", - "glpi": "source read at 11.0.9: src/Impact.php:252 displayGraphView and src/Impact.php:1559 makeDataForCytoscape draw the relation network, with editing tools add asset, add relation, add group at src/Impact.php:1160. Reached on: Appliance > Impact analysis tab, graph view.", + "glpi": "source read at 11.0.9: src/Impact.php:252 displayGraphView and src/Impact.php:1559 makeDataForCytoscape draw the relation network, with editing tools add asset, add relation, add group at src/Impact.php:1160. Reached on: Appliance > Impact analysis tab, graph view. Driven on the lab at 11.0.9 (2026-09-26): the Impact analysis tab renders the graph editor with Add assets, Edit group and Edit edge tools.", "stackiq": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"After you define the relationship between assets, you can use the graphical overview to see a visual representation of their relationship\" (read 2026-09-26). Reached on: Asset card > graphical overview.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30890: \"Tekenen van een view met koppelingen ... Een koppeling is gemodelleerd als een Archimate flow relatie\" (read 2026-09-26). Diagrams are drawn in Archi after an AMEFF export, not in the catalogue." @@ -795,7 +808,7 @@ "name": "Before changing or retiring an application, see what depends on it.", "origin": "competitor", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "yes", "topdesk": "partial", @@ -814,7 +827,8 @@ "glpi": "source read at 11.0.9: src/Impact.php:49 class Impact 'Impact analysis', src/Impact.php:713 bfs walks the graph by direction and src/Impact.php:612 buildListData lists what is impacted, with ongoing tickets, problems and changes on impacted items (src/Impact.php:313). Reached on: Tools > Impact analysis (src/Html.php:1309) and the item's Impact analysis tab.", "topdesk": "https://docs.topdesk.com/en/managing-disruptions-in-your-asset-management-process.html: \"you want to know how far the reach of the disruption is ... the operational/impacted status for assets ... Status impacts are also only shown in the graphical overview when a link type is used\" (read 2026-09-26). Disruption impact, not a pre-change dependency analysis. Reached on: Asset card > General widget > Determine status automatically.", "stackiq": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Pakketversies die niet meer in gebruik zijn, kunnen verwijderd worden waarbij feedback gegeven wordt over de koppelingen die ook automatisch verwijderd zullen worden\" (read 2026-09-26). Only on delete, no dependency analysis." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Pakketversies die niet meer in gebruik zijn, kunnen verwijderd worden waarbij feedback gegeven wordt over de koppelingen die ook automatisch verwijderd zullen worden\" (read 2026-09-26). Only on delete, no dependency analysis.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model: 'These relations are the basis for all the reports and allow you to analyze impact of changes, dependencies, risks, redundancies'; https://help.sap.com/docs/leanix/ea/data-flow: 'directional interface mapping, dependency analysis' (read 2026-09-26). Reached on: Reports and Data Flow Diagrams." } }, { @@ -823,7 +837,7 @@ "name": "Filter connections by type, such as an API, a file exchange or a message.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -841,6 +855,7 @@ "stackiq": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter", "topdesk": "unknown: custom link types exist, but filtering relations by type is not described; https://tip.topdesk.com/c/90-graphical-overview-improvements is still under consideration; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: connections carry a standard and \"het soort overdracht\" (upload naar portaal, webservices), but the docs do not name a type filter on the connection list; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: interface subtypes 'Logical interface, API, MCP server' and 'You can capture data flow directions, type of transfer, and frequency with the interface fact sheet'; subtypes and fields are filterable in the inventory (read 2026-09-26). Reached on: Inventory > Interface > filter by subtype or transfer type.", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations has only a free name besides the two endpoints, no connection type (API, file, message), so there is nothing to filter on; the graph settings (src/Impact.php:1167 impact_settings) cover depth and direction." } }, @@ -1672,7 +1687,7 @@ "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/leveranciers: \"Leveranciers ... Zoek in leveranciers ... 354 resultaten gevonden\", filter \"Met ondertekend addendum\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle leveranciers.", - "glpi": "source read at 11.0.9: src/Supplier.php:46 Supplier list under Management (src/Html.php:1298) with search, filters and a supplier type (install/mysql/glpi-empty.sql:7072 suppliertypes_id), but it holds only the suppliers this organisation entered, not all organisations offering to government. Reached on: Management > Suppliers (front/supplier.php)." + "glpi": "source read at 11.0.9: src/Supplier.php:46 Supplier list under Management (src/Html.php:1298) with search, filters and a supplier type (install/mysql/glpi-empty.sql:7072 suppliertypes_id), but it holds only the suppliers this organisation entered, not all organisations offering to government. Reached on: Management > Suppliers (front/supplier.php). Driven on the lab at 11.0.9 (2026-09-26): created supplier \"Lab Leverancier BV\" through /front/supplier.form.php; it appears in the Suppliers list." } }, { @@ -2185,7 +2200,7 @@ "featureConfidence": "medium", "note": "The application page has no contracts list, and a contract links to a usage and a service rather than the application, so there is no path from an application to its contracts in the UI.", "evidence": { - "glpi": "source read at 11.0.9: src/Appliance.php:99 and src/Software.php:131 add the Contract_Item tab (src/Contract_Item.php:43, install/mysql/glpi-empty.sql:1536 glpi_contracts_items) listing every contract of the application. Reached on: Management > Appliances > Contracts tab.", + "glpi": "source read at 11.0.9: src/Appliance.php:99 and src/Software.php:131 add the Contract_Item tab (src/Contract_Item.php:43, install/mysql/glpi-empty.sql:1536 glpi_contracts_items) listing every contract of the application. Reached on: Management > Appliances > Contracts tab. Driven on the lab at 11.0.9 (2026-09-26): after linking the contract, the appliance Contracts tab showed \"Lab contract, 2025-01-01, 12 months -> 2025-12-31\".", "stackiq": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: assets link to \"Service cards\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"On the Services tab, link the services that apply to this contract\" (read 2026-09-26). Contract to asset runs through the service. Reached on: Contract > Services tab > Service > Links > Assets.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" @@ -2354,7 +2369,7 @@ "providerHow": "read-from-code", "note": "Contracts carry a cost and a period, but there is no budget to charge them against.", "evidence": { - "glpi": "source read at 11.0.9: src/Budget.php:46 Budget with a period and value (install/mysql/glpi-empty.sql:306 begin_date, :307 end_date, :308 value); contract costs (install/mysql/glpi-empty.sql:1466 budgets_id) and financial records (src/Infocom.php:599 budgets_id check) are charged to it. Reached on: Management > Budgets.", + "glpi": "source read at 11.0.9: src/Budget.php:46 Budget with a period and value (install/mysql/glpi-empty.sql:306 begin_date, :307 end_date, :308 value); contract costs (install/mysql/glpi-empty.sql:1466 budgets_id) and financial records (src/Infocom.php:599 budgets_id check) are charged to it. Reached on: Management > Budgets. Driven on the lab at 11.0.9 (2026-09-26): /front/budget.php lists budgets with type, start date, end date and value.", "stackiq": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Budget holder: Cost-accounting owner of the contract\" and \"Applicable to ... Budget holder\" (read 2026-09-26). No budget with a period is described. Reached on: Contract card > Financial.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" @@ -2930,7 +2945,7 @@ "providerHow": "read-from-code", "note": "Stackiq has no directory sync for users or groups. Nextcloud's LDAP app could do it platform-wide, outside stackiq.", "evidence": { - "glpi": "source read at 11.0.9: src/AuthLDAP.php:59 LDAP directories with user import and group import (src/AuthLDAP.php:2816 ldapImportGroup), and the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users (alias ldap:sync at :80). Reached on: Administration > Users > LDAP directory link; Setup > Authentication > LDAP directories.", + "glpi": "source read at 11.0.9: src/AuthLDAP.php:59 LDAP directories with user import and group import (src/AuthLDAP.php:2816 ldapImportGroup), and the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users (alias ldap:sync at :80). Reached on: Administration > Users > LDAP directory link; Setup > Authentication > LDAP directories. Driven on the lab at 11.0.9 (2026-09-26): /front/ldap.php offers \"Bulk import users from a LDAP directory\" and \"Synchronizing already imported users\".", "stackiq": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/", "topdesk": "https://docs.topdesk.com/en/manual-login-with-ldap.html: \"This is also required if you want to import persons from your AD via Supporting files import\" (read 2026-09-26); https://tip.topdesk.com/c/242-support-scim-when-importing-users-from-entra-id-to-topdesk: roadmap card in column \"Launched\", \"Support SCIM when importing users from Entra ID to TOPdesk\" (read 2026-09-26). Reached on: Settings > Import settings > Supporting Files imports.", "vng-softwarecatalogus": "unknown: no directory sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" @@ -3158,7 +3173,7 @@ "evidence": { "sap-leanix": "docs, intelligence competitor_features#48867 'REST & GraphQL API' (2026-07-23): Programmatic access to the workspace graph.", "bluedolphin": "docs, intelligence competitor_features#48972 'REST API' (2026-07-23): Programmatic integration with other systems.", - "glpi": "source read at 11.0.9: legacy REST API src/Glpi/Api/APIRest.php:60 (documented in apirest.md) and the v2 high level API, src/Glpi/Api/HL/Controller/AssetController.php:149 /Assets with GET list (:2825), GET item (:2839) and POST create (:2988), Appliance and Software included (src/Glpi/Api/HL/Controller/AssetController.php:39, :133). Reached on: /apirest.php and /api.php/v2.", + "glpi": "source read at 11.0.9: legacy REST API src/Glpi/Api/APIRest.php:60 (documented in apirest.md) and the v2 high level API, src/Glpi/Api/HL/Controller/AssetController.php:149 /Assets with GET list (:2825), GET item (:2839) and POST create (:2988), Appliance and Software included (src/Glpi/Api/HL/Controller/AssetController.php:39, :133). Reached on: /apirest.php and /api.php/v2. Driven on the lab at 11.0.9 (2026-09-26): the legacy API answers \"There isn't an active API client matching your IP address\" until an administrator adds an API client, and the v2 API is off until enabled in Setup > General > API.", "topdesk": "https://docs.topdesk.com/en/required-knowledge.html: \"basic knowledge of REST API requests (see developers.topdesk.com )\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: \"API access > REST API : this permission is necessary for operator cards that are used for accessing the TOPdesk API\" (read 2026-09-26). Reached on: developers.topdesk.com.", "stackiq": "Every catalogue entity is an OpenRegister object (src/manifest.json pages read register @resolve:voorzieningen_register), so OpenRegister's /apps/openregister/api/objects/{register}/{schema} CRUD applies, gated by the schema authorization rules (lib/Settings/softwarecatalogus_register.json:6777 module and others). Stackiq adds its own routed endpoints in appinfo/routes.php (e.g. :202 /api/aanbod, :255-261 /api/aangeboden-gebruik, :298 /api/gebruik, :303 /api/portfolio-report).", "vng-softwarecatalogus": "unknown: https://www.softwarecatalogus.nl/api answers only \"Services Endpoint api has been setup successfully.\" and no API is documented; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api (read 2026-09-26)" @@ -3186,7 +3201,7 @@ "providerHow": "read-from-code", "note": "The generated OpenAPI file is empty. What exists is hand-written: two JSON doc endpoints and markdown pages. OpenRegister may generate an OAS per register, but stackiq does not surface it.", "evidence": { - "glpi": "source read at 11.0.9: src/Glpi/Api/HL/Controller/CoreController.php:322 route /doc serves a Swagger UI 'GLPI API Documentation' (:329 to :331) over the spec built by src/Glpi/Api/HL/OpenAPIGenerator.php. Reached on: /api.php/doc.", + "glpi": "source read at 11.0.9: src/Glpi/Api/HL/Controller/CoreController.php:322 route /doc serves a Swagger UI 'GLPI API Documentation' (:329 to :331) over the spec built by src/Glpi/Api/HL/OpenAPIGenerator.php. Reached on: /api.php/doc. Driven on the lab at 11.0.9 (2026-09-26): on a fresh install /api.php/v2/doc answers 403 \"The High-Level API is disabled\"; after switching on enable_hlapi in Setup > General > API it serves the Swagger UI \"GLPI API Documentation\".", "stackiq": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261). The views docs endpoint is login-only; the aangeboden-gebruik docs endpoint is @PublicPage (AangebodenGebruikController.php:860), so anyone can read it (corrected 2026-09-26). Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint.", "topdesk": "https://developers.topdesk.com/: TOPdesk API reference site, linked from the docs as \"TOPdesk API documentation\" (read 2026-09-26); https://docs.topdesk.com/en/generate-a-document.html: \"see FreeMarker and the TOPdesk API documentation\" (read 2026-09-26). Reached on: developers.topdesk.com.", "vng-softwarecatalogus": "unknown: no API documentation for the current catalogue was found; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" @@ -3216,7 +3231,7 @@ "note": "A full ArchiMate export exists but is only reached from admin settings. The one export on a user page is the portfolio report CSV, and the catalogue list pages offer no export.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"De publieke informatie is ook beschikbaar als download van exportbestanden ... Mijn pakketten, Mijn koppelingen: Knop [Exporteren]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Exporteren; Beschikbare downloads.", - "glpi": "source read at 11.0.9: every search list exports to CSV, PDF, ODS and XLSX through src/Glpi/Search/Output/Csv.php, Pdf.php, Ods.php and Xlsx.php, plus impact CSV (front/impactcsv.php) and the APIs (src/Glpi/Api/HL/Controller/AssetController.php:2825). Reached on: any list, Export menu.", + "glpi": "source read at 11.0.9: every search list exports to CSV, PDF, ODS and XLSX through src/Glpi/Search/Output/Csv.php, Pdf.php, Ods.php and Xlsx.php, plus impact CSV (front/impactcsv.php) and the APIs (src/Glpi/Api/HL/Controller/AssetController.php:2825). Reached on: any list, Export menu. Driven on the lab at 11.0.9 (2026-09-26): the Appliances list exported to CSV (/front/report.dynamic.php display_type 3) with the created record.", "stackiq": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json).", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: tile actions \"Export to .CSV Export to Excel\" (read 2026-09-26); https://docs.topdesk.com/en/create-odata-reports-for-asset-management.html: \"generate reports by using the TOPdesk OData feed ... Microsoft Power BI, or Microsoft Excel\" (read 2026-09-26). Reached on: Asset dashboard; OData feed." } @@ -3329,7 +3344,7 @@ "providerHow": "read-from-code", "note": "A user can save the facet and search selection as a named view and reopen it. Storage is OpenRegister's views API. It covers only those two pages.", "evidence": { - "glpi": "source read at 11.0.9: src/SavedSearch.php:52 SavedSearch, private or shared, listed under Tools > Saved searches (src/Html.php:1309) with optional alerts (front/savedsearch_alert.form.php). Reached on: Tools > Saved searches (front/savedsearch.php).", + "glpi": "source read at 11.0.9: src/SavedSearch.php:52 SavedSearch, private or shared, listed under Tools > Saved searches (src/Html.php:1309) with optional alerts (front/savedsearch_alert.form.php). Reached on: Tools > Saved searches (front/savedsearch.php). Driven on the lab at 11.0.9 (2026-09-26): Tools > Saved searches (/front/savedsearch.php) lists saved searches with private or shared scope and a default flag.", "stackiq": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back.", "topdesk": "https://tip.topdesk.com/c/83-share-saved-overviews-with-operators-and-operator-groups: roadmap card in column \"Launched\", \"User is able to share saved overviews with operators and operator groups - Rename the saved overview\" (read 2026-09-26)", "vng-softwarecatalogus": "unknown: only VNG-defined \"Marktscans-voorgedefinieerde filters\" are described; users saving their own view is not; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Marktscans (read 2026-09-26)" @@ -3411,7 +3426,7 @@ "providerHow": "read-from-code", "note": "The report picker exists and opens a working report. The list holds exactly one report.", "evidence": { - "glpi": "source read at 11.0.9: src/Report.php:52 Report builds a pick list of ready made reports, src/Report.php:77 default, :81 by contract, :85 by year, :87 financial information, :110 status, chosen from 'Select the report you want to generate' (src/Report.php:143). Reached on: Tools > Reports (front/report.php).", + "glpi": "source read at 11.0.9: src/Report.php:52 Report builds a pick list of ready made reports, src/Report.php:77 default, :81 by contract, :85 by year, :87 financial information, :110 status, chosen from 'Select the report you want to generate' (src/Report.php:143). Reached on: Tools > Reports (front/report.php). Driven on the lab at 11.0.9 (2026-09-26): /front/report.php offers Default report, By contract, By year, Hardware financial and administrative information, Other financial and administrative information, Network report, Loan and Status.", "stackiq": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303).", "topdesk": "https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub ... So far, you could find dashboards and reports in different places\" (read 2026-09-26); https://tip.topdesk.com/c/20-reporting-hub: roadmap card in column \"Launched\", \"Reporting Hub\" (read 2026-09-26). Reached on: TOPdesk menu > Reporting Hub.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/rapportages: \"Regelmatig worden er rapportages gemaakt over het gebruik van de Softwarecatalogus\" (read 2026-09-26); compliancy monitor and digital accessibility monitor pages. Reached on: Rapportages; Compliancy monitor." @@ -3470,7 +3485,7 @@ "featureConfidence": "low", "note": "One fixed report exports to CSV for a selected organisation. The filtered catalogue lists cannot be exported.", "evidence": { - "glpi": "source read at 11.0.9: src/Glpi/Search/Output/Csv.php, Ods.php, Xlsx.php and Pdf.php export the filtered list; the output format selector is rendered by src/Html.php:4219 Dropdown::showOutputFormat. Reached on: any filtered list, Export.", + "glpi": "source read at 11.0.9: src/Glpi/Search/Output/Csv.php, Ods.php, Xlsx.php and Pdf.php export the filtered list; the output format selector is rendered by src/Html.php:4219 Dropdown::showOutputFormat. Reached on: any filtered list, Export. Driven on the lab at 11.0.9 (2026-09-26): the filtered Appliances list exported to CSV with the created record.", "stackiq": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export.", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"Export to .CSV Export to Excel\" (read 2026-09-26). Reached on: Asset dashboard tile menu.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: \"Export to CSV\" on the filtered package-version list (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Ook beschikbaar via knop [Export to csv] op pagina Alle pakketten\" (read 2026-09-26). Reached on: Alle pakketversies > Export to CSV." @@ -3607,7 +3622,7 @@ "providerHow": "read-from-code", "note": "There is no knowledge base. Files can be attached to an application, but that is not searchable articles.", "evidence": { - "glpi": "source read at 11.0.9: src/KnowbaseItem.php:57 knowledge base articles with categories and visibility, linked to items through src/KnowbaseItem_Item.php:45 and shown on the appliance Knowledge base tab (src/Appliance.php:104); menu src/Html.php:1307. Reached on: Tools > Knowledge base (front/knowbaseitem.php).", + "glpi": "source read at 11.0.9: src/KnowbaseItem.php:57 knowledge base articles with categories and visibility, linked to items through src/KnowbaseItem_Item.php:45 and shown on the appliance Knowledge base tab (src/Appliance.php:104); menu src/Html.php:1307. Reached on: Tools > Knowledge base (front/knowbaseitem.php). Driven on the lab at 11.0.9 (2026-09-26): /front/knowbaseitem.php opens the knowledge base with Search and Browse.", "topdesk": "https://docs.topdesk.com/en/knowledge-management.html: \"The Knowledge Base is set up and managed by your organization's knowledge managers. Every operator is able to use information from the Knowledge Base\" (read 2026-09-26). Reached on: Modules > Knowledge Management.", "stackiq": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel.", "vng-softwarecatalogus": "unknown: the FAQ and manuals are site help, no knowledge base about applications is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" @@ -3797,7 +3812,7 @@ "providerHow": "read-from-code", "note": "No ticketing.", "evidence": { - "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:301 ticket_types includes Appliance (line 305), so tickets link to an application through src/Item_Ticket.php:41, shown on the appliance Tickets tab (src/Appliance.php:105). Reached on: Assistance > Tickets; Appliance > Tickets tab.", + "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:301 ticket_types includes Appliance (line 305), so tickets link to an application through src/Item_Ticket.php:41, shown on the appliance Tickets tab (src/Appliance.php:105). Reached on: Assistance > Tickets; Appliance > Tickets tab. Driven on the lab at 11.0.9 (2026-09-26): the default Super-Admin profile lists Computer, Monitor, NetworkEquipment, Peripheral, Phone, Printer, Software, DCRoom, Rack, Enclosure and Database as associable to tickets, not Appliance, so an appliance shows no Tickets tab until an administrator adds it in the profile; rating kept.", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity) ... cards, you can link multiple assets\" (read 2026-09-26). Reached on: Call card > Links > Assets.", "stackiq": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" @@ -3881,7 +3896,7 @@ "topdesk": "https://docs.topdesk.com/en/mobile-access-to-the-self-service-portal.html: \"The SSP layout is suited to be displayed in a mobile interface\" (read 2026-09-26); https://tip.topdesk.com/c/86-webshop-is-connected-with-asset-management: roadmap card in column \"Building\", \"End-user can order items which are in Asset Management\" (read 2026-09-26); pricing lists \"Self-Service Portal\" and \"Webshop\". Reached on: Self-Service Portal.", "stackiq": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "glpi": "source read at 11.0.9: the 11.0 service catalog src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45 lists native forms for self service users (menu src/Html.php:1283), and a form question can offer software items to pick, src/Glpi/Form/QuestionType/QuestionTypeItem.php:180 Software::class, creating a ticket from the answer. Reached on: Self service > Service catalog." + "glpi": "source read at 11.0.9: the 11.0 service catalog src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45 lists native forms for self service users (menu src/Html.php:1283), and a form question can offer software items to pick, src/Glpi/Form/QuestionType/QuestionTypeItem.php:180 Software::class, creating a ticket from the answer. Reached on: Self service > Service catalog. Driven on the lab at 11.0.9 (2026-09-26): /ServiceCatalog shows the service catalog with \"Report an issue\" and \"Request a service\"." } }, { @@ -3937,7 +3952,7 @@ "stackiq": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674).", "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"when tracking imports/Exchange exports via system events ... on a schedule\" (read 2026-09-26); https://tip.topdesk.com/c/116-support-for-importing-persons-and-operators-directly-from-local-active-directory: roadmap card in column \"Launched\", person import from AD (read 2026-09-26). Reached on: Settings > Import settings.", "vng-softwarecatalogus": "unknown: only \"De kaart wordt dagelijks bijgewerkt\" is stated; no organisation or contact sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/17042 (read 2026-09-26)", - "glpi": "source read at 11.0.9: automatic actions are scheduled and show their last run, src/CronTask.php:59 with install/mysql/glpi-empty.sql:1610 glpi_crontasks.lastrun, but LDAP user and group synchronisation is not one of them (grep -i ldap over the cron seed in install/empty_data.php:438 finds none); it is the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users, which must be scheduled by the system cron. Organisation (supplier) records have no sync at all. Reached on: Setup > Automatic actions; CLI bin/console ldap:sync." + "glpi": "source read at 11.0.9: automatic actions are scheduled and show their last run, src/CronTask.php:59 with install/mysql/glpi-empty.sql:1610 glpi_crontasks.lastrun, but LDAP user and group synchronisation is not one of them (grep -i ldap over the cron seed in install/empty_data.php:438 finds none); it is the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users, which must be scheduled by the system cron. Organisation (supplier) records have no sync at all. Reached on: Setup > Automatic actions; CLI bin/console ldap:sync. Driven on the lab at 11.0.9 (2026-09-26): /front/crontask.php lists automatic actions with run mode, frequency and last run." } } ], @@ -4568,7 +4583,7 @@ "note": "All the fields are on the contract form, but a contract requires a usage (gebruik) record and no stackiq page can create one, so on a fresh install the form cannot be completed without data from elsewhere (demo data, API, external frontend).", "evidence": { "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; their absence is not stated either; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", - "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1483 glpi_contracts with name, num (contract number), contracttypes_id, begin_date, duration, notice and renewal, and costs in install/mysql/glpi-empty.sql:1458 glpi_contractcosts. Reached on: Management > Contracts.", + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1483 glpi_contracts with name, num (contract number), contracttypes_id, begin_date, duration, notice and renewal, and costs in install/mysql/glpi-empty.sql:1458 glpi_contractcosts. Reached on: Management > Contracts. Driven on the lab at 11.0.9 (2026-09-26): created \"Lab contract\" with number C-001, start date, 12 month duration and 1 month notice.", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Contract Number (mandatory) ... Type ... Start Date (mandatory) ... End Date (mandatory) ... Costs (Services)\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > New.", "stackiq": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)" }, @@ -4982,7 +4997,7 @@ "stackiq": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909).", "topdesk": "https://docs.topdesk.com/en/let-your-topdesk-talk-to-other-applications.html: \"Send a request from TOPdesk to another program ... This way you can create an integration with almost any software that has an API\" (read 2026-09-26) triggered by card events (https://docs.topdesk.com/en/events-that-trigger-actions.html). Reached on: Action Management > action sequences.", "vng-softwarecatalogus": "unknown: notifications go to people by mail and inbox, no system webhooks are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "glpi": "source read at 11.0.9: src/Webhook.php:64 Webhook sends HTTP calls on new, update and delete events (src/Webhook.php:311 getDefaultEventsList) for management itemtypes including Appliance, Budget, Contact and others (src/Webhook.php:398). Reached on: Setup > Webhooks (src/Html.php:1331)." + "glpi": "source read at 11.0.9: src/Webhook.php:64 Webhook sends HTTP calls on new, update and delete events (src/Webhook.php:311 getDefaultEventsList) for management itemtypes including Appliance, Budget, Contact and others (src/Webhook.php:398). Reached on: Setup > Webhooks (src/Html.php:1331). Driven on the lab at 11.0.9 (2026-09-26): Setup > Webhooks (/front/webhook.php) lists webhooks with type, event and category." }, "pendingQuestion": "Can a flow created on stackiq's Flows page be triggered by object.updated on a catalogue schema and make an outbound HTTP call to an external system?" }, @@ -5009,7 +5024,7 @@ "featureConfidence": "high", "note": "Per-record history is shown on 11 detail pages, backed by OpenRegister's audit trail. There is no catalogue-wide view of who changed what, and the overlay itself lists audit-trail-view as 'soon'.", "evidence": { - "glpi": "source read at 11.0.9: src/Appliance.php:58 dohistory is true and src/Appliance.php:112 adds the Historical tab (src/Log.php:48 Log), recording who changed which field and when. Reached on: Management > Appliances > Historical tab.", + "glpi": "source read at 11.0.9: src/Appliance.php:58 dohistory is true and src/Appliance.php:112 adds the Historical tab (src/Log.php:48 Log), recording who changed which field and when. Reached on: Management > Appliances > Historical tab. Driven on the lab at 11.0.9 (2026-09-26): the appliance Historical tab listed two entries, including the contract link made by glpi.", "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"History widget : shows both present and past changes that have been made to an asset\" (read 2026-09-26); https://docs.topdesk.com/en/cards-in-call-management.html: \"Audit trail tab Previous events while processing this call\" (read 2026-09-26). Reached on: Asset card > History widget.", "stackiq": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object.", "vng-softwarecatalogus": "unknown: only a \"Laatst gewijzigd\" date on supplier pages and a mutation date in exports are shown; who changed what is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)" @@ -5097,7 +5112,7 @@ "providerHow": "read-from-code", "note": "The store installs configuration sets and flows, not code plugins, and it depends on a registry being configured.", "evidence": { - "glpi": "source read at 11.0.9: src/Glpi/Marketplace/View.php:53 marketplace view at front/marketplace.php (src/Glpi/Marketplace/View.php:103) and src/Glpi/Marketplace/Controller.php:64 download and install of plugins; src/Glpi/Marketplace/View.php:185 notes that a registration, at least a free one, is required. Reached on: Setup > Plugins > Marketplace.", + "glpi": "source read at 11.0.9: src/Glpi/Marketplace/View.php:53 marketplace view at front/marketplace.php (src/Glpi/Marketplace/View.php:103) and src/Glpi/Marketplace/Controller.php:64 download and install of plugins; src/Glpi/Marketplace/View.php:185 notes that a registration, at least a free one, is required. Reached on: Setup > Plugins > Marketplace. Driven on the lab at 11.0.9 (2026-09-26): Setup > Plugins > Marketplace, Discover tab: \"A registration, at least a free one, is required to use marketplace\"; plugins can still be installed by hand from their repositories.", "topdesk": "https://marketplace.topdesk.com/: \"Showing all 133 results\" of integrations (read 2026-09-26); https://docs.topdesk.com/en/exporting-and-importing.html: \"import an action sequence example from the TOPdesk Marketplace\" (read 2026-09-26). Integrations and action-sequence templates, not installable plugins. Reached on: TOPdesk Marketplace.", "stackiq": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items.", "vng-softwarecatalogus": "unknown: no plugins are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" From 5c5232692906daf750d9fb52b374344429d315c2 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:23:03 +0200 Subject: [PATCH 06/12] chore(parity): glpi driven at 11.0.9, VNG and TOPdesk read 2026-09-26, sources objects for three systems --- openspec/parity/capabilities.json | 222 +++++++++++++++++++++++++----- 1 file changed, 190 insertions(+), 32 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index d1b800b3..a7c5c91b 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -18,9 +18,58 @@ "key": "vng-softwarecatalogus", "name": "GEMMA Softwarecatalogus", "vendor": "VNG Realisatie", - "readOn": "2026-07-23", + "readOn": "2026-09-26", "evidenceGrade": "docs-only", - "unknownReason": "Not covered by the 20 intelligence rows for this system (a docs pass dated 2026-04-12 and 2026-07-23); the public site was not driven." + "unknownReason": "The live softwarecatalogus.nl manuals, FAQ, release letters and public pages do not describe these capabilities, and the successor repository is not evidence for the incumbent.", + "readNote": "Public documentation of the live softwarecatalogus.nl (the Drupal 7 build in production) read 2026-09-26. The successor build on github.com/VNG-Realisatie is Conduction's own work (stackiq), so nothing from that repository counts as evidence for this column; its PvE wensen are used only as the origin of demand rows.", + "sources": { + "docs": "https://www.softwarecatalogus.nl/handleidingen_voor_gemeenten", + "sourceRepo": null, + "featurePage": "https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus", + "featureRequests": "https://www.softwarecatalogus.nl/gebruikersonderzoek%202021", + "issueTracker": { + "url": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues", + "featureLabel": "PvE wens" + }, + "roadmap": null, + "changelog": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1", + "apiReference": null, + "marketplace": null, + "pricing": null, + "accessibilityStatement": "https://www.toegankelijkheidsverklaring.nl/register/20209", + "securityDocs": null, + "demoInstance": null, + "community": null, + "reviews": null, + "videos": "https://www.youtube.com/channel/UCg0bWcCn9Shnt57-L7hSbow", + "caseStudies": "https://www.softwarecatalogus.nl/praktijkvoorbeelden%20softwarecatalogus", + "partnerDirectory": null, + "trainingCurriculum": null, + "jobPostings": null, + "tenders": [ + "TenderNed 343458 Vernieuwen GEMMA Softwarecatalogus (VNG Realisatie, market consultation, 2024-07-17)", + "TenderNed 354602, 354933, 356544 Vernieuwing Softwarecatalogus (VNG Realisatie, 2024-10 to 2024-11)", + "TenderNed 401475 Vernieuwing Softwarecatalogus (VNG Realisatie, 2025-11-18)", + "TenderNed 264353 functioneel beheerder GEMMA Online en Softwarecatalogus (VNG Realisatie, 2022-06-14)", + "Requirement text naming the Softwarecatalogus as the place for supplier product information: TenderNed 418890 (Noordwijk), 417169 (Reimerswaal), 415897 (FUMO), 383984 (HLT Samen)", + "Requirements scoping a solution by GEMMA Softwarecatalogus reference components: TenderNed 241147, 229235, 227989, 226100 (Stein)" + ], + "nullReasons": { + "sourceRepo": "The live catalogue runs on Drupal 7 (per the nieuws page) and its source is not public. github.com/VNG-Realisatie/Softwarecatalogus holds the successor build, not the incumbent.", + "roadmap": "FAQ E14 points to a homepage block 'Binnenkort in de Softwarecatalogus', which is absent from today's homepage.", + "apiReference": "https://www.softwarecatalogus.nl/api returns only 'Services Endpoint api has been setup successfully.'; no API documentation for the incumbent exists. The API specification on vng-realisatie.github.io describes the successor.", + "marketplace": "No plugin or extension marketplace; the catalogue is a single hosted service.", + "pricing": "No price or fee page found; no page states the service is free either.", + "securityDocs": "Only a privacy statement (Privacyverklaring softwarecatalogus) exists; no security documentation found.", + "demoInstance": "No demo or sandbox; the public site is browseable without login but no demo login is offered.", + "community": "No forum for the incumbent; contact runs through softwarecatalogus@vng.nl.", + "reviews": "No third-party review listings found for a free public-sector catalogue.", + "partnerDirectory": "No implementation partners; the supplier list at /leveranciers is catalogue content, not a partner directory.", + "trainingCurriculum": "Only manuals and FAQ; no training programme found.", + "jobPostings": "vng.nl/artikelen/werken-bij-de-vng is linked from the footer but answered 403 to scripted reads." + }, + "readHow": "curl with a browser user agent on 2026-09-26: every non-null URL returned HTTP 200 (docs, featurePage, featureRequests, changelog, caseStudies, videos, accessibilityStatement, issueTracker). The accessibility statement is status C, last updated 02-04-2026. gh api confirmed the GitHub repo (pushed 2026-02-26, 209 open issues) and its label 'PvE wens'. The GitHub issue tracker and label belong to the successor project, whose PvE wensen describe what the incumbent lacks. vng.nl pages answered 403; gemmaonline.nl answered a JavaScript challenge and was not read. Ruling 2026-09-26: the column rests on the live softwarecatalogus.nl (the old Drupal 7 build) only; the successor build on GitHub is our own work, so nothing from that repo counts as incumbent evidence." + } }, { "key": "sap-leanix", @@ -42,17 +91,94 @@ "key": "glpi", "name": "GLPI", "vendor": "Teclib", - "readOn": "2026-07-23", - "evidenceGrade": "docs-only", - "unknownReason": "Not covered by the GLPI rows read for this product (a docs pass dated 2026-07-23) or by the procest lane's source reading of 2026-09-14, which answered case-management questions." + "readOn": "2026-09-26", + "evidenceGrade": "driven", + "unknownReason": "No glpi cell is unknown after the source read at 11.0.9.", + "readVersion": "11.0.9 (tag 11.0.9, commit 2a44dd1527a1f70da48d6b484bcb7a8849a6e5fb; version/11.0.9 and src/autoload/constants.php:43 agree)", + "readNote": "Source read at tag 11.0.9 across all 173 rows (routes, itemtypes, schema, rights, templates, locales, tests), plugins pluginsGLPI/datainjection 2.15.11, pluginsGLPI/fields 1.24.5 and yild/gdprropa 1.0.3 read at their tags where a row depends on them. Then driven on a lab at 11.0.9 (glpi/glpi:11.0.9, market-intelligence stackiq/glpi) for 26 rows marked \"Driven on the lab at 11.0.9\"; the rest rest on the source read at the same version.", + "sources": { + "docs": "https://glpi-user-documentation.readthedocs.io/", + "sourceRepo": "https://github.com/glpi-project/glpi (tag 11.0.9, 2a44dd15)", + "featurePage": "https://glpi-project.org/features/", + "featureRequests": "https://github.com/glpi-project/roadmap/discussions", + "issueTracker": { + "url": "https://github.com/glpi-project/glpi/issues", + "featureLabel": "feature suggestion" + }, + "roadmap": "https://glpi-project.org/roadmap/", + "changelog": "https://github.com/glpi-project/glpi/blob/11.0.9/CHANGELOG.md", + "apiReference": "https://github.com/glpi-project/glpi/blob/11.0.9/apirest.md", + "marketplace": "https://plugins.glpi-project.org/", + "pricing": "https://glpi-project.org/pricing/", + "accessibilityStatement": null, + "securityDocs": "https://www.glpi-project.org/en/security-policy/", + "demoInstance": null, + "community": "https://forum.glpi-project.org/", + "reviews": null, + "videos": "https://www.youtube.com/playlist?list=PLUMG2P30gRaHYVZwtqLdRIe2DtkDkNG_s", + "caseStudies": "https://glpi-project.org/customers/", + "partnerDirectory": "https://glpi-project.org/partners/", + "trainingCurriculum": "https://www.glpi-project.org/en/trainings/", + "jobPostings": null, + "tenders": [ + "No TenderNed tender names GLPI (name, description and requirement text searched 2026-09-26)", + "portugal-base 7721/2025 Renovacao de Licencas de Software GLPI e Fortinet (ANQEP, 2025-03-26)", + "spain-placsp ES-PLACSP-19542624 official plugins for the GLPI instance used by INTEF (2026-04-22)" + ], + "nullReasons": { + "accessibilityStatement": "no statement found: https://glpi-project.org/accessibility/ and /accessibility-statement/ return 404 and the pricing and home pages link none.", + "demoInstance": "no public demo: https://glpi-project.org/demo/ returns 404; the pricing page offers only a 45 day GLPI Network trial behind registration (https://myaccount.glpi-network.cloud/register.php), which readers may not open.", + "reviews": "G2 (https://www.g2.com/products/glpi/reviews), Capterra, Gartner Peer Insights, TrustRadius, SourceForge and AlternativeTo all return 403 to curl and WebFetch, so none could be confirmed.", + "jobPostings": "the GLPI home page links https://www.welcometothejungle.com/fr/companies/teclib, which returns 403 to non-browser clients; https://www.teclib.com/en/careers/ redirects to the GLPI home page, so no job list was confirmed." + }, + "readHow": "2026-09-26: curl -sIL with a browser user agent returned 200 for docs, sourceRepo, featurePage (title 'Discover GLPI features'), issueTracker, changelog and apiReference at tag 11.0.9, marketplace, pricing, securityDocs, community (title 'Forum GLPI-Project'), videos (playlist title 'GLPI Success Stories'), caseStudies, partnerDirectory, trainingCurriculum; WebFetch confirmed content of pricing (GLPI Network public cloud 19 EUR per user per month, private cloud 21 EUR, self hosted Basic 100 EUR to Enterprise 4,500 EUR per month), roadmap (community roadmap pointing to GitHub discussions), featureRequests (suggest.glpi-project.org 301 redirects to github.com/glpi-project/roadmap/discussions, 'Ideas and feature requests' category, 118 discussions listed through the GitHub GraphQL API), marketplace, customers, partners (searchable by country) and trainings (four courses, no certification). github.com/glpi-project/glpi/discussions returns 404, so the roadmap repository is the feature channel. featureLabel read from the GitHub labels API (labels 'feature suggestion' and 'enhancement'). Plugin repositories read at their release tags: github.com/pluginsGLPI/datainjection 2.15.11, github.com/pluginsGLPI/fields 1.24.5, github.com/yild/gdprropa 1.0.3 (declares GLPI 10 only)." + } }, { "key": "topdesk", "name": "TOPdesk", "vendor": "TOPdesk", - "readOn": "2026-07-23", + "readOn": "2026-09-26", "evidenceGrade": "docs-only", - "unknownReason": "Not covered by the 50 intelligence rows for this system (docs passes dated 2026-04-10 to 2026-07-23); the product was not driven." + "unknownReason": "The public TOPdesk documentation, developer docs and roadmap do not cover these capabilities; releasenotes.topdesk.com (a JavaScript app) and community.topdesk.com/ideas (403) could not be read.", + "readNote": "Public TOPdesk documentation read 2026-09-26 through the docs.topdesk.com offline search index, with every cited URL re-fetched at HTTP 200; the public roadmap on tip.topdesk.com read from its embedded data. No trial, no login.", + "sources": { + "docs": "https://docs.topdesk.com/", + "sourceRepo": null, + "featurePage": "https://www.topdesk.com/en/features/", + "featureRequests": "https://tip.topdesk.com/", + "issueTracker": null, + "roadmap": "https://tip.topdesk.com/", + "changelog": "https://releasenotes.topdesk.com/", + "apiReference": "https://developers.topdesk.com/", + "marketplace": "https://marketplace.topdesk.com/", + "pricing": "https://www.topdesk.com/en/pricing/", + "accessibilityStatement": "https://www.topdesk.com/en/accessibility/", + "securityDocs": "https://docs.topdesk.com/en/security.html", + "demoInstance": null, + "community": "https://community.topdesk.com/", + "reviews": null, + "videos": "https://www.topdesk.com/en/demo/", + "caseStudies": "https://www.topdesk.com/en/customer-stories/", + "partnerDirectory": null, + "trainingCurriculum": null, + "jobPostings": "https://careers.topdesk.com/", + "tenders": [ + "TenderNed 399078 Vrijwillige transparantie TOPdesk MGR (Rijk van Nijmegen, 2025-10-31)", + "TenderNed 402170 Service- en vastgoed management systeem (Velsen, 2025-11-21): requirements REQ6, REQ12, REQ15 name integration with OGD/TOPdesk", + "TenderNed 206168 and 219511 TOPdesk migration (Amsterdam, 2020 to 2021)", + "TenderNed 324002 and 237630 TOPdesk specialist hire (Zorginstituut Nederland)" + ], + "nullReasons": { + "sourceRepo": "TOPdesk is closed source.", + "issueTracker": "No public issue tracker; support runs through My TOPdesk (login). Public input goes through the roadmap portal tip.topdesk.com.", + "demoInstance": "No public demo instance; a community question about a trial (community.topdesk.com/q-a-129/topdesk-trial-version-personal-instance-974) shows trials run through sales.", + "reviews": "G2 (g2.com/products/topdesk/reviews) and Capterra answered 403 to scripted reads; not confirmed.", + "partnerDirectory": "www.topdesk.com/en/partners/ answered 404 and no partner directory is linked from the English site.", + "trainingCurriculum": "www.topdesk.com/en/training/ answered 404; only consultancy services are linked (www.topdesk.com/en/services/consultancy/)." + }, + "readHow": "curl with a browser user agent on 2026-09-26, all non-null URLs HTTP 200. docs.topdesk.com was read through its full-text search index en/js/fuzzydata.js (1,532 sections, 987 pages); every docs page cited in the pack was re-fetched with HTTP 200. tip.topdesk.com (Productboard public roadmap, columns Under consideration, Planned, Building, Launched) was parsed from the page's embedded JSON, 185 cards. releasenotes.topdesk.com is a JavaScript app whose entries were not read. community.topdesk.com/ideas answered 403; the community has no ideas board, ideas go to tip.topdesk.com per docs.topdesk.com/en/product-updates.html. docs.topdesk.com also carries Virtual Appliance (on-premises) documentation per release." + } } ], "areas": [ @@ -880,7 +1006,7 @@ "providerHow": "read-from-code", "note": "Stackiq has no record for an API an application exposes.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#27425 'API Management' (2026-04-12): Catalog and manage APIs across the application landscape", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: interface subtype 'API ... APIs provide functionalities accessible to external applications ... Examples: Metrics API, Import API', related to the providing application (read 2026-09-26). Reached on: Inventory > Interface fact sheet, subtype API.", "stackiq": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label", "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no register of APIs an application exposes is described; standards are declared instead; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -893,7 +1019,7 @@ "name": "Export the graph of what an application is linked to, for use elsewhere.", "origin": "competitor", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -913,7 +1039,8 @@ "glpi": "source read at 11.0.9: front/impactcsv.php streams Glpi\\Csv\\ImpactCsvExport for an item, linked from the impact list view at src/Impact.php:393; the graph Download button src/Impact.php:1165 calls js/impact.js:2528 download, which writes PNG (js/impact.js:2539) or JPEG (js/impact.js:2546). Reached on: Appliance > Impact analysis tab, Download and CSV export.", "stackiq": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*", "topdesk": "unknown: exporting the relation graph is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: \"Pakketten én koppelingen worden in 1 model geëxporteerd ... AMEFF-export\" (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Mijn koppelingen: Knop [Exporteren] op tabblad Koppelingen\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten or Koppelingen > Exporteren > AMEFF-export." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: \"Pakketten én koppelingen worden in 1 model geëxporteerd ... AMEFF-export\" (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Mijn koppelingen: Knop [Exporteren] op tabblad Koppelingen\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten or Koppelingen > Exporteren > AMEFF-export.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams: diagrams export 'in the following formats: PDF, SVG, PNG, HTML embed code, and XML' and open in draw.io; https://help.sap.com/docs/leanix/ea/exporting-fact-sheet-data-as-excel-file exports fact sheet data. No export of an application's relation graph as data is documented as such (read 2026-09-26). Reached on: Diagrams > Export (XML, draw.io); Inventory > Export." } }, { @@ -922,7 +1049,7 @@ "name": "Add and check the organisation's outside integrations from one integrations overview.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "partial", @@ -940,6 +1067,7 @@ "stackiq": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq", "topdesk": "https://docs.topdesk.com/en/connections.html: \"TOPdesk offers a storage space for usernames, passwords, and authentication tokens used in automated actions ... Better overview: Observe when specific credentials are applied\" (read 2026-09-26); https://docs.topdesk.com/en/using-the-automated-actions-overview.html: \"contains all asset actions, webhooks, scheduled actions ... The last execution status\" (read 2026-09-26). Reached on: Settings > Connections; Action Management > Automated Actions.", "vng-softwarecatalogus": "unknown: no overview of the catalogue's own outside integrations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/discovering-ai-agents-using-api: 'Go to the Integrations section in the administration area. Choose Add Integration'; https://help.sap.com/docs/leanix/ea/collibra-data-catalog-integration: 'Administration > Integrations > Sync Log' to check each integration (read 2026-09-26). Reached on: Administration > Integrations (Add Integration, Sync Log).", "glpi": "source read at 11.0.9: outside integrations are set up on separate Setup pages, not one overview: src/Html.php:1331 Webhook, src/Html.php:1333 OAuthClient and MailCollector, Auth (LDAP, SSO) on src/Html.php:1332; src/Webhook.php:64 Webhook and src/OAuthClient.php:45 OAuthClient each have their own list. Reached on: Setup > Webhooks, Setup > OAuth clients, Setup > Authentication." } }, @@ -970,6 +1098,7 @@ "stackiq": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: only export to AMEFF is documented; importing an ArchiMate file into the catalogue is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea (all EA pages grepped for ArchiMate and exchange format); diagram import supports '.drawio, Lucidchart, .vsdx, PNG, SVG, JPEG' only (https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams), ArchiMate appears only as a shape template (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma\\|togaf' over src/ templates/ locales/glpi.pot returns nothing; no model import exists. Import paths in core are inventory (src/Glpi/Inventory/Inventory.php:106) and form import (src/Glpi/Controller/Form/Import/), neither for models." } }, @@ -1000,6 +1129,7 @@ "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", "stackiq": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; exports are PDF, SVG, PNG, HTML and draw.io XML (https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams); no ArchiMate exchange format export is documented, ArchiMate 3.2 is only a visual template (https://help.sap.com/docs/leanix/ea/styles-and-patterns) (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing; exports are CSV, PDF and spreadsheet search output (src/Glpi/Csv/) only. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43 and the spreadsheet siblings." } }, @@ -1029,6 +1159,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: export file named \"GEMMA_Softwarecatalogus__ameff_model\" (read 2026-09-26); https://www.softwarecatalogus.nl/Archi_modellen_samenvoegen: \"De export van de Softwarecatalogus bevat de GEMMA en alle pakketten en koppelingen van de gemeente\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: \"GEMMA views met daarop geplot de pakketten van de gemeente\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Exporteren > AMEFF-export.", "stackiq": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no GEMMA content and no ArchiMate file export are documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma' over src/ templates/ locales/glpi.pot returns nothing; no GEMMA plotting or per entity model export. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43, no model file." } }, @@ -1058,6 +1189,7 @@ "stackiq": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the merge guide checks the result inside Archi via its status log; the catalogue itself offers no round-trip check; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Archi_modellen_samenvoegen (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no model file import and export pair (ArchiMate or similar) is documented, so no round trip check exists in the docs (read 2026-09-26)", "glpi": "source read at 11.0.9: there is no model import or export to round trip, grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43, no model file." } }, @@ -1067,7 +1199,7 @@ "name": "Follow a long model import while it runs, and cancel it if needed.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -1087,6 +1219,7 @@ "stackiq": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no model import is documented; for export only \"Er verschijnt een venster met de melding dat de export gegenereerd wordt\"; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools (read 2026-09-26)", + "sap-leanix": "https://updates.leanix.net/announcements/product-update-march-2026: 'The new asynchronous import process runs entirely in the background ... A real-time progress widget in the inventory side-panel keeps you informed of import status'. This is the Excel import, not a model import, and cancelling is not described (read 2026-09-26). Reached on: Inventory side panel > import progress widget.", "glpi": "source read at 11.0.9: no model import exists (grep -ril 'archimate' src/ returns nothing), so there is no import to follow; the generic progress endpoint src/Glpi/Controller/ProgressController.php serves other long operations. The progress route is src/Glpi/Controller/ProgressController.php:50 /progress/check/{key}, used by the installer (src/Glpi/Controller/InstallController.php:57)." } }, @@ -1116,6 +1249,7 @@ "stackiq": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only", "topdesk": "unknown: GEMMA is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/lexicon: lexicon of catalogue terms (Addendum, Referentiecomponent, Standaard, SaaS); terms in page text link to it (read 2026-09-26); https://www.softwarecatalogus.nl/node/13683: \"Alle referentiecomponenten ... de toelichting bij de referentiecomponenten\" (read 2026-09-26). Reached on: Lexicon; Alle referentiecomponenten.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no GEMMA terms and no in-place glossary of reference architecture terms are documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'gemma\\|glossary' over src/ templates/ locales/glpi.pot returns nothing; no reference term definitions ship in core. The knowledge base (src/KnowbaseItem.php:57) is the only place definitions could be written by hand." } }, @@ -1142,7 +1276,7 @@ "featureConfidence": "medium", "note": "The mapping to GEMMA reference components exists, but there is no map view in stackiq; you only see it as a facet list or in Archi after an admin export.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | docs, intelligence competitor_features#27420 'Business Capability Mapping' (2026-04-12): Map applications to business capabilities and processes", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model: 'A business capability is supported by an application'; https://help.sap.com/docs/leanix/ea/application-portfolio-assessment lists a 'Business capability map' (read 2026-09-26). Reached on: Reports > Landscape Report on Business Capabilities.", "bluedolphin": "docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", "stackiq": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies", "topdesk": "unknown: no capability or function map is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", @@ -1171,7 +1305,7 @@ "providerHow": "read-from-code", "note": "Models are imported and exported as ArchiMate files; nothing lets a user draw or edit a model inside stackiq.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48869 'Architecture diagrams / free-draw' (2026-07-23): Auto-generated and manual architecture diagrams from the data model.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams and https://help.sap.com/docs/leanix/ea/working-with-fact-sheets-in-diagrams: free draw and data flow diagrams edited in the diagram editor, with an ArchiMate 3.2 shape template (https://help.sap.com/docs/leanix/ea/styles-and-patterns) (read 2026-09-26). Reached on: Diagrams > New Diagram (diagram editor).", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models.", "stackiq": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components", "topdesk": "unknown: no architecture modelling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", @@ -1185,7 +1319,7 @@ "name": "Model business processes and link them to the applications that support them.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", @@ -1204,6 +1338,7 @@ "stackiq": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json", "topdesk": "unknown: no process modelling linked to applications is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no process modelling is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/business-context-modeling-guidelines: business context subtype 'Process : Processes show the different steps and interactions', related to applications; SAP Signavio integration documented under Discovery and Integrations (read 2026-09-26). Reached on: Business Context fact sheet, subtype Process.", "glpi": "source read at 11.0.9: grep -rli 'business process' over src/ and locales/glpi.pot returns nothing; no process itemtype to link to applications. Appliance tabs (src/Appliance.php:98 onwards) link no process." } }, @@ -1213,7 +1348,7 @@ "name": "Model a future-state landscape and compare it with today's.", "origin": "competitor", "vng-softwarecatalogus": "partial", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -1228,7 +1363,7 @@ "providerHow": "read-from-code", "note": "Planned usage and planned replacements exist per record, but there is no future-state model and no comparison with today.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#27419 'IT Transformation' (2026-04-12): Plan and execute cloud migrations and modernization | Rated partial because transformation planning.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/sap-leanix-architecture-and-road-map-planning: 'plan your target architecture and monitor initiative progress', transformation templates and impacts; https://updates.leanix.net/announcements/plan-with-consistent-future-architecture-data-introducing-the-committed-future (2026-09-24): 'Understanding your architecture across the past, present, and future ... introducing the committed future'. In the Architecture and Road Map Planning add on (read 2026-09-26). Reached on: Architecture and Road Map Planning > Transformations, target architecture diagrams.", "stackiq": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape", "topdesk": "unknown: Long-Term Planning scenarios are for maintenance planning and the module \"will reach end of life ... November 2026\"; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"geplande harmonisaties ... met een status gepland met bijbehorende datum. Zo kan ook het uiteindelijke doel-landschap in 1 overzicht inzichtelijk worden gemaakt\" (read 2026-09-26). No side-by-side comparison of today and target. Reached on: Mijn softwarecatalogus (samenwerking) > Pakketten > status Gepland.", @@ -1241,7 +1376,7 @@ "name": "Find reference components that no application in your landscape covers.", "origin": "competitor", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", @@ -1260,6 +1395,7 @@ "stackiq": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage", "topdesk": "unknown: GEMMA reference components are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tile \"Pakketten met meer mogelijkheden: U heeft in uw pakketoverzicht pakketten die geschikt zijn voor referentiecomponenten waarbij u nog geen pakket heeft opgevoerd\" (read 2026-09-26). It lists uncovered components only where an owned package could fill them. Reached on: Dashboard tile Pakketten met meer mogelijkheden.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/report-types: Matrix Report 'Displays relations between fact sheets in a two-dimensional matrix' for 'Coverage gap analysis'. Gaps are business capabilities without supporting applications; no reference architecture such as GEMMA is shipped (read 2026-09-26). Reached on: Reports > Matrix Report.", "glpi": "source read at 11.0.9: no reference component model to compare against, grep -ril 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; appliances are typed only by the free Appliance type dropdown (install/mysql/glpi-empty.sql:8941)." } }, @@ -1269,7 +1405,7 @@ "name": "Have a diagram drafted for you by an assistant from a description.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", @@ -1288,6 +1424,7 @@ "stackiq": "no diagram generation in lib/Service or src; no AI integration for diagrams", "topdesk": "unknown: the AI features cover tickets and knowledge, not diagrams; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no assistant is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://updates.leanix.net/announcements/build-and-edit-architecture-diagrams-with-ai-agents (2026-09-15): 'AI agents connected to your workspace via the MCP server can now create, populate, and edit diagrams ... You describe what you want to see, and the agent adds fact sheets to a canvas' (read 2026-09-26). Reached on: MCP server with an AI agent > diagrams.", "glpi": "source read at 11.0.9: grep -rli 'openai\\|llm\\|mistral\\|chatgpt\\|artificial intelligence' over src/ templates/ returns nothing; diagrams are drawn by hand in the impact graph (src/Impact.php:1160)." } }, @@ -1297,7 +1434,7 @@ "name": "Browse a register of the standards applications are expected to support.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -1317,6 +1454,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle standaarden: Dit overzicht is een opsomming van alle standaarden waaraan pakketten mogelijk moeten voldoen. Alle standaarden hebben een toelichting en indien aanwezig een toelichting op het compliancy-instrument\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle standaarden.", "stackiq": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/technology-standards-management-capabilities: Technology Risk and Compliance helps 'establish technology standards' for frameworks and languages. These are technology standards for components, not interoperability standards an application must support (read 2026-09-26). Reached on: Technology Risk and Compliance > technology standards.", "glpi": "source read at 11.0.9: no standards itemtype, grep -ril 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing and the word standard in src/Appliance.php occurs only in addStandardTab (src/Appliance.php:100)." } }, @@ -1326,7 +1464,7 @@ "name": "Attach a test report or other evidence to a compliance claim.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -1346,6 +1484,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Door de vakje achter de standaard aan te vinken voor Ondersteuning(gepland) en Compliancy, wordt de optie om een testrapport of auditrapport op te voeren geopend\" (read 2026-09-26). Reached on: Supplier login > productversie > Voeg extra standaarden toe.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets: 'The Resources tab ... You can upload files up to 10 MB' and links on any fact sheet. Files attach to the fact sheet, not to a specific compliance claim (read 2026-09-26). Reached on: Fact sheet > Resources tab.", "glpi": "source read at 11.0.9: any document can be attached to an appliance through the Documents tab, src/Appliance.php:100 Document_Item tab and src/Document_Item.php:46, stored in install/mysql/glpi-empty.sql:2585 glpi_documents; there is no compliance claim to attach it to. Reached on: Management > Appliances > Documents tab." } }, @@ -1375,6 +1514,7 @@ "stackiq": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C8: \"Gepubliceerde testrapporten voor een aantal standaarden die in de compliancy-monitor staan, worden sinds eind 2016 door VNG Realisatie gecontroleerd en daarna op status goedgekeurd of afgekeurd gezet\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facet \"Standaard met testrapport: Toon alleen pakketversies met compliancy aangetoond in een testrapport\" (read 2026-09-26). Reached on: Alle pakketversies > filter Standaard met testrapport; Compliancy monitor.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a quality seal approves fact sheet data as a whole (https://help.sap.com/docs/leanix/ea/updating-lifecycle-phase-and-approving-quality-seal) but no distinction between verified and supplier asserted compliance claims is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no compliance claim model, grep -rli 'complian' over src/Appliance.php src/Software.php returns nothing; nothing to mark verified or claimed (src/Appliance.php:46 fields are inventory and management fields only)." } }, @@ -1384,7 +1524,7 @@ "name": "See applications against chosen standards in one matrix, cell by cell.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -1404,6 +1544,7 @@ "stackiq": "src/manifest.json ComplianceMatrix /compliance-matrix custom page -> src/customComponents.js ComplianceMatrixView -> src/views/ComplianceMatrixView.vue (modules x selected standard versions or BIO measures, src/utils/complianceMatrix.js:270 columns)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/compliancy_monitor: per standard (e.g. \"Betalen en invorderen services 1.0\") a table of Leverancier, Pakketversie, Compliancy \"Ok\" or \"Niet ok\" (read 2026-09-26). Fixed per standard, not a matrix of chosen applications against chosen standards. Reached on: Homepage > Compliancy monitor.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model-dora-extension: 'You can create a regulatory dictionary, categorize DORA requirements, and link DORA obligations directly to specific IT and business architecture elements'; https://help.sap.com/docs/leanix/ea/report-types: Matrix Report maps relations cell by cell. Regulation obligations, not interoperability standards (read 2026-09-26). Reached on: DORA extension + Reports > Matrix Report.", "glpi": "source read at 11.0.9: there are no standards in core (grep -rli 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing), so no application by standard matrix; search output (src/Glpi/Search/Output/Spreadsheet.php) only tabulates item fields. The spreadsheet output is src/Glpi/Search/Output/Csv.php:38 and siblings." } }, @@ -1433,6 +1574,7 @@ "stackiq": "appinfo/routes.php:275 POST /api/bulk-sync-standards -> lib/Controller/SettingsController.php:3598 (isAdmin check) -> lib/Service/ModuleComplianceService.php:527 bulkSyncModuleStandards (reads up to 1000 compliancy records and updates module standards); UI src/views/settings/sections/StatisticsOverview.vue:79 button -> src/modals/BulkSyncDialog.vue:321", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: only per-version copying is described (\"opvoer van een nieuwe versies mogelijk als kopie van een op te geven vorige versie\"); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no action that refreshes the standards set of many applications is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no standards model exists (see comp-standards-register); massive actions (src/MassiveAction.php:666 Update) update item fields only." } }, @@ -1462,6 +1604,7 @@ "stackiq": "src/manifest.json BioMaatregelen /bio-maatregelen index (columns code,name,thema,bioVersion,bbnNiveau) and BioMaatregelDetail; register property is bbnLevel (lib/Settings/softwarecatalogus_register.json bioMeasure), so the bbnNiveau column is empty; no BIO catalogue is seeded (only 6 demo objects in lib/Settings/stackiq_mock_register.json)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: BIO measures are not in the catalogue docs; BBN views live on GEMMA Online per the news page; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/nieuws (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for BIO and Baseline Informatiebeveiliging, no hits; LeanIX documents DORA and GDPR content only (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'iso 27001\\|27002' and grep -rwi 'bio' over src/ locales/glpi.pot return nothing; no security measure catalogue ships (menus at src/Html.php:1295 onwards list none)." } }, @@ -1491,6 +1634,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.bioMeasure links a module to a BIO measure; src/manifest.json ModuleDetail md-compliance lists claims incl. bioMaatregel column, BioMaatregelDetail bm-compliance lists modules per measure; compliancy has no status/met-not-met field", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no BIO assessment per application is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for BIO, no hits; no BIO measure assessment per application is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no measure catalogue and no assessment itemtype; grep -rli 'iso 27001\\|27002' over src/ locales/glpi.pot returns nothing and Appliance tabs (src/Appliance.php:98 onwards) hold no assessment." } }, @@ -1520,6 +1664,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json module.dpiaStatus (enum not required/required/executed), dpiaDate, dpiaNextAssessment, dpiaDocumentRef; src/manifest.json ModuleDetail md-data includes the DPIA fields; Modules /modules quick filter 'Without DPIA (BBN2+)'", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no DPIA field is described; the VWO addendum is a supplier-level processing agreement; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/leveranciers (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for DPIA and data protection impact assessment, no hits; only data classification of data objects for GDPR is documented (https://help.sap.com/docs/leanix/ea/data-object-modeling-guidelines 'classified into personally identifiable data (e.g., to cater to GDPR use cases)') (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'dpia\\|impact assessment\\|gdpr' over src/ returns nothing, locales/glpi.pot:12792 'gdpr-tools' is only an icon name. The GDPR records plugin yild/gdprropa read at tag 1.0.3 has 'PIA required' and 'PIA status' (inc/record.class.php:459, :468) but declares GLPI 10 only, setup.php:56 max 10.99.99, so it does not run on 11.0.9." } }, @@ -1547,6 +1692,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/inkoopondersteuning%20standaarden: \"De verplichte standaarden zijn: ... de open standaarden die onder het pas-toe-of-leg-uit regime van de overheid binnen het werkingsgebied vallen\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: package version shows \"Verplichte standaarden ... Ondersteuning Compliancy Testrapport\" (read 2026-09-26). Comply-or-explain standards are mixed into the mandatory set, not shown as their own list. Reached on: Package page > Standaarden; Inkoopondersteuning.", "stackiq": "grep for forum standaardisatie / pas toe of leg uit / comply-or-explain in lib and src: no hits; standards come only from the GEMMA AMEF import (element gemmaType=standaard)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for Forum Standaardisatie and comply or explain, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'standaard\\|forum standaardisatie\\|comply' over src/ locales/glpi.pot returns nothing relevant; no comply or explain list in core (Setup menu src/Html.php:1330 onwards)." } }, @@ -1556,7 +1702,7 @@ "name": "Score the correctness and completeness of the register against a rule set.", "origin": "competitor", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -1574,6 +1720,7 @@ "stackiq": "grep for completeness/health score/quality score in lib and src: no hits; lib/Command/ReferencesAuditCommand.php:34 (occ stackiq:references:audit) only audits cross-app uuid references, it is not a scored rule set", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C7: automatic checks and \"Te corrigeren fouten ... Bijvoorbeeld over het ontbreken van pakketversies, of tegenstrijdigheid in de status van een pakketversie en vermelde datum distributie\" (read 2026-09-26); https://www.softwarecatalogus.nl/voortgang-verbeteren: star criteria for completeness (read 2026-09-26). Reached on: Supplier dashboard Te corrigeren fouten; Voortgang sterren.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-portfolio-management-dashboard: 'Data Quality KPI ... Overall Completion of Applications ... Broken quality seal ... Missing Business Capability'; completion score weights set by admins (https://help.sap.com/docs/leanix/ea/fact-sheet-completeness) (read 2026-09-26). Reached on: Dashboards > Application Portfolio Management Dashboard > Data Quality KPIs.", "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing and no rule set scores register quality; the rules engine (src/Glpi/Rules/, src/RuleCollection.php) assigns and imports data, it does not score it. The rules engine base is src/RuleCollection.php:48." } }, @@ -1583,7 +1730,7 @@ "name": "Send a compliance questionnaire to a supplier and keep the answers with the application.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", @@ -1602,6 +1749,7 @@ "stackiq": "grep for questionnaire/vragenlijst in lib and src: no hits; no questionnaire schema in lib/Settings/softwarecatalogus_register.json", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no questionnaire to suppliers is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/reviewing-responses: survey answers are reviewed and saved to the fact sheet; recipients are the users 'assigned to the fact sheet'. Sending to an outside supplier is not documented (read 2026-09-26). Reached on: Surveys.", "glpi": "source read at 11.0.9: native forms (src/Glpi/Form/Form.php:92) are filled by logged in or helpdesk users and only produce tickets, changes or problems (src/Glpi/Form/Destination/FormDestinationTicket.php:47); nothing sends a questionnaire to a supplier or stores answers on an appliance." } }, @@ -1631,6 +1779,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Deze handleiding is bedoeld voor de leveranciers en legt uit hoe de leveranciers hun productportfolio kunnen aanvullen en beheren ... voeg pakket toe\" (read 2026-09-26). Reached on: Supplier login > Productportfolio.", "stackiq": "src/manifest.json:592 Modules and :647 Diensten are FacetedCatalogIndexView over schema module/catalogService (CnIndexPage, showAdd default true); lib/Settings/softwarecatalogus_register.json:6779 module has provider + publicationDate (visible on form) and public read when publicationDate <= now or registeredBy Supplier", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; LeanIX is a customer's internal EA workspace, no supplier facing publication of offerings is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers are records kept by the buying organisation, install/mysql/glpi-empty.sql:7067 glpi_suppliers, with no supplier login or offering page; profiles (src/Profile.php) cover internal users and the self-service helpdesk only." } }, @@ -1660,6 +1809,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Ik ben op zoek naar een nieuw pakket voor referentiecomponent voor BAG-administratie\" and standards filters combine (read 2026-09-26); https://www.softwarecatalogus.nl/pakketten: facets Referentiecomponent and Standaard (read 2026-09-26). Reached on: Alle pakketten > filters.", "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS referenceComponent, standard, applicationService, domain for schemas module and catalogService (:102); src/views/FacetedCatalogIndexView.vue:108 CnFacetSidebar narrows CnIndexPage; route GET /api/facets/{schema} called from src/services/facets.js", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/applications-in-reference-catalog: the catalog 'covers SAP applications, SAP AI agents, and SaaS applications' and is used to link your own fact sheets; market search by reference component and standard is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: search covers only the organisation's own records (src/Glpi/Search/SearchEngine.php); there is no market wide catalogue and no reference component or standard to filter on (grep -ril 'gemma\\|reference component' src/ returns nothing). The marketplace (src/Glpi/Marketplace/) lists GLPI plugins, not software for a task. The search engine is src/Glpi/Search/SearchEngine.php:101; the marketplace is src/Glpi/Marketplace/Controller.php:64." } }, @@ -1687,6 +1837,7 @@ "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/leveranciers: \"Leveranciers ... Zoek in leveranciers ... 354 resultaten gevonden\", filter \"Met ondertekend addendum\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle leveranciers.", + "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/provider-modeling-guidelines: 'SAP LeanIX has a catalog of 9000 providers' added automatically with IT components; browsing that catalog as a directory with filters is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Supplier.php:46 Supplier list under Management (src/Html.php:1298) with search, filters and a supplier type (install/mysql/glpi-empty.sql:7072 suppliertypes_id), but it holds only the suppliers this organisation entered, not all organisations offering to government. Reached on: Management > Suppliers (front/supplier.php). Driven on the lab at 11.0.9 (2026-09-26): created supplier \"Lab Leverancier BV\" through /front/supplier.form.php; it appears in the Suppliers list." } }, @@ -1714,6 +1865,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle gemeenten ... inclusief contactgegevens van gemeenten ... U kunt contact onderhouden met deze gemeenten\" (read 2026-09-26). Reached on: Inlogmenu > Alle gemeenten.", "stackiq": "Looked in src/components, src/views and lib/Controller for any contact or messaging between organisations sharing a module: none. Usage read rules (register :3137) hide other organisations' usages from municipalities.", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a vendor community exists (https://community.leanix.net/) but no in product way to find organisations using the same product is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: each GLPI instance holds one organisation's data (entities are internal subdivisions, src/Entity.php), so there is no view of other organisations using the same product; grep -rli 'peer' src/*.php matches only relation and network code such as src/CommonDBConnexity.php, no peer organisation feature." } }, @@ -1723,7 +1875,7 @@ "name": "Read a supplier's declared roadmap and planned releases for a product.", "origin": "competitor", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -1743,6 +1895,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle pakketversies en planningen ... gelijk zichtbaar de planning van de diverse pakketversies\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facet \"Status planning ... Filter op in ontwikkeling en zie de distributie planningsdata\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle pakketversies en planningen.", "stackiq": "register :7651 moduleVersion with status enum in development/in use/end of support/withdrawn and dateInDevelopment/dateInUse/dateEndSupport, read public; src/manifest.json:915 Moduleversies index + ModuleversieDetail", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-components-in-reference-catalog: 'The catalog provides standardized IT component data including lifecycle dates, vendor information ... You no longer need to track vendor lifecycle dates manually'. Vendor lifecycle and support dates, not planned releases; needs Technology Risk and Compliance (read 2026-09-26). Reached on: IT Component fact sheet linked to the reference catalog.", "glpi": "source read at 11.0.9: suppliers (install/mysql/glpi-empty.sql:7067 glpi_suppliers) carry address and contact fields only, and software versions (install/mysql/glpi-empty.sql:6900) carry no planned release date; grep -rli 'roadmap' src/*.php returns nothing." } }, @@ -1772,6 +1925,7 @@ "stackiq": "src/manifest.json:514 ModuleDetail bodyWidget ReviewsPanel; src/components/reviews/ReviewsPanel.vue:63 opens SubmitReviewModal; POST /api/reviews -> lib/Service/ReviewService.php:232 stamps author and forces status pending; rating 1..10 in software-review schema (:3961)", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no reviews are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no user review of an application with a rating is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no product review model; satisfaction surveys rate ticket handling only (src/CommonITILSatisfaction.php) and knowledge base comments (src/KnowbaseItem_Comment.php) carry no rating. Ticket satisfaction is src/CommonITILSatisfaction.php:43 and knowledge base comments src/KnowbaseItem_Comment.php:43." } }, @@ -1801,6 +1955,7 @@ "stackiq": "lib/Service/ReviewAggregateService.php:51 approved-only average + count; GET /api/reviews/aggregate (PublicPage) called from src/utils/reviewAggregate.js imported by src/components/reviews/ReviewsPanel.vue", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no ratings are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no review ratings exist in the docs to aggregate (read 2026-09-26)", "glpi": "source read at 11.0.9: with no product reviews there is no average rating; the only averages are ticket satisfaction statistics (src/CommonITILSatisfaction.php). Ticket satisfaction is src/CommonITILSatisfaction.php:43." } }, @@ -1828,6 +1983,7 @@ "stackiq": "register :6856 module.contactPerson -> contactPerson with x-relation-filter organization = @object.provider; catalogService and suite also carry contactPerson; src/manifest.json:500 ModuleDetail md-data include lists 'contactpersoon', 'beschrijvingKort', 'beschrijvingLang', which are not module properties (renamed to contactPerson/shortDescription/longDescription)", "topdesk": "unknown: supplier contacts are registered per supplier (\"Registering a supplier contact\"); contacts per product are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the docs name one contact per supplier (\"Bij elke leverancier is een contactpersoon opgevoerd\"); whether a product can carry its own is not stated; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30402 (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; subscriptions name internal users per fact sheet, but supplier contact persons per product are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: contacts link to a supplier as a whole, src/Contact_Supplier.php:39 (install/mysql/glpi-empty.sql:1429 glpi_contacts_suppliers), not to a product; per application there is only the free text contact field on an appliance (src/Appliance.php:214) and the user or technician in charge. Reached on: Management > Suppliers > Contacts tab; Appliance contact field." } }, @@ -1852,7 +2008,7 @@ "providerHow": "read-from-code", "note": "One organisation record is the supplier; products reference it and the detail page lists them. A contract reaches the supplier only through its service, not by its own field.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers. | Rated yes because Provider fact sheet.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/provider-modeling-guidelines: 'Providers are companies or entities that supply IT solutions, services, or technologies'; one provider fact sheet linked from IT components and contracts (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) (read 2026-09-26). Reached on: Inventory > Provider fact sheet.", "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier ... The Supplier Card has been created\" and \"Registering a supplier contact\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Create a new preliminary contract or preliminary supplier contract\" (read 2026-09-26). Reached on: Supporting Files > New > Supplier.", "stackiq": "register :2022 organization (one record, type Supplier); module.provider (:6921) and catalogService.provider (:3762) are $ref organization; catalogContract points at service (+usage), register :3252; OrganisatieDetail src/manifest.json:403 lists the supplier's services and applications", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"De verbinding met de leveranciersgegevens garandeert juiste schrijfwijzes van leveranciers- en pakketnamen en juiste versienummering\" (read 2026-09-26); https://www.softwarecatalogus.nl/leveranciers: one record per supplier with contact and addenda (read 2026-09-26). There are no contracts to point to it. Reached on: Alle leveranciers > supplier page.", @@ -1883,7 +2039,7 @@ "note": "Pick an organisation and its applications in use are grouped by derived lifecycle phase. The usage records themselves cannot be created or edited on any stackiq page (see life-planned-replacement).", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A1: \"Bij de oude versie kan de status gewijzigd worden in uit-te-faseren / uitgefaseerd\" (read 2026-09-26); https://www.softwarecatalogus.nl/voortgang-verbeteren: \"pakketversies hebben de status Gepland óf Uit te faseren\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: \"Vul onder Planning bij Status in gebruik in\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Planning Status.", - "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options: 'The lifecycle filter enables filtering of fact sheets by their lifecycle state: plan, phase-in, active, phase-out, and end-of-life' (read 2026-09-26). Reached on: Application fact sheet > Lifecycle.", "topdesk": "https://docs.topdesk.com/en/managing-disruptions-in-your-asset-management-process.html: built-in \"operational/impacted status for assets\" (read 2026-09-26); lifecycle phases need a self-defined drop-down field (https://docs.topdesk.com/en/creating-new-fields.html). No planned, in use, phase-out model ships. Reached on: Asset card > General widget.", "stackiq": "src/manifest.json LifecycleRoadmap /portfolio-roadmap custom page -> src/views/LifecycleRoadmapView.vue:55 groups the selected organisation's usages by phase, derived from usage dates by src/utils/lifecyclePhase.js derivePhase (:408); usage.status enum Acquisition/Planned/In production/To be phased out/Phased out in lib/Settings/softwarecatalogus_register.json", "glpi": "source read at 11.0.9: appliances carry a status, install/mysql/glpi-empty.sql:8950 glpi_appliances.states_id and src/Appliance.php:350 search option Status, whose values are an admin defined tree dropdown src/State.php:45 (install/mysql/glpi-empty.sql:7027 glpi_states), so phases such as planned, in use and being phased out are set up and filtered on. Reached on: Management > Appliances, Status field; Setup > Dropdowns > Statuses of items." @@ -1913,7 +2069,7 @@ "note": "Per organisation it shows which applications are phased out or replaced and when; it is a grouped list ordered by urgency rather than a timeline chart.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"de uit te faseren applicaties van die status worden voorzien inclusief datum. Zo ontstaat inzicht in het totale huidige- en doel-landschap in 1 overzicht\" (read 2026-09-26). Dates per status, no roadmap view described. Reached on: Mijn softwarecatalogus > Pakketten > Planning.", - "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/report-types: 'Roadmap Report Visualizes fact sheets on a timeline to show the evolution of the IT landscape'; https://help.sap.com/docs/leanix/ea/application-rationalization-create-roadmap (read 2026-09-26). Reached on: Reports > Roadmap Report.", "stackiq": "src/views/LifecycleRoadmapView.vue:28 organisation select, :55 phase groups, :96-110 phase-out date, planned replacement and link to the replacing module (:400 plannedReplacement, :423 plannedReplacementDate), ordered by nearest urgency (:428)", "topdesk": "unknown: no replacement roadmap is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "glpi": "source read at 11.0.9: replacements can be planned as projects linked to the appliance, src/Appliance.php:108 Item_Project tab (src/Item_Project.php:45) and src/Project.php:50 Project with Kanban; the Gantt view is the separate gantt plugin (src/Project.php:599 checks isActivated('gantt')). No per organisation application roadmap view exists. Reached on: Tools > Projects, Appliance > Projects tab." @@ -1940,7 +2096,7 @@ "providerHow": "read-from-code", "note": "Nothing finds applications in your landscape that fulfil the same reference component; the Reports card promises 'overlapping' software but the report does not compute it.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48861 'Business capability modeling' (2026-07-23): Maps applications to a business capability map for portfolio rationalisation. | Rated partial because rationalisation through capability map.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-rationalization: 'Application rationalization reduces costs, eliminates redundancies', using applications mapped to business capabilities; overlap is found per customer capability, not per reference component (read 2026-09-26). Reached on: Reports > Landscape Report by Business Capability.", "stackiq": "grep for overlap/redundant in lib and src finds only code comments and the Reports card description (src/manifest.json:1031 'Overlapping and ageing software'); lib/Service/PortfolioReportService.php computes TIME quadrants, EOL exposure, cloud share and cost, no grouping by reference component; the /modules facet counts modules per reference component across the whole catalogue, not your landscape", "topdesk": "unknown: no functional classification to detect overlap is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tile \"Referentiecomponenten met meerdere pakketten: Deze tegel signaleert dat er meer dan 1 pakket(versie) bij eenzelfde referentiecomponent in productie is\" (read 2026-09-26). Reached on: Dashboard tile Referentiecomponenten met meerdere pakketten.", @@ -1968,7 +2124,7 @@ "providerHow": "read-from-code", "note": "The report covers ageing software (EOL exposure) with TIME quadrants, cost and a CSV export, but not overlap, even though its card says 'overlapping and ageing'.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R). | docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-rationalization-evaluate-data: 'Leverage automated TIME classification, application portfolio and landscape reports ... to streamline application rationalization' (read 2026-09-26). Reached on: Use case Application Rationalization > reports.", "stackiq": "appinfo/routes.php:303 GET /api/portfolio-report -> lib/Controller/PortfolioReportController.php -> lib/Service/PortfolioReportService.php + PortfolioReportDerivation.php; UI src/views/organisaties/PortfolioReport.vue (TIME chart :112, quadrant summary :126 with EOL exposure/cloud/cost, rows :176, CSV export :50)", "topdesk": "unknown: no rationalisation report is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Referentiecomponenten met meerdere pakketten ... per referentiecomponent aan welke pakketversies daaraan gekoppeld zijn\" (read 2026-09-26). Overlap only, ageing not covered. Reached on: Dashboard tile.", @@ -1981,7 +2137,7 @@ "name": "Record which version of an application your organisation currently runs.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -2001,6 +2157,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json usage.moduleVersion ($ref moduleVersion); read by src/views/LifecycleRoadmapView.vue:397 for EOL state; ModuleversieDetail mv-related shows related usages; no usage create/edit page in src/manifest.json", "topdesk": "unknown: versions in use are only possible as a self-defined field; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Pakketversie - selecteer de versie die in gebruik is\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: version can be captured 'in the Release field of the application fact sheets', which the guide says rarely adds value; IT components carry release per catalog item (https://help.sap.com/docs/leanix/ea/it-components-in-reference-catalog) (read 2026-09-26). Reached on: Application or IT Component fact sheet > Release.", "glpi": "source read at 11.0.9: src/Item_SoftwareVersion.php:39 records which software version is installed on which item (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions with date_install at :1074), filled by hand or by native inventory, and listed on the Software Installations tab (src/Software.php:129). Reached on: Assets > Software > Installations tab." } }, @@ -2030,6 +2187,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications module-version-published (trigger created, recipients object-acl manage + group software-catalog-admins); no notification code in lib (no INotificationManager use)", "topdesk": "unknown: no supplier version feed is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/suggesties_overnemen: \"Wanneer een leverancier een pakketversie registreert kan deze een suggestie versturen naar de gemeenten en samenwerkingen die dit pakket afnemen\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C2: \"Via de notificatiefunctie krijgt u een signaal zodra het versienummer is toegevoegd\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Suggesties; Inbox.", + "sap-leanix": "unknown: https://updates.leanix.net/announcements/work-with-complete-technology-version-coverage-without-raising-manual-requests (2026-09-17) says the catalog is 'kept current as new versions are released', with version concurrency management planned for Q4; a notification to users about a new version is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: GLPI has no feed of supplier releases; software versions appear only when entered or inventoried (src/SoftwareVersion.php:42), and notification events for software are licence expiry only (src/NotificationTargetSoftwareLicense.php)." } }, @@ -2054,7 +2212,7 @@ "providerHow": "read-from-code", "note": "You could register a database as its own 'System software' module and feed its EOL, but nothing ties it to the applications that depend on it; SBOM components carry no lifecycle.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/obsolescence-risk-management: 'SAP LeanIX helps you gain an overview of your application landscape's obsolescence risk exposure' over the technology layer; lifecycle dates of IT components from the catalog in Technology Risk and Compliance (read 2026-09-26). Reached on: Use case Obsolescence Risk Management; IT Component lifecycle.", "stackiq": "lib/Settings/softwarecatalogus_register.json sbomComponent has name/version/purl/licenses/type/hashes/bomRef/vexCveIds, no lifecycle or EOL field; the EOL feed (lib/Service/EolSyncService.php:290) only stamps versions of modules with eolProductSlug; no relation from an application to the platform it runs on", "topdesk": "unknown: no technology lifecycle is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: technologies per version are recorded (\"Pakketversie is beschikbaar voor één of meerdere technologien; databases, OS, SAAS\") but no lifecycle for them is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", From 2540bded6e8a5a3f925191ce913e55fb80294fd3 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:25:17 +0200 Subject: [PATCH 07/12] feat(parity): 31 demand rows mined from tenders, feature requests, roadmaps and changelogs, stackiq rated from code --- openspec/parity/capabilities.json | 1320 +++++++++++++++++++++++++---- 1 file changed, 1144 insertions(+), 176 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index a7c5c91b..6a492a05 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -2225,7 +2225,7 @@ "name": "Link applications to the strategic goals they serve.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", @@ -2244,6 +2244,7 @@ "stackiq": "no goal/strategy schema among the 20 in lib/Settings/softwarecatalogus_register.json; grep for strateg/doel in src/manifest.json: none", "topdesk": "unknown: no strategic goals are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no strategic goals are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/objective-modeling-guidelines: 'Objectives link to business capabilities and initiatives so progress can be tracked over time'. Applications reach objectives through capabilities and initiatives; a direct application to objective relation is not described (read 2026-09-26). Reached on: Objective fact sheet.", "glpi": "source read at 11.0.9: grep -i 'strategic\\|goal\\|objective' over src/Appliance.php and src/Project.php returns nothing; no goal itemtype exists and the Appliance tabs (src/Appliance.php:98 onwards) link items, contracts, documents, tickets and projects only." } }, @@ -2273,6 +2274,7 @@ "stackiq": "openspec/features.overlay.json maintenance-and-supplier-roadmap status 'soon'; no maintenance schema in lib/Settings/softwarecatalogus_register.json and no page in src/manifest.json", "topdesk": "https://docs.topdesk.com/en/operations-management.html: \"In TOPdesk you can easily schedule operational activities in the user-friendly planner. If you wish to schedule a recurring activity, you can use a series\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: assets can be linked to \"Operational Activity\" cards (read 2026-09-26). Reached on: Modules > Operations Management > Planner.", "vng-softwarecatalogus": "unknown: no maintenance announcements are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; planned maintenance is documented only for LeanIX's own service status (https://help.sap.com/docs/leanix/ea/status-pages-and-status-emails), not for applications in the inventory (read 2026-09-26)", "glpi": "source read at 11.0.9: no maintenance window on an item ('Maintenance mode' in locales/glpi.pot:7534 is GLPI's own downtime switch); planned work is a change linked to the appliance, src/Appliance.php:107 Change_Item tab, with planned tasks carrying begin and end (install/mysql/glpi-empty.sql:792 glpi_changetasks, :799 begin, :800 end) shown in the planning. Reached on: Appliance > Changes tab; Assistance > Planning." } }, @@ -2282,7 +2284,7 @@ "name": "See each contract's status move from active to expiring to expired on its own.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "yes", @@ -2302,6 +2304,7 @@ "stackiq": "lib/Service/ContractStatusService.php:77 shouldExpire and :114 expirePastContracts set Active -> Expired when endDate < now; lib/BackgroundJob/ContractStatusJob.php:57 daily, registered in appinfo/info.xml:99", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Status: Configurable drop-down showing the contract's lifecycle status, e.g. draft, active ... Reminder date\" (read 2026-09-26); https://docs.topdesk.com/en/terminating-a-contract.html: \"The contract will terminate once the end date passes\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'The contract fact sheet uses lifecycle phases to represent the current state of a contract': Plan, Phase In, Contract Start Date (active), Contract Notice Period, Contract End Date (expired). Requires the contract extension (read 2026-09-26). Reached on: Contract fact sheet > Lifecycle.", "glpi": "source read at 11.0.9: contract status is a manual dropdown (install/mysql/glpi-empty.sql:1512 glpi_contracts.states_id); expiry is computed, src/Contract.php:654 virtual 'Expiration' column from begin date, duration and renewal, and src/Contract.php:1092 cronContract sends end and notice alerts, but the status itself never moves by itself. Reached on: Management > Contracts list, Expiration column." } }, @@ -2311,7 +2314,7 @@ "name": "Raise a renewal of a contract as a decision and see its outcome on the contract.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "yes", @@ -2332,6 +2335,7 @@ "stackiq": "src/components/contracts/ContractApprovalPanel.vue:183 canSubmitRenewal for status Expired; POST /api/contracts/{uuid}/approval/renewal -> ContractApprovalService.php:254 with decisionType contract-renewal; lib/EventListener/DecisionConcludedListener.php projects the outcome (approvalState, status Active) via DECISION_CONCLUDED_EVENTS registered in lib/AppInfo/Application.php:830", "topdesk": "https://docs.topdesk.com/en/extending-a-contract.html: \"Under Create , select Extend contract ... The contract is now a preliminary contract ... Click Validate Contract\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Sequence Number ... goes up by 1 each time the contract is extended ... so you can trace the contract's extension history\" (read 2026-09-26). Reached on: Contract card > Create > Extend contract.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Contract Renewal Status ... Backlog, In Review, In Progress, or Done', 'Contract Renewal Decision ... Renew, Terminate, or No Decision', 'Contract Renewal Comments' (read 2026-09-26). Reached on: Contract fact sheet > Contract Renewal.", "glpi": "source read at 11.0.9: src/Contract.php:60 to :62 renewal kinds never, tacit and express, with the renewal computation in the alert cron (src/Contract.php:1293); there is no renewal decision record or outcome, only the contract's renewal setting and an optional approval through a change. Reached on: Management > Contracts, Renewal field." } }, @@ -2341,7 +2345,7 @@ "name": "See the contracts behind an application from that application's page.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -2361,7 +2365,8 @@ "glpi": "source read at 11.0.9: src/Appliance.php:99 and src/Software.php:131 add the Contract_Item tab (src/Contract_Item.php:43, install/mysql/glpi-empty.sql:1536 glpi_contracts_items) listing every contract of the application. Reached on: Management > Appliances > Contracts tab. Driven on the lab at 11.0.9 (2026-09-26): after linking the contract, the appliance Contracts tab showed \"Lab contract, 2025-01-01, 12 months -> 2025-12-31\".", "stackiq": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: assets link to \"Service cards\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"On the Services tab, link the services that apply to this contract\" (read 2026-09-26). Contract to asset runs through the service. Reached on: Contract > Services tab > Service > Links > Assets.", - "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: relation 'Attached to Contract - Application Many-to-Many Links the contract to the applications it licenses or supports' (read 2026-09-26). Reached on: Application fact sheet > Contracts relation." } }, { @@ -2370,7 +2375,7 @@ "name": "See what the portfolio costs per year across its contracts.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -2387,7 +2392,7 @@ "featureConfidence": "high", "note": "The portfolio report sums annualised contract cost per organisation and TIME quadrant, and the license posture page per vendor. The Dashboard only counts contracts.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS cost.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Contract Licensing Cost ... Annual licensing fees', maintenance and support costs; https://help.sap.com/docs/leanix/ea/application-total-cost-of-ownership-extension: 'Gain clear visibility into costs on different levels' with reports and KPIs (read 2026-09-26). Reached on: Contract fact sheet + TCO extension reports.", "glpi": "source read at 11.0.9: contract costs have a period and a budget, install/mysql/glpi-empty.sql:1458 glpi_contractcosts with begin_date, end_date, cost and budgets_id; the contract list sums them in the 'Total cost' column (src/Contract.php:773) and a budget with a period shows spend per entity and type (src/Budget.php:537 showValuesByEntity). Reached on: Management > Contracts (Total cost column); Management > Budgets.", "stackiq": "lib/Service/PortfolioReportDerivation.php:163 annualisedCost (Monthly x12, Annually x1, One-off separate); lib/Service/PortfolioReportService.php:337 sumContractCost per quadrant; src/views/organisaties/PortfolioReport.vue:167 and :248 show annualised cost; src/utils/contractCost.js:111 totalAnnualisedCost used by src/views/LicensePostureView.vue per vendor", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Costs (Services) ... Total internal cost, based on the service levels linked\" (read 2026-09-26); https://docs.topdesk.com/en/obtain-insights-with-asset-type-report.html: \"do you need an overview of the total costs of new assets? Use the Asset Type Report\" (read 2026-09-26). Reached on: Contract card > Financial; Asset Type Report.", @@ -2400,7 +2405,7 @@ "name": "Record the licence model of an application, such as open source, per user or per organisation.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -2420,7 +2425,8 @@ "glpi": "source read at 11.0.9: each licence has a type, install/mysql/glpi-empty.sql:6775 glpi_softwarelicenses.softwarelicensetypes_id, an admin editable dropdown seeded with types such as OEM (install/empty_data.php:9294). Reached on: Management > Licenses (front/softwarelicense.php), Type field.", "stackiq": "register :6937 module.licentietype enum Closed source/Open source and module.licence (five open-source licence names); catalogContract.contractType enum SLA/Licence/Maintenance (:3341)", "topdesk": "unknown: licence cards hold number, code, purchase and expiration date; a licence model is only possible as a self-defined field; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/nieuws: \"is er de leverancier Open Source Pakketten aangemaakt. Onder deze leverancier staat nu een aantal veelgebruikte open source pakketten geregistreerd\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: Archi listed under supplier \"Open Source pakketten\", version \"Open source\" (read 2026-09-26). Other licence models are not recorded. Reached on: Alle pakketten > Leverancier Open Source pakketten." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/nieuws: \"is er de leverancier Open Source Pakketten aangemaakt. Onder deze leverancier staat nu een aantal veelgebruikte open source pakketten geregistreerd\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: Archi listed under supplier \"Open Source pakketten\", version \"Open source\" (read 2026-09-26). Other licence models are not recorded. Reached on: Alle pakketten > Leverancier Open Source pakketten.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Contract Pricing Type Single select Consumption Based, Yearly Commitment, or Perpetual Licenses'. No open source or per user licence model field on the application is documented (read 2026-09-26). Reached on: Contract fact sheet > Contract Pricing Type." } }, { @@ -2447,6 +2453,7 @@ "stackiq": "src/views/LicensePostureView.vue:11 open-source vs closed-source share weighted by in-production usage, :64 per-vendor rollup, per-organisation open-source-first report; derived in src/utils/licensePosture.js", "topdesk": "unknown: no portfolio licence posture is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; licence analysis exists only for SBOM components of self-built software (https://help.sap.com/docs/leanix/ea/sbom-explorer 'assess license risks by filtering for unpermitted licenses'), not a portfolio share of open source applications (read 2026-09-26)", "glpi": "source read at 11.0.9: licences can be listed and filtered by type in search (install/mysql/glpi-empty.sql:6775 softwarelicensetypes_id), but the dashboard's per type charts cover asset types and Software only (src/Glpi/Dashboard/Grid.php:1452), not licences, and no portfolio share view exists. Reached on: Management > Licenses, filtered by type." } }, @@ -2476,7 +2483,8 @@ "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:6774 glpi_softwarelicenses.number is the bought quantity; src/SoftwareLicense.php:158 computeValidityIndicator compares it with assigned items (Item_SoftwareLicense::countForLicense) and flags over use in red (src/SoftwareLicense.php:1030), with allow_overquota at install/mysql/glpi-empty.sql:6797. Reached on: Assets > Software > Licenses tab.", "stackiq": "grep for seat/licence count across lib/, src/ and the register finds no seat or quantity field on catalogContract (:3252), module or usage", "topdesk": "https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"add fields to fill the number of licences you have purchased and still have left ... the Relationship grid widget on the software cards will display details about the licences\" (read 2026-09-26). Reached on: Asset Management > software card > Relationship grid.", - "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for seats and licence counts, no hits; the contract fact sheet has cost fields but no licence quantity (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) (read 2026-09-26)" } }, { @@ -2503,6 +2511,7 @@ "stackiq": "No entitlement or consumption fields exist (see ctr-seat-count); no service computes a licence position in lib/Service/", "topdesk": "https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"Knowing which software tools are used by whom ... the legal implications of using a tool without being licensed\" (read 2026-09-26). Entitlement against linked users, no measured consumption. Reached on: Asset Management > licence cards.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no entitlement against consumption computation is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: entitlement is compared with licence assignments (src/SoftwareLicense.php:158 computeValidityIndicator), while measured installations are counted separately (src/Item_SoftwareVersion.php:39); core has no computed effective licence position report reconciling the two for an audit. Reached on: Assets > Software > Licenses and Installations tabs." } }, @@ -2530,7 +2539,8 @@ "glpi": "source read at 11.0.9: src/Budget.php:46 Budget with a period and value (install/mysql/glpi-empty.sql:306 begin_date, :307 end_date, :308 value); contract costs (install/mysql/glpi-empty.sql:1466 budgets_id) and financial records (src/Infocom.php:599 budgets_id check) are charged to it. Reached on: Management > Budgets. Driven on the lab at 11.0.9 (2026-09-26): /front/budget.php lists budgets with type, start date, end date and value.", "stackiq": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Budget holder: Cost-accounting owner of the contract\" and \"Applicable to ... Budget holder\" (read 2026-09-26). No budget with a period is described. Reached on: Contract card > Financial.", - "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; the contract has a 'Contract Cost Center' string (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) but charging costs against a budget with a period is not documented (read 2026-09-26)" } }, { @@ -2557,7 +2567,8 @@ "glpi": "source read at 11.0.9: the financial record of any item, licences included (src/SoftwareLicense.php:245 Infocom tab), carries depreciation type, duration and coefficient (install/mysql/glpi-empty.sql:3269 sink_time, :3270 sink_type, :3271 sink_coeff); src/Infocom.php:872 Linear and degressive types and src/Infocom.php:1085 linearAmortise compute the table. Reached on: Management > Licenses > Management tab.", "stackiq": "grep for depreciation/afschrijving finds nothing in lib/, src/ or the register", "topdesk": "unknown: depreciation is not mentioned (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for depreciation and amortisation, no hits (read 2026-09-26)" } }, { @@ -2566,7 +2577,7 @@ "name": "Keep the signed contract document with the contract record.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -2587,6 +2598,7 @@ "stackiq": "src/manifest.json:567 ContractDetail ct-files integration 'files' (Documents panel); catalogContract.documentReference text field (register :3252)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"You can view the contracts in a variety of formats, including PDF\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Archive Number (Free text) Reference to a physical or external archived copy of the contract document\" (read 2026-09-26). Reached on: Contract card.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets: 'Files : You can upload files up to 10 MB. Uploaded files are then visible in the Resources tab', which applies to the contract fact sheet of the contract extension (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) (read 2026-09-26). Reached on: Contract fact sheet > Resources tab.", "glpi": "source read at 11.0.9: src/Contract.php:126 adds the Documents tab (Document_Item) to every contract, storing the signed file in install/mysql/glpi-empty.sql:2585 glpi_documents. Reached on: Management > Contracts > Documents tab." } }, @@ -2596,7 +2608,7 @@ "name": "See SaaS subscriptions and their spend, including ones bought outside IT.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "yes", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -2611,7 +2623,7 @@ "providerHow": "read-from-code", "note": "The portfolio report shows each application in use with its cloud model and annualised cost, which lets you pick out SaaS spend. There is no SaaS subscription list and nothing discovers purchases made outside IT.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model. | docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/saas-discovery: discovery helps 'Eliminate shadow IT and business-managed IT' but 'The SaaS discovery feature in SAP LeanIX does not provide insight into cost, adoptions, contracts, and other SaaS specifics'. Spend only through manually kept contract costs (read 2026-09-26). Reached on: SaaS Discovery inbox; Contract fact sheet costs.", "stackiq": "usage.cloudDienstverleningsmodel (register :3050) plus contract cost; lib/Service/PortfolioReportService.php:302 per-usage annualised cost and cloud-transition share; src/views/organisaties/PortfolioReport.vue:166 cloudTransitionLabel per row", "topdesk": "unknown: no SaaS spend tracking is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", @@ -2642,6 +2654,7 @@ "vng-softwarecatalogus": "unknown: no vulnerability register is described; the docs do not state its absence either (the IBD-foto export only hands CPE identifiers to the IBD); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Hoe%20maak%20je%20een%20ICT-foto%20voor%20de%20IBD%3F (read 2026-09-26)", "stackiq": "src/views/KwetsbaarhedenView.vue:378 reportVulnerability opens the generic ObjectModal for 'vulnerability'; register.json:1619 vulnerability schema with cveCode (pattern CVE-yyyy-n, :1679) and cvssScore 0-10", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no vulnerability record with CVE code and score exists, vulnerabilities are handled by searching SBOM components (https://help.sap.com/docs/leanix/ea/searching-for-sbom-library-components-by-package-url 'after a CVE alert') (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'cve\\|vulnerab\\|cvss' over src/ templates/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74 (a PHP version warning) and a session comment at src/Session.php:1085; no vulnerability itemtype exists." } }, @@ -2669,6 +2682,7 @@ "stackiq": "register.json:1701 vulnerability.modules links to module (applications), not moduleVersion; version level only via read-time SBOM match (src/utils/sbomVulnerabilityMatch.js, sbomComponent.vexCveIds register.json:8024) on the ModuleversieDetail Components tab", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a PURL search finds services using a given library version, but linking a vulnerability record to affected versions is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no vulnerability model (see src/Glpi/System/Requirement/PhpSupportedVersion.php:74 as the only 'vulnerabilities' hit), so nothing links to software versions (install/mysql/glpi-empty.sql:6900)." } }, @@ -2678,7 +2692,7 @@ "name": "Import a software bill of materials in CycloneDX or SPDX for a version.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -2696,6 +2710,7 @@ "stackiq": "src/components/sbom/SbomComponentsPanel.vue:53-90 upload control (.json) -> POST /api/moduleversies/{uuid}/sbom (appinfo/routes.php:92) -> lib/Controller/SbomController.php:129 importSbom -> lib/Service/SbomParserService.php:77 parse (CycloneDX JSON) and :127 parseSpdx (SPDX 2.x JSON)", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/uploading-sboms-from-fact-sheets: 'select a CycloneDX or SPDX file in JSON or XML format' on a microservice fact sheet; also through the Self-Built Software Discovery API. Technology Risk and Compliance product (read 2026-09-26). Reached on: Microservice fact sheet > SBOM > Upload SBOM.", "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; inventory import (src/Glpi/Inventory/) takes glpi-agent JSON only. Inventory import is src/Glpi/Inventory/Inventory.php:106." } }, @@ -2705,7 +2720,7 @@ "name": "Match the catalogue automatically against a public CVE feed.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "no", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -2723,6 +2738,7 @@ "stackiq": "src/utils/sbomVulnerabilityMatch.js header: 'no HTTP request to an external advisory feed is ever made'; lib/Service/EolSyncService.php syncs endoflife.date support dates, not CVEs", "topdesk": "unknown: no CVE matching is described; the roadmap card https://tip.topdesk.com/c/186-automated-asset-scanning-tool (under consideration) mentions monitoring \"security vulnerabilities\" as a future idea; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue does not match CVEs itself; its \"IBD-foto\" export lists supplier, product and CPE so the IBD can do so; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Hoe%20maak%20je%20een%20ICT-foto%20voor%20de%20IBD%3F (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/api-updates-sbom-async-processing: 'Switching to asynchronous processing will allow us to add additional post-processing mechanisms in the future, such as vulnerability checks. Though there's no established timeline for these enhancements' (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'cve' over src/ templates/ finds no feed matching (only src/Glpi/System/Requirement/PhpSupportedVersion.php:74 text); no pluginsGLPI cve repository exists (git ls-remote https://github.com/pluginsGLPI/cve: repository not found)." } }, @@ -2747,7 +2763,7 @@ "providerHow": "read-from-code", "note": "Only individual vulnerabilities get a severity band. No application gets a combined score from its vulnerabilities and support status.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks | Rated partial because technology risk.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/technology-obsolescence-risk-statuses-and-views-in-reports: 'Learn how risk statuses are determined for IT components and applications', e.g. 'Unaddressed Risk ... when the internal end-of-life date or vendor-provided end-of-support date is in the past'. Based on support status, not vulnerabilities (read 2026-09-26). Reached on: Technology Risk and Compliance > obsolescence risk status on applications.", "stackiq": "src/utils/vulnerabilitySeverity.js derives a severity band per vulnerability from CVSS; no per-application risk score in lib/ or src/ (searched risk)", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -2778,6 +2794,7 @@ "stackiq": "register.json:1619 vulnerability has no fixed-in version field; src/utils/vulnerabilityExposure.js computeExposure carries the deployed moduleVersion per usage but nothing compares it to a fix", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no per vulnerability patch status is documented, and vulnerability checks are a future item (https://help.sap.com/docs/leanix/ea/api-updates-sbom-async-processing) (read 2026-09-26)", "glpi": "source read at 11.0.9: installed versions are known (src/Item_SoftwareVersion.php:39) but no vulnerability or fixed in version exists to compare against (grep -rli 'cve' src/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74)." } }, @@ -2805,6 +2822,7 @@ "stackiq": "src/manifest.json:969 Kwetsbaarheden custom page -> src/views/KwetsbaarhedenView.vue table with severity tabs; row click openDetail (:417) opens the record in the generic ObjectModal", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no vulnerability list exists, only the SBOM explorer of components (https://help.sap.com/docs/leanix/ea/sbom-explorer) (read 2026-09-26)", "glpi": "source read at 11.0.9: no vulnerability itemtype and no such entry in any menu (src/Html.php:1295 to :1334 list Management, Tools, Administration and Setup types)." } }, @@ -2814,7 +2832,7 @@ "name": "Register an organisation, such as a municipality, supplier or cooperation, with its type.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "yes", @@ -2832,6 +2850,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Als leverancier kunt u zich aanmelden door de volgende gegevens te sturen naar softwarecatalogus@vng.nl\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C4 roles for gemeente and samenwerking accounts (read 2026-09-26); organisation types gemeente, samenwerking, leverancier. Reached on: Registration via VNG helpdesk.", "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization (Add form); register :2022 organization.type enum Municipality/Supplier/Collaboration/Community, required contactsUid + type", "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier ... In the Tasks block, specify whether first or second line incidents, or services or changes, may be assigned to the supplier\" (read 2026-09-26); branches are registered as Branch cards (https://docs.topdesk.com/en/drop-down-lists-settings.html \"the Person and Branch cards\"). Reached on: Supporting Files > New > Supplier / Branch.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines: organization subtypes 'Business Unit, Customer, Region, Legal Entity, Team' for 'your hierarchical business architecture'; suppliers are separate provider fact sheets. No municipality or cooperation types for outside organisations (read 2026-09-26). Reached on: Inventory > Organization fact sheet.", "glpi": "source read at 11.0.9: external organisations are suppliers with a type dropdown (src/Supplier.php:46, install/mysql/glpi-empty.sql:7072 suppliertypes_id); the organisation's own units are entities (src/Entity.php:58). There is no generic organisation register covering municipalities or cooperations. Reached on: Management > Suppliers; Administration > Entities." } }, @@ -2861,6 +2880,7 @@ "stackiq": "src/views/settings/StackiqSettings.vue:92 ModerationQueue (type organisation) -> src/utils/adminApi.js -> GET /api/moderation/pending, POST /api/moderation/{uuid}/approve|reject; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; lib/Service/ModerationService.php:230 approval sets registrationStatus active and stamps publicationDate (:173)", "topdesk": "unknown: no review queue for organisations is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Om te kunnen deelnemen aan de softwarecatalogus controleren wij of de leverancier voldoet aan de richtlijnen van de softwarecatalogus\" (read 2026-09-26). Manual review by e-mail, no queue described.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; organisations do not self register, so no moderation queue is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers are created by staff (src/Supplier.php:75 sets is_active on a new record) and there is no self registration or approval queue for organisations; grep -i 'moderat' over src/Supplier.php src/Entity.php returns nothing." } }, @@ -2888,6 +2908,7 @@ "stackiq": "register organization.status enum Draft/Active/Inactive is visible:false (:2022); src/manifest.json:403 OrganisatieDetail overrides status editable:false; src/modals/object/ChangeOrganisatieStatusDialog.vue:211 is never opened (no setDialog('changeOrganisatieStatus') in src); src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters status 'concept' and :129 writes 'actief', neither an enum value", "topdesk": "unknown: cards can be archived; concept, active, inactive states for organisations are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: suppliers carry a \"heeft geldig convenant\" flag and may be removed, but no concept, active, inactive status is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/leveranciers (read 2026-09-26)", + "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines does not describe concept, active and inactive states for organizations; only archiving of fact sheets in general (https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets) (read 2026-09-26)", "glpi": "source read at 11.0.9: a supplier is active or inactive, src/Supplier.php:365 is_active search option (install/mysql/glpi-empty.sql:7087 glpi_suppliers.is_active); there is no concept state. Reached on: Management > Suppliers, Active field." } }, @@ -2897,7 +2918,7 @@ "name": "Keep the contact persons of an organisation with their roles.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -2915,6 +2936,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30402: \"Bij elke leverancier is een contactpersoon opgevoerd. Deze persoon is verantwoordelijk voor de inhoud\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E4 contact details of municipalities (read 2026-09-26). One contact, no roles. Reached on: Supplier page header.", "stackiq": "src/manifest.json:418 OrganisatieDetail org-contactpersonen object-list (role, roles) with rowRoute ContactpersoonDetail; register :1788 contactPerson (contactsUid, role, organization, roles enum of catalogue roles)", "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier contact ... The Supplier card where the contact person is active must be registered first\" (read 2026-09-26). Roles per contact are not described. Reached on: Supporting Files > New > Supplier Contact.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/subscription-roles: users subscribe to any fact sheet, including organization fact sheets, with roles 'such as application owner, project manager'. Contacts must be workspace users; external contact persons are not documented (read 2026-09-26). Reached on: Organization fact sheet > Subscriptions.", "glpi": "source read at 11.0.9: contacts (src/Contact.php:45, install/mysql/glpi-empty.sql:1390 glpi_contacts) carry a contact type and a title (:1402 contacttypes_id, :1405 usertitles_id) and are linked to suppliers through src/Contact_Supplier.php:39. Reached on: Management > Contacts; Supplier > Contacts tab." } }, @@ -2924,7 +2946,7 @@ "name": "Give a colleague access to your organisation's part of the catalogue.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -2943,6 +2965,7 @@ "stackiq": "src/components/organisations/OrganisationSwitcher.vue:48 'Manage members' (isBeheerder) opens src/modals/GrantOrganisationAccessModal.vue; POST /api/organisations/{uuid}/members -> lib/Controller/OrganisationMembersController.php:108 authorizeBeheerder then OpenRegister joinOrganisation (:123)", "topdesk": "https://docs.topdesk.com/en/step-2, operator-import-with-a-linked-person.html: \"Create new operators via import\" (read 2026-09-26); permissions via permission groups (https://docs.topdesk.com/en/automated-actions.html). Administrators create accounts; no invitation flow. Reached on: Supporting Files > Operators.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/gebruikersbeheer: \"Beheerders van gemeenten, samenwerkingen of leveranciers kunnen voor collega's een account aanmaken ... ontvangt deze nieuwe gebruiker een e-mail met daarin de inloginstructies\" (read 2026-09-26). Reached on: Menu > Gebruikersbeheer > Gebruiker toevoegen.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/users-overview: 'Invited users who haven't yet accepted the invitation request. You can reinvite a user'; https://help.sap.com/docs/leanix/ea/virtual-workspaces-configuration: 'Set up virtual workspaces to manage access for custom user groups' (read 2026-09-26). Reached on: Administration > Users > Invite.", "glpi": "source read at 11.0.9: an administrator gives a user a profile on an entity, install/mysql/glpi-empty.sql:5917 glpi_profiles_users with profiles_id and entities_id, set on the user's Authorizations tab or automatically by authorisation rules (src/RuleRight.php:297 profiles_id action, :273 entities_id action). There is no emailed invitation link. Reached on: Administration > Users > Authorizations tab." } }, @@ -2952,7 +2975,7 @@ "name": "Act for more than one organisation with one account and switch between them.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -2971,6 +2994,7 @@ "stackiq": "src/components/organisations/OrganisationSwitcher.vue:197 POST /apps/openregister/api/organisations/{uuid}/set-active; mounted in src/App.vue:55", "topdesk": "unknown: one account acting for several organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4: \"Een account kan ook beide rollen gekregen hebben. In het inlogmenu kan dan van rol gewisseld worden ... Gecombineerde rollen kunnen alleen door VNG Realisatie aangemaakt worden\" (read 2026-09-26). Reached on: Inlogmenu > rol wisselen.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/manage-workspace-access: 'Provide users with access to exactly their relevant workspaces ... direct URL, base URLs or the workspace chooser to access available workspaces' (read 2026-09-26). Reached on: Workspace chooser.", "glpi": "source read at 11.0.9: one user can hold several profile and entity pairs (install/mysql/glpi-empty.sql:5917 glpi_profiles_users) and switch between them in the session, src/Session.php:461 changeActiveEntities and src/Session.php:592 changeProfile. Reached on: user menu, entity and profile selector." } }, @@ -2998,6 +3022,7 @@ "stackiq": "src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail; POST /api/organisaties/{uuid}/merge -> lib/Controller/MergeController.php:142 isAdmin; lib/Service/MergeOrganisatieService.php:111 re-points usage.consumer/participants, contactPerson.organization, connection.provider and @self.organisation of catalogContract/compliancy; module.provider and catalogService.provider are not re-pointed", "topdesk": "unknown: merging organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for merge of fact sheets or organizations, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: entities cannot be merged, src/Entity.php:202 forbids the dropdown merge action for Entity; records can be moved into another entity with src/Transfer.php:50 Transfer (massive action add_transfer_list, src/MassiveAction.php:598), keeping or cleaning linked items per transfer options. Reached on: Administration > Entities; list Actions > Add to transfer list." } }, @@ -3025,7 +3050,8 @@ "glpi": "source read at 11.0.9: with no merge (src/Entity.php:202 forbids merge for Entity) there is nothing to preview; the transfer (src/Transfer.php:50) runs directly without a what would change report.", "stackiq": "src/components/organisations/OrganisationMergePanel.vue:324 organisatieStore.dryRunMerge shows dryRunCounts before execute; POST /api/organisaties/{uuid}/merge/dry-run -> lib/Service/MergeOrganisatieService.php:160 dryRun", "topdesk": "unknown: merging organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no merge, so no merge preview is documented (read 2026-09-26)" } }, { @@ -3034,7 +3060,7 @@ "name": "Map catalogue roles such as administrator, buyer and civil servant onto user groups.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3052,7 +3078,8 @@ "glpi": "source read at 11.0.9: roles are profiles with per right settings (src/Profile.php:55), mapped onto groups and directory attributes by authorisation rules, src/RuleRight.php:236 group criterion and src/RuleRight.php:297 profile action. Reached on: Administration > Profiles; Administration > Rules > Authorizations assignment rules.", "stackiq": "src/views/settings/StackiqSettings.vue:80 UserGroupsConfiguration -> GET/POST /api/user-groups/config (src/store/modules/settings.js:830); lib/Controller/SettingsController.php:3379; lib/Service/Stackiq/GroupHandler.php:103 generic groups, :167 fixed role groups (aanbod-beheerder, gebruik-beheerder, ...), group choice by organisation type (:471)", "topdesk": "https://docs.topdesk.com/en/automated-actions.html: \"Assign these permissions via Supporting Files > Permission Groups > [Permission Group]\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: permission tables per module (read 2026-09-26). Reached on: Supporting Files > Permission Groups.", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4 roles gemeentebeheerder, raadpleger, samenwerkingsbeheerder; \"Er is géén rol voor het raadplegen van een samenwerking\" (read 2026-09-26). Fixed roles, no mapping onto groups. Reached on: Gebruikersbeheer." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4 roles gemeentebeheerder, raadpleger, samenwerkingsbeheerder; \"Er is géén rol voor het raadplegen van een samenwerking\" (read 2026-09-26). Fixed roles, no mapping onto groups. Reached on: Gebruikersbeheer.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/sso-attribute-overview: 'The role to be assigned to the user. Required values: ADMIN, MEMBER, or VIEWER' and 'customer_roles ... The custom role to be assigned', mapped from identity provider groups (read 2026-09-26). Reached on: Administration > Users; SSO role attributes." } }, { @@ -3061,7 +3088,7 @@ "name": "Sign in with the organisation's own identity provider.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3079,7 +3106,8 @@ "glpi": "source read at 11.0.9: src/Auth.php:106 EXTERNAL (web server provided identity, for example a SAML or OIDC module in front of GLPI), src/Auth.php:107 CAS with phpCAS::client at src/Auth.php:557, and src/Auth.php:108 X509 certificates, next to LDAP at src/Auth.php:105. Reached on: Setup > Authentication > Other authentication methods.", "topdesk": "https://docs.topdesk.com/en/automatic-login-methods.html: \"Single Sign-on via SAML requirements TOPdesk uses OpenSAML 3 for authentication. You can connect all common IdP solutions which support SAML 2.0\" (read 2026-09-26). Reached on: Settings > Login Settings.", "stackiq": "No OIDC/SAML code in lib/ or src/; stackiq creates local Nextcloud users with a password (lib/Service/Stackiq/ContactPersonHandler.php:292)", - "vng-softwarecatalogus": "unknown: login is by username and password (\"Vul uw GEMMA Softwarecatalogus-gebruikersnaam in\"); no identity provider sign-in is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/user/login (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: login is by username and password (\"Vul uw GEMMA Softwarecatalogus-gebruikersnaam in\"); no identity provider sign-in is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/user/login (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/managing-users: 'SSO : You manage access through your identity provider (IdP) system. Users sign in through your IdP'; guides for Entra ID, Okta, OneLogin (read 2026-09-26). Reached on: Administration > Single Sign-On." } }, { @@ -3088,7 +3116,7 @@ "name": "Keep users and groups in step with a directory such as LDAP.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3106,7 +3134,8 @@ "glpi": "source read at 11.0.9: src/AuthLDAP.php:59 LDAP directories with user import and group import (src/AuthLDAP.php:2816 ldapImportGroup), and the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users (alias ldap:sync at :80). Reached on: Administration > Users > LDAP directory link; Setup > Authentication > LDAP directories. Driven on the lab at 11.0.9 (2026-09-26): /front/ldap.php offers \"Bulk import users from a LDAP directory\" and \"Synchronizing already imported users\".", "stackiq": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/", "topdesk": "https://docs.topdesk.com/en/manual-login-with-ldap.html: \"This is also required if you want to import persons from your AD via Supporting files import\" (read 2026-09-26); https://tip.topdesk.com/c/242-support-scim-when-importing-users-from-entra-id-to-topdesk: roadmap card in column \"Launched\", \"Support SCIM when importing users from Entra ID to TOPdesk\" (read 2026-09-26). Reached on: Settings > Import settings > Supporting Files imports.", - "vng-softwarecatalogus": "unknown: no directory sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no directory sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/scim-provisioning: 'SCIM facilitates the transfer of user information from a source system, such as an external identity provider (IdP), to a target system, such as SAP LeanIX'; setup guides for Entra ID and Okta (read 2026-09-26). Reached on: Administration > SCIM provisioning." } }, { @@ -3115,7 +3144,7 @@ "name": "Change your own password and see your own account details.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3133,6 +3162,7 @@ "stackiq": "src/components/ContactpersonenList.vue:115 'Change Password' opens src/dialogs/ChangePasswordDialog.vue -> POST /api/contactpersonen/change-password -> lib/Controller/ContactpersonenController.php:718, self-reset allowed at :753; GET /api/me (:1578) used only by src/App.vue and OrganisationSwitcher", "topdesk": "https://docs.topdesk.com/en/editing-your-personal-profile.html: \"Click on Personal Profile . In the General and Private section, you can edit your personal information. In the Change password section, you can change your password\" (read 2026-09-26). Reached on: Profile picture > Personal Profile.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/wachtwoord-vergeten: \"Op het inlogscherm ... staat een link om een nieuw wachtwoord aan te vragen\" (read 2026-09-26). Reset by mail; viewing own account details is not described. Reached on: Inloggen > Vraag een nieuw wachtwoord aan.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/user-profile: 'Manage your user profile settings. Change or reset your password if needed' on the My Settings profile page (read 2026-09-26). Reached on: User menu > My Settings.", "glpi": "source read at 11.0.9: front/preference.php renders the user's own form through src/User.php:3105 showMyForm (template pages/admin/user/user.html.twig), whose preference variant shows a 'Change password' button to front/updatepassword.php at templates/pages/admin/user/user.html.twig:277 to :279; the new password form is templates/password_form.html.twig:79." } }, @@ -3142,7 +3172,7 @@ "name": "Send registration, activation and account mails from templates an administrator can edit.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -3160,7 +3190,8 @@ "glpi": "source read at 11.0.9: src/NotificationTargetUser.php:44 user events passwordexpires, passwordforget and passwordinit; their text lives in admin editable templates, src/NotificationTemplate.php:47 and translations src/NotificationTemplateTranslation.php:42, seeded at install/empty_data.php:3212 (passwordinit) and :5640. Reached on: Setup > Notifications > Notification templates.", "stackiq": "lib/Service/SymfonyEmailService.php:466 registration, :553 activation, :641 user creation mails from templates; src/views/settings/sections/EmailConfiguration.vue:902 saveTemplate is a stub that logs 'not yet implemented in the backend' and still shows success; backend POST /api/email/templates/{templateName} (lib/Controller/SettingsController.php:2194) has no caller in src/; lib/Settings/connections.json email adapter reports the 'null' transport as simulated", "topdesk": "unknown: email designs are editable for automated actions, but account activation mails are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: new users receive a login mail, but administrator-editable templates are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: new users receive a login mail, but administrator-editable templates are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/users-overview: users are invited 'individually or in bulk' with a 'Send Invitation Email' option; editing the text of account mails is not documented (read 2026-09-26). Reached on: Administration > Users > Invite." } }, { @@ -3189,6 +3220,7 @@ "stackiq": "lib/Controller/PublicationController.php:87 publish/depublish (routes.php:208-209, PUT/DELETE /api/publication/{objectType}/{uuid}) with an IDOR guard; lib/Service/PublicationService.php:51 publishable types catalogService, module, connection, organization. No src/ caller of /api/publication (only a comment in src/utils/openDataProjection.js). The publish buttons in src/modals/object/ViewObject.vue:4854 are unreachable: Modals.vue renders ViewObject only for modal 'viewOrganisatie'/'viewContactpersoon', which nothing sets. Workaround: publicationDate/depublicationDate are visible, editable fields on module/catalogService/organization/connection (lib/Settings/softwarecatalogus_register.json:6777 schema).", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: supplier data is public by default and municipal data is never public; publishing or withdrawing one entry is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; publishing a single entry as open data is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'open data\\|opendata' over src/ locales/glpi.pot returns nothing; items have no publish state, the closest is is_helpdesk_visible (install/mysql/glpi-empty.sql:8956 on glpi_appliances), which only shows the item to helpdesk users of the same instance." } }, @@ -3218,6 +3250,7 @@ "stackiq": "src/utils/openDataProjection.js:36 STRIPPED_FIELDS (PII projection) is imported by nothing in src/ and has no PHP counterpart (grep 'projection' in lib/ finds none). Usage schema read rule lib/Settings/softwarecatalogus_register.json:3150 has no public group; lib/Controller/GebruikController.php:102 returns an empty result to anonymous callers.", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Beschikbare%20downloads: public CSV downloads of packages, versions and compliance (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: \"Ingevuld door (28) Aantal gemeenten met een versie van het pakket in productie\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C5 contact details \"alleen als contactgegevens voor andere ingelogde gebruikers\" (read 2026-09-26). Reached on: Beschikbare downloads; package page.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no open data publication is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no open data publication exists (grep -rli 'open data' src/ returns nothing); anonymisation settings cover ticket actors only (install/mysql/glpi-empty.sql:2824 anonymize_support_agents on entities)." } }, @@ -4112,226 +4145,1131 @@ "vng-softwarecatalogus": "unknown: only \"De kaart wordt dagelijks bijgewerkt\" is stated; no organisation or contact sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/17042 (read 2026-09-26)", "glpi": "source read at 11.0.9: automatic actions are scheduled and show their last run, src/CronTask.php:59 with install/mysql/glpi-empty.sql:1610 glpi_crontasks.lastrun, but LDAP user and group synchronisation is not one of them (grep -i ldap over the cron seed in install/empty_data.php:438 finds none); it is the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users, which must be scheduled by the system cron. Organisation (supplier) records have no sync at all. Reached on: Setup > Automatic actions; CLI bin/console ldap:sync. Driven on the lab at 11.0.9 (2026-09-26): /front/crontask.php lists automatic actions with run mode, frequency and last run." } - } - ], - "pending": [ + }, { - "id": "land-usage-record", - "area": "landscape", - "name": "Record that your organisation uses a module, as a usage separate from the product itself.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "partial", - "bluedolphin": "partial", - "glpi": "partial", - "topdesk": "unknown", - "stackiq": "partial", + "id": "arch-ggm-link", + "area": "architecture", + "name": "Relate applications to the entities of the Gemeentelijk Gegevensmodel they hold data for.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/398728", + "stackiq": "no", "built": { - "state": "built", - "evidence": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", + "state": "none", + "evidence": "lib/Settings/softwarecatalogus_register.json:5038 ggm-guid (and ggm-naam, ggm-definitie) are properties of the element schema (register.json:4130), filled by the AMEF import (lib/Repair/RenameDutchCatalogColumns.php:25-27); the module schema (register.json:6777) has no property that points to a GGM entity, and the only element page, Standaarden, is filtered to gemmaType standaard (src/manifest.json:708)", "owner": "ConductionNL/stackiq" }, - "reachedOn": "API only: /api/aangeboden-gebruik/*, /api/gebruik and OpenRegister objects API; read-only on Portfolio roadmap /portfolio-roadmap", + "reachedOn": "nothing reaches it", "provider": "stackiq", "providerHow": "read-from-code", - "feature": "offering-and-usage-listings", - "featureConfidence": "high", - "note": "The usage schema models this separation properly, but no stackiq page creates or edits a usage: the ObjectModal accepts type 'usage' (src/modals/Modals.vue:38) yet nothing opens it. Usages are only read by the roadmap, compliance matrix and vulnerability views.", + "feature": "gemma-alignment", + "featureConfidence": "medium", + "note": "Helmond's architecture repository tender (REQ3, REQ61) asks to relate the repository to the GGM. GGM metadata survives an ArchiMate import on architecture elements, but no field or page links an application to a GGM entity.", + "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: municipality adds the supplier's package and version to its own landscape (\"om het pakket toe te voegen aan je omgeving\") (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E1 \"Leveranciers onderhouden de gegevens van hun producten ... Gemeenten en Samenwerkingen onderhouden de gegevens van het eigen applicatieportfolio\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten.", - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", - "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", - "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", - "topdesk": "unknown: one organisation per environment; a separate usage record is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "glpi": "source read at 11.0.9: use is recorded as installations separate from the software product, src/Item_SoftwareVersion.php:39 (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions) per device, and licence assignments per item or user; there is no usage record of a module by an organisation as such. Reached on: Assets > Software > Installations tab." + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Does the external VNG Softwarecatalogus frontend create usage (gebruik) records through /api/aangeboden-gebruik or the OpenRegister objects API, and is that frontend part of what stackiq ships?" + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" }, { - "id": "land-migrate-legacy", - "area": "landscape", - "name": "Bring over what was registered in the previous catalogue, so nobody types it again.", - "origin": "competitor", + "id": "arch-views-office", + "area": "architecture", + "name": "Put architecture views into Word or PowerPoint documents straight from the tool.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/398728", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "appinfo/routes.php:97-98 the only view exports are ArchiMate exchange files (POST /api/archimate/export, GET /api/archimate/export/organization/{organizationUuid}); no image, docx or pptx export of a view anywhere in lib/ or src/ (the docx/pptx strings in src/modals/object/MergeObject.vue are file-type labels)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "archimate-import-and-export", + "featureConfidence": "medium", + "note": "Helmond REQ19 asks for architecture views embedded in office documents. stackiq renders no view at all (see arch-gemma-views) and exports only ArchiMate files.", "vng-softwarecatalogus": "unknown", + "evidence": { + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "partial", - "topdesk": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "arch-data-model", + "area": "architecture", + "name": "Model data entities and their relations, as an entity relationship or UML diagram, next to the applications.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/398728", "stackiq": "no", "built": { "state": "none", - "evidence": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", + "evidence": "src/manifest.json has no page for the element, relation or view schema other than Standaarden (src/manifest.json:708, filtered to standards); no diagram editor under src/views or src/components (same finding as arch-modelling)", "owner": "ConductionNL/stackiq" }, "reachedOn": "nothing reaches it", "provider": "stackiq", "providerHow": "read-from-code", - "note": "There is no importer for the previous VNG Softwarecatalogus's registrations. The repair steps only rename stackiq's own earlier data, and the ArchiMate import brings in the GEMMA model, not organisations' entries.", + "featureConfidence": "high", + "note": "Helmond REQ54 asks for entity relationship or UML data models. stackiq holds imported ArchiMate elements but models nothing itself.", + "vng-softwarecatalogus": "unknown", "evidence": { - "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", - "topdesk": "unknown: no import from the VNG Softwarecatalogus is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: this is the previous catalogue itself; no import of an earlier registration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "glpi": "source read at 11.0.9: data from earlier GLPI versions is carried over by src/Update.php:172 doUpdates with the chain in install/migrations/ (update_0.85.x_to_0.90.0.php up to the 11.0 steps); data from another catalogue needs the separate datainjection plugin (pluginsGLPI/datainjection tag 2.15.11, inc/backendcsv.class.php). Reached on: web installer update; plugin Data injection." + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Is the data from the previous VNG Softwarecatalogus meant to be brought over by a one-off migration outside this repo (for example an OpenRegister register import of an export file)?" + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" }, { - "id": "conn-register-connection", - "area": "connections", - "name": "Register a connection between two applications, with its direction and the standard it uses.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", - "sap-leanix": "yes", - "bluedolphin": "partial", - "glpi": "partial", - "topdesk": "partial", - "stackiq": "partial", + "id": "org-access-review", + "area": "organisations", + "name": "Review periodically whether every user still needs their access, and withdraw what is no longer needed.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/398728", + "stackiq": "no", "built": { - "state": "built", - "evidence": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", + "state": "none", + "evidence": "lib/Service/ContactpersoonService.php:889 returns a user's lastLogin and src/components/ContactpersonenList.vue:482 stores it, but nothing renders it; no review, recertification or expiry of access in lib/ or src/ (grep recertif, accessReview)", "owner": "ConductionNL/stackiq" }, - "reachedOn": "API only: OpenRegister objects API; no stackiq page", + "reachedOn": "nothing reaches it", "provider": "stackiq", "providerHow": "read-from-code", - "feature": "software-landscape-register", "featureConfidence": "medium", - "note": "The connection model with direction and standard is complete, and the demo data ships six, but no stackiq page creates or edits one.", + "note": "Helmond REQ78 asks administrators to check periodically that every user still needs access. stackiq fetches the last login of each contact's account and never shows it.", + "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Selecteer vervolgens de betreffende pakketversie. De richting van het berichtenverkeer ... Selecteer vervolgens de betreffende standaard en versie\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > toevoegen.", - "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", - "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", - "topdesk": "https://docs.topdesk.com/en/hierarchy-of-relationships.html: \"When assets are linked with a link type , one of the assets often supplies a certain feature to another asset. The supplying asset therefore is the parent asset\" (read 2026-09-26). Direction via parent and child; no standard per relation. Reached on: Asset card > Relationships widget.", - "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations stores a directed link from a source item to an impacted item with a name, added via src/Impact.php:1161 'Add relation'; there is no field for the standard or protocol used. Reached on: Appliance > Impact analysis tab, Add relation." + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Does the external VNG Softwarecatalogus frontend register koppelingen through the OpenRegister objects API, and does it count as part of stackiq?" - }, - { - "id": "conn-usage-of-connection", - "area": "connections", - "name": "Record that your organisation actually runs a given connection, not only that it exists.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "no", - "topdesk": "unknown", - "stackiq": "partial", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "comp-processing-register", + "area": "compliance", + "name": "Link each application to its entry in the organisation's register of processing activities.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/398728", + "stackiq": "yes", "built": { "state": "built", - "evidence": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", + "evidence": "lib/Settings/softwarecatalogus_register.json:7287 module.verwerkingsregisterRef (a URL or identifier; the register itself is not modelled); shown in the ModuleDetail data widget, src/manifest.json:500 include list", "owner": "ConductionNL/stackiq" }, - "reachedOn": "API only", + "reachedOn": "ModuleDetail /modules/:id Application data widget (reached from OrganisatieDetail, see land-detail-page)", "provider": "stackiq", "providerHow": "read-from-code", - "feature": "offering-and-usage-listings", - "featureConfidence": "medium", - "note": "The model records which connections a usage runs, but neither usages nor connections have a page.", + "feature": "standards-compliance", + "featureConfidence": "high", + "note": "Helmond REQ4 wants the processing register kept apart from the repository but linked. stackiq stores and shows a reference per application; it does not hold the register.", + "vng-softwarecatalogus": "unknown", "evidence": { - "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", - "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Geef bij status in productie of gepland aan\"; connections are registered in the organisation's own landscape (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen.", - "glpi": "source read at 11.0.9: an impact relation (install/mysql/glpi-empty.sql:1247) is a single fact in one instance; there is no separate usage record saying the organisation runs it, and grep -n 'usage' src/ImpactRelation.php returns nothing." + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Does the external VNG Softwarecatalogus frontend let an organisation record the connections it runs, through /api/koppelingen-gebruik or the objects API?" - }, - { - "id": "conn-shared-with-others", - "area": "connections", - "name": "See which connections you run together with other organisations.", - "origin": "own-code", - "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "no", - "topdesk": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "mkt-tender-product-info", + "area": "market", + "name": "As a supplier, keep your product information public in the catalogue so a buyer's tender can point to it instead of asking for separate documentation.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/418890", "stackiq": "partial", "built": { "state": "built", - "evidence": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", + "evidence": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public once publicationDate has passed (same rule as share-public-browse); no stackiq route or page serves it anonymously, the public surface is OpenRegister's objects API and the external VNG frontend", "owner": "ConductionNL/stackiq" }, - "reachedOn": "API only: /api/aangeboden-gebruik/deelnemers", + "reachedOn": "external frontend, not in this repo", "provider": "stackiq", "providerHow": "read-from-code", - "feature": "shared-usage-on-gemma-views", + "feature": "offering-and-usage-listings", "featureConfidence": "medium", - "note": "Shared usage (with the connections it carries) is answerable through the API, but no stackiq page shows it.", + "note": "Standard municipal tender text (Noordwijk 418890, Reimerswaal 417169, FUMO 415897, HLT Samen 383984): a supplier inside the GEMMA scope can make its product information transparent through the Softwarecatalogus. stackiq publishes the data; the page a buyer opens lives in the external frontend.", + "vng-softwarecatalogus": "unknown", "evidence": { - "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", - "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A10: \"Een Samenwerking geeft aan welke gemeenten gebruik maken van een betreffende koppeling. Die gemeentenamen worden getoond\" (read 2026-09-26). Reached on: Alle koppelingen.", - "glpi": "source read at 11.0.9: relations live inside one instance (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and entities are subdivisions of one organisation (src/Entity.php:58); no cross organisation sharing of connections exists (grep -rli 'federat' src/ returns nothing)." + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Does the external VNG Softwarecatalogus frontend show shared connections from /api/aangeboden-gebruik/deelnemers?" - }, - { - "id": "arch-refcomp-mapping", - "area": "architecture", - "name": "Place an application on the GEMMA reference components it fulfils.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "no", - "topdesk": "unknown", - "stackiq": "partial", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "life-value-assessment", + "area": "lifecycle", + "name": "Score each application on business value, cost and risk to decide where to invest.", + "origin": "tender", + "originUrl": "https://www.tenderned.nl/aankondigingen/overzicht/398728", + "stackiq": "no", "built": { - "state": "built", - "evidence": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", + "state": "none", + "evidence": "lib/Settings/softwarecatalogus_register.json:3092 usage.timeClassification holds only the TIME verdict and its rationale; no business value, technical fit or risk score property on module or usage, and PortfolioReport (src/manifest.json:1040) plots the TIME quadrant only", "owner": "ConductionNL/stackiq" }, - "reachedOn": "Modules /modules (FacetedCatalogIndexView) filters by reference component (read only); no stackiq page sets the mapping: module form hides it (hideOnForm), usage has no page", + "reachedOn": "nothing reaches it", "provider": "stackiq", "providerHow": "read-from-code", - "feature": "gemma-alignment", - "featureConfidence": "high", - "note": "The mapping is stored and can be filtered on, but no stackiq screen writes it: the module field is hideOnForm and the usage schema has no index or edit page; writes come through ArchiMate import, the OpenRegister objects API or the external VNG frontend.", + "feature": "portfolio-reporting", + "featureConfidence": "medium", + "note": "Helmond REQ41 asks for analysis of application use, cost, risk and value. stackiq records a TIME classification (life-time-classification) without the scores that would justify it.", + "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Referentiecomponenten aangegeven door leverancier ... Toegevoegde referentiecomponenten\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", - "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", - "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "glpi": "source read at 11.0.9: grep -rli 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; the only classification of an appliance is its type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Does the Modules page's CnIndexPage create/edit dialog in nextcloud-vue 2.55.1 render module.referenceComponents (hideOnForm:true, items.$ref element in the AMEF register) as a working multiselect of reference components? nextcloud-vue's fieldsFromSchema (src/utils/schema.js:529) does not check hideOnForm." - }, - { - "id": "arch-gemma-views", - "area": "architecture", - "name": "Open a GEMMA architecture view with your own applications drawn inside it.", - "origin": "own-code", - "vng-softwarecatalogus": "yes", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "no", - "topdesk": "unknown", - "stackiq": "partial", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "comp-security-officer-signoff", + "area": "compliance", + "name": "Have the security officer review and sign off the organisation's list of applications in use.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/136", + "stackiq": "no", "built": { - "state": "built", - "evidence": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", + "state": "none", + "evidence": "no approval of an organisation's application list: ContractApprovalService (lib/Service/ContractApprovalService.php) covers contracts only, and no schema or page records a sign-off on the landscape (grep fiat, sign-off, goedkeur in lib/ and src/)", "owner": "ConductionNL/stackiq" }, - "reachedOn": "API only: GET /api/views (src/store/modules/view.js:89 defines a store but nothing imports useViewStore); the drawn view is only visible in Archi after 'Organization Export' on admin settings section ArchiMate Import/Export", + "reachedOn": "nothing reaches it", "provider": "stackiq", "providerHow": "read-from-code", - "feature": "gemma-alignment", "featureConfidence": "medium", - "note": "No stackiq page renders a GEMMA view. The enriched view data is served for an external frontend, and the org export draws applications into view copies that open in Archi.", + "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart.", - "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", - "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "glpi": "source read at 11.0.9: grep -rli 'gemma\\|archimate' over src/ templates/ locales/glpi.pot returns nothing; the only diagram is the impact graph (src/Impact.php:252 displayGraphView)." + "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #136 'Als CISO wil ik ons gemeentelijk pakketoverzicht kunnen controleren en vervolgens fiatteren'; no approval step for the landscape appears in the incumbent manuals (https://www.softwarecatalogus.nl/node/19703). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, - "pendingQuestion": "Does the external VNG Softwarecatalogus frontend render /api/views/{id} with include_gebruik, and is that frontend in scope for stackiq's column?" + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" }, { - "id": "arch-shared-overlay", - "area": "architecture", - "name": "On a GEMMA view, see the applications you share with partners, drawn apart from your own.", - "origin": "own-code", + "id": "comp-processing-register-generate", + "area": "compliance", + "name": "Generate a register of processing activities from the applications the organisation uses.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/82", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "lib/Settings/softwarecatalogus_register.json:7287 module.verwerkingsregisterRef only stores a reference, and its description says the register itself is not modelled; no export or report builds one", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "unknown", + "evidence": { + "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #82 'Als gebruik-raadpleger wil ik een register van verwerkingen kunnen genereren'; the incumbent exports only package, connection and IBD-foto files (https://www.softwarecatalogus.nl/Beschikbare%20downloads). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "ctr-collective-agreements", + "area": "contracts", + "name": "Find suppliers and products covered by collective agreements made for all municipalities.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/50", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "'Addendum' exists only as a glossary object (lib/Settings/softwarecatalogus_register.json:613, lexicon entry in the objects seed at :27); no schema records which supplier signed which collective agreement", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "partial", + "evidence": { + "vng-softwarecatalogus": "Open PvE wens #50 (search) and #48 (register collective agreements incl. AVG and BIO terms); the incumbent lists signed addenda per supplier with a filter (https://www.softwarecatalogus.nl/addenda), which covers part of it. (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "share-compliance-documents", + "area": "sharing", + "name": "Share documents such as DPIAs, processing agreements and pentest reports with other organisations.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/41", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "compliance records carry bewijsReferentie and a Documentation files panel (src/manifest.json:885 KompliantieDetail), and module.dpiaDocumentRef (lib/Settings/softwarecatalogus_register.json:7280) links a DPIA; these are published per record under the register read rules, but nothing shares a processing agreement or pentest report between organisations as such", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "KompliantieDetail /komplianties/:id Evidence documents; ModuleDetail DPIA document field", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "unknown", + "evidence": { + "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #41 'relevante documenten zoals DPIA's, verwerkersovereenkomsten en pentesten kunnen delen zodat andere gemeenten hier eenvoudig gebruik van kunnen maken'; the incumbent only holds supplier test reports (https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "sec-baseline-classification", + "area": "security", + "name": "Classify each application with a baseline security level for availability, integrity and confidentiality.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/46", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json:7225 module.bbnLevel (BBN1 to BBN3), shown in the ModuleDetail data widget (src/manifest.json:500) and filterable on Modules (src/manifest.json:608); one level per application, not per organisation and not split into availability, integrity and confidentiality", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ModuleDetail /modules/:id and Modules /modules BBN filter", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "unknown", + "evidence": { + "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #46 'Als CISO wil ik de pakketten in mijn pakketoverzicht van een BBN classificatie voorzien'; BBN exists only as a GEMMA view per reference component per the news page (https://www.softwarecatalogus.nl/nieuws). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "mkt-side-by-side-compare", + "area": "market", + "name": "Select several products and compare their properties and usage side by side in one table.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/31", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no compare view in src/views or src/manifest.json pages; the Modules page lists and filters only (src/views/FacetedCatalogIndexView.vue:108)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "unknown", + "evidence": { + "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #31 'meerdere pakketten kunnen selecteren en deze in een overzichtelijke tabel naast elkaar vergelijken'; the incumbent offers filtered lists only (https://www.softwarecatalogus.nl/node/13683). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "org-act-as-user", + "area": "organisations", + "name": "Let a functional administrator view the catalogue as another account to reproduce what that user sees.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/104", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no impersonation in lib/ or src/ (grep impersonat); stackiq relies on Nextcloud users", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "unknown", + "evidence": { + "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #104 'Als functioneel beheerder wil ik me kunnen voordoen als een ander account'; not in the incumbent FAQ (https://www.softwarecatalogus.nl/node/16564). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "comp-common-ground-fit", + "area": "compliance", + "name": "Declare how a product fits the Common Ground goals and principles.", + "origin": "featureRequest", + "originUrl": "https://github.com/VNG-Realisatie/Softwarecatalogus/issues/147", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "'Common Ground' is only a glossary object (lib/Settings/softwarecatalogus_register.json:543); the module schema has no Common Ground property", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "partial", + "evidence": { + "vng-softwarecatalogus": "Open PvE wens #147; the incumbent shows whether a supplier signed the Groeipact Common Ground addendum (https://www.softwarecatalogus.nl/leveranciers), a supplier-level signal, not per product. (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "land-version-carry-connections", + "area": "landscape", + "name": "Carry an application's connections over automatically when a new version replaces the old one.", + "origin": "featureRequest", + "originUrl": "https://www.softwarecatalogus.nl/gebruikersonderzoek%202021", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "moduleVersion (lib/Settings/softwarecatalogus_register.json) is created on the Moduleversies index form; no copy of a version with its connections and no carry-over logic in lib/Service/ModuleVersionService.php", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "vng-softwarecatalogus": "partial", + "evidence": { + "vng-softwarecatalogus": "2021 user survey suggestion 'Koppelingen automatisch bijwerken bij een nieuwe versie van pakket'; release 4.1 added a manual copy of a version including its connections (https://www.softwarecatalogus.nl/node/16564, FAQ A1). (read 2026-09-26)", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "comp-retention-cleanup", + "area": "compliance", + "name": "Remove attached files and mails automatically a set time after a record is closed, to meet retention rules.", + "origin": "changelog", + "originUrl": "https://tip.topdesk.com/c/152-more-control-over-card-file-removal", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no retention or file clean-up job in lib/BackgroundJob or lib/Service for stackiq records (grep retention, bewaartermijn)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "yes", + "evidence": { + "topdesk": "Card 'More control over card & file removal' in Launched (updated 2026-02-09); docs https://docs.topdesk.com/en/file-maintenance.html: 'you can set how many days after closing or archiving a card its uploaded files and linked emails should be removed'. (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" + }, + { + "id": "land-dependent-fields", + "area": "landscape", + "name": "Make the options of one field depend on another, such as model depending on brand.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/87-field-dependencies-brand-type-model-", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "register properties are independent enums; no dependent option lists in lib/Settings/softwarecatalogus_register.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "no", + "evidence": { + "topdesk": "Card 'Field Dependencies (brand/type/model)' in Under consideration: 'User can set up dependencies between fields'; not in the field docs (https://docs.topdesk.com/en/editing-fields.html). (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" + }, + { + "id": "land-change-entry-type", + "area": "landscape", + "name": "Change the type of an existing entry without recreating it.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/89-changing-the-type-of-an-asset", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "each entry lives in one schema (module, catalogService, suite) and no action moves an object to another schema", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "no", + "evidence": { + "topdesk": "Card 'Changing the type of an asset' in Under consideration: 'User can change the type of an exiting asset'. (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" + }, + { + "id": "ins-ai-action-audit", + "area": "insight", + "name": "See which actions an AI assistant took on the data, when and on which records.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/252-audit-logging-for-topdesk-mcp-server", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "stackiq has no AI or MCP integration of its own (see share-ai-assistant); the History tab (widget type audit, src/manifest.json:436) shows every change per object but does not single out actions an assistant took", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "no", + "evidence": { + "topdesk": "Card 'Audit Logging for TOPdesk - MCP Server' in Building: 'you should be able to see exactly what that AI did, which actions it took, when, and on what data'. (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" + }, + { + "id": "sec-multi-factor-sign-in", + "area": "security", + "name": "Require a second factor when users sign in.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/162-support-multi-factor-authentication-mfa-", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no sign-in code in stackiq; stackiq creates local Nextcloud users (lib/Service/Stackiq/ContactPersonHandler.php:292) and second factors come from Nextcloud two-factor apps platform-wide, as with org-sso", + "owner": "nextcloud/server" + }, + "reachedOn": "nothing reaches it in stackiq; Nextcloud two-factor apps apply platform-wide", + "provider": "nextcloud", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "partial", + "evidence": { + "topdesk": "Card 'Support Multi-Factor Authentication (MFA)' in Under consideration; today MFA only comes from the identity provider behind SAML SSO (https://docs.topdesk.com/en/topdesk-mobile.html: 'We test the store application with the Microsoft two-step authentication (2FA) for the SSO'). (read 2026-09-26)", + "glpi": "source read at 11.0.9: CHANGELOG.md:277 11.0.0 added Two-Factor Authentication via TOTP; implemented by src/Glpi/Security/TOTPManager.php:60, with the disable action on the user's settings page (front/preference.php).", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26. Also shipped in GLPI 11.0.0 (https://github.com/glpi-project/glpi/releases/tag/11.0.0).", + "glpi": "yes", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown" + }, + { + "id": "sec-password-policy", + "area": "security", + "name": "Enforce a strong password policy for local accounts.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/163-enforce-strong-passwords", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "stackiq sets passwords through lib/Controller/ContactpersonenController.php:718 change-password and relies on Nextcloud for rules; a strength policy is the Nextcloud password_policy app, platform-wide", + "owner": "nextcloud/server" + }, + "reachedOn": "nothing reaches it in stackiq; the Nextcloud password policy applies platform-wide", + "provider": "nextcloud", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "no", + "evidence": { + "topdesk": "Card 'Enforce strong passwords' in Under consideration: 'By setting rules for things like minimum length, numbers, symbols, or uppercase letters, weak passwords are blocked'. (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" + }, + { + "id": "ops-change-risk-score", + "area": "operations", + "name": "Get a risk score for a planned change based on past outcomes and dependencies.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/241-ai-risk-prediction-", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "stackiq runs no changes and scores no risk (see ops-change)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "no", + "evidence": { + "topdesk": "Card 'AI - Risk & prediction' in Under consideration: 'Change risk prediction helps change managers assess how risky a planned change is before it's approved'. (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" + }, + { + "id": "conn-auto-populate-dependencies", + "area": "connections", + "name": "Fill in an application's dependencies automatically from what is already known about connected items, instead of drawing each link by hand.", + "origin": "featureRequest", + "originUrl": "https://github.com/glpi-project/roadmap/discussions/336", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "connections are registered one at a time or arrive through the ArchiMate import (lib/Service/ArchiMateImportService.php); nothing derives dependencies from known relations", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "no", + "evidence": { + "glpi": "source read at 11.0.9: open request #336 (2026-05-22) asks to add all connected assets to the impact analysis at once; in core every impact relation is added by hand through src/Impact.php:1161 'Add relation' into install/mysql/glpi-empty.sql:1247 glpi_impactrelations, and the inventory (src/Glpi/Inventory/Inventory.php:106) does not create impact relations.", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (featureRequest) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + }, + { + "id": "ctr-linked-contracts", + "area": "contracts", + "name": "Link contracts to each other, such as a call-off under a framework agreement or a sub-contract that depends on a main contract.", + "origin": "featureRequest", + "originUrl": "https://github.com/glpi-project/roadmap/discussions/182", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "catalogContract.contract (lib/Settings/softwarecatalogus_register.json:3282) is a plain uuid to shillinq's governing Contract, not shown on ContractDetail (src/manifest.json:563 data fields) and not a link between catalogue contracts", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "no", + "evidence": { + "glpi": "source read at 11.0.9: open request #182 (2026-03-27) states contracts cannot be linked in GLPI 11; install/mysql/glpi-empty.sql:1536 glpi_contracts_items links a contract to items, and Contract is not among the linkable item types there, with no parent contract column in install/mysql/glpi-empty.sql:1483 glpi_contracts.", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (featureRequest) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + }, + { + "id": "ctr-contract-owner", + "area": "contracts", + "name": "Name the person or team responsible for a contract, so expiry warnings go to them.", + "origin": "featureRequest", + "originUrl": "https://github.com/glpi-project/roadmap/discussions/290", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "catalogContract.contactPersonUser (lib/Settings/softwarecatalogus_register.json:3398) names the responsible person on the user side, shown on ContractDetail (src/manifest.json:563); expiry warnings do not reach them because the only expiry notification never matches (see ctr-expiry-alert)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "ContractDetail /contracten/:id contract details", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "no", + "evidence": { + "glpi": "source read at 11.0.9: open request #290 (2026-05-07) asks for contract assignees as notification recipients; install/mysql/glpi-empty.sql:1483 glpi_contracts has no users_id or groups_id column, so contract alerts (src/NotificationTargetContract.php:47) go to configured global recipients only.", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (featureRequest) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + }, + { + "id": "life-dates-follow-status", + "area": "lifecycle", + "name": "Have in-use and retirement dates filled in automatically when an entry's lifecycle status changes.", + "origin": "featureRequest", + "originUrl": "https://github.com/glpi-project/roadmap/discussions/457", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "the lifecycle phase is derived from usage dates (src/utils/lifecyclePhase.js derivePhase) and contract status from the end date (lib/Service/ContractStatusService.php:77), the reverse direction; no date is filled when a status changes", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "partial", + "evidence": { + "glpi": "source read at 11.0.9: request #457 (2026-07-27, open) asks to tie dates to status; core already lets an entity fill financial dates when an item enters a chosen status, install/mysql/glpi-empty.sql:2800 autofill_use_date and :2822 autofill_decommission_date on glpi_entities, applied by src/Infocom.php:505 autofillDates, but only for the financial record's dates.", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (featureRequest) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + }, + { + "id": "org-assigned-only-rights", + "area": "organisations", + "name": "Let the people responsible for an application see and edit only the entries assigned to them.", + "origin": "changelog", + "originUrl": "https://github.com/glpi-project/glpi/releases/tag/11.0.0", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "read and write rules in the register scope by organisation ({match: {_organisation: $organisation}}, see org-data-segregation), not by the person or group assigned to an entry", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "yes", + "evidence": { + "glpi": "source read at 11.0.9: CHANGELOG.md:281 11.0.0 added 'View assigned' and 'Update assigned' rights; src/Glpi/Features/AssignableItem.php:68 grants read when the user or group is assigned and src/Glpi/Features/AssignableItem.php:79 checks UPDATE_ASSIGNED; Appliance uses this trait (src/Appliance.php:46 implements AssignableItemInterface).", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + }, + { + "id": "ops-own-house-style", + "area": "operations", + "name": "Apply the organisation's own colours and house style to the interface.", + "origin": "changelog", + "originUrl": "https://github.com/glpi-project/glpi/releases/tag/11.0.0", + "stackiq": "yes", + "built": { + "state": "built", + "evidence": "stackiq styles use Nextcloud's theming variables (src/views/KwetsbaarhedenView.vue:478 var(--color-primary-element)), so the colours and logo an admin sets in Nextcloud theming apply to stackiq pages", + "owner": "nextcloud/server" + }, + "reachedOn": "every stackiq page, through Nextcloud theming", + "provider": "nextcloud", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "yes", + "evidence": { + "glpi": "source read at 11.0.9: CHANGELOG.md:276 11.0.0 added custom palette and theme support; src/Glpi/UI/ThemeManager.php:103 getCustomThemesDirectory and :112 getCustomThemes load admin supplied themes, offered in src/Config.php:1612 getPalettes.", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + }, + { + "id": "land-copy-entry", + "area": "landscape", + "name": "Start a new application entry by copying an existing one with its links.", + "origin": "changelog", + "originUrl": "https://github.com/glpi-project/glpi/releases/tag/11.0.0", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "library CnIndexPage mass copy on stackiq index pages: @conduction/nextcloud-vue v2.55.1 src/components/CnIndexPage/CnIndexPage.vue:215 CnMassCopyDialog, showMassCopy default true at :1611 (package.json:45 pins ^2.55.1); whether relations are copied along was not traced", + "owner": "ConductionNL/nextcloud-vue" + }, + "reachedOn": "index pages such as Module versions /moduleversies: select rows, Copy", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "glpi": "yes", + "evidence": { + "glpi": "source read at 11.0.9: CHANGELOG.md:285 and :286 11.0.0 added cloning of templates and creating a template from an existing item; appliances are clonable (src/Appliance.php:49 use Clonable) together with their items, contracts, documents and financial record (src/Appliance.php:62 getCloneRelations).", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from glpi (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "topdesk": "unknown" + } + ], + "pending": [ + { + "id": "land-usage-record", + "area": "landscape", + "name": "Record that your organisation uses a module, as a usage separate from the product itself.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "partial", + "bluedolphin": "partial", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: /api/aangeboden-gebruik/*, /api/gebruik and OpenRegister objects API; read-only on Portfolio roadmap /portfolio-roadmap", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "high", + "note": "The usage schema models this separation properly, but no stackiq page creates or edits a usage: the ObjectModal accepts type 'usage' (src/modals/Modals.vue:38) yet nothing opens it. Usages are only read by the roadmap, compliance matrix and vulnerability views.", + "evidence": { + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: municipality adds the supplier's package and version to its own landscape (\"om het pakket toe te voegen aan je omgeving\") (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E1 \"Leveranciers onderhouden de gegevens van hun producten ... Gemeenten en Samenwerkingen onderhouden de gegevens van het eigen applicatieportfolio\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten.", + "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", + "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", + "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", + "topdesk": "unknown: one organisation per environment; a separate usage record is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: use is recorded as installations separate from the software product, src/Item_SoftwareVersion.php:39 (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions) per device, and licence assignments per item or user; there is no usage record of a module by an organisation as such. Reached on: Assets > Software > Installations tab." + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend create usage (gebruik) records through /api/aangeboden-gebruik or the OpenRegister objects API, and is that frontend part of what stackiq ships?" + }, + { + "id": "land-migrate-legacy", + "area": "landscape", + "name": "Bring over what was registered in the previous catalogue, so nobody types it again.", + "origin": "competitor", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "partial", + "topdesk": "unknown", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "note": "There is no importer for the previous VNG Softwarecatalogus's registrations. The repair steps only rename stackiq's own earlier data, and the ArchiMate import brings in the GEMMA model, not organisations' entries.", + "evidence": { + "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", + "topdesk": "unknown: no import from the VNG Softwarecatalogus is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "unknown: this is the previous catalogue itself; no import of an earlier registration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: data from earlier GLPI versions is carried over by src/Update.php:172 doUpdates with the chain in install/migrations/ (update_0.85.x_to_0.90.0.php up to the 11.0 steps); data from another catalogue needs the separate datainjection plugin (pluginsGLPI/datainjection tag 2.15.11, inc/backendcsv.class.php). Reached on: web installer update; plugin Data injection." + }, + "pendingQuestion": "Is the data from the previous VNG Softwarecatalogus meant to be brought over by a one-off migration outside this repo (for example an OpenRegister register import of an export file)?" + }, + { + "id": "conn-register-connection", + "area": "connections", + "name": "Register a connection between two applications, with its direction and the standard it uses.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "yes", + "bluedolphin": "partial", + "glpi": "partial", + "topdesk": "partial", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: OpenRegister objects API; no stackiq page", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "software-landscape-register", + "featureConfidence": "medium", + "note": "The connection model with direction and standard is complete, and the demo data ships six, but no stackiq page creates or edits one.", + "evidence": { + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Selecteer vervolgens de betreffende pakketversie. De richting van het berichtenverkeer ... Selecteer vervolgens de betreffende standaard en versie\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > toevoegen.", + "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", + "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", + "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", + "topdesk": "https://docs.topdesk.com/en/hierarchy-of-relationships.html: \"When assets are linked with a link type , one of the assets often supplies a certain feature to another asset. The supplying asset therefore is the parent asset\" (read 2026-09-26). Direction via parent and child; no standard per relation. Reached on: Asset card > Relationships widget.", + "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations stores a directed link from a source item to an impacted item with a name, added via src/Impact.php:1161 'Add relation'; there is no field for the standard or protocol used. Reached on: Appliance > Impact analysis tab, Add relation." + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend register koppelingen through the OpenRegister objects API, and does it count as part of stackiq?" + }, + { + "id": "conn-usage-of-connection", + "area": "connections", + "name": "Record that your organisation actually runs a given connection, not only that it exists.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "no", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "offering-and-usage-listings", + "featureConfidence": "medium", + "note": "The model records which connections a usage runs, but neither usages nor connections have a page.", + "evidence": { + "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", + "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Geef bij status in productie of gepland aan\"; connections are registered in the organisation's own landscape (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen.", + "glpi": "source read at 11.0.9: an impact relation (install/mysql/glpi-empty.sql:1247) is a single fact in one instance; there is no separate usage record saying the organisation runs it, and grep -n 'usage' src/ImpactRelation.php returns nothing." + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend let an organisation record the connections it runs, through /api/koppelingen-gebruik or the objects API?" + }, + { + "id": "conn-shared-with-others", + "area": "connections", + "name": "See which connections you run together with other organisations.", + "origin": "own-code", + "vng-softwarecatalogus": "partial", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "no", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: /api/aangeboden-gebruik/deelnemers", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "shared-usage-on-gemma-views", + "featureConfidence": "medium", + "note": "Shared usage (with the connections it carries) is answerable through the API, but no stackiq page shows it.", + "evidence": { + "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", + "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A10: \"Een Samenwerking geeft aan welke gemeenten gebruik maken van een betreffende koppeling. Die gemeentenamen worden getoond\" (read 2026-09-26). Reached on: Alle koppelingen.", + "glpi": "source read at 11.0.9: relations live inside one instance (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and entities are subdivisions of one organisation (src/Entity.php:58); no cross organisation sharing of connections exists (grep -rli 'federat' src/ returns nothing)." + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend show shared connections from /api/aangeboden-gebruik/deelnemers?" + }, + { + "id": "arch-refcomp-mapping", + "area": "architecture", + "name": "Place an application on the GEMMA reference components it fulfils.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "no", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "Modules /modules (FacetedCatalogIndexView) filters by reference component (read only); no stackiq page sets the mapping: module form hides it (hideOnForm), usage has no page", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "high", + "note": "The mapping is stored and can be filtered on, but no stackiq screen writes it: the module field is hideOnForm and the usage schema has no index or edit page; writes come through ArchiMate import, the OpenRegister objects API or the external VNG frontend.", + "evidence": { + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Referentiecomponenten aangegeven door leverancier ... Toegevoegde referentiecomponenten\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", + "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; the only classification of an appliance is its type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." + }, + "pendingQuestion": "Does the Modules page's CnIndexPage create/edit dialog in nextcloud-vue 2.55.1 render module.referenceComponents (hideOnForm:true, items.$ref element in the AMEF register) as a working multiselect of reference components? nextcloud-vue's fieldsFromSchema (src/utils/schema.js:529) does not check hideOnForm." + }, + { + "id": "arch-gemma-views", + "area": "architecture", + "name": "Open a GEMMA architecture view with your own applications drawn inside it.", + "origin": "own-code", + "vng-softwarecatalogus": "yes", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "no", + "topdesk": "unknown", + "stackiq": "partial", + "built": { + "state": "built", + "evidence": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "API only: GET /api/views (src/store/modules/view.js:89 defines a store but nothing imports useViewStore); the drawn view is only visible in Archi after 'Organization Export' on admin settings section ArchiMate Import/Export", + "provider": "stackiq", + "providerHow": "read-from-code", + "feature": "gemma-alignment", + "featureConfidence": "medium", + "note": "No stackiq page renders a GEMMA view. The enriched view data is served for an external frontend, and the org export draws applications into view copies that open in Archi.", + "evidence": { + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart.", + "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", + "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'gemma\\|archimate' over src/ templates/ locales/glpi.pot returns nothing; the only diagram is the impact graph (src/Impact.php:252 displayGraphView)." + }, + "pendingQuestion": "Does the external VNG Softwarecatalogus frontend render /api/views/{id} with include_gebruik, and is that frontend in scope for stackiq's column?" + }, + { + "id": "arch-shared-overlay", + "area": "architecture", + "name": "On a GEMMA view, see the applications you share with partners, drawn apart from your own.", + "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -5276,6 +6214,36 @@ "vng-softwarecatalogus": "unknown: no plugins are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" }, "pendingQuestion": "Is a store registry configured on a default install, and are any stackiq configuration sets published to it?" + }, + { + "id": "org-field-level-permissions", + "area": "organisations", + "name": "Restrict who can see or edit specific fields of an entry.", + "origin": "roadmap", + "originUrl": "https://tip.topdesk.com/c/88-permission-for-fields-and-or-widgets", + "stackiq": "partial", + "built": { + "state": "specified", + "evidence": "property-level authorization is declared in the register, for example lib/Settings/softwarecatalogus_register.json:1906 (update limited to gebruik-beheerder and admin) and :2194 (read limited to authenticated); executing it is up to OpenRegister, so the row is pending until that is shown", + "owner": "ConductionNL/openregister" + }, + "reachedOn": "no page: enforced, if at all, by OpenRegister on every read and write", + "provider": "openregister", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "topdesk": "no", + "evidence": { + "topdesk": "Card 'Permission for fields and/or widgets' in Under consideration: 'User can set up permission for any fields or widgets'. (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from topdesk (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown" } ] } From 5e4f50bc2c5fa0bb7a4370b65e38d29581f66960 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:26:59 +0200 Subject: [PATCH 08/12] chore(parity): back-fill VNG and TOPdesk on the 31 demand rows --- openspec/parity/capabilities.json | 208 +++++++++++++++++------------- 1 file changed, 116 insertions(+), 92 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index 6a492a05..487e7b2f 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -3280,6 +3280,7 @@ "stackiq": "lib/Service/Federation/FederationService.php:215 announce() calls OpenCatalogi BroadcastService->broadcast(directory URL); only caller is lib/BackgroundJob/FederationSyncJob.php:73. Off by default: lib/Service/Federation/FederationConfig.php:56 federation_enabled=false; lib/Settings/connections.json lists federation as switch-only via occ. isAvailable() is class_exists('OCA\\\\OpenCatalogi\\\\Service\\\\DirectoryService') (FederationService.php:95).", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no shared directory of catalogues or federation between workspaces is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'federat\\|activitypub' over src/ returns nothing; every instance is standalone and the only outbound registration is the plugin marketplace client (src/Glpi/Marketplace/). The marketplace client is src/Glpi/Marketplace/Controller.php:64." } }, @@ -3309,6 +3310,7 @@ "stackiq": "lib/Service/Federation/FederationService.php:434 fetchPeerCatalog() calls OpenCatalogi DirectoryService->getDirectory(['url' => $peerUrl]); OpenCatalogi's getDirectory (opencatalogi lib/Service/DirectoryService.php:2409, also on origin/development) reads only filters/limit/offset/include-federated and ignores 'url', so it returns this instance's own directory listings, not the peer's published entries. Provenance marking itself is built: lib/Service/Federation/FederationMerger.php:239 stamps _source.instance. Mirrors are written into the organization schema (FederationService.php:56 PEER_MIRROR_TYPE). No src/ code reads _source, so no page shows where an entry came from.", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; pulling entries from peer catalogues is not documented, only integrations with named tools (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'federat' over src/ returns nothing; data enters only through the UI, the APIs (src/Glpi/Api/APIRest.php:60, src/Glpi/Api/HL/Router.php) and inventory, never from peer catalogues." } }, @@ -3338,6 +3340,7 @@ "stackiq": "lib/Controller/FederationController.php:86 addPeer / removePeer (routes.php:246-247), #[AuthorizedAdminSetting(StackiqAdmin)]; lib/Service/Federation/FederationService.php:157/191 with an SSRF host guard; UI src/views/settings/sections/FederationSettings.vue:283 (POST) and :307 (DELETE), mounted from src/views/settings/StackiqSettings.vue:114.", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no peer catalogue management is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'federat' over src/ returns nothing; there is no peer list in the Setup menu (src/Html.php:1330 onwards)." } }, @@ -3362,7 +3365,7 @@ "providerHow": "read-from-code", "note": "Read and write through a REST API is live through OpenRegister, with stackiq's own role-scoped endpoints on top.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48867 'REST & GraphQL API' (2026-07-23): Programmatic access to the workspace graph.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/sap-leanix-apis: 'These APIs are ideal for integration with systems that support RESTful interactions' and 'The GraphQL API enables you to retrieve and update fact sheets and related data' (read 2026-09-26). Reached on: Developer Guide > SAP LeanIX APIs.", "bluedolphin": "docs, intelligence competitor_features#48972 'REST API' (2026-07-23): Programmatic integration with other systems.", "glpi": "source read at 11.0.9: legacy REST API src/Glpi/Api/APIRest.php:60 (documented in apirest.md) and the v2 high level API, src/Glpi/Api/HL/Controller/AssetController.php:149 /Assets with GET list (:2825), GET item (:2839) and POST create (:2988), Appliance and Software included (src/Glpi/Api/HL/Controller/AssetController.php:39, :133). Reached on: /apirest.php and /api.php/v2. Driven on the lab at 11.0.9 (2026-09-26): the legacy API answers \"There isn't an active API client matching your IP address\" until an administrator adds an API client, and the v2 API is off until enabled in Setup > General > API.", "topdesk": "https://docs.topdesk.com/en/required-knowledge.html: \"basic knowledge of REST API requests (see developers.topdesk.com )\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: \"API access > REST API : this permission is necessary for operator cards that are used for accessing the TOPdesk API\" (read 2026-09-26). Reached on: developers.topdesk.com.", @@ -3376,7 +3379,7 @@ "name": "Read generated documentation of the catalogue API.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3395,7 +3398,8 @@ "glpi": "source read at 11.0.9: src/Glpi/Api/HL/Controller/CoreController.php:322 route /doc serves a Swagger UI 'GLPI API Documentation' (:329 to :331) over the spec built by src/Glpi/Api/HL/OpenAPIGenerator.php. Reached on: /api.php/doc. Driven on the lab at 11.0.9 (2026-09-26): on a fresh install /api.php/v2/doc answers 403 \"The High-Level API is disabled\"; after switching on enable_hlapi in Setup > General > API it serves the Swagger UI \"GLPI API Documentation\".", "stackiq": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261). The views docs endpoint is login-only; the aangeboden-gebruik docs endpoint is @PublicPage (AangebodenGebruikController.php:860), so anyone can read it (corrected 2026-09-26). Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint.", "topdesk": "https://developers.topdesk.com/: TOPdesk API reference site, linked from the docs as \"TOPdesk API documentation\" (read 2026-09-26); https://docs.topdesk.com/en/generate-a-document.html: \"see FreeMarker and the TOPdesk API documentation\" (read 2026-09-26). Reached on: developers.topdesk.com.", - "vng-softwarecatalogus": "unknown: no API documentation for the current catalogue was found; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no API documentation for the current catalogue was found; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/sap-leanix-apis: 'we provide the OpenAPI explorer . This tool enables you to explore APIs, send requests, and view responses directly in your browser' (read 2026-09-26). Reached on: Workspace > OpenAPI explorer." } }, { @@ -3404,7 +3408,7 @@ "name": "Export your own catalogue data for use elsewhere.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3424,7 +3428,8 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"De publieke informatie is ook beschikbaar als download van exportbestanden ... Mijn pakketten, Mijn koppelingen: Knop [Exporteren]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Exporteren; Beschikbare downloads.", "glpi": "source read at 11.0.9: every search list exports to CSV, PDF, ODS and XLSX through src/Glpi/Search/Output/Csv.php, Pdf.php, Ods.php and Xlsx.php, plus impact CSV (front/impactcsv.php) and the APIs (src/Glpi/Api/HL/Controller/AssetController.php:2825). Reached on: any list, Export menu. Driven on the lab at 11.0.9 (2026-09-26): the Appliances list exported to CSV (/front/report.dynamic.php display_type 3) with the created record.", "stackiq": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json).", - "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: tile actions \"Export to .CSV Export to Excel\" (read 2026-09-26); https://docs.topdesk.com/en/create-odata-reports-for-asset-management.html: \"generate reports by using the TOPdesk OData feed ... Microsoft Power BI, or Microsoft Excel\" (read 2026-09-26). Reached on: Asset dashboard; OData feed." + "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: tile actions \"Export to .CSV Export to Excel\" (read 2026-09-26); https://docs.topdesk.com/en/create-odata-reports-for-asset-management.html: \"generate reports by using the TOPdesk OData feed ... Microsoft Power BI, or Microsoft Excel\" (read 2026-09-26). Reached on: Asset dashboard; OData feed.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/exporting-fact-sheet-data-as-excel-file: 'export fact sheet data as an Excel file'; https://help.sap.com/docs/leanix/ea/exporting-workspace-snapshots: 'Export snapshots of your workspace data through the Pathfinder REST API' (read 2026-09-26). Reached on: Inventory > Export; snapshot API." } }, { @@ -3448,7 +3453,7 @@ "providerHow": "read-from-code", "note": "No integration with a service management tool exists.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48866 'Out-of-the-box integrations (ServiceNow, Signavio, SAP)' (2026-07-23): Pre-built connectors sync CMDB, process and ERP data.", + "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: 'ServiceNow integration An integration that connects the subscription services to the customer's ServiceNow subscription to synchronize infrastructure and software asset information'; Jira Service Management integration at https://help.sap.com/docs/leanix/ea/jira-service-management-integration-faqs (read 2026-09-26). Reached on: Administration > Integrations > ServiceNow.", "bluedolphin": "docs, intelligence competitor_features#48973 'TOPdesk integration' (2026-07-23): Connector to TOPdesk asset/service data. | docs, intelligence competitor_features#27465 'TOPdesk Integration' (2026-04-12): Available on TOPdesk Marketplace for IT landscape insights", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"Go to Links > Assets . Click Link asset\" (read 2026-09-26) on calls and changes; TOPdesk is itself the service management tool. Reached on: Call card > Links > Assets.", "stackiq": "No ITSM connector: lib/Settings/connections.json lists only email, federation and eol-feed; grep for topdesk/servicenow/itsm in lib/ and src/ finds nothing.", @@ -3477,7 +3482,7 @@ "providerHow": "read-from-code", "note": "As a Nextcloud app it runs on whatever infrastructure hosts the Nextcloud instance.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", + "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf describes 'The SaaS services' and a customer 'workspace'; https://www.leanix.net/hubfs/Legal/Operational-Terms-Exhibit-v.2.0.pdf defines 'the data center utilized by LeanIX to host Customer's Data' with maintenance windows per hosting region. Only a vendor hosted subscription is offered (read 2026-09-26)", "bluedolphin": "docs, intelligence competitor_features#27467 'SaaS Platform' (2026-04-12): Cloud-native SaaS, no installation required", "glpi": "source read at 11.0.9: GPL 3 source distributed for installation on own servers (LICENSE, INSTALL.md, install/mysql/glpi-empty.sql schema and the web installer src/Glpi/Controller/InstallController.php). The version is src/autoload/constants.php:43 GLPI_VERSION 11.0.9, the installer controller src/Glpi/Controller/InstallController.php:57, the licence LICENSE:1 GNU GPL version 3.", "topdesk": "https://docs.topdesk.com/VA2026R3/index.html: \"TOPdesk Virtual Appliance documentation\", releases VA 2023 R2 to VA 2026 R3 (read 2026-09-26); https://tip.topdesk.com/c/255-va-release-q4-2026: roadmap card in column \"Planned\", \"VA Release Q4 2026\" in section \"On premise - VA releases\" (read 2026-09-26). Reached on: Virtual Appliance.", @@ -3491,7 +3496,7 @@ "name": "Search the catalogue and narrow the results with facets such as reference component and supplier.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -3511,7 +3516,8 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Aan de linkerkant staan zogenaamde filter mogelijkheden. Deze werken ook in combinatie ... Achter de te zetten filters staat een getal\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facets Leverancier, Standaard, Referentiecomponent, Status planning, Domein, Doelgroep, Bedrijfsfunctie (read 2026-09-26). Reached on: Alle pakketten / Alle pakketversies.", "glpi": "source read at 11.0.9: every list has a criteria builder, src/Glpi/Search/Input/QueryBuilder.php:72 showGenericSearch, over all search options, for example manufacturer on appliances (src/Appliance.php:229 region, glpi_manufacturers) and status (src/Appliance.php:350); there are no counted facets and no reference component to filter on. Reached on: Management > Appliances, search criteria.", "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS = referenceComponent, standard, applicationService, domain (GET /api/facets/{schema}, routes.php:195); src/views/FacetedCatalogIndexView.vue renders CnFacetSidebar with these plus search, on the Applications and Services pages. Supplier is only a column (src/manifest.json Modules config columns 'provider'), not a facet, although the module schema marks provider facetable.", - "topdesk": "https://docs.topdesk.com/en/the-asset-management-module-page.html: \"Asset overview : view all your assets in a filterable list\" (read 2026-09-26). Facets with counts are not described. Reached on: Asset Management > Asset overview." + "topdesk": "https://docs.topdesk.com/en/the-asset-management-module-page.html: \"Asset overview : view all your assets in a filterable list\" (read 2026-09-26). Facets with counts are not described. Reached on: Asset Management > Asset overview.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options: inventory filters by lifecycle, subscription, tags and fields, and https://help.sap.com/docs/leanix/ea/filtering-in-report-urls: 'Apply a filter using the facet filter column' (read 2026-09-26). Reached on: Inventory > facet filter column." } }, { @@ -3520,7 +3526,7 @@ "name": "Save a filtered view of the catalogue and open it again later.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3538,7 +3544,8 @@ "glpi": "source read at 11.0.9: src/SavedSearch.php:52 SavedSearch, private or shared, listed under Tools > Saved searches (src/Html.php:1309) with optional alerts (front/savedsearch_alert.form.php). Reached on: Tools > Saved searches (front/savedsearch.php). Driven on the lab at 11.0.9 (2026-09-26): Tools > Saved searches (/front/savedsearch.php) lists saved searches with private or shared scope and a default flag.", "stackiq": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back.", "topdesk": "https://tip.topdesk.com/c/83-share-saved-overviews-with-operators-and-operator-groups: roadmap card in column \"Launched\", \"User is able to share saved overviews with operators and operator groups - Rename the saved overview\" (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: only VNG-defined \"Marktscans-voorgedefinieerde filters\" are described; users saving their own view is not; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Marktscans (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: only VNG-defined \"Marktscans-voorgedefinieerde filters\" are described; users saving their own view is not; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Marktscans (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options mentions 'creating saved searches' and shareable filtered URLs; the feature list says 'Reports can be saved and shared with user to retrieve the specific view later' (https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf) (read 2026-09-26). Reached on: Inventory > Saved searches." } }, { @@ -3562,7 +3569,7 @@ "providerHow": "read-from-code", "note": "The dashboard shows counts of organisations, applications, services and contracts. The counts are computed by OpenRegister through the library stat widget.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports. | docs, intelligence competitor_features#27424 'Dashboards & Reports' (2026-04-12): Real-time dashboards for CIO-level reporting", + "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: 'Configurable dashboards visualize inventory content as charts, lists, and KPIs'; https://help.sap.com/docs/leanix/ea/application-portfolio-management-dashboard (read 2026-09-26). Reached on: Dashboards.", "glpi": "source read at 11.0.9: src/Glpi/Dashboard/Grid.php:1400 adds a 'Number of %s' card for every menu itemtype, so suppliers, appliances, software and contracts are counted (menu types src/Html.php:1298 to :1300); dashboards are stored by src/Glpi/Dashboard/Dashboard.php:66 and shown on the central page (src/Central.php:135). Reached on: Home > Dashboard; Assets > Dashboard.", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"open the Asset dashboard to see statistics and visualised information regarding your registered assets\" (read 2026-09-26); https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub\" (read 2026-09-26). Reached on: Asset Management > Asset dashboard.", "stackiq": "src/manifest.json:72 Dashboard page with stat widgets kpi-organisations, kpi-modules, kpi-services, kpi-contracts (source metric count on organization/module/catalogService/catalogContract) plus catalog-panels.", @@ -3593,6 +3600,7 @@ "stackiq": "lib/Dashboard/ConceptOrganisatiesWidget.php registered at lib/AppInfo/Application.php:760; src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters organisations on status === 'concept', but the status enum is Draft/Active/Inactive/merged (lib/Settings/softwarecatalogus_register.json:2321) after lib/Repair/RenameDutchCatalogValues.php:76 renamed 'Concept' to 'Draft'. Accept writes status 'actief' (:129), which is not in the enum either.", "topdesk": "unknown: not a Nextcloud app; no such widget applies; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue is not a Nextcloud app; no such widget applies; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; organisations have no concept state and there is no Nextcloud dashboard, so this is not covered (read 2026-09-26)", "glpi": "source read at 11.0.9: GLPI is not a Nextcloud app and has no concept organisation state (suppliers only have is_active, install/mysql/glpi-empty.sql:7087), so no such widget exists in its own dashboards (src/Glpi/Dashboard/Grid.php:67)." } }, @@ -3602,7 +3610,7 @@ "name": "Pick a ready-made report from a list and open it.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3620,7 +3628,8 @@ "glpi": "source read at 11.0.9: src/Report.php:52 Report builds a pick list of ready made reports, src/Report.php:77 default, :81 by contract, :85 by year, :87 financial information, :110 status, chosen from 'Select the report you want to generate' (src/Report.php:143). Reached on: Tools > Reports (front/report.php). Driven on the lab at 11.0.9 (2026-09-26): /front/report.php offers Default report, By contract, By year, Hardware financial and administrative information, Other financial and administrative information, Network report, Loan and Status.", "stackiq": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303).", "topdesk": "https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub ... So far, you could find dashboards and reports in different places\" (read 2026-09-26); https://tip.topdesk.com/c/20-reporting-hub: roadmap card in column \"Launched\", \"Reporting Hub\" (read 2026-09-26). Reached on: TOPdesk menu > Reporting Hub.", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/rapportages: \"Regelmatig worden er rapportages gemaakt over het gebruik van de Softwarecatalogus\" (read 2026-09-26); compliancy monitor and digital accessibility monitor pages. Reached on: Rapportages; Compliancy monitor." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/rapportages: \"Regelmatig worden er rapportages gemaakt over het gebruik van de Softwarecatalogus\" (read 2026-09-26); compliancy monitor and digital accessibility monitor pages. Reached on: Rapportages; Compliancy monitor.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/report-types lists ready report types such as 'Landscape Report', 'Matrix Report', 'Roadmap Report'; the feature list names 'Pre-configured reports with adjustable filters' (https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf) (read 2026-09-26). Reached on: Reports." } }, { @@ -3646,7 +3655,7 @@ "featureConfidence": "high", "note": "Users cannot build their own report. The one fixed portfolio report can be exported as CSV, but it is not configurable.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48868 'CXO dashboards & reporting' (2026-07-23): Executive dashboards and role-based reports.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/sap-leanix-apis: 'GraphQL is used to create custom reports'; https://help.sap.com/docs/leanix/ea/reporting-framework-and-cli: reporting library with 'Export to PDF and PNG files' (read 2026-09-26). Reached on: Reports > custom reports (reporting framework, Extension Hub).", "glpi": "source read at 11.0.9: any itemtype list takes arbitrary criteria (src/Glpi/Search/Input/QueryBuilder.php:72), selectable columns, and exports to CSV, PDF, ODS or XLSX (src/Glpi/Search/Output/Xlsx.php); the result can be saved (src/SavedSearch.php:52) and charted on a dashboard (src/Glpi/Dashboard/Grid.php:67). Reached on: any list with criteria, column selection and export.", "stackiq": "No report builder in src/ or lib/. The only report is the fixed Gartner TIME portfolio report (lib/Controller/PortfolioReportController.php, CSV at :105). The overlay lists portfolio-reporting as status 'soon'.", "topdesk": "https://docs.topdesk.com/en/reporting.html: \"The Report Wizard is not available for the Asset Management module. Further reporting can be done with the Asset Type Report or the OData feed\" (read 2026-09-26). Reached on: Asset Type Report; OData.", @@ -3659,7 +3668,7 @@ "name": "Export a filtered list to a spreadsheet.", "origin": "competitor", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3679,7 +3688,8 @@ "glpi": "source read at 11.0.9: src/Glpi/Search/Output/Csv.php, Ods.php, Xlsx.php and Pdf.php export the filtered list; the output format selector is rendered by src/Html.php:4219 Dropdown::showOutputFormat. Reached on: any filtered list, Export. Driven on the lab at 11.0.9 (2026-09-26): the filtered Appliances list exported to CSV with the created record.", "stackiq": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export.", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"Export to .CSV Export to Excel\" (read 2026-09-26). Reached on: Asset dashboard tile menu.", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: \"Export to CSV\" on the filtered package-version list (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Ook beschikbaar via knop [Export to csv] op pagina Alle pakketten\" (read 2026-09-26). Reached on: Alle pakketversies > Export to CSV." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: \"Export to CSV\" on the filtered package-version list (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Ook beschikbaar via knop [Export to csv] op pagina Alle pakketten\" (read 2026-09-26). Reached on: Alle pakketversies > Export to CSV.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/exporting-fact-sheet-data-as-excel-file: 'In the inventory, apply filters to narrow down to the fact sheets that you need to export ... export fact sheet data as an Excel file' (read 2026-09-26). Reached on: Inventory > table view > Export." } }, { @@ -3706,6 +3716,7 @@ "stackiq": "No scheduled report or report mail job: lib/BackgroundJob/ holds only ContractStatusJob, EolSyncJob, FederationSyncJob and OrganizationContactSyncJob; grep for report scheduling in lib/ and src/ finds nothing.", "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"Reports & Selections > Schedule reports with my own authorizations : the operator can schedule reports to be regularly saved or sent to contact persons\" (read 2026-09-26). Reached on: Reports & Selections.", "vng-softwarecatalogus": "unknown: no scheduled reports are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; scheduled notification digests (https://help.sap.com/docs/leanix/ea/notifications-center) and scheduled snapshot exports by API (https://help.sap.com/docs/leanix/ea/export) exist, but mailing a report to named people on a schedule is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: saved search alerts, src/SavedSearch_Alert.php:45 with count conditions (src/SavedSearch_Alert.php:53 to :58) and a frequency, run by src/SavedSearch_Alert.php:307 cronSavedSearchesAlerts and sent through the notification system to configured recipients; they notify on a result count rather than sending the report itself. Reached on: Tools > Saved searches > Alerts tab." } }, @@ -3715,7 +3726,7 @@ "name": "See a report of software cost per organisation or per domain.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "partial", @@ -3735,7 +3746,8 @@ "glpi": "source read at 11.0.9: src/Budget.php:537 showValuesByEntity shows spend per entity and item type for a budget, and src/Report.php:89 'Other financial and administrative information (licenses, cartridges, consumables)' (front/report.infocom.conso.php); there is no cost per domain or reference component view. Reached on: Management > Budgets > budget tabs; Tools > Reports.", "stackiq": "src/views/LicensePostureView.vue:84 per-vendor rollup with annual cost from contracts (src/utils/licensePosture.js perVendorRollup); src/views/organisaties/PortfolioReport.vue:143 annualised and one-off cost per TIME quadrant for one selected organisation (lib/Service/PortfolioReportService.php via GET /api/portfolio-report).", "topdesk": "https://docs.topdesk.com/en/obtain-insights-with-asset-type-report.html: \"do you need an overview of the total costs of new assets?\" (read 2026-09-26); call cost fields in https://docs.topdesk.com/en/fields-for-call-management-reports.html. Reached on: Asset Type Report.", - "vng-softwarecatalogus": "unknown: costs are not recorded; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: costs are not recorded; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-portfolio-management-dashboard: 'application run cost broken down by business capability'; https://help.sap.com/docs/leanix/ea/dashboard-modeling: 'Report on cost per business capability' (read 2026-09-26). Reached on: Dashboards > Application Portfolio Management Dashboard." } }, { @@ -3744,7 +3756,7 @@ "name": "See in the app which features are available, in beta or coming soon.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "partial", @@ -3762,6 +3774,7 @@ "stackiq": "src/manifest.json:1048 FeaturesRoadmap page (type roadmap, line 1050), footer menu entry FeaturesRoadmapMenu; content from openspec/features.overlay.json statuses stable/beta/soon.", "topdesk": "https://docs.topdesk.com/en/topdesk-labs.html: \"As a SaaS user, you can turn on the labs features you are curious about through Functional Settings > Labs\" (read 2026-09-26); https://docs.topdesk.com/en/ai-features.html: \"On your settings page, you can find an overview of all the AI features currently available in your environment\" (read 2026-09-26). Coming-soon items live on the external roadmap, not in the app. Reached on: Functional Settings > Labs.", "vng-softwarecatalogus": "unknown: FAQ E14 points to a homepage block \"Binnenkort in de Softwarecatalogus\", but today's homepage shows no such block; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/ (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/ai-governance-extension: 'Go to Administration > Optional Features and Early Access' to activate extensions; the public roadmap is outside the app at https://roadmap.leanix.net/ (read 2026-09-26). Reached on: Administration > Optional Features and Early Access.", "glpi": "source read at 11.0.9: grep -rli 'coming soon' over src/ templates/ returns no in app feature status page; src/Glpi/Features/ holds item traits (for example src/Glpi/Features/Kanban.php), not feature flags. src/Glpi/Features/Kanban.php:45 is a trait, typical of that directory." } }, @@ -3771,7 +3784,7 @@ "name": "Follow the progress of a long synchronisation or import.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -3789,7 +3802,8 @@ "glpi": "source read at 11.0.9: massive actions over many records show a progress bar, src/MassiveAction.php:1294 displayProgressBar; the LDAP synchronisation command shows one per user batch, src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:382; long web operations report through src/Glpi/Controller/ProgressController.php:50 /progress/check/{key}. Inventory imports run per agent request without a progress view. Reached on: massive action screen; CLI ldap:sync.", "stackiq": "lib/Controller/SettingsController.php:1289 getProgress and :1360 streamProgress (routes.php:119-120) serve lib/Service/ProgressTracker.php, used only by lib/Service/MergeOrganisatieService.php; no src/ caller of /api/progress. The admin ArchiMate import shows a spinner then the final objects-processed count (src/views/settings/sections/ArchiMateImportExport.vue:103). Organisation sync shows a status block with last sync time and organisations to process (src/views/settings/sections/OrganizationSynchronization.vue:211).", "topdesk": "unknown: import errors can be downloaded as logs; following progress of a running import is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: no progress display for sync or import is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no progress display for sync or import is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://updates.leanix.net/announcements/product-update-march-2026: 'A real-time progress widget in the inventory side-panel keeps you informed of import status'; integration runs are followed in 'Administration > Integrations > Sync Log' (https://help.sap.com/docs/leanix/ea/collibra-data-catalog-integration) (read 2026-09-26). Reached on: Inventory side panel import progress; Administration > Integrations > Sync Log." } }, { @@ -3816,7 +3830,8 @@ "glpi": "source read at 11.0.9: src/KnowbaseItem.php:57 knowledge base articles with categories and visibility, linked to items through src/KnowbaseItem_Item.php:45 and shown on the appliance Knowledge base tab (src/Appliance.php:104); menu src/Html.php:1307. Reached on: Tools > Knowledge base (front/knowbaseitem.php). Driven on the lab at 11.0.9 (2026-09-26): /front/knowbaseitem.php opens the knowledge base with Search and Browse.", "topdesk": "https://docs.topdesk.com/en/knowledge-management.html: \"The Knowledge Base is set up and managed by your organization's knowledge managers. Every operator is able to use information from the Knowledge Base\" (read 2026-09-26). Reached on: Modules > Knowledge Management.", "stackiq": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel.", - "vng-softwarecatalogus": "unknown: the FAQ and manuals are site help, no knowledge base about applications is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: the FAQ and manuals are site help, no knowledge base about applications is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; fact sheets hold links and files in a Resources tab (https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets), but no searchable knowledge base of articles is documented (read 2026-09-26)" } }, { @@ -3843,7 +3858,8 @@ "glpi": "source read at 11.0.9: native inventory receives glpi-agent submissions at src/Glpi/Controller/InventoryController.php:61 /Inventory (legacy :62 /front/inventory.php), processed by src/Glpi/Inventory/Inventory.php:106 with src/Glpi/Inventory/Asset/Software.php creating software and installations. The agent is the separate glpi-project/glpi-agent repository. Reached on: Administration > Inventory; Assets > Software.", "stackiq": "No discovery agent or agent-ingest endpoint in lib/ or appinfo/routes.php. The nearest capability is SBOM import per module version (lib/Controller/SbomController.php:129), which records components of a known release, not installed software.", "topdesk": "https://docs.topdesk.com/en/taking-inventory-with-configuration-management.html: \"TOPsis will scan the workstations in your network and import the data into TOPdesk\" (read 2026-09-26) (old Configuration Management); https://docs.topdesk.com/en/migration-status.html: \"For network scanning purposes, we advise you to use other solutions that are available via the TOPdesk Marketplace: Lansweeper integration Microsoft Endpoint Manager integration\" (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; LeanIX has no own installation agent, software assets come in through the ServiceNow integration (https://help.sap.com/docs/leanix/ea/obsolescence-risk-management-import-software-assets) (read 2026-09-26)" } }, { @@ -3870,7 +3886,8 @@ "glpi": "source read at 11.0.9: src/Glpi/Inventory/Request.php:97 NETDISCOVERY_ACTION calls src/Glpi/Inventory/Request.php:237 networkDiscovery, importing devices found by the agent's network discovery; scheduling discovery tasks from the server goes through the HANDLE_NETDISCOVERY_TASK hook (src/Glpi/Inventory/Request.php:448), which the separate glpiinventory plugin implements. Reached on: Administration > Inventory; Assets > Network devices.", "stackiq": "No network scanning code in lib/ or routes (appinfo/routes.php).", "topdesk": "https://docs.topdesk.com/en/creating-a-new-import.html: \"Connecting to Lansweeper as Asset Management import source\" (read 2026-09-26); https://tip.topdesk.com/c/186-automated-asset-scanning-tool: roadmap card in column \"Under consideration\", \"The asset discovery tool constantly monitors the entire network for new devices\" (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; network device discovery is not documented (read 2026-09-26)" } }, { @@ -3894,7 +3911,7 @@ "providerHow": "read-from-code", "note": "No discovery of unregistered SaaS use.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48864 'SaaS Management & discovery' (2026-07-23): Discovers SaaS usage and shadow IT, integrates with the fact sheet model.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/saas-discovery: 'SaaS discovery identifies your organization's SaaS applications through integrations with third-party systems like Single-Sign-on (SSO) ... Eliminate shadow IT and business-managed IT' (read 2026-09-26). Reached on: Discovery > SaaS discovery inbox.", "stackiq": "No SaaS or SSO-log discovery code in lib/; lib/Settings/connections.json has no such source.", "topdesk": "unknown: SaaS discovery is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -3907,7 +3924,7 @@ "name": "Register hardware such as laptops and servers alongside software.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3925,7 +3942,8 @@ "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:208 asset_types lists Computer, Monitor, NetworkEquipment and the other hardware types managed next to software, under the Assets menu. Reached on: Assets > Computers, Monitors, Network devices.", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"Think of a router that provides a computer with access to your network, or a printer\" (read 2026-09-26); any asset type via templates. Reached on: Asset Management.", "stackiq": "No hardware schema in lib/Settings/softwarecatalogus_register.json (schemas are software, organisation, contract and GEMMA model types only).", - "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-component-modeling-guidelines: IT component subtype 'Hardware ... (e.g., servers, mainframe computers, storage devices)'. Modeled as technology types an application depends on, not individual laptops as assets (read 2026-09-26). Reached on: IT Component fact sheet, subtype Hardware." } }, { @@ -3934,7 +3952,7 @@ "name": "Record configuration items and their relations in a CMDB.", "origin": "competitor", "vng-softwarecatalogus": "no", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -3952,7 +3970,8 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"Dubbel beheer (én in de Softwarecatalogus én in de CMDB) ... Een CMDB die separaat wordt bijgehouden\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/19703: \"Zolang de CMDB niet gekoppeld is aan de Softwarecatalogus\" (read 2026-09-26). The docs treat the CMDB as a separate tool.", "glpi": "source read at 11.0.9: configuration items are the asset types (src/autoload/CFG_GLPI.php:208) plus appliances, with relations recorded as appliance membership (src/Appliance_Item.php:45), impact relations (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and network port links. Reached on: Assets menu; item > Impact analysis tab.", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"You register these functionalities as custom link types, and these link types are shown in the graphical overview of assets\" (read 2026-09-26). Reached on: Asset card > Relationships widget.", - "stackiq": "Applications (module lib/Settings/softwarecatalogus_register.json:6777), versions (moduleVersion :7649), suites (suite :1135) and application-to-application connections (connection :3563) with relations; ModuleDetail and SuiteDetail show a Related panel. No manifest page has register+schema 'connection' or 'usage', so connections are not listed or created on their own page." + "stackiq": "Applications (module lib/Settings/softwarecatalogus_register.json:6777), versions (moduleVersion :7649), suites (suite :1135) and application-to-application connections (connection :3563) with relations; ModuleDetail and SuiteDetail show a Related panel. No manifest page has register+schema 'connection' or 'usage', so connections are not listed or created on their own page.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/jira-service-management-integration: 'Use the Jira Service Management integration to synchronize data between your configuration management database (CMDB) and SAP LeanIX ... Configuration items from Jira Service Management can be mapped to various fact sheet types'. LeanIX consumes a CMDB, it does not act as one (read 2026-09-26). Reached on: Jira Service Management and ServiceNow integrations." } }, { @@ -3961,7 +3980,7 @@ "name": "Deduplicate and reconcile records that arrive from several sources.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -3979,6 +3998,7 @@ "stackiq": "Organisation merge: src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail, calling /api/organisaties/{uuid}/merge/dry-run and /merge (src/store/modules/organisatie.js:486/524, lib/Controller/MergeController.php:106, admin-only body guard). Federation mirrors are reconciled per peer by lib/Service/Federation/FederationMerger.php.", "topdesk": "unknown: deduplication across sources is not described; https://tip.topdesk.com/c/239-ai-cmdb-monitoring- (duplicates) is under consideration; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/aggregation-and-linkage-of-software-records: 'import software records from ServiceNow as aggregated software fact sheets'; https://help.sap.com/docs/leanix/ea/matching-rules: custom matching to avoid 'duplicate fact sheets'; SaaS discovery links the same SaaS found in several SSOs (https://help.sap.com/docs/leanix/ea/saas-discovery) (read 2026-09-26). Reached on: ServiceNow integration > aggregation; matching rules; SaaS discovery inbox.", "glpi": "source read at 11.0.9: src/RuleImportAsset.php:46 import and link rules decide whether an incoming inventory record matches an existing asset (by serial, UUID, MAC and similar) or creates one; src/RuleDictionnarySoftware.php:44 normalises software names and publishers from different sources; duplicates can be merged afterwards (src/Software.php:1011). Reached on: Administration > Rules > Rules for import and link equipments; Dictionaries." } }, @@ -3988,7 +4008,7 @@ "name": "Log incidents and requests against an application.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -4006,7 +4026,8 @@ "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:301 ticket_types includes Appliance (line 305), so tickets link to an application through src/Item_Ticket.php:41, shown on the appliance Tickets tab (src/Appliance.php:105). Reached on: Assistance > Tickets; Appliance > Tickets tab. Driven on the lab at 11.0.9 (2026-09-26): the default Super-Admin profile lists Computer, Monitor, NetworkEquipment, Peripheral, Phone, Printer, Software, DCRoom, Rack, Enclosure and Database as associable to tickets, not Appliance, so an appliance shows no Tickets tab until an administrator adds it in the profile; rating kept.", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity) ... cards, you can link multiple assets\" (read 2026-09-26). Reached on: Call card > Links > Assets.", "stackiq": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php.", - "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/portals: an Application Portal 'accessible to everyone to order software, issue support tickets' through configurable links to the helpdesk; incidents themselves stay in the ITSM tool (read 2026-09-26). Reached on: Portals > links to helpdesk." } }, { @@ -4033,7 +4054,8 @@ "glpi": "source read at 11.0.9: changes link to the appliance (src/Appliance.php:107 Change_Item tab) and go through approvals, src/ChangeValidation.php:39 ChangeValidation extends CommonITILValidation. Reached on: Assistance > Changes; Appliance > Changes tab.", "topdesk": "https://docs.topdesk.com/en/requesting-a-change.html: \"A Preliminary Request for Change can only be dealt with as a Request for Change after it is authorized\" (read 2026-09-26). Reached on: Modules > Change Management.", "stackiq": "No change-request workflow for applications. The only approval flow is for contracts: src/components/contracts/ContractApprovalPanel.vue on ContractDetail via /api/contracts/{uuid}/approval (routes.php:35-37), delegated to decidiq.", - "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; architecture decisions have a review process (https://help.sap.com/docs/leanix/ea/architecture-decisions) but a change approval workflow on an application is not documented (read 2026-09-26)" } }, { @@ -4042,7 +4064,7 @@ "name": "Track service level targets for an application or supplier.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -4060,7 +4082,8 @@ "glpi": "source read at 11.0.9: src/SLM.php:42 service level management with src/SLA.php:44 SLA and OLA targets on tickets (install/mysql/glpi-empty.sql:7304 glpi_tickets.slas_id_ttr), assigned by business rules (src/RuleCommonITILObject.php:73) that can key on the linked appliance (src/RuleCommonITILObject.php:305 assign_appliance). Reached on: Setup > Service levels.", "topdesk": "https://docs.topdesk.com/en/track-when-you-respond-to-calls, response-times.html: \"you register and track how quickly your operators need to respond ... you need a Contract Management and SLM license\" (read 2026-09-26). Reached on: Contract Management and SLM.", "stackiq": "catalogContract.contractType enum includes 'SLA' (lib/Settings/softwarecatalogus_register.json:3344) as a label only; no service-level target, measurement or breach fields in any schema.", - "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Service Level Agreement (SLA) Single Select Corporate-Level SLA, Customer-Level SLA, Service-Level SLA' and an SLA description on the contract. No tracking of targets against results (read 2026-09-26). Reached on: Contract fact sheet > Governance and Regulations." } }, { @@ -4069,7 +4092,7 @@ "name": "Let end users request software through a self-service portal.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -4087,6 +4110,7 @@ "topdesk": "https://docs.topdesk.com/en/mobile-access-to-the-self-service-portal.html: \"The SSP layout is suited to be displayed in a mobile interface\" (read 2026-09-26); https://tip.topdesk.com/c/86-webshop-is-connected-with-asset-management: roadmap card in column \"Building\", \"End-user can order items which are in Asset Management\" (read 2026-09-26); pricing lists \"Self-Service Portal\" and \"Webshop\". Reached on: Self-Service Portal.", "stackiq": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/portals: 'create an Application Portal that is accessible to everyone to order software ... Action button: Perform an action, in this case \"Request new Application\"' (read 2026-09-26). Reached on: Portals > Application Portal.", "glpi": "source read at 11.0.9: the 11.0 service catalog src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45 lists native forms for self service users (menu src/Html.php:1283), and a form question can offer software items to pick, src/Glpi/Form/QuestionType/QuestionTypeItem.php:180 Software::class, creating a ticket from the answer. Reached on: Self service > Service catalog. Driven on the lab at 11.0.9 (2026-09-26): /ServiceCatalog shows the service catalog with \"Report an issue\" and \"Request a service\"." } }, @@ -4166,11 +4190,11 @@ "note": "Helmond's architecture repository tender (REQ3, REQ61) asks to relate the repository to the GGM. GGM metadata survives an ArchiMate import on architecture elements, but no field or page links an application to a GGM entity.", "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: the Gemeentelijk Gegevensmodel is not mentioned; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: the Gemeentelijk Gegevensmodel is not mentioned (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -4195,13 +4219,13 @@ "feature": "archimate-import-and-export", "featureConfidence": "medium", "note": "Helmond REQ19 asks for architecture views embedded in office documents. stackiq renders no view at all (see arch-gemma-views) and exports only ArchiMate files.", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"Download de kaart met de knop [download SVG] ... De kaart volledig schaalbaar\" (read 2026-09-26). A map is downloaded as SVG for printing; placing it in Word or PowerPoint is a manual step. Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart > download SVG.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: architecture views and Word or PowerPoint are not mentioned (0 hits for PowerPoint); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -4227,11 +4251,11 @@ "note": "Helmond REQ54 asks for entity relationship or UML data models. stackiq holds imported ArchiMate elements but models nothing itself.", "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: no data modelling is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: no data entity or UML modelling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -4255,18 +4279,18 @@ "providerHow": "read-from-code", "featureConfidence": "medium", "note": "Helmond REQ78 asks administrators to check periodically that every user still needs access. stackiq fetches the last login of each contact's account and never shows it.", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/gebruikersbeheer: \"Er opent zich een overzicht met alle geregistreerde gebruikers van uw organisatie ... inclusief wanneer zij voor het laatst hebben ingelogd\" (read 2026-09-26); https://www.softwarecatalogus.nl/: tip \"Controleer of alle gebruikers nog werkzaam zijn bij de gemeente of samenwerking\" (read 2026-09-26). A manual check, no review cycle. Reached on: Menu > Gebruikersbeheer.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "https://docs.topdesk.com/en/operator-licence-overview.html: the list of operators shows \"When the given operator was last active (meaning their last login)\" (read 2026-09-26). Input for a review; no periodic review process is described. Reached on: Operator licence overview." }, "sap-leanix": "unknown", "bluedolphin": "unknown", "glpi": "unknown", - "topdesk": "unknown" + "topdesk": "partial" }, { "id": "comp-processing-register", @@ -4288,11 +4312,11 @@ "note": "Helmond REQ4 wants the processing register kept apart from the repository but linked. stackiq stores and shows a reference per application; it does not hold the register.", "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: no link to a register of processing activities is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: no register of processing activities is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -4317,13 +4341,13 @@ "feature": "offering-and-usage-listings", "featureConfidence": "medium", "note": "Standard municipal tender text (Noordwijk 418890, Reimerswaal 417169, FUMO 415897, HLT Samen 383984): a supplier inside the GEMMA scope can make its product information transparent through the Softwarecatalogus. stackiq publishes the data; the page a buyer opens lives in the external frontend.", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "yes", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"De leveranciersinformatie in de Softwarecatalogus is openbaar\" (read 2026-09-26); https://www.softwarecatalogus.nl/inkoopondersteuning%20standaarden: \"De gegenereerde bestekstekst kunt u gebruiken in uw offerte-uitvraag ... Als informatiebron is de GEMMA softwarecatalogus gebruikt\" (read 2026-09-26). Reached on: Supplier login > Productportfolio; Inkoopondersteuning.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: TOPdesk is a single-organisation tool; public supplier product information is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -4350,11 +4374,11 @@ "note": "Helmond REQ41 asks for analysis of application use, cost, risk and value. stackiq records a TIME classification (life-time-classification) without the scores that would justify it.", "vng-softwarecatalogus": "unknown", "evidence": { - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: no value, cost or risk scoring is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: no value, cost and risk scoring of applications is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", @@ -4383,7 +4407,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: a sign-off of the application list is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4413,7 +4437,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: no register of processing activities is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4443,7 +4467,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: collective agreements across organisations are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4473,7 +4497,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: assets hold documents in a Documents widget, but sharing them with other organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4503,7 +4527,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: no availability, integrity and confidentiality classification is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4533,7 +4557,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: no product comparison table is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4563,7 +4587,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: acting as another user is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4593,7 +4617,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: Common Ground is not mentioned; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4623,7 +4647,7 @@ "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: versions of applications are not modelled; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", @@ -4650,7 +4674,7 @@ "topdesk": "yes", "evidence": { "topdesk": "Card 'More control over card & file removal' in Launched (updated 2026-02-09); docs https://docs.topdesk.com/en/file-maintenance.html: 'you can set how many days after closing or archiving a card its uploaded files and linked emails should be removed'. (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: retention cleanup is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" @@ -4680,7 +4704,7 @@ "topdesk": "no", "evidence": { "topdesk": "Card 'Field Dependencies (brand/type/model)' in Under consideration: 'User can set up dependencies between fields'; not in the field docs (https://docs.topdesk.com/en/editing-fields.html). (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: dependent fields are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" @@ -4710,7 +4734,7 @@ "topdesk": "no", "evidence": { "topdesk": "Card 'Changing the type of an asset' in Under consideration: 'User can change the type of an exiting asset'. (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: changing an entry type is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" @@ -4740,7 +4764,7 @@ "topdesk": "no", "evidence": { "topdesk": "Card 'Audit Logging for TOPdesk - MCP Server' in Building: 'you should be able to see exactly what that AI did, which actions it took, when, and on what data'. (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: no AI assistant is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" @@ -4771,7 +4795,7 @@ "evidence": { "topdesk": "Card 'Support Multi-Factor Authentication (MFA)' in Under consideration; today MFA only comes from the identity provider behind SAML SSO (https://docs.topdesk.com/en/topdesk-mobile.html: 'We test the store application with the Microsoft two-step authentication (2FA) for the SSO'). (read 2026-09-26)", "glpi": "source read at 11.0.9: CHANGELOG.md:277 11.0.0 added Two-Factor Authentication via TOTP; implemented by src/Glpi/Security/TOTPManager.php:60, with the disable action on the user's settings page (front/preference.php).", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: login is by username and password (https://www.softwarecatalogus.nl/user/login); a second factor is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" }, @@ -4800,7 +4824,7 @@ "topdesk": "no", "evidence": { "topdesk": "Card 'Enforce strong passwords' in Under consideration: 'By setting rules for things like minimum length, numbers, symbols, or uppercase letters, weak passwords are blocked'. (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: a password policy is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" @@ -4830,7 +4854,7 @@ "topdesk": "no", "evidence": { "topdesk": "Card 'AI - Risk & prediction' in Under consideration: 'Change risk prediction helps change managers assess how risky a planned change is before it's approved'. (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: change management is not covered; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" @@ -4860,10 +4884,10 @@ "glpi": "no", "evidence": { "glpi": "source read at 11.0.9: open request #336 (2026-05-22) asks to add all connected assets to the impact analysis at once; in core every impact relation is added by hand through src/Impact.php:1161 'Add relation' into install/mysql/glpi-empty.sql:1247 glpi_impactrelations, and the inventory (src/Glpi/Inventory/Inventory.php:106) does not create impact relations.", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: connections are entered by hand per the iJw and iWmo manual; automatic filling is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: relations are created by hand in the Relationships widget; automatic filling is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", "vng-softwarecatalogus": "unknown", @@ -4890,16 +4914,16 @@ "glpi": "no", "evidence": { "glpi": "source read at 11.0.9: open request #182 (2026-03-27) states contracts cannot be linked in GLPI 11; install/mysql/glpi-empty.sql:1536 glpi_contracts_items links a contract to items, and Contract is not among the linkable item types there, with no parent contract column in install/mysql/glpi-empty.sql:1483 glpi_contracts.", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: contracts are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"TOPdesk allows you to link your services to supplier services, so that the duration of your services will always be in line with the duration of supplier services\" (read 2026-09-26). Linking runs through underpinning services, not contract to contract. Reached on: Contract Management and SLM > Service card." }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "topdesk": "unknown" + "topdesk": "partial" }, { "id": "ctr-contract-owner", @@ -4920,16 +4944,16 @@ "glpi": "no", "evidence": { "glpi": "source read at 11.0.9: open request #290 (2026-05-07) asks for contract assignees as notification recipients; install/mysql/glpi-empty.sql:1483 glpi_contracts has no users_id or groups_id column, so contract alerts (src/NotificationTargetContract.php:47) go to configured global recipients only.", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: contracts are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Operator The TOPdesk operator responsible for managing the contract ... Reminder date Date on which an operator should be reminded about the contract, e.g. ahead of expiry\" (read 2026-09-26); https://docs.topdesk.com/en/events-that-trigger-actions.html: \"notify a manager that a contract will expire in a month\" (read 2026-09-26). Reached on: Contract card > Management > Operator." }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "topdesk": "unknown" + "topdesk": "yes" }, { "id": "life-dates-follow-status", @@ -4950,10 +4974,10 @@ "glpi": "partial", "evidence": { "glpi": "source read at 11.0.9: request #457 (2026-07-27, open) asks to tie dates to status; core already lets an entity fill financial dates when an item enters a chosen status, install/mysql/glpi-empty.sql:2800 autofill_use_date and :2822 autofill_decommission_date on glpi_entities, applied by src/Infocom.php:505 autofillDates, but only for the financial record's dates.", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: statuses and planning dates are entered separately; automatic dates are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "unknown: automated actions can update cards, but dates following a lifecycle status are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", "vng-softwarecatalogus": "unknown", @@ -4980,16 +5004,16 @@ "glpi": "yes", "evidence": { "glpi": "source read at 11.0.9: CHANGELOG.md:281 11.0.0 added 'View assigned' and 'Update assigned' rights; src/Glpi/Features/AssignableItem.php:68 grants read when the user or group is assigned and src/Glpi/Features/AssignableItem.php:79 checks UPDATE_ASSIGNED; Appliance uses this trait (src/Appliance.php:46 implements AssignableItemInterface).", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: roles are beheerder and raadpleger per organisation; rights per assigned application are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"To restrict access to specific data, link the operator to branch, operator, or category filters\" (read 2026-09-26); https://docs.topdesk.com/en/reservations-management-and-other-modules.html: \"Operator filter: operators can see all reservations, but can only edit reservations that are created by them or their operator group\" (read 2026-09-26). Filters by branch, operator or category; not shown for assets assigned to a person. Reached on: Operator card > filters." }, "note": "Mined from glpi (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "topdesk": "unknown" + "topdesk": "partial" }, { "id": "ops-own-house-style", @@ -5010,16 +5034,16 @@ "glpi": "yes", "evidence": { "glpi": "source read at 11.0.9: CHANGELOG.md:276 11.0.0 added custom palette and theme support; src/Glpi/UI/ThemeManager.php:103 getCustomThemesDirectory and :112 getCustomThemes load admin supplied themes, offered in src/Config.php:1612 getPalettes.", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: the catalogue is one VNG-branded site; organisation styling is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "https://docs.topdesk.com/en/self-service-portal-278632.html: \"you can create several SSP designs, with different colours, logos, and search bar backgrounds, to show a distinct look and feel to different branches\" (read 2026-09-26). Self-Service Portal only; operator interface styling is not described. Reached on: Self-Service Portal designer." }, "note": "Mined from glpi (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "topdesk": "unknown" + "topdesk": "partial" }, { "id": "land-copy-entry", @@ -5040,16 +5064,16 @@ "glpi": "yes", "evidence": { "glpi": "source read at 11.0.9: CHANGELOG.md:285 and :286 11.0.0 added cloning of templates and creating a template from an existing item; appliances are clonable (src/Appliance.php:49 use Clonable) together with their items, contracts, documents and financial record (src/Appliance.php:62 getCloneRelations).", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: FAQ A1 \"opvoer van een nieuwe versies mogelijk als kopie van een op te geven vorige versie ... Gegevens van die vorige versie worden overgenomen in de nieuwe versie, ook koppelingen worden overgenomen\" (read 2026-09-26). Copies a version of the same package with its connections, not a new application. Reached on: Mijn softwarecatalogus > Pakketten > kopie-symbool.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "topdesk": "https://docs.topdesk.com/en/copying-assets.html: \"you can save time by copying an existing asset ... Dataset content will not be copied during this action ... Read permissions for any linked asset type\" (read 2026-09-26). Whether links are copied is implied by the permission note, not stated. Reached on: Asset card > More > Copy." }, "note": "Mined from glpi (changelog) on 2026-09-26.", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", "bluedolphin": "unknown", - "topdesk": "unknown" + "topdesk": "partial" } ], "pending": [ @@ -6234,7 +6258,7 @@ "topdesk": "no", "evidence": { "topdesk": "Card 'Permission for fields and/or widgets' in Under consideration: 'User can set up permission for any fields or widgets'. (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: field-level permissions are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" From 69ef74e4173c3b9d11d1ec94cab467200a1ffa5e Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:30:12 +0200 Subject: [PATCH 09/12] chore(parity): back-fill GLPI on the demand rows from source at 11.0.9 --- openspec/parity/capabilities.json | 192 ++++++++++++++++++------------ 1 file changed, 113 insertions(+), 79 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index 487e7b2f..87423ff5 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -4138,6 +4138,7 @@ "topdesk": "https://docs.topdesk.com/en/installing-the-topdesk-mobile-store-application.html: \"Scan the QR code to download the app from the Play store\" (read 2026-09-26). Reached on: TOPdesk Mobile app.", "stackiq": "No mobile app or mobile-specific surface in the repo; the app is the Nextcloud web UI (src/manifest.json).", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for mobile app, iOS and Android, no hits; only a Microsoft Teams app is documented (https://help.sap.com/docs/leanix/ea/sap-leanix-app-for-microsoft-teams) (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'android\\|ios app\\|mobile app' over src/ templates/ returns nothing; the repository ships only the responsive web interface (templates/) and APIs (src/Glpi/Api/HL/Controller/CoreController.php:322 docs), no native mobile client." } }, @@ -4147,7 +4148,7 @@ "name": "Run the organisation and contact synchronisation on a schedule and see when it last ran.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "partial", @@ -4167,6 +4168,7 @@ "stackiq": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674).", "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"when tracking imports/Exchange exports via system events ... on a schedule\" (read 2026-09-26); https://tip.topdesk.com/c/116-support-for-importing-persons-and-operators-directly-from-local-active-directory: roadmap card in column \"Launched\", person import from AD (read 2026-09-26). Reached on: Settings > Import settings.", "vng-softwarecatalogus": "unknown: only \"De kaart wordt dagelijks bijgewerkt\" is stated; no organisation or contact sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/17042 (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/configuring-automated-nightly-runs-for-inbound-processors: 'enable automated nightly runs for an inbound Integration API processor'; SaaS discovery retrieves data 'usually twice a day' (https://help.sap.com/docs/leanix/ea/saas-discovery); runs visible in 'Administration > Integrations > Sync Log' (read 2026-09-26). Reached on: Administration > Integrations > Sync Log.", "glpi": "source read at 11.0.9: automatic actions are scheduled and show their last run, src/CronTask.php:59 with install/mysql/glpi-empty.sql:1610 glpi_crontasks.lastrun, but LDAP user and group synchronisation is not one of them (grep -i ldap over the cron seed in install/empty_data.php:438 finds none); it is the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users, which must be scheduled by the system cron. Organisation (supplier) records have no sync at all. Reached on: Setup > Automatic actions; CLI bin/console ldap:sync. Driven on the lab at 11.0.9 (2026-09-26): /front/crontask.php lists automatic actions with run mode, frequency and last run." } }, @@ -4193,12 +4195,12 @@ "vng-softwarecatalogus": "unknown: the Gemeentelijk Gegevensmodel is not mentioned; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'gegevensmodel\\|ggm' over src/ templates/ locales/glpi.pot returns nothing; appliances have no data entity model to relate to (install/mysql/glpi-empty.sql:8935 glpi_appliances).", "topdesk": "unknown: the Gemeentelijk Gegevensmodel is not mentioned (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4224,12 +4226,12 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"Download de kaart met de knop [download SVG] ... De kaart volledig schaalbaar\" (read 2026-09-26). A map is downloaded as SVG for printing; placing it in Word or PowerPoint is a manual step. Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart > download SVG.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: the only diagram is the impact graph, whose Download writes PNG or JPEG (js/impact.js:2539, :2546); grep -rli 'docx\\|pptx\\|powerpoint' over src/ finds no Office export of views, only XLSX and ODS list output (src/Glpi/Search/Output/Xlsx.php).", "topdesk": "unknown: architecture views and Word or PowerPoint are not mentioned (0 hits for PowerPoint); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4254,12 +4256,12 @@ "vng-softwarecatalogus": "unknown: no data modelling is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'entity.relationship\\|uml' over src/ templates/ locales/glpi.pot returns nothing; databases are inventoried as instances and names (src/DatabaseInstance.php:43, src/Database.php:41, install/mysql/glpi-empty.sql:9468 glpi_databases) without entities or relations.", "topdesk": "unknown: no data entity or UML modelling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4284,12 +4286,12 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/gebruikersbeheer: \"Er opent zich een overzicht met alle geregistreerde gebruikers van uw organisatie ... inclusief wanneer zij voor het laatst hebben ingelogd\" (read 2026-09-26); https://www.softwarecatalogus.nl/: tip \"Controleer of alle gebruikers nog werkzaam zijn bij de gemeente of samenwerking\" (read 2026-09-26). A manual check, no review cycle. Reached on: Menu > Gebruikersbeheer.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'recertif\\|access review' over src/ templates/ locales/glpi.pot returns nothing; users carry last_login and validity dates (install/mysql/glpi-empty.sql:7813 last_login, :7866 begin_date, :7867 end_date) that an admin can search on, but there is no periodic review campaign.", "topdesk": "https://docs.topdesk.com/en/operator-licence-overview.html: the list of operators shows \"When the given operator was last active (meaning their last login)\" (read 2026-09-26). Input for a review; no periodic review process is described. Reached on: Operator licence overview." }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "partial" }, { @@ -4315,12 +4317,12 @@ "vng-softwarecatalogus": "unknown: no link to a register of processing activities is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'processing activit\\|gdpr' over src/ returns nothing; the records of processing plugin yild/gdprropa (tag 1.0.3, setup.php:56) supports GLPI 10 only.", "topdesk": "unknown: no register of processing activities is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4346,12 +4348,12 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"De leveranciersinformatie in de Softwarecatalogus is openbaar\" (read 2026-09-26); https://www.softwarecatalogus.nl/inkoopondersteuning%20standaarden: \"De gegenereerde bestekstekst kunt u gebruiken in uw offerte-uitvraag ... Als informatiebron is de GEMMA softwarecatalogus gebruikt\" (read 2026-09-26). Reached on: Supplier login > Productportfolio; Inkoopondersteuning.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: suppliers have no account or public product page (install/mysql/glpi-empty.sql:7067 glpi_suppliers); anonymous access covers only the FAQ (src/KnowbaseItem.php:131 use_public_faq).", "topdesk": "unknown: TOPdesk is a single-organisation tool; public supplier product information is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4377,12 +4379,12 @@ "vng-softwarecatalogus": "unknown: no value, cost or risk scoring is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'business value' over src/ locales/glpi.pot returns nothing; appliances carry no value, cost or risk score fields (install/mysql/glpi-empty.sql:8935 glpi_appliances), only the software ticket_tco figure (install/mysql/glpi-empty.sql:6872).", "topdesk": "unknown: no value, cost and risk scoring of applications is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4406,13 +4408,13 @@ "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #136 'Als CISO wil ik ons gemeentelijk pakketoverzicht kunnen controleren en vervolgens fiatteren'; no approval step for the landscape appears in the incumbent manuals (https://www.softwarecatalogus.nl/node/19703). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: approvals exist only on ITIL objects (src/CommonITILValidation.php:49, children TicketValidation and src/ChangeValidation.php:39); there is no sign off of the appliance list itself. A change could be used to carry an approval, which is not a catalogue sign off.", "topdesk": "unknown: a sign-off of the application list is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4436,13 +4438,13 @@ "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #82 'Als gebruik-raadpleger wil ik een register van verwerkingen kunnen genereren'; the incumbent exports only package, connection and IBD-foto files (https://www.softwarecatalogus.nl/Beschikbare%20downloads). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'processing activit\\|gdpr' over src/ returns nothing, so there is no register to generate; the report list (src/Report.php:77 to :111) has no such report.", "topdesk": "unknown: no register of processing activities is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4466,13 +4468,13 @@ "vng-softwarecatalogus": "Open PvE wens #50 (search) and #48 (register collective agreements incl. AVG and BIO terms); the incumbent lists signed addenda per supplier with a filter (https://www.softwarecatalogus.nl/addenda), which covers part of it. (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'collective agreement\\|raamovereenkomst' over src/ locales/glpi.pot returns nothing; contracts (install/mysql/glpi-empty.sql:1483) belong to the instance's own entities and nothing is shared across organisations.", "topdesk": "unknown: collective agreements across organisations are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4496,13 +4498,13 @@ "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #41 'relevante documenten zoals DPIA's, verwerkersovereenkomsten en pentesten kunnen delen zodat andere gemeenten hier eenvoudig gebruik van kunnen maken'; the incumbent only holds supplier test reports (https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: documents (src/Document.php:67) are visible only inside the instance through entities and profiles; anonymous access is limited to FAQ attachments when use_public_faq is on (src/Document.php:717), and there is no sharing with other organisations.", "topdesk": "unknown: assets hold documents in a Documents widget, but sharing them with other organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4526,13 +4528,13 @@ "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #46 'Als CISO wil ik de pakketten in mijn pakketoverzicht van een BBN classificatie voorzien'; BBN exists only as a GEMMA view per reference component per the news page (https://www.softwarecatalogus.nl/nieuws). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'confidentialit' over src/ templates/ locales/glpi.pot returns nothing and appliances have no availability, integrity or confidentiality fields (install/mysql/glpi-empty.sql:8935 glpi_appliances); only a repurposed dropdown or a custom asset field could hold it.", "topdesk": "unknown: no availability, integrity and confidentiality classification is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4556,13 +4558,13 @@ "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #31 'meerdere pakketten kunnen selecteren en deze in een overzichtelijke tabel naast elkaar vergelijken'; the incumbent offers filtered lists only (https://www.softwarecatalogus.nl/node/13683). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: any list can be narrowed to chosen entries with criteria (src/Glpi/Search/Input/QueryBuilder.php:72) and shows the chosen columns in one table, with installation counts per software on the software list; there is no dedicated compare view across products and no market data to compare (src/Glpi/Search/SearchEngine.php:101 searches own records only). Reached on: Assets > Software list with chosen columns.", "topdesk": "unknown: no product comparison table is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown" }, { @@ -4586,13 +4588,13 @@ "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #104 'Als functioneel beheerder wil ik me kunnen voordoen als een ander account'; not in the incumbent FAQ (https://www.softwarecatalogus.nl/node/16564). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: src/Session.php:2054 startImpersonating and :2113 stopImpersonating, allowed by src/Session.php:1995 canImpersonate for users with fewer rights and the Impersonate right (src/User.php:6235); the button 'Impersonate' is on the user form (src/User.php:2974). CHANGELOG.md 11.0.0 adds the dedicated right. Reached on: Administration > Users > user form, Impersonate.", "topdesk": "unknown: acting as another user is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown" }, { @@ -4616,13 +4618,13 @@ "vng-softwarecatalogus": "Open PvE wens #147; the incumbent shows whether a supplier signed the Groeipact Common Ground addendum (https://www.softwarecatalogus.nl/leveranciers), a supplier-level signal, not per product. (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: grep -rli 'common ground' over src/ templates/ locales/glpi.pot returns nothing; software and appliances carry no principle or goal declarations (install/mysql/glpi-empty.sql:6856 glpi_softwares).", "topdesk": "unknown: Common Ground is not mentioned; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4646,13 +4648,13 @@ "vng-softwarecatalogus": "2021 user survey suggestion 'Koppelingen automatisch bijwerken bij een nieuwe versie van pakket'; release 4.1 added a manual copy of a version including its connections (https://www.softwarecatalogus.nl/node/16564, FAQ A1). (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "source read at 11.0.9: installations can be moved to another version by the massive action src/Item_SoftwareVersion.php:179 move_version, but impact relations (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) point at the item and are never copied to a replacing version or appliance; grep -n 'Impact' src/SoftwareVersion.php returns nothing.", "topdesk": "unknown: versions of applications are not modelled; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -4677,13 +4679,13 @@ "vng-softwarecatalogus": "unknown: retention cleanup is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: closed tickets are purged after a per entity delay, src/Ticket.php:5363 cronPurgeTicket using install/mysql/glpi-empty.sql:2777 autopurge_delay, and documents left without any linked item are removed by src/Document.php:1713 cronCleanOrphansDocument (described at src/Document.php:1700); catalogue records such as appliances or contracts have no closed state or retention delay. Reached on: Administration > Entities > Assistance tab (automatic purge); Setup > Automatic actions." }, "note": "Mined from topdesk (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "partial" }, { "id": "land-dependent-fields", @@ -4707,13 +4709,13 @@ "vng-softwarecatalogus": "unknown: dependent fields are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: native forms show or hide questions on conditions (src/Glpi/Form/Condition/Engine.php:138, src/Glpi/Form/Condition/VisibilityStrategy.php:39), but options of one field do not filter by another on item forms; the open requests github.com/glpi-project/roadmap/discussions/414 (cascading filters) and /240 (custom field conditions) ask for it. Reached on: Administration > Forms, question conditions." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "partial" }, { "id": "land-change-entry-type", @@ -4737,13 +4739,13 @@ "vng-softwarecatalogus": "unknown: changing an entry type is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: the type of an appliance is an editable dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id), changeable in place or by massive update (src/MassiveAction.php:666); changing the itemtype itself (for example a custom asset to another definition) is not possible, since each custom asset class is bound to one definition (src/Glpi/Asset/Asset.php:113), and the open request github.com/glpi-project/roadmap/discussions/232 asks for it. Reached on: Management > Appliances, Type field." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "partial" }, { "id": "ins-ai-action-audit", @@ -4767,13 +4769,13 @@ "vng-softwarecatalogus": "unknown: no AI assistant is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: there is no AI assistant in core (grep -rliw 'llm\\|mcp' over src/ returns nothing); the history log (src/Log.php:48) records changes per user or API client, without any AI actor." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "no" }, { "id": "sec-multi-factor-sign-in", @@ -4827,13 +4829,13 @@ "vng-softwarecatalogus": "unknown: a password policy is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: Setup > General > Security enables a password policy (templates/pages/setup/general/security_setup.html.twig:46 use_password_security, :56 password_min_length, :63 password_need_number, :70 password_need_letter), enforced by src/User.php:7187 validatePassword with checks for length, digits, letters, capitals and symbols (src/User.php:7196 onwards), plus expiry settings (install/empty_data.php:380 password_expiration_delay). Reached on: Setup > General > Security." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "yes" }, { "id": "ops-change-risk-score", @@ -4857,13 +4859,13 @@ "vng-softwarecatalogus": "unknown: change management is not covered; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: changes carry manual urgency, impact and priority (install/mysql/glpi-empty.sql:659 urgency, :660 impact, :661 priority) and a free text impact analysis (:663 impactcontent); no score is computed from past outcomes or dependencies, and grep -rli 'risk' over src/Change.php returns nothing." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "no" }, { "id": "conn-auto-populate-dependencies", @@ -5083,7 +5085,7 @@ "name": "Record that your organisation uses a module, as a usage separate from the product itself.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", @@ -5101,7 +5103,7 @@ "note": "The usage schema models this separation properly, but no stackiq page creates or edits a usage: the ObjectModal accepts type 'usage' (src/modals/Modals.vue:38) yet nothing opens it. Usages are only read by the roadmap, compliance matrix and vulnerability views.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: municipality adds the supplier's package and version to its own landscape (\"om het pakket toe te voegen aan je omgeving\") (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E1 \"Leveranciers onderhouden de gegevens van hun producten ... Gemeenten en Samenwerkingen onderhouden de gegevens van het eigen applicatieportfolio\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten.", - "sap-leanix": "docs, intelligence competitor_features#48860 'Fact Sheet data model (Application / IT Component / Provider)' (2026-07-23): Structured fact sheets are the core inventory unit for applications, components and providers.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model: 'An organization uses an application' as a relation between organization and application fact sheets; https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines: 'Organizations are intended to address who is using certain applications' (read 2026-09-26). Reached on: Application fact sheet > Organizations relation.", "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", "topdesk": "unknown: one organisation per environment; a separate usage record is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", @@ -5115,7 +5117,7 @@ "name": "Bring over what was registered in the previous catalogue, so nobody types it again.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -5133,6 +5135,7 @@ "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", "topdesk": "unknown: no import from the VNG Softwarecatalogus is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: this is the previous catalogue itself; no import of an earlier registration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-fact-sheet-data-through-excel-file and https://help.sap.com/docs/leanix/ea/integration-api: bulk import from spreadsheets and a JSON based Integration API; no importer for a specific previous catalogue is documented (read 2026-09-26). Reached on: Inventory > Import; Integration API.", "glpi": "source read at 11.0.9: data from earlier GLPI versions is carried over by src/Update.php:172 doUpdates with the chain in install/migrations/ (update_0.85.x_to_0.90.0.php up to the 11.0 steps); data from another catalogue needs the separate datainjection plugin (pluginsGLPI/datainjection tag 2.15.11, inc/backendcsv.class.php). Reached on: web installer update; plugin Data injection." }, "pendingQuestion": "Is the data from the previous VNG Softwarecatalogus meant to be brought over by a one-off migration outside this repo (for example an OpenRegister register import of an export file)?" @@ -5161,7 +5164,7 @@ "note": "The connection model with direction and standard is complete, and the demo data ships six, but no stackiq page creates or edits one.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Selecteer vervolgens de betreffende pakketversie. De richting van het berichtenverkeer ... Selecteer vervolgens de betreffende standaard en versie\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > toevoegen.", - "sap-leanix": "docs, intelligence competitor_features#27421 'Integration Architecture' (2026-04-12): Visualize data flows and integration patterns between applications", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: 'Interfaces should have one provider application and could have multiple consumer applications', data flow direction incl. 'Bi-Directional', and 'type of transfer' (read 2026-09-26). Reached on: Inventory > Interface fact sheet.", "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", "topdesk": "https://docs.topdesk.com/en/hierarchy-of-relationships.html: \"When assets are linked with a link type , one of the assets often supplies a certain feature to another asset. The supplying asset therefore is the parent asset\" (read 2026-09-26). Direction via parent and child; no standard per relation. Reached on: Asset card > Relationships widget.", @@ -5195,6 +5198,7 @@ "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Geef bij status in productie of gepland aan\"; connections are registered in the organisation's own landscape (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; interfaces belong to one workspace, and a usage of a connection separate from its existence is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: an impact relation (install/mysql/glpi-empty.sql:1247) is a single fact in one instance; there is no separate usage record saying the organisation runs it, and grep -n 'usage' src/ImpactRelation.php returns nothing." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend let an organisation record the connections it runs, through /api/koppelingen-gebruik or the objects API?" @@ -5225,6 +5229,7 @@ "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A10: \"Een Samenwerking geeft aan welke gemeenten gebruik maken van een betreffende koppeling. Die gemeentenamen worden getoond\" (read 2026-09-26). Reached on: Alle koppelingen.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; each workspace is one customer's own, and connections run jointly with other organisations are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: relations live inside one instance (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and entities are subdivisions of one organisation (src/Entity.php:58); no cross organisation sharing of connections exists (grep -rli 'federat' src/ returns nothing)." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend show shared connections from /api/aangeboden-gebruik/deelnemers?" @@ -5255,6 +5260,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Referentiecomponenten aangegeven door leverancier ... Toegevoegde referentiecomponenten\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, VNG and municipal, no hits; the reference catalog offers business capability blueprints by industry (https://help.sap.com/docs/leanix/ea/reference-catalog) but GEMMA reference components are not mentioned (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; the only classification of an appliance is its type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." }, "pendingQuestion": "Does the Modules page's CnIndexPage create/edit dialog in nextcloud-vue 2.55.1 render module.referenceComponents (hideOnForm:true, items.$ref element in the AMEF register) as a working multiselect of reference components? nextcloud-vue's fieldsFromSchema (src/utils/schema.js:529) does not check hideOnForm." @@ -5285,6 +5291,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart.", "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'gemma\\|archimate' over src/ templates/ locales/glpi.pot returns nothing; the only diagram is the impact graph (src/Impact.php:252 displayGraphView)." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend render /api/views/{id} with include_gebruik, and is that frontend in scope for stackiq's column?" @@ -5315,6 +5322,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: cooperation packages: \"kies bij Organisaties welke gemeenten ... de betreffende applicatie gebruiken ... Het pakket verschijnt dan ook alleen op de lijst en kaart van de samenwerking en niet bij de gemeenten\" (read 2026-09-26). Drawing shared apart from own is not described. Reached on: Samenwerking > Pakketten > Organisaties.", "stackiq": "lib/Service/ViewService.php:1187 getDeelnamesGebruikData + :924 tags shared usage with _type='deelnames' and _sourceOrganization; lib/Service/ArchiMateExportService.php:3005 org export gives every nested application the same green fillColor, deelnames only get their own folder (:3086)", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, no hits; no partner overlay on a reference view is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no GEMMA views (grep -rli 'gemma' src/ returns nothing) and no partner sharing; the impact graph (src/Impact.php:1559 makeDataForCytoscape) draws one instance's items only." }, "pendingQuestion": "Does the external VNG frontend draw deelnames nodes differently from own usage on a GEMMA view?" @@ -5345,6 +5353,7 @@ "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/docs, /api/views/{viewId} -> lib/Controller/ViewController.php:82,218 (@NoAdminRequired) -> lib/Service/ViewService.php:108,166 read views from the AMEF register; GEMMA elements are element objects in the AMEF register, readable through the OpenRegister objects API", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no API over GEMMA in the catalogue is documented; GEMMA overviews are copied from GEMMA Online tables; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: the v2 API controllers (src/Glpi/Api/HL/Controller/, for example AssetController.php:149 /Assets) expose GLPI itemtypes only; grep -rli 'gemma' src/ returns nothing." }, "pendingQuestion": "Is the view API reachable without a Nextcloud login (no #[PublicPage] on ViewController), and does the row require public access?" @@ -5375,6 +5384,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"via de optie Voeg extra standaarden toe de gewenste standaard te selecteren ... Ondersteuning(gepland) en Compliancy\" (read 2026-09-26). Reached on: Supplier login > productversie > standaarden.", "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.standardVersion ($ref element, queryParams gemmaType=standaardversie) + compliancy.module + compliancy.standardGemma (string); src/manifest.json Komplianties /komplianties index on the voorzieningen register; ModuleDetail md-compliance object-list has allowCreate:false; module.standardVersions is hideOnForm", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; technology standards apply to tech stack items (https://help.sap.com/docs/leanix/ea/technology-standards-management-capabilities), declaring support for a version of an interoperability standard per application is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no standards model (grep -rli 'standaard' src/ locales/glpi.pot returns nothing); software versions (install/mysql/glpi-empty.sql:6900) carry no supported standard." }, "pendingQuestion": "On /komplianties, does the create form's standardVersion select (items $ref element, which lives only in the AMEF register) list standard versions, or does it resolve against the voorzieningen register and come back empty/404 as the Standaarden page did before its register fix?" @@ -5405,6 +5415,7 @@ "stackiq": "lib/Controller/AanbodController.php:200 acceptAanbod and :303 denyAanbod, lib/Service/AanbodService.php:289 checks the active organisation is aanbieder or afnemer then re-owns the object; routes appinfo/routes.php PUT /api/aanbod/{uuid}/accept, DELETE /api/aanbod/{uuid}/deny; also /api/aangeboden-gebruik/{id}/set-self and /deny", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: suppliers see \"Mijn gemeenten\" (who registered their packages) but accepting or declining a usage is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; suppliers have no role in a customer workspace, so accepting a claimed usage is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers have no login or role (install/mysql/glpi-empty.sql:7067 glpi_suppliers is a plain record; profiles in src/Profile.php:55 are for users), so no supplier can accept or decline a claimed usage." }, "pendingQuestion": "Does the external VNG Softwarecatalogus frontend (not in this repo) call PUT /api/aanbod/{uuid}/accept and /api/aangeboden-gebruik/{id}/set-self, and is that frontend part of what we ship?" @@ -5435,6 +5446,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle gemeenten helpt bijvoorbeeld in het verkrijgen van inzicht welke gemeenten dezelfde pakketten gebruiken ... Ook met betrekking tot een bepaald beleidsthema, referentiecomponent of standaard\" (read 2026-09-26). Reached on: Inlogmenu > Alle gemeenten / Alle pakketoverzichten.", "stackiq": "lib/Controller/ViewController.php (routes GET /api/views, /api/views/{viewId}) enriches GEMMA views with shared usage (deelnames); src/store/modules/view.js:89 calls it but no component imports that store", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; comparison with other customers' landscapes is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no reference components (grep -rli 'reference component' src/ returns nothing) and no data from comparable organisations, since each instance is standalone (src/Entity.php:58 entities are internal)." }, "pendingQuestion": "Does the external VNG frontend render /api/views with the deelnames enrichment, and does that count as a stackiq page?" @@ -5445,7 +5457,7 @@ "name": "See which organisations use a given application.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -5465,6 +5477,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Marktscans: \"kunnen ingelogde gemeenten of samenwerkingen zien bij welke collega-gemeenten betreffende pakketversie in het applicatielandschap staat (klik daarvoor op het getal boven Ingevuld door)\" (read 2026-09-26). Reached on: Package page > Ingevuld door.", "stackiq": "register :2656 usage (consumer, module); usage read rule lets aanbod-beheerder read usages where provider = own organisation (:3137); ModuleDetail md-related widget src/manifest.json:491; GET /api/koppelingen-gebruik/{uuid} and /api/gebruik in lib/Controller/AangebodenGebruikController.php, lib/Controller/GebruikController.php", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines: 'Organizations are intended to address who is using certain applications', within one customer's own business units, regions and legal entities, not across outside organisations (read 2026-09-26). Reached on: Application fact sheet > Organizations relation.", "glpi": "source read at 11.0.9: within one instance the version Summary tab shows installations per entity, src/Item_SoftwareVersion.php:850 showForVersionByEntity, and the installation list carries the entity column (src/Item_SoftwareVersion.php:484); organisations outside the instance are not visible. Reached on: Assets > Software > version > Summary tab." }, "pendingQuestion": "Does the generic 'related' widget on ModuleDetail list usage objects that point at the module (inverse relation), and for which roles?" @@ -5495,6 +5508,7 @@ "stackiq": "lib/Service/ReviewService.php:232 forces pending; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; src/views/settings/StackiqSettings.vue:98 ModerationQueue type=software-review via src/utils/adminApi.js; lib/Settings/register.d/catalog-ratings.json public read only matches status approved but every catalogue group reads all reviews and may create them", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no reviews are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; there are no reviews, so no review moderation is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: there are no product reviews (see mkt-reviews); the only moderation is knowledge base publication by rights on src/KnowbaseItem.php:57, unrelated to reviews." }, "pendingQuestion": "Does the installed OpenRegister let a catalogue user create a software-review with status=approved through /reviews (the generic create), bypassing ReviewService?" @@ -5505,7 +5519,7 @@ "name": "Keep your application landscape and connections hidden from suppliers.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "unknown", @@ -5524,6 +5538,7 @@ "stackiq": "register usage authorization (:3137) reads scoped to _organisation or consumer; aanbod-beheerder also reads usages where provider = own organisation; connection read (:3855) public when published and by provider; openspec/specs/vendor-visibility-rbac", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E2: \"Leveranciers kunnen alleen hun eigen applicatieversies die in gebruik zijn bij gemeenten en samenwerkingen zien ... overigens ziet de leverancier geen status-informatie. Die is vertrouwelijk\" (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/manage-workspace-access: 'If a workspace has activated Invitation Only: Visible if the user is invited to this workspace and has a role'; the workspace is 'a self-contained, customer-specific environment' (https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf) (read 2026-09-26). Reached on: Administration > Workspace access.", "glpi": "source read at 11.0.9: suppliers are records without accounts (install/mysql/glpi-empty.sql:7067 glpi_suppliers) and all data is visible only through the profiles and entities assigned to users (install/mysql/glpi-empty.sql:5917 glpi_profiles_users), so a supplier sees nothing unless given an account. Reached on: Administration > Profiles." }, "pendingQuestion": "Does the installed OpenRegister enforce the declared authorization.read match rules (e.g. {group: aanbod-beheerder, match: {provider: $organisation}}) on usage and connection reads?" @@ -5551,7 +5566,7 @@ "note": "The software is free and published entries are publicly readable, but the repo ships no hosted public catalogue; the public-facing frontend is the external VNG one.", "evidence": { "vng-softwarecatalogus": "unknown: public browsing is open (\"Iedereen kan de softwarecatalogus raadplegen\", FAQ E6) but no page states the use is free of charge; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden (read 2026-09-26)", - "sap-leanix": "docs, intelligence competitor_features#48871 'Cloud-only SaaS, per-application tiered pricing' (2026-07-23): GAP: no self-host; priced per application tier (400/600/1000 apps), considered expensive.", + "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: usage metric 'Application' counted for the subscription, add on products 'subject to additional subscription fees'; https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Application fact sheets are counted for pricing calculations' (read 2026-09-26)", "glpi": "source read at 11.0.9: LICENSE:1 GNU General Public License version 3, so any municipality or supplier can run it without licence fees; there is no free hosted public service, the paid cloud is GLPI Network by Teclib. Reached on: self hosted install.", "stackiq": "LICENSE (EUPL-1.2) and appinfo/info.xml: the app is free open source; catalogService and organization carry public read rules for published entries; module's public read also admits every object with registeredBy Supplier, a rule with no publication-date or status condition (lib/Settings/softwarecatalogus_register.json:7322-7327, corrected 2026-09-26); public intake POST /api/intake/register", "topdesk": "https://www.topdesk.com/en/pricing/: \"Essential ... £51 Per agent/month\", \"Engaged ... £72\", \"Excellent ... £101\" (read 2026-09-26)" @@ -5582,7 +5597,7 @@ "note": "You see an 'approaching end of support' badge when you open the roadmap. A pushed warning rests only on a register declaration, and that rule addresses catalogue admins and the version's managers, not the organisations using the application.", "evidence": { "vng-softwarecatalogus": "unknown: suppliers set a status \"Einde ondersteuning\" and municipalities are notified of supplier changes, but an advance warning before support ends is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/pakketversies (read 2026-09-26)", - "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | docs, intelligence competitor_features#27418 'Technology Risk Management' (2026-04-12): Track technology obsolescence and end-of-life risks", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/obsolescence-risk-management-monitor-mitigation: 'You can use automation features to initiate an end-of-life process for applications and alert the responsible individuals well before the end-of-life of an IT component' (read 2026-09-26). Reached on: Administration > Automations (end of life process).", "stackiq": "src/views/LifecycleRoadmapView.vue:73-86 EOL passed/approaching/withdrawn badges with EOL_WINDOW_DAYS=180 (:143); lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications eol-approaching (scheduled, dateEndSupport withinNext P180D, recipients software-catalog-admins + object-acl manage) is a declaration only; no notification code in lib (no INotificationManager use)", "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"…when a card date will be reached within a particular period of time\" (read 2026-09-26). Works on any date field, e.g. a self-defined end-of-support date; no built-in end-of-support. Reached on: Action Management > events.", "glpi": "source read at 11.0.9: alerts exist for dates GLPI stores, licence expiry (src/NotificationTargetSoftwareLicense.php:46 'Alarms on expired licenses'), contract end and notice (src/NotificationTargetContract.php:47) and warranty expiry (src/Infocom.php:651 cronInfocom); no end of support date exists on an application or version (install/mysql/glpi-empty.sql:6900 glpi_softwareversions). Reached on: Setup > Notifications; Setup > Automatic actions." @@ -5595,7 +5610,7 @@ "name": "Fill in end-of-support dates automatically from a public end-of-life feed.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -5612,7 +5627,7 @@ "featureConfidence": "high", "note": "The matcher is complete, but it is off by default, only an admin can switch it on, each module needs an eolProductSlug, and the feed data only exists when integriq's endoflife.date source is provisioned.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48863 'Technology risk & obsolescence (EOL/lifecycle)' (2026-07-23): Tracks technology lifecycle, end-of-life and obsolescence risk. | Rated partial because obsolescence tracking; source of dates not named.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-components-in-reference-catalog: 'When you link an IT component fact sheet to a catalog item, the fact sheet stays in sync with that metadata automatically. You no longer need to track vendor lifecycle dates manually'. Requires Technology Risk and Compliance; the catalog is SAP's own, not a public feed (read 2026-09-26). Reached on: IT Component fact sheet linked to the reference catalog.", "stackiq": "lib/BackgroundJob/EolSyncJob.php (registered appinfo/info.xml:101) + appinfo/routes.php:292-295 /api/eol-sync/* -> lib/Service/EolSyncService.php:145 run() reads eol_cycle objects via OpenRegister ObjectService (:328), stamps dateEndSupport on module versions via EolMatcherService; enabled defaults to false (lib/Service/SettingsService.php:7211); lib/Settings/connections.json eol-feed is a switch, off until enabled; the cycles are fetched by integriq's endoflife-date source", "topdesk": "unknown: no end-of-life feed is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: end-of-support comes from supplier input; no public feed is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -5626,7 +5641,7 @@ "name": "Record which application is planned to replace another.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "unknown", @@ -5646,6 +5661,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json usage.plannedReplacement ($ref module) + plannedReplacementDate; read by src/views/LifecycleRoadmapView.vue:400; no usage page in src/manifest.json and navigationStore.setModal('usage') is never called (src/modals/Modals.vue:38 lists usage but nothing opens it)", "topdesk": "unknown: no replacement link is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"geplande harmonisaties ... status gepland met bijbehorende datum ... de uit te faseren applicaties van die status worden voorzien inclusief datum\" (read 2026-09-26). No explicit replaces link. Reached on: Mijn softwarecatalogus > Pakketten > Planning.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options: 'analyze your target architecture landscape, provided that you have also modeled successors effectively'; roadmap report option 'showSuccessors' (https://help.sap.com/docs/leanix/ea/report-url-parameter-reference) (read 2026-09-26). Reached on: Fact sheet > Successor relation; Roadmap Report.", "glpi": "source read at 11.0.9: a software can be flagged as an 'Upgrade from' another software, templates/pages/assets/software.html.twig:46 to :50 (is_update with softwares_id, install/mysql/glpi-empty.sql:6864 and :6865); this records succession after the fact, with no planned replacement link for appliances. Reached on: Assets > Software form, Upgrade from." }, "pendingQuestion": "Is the external VNG Softwarecatalogus frontend (which writes usage objects) counted as part of stackiq for this row?" @@ -5671,7 +5687,7 @@ "providerHow": "read-from-code", "note": "The TIME classification is stored and reported per quadrant, but there is no page in stackiq where a user classifies an application.", "evidence": { - "sap-leanix": "docs, intelligence competitor_features#48862 'Application Portfolio Management' (2026-07-23): Rationalise, assess and plan the application portfolio (TIME/6R).", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/time: 'TIME stands for Tolerate, Invest, Migrate, and Eliminate. It categorizes applications based on their strategic value' (read 2026-09-26). Reached on: Application fact sheet > TIME classification.", "stackiq": "lib/Settings/softwarecatalogus_register.json usage.timeClassification enum Tolerate/Invest/Migrate/Eliminate + timeRationale + timeReviewDate; read by lib/Service/PortfolioReportService.php and rendered in src/views/organisaties/PortfolioReport.vue:112 quadrant chart; src/modals/object/ObjectModal.vue:178 has the enum select but is never opened for usage", "topdesk": "unknown: no TIME classification is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no TIME classification is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -5685,7 +5701,7 @@ "name": "Register a contract for a service with its number, type, term and cost.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -5705,7 +5721,8 @@ "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; their absence is not stated either; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1483 glpi_contracts with name, num (contract number), contracttypes_id, begin_date, duration, notice and renewal, and costs in install/mysql/glpi-empty.sql:1458 glpi_contractcosts. Reached on: Management > Contracts. Driven on the lab at 11.0.9 (2026-09-26): created \"Lab contract\" with number C-001, start date, 12 month duration and 1 month notice.", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Contract Number (mandatory) ... Type ... Start Date (mandatory) ... End Date (mandatory) ... Costs (Services)\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > New.", - "stackiq": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)" + "stackiq": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: contract fact sheet with 'Contract Number', 'Contract Pricing Type', lifecycle phases for start, notice and end, and licensing, maintenance and support costs, linked to applications and providers (read 2026-09-26). Reached on: Inventory > Contract fact sheet (contract extension)." }, "pendingQuestion": "Does the installed OpenRegister accept a catalogContract without the required usage (schema hardValidation false), and can the related-object picker create a usage inline?" }, @@ -5715,7 +5732,7 @@ "name": "Get warned before a contract expires.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "partial", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -5734,7 +5751,7 @@ "note": "The only expiry warning is a declared OpenRegister notification whose filter value 'Actief' never matches the English status 'Active', so even if OpenRegister dispatches it, no contract qualifies. No page shows contracts that are about to expire.", "evidence": { "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "docs, intelligence competitor_features#27427 'SaaS Management' (2026-04-12): Track SaaS usage, costs, and renewal dates | Rated partial because SaaS renewal dates.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/step-2-set-up-contract-lifecycle-automations: 'Prevent missed renewals through proactive notification workflows ... Enable timely decisions with escalation alerts before notice periods' (read 2026-09-26). Reached on: Administration > Automations (contract lifecycle).", "stackiq": "lib/Settings/softwarecatalogus_register.json:3255 x-openregister-notifications contract-expiry filters status equals 'Actief' but the status enum is Active/Expired/In negotiation (:3428), and the subject uses {{contractNummer}}/{{eindDatum}} while fields are contractNumber/endDate; Contracten quick filter 'Expiring / expired' filters status Expired only (src/manifest.json:527)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"To prevent the accidental extension of unwanted contracts, TOPdesk warns you when contracts are about to expire\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Reminder date Date on which an operator should be reminded about the contract, e.g. ahead of expiry\" (read 2026-09-26). Reached on: Contract card > Reminder date.", "glpi": "source read at 11.0.9: src/Contract.php:1092 cronContract computes end and notice dates and sends the events of src/NotificationTargetContract.php:47 (end of contract, notice, periodicity, periodicity notice); install/mysql/glpi-empty.sql:1508 glpi_contracts.alert sets which alerts apply. Reached on: Management > Contracts, Email alarms field; Setup > Notifications." @@ -5768,6 +5785,7 @@ "stackiq": "lib/Service/ContractApprovalService.php:254 submitForApproval dispatches OCA\\Decidiq\\Event\\DecisionRequestedEvent (fail-closed), :412 projectOutcome sets status Active only on approved; src/manifest.json:579 ContractApprovalPanel on ContractDetail; but register :3428 status enum incl. Active is an editable form field and approvalState (register.d/contracts-to-decidesk.json) is not readOnly; the declared x-openregister-lifecycle uses Dutch states 'In onderhandeling'/'Actief' that match no enum value", "topdesk": "https://docs.topdesk.com/en/registering-and-validating-contracts.html: \"Create a new Preliminary Contract card ... Validate the contract. You have created an active contract\" (read 2026-09-26). A validation step, no recorded approval decision. Reached on: Contract card > Validate Contract.", "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; contracts carry a renewal decision field and fact sheets a quality seal approval (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model), but gating a contract's activation on a recorded approval is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -n 'alidation' src/Contract.php returns nothing and no ContractValidation class exists; approvals exist only for ITIL objects (src/ChangeValidation.php:39), and the contract status is a free dropdown (install/mysql/glpi-empty.sql:1512 states_id)." }, "pendingQuestion": "Does the installed OpenRegister enforce x-openregister-lifecycle transitions on catalogContract.status, given its states are Dutch ('Actief') and the enum is English ('Active')?" @@ -5778,7 +5796,7 @@ "name": "See which organisations and usages are exposed to a vulnerability.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -5796,6 +5814,7 @@ "stackiq": "src/utils/vulnerabilityExposure.js:54 in-production join vulnerability.modules -> usage.module -> usage.consumer; count shown in the list (src/views/KwetsbaarhedenView.vue:111); per-organisation rows in VulnerabilityExposurePanel on KwetsbaarheidDetail tab (src/manifest.json:997), but a list row opens the edit modal, not the detail page (KwetsbaarhedenView.vue:417)", "topdesk": "unknown: vulnerabilities are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/searching-for-sbom-library-components-by-package-url: 'Vulnerability remediation tracking: Retrieve the business applications linked to a vulnerable component ... assess the blast radius of a pkg:maven/org.apache.logging.log4j/log4j-core vulnerability'. Only for self-built software with SBOMs (read 2026-09-26). Reached on: SBOM explorer and component search API (Technology Risk and Compliance).", "glpi": "source read at 11.0.9: no vulnerability data exists (grep -rli 'cve' src/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74), so exposure cannot be derived even though installations per entity are known (src/Item_SoftwareVersion.php:850)." }, "pendingQuestion": "Is KwetsbaarheidDetail reachable from any page, for example by clicking a vulnerability in ModuleDetail's Related panel?" @@ -5806,7 +5825,7 @@ "name": "Get an alert when a vulnerability is reported for software you use.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "no", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -5826,6 +5845,7 @@ "stackiq": "register.json:1622 x-openregister-notifications 'vulnerability-reported' on vulnerability, trigger created, channels nc-notification + email, recipients group software-catalog-admins and object-acl manage (a declaration only)", "topdesk": "unknown: vulnerabilities are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/api-updates-sbom-async-processing: asynchronous SBOM processing 'will allow us to add additional post-processing mechanisms in the future, such as vulnerability checks. Though there's no established timeline' (read 2026-09-26)", "glpi": "source read at 11.0.9: no vulnerability events among notification targets; software notifications are licence expiry only (src/NotificationTargetSoftwareLicense.php:46)." }, "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications 'vulnerability-reported' rule on the vulnerability schema, and can recipients be the consumers of the affected modules?" @@ -5856,6 +5876,7 @@ "stackiq": "lib/Controller/IntakeController.php:74 PublicPage + AnonRateLimit(5/h) on POST /api/intake/register; lib/Service/IntakeService.php:146 forces registrationStatus pending, publicationDate null; no caller in src/. Separately, organization authorization.create includes 'public' (register :2467)", "topdesk": "unknown: organisations signing themselves up is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Als leverancier kunt u zich aanmelden door de volgende gegevens te sturen naar softwarecatalogus@vng.nl\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-gemeente-aanmelden: cooperations without an account \"vraag deze dan aan door een mail te sturen\" (read 2026-09-26). Sign-up by e-mail, no online form.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; workspaces are provisioned per customer (https://help.sap.com/docs/leanix/ea/sap-for-me-super-cloud-admin-for-workspace-provisioning), self sign up of organisations is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers are created by staff only (src/Supplier.php:75 sets is_active on add from the staff form) and there is no public sign up page among front/ pages (front/lostpassword.php and front/initpassword.php are the only anonymous account pages)." }, "pendingQuestion": "Does the external VNG frontend post to /api/intake/register, and does OpenRegister's generic public create on organization let an anonymous caller set registrationStatus/status/publicationDate directly?" @@ -5866,7 +5887,7 @@ "name": "Turn a contact person into a user account with the right role automatically.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "partial", @@ -5886,6 +5907,7 @@ "stackiq": "lib/Controller/ContactpersonenController.php:393 convertToUser -> lib/Service/Stackiq/ContactPersonHandler.php:292 createUserAccount reads objectData['email'] (:299); automatic path lib/EventListener/StackiqEventListener.php -> lib/Service/ContactpersoonService.php:128 also reads contactData['email']; contactPerson schema (:1788) declares no email (identity moved to Nextcloud Contacts via contactsUid); UI: src/components/ContactpersonenList.vue:97 'Convert to User' inside OrganisatieCard", "topdesk": "https://docs.topdesk.com/en/step-2, operator-import-with-a-linked-person.html: \"To create operators with a person card linked via the Supporting Files import\" (read 2026-09-26); https://docs.topdesk.com/en/assigning-or-editing-self-service-portal-login-data.html: \"select the TOPdesk field Has access to Self-Service Portal and map it\" (read 2026-09-26). Reached on: Supporting Files imports.", "vng-softwarecatalogus": "unknown: no conversion of contact persons into accounts is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/users-overview: 'You can also invite contacts from the Subscriptions tab on a specific fact sheet'; roles come from the invitation or SSO, not automatically from the contact's role (read 2026-09-26). Reached on: Fact sheet > Subscriptions > Invite.", "glpi": "source read at 11.0.9: contacts (src/Contact.php:45) and users are separate itemtypes with no conversion action; user accounts come from manual creation, LDAP import (src/AuthLDAP.php:59) or authorisation rules (src/RuleRight.php:297 profile action)." }, "pendingQuestion": "Does a contactPerson created via the current form reach createUserAccount with an email (e.g. resolved from Nextcloud Contacts by contactsUid somewhere I did not find), or does conversion fail for every post-migration contact?" @@ -5916,6 +5938,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"Handleiding beheer gemeente-samenwerking ... Samenwerkingsverbanden die als doel hebben om de applicatielandschappen van de aangesloten gemeenten te harmoniseren\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: cooperation selects the member municipalities per package (read 2026-09-26). Reached on: Samenwerking account > Pakketten.", "stackiq": "register organization.type 'Collaboration' + participants/deelnames (:2236); usage.participants (:2718); shared landscape endpoint GET /api/aangeboden-gebruik/deelnemers (lib/Controller/AangebodenGebruikController.php) has no caller in src/", "topdesk": "unknown: cooperations of organisations are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; cooperations of separate organisations sharing a landscape are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: entities form a tree (src/Entity.php:58 extends CommonTreeDropdown) and records flagged recursive are shared with all child entities (src/Appliance.php:325 is_recursive), so a parent entity can hold a landscape shared by several subordinate units; there is no cooperation of independent organisations. Reached on: Administration > Entities; Appliance Child entities field." }, "pendingQuestion": "Does the external VNG frontend show a cooperation's shared landscape from /api/aangeboden-gebruik/deelnemers?" @@ -5926,7 +5949,7 @@ "name": "Keep each organisation's records visible only to that organisation unless published.", "origin": "own-code", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -5945,7 +5968,8 @@ "glpi": "source read at 11.0.9: every query on entity scoped items is restricted to the user's active entities, src/DbUtils.php:920 getEntitiesRestrictCriteria; records carry entities_id and is_recursive (install/mysql/glpi-empty.sql:8937 and :8938 on glpi_appliances), so an entity's records stay invisible to other entities unless shared down the tree. Reached on: entity selector in the header.", "stackiq": "register authorization.read rules with {match: {_organisation: $organisation}} on catalogContract (:3474), contactPerson (:1788), usage (:3137), connection (:3855); public reads only for published entries; lib/Controller/ContactpersonenController.php:293 org guard on the custom endpoint", "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"To restrict access to specific data, link the operator to branch, operator, or category filters\" (read 2026-09-26). Reached on: Operator card > filters.", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Alle gegevens ingevoerd door de gemeenten en samenwerkingen zijn alleen zichtbaar voor gemeentelijke raadplegers en beheerders\"; E2 \"Ingelogde gemeenten en samenwerkingsverbanden kunnen de applicatielandschappen en koppelingen van collega-gemeenten ... bekijken\" (read 2026-09-26)" + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Alle gegevens ingevoerd door de gemeenten en samenwerkingen zijn alleen zichtbaar voor gemeentelijke raadplegers en beheerders\"; E2 \"Ingelogde gemeenten en samenwerkingsverbanden kunnen de applicatielandschappen en koppelingen van collega-gemeenten ... bekijken\" (read 2026-09-26)", + "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: 'Virtual workspaces to control users' read and edit permissions for fact sheets and their content in a federated organization'; https://help.sap.com/docs/leanix/ea/virtual-workspaces-configuration (read 2026-09-26). Reached on: Administration > Virtual Workspaces." }, "pendingQuestion": "Does the installed OpenRegister evaluate authorization.read match rules with $organisation on the generic object list and detail endpoints the stackiq pages use?" }, @@ -5975,6 +5999,7 @@ "stackiq": "lib/Service/Stackiq/ContactPersonHandler.php:646 first contact of an organisation gets the organisation-admin groups; lib/Service/Stackiq/HierarchyHandler.php:79 ensureOrganizationBeheerder and :130 setupManagerRelationships make later users report to the primary beheerder", "topdesk": "unknown: first-user administrator rules are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/17042: \"Vanuit de gemeente is minimaal één gebruiker aangewezen als beheerder. Deze gebruiker kan nieuwe accounts aanmaken voor collega's\" (read 2026-09-26). Reached on: Gebruikersbeheer.", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; admins invite and manage users (https://help.sap.com/docs/leanix/ea/managing-users), but making an organisation's first user its administrator is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: an administrator can delegate user management per entity with a profile holding user rights, and GLPI stops a delegate from granting a profile stronger than their own, src/Profile.php:744 currentUserHaveMoreRightThan and src/Profile.php:679 getUnderActiveProfileRestrictCriteria; nothing makes the first user of an organisation its administrator automatically. Reached on: Administration > Users > Authorizations tab." }, "pendingQuestion": "Same as org-contact-to-account: does conversion get an email for a post-migration contact?" @@ -5985,7 +6010,7 @@ "name": "Let anyone browse the published catalogue without signing in.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -6005,6 +6030,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Iedereen kan de softwarecatalogus raadplegen ... De gegevens ingevoerd door de leveranciers zijn openbaar\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketten: package list readable without login (read 2026-09-26). Reached on: Alle pakketten.", "stackiq": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public on publicationDate<=$now (and, separately, on registeredBy=Supplier); lib/Settings/softwarecatalogus_register.json:1559 catalogService same; suite read is plain 'public' (lib/Settings/softwarecatalogus_register.json:1270). No stackiq route is #[PublicPage] except intake/review aggregate/gebruik (lib/Controller/GebruikController.php:102 returns an empty envelope to anonymous callers). The app's pages are all behind Nextcloud login (appinfo/routes.php:313 SPA catch-all).", "topdesk": "unknown: the Self-Service Portal requires a login per the SSP login settings; public browsing of assets is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/portal-faqs: portals make data 'available to a broad audience outside the IT organization ... an Application Portal that is accessible to everyone'. Whether portal visitors must sign in is not stated (read 2026-09-26). Reached on: Administration > Self Service Portal.", "glpi": "source read at 11.0.9: the only anonymous content is the public FAQ, gated by use_public_faq (src/KnowbaseItem.php:131, src/Document.php:717); asset, appliance and software lists all require a session (src/Glpi/Controller/GenericListController.php checks canView)." }, "pendingQuestion": "Does the installed OpenRegister honour the {group: public, match: {publicationDate: {$lte: $now}}} read rule on module/catalogService for an anonymous GET /apps/openregister/api/objects, and which public frontend (the external VNG Softwarecatalogus site) is the intended browse surface?" @@ -6033,7 +6059,8 @@ "glpi": "source read at 11.0.9: the v2 API routes without authentication are only the index, documentation and getting started pages, src/Glpi/Api/HL/Controller/CoreController.php:301, :322, :397, :407; all data routes require OAuth or session auth, and there is no supplier offering to expose.", "stackiq": "Anonymous read of the supplier offering depends on declared rules: lib/Settings/softwarecatalogus_register.json:7307 module read includes public on publicationDate<=$now and on registeredBy=Supplier; lib/Settings/softwarecatalogus_register.json:1559 catalogService public on publicationDate. Stackiq's own offering endpoint lib/Controller/AanbodController.php (routes.php:202) is authenticated-only (@NoAdminRequired + in-body guard). Rate limit only on GebruikController (#[AnonRateLimit]).", "topdesk": "unknown: the REST API requires an operator or API account; a public API is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", - "vng-softwarecatalogus": "unknown: no public API is documented; public data is offered as CSV downloads; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no public API is documented; public data is offered as CSV downloads; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; all APIs authenticate with workspace tokens (https://help.sap.com/docs/leanix/ea/authentication-to-sap-leanix-services), a public API over a supplier offering is not documented (read 2026-09-26)" }, "pendingQuestion": "Does the installed OpenRegister execute the module/catalogService public read rules for anonymous API callers, and is any API key or rate limit applied to that public surface?" }, @@ -6043,7 +6070,7 @@ "name": "Show catalogue content on a shared external portal next to other apps' content.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", @@ -6061,6 +6088,7 @@ "stackiq": "lib/Portal/PortalContributionProvider.php:130 getContribution() declares read-only, organisation-scoped collections (catalogService, usage, catalogContract, compliancy) for the vendor-org and participant-org audiences. Portaliq discovers it by FQCN from the Stackiq in appinfo/info.xml (portaliq lib/Contribution/PortalProviderLocator.php:49/77). No info.xml dependency; inert without portaliq.", "topdesk": "unknown: no shared external portal is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no external portal integration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://updates.leanix.net/announcements/embed-reports-diagrams-into-portals (2025-12-22): 'Portals can also serve as the primary entry point for business users ... diagrams and reports ... can now be added to portals'; https://help.sap.com/docs/leanix/ea/portals (read 2026-09-26). Reached on: Portals.", "glpi": "source read at 11.0.9: no embeddable widget or external portal integration for catalogue content; the self service interface (src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45) is GLPI's own helpdesk portal and grep -rli 'iframe embed\\|oembed' over src/ returns nothing." }, "pendingQuestion": "Does the installed portaliq render stackiq's contribution (its PortalProviderLocator iterating installed apps), and is that portal live for any stackiq customer?" @@ -6071,7 +6099,7 @@ "name": "Let an AI assistant query and update the catalogue through a tool interface.", "origin": "own-code", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "no", @@ -6089,6 +6117,7 @@ "stackiq": "No MCP, tool-provider, TaskProcessing or ContextChat code in stackiq lib/ or src/ (grep 'mcp|ToolProvider|assistant|TaskProcessing|ContextChat' in lib/ finds nothing). OpenRegister ships a generic MCP endpoint (openregister appinfo/routes.php:1969 /api/mcp/v1/discover and the JSON-RPC endpoint) over all registers.", "topdesk": "https://tip.topdesk.com/c/200-ai-mcp-based-service-: roadmap card in column \"Building\", \"Model Context Protocol (MCP-based service) allows secure, controlled connectivity between your TOPdesk environment and LLM-powered assistants\" (read 2026-09-26); the shipped TOPdesk Robin works inside tickets (https://docs.topdesk.com/en/td-robin-for-operators.html).", "vng-softwarecatalogus": "unknown: no assistant or tool interface is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/mcp-server-toolsets: toolset 'inventory ... Get fact sheet information', with create tools for surveys, architecture decisions, diagrams and automations; no tool to update fact sheet fields is listed (read 2026-09-26). Reached on: MCP server (https://mcp.leanix.net/services/mcp-server/v1/mcp).", "glpi": "source read at 11.0.9: grep -rli 'mcp\\|model context\\|openai\\|llm' over src/ returns nothing; AI tool access would go through the generic v2 API (src/Glpi/Api/HL/Controller/AssetController.php:149) with no tool interface of its own." }, "pendingQuestion": "Does OpenRegister's MCP server expose the voorzieningen register's objects (module, catalogService, organization) for read and write to an AI client with a stackiq user's rights?" @@ -6099,7 +6128,7 @@ "name": "Notify another system automatically when a catalogue entry changes.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -6117,6 +6146,7 @@ "stackiq": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909).", "topdesk": "https://docs.topdesk.com/en/let-your-topdesk-talk-to-other-applications.html: \"Send a request from TOPdesk to another program ... This way you can create an integration with almost any software that has an API\" (read 2026-09-26) triggered by card events (https://docs.topdesk.com/en/events-that-trigger-actions.html). Reached on: Action Management > action sequences.", "vng-softwarecatalogus": "unknown: notifications go to people by mail and inbox, no system webhooks are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/webhooks: 'Webhooks let you receive updates about events as they happen in near real time ... PUSH webhooks : As events occur in SAP LeanIX , they're sent through HTTP POST requests to the specified target URL' (read 2026-09-26). Reached on: Administration > Webhooks.", "glpi": "source read at 11.0.9: src/Webhook.php:64 Webhook sends HTTP calls on new, update and delete events (src/Webhook.php:311 getDefaultEventsList) for management itemtypes including Appliance, Budget, Contact and others (src/Webhook.php:398). Reached on: Setup > Webhooks (src/Html.php:1331). Driven on the lab at 11.0.9 (2026-09-26): Setup > Webhooks (/front/webhook.php) lists webhooks with type, event and category." }, "pendingQuestion": "Can a flow created on stackiq's Flows page be triggered by object.updated on a catalogue schema and make an outbound HTTP call to an external system?" @@ -6127,7 +6157,7 @@ "name": "Look back at who changed what in the catalogue, and when.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "yes", @@ -6147,7 +6177,8 @@ "glpi": "source read at 11.0.9: src/Appliance.php:58 dohistory is true and src/Appliance.php:112 adds the Historical tab (src/Log.php:48 Log), recording who changed which field and when. Reached on: Management > Appliances > Historical tab. Driven on the lab at 11.0.9 (2026-09-26): the appliance Historical tab listed two entries, including the contract link made by glpi.", "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"History widget : shows both present and past changes that have been made to an asset\" (read 2026-09-26); https://docs.topdesk.com/en/cards-in-call-management.html: \"Audit trail tab Previous events while processing this call\" (read 2026-09-26). Reached on: Asset card > History widget.", "stackiq": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object.", - "vng-softwarecatalogus": "unknown: only a \"Laatst gewijzigd\" date on supplier pages and a mutation date in exports are shown; who changed what is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: only a \"Laatst gewijzigd\" date on supplier pages and a mutation date in exports are shown; who changed what is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets: the fact sheet change log shows 'Old Value / New Value', 'User', 'Time' and 'Entries in the log cannot be deleted manually' (read 2026-09-26). Reached on: Fact sheet > History log." }, "pendingQuestion": "Is OpenRegister's audit trail enabled for the voorzieningen register on a default install, so the History tab shows entries?" }, @@ -6177,6 +6208,7 @@ "stackiq": "src/composables/useLiveCollections.js:40 subscribes via the library's useObjectSubscription; used in src/views/KwetsbaarhedenView.vue:197, LicensePostureView.vue:209, LifecycleRoadmapView.vue:184, ComplianceMatrixView.vue:326, PortfolioReport.vue:323. The standard index pages (Contracts, Organisations and others) rely on whatever the library's CnIndexPage does.", "topdesk": "unknown: live list updates are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no live list updates are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; target architecture diagrams apply changes immediately (https://help.sap.com/docs/leanix/ea/working-with-fact-sheets-in-diagrams), but a self refreshing inventory list is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'websocket\\|EventSource' over src/ finds only src/Glpi/Api/HL/Controller/NotificationController.php:303 'websocket: Not used by GLPI core'; lists refresh on reload only." }, "pendingQuestion": "Does the installed OpenRegister publish or-collection-{register}-{schema} events over a transport (notify_push or SSE) that the nc-vue liveUpdatesPlugin receives, so these pages update without a reload?" @@ -6187,7 +6219,7 @@ "name": "Receive in-app notifications about changes that concern you.", "origin": "own-code", "vng-softwarecatalogus": "yes", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial", "topdesk": "partial", @@ -6207,7 +6239,8 @@ "glpi": "source read at 11.0.9: besides mail there is a browser notification mode, src/NotificationAjax.php:42 and src/Notification_NotificationTemplate.php:56 MODE_AJAX, but it only carries events that notification targets define (tickets, changes, contracts, licences, saved search alerts and similar); changes to an appliance raise no notification event. Reached on: Setup > Notifications > Browser followups configuration.", "stackiq": "Only declarations: x-openregister-notifications on vulnerability (lib/Settings/softwarecatalogus_register.json:1622), usage (:2662), catalogContract (:3253), software-review (:3962), module (:6781), moduleVersion (:7652). Stackiq has no INotifier or notification code of its own (grep in lib/). The contract-expiry rule filters status equals 'Actief' (lib/Settings/softwarecatalogus_register.json:3255) while the enum is Active/Expired/In negotiation, so it can never match.", "topdesk": "https://docs.topdesk.com/en/topdesk-mobile.html: \"change your notification settings\" in the mobile app (read 2026-09-26); https://docs.topdesk.com/en/action-management.html: \"specific mobile alerts for operators\" (read 2026-09-26). Mostly email and mobile alerts, no in-app inbox described. Reached on: TOPdesk Mobile; Action Management.", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Gemeenten, samenwerkingen, en leveranciers hebben nu rechtsboven bij het inlogmenu een inbox-symbool met daarbij het aantal nieuwe berichten\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E17 \"De softwarecatalogus bevat een notificatievoorziening en een inbox voor gemeenten en samenwerkingen\" (read 2026-09-26). Reached on: Inlogmenu > Inbox." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Gemeenten, samenwerkingen, en leveranciers hebben nu rechtsboven bij het inlogmenu een inbox-symbool met daarbij het aantal nieuwe berichten\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E17 \"De softwarecatalogus bevat een notificatievoorziening en een inbox voor gemeenten en samenwerkingen\" (read 2026-09-26). Reached on: Inlogmenu > Inbox.", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/notifications: 'Notification Channels ... Email : This is the primary channel for notifications ... Microsoft Teams', for fact sheet updates, subscriptions, to-dos and surveys; no in-app channel is listed (read 2026-09-26). Reached on: User menu > My Settings > Notifications." }, "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications rules on vulnerability, software-review, moduleVersion and the scheduled rules on catalogContract/usage/module, as Nextcloud notifications to the listed recipients?" }, @@ -6217,7 +6250,7 @@ "name": "Extend the product with plugins installed from a marketplace.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes", "topdesk": "partial", @@ -6235,7 +6268,8 @@ "glpi": "source read at 11.0.9: src/Glpi/Marketplace/View.php:53 marketplace view at front/marketplace.php (src/Glpi/Marketplace/View.php:103) and src/Glpi/Marketplace/Controller.php:64 download and install of plugins; src/Glpi/Marketplace/View.php:185 notes that a registration, at least a free one, is required. Reached on: Setup > Plugins > Marketplace. Driven on the lab at 11.0.9 (2026-09-26): Setup > Plugins > Marketplace, Discover tab: \"A registration, at least a free one, is required to use marketplace\"; plugins can still be installed by hand from their repositories.", "topdesk": "https://marketplace.topdesk.com/: \"Showing all 133 results\" of integrations (read 2026-09-26); https://docs.topdesk.com/en/exporting-and-importing.html: \"import an action sequence example from the TOPdesk Marketplace\" (read 2026-09-26). Integrations and action-sequence templates, not installable plugins. Reached on: TOPdesk Marketplace.", "stackiq": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items.", - "vng-softwarecatalogus": "unknown: no plugins are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no plugins are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/extension-hub: 'The SAP LeanIX extension hub is a centralized location where you can discover and install ready-to-use extensions for your SAP LeanIX workspace. These include meta model extensions, surveys, and custom reports'; public hub at https://exthub.leanix.net/en (read 2026-09-26). Reached on: Extension Hub." }, "pendingQuestion": "Is a store registry configured on a default install, and are any stackiq configuration sets published to it?" }, @@ -6261,13 +6295,13 @@ "vng-softwarecatalogus": "unknown: field-level permissions are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: custom fields of custom asset types can be made read only or hidden per profile, src/Glpi/Asset/CustomFieldType/AbstractType.php:79 'Readonly for these profiles' and :80 'Hidden for these profiles'; ITIL templates hide or lock ticket fields (src/ITILTemplateHiddenField.php:43, src/ITILTemplateReadonlyField.php:43). Core Appliance and Software fields have rights per itemtype only (src/Appliance.php:59 rightname). Reached on: Setup > Asset definitions > Fields; Assistance templates." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", "bluedolphin": "unknown", - "glpi": "unknown" + "glpi": "partial" } ] } From 4d6fb66db022a716afb0e6f453f0b9727ecd5377 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:54:23 +0200 Subject: [PATCH 10/12] feat(parity): LeanIX and BlueDolphin read 2026-09-26, 11 more demand rows, sources for all five systems --- openspec/parity/capabilities.json | 920 ++++++++++++++++++++++++------ 1 file changed, 738 insertions(+), 182 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index 87423ff5..de87c34c 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -75,17 +75,90 @@ "key": "sap-leanix", "name": "SAP LeanIX", "vendor": "SAP", - "readOn": "2026-07-23", + "readOn": "2026-09-26", "evidenceGrade": "docs-only", - "unknownReason": "Not covered by the 24 intelligence rows for this system (docs passes dated 2026-04-12 and 2026-07-23); no trial was opened." + "unknownReason": "The public SAP LeanIX documentation, announcements and roadmap do not cover these capabilities; GEMMA and BIO rows stay unknown because no LeanIX page mentions either.", + "readNote": "Public SAP LeanIX documentation read 2026-09-26 through help.sap.com public JSON endpoints, the updates.leanix.net announcements and the Productboard roadmap card data at roadmap.leanix.net. No trial, no login.", + "sources": { + "docs": "https://help.sap.com/docs/leanix/ea", + "sourceRepo": null, + "featurePage": "https://www.leanix.net/en/products/application-portfolio-management", + "featureRequests": "https://roadmap.leanix.net/", + "issueTracker": null, + "roadmap": "https://roadmap.leanix.net/", + "changelog": "https://updates.leanix.net/", + "apiReference": "https://help.sap.com/docs/leanix/ea/sap-leanix-apis", + "marketplace": "https://exthub.leanix.net/en", + "pricing": "https://www.leanix.net/en/enterprise-architecture/pricing", + "accessibilityStatement": "https://www.leanix.net/en/enterprise-architecture/accessibility", + "securityDocs": "https://www.leanix.net/en/products/security-and-trust", + "demoInstance": null, + "community": "https://community.leanix.net/", + "reviews": "https://www.peerspot.com/products/leanix-reviews", + "videos": "https://www.youtube.com/@SAPLeanIX", + "caseStudies": "https://www.leanix.net/en/customers/success-stories", + "partnerDirectory": null, + "trainingCurriculum": "https://learning.sap.com/products/business-transformation-management/leanix", + "jobPostings": null, + "tenders": null, + "nullReasons": { + "sourceRepo": "Closed source SaaS; only a public reporting library exists (github.com/leanix/leanix-reporting, named in https://help.sap.com/docs/leanix/ea/reporting-framework-and-cli), not the product source.", + "issueTracker": "No public issue tracker; bugs and configuration requests go to SAP for Me, which needs a login (stated in the 2026 product update newsletters on updates.leanix.net).", + "demoInstance": "No public demo instance; https://www.leanix.net/en/demo-eam is a demo request form, and sandbox workspaces are a paid add on.", + "partnerDirectory": "https://www.leanix.net/en/partner-program explains the partner program but no browsable partner directory was found; /en/partner and /en/partners/find-a-partner answer 404.", + "jobPostings": "LeanIX jobs are listed on jobs.sap.com (linked from the LeanIX home page), which answered 403 to scripted reads, so it could not be confirmed today.", + "tenders": "no tender in the intelligence database names LeanIX in its name, description or requirement text (searched 2026-09-26); category tenders for architecture tools (Helmond 398728, Breda 413833, Noord-Brabant 434026, Zutphen 363416, Apeldoorn 321765) name no product" + }, + "readHow": "All checks on 2026-09-26. docs: help.sap.com is a JavaScript app, so the 663 pages of the LeanIX EA deliverable were read in full through the portal's public JSON endpoints (http.svc/deliverableMetadata and http.svc/pagecontent, curl, HTTP 200) and cited by their readable URLs; docs-eam.leanix.net and docs.leanix.net redirect there (curl -L, 200). changelog: updates.leanix.net (LaunchNotes) index pages 1 to 25 and all 171 announcements from pages 1 to 17 (Sept 2025 to Sept 2026) fetched with curl, 200. roadmap and featureRequests: roadmap.leanix.net is a Productboard portal whose card data (392 cards, Voting, In progress, On roadmap, Released) is embedded in the page and was parsed; new idea submissions are allowed per the portal config and the product updates say to share feature ideas there; card URLs follow the /c/- form the vendor uses inside its own card texts; ideas.leanix.net did not resolve (curl 000); Productboard answers 200 for any path so card paths were confirmed only through the embedded data. featurePage, pricing, accessibilityStatement, securityDocs, caseStudies: curl 200 on links taken from the leanix.net home page (pricing gives the model, per application, no public prices; the accessibility page is titled 'Accessibility Statement'). apiReference: help page read through the JSON endpoint; the OpenAPI explorer itself is inside a workspace behind login. marketplace: store.leanix.net redirects to exthub.leanix.net/en, curl 200. community: curl 200. reviews: peerspot page title 'LeanIX reviews 2026', curl 200; Gartner Peer Insights, G2 and TrustRadius answered 403. videos: YouTube page title 'SAP LeanIX - YouTube', curl 200. trainingCurriculum: learning.sap.com, curl 200. Also read: www.leanix.net/en/legal/commercial and its PDFs Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf and Operational-Terms-Exhibit-v.2.0.pdf (curl 200, text extracted). Not readable: www.sap.com trust center and accessibility pages (403), jobs.sap.com (403), g2.com, gartner.com, trustradius.com (403). The browser connection browser-3 was used only to discover the help portal's JSON endpoints; no login and no trial were used. Ruling 2026-09-26: LeanIX was read through help.sap.com public JSON endpoints and the Productboard roadmap card data." + } }, { "key": "bluedolphin", "name": "BlueDolphin", "vendor": "ValueBlue", - "readOn": "2026-07-23", + "readOn": "2026-09-26", "evidenceGrade": "docs-only", - "unknownReason": "Not covered by the 22 intelligence rows for this system (docs passes dated 2026-04-12 and 2026-07-23); no trial was opened." + "unknownReason": "The public BlueDolphin help centre and product news do not cover these capabilities; GEMMA and BIO rows stay unknown except arch-ggm-link, which rests on a third-party Gemeente Delft README.", + "readNote": "Public BlueDolphin documentation read 2026-09-26 at help.bluedolphin.io and bluedolphin.io product news (ValueBlue rebranded to BlueDolphin in April 2026; the old support domains are dead or behind a challenge). No trial, no login.", + "sources": { + "docs": "https://help.bluedolphin.io/en/", + "sourceRepo": null, + "featurePage": "https://bluedolphin.io/products/", + "featureRequests": null, + "issueTracker": null, + "roadmap": null, + "changelog": "https://bluedolphin.io/product-news/", + "apiReference": "https://public-api.eu.bluedolphin.app/swagger/index.html", + "marketplace": null, + "pricing": "https://bluedolphin.io/pricing/", + "accessibilityStatement": null, + "securityDocs": "https://bluedolphin.io/pricing/", + "demoInstance": null, + "community": "https://community.bluedolphin.io/", + "reviews": "https://www.peerspot.com/products/bluedolphin-reviews", + "videos": "https://www.youtube.com/@bluedolphinhq", + "caseStudies": "https://bluedolphin.io/customer-stories/", + "partnerDirectory": null, + "trainingCurriculum": "https://bluedolphin.io/academy/", + "jobPostings": null, + "tenders": [ + "TenderNed 421044 Tactisch beheer Blue Dolphin (Provincie Noord-Brabant, 2026-04-16)", + "TenderNed 367217 Tactisch beheerder Blue Dolphin (Provincie Noord-Brabant, 2025-02-11)", + "TenderNed 227678 onderhandse gunning Architectuurtool (Amersfoort, 2021-05-12), description names BlueDolphin" + ], + "nullReasons": { + "sourceRepo": "Closed source SaaS; no public repository found.", + "featureRequests": "No public ideas portal found; the product news page and the success page mention no ideas channel, and the community (Hivebrite) needs a login for most content.", + "issueTracker": "No public issue tracker; support requests go through the help center and in app chat.", + "roadmap": "No public roadmap found; https://bluedolphin.io/success/ says upcoming features are shown in live quarterly webinars for customers.", + "marketplace": "The integrations Marketplace is inside the product (paid add on, https://help.bluedolphin.io/en/articles/11967779-add-an-integration-in-bluedolphin); the Microsoft marketplace listings found by search answered 403 to scripted reads.", + "accessibilityStatement": "No accessibility statement or VPAT found on bluedolphin.io or in the help center.", + "demoInstance": "No public demo instance; a free trial needs a sign up (https://bluedolphin.app/free-trial/) and demos are booked through a form.", + "partnerDirectory": "https://bluedolphin.io/partners/ describes the partner program and shows logos without a browsable directory of partners.", + "jobPostings": "careers.bluedolphin.io redirects (301) to the LinkedIn company page, which was not read." + }, + "readHow": "All checks on 2026-09-26. The vendor rebranded from ValueBlue to BlueDolphin in April 2026: support.valueblue.nl no longer resolves (DNS ENOTFOUND), valueblue.zendesk.com answers 403 with a Cloudflare challenge (also in the headless browser-3, so it was left), and www.valueblue.com fails the TLS handshake. docs: help.bluedolphin.io sitemap.xml read with curl (200) and all 267 English articles downloaded with curl (200) and grepped; every cited help URL was checked against that sitemap. bluedolphin.io answers 403 to curl, so its pages were read with WebFetch (home, products, pricing, product-news, success, integrations-partners, capability-based-planning, application-portfolio-management-application-rationalization, customer-stories and two municipality stories, academy, partners, and the product update posts of October, November and December 2025 and February, May, June and July 2026); its post, page and customer story sitemaps were read with curl (200). apiReference: Swagger at public-api.eu.bluedolphin.app answered 200 to curl and is named in the help center quick start guide. securityDocs: the pricing page lists 'SOC 2 Certified' and 'ISO 27001 Certified', BYOK and data center localization; no separate trust page was found. community: WebFetch, Hivebrite platform, mostly behind login. reviews: peerspot page, curl 200; Capterra and G2 answered 403. videos: YouTube page title 'BlueDolphin HQ - YouTube', curl 200. A third party README (github.com/Gemeente-Delft/Gemeentelijk-Gegevensmodel, raw file via curl 200) was read for the GGM row. Not readable: valueblue.zendesk.com, support.valueblue.nl, www.valueblue.com, capterra.com, g2.com, the Microsoft marketplace listings, and the LinkedIn careers target. No login and no trial were used. Ruling 2026-09-26: BlueDolphin was read from help.bluedolphin.io; ValueBlue rebranded in April 2026 and the old support domains are dead or challenged." + } }, { "key": "glpi", @@ -306,7 +379,7 @@ "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"klik dan op de knop + achter de beschrijving van het pakket om het pakket toe te voegen aan je omgeving ... Pakketversie ... Referentiecomponenten ... Vul onder Planning bij Status in gebruik in\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus: \"Wanneer Gemeenten en samenwerkingen hun applicatielandschap hebben ingevoerd, wordt deze automatisch geplot op de GEMMA referentiecomponentenkaart\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Voeg pakket toe.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Applications are software systems or programs that process or analyze business data'; application fact sheet with description and lifecycle, supplier via 'provider -> IT component -> application relation' (https://help.sap.com/docs/leanix/ea/provider-modeling-guidelines) (read 2026-09-26). Reached on: Inventory > Application fact sheet.", - "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository. | docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967529-welcome-to-the-objects: 'a centralized space for managing architectural objects ... create, edit, delete'; https://help.bluedolphin.io/en/articles/11967745-update-an-object-definition shows an object definition 'New Application' with property 'Supplier'; status as lifecycle state (https://help.bluedolphin.io/en/articles/11967531-object-lifecycle-state) (read 2026-09-26). Reached on: Objects > Application Component object.", "glpi": "source read at 11.0.9: src/Appliance.php:46 class Appliance is GLPI's application itemtype; install/mysql/glpi-empty.sql:8935 glpi_appliances carries name, comment (description), manufacturers_id and states_id (status); src/Appliance.php:350 search option Status; supplier through the Management tab Infocom (install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id) and Contract_Item (src/Appliance.php:99); menu src/Html.php:1300 lists Appliance under Management, served by src/Glpi/Kernel/Listener/RequestListener/LegacyItemtypeRouteListener.php:100. Reached on: Management > Appliances (front/appliance.php). Driven on the lab at 11.0.9 (2026-09-26): created the appliance \"Zaaksysteem lab\" with a description through /front/appliance.form.php; it appears in the Appliances list and CSV export.", "topdesk": "https://docs.topdesk.com/en/migrating-objects-to-asset-management.html: \"In the new Asset Management you design your own template for each type of asset you have\" (read 2026-09-26); https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"Create a new template for software cards\" (read 2026-09-26). Applications are a self-designed asset type, no application model ships. Reached on: Modules > Asset Management > Template Designer / Asset overview > New.", "stackiq": "src/manifest.json:592 Modules page (FacetedCatalogIndexView, schema module) with the library CnIndexPage create form at src/views/FacetedCatalogIndexView.vue:108; lib/Settings/softwarecatalogus_register.json:6777 module schema has name, shortDescription/longDescription and provider (Supplier) but NO status property; status lives on usage (register.json:2654, enum Acquisition..In production) which has no page" @@ -319,7 +392,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", @@ -339,6 +412,7 @@ "stackiq": "register.json:1135 suite schema with applications[] (register.json:1231); src/manifest.json:674 SuiteDetail with suite-related panel; no schema breaks one application into sub-modules (module IS the application, register.json:6777 title 'Application')", "topdesk": "unknown: assets can be linked parent to child, but no application module concept is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the docs model a pakket and its pakketversies only, no module level is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967518-grouping-and-child-objects-in-architecture-views: 'The child objects option allows you to define hierarchical relationships between objects based on the composition relationship type ... breaking down a system into its components' (read 2026-09-26). Reached on: View > object context menu > Child objects.", "glpi": "source read at 11.0.9: src/Appliance_Item.php:45 links an Appliance to member items; src/autoload/CFG_GLPI.php:562 appliance_types includes Software, Appliance, Database and DatabaseInstance, so an application can be split into software and sub-appliances on its Items tab (src/Appliance.php:98). There is no module entity that belongs to a supplier product: grep -i 'module' src/Software.php src/Appliance.php returns no module concept. Reached on: Management > Appliances > Items tab." } }, @@ -369,6 +443,7 @@ "stackiq": "src/manifest.json:915 Moduleversies type:index (columns version, module, dateInUse, status) + :937 ModuleversieDetail; register.json:7649 moduleVersion schema with dateInUse (register.json:7746), dateInDevelopment, dateEndSupport, dateWithdrawn", "topdesk": "unknown: no version records per application or module are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Titel is de naam van uw productversie ... Status geeft aan of uw product in ontwikkeling, in productie, of teruggetrokken is ... startdata van ontwikkeling, test en distributie\" (read 2026-09-26). Versions are recorded per package (pakketversie), not per module. Reached on: Supplier login > Productportfolio > product > plus (versie toevoegen).", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ (267 articles); versions appear only as a field in an example import source (https://help.bluedolphin.io/en/articles/11967767-uploading-a-source), no version records with dates are documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'if versioning is relevant ... you can capture it in the Release field of the application fact sheets'; each fact sheet carries lifecycle phase dates, but the guide says 'versioning for applications doesn't add significant value' (read 2026-09-26). Reached on: Application fact sheet > Name and Description > Release." } }, @@ -379,7 +454,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", @@ -398,6 +473,7 @@ "stackiq": "src/dialogs/SuiteWizardDialog.vue:183 onSubmit saves a suite via objectStore.saveObject('suite') with applications[] (src/utils/suiteWizard.js:44 requires at least one); mounted by src/views/suites/SuitesIndexView.vue:46 on manifest page Suites (src/manifest.json:666)", "topdesk": "unknown: no suite bundling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no bundling of packages into a suite is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967518-grouping-and-child-objects-in-architecture-views: child objects by composition and an ArchiMate 'Grouping' object 'to cluster related elements logically'. Modeling structure only, not a product offered to others (read 2026-09-26). Reached on: View > Child objects or Grouping.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Adobe Creative Cloud is a suite that bundles various applications ... It is modeled as the parent entity'; a platform fact sheet can group applications. Modeled for the buyer's own inventory, not as a product offered to others (read 2026-09-26). Reached on: Application fact sheet hierarchy, Platform fact sheet.", "glpi": "source read at 11.0.9: src/autoload/CFG_GLPI.php:562 appliance_types contains Appliance and Software, so an Appliance can bundle existing appliances and software through src/Appliance_Item.php:45 (table install/mysql/glpi-empty.sql:8979 glpi_appliances_items). There is no notion of offering the bundle as a product to others. Reached on: Management > Appliances > Items tab." } @@ -409,7 +485,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "yes", "stackiq": "yes", @@ -428,6 +504,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: facet \"Ondersteunde technologie: On-premise, Dienst - Software as a Service (SAAS)\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: \"Onder het tabblad Technologie selecteer je de onderliggende technieken van het pakket. Veelal Saas of on-premise\" (read 2026-09-26). Hosting as SaaS is a property of a package version, no separate service record (hosting, support) is documented. Reached on: Alle pakketversies > filter Ondersteunde technologie.", "stackiq": "src/manifest.json:647 Diensten page (FacetedCatalogIndexView, schema catalogService) with the CnIndexPage create form; register.json:1324 catalogService with provider (required), modules[] (register.json:1419) and type enum Functional/Application/Technical management, Implementation support, Training, Licence reseller (register.json:1459)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"Services you offer may rely on services of external suppliers. These services are called underpinning services. TOPdesk allows you to link your services to supplier services\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity), Operational Activity, Knowledge Item, Problem, and Service cards, you can link multiple assets in one go\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > Service card > Links > Assets.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl lists ArchiMate object definitions 'Business Service', 'Technology Service' and 'Contract', which can model a hosting or support service; no supplier service register as such is documented (read 2026-09-26). Reached on: Objects > Technology Service object.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-component-modeling-guidelines: IT component subtype 'Service : Services refer to the provisioning of services related to IT components (usually provided by a 3rd party) ... Examples: Maintenance/Support Service ... Hosting Service'; linked to providers (read 2026-09-26). Reached on: Inventory > IT Component fact sheet, subtype Service.", "glpi": "source read at 11.0.9: no supplier service itemtype; services are held as contracts, src/ContractType.php:37 admin dropdown of contract types (for example hosting or support), install/mysql/glpi-empty.sql:1550 glpi_contracts_suppliers ties the contract to a Supplier and install/mysql/glpi-empty.sql:1536 glpi_contracts_items ties it to the Appliance or Software it covers. Reached on: Management > Contracts (front/contract.php), Suppliers tab." } @@ -439,7 +516,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "no", @@ -456,6 +533,7 @@ "stackiq": "register.json:1034 sector schema (name, description only); no schema property references #/components/schemas/sector (grep found none), no manifest page for sector; only the admin schema mapping in src/views/settings/sections/OpenRegisterIntegration.vue:395", "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: facets \"Domein\" (Bestuur, Fysieke leefomgeving, Sociaal domein, ...) and \"Doelgroep\" (Gemeente, Generiek, Inwoners en ondernemers, Ketenpartners) (read 2026-09-26). Domains are municipal policy domains, the catalogue serves municipalities only, not other government sectors. Reached on: Alle pakketversies > filters Domein, Doelgroep.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967603-manage-object-questionnaires: 'A questionnaire is a group of fields that add more details to objects' configured by admins, which can hold a sector field; no sector list is shipped (read 2026-09-26). Reached on: Admin > Object questionnaires.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/tags-and-custom-fields: tags and tag groups for 'quick, high-level classification', filterable and usable as reporting views; no predefined government sector list is documented (read 2026-09-26). Reached on: Fact sheet > Tags.", "glpi": "source read at 11.0.9: no government sector concept, grep -i 'sector' over src/*.php and locales/glpi.pot hits only menu sectorization (src/Html.php:1019); the nearest holder is the single-valued Appliance type dropdown install/mysql/glpi-empty.sql:8941 appliancetypes_id, or an admin custom dropdown (install/mysql/glpi-empty.sql:10113 glpi_dropdowns_dropdowndefinitions) used as a field of a custom asset. Multi-valued tagging needs the separate tag plugin (github.com/pluginsGLPI/tag, not read). Reached on: Management > Appliances, Appliance type field." } @@ -467,7 +545,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "partial", @@ -487,6 +565,7 @@ "stackiq": "register.json:6856 module.contactPerson is a single related contactPerson; register.json:1786 contactPerson has free-text role (job title) and a roles enum of catalogue roles (Aanbod-beheerder, Gebruik-beheerder, ...), no business/technical owner distinction; shown on ModuleDetail md-data (src/manifest.json:500 lists the stale key 'contactpersoon', not 'contactPerson')", "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"Assignment widget : assigns locations and persons to the asset\" (read 2026-09-26). No separate business and technical owner roles are described. Reached on: Asset card > Assignment widget.", "vng-softwarecatalogus": "unknown: the landscape entry fields listed (pakketversie, referentiecomponenten, technologie, status) include no business or technical owner; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30355 (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967633-datacollector-select-tricks: an example import maps '[Application Owner]' into object properties; ownership otherwise is modeled as questionnaire fields or ArchiMate relations. No built in business and technical owner fields are documented (read 2026-09-26). Reached on: Object properties or questionnaire fields.", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:8935 glpi_appliances holds users_id and users_id_tech; src/Appliance.php:186 search option User and src/Appliance.php:195 Group (business side), src/Appliance.php:240 'Technician in charge' and the 'Group in charge' option a few lines below (technical side). Reached on: Management > Appliances, form fields User, Group, Technician in charge, Group in charge. Driven on the lab at 11.0.9 (2026-09-26): the saved appliance holds users_id and users_id_tech (glpi_appliances row 1), shown as User and Technician in charge." } }, @@ -497,7 +576,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "yes", "stackiq": "no", @@ -516,7 +595,8 @@ "glpi": "source read at 11.0.9: native custom fields exist only for admin defined custom asset types, src/Glpi/Asset/CustomFieldDefinition.php:52 child of AssetDefinition (install/mysql/glpi-empty.sql:10159 glpi_assets_customfielddefinitions keyed on assets_assetdefinitions_id), set up under Setup > Asset definitions (src/Html.php:1330). The core Appliance and Software types take no custom fields in core; that needs the fields plugin, read at pluginsGLPI/fields tag 1.24.5, inc/container.class.php:91 containers with a list of itemtypes. Reached on: Setup > Asset definitions > Custom fields; or plugin Fields. Driven on the lab at 11.0.9 (2026-09-26): Setup > Asset definitions (/front/asset/assetdefinition.php) is where custom asset types and their fields are defined; appliances themselves take no custom fields in core.", "stackiq": "Looked in src/manifest.json, src/views, lib/Controller: no field-definition or schema-extension UI in stackiq; the data model is fixed in lib/Settings/softwarecatalogus_register.json", "topdesk": "https://docs.topdesk.com/en/creating-new-fields.html: \"Whether it is a contact person, a purchase price, or a reminder date ... Use fields in a fieldset or dataset widget to register any useful information about an asset\" (read 2026-09-26). Reached on: Asset Management > Template Designer > Fields.", - "vng-softwarecatalogus": "unknown: no user-defined fields are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: no user-defined fields are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967603-manage-object-questionnaires: 'it is possible to add questionnaires to an object type in the Admin module. A questionnaire is a group of fields that add more details to objects' (read 2026-09-26). Reached on: Admin > Object questionnaires." } }, { @@ -541,7 +621,7 @@ "note": "The generic index page offers a file import (CSV per schema, or a register-wide JSON/Excel) that OpenRegister executes. Nothing stackiq-specific maps a spreadsheet's supplier names to organisation references, so relation columns must already hold identifiers.", "evidence": { "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-fact-sheet-data-through-excel-file and https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: 'using the import option, you can update multiple fact sheets in bulk' via Excel export and import (read 2026-09-26). Reached on: Inventory > Import (Excel).", - "bluedolphin": "docs, intelligence competitor_features#48971 'Data import (Excel)' (2026-07-23): Bulk import of application/portfolio data.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967629-import-and-export-options-with-bluedolphin: import 'Access databases, Excel files, and CSV files' with the DataCollector; https://help.bluedolphin.io/en/articles/11967643-use-datasource-to-create-objects (read 2026-09-26). Reached on: Admin > Sources; DataCollection Frontend.", "stackiq": "Library CnIndexPage (@conduction/nextcloud-vue 2.55.1, package-lock) showMassImport default true (CnIndexPage.vue:1599) and self-mode handleMassImport (selfModeActions.js:168) POSTs to /apps/openregister/api/registers/{register}/import with the schema for CSV (selfModeIO.js:82); rendered on the Modules page's CnIndexPage (src/views/FacetedCatalogIndexView.vue:108)", "topdesk": "https://docs.topdesk.com/en/generate-import-file.html: \"Importing assets speeds up this task ... export an asset template to XLSX format\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-new-import.html: \"You can use a file (CSV or XLSX), connect with an MS SQL database or import from Microsoft Intune , or Lansweeper\" (read 2026-09-26). Reached on: Settings > Import settings > Asset Management imports.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"Een import vanuit die tools naar de Softwarecatalogus zodat 2-richtingverkeer mogelijk wordt voor actualisatie, is vooralsnog niet voorhanden\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/19703: inventory goes in a spreadsheet, then \"Kies met de + toets het pakket dat opgevoerd moet worden\", one package at a time (read 2026-09-26)", @@ -555,7 +635,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "partial", "stackiq": "partial", @@ -575,6 +655,7 @@ "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines and https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: the application fact sheet holds lifecycle, relations to IT components, organizations, interfaces, cost on relations, and a Relations Explorer on one fact sheet (read 2026-09-26). Reached on: Inventory > Application fact sheet.", "stackiq": "src/manifest.json:491 ModuleDetail: md-versions (:504), md-compliance (:503), md-related generic Related panel (:502); no contract widget (catalogContract links to service/usage, register.json:3250, not to module); md-data include lists stale keys beschrijvingKort/beschrijvingLang/contactpersoon (:500)", "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: twelve widgets incl. \"History\", \"Relationships\", \"Relationship grid\", \"Documents\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: assets linked to calls, changes, services (read 2026-09-26). Versions and compliance are not part of it. Reached on: Asset card.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967521-object-viewer: 'shows all the object properties like title, name, or lifecycle state. Also, you can see the relationships, history, objects being used in other views, or questionnaires' (read 2026-09-26). Reached on: Objects > object properties / Objectviewer.", "glpi": "source read at 11.0.9: src/Appliance.php:98 onwards defineTabs puts Items, Contracts, Documents, Management (Infocom), Certificates, Domains, Knowledge base, Tickets, Problems, Changes and Impact on the one appliance page; versions sit on the separate Software page (src/SoftwareVersion.php:42), and no compliance tab exists (grep -i 'complian' src/Appliance.php returns nothing). Reached on: Management > Appliances > appliance form tabs." } }, @@ -585,7 +666,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "partial", @@ -604,6 +685,7 @@ "stackiq": "Library CnIndexPage mass delete/copy/export (showMassDelete default true, CnIndexPage.vue:1617; selfModeActions.js:63 handleMassDelete) on index pages; stackiq's MassPublishObjects/MassLockObjects dialogs (src/dialogs/Dialogs.vue:8-14) are only opened from src/modals/object/ViewObject.vue:4865, and ViewObject is only mounted for modals 'viewOrganisatie'/'viewContactpersoon' (src/modals/Modals.vue:7,19) which nothing in src/ sets", "topdesk": "https://docs.topdesk.com/en/editing-assets-in-bulk.html: \"select multiple assets by ticking their boxes ... You can use bulk edit for updating up to 500 assets\" (read 2026-09-26); editable are assignments, drop-down, date, number, text and checkbox fields. Bulk publish or delete is not described. Reached on: Asset Management > Asset overview > select > bulk edit.", "vng-softwarecatalogus": "unknown: no multi-select publish, lock or delete is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967533-edit-multiple-objects: 'edit multiple objects at the same time'; the API offers 'Delete multiple objects' (https://help.bluedolphin.io/en/articles/11967756-delete-multiple-objects); no publish or lock action (read 2026-09-26). Reached on: Objects > Edit selected objects.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: 'switch to table view in the inventory, you can perform inline editing across multiple fact sheets'; https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets: 'Archiving Fact Sheets in Bulk' through an Excel action column. No publish or lock action is documented (read 2026-09-26). Reached on: Inventory > Table view; Excel import with action column.", "glpi": "source read at 11.0.9: every search list offers massive actions, src/MassiveAction.php:666 Update (any field, for example status), src/MassiveAction.php:698 Put in trashbin, src/MassiveAction.php:652 Delete permanently, src/MassiveAction.php:656 Restore. There is no publish state; locking applies to inventory fields only. Reached on: any list, for example Management > Appliances, Actions button. Driven on the lab at 11.0.9 (2026-09-26): the Appliances list carries the massive actions control." } @@ -632,6 +714,7 @@ "stackiq": "src/components/organisations/OrganisationMergePanel.vue:46 (admin-only controls) mounted as OrganisatieDetail bodyWidget org-merge (src/manifest.json:430); lib/Controller/MergeController.php:106 execute with isAdmin check at :142; generic src/modals/object/MergeObject.vue only mounted for modal 'mergeOrganisatie' which nothing sets", "topdesk": "https://docs.topdesk.com/en/migration-status.html: \"You cannot merge the two cards into one card\" (read 2026-09-26); https://tip.topdesk.com/c/239-ai-cmdb-monitoring-: roadmap card in column \"Under consideration\", \"AI can continuously scan your configuration database for duplicate records ... and surfaces them for review\" (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no merge of entries is described; the news page only mentions a pseudo-supplier \"Open Source Pakketten\" created against duplicate spellings; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/nieuws (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; imports merge source records that share a key into one object (https://help.bluedolphin.io/en/articles/11967635-four-things-you-need-to-know-before-you-start-importing-sources), but merging two existing entries by a user is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea (all 663 EA pages grepped for merge); duplicates are handled by archiving (https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets 'removing outdated or duplicate fact sheets'), no merge of two fact sheets is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Software.php:109 'Merging' tab on a recursive software, src/Software.php:926 showMergeCandidates lists same named software, src/Software.php:997 massive action Merge, src/Software.php:1011 private function merge moves versions and licences into the kept entry; dropdowns get Replace, src/CommonDropdown.php:680. Reached on: Assets > Software > Merging tab." } @@ -658,7 +741,7 @@ "note": "Nothing asks owners to confirm or correct their entries.", "evidence": { "sap-leanix": "https://help.sap.com/docs/leanix/ea/reviewing-responses: 'Review and approve survey responses before they are saved to fact sheets'; https://help.sap.com/docs/leanix/ea/application-modernization-collect-data: 'Create a new survey to get key information from application or business owners' (read 2026-09-26). Reached on: Surveys.", - "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967524-create-a-survey: surveys 'gather input from stakeholders outside your core BlueDolphin users ... allowing external stakeholders to contribute directly to the Enterprise Architecture repository' on an object's questionnaire (read 2026-09-26). Reached on: Object > Questionnaire tab > Create survey.", "stackiq": "No survey, attestation or owner-confirmation code in lib/ or src/ (searched survey/enquete/confirm entry)", "topdesk": "unknown: Survey Management runs general surveys (and \"will reach end of life ... November 2026\"), not confirmation of entries by owners; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C7: \"Leveranciers krijgen ook periodiek notificatiemails met een aantal automatische controles en de Te corrigeren fouten staan ook op het dashboard van ingelogde leveranciers\" (read 2026-09-26); https://www.softwarecatalogus.nl/suggesties_overnemen: suppliers send suggestions that municipalities accept or decline (read 2026-09-26). No survey to application owners.", @@ -672,7 +755,7 @@ "origin": "competitor", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -689,6 +772,7 @@ "stackiq": "No completeness or data-quality score in lib/ or src/ (searched completeness/volledigheid/score outside reviews)", "topdesk": "unknown: the only readiness score described is the AI readiness score for the knowledge base; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/voortgang-verbeteren: \"Met het aantal sterren (*) wordt een indicatie van volledigheid van ingevulde gegevens aangegeven\", criteria include referentiecomponenten filled, statuses, koppelingen and \"Datum laatste wijziging is recenter dan 3 maanden geleden\" (read 2026-09-26). Scored per organisation, not per application entry. Reached on: Homepage block Voortgang gemeenten; organisation page header.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967713-governance-insights: governance report 'Object completeness : Lists all objects and the completeness score of each object' (read 2026-09-26). Reached on: Insights > Governance reports > Object completeness.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/fact-sheet-completeness: 'The fact sheet completion score measures how much of the required data has been filled out for a fact sheet ... You can view the fact sheet completion score in the fact sheet's header' (read 2026-09-26). Reached on: Fact sheet header > completion score.", "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing; no score of how filled in an item is exists in core. The item form tabs (src/Appliance.php:98 onwards) show no score." } @@ -700,7 +784,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", @@ -717,6 +801,7 @@ "stackiq": "src/manifest.json:3 setup wizard step load-demo-data (:24); lib/Controller/SetupController.php:202 runAction load-demo-data (AuthorizedAdminSetting); lib/Service/DemoDataService.php:202 install() imports lib/Settings/stackiq_mock_register.json (120 objects, 6 per schema) through OpenRegister ConfigurationService::importFromApp", "topdesk": "unknown: no example data set is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue is one hosted service; no loadable example data set is described (a \"VNG Realisatie Demo\" supplier appears in the live data); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967592-download-and-update-the-templates-in-the-library: 'A quick way of getting started with BlueDolphin and discovering its possibilities is by downloading a standard template'; standard templates are 'Preconfigured BlueDolphin sites that can contain objects, views, questionnaires' (https://help.bluedolphin.io/en/articles/11967590-introduction-to-templates) (read 2026-09-26). Reached on: Admin > Templates > Library > Standard templates.", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; demo and sandbox workspaces are mentioned (https://help.sap.com/docs/leanix/ea/automations 'Demo and sandbox workspaces allow up to 10,000 automations per month') but loading an example data set into a workspace is not described (read 2026-09-26)", "glpi": "source read at 11.0.9: on a clean install dashboards render placeholder figures from src/Glpi/Dashboard/FakeProvider.php:65 FakeProvider, with the banner 'You are viewing demonstration data.' and a 'Disable demonstration' button (src/Glpi/Dashboard/Grid.php:427, :428, :448); CHANGELOG.md 11.0.0 lists it. No example records (applications, contracts, suppliers) are loaded; the console entry point src/Glpi/Console/Application.php:66 has no demo data command. Reached on: Home > Dashboard on a fresh install. Driven on the lab at 11.0.9 (2026-09-26): glpi_configs.is_demo_dashboards is 1 on the fresh install, so the dashboard cards come from FakeProvider until an administrator disables the demonstration." } @@ -745,6 +830,7 @@ "stackiq": "src/dialogs/SuiteWizardDialog.vue (3 steps) is the only wizard, opened from src/views/suites/SuitesIndexView.vue:46; applications, services and connections use the bare CnIndexPage form (FacetedCatalogIndexView.vue:108) or nothing", "topdesk": "unknown: wizards exist for imports and migration, not for adding an application; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the manuals describe forms (\"Hierna opent een formulier\"), no step-by-step wizard; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30355 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; creating an object is a form (https://help.bluedolphin.io/en/articles/11967530-create-a-new-object), and the survey setup has three steps, but a step by step wizard for adding an application is not documented (read 2026-09-26)", "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/creating-fact-sheets describes creating a fact sheet in the inventory with reference catalog suggestions and duplicate hints, not a step by step wizard; wizards are documented only for KPI and integration mapping configuration (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'wizard' over src/ templates/ locales/glpi.pot returns nothing for item creation; appliances are added through the plain form only (install/mysql/glpi-empty.sql:8935 glpi_appliances has no is_template column)." } @@ -773,6 +859,7 @@ "stackiq": "src/components/sbom/SbomComponentsPanel.vue lists sbomComponent rows (name/version/purl/licenses) as the ModuleversieDetail 'Components' sidebar tab (src/manifest.json:961); register.json:7920 sbomComponent schema", "topdesk": "unknown: no software components per version are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no third-party component list per version is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for SBOM and bill of materials, no hits (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/uploading-sboms-from-fact-sheets: 'Upload SBOM files directly from a microservice fact sheet'; https://help.sap.com/docs/leanix/ea/tech-stack-discovery-from-sboms: 'the system automatically analyzes the SBOM components and builds a structured view of your technology stack'. Part of SAP LeanIX Technology Risk and Compliance (read 2026-09-26). Reached on: Microservice fact sheet > SBOM (Technology Risk and Compliance).", "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; software versions carry no component list (install/mysql/glpi-empty.sql:6900 glpi_softwareversions)." } @@ -784,7 +871,7 @@ "origin": "competitor", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", @@ -804,6 +891,7 @@ "stackiq": "register.json:6869 module.cloudDienstverleningsmodel enum On-premises, IaaS, PaaS, SaaS; register.json:6906 hostingLocation and hostingJurisdiction; usage.cloudDienstverleningsmodel (register.json:3050); on ModuleDetail md-data include (src/manifest.json:500)", "topdesk": "unknown: only possible as a self-defined field; no hosting model is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Indien een leverancier zowel SaaS als On premise ondersteunt, kan je aangeven welke van deze twee varianten gebruikt wordt binnen de gemeente\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen > tabblad Technologie.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967633-datacollector-select-tricks: an example import carries '[Hosting Type]' into object properties; hosting is otherwise modeled with ArchiMate technology objects. No built in hosting field is documented (read 2026-09-26). Reached on: Object properties or questionnaire field.", "glpi": "source read at 11.0.9: no hosting model field; the closest holders are the admin editable Environment dropdown on an appliance, src/Appliance.php:277 ApplianceEnvironment search option (install/mysql/glpi-empty.sql:8945 applianceenvironments_id), plus locations_id and the Appliance type dropdown. grep -i 'saas' over src/ finds nothing; 'On-premise' in locales/glpi.pot:12997 is only an icon label. Reached on: Management > Appliances, Environment field." } }, @@ -833,6 +921,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"De richting van het berichtenverkeer, de landelijke voorziening waarmee gekoppeld is/wordt, in dit geval GGK\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-werkt-de-catalogus: \"kunnen koppelingen tussen applicaties onderling en met Landelijke Voorzieningen vastgelegd worden\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > koppeling toevoegen.", "stackiq": "register.json:3720 connection.nonMunicipalProvision -> element filtered gemmaType 'Buitengemeentenlijke voorziening'; no page for connection", "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; connections are generic ArchiMate relationships between objects (https://help.bluedolphin.io/en/articles/11967550-working-with-object-relationships), national provisions such as basisregistraties are not mentioned (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Modeling External Applications ... applications of business partners, service providers, authorities', linked 'through an interface to analyze dependencies'. Generic external application modeling, no catalogue of national provisions such as basisregistraties (read 2026-09-26). Reached on: Application fact sheet (external) + Interface fact sheet.", "glpi": "source read at 11.0.9: no national provision concept (grep -ril 'basisregistratie' src/ locales/glpi.pot returns nothing); a provision can be held as another Appliance and linked through an impact relation, install/mysql/glpi-empty.sql:1247 glpi_impactrelations (source item, impacted item, name), with Appliance enabled for impact at src/autoload/CFG_GLPI.php:649. Reached on: Appliance > Impact analysis tab, Add relation." } @@ -844,7 +933,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -863,6 +952,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle koppelingen ... staan de koppelingen van alle gemeenten en samenwerkingsverbanden ... Door te klikken op het icoontje rechts van een koppeling, krijg je nog enige detail informatie\" (read 2026-09-26). Reached on: Inlogmenu > Alle koppelingen (logged-in municipal users).", "stackiq": "No manifest page with schema connection (src/manifest.json and src/manifest.d/*.json); the Integrations page (src/manifest.d/connection-registry.json:23) lists integriq app_connection, explicitly not stackiq's connection schema (its _note)", "topdesk": "unknown: relations are shown per asset and in a graphical overview; a list of all relations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967713-governance-insights: governance report 'Objects and relationships : Lists all relations between two objects with relevant information like relation definition, related object title', with clickable object titles. A report, not a dedicated connections page (read 2026-09-26). Reached on: Insights > Governance reports > Objects and relationships.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: 'Interfaces are connections between applications that illustrate how data exchange occurs', each a fact sheet listed in the inventory by fact sheet type (read 2026-09-26). Reached on: Inventory > filter fact sheet type Interface.", "glpi": "source read at 11.0.9: src/ImpactRelation.php:39 ImpactRelation has only prepareInputForAdd and getIDFromInput (src/ImpactRelation.php:47, :107), no search options and no list page; relations are only seen per item in the Impact analysis tab (src/Impact.php:91). Driven on the lab at 11.0.9 (2026-09-26): /front/impactrelation.php opens by URL only (no menu entry) as a generic list whose only criterion and column is ID, so relations cannot be browsed by endpoint; rating unchanged." } @@ -874,7 +964,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "partial", "stackiq": "partial", @@ -893,6 +983,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Mijn pakketoverzicht ... Onder het eerste tabblad zitten de pakketten en onder het tweede tabblad de koppelingen\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: \"Door op een applicatienaam in het Models venster te klikken, zie je in de Visualiser alle koppelingen tussen die applicatie met andere applicaties\" (in Archi after export) (read 2026-09-26). No per-application connection view inside the catalogue is described. Reached on: Mijn softwarecatalogus > Koppelingen.", "stackiq": "src/manifest.json:502 ModuleDetail md-related generic Related panel (OpenRegister /uses + /used merged into an Objects tab); register.json:7064 module.koppelingen is hideOnForm and not in md-data include (:500); lib/Controller/AangebodenGebruikController.php:208 GET /api/koppelingen-gebruik/{uuid} (public) has no caller in src/", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"Links between assets are created and managed via the Relationships widget. For current relationships with other assets, the widget shows the template's icon, the Asset ID\" (read 2026-09-26). Generic asset relations, not interfaces. Reached on: Asset card > Relationships widget.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967550-working-with-object-relationships: 'select the Objects and go to the Relationships tab ... View the current relationships of an object' (read 2026-09-26). Reached on: Objects > object > Relationships tab.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/circle-map-report: the Interface Circle Map 'helps you track changes and updates in application dependencies', and https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets: relations incl. interfaces shown on the fact sheet and in the Relations Explorer (read 2026-09-26). Reached on: Application fact sheet > Relations (Provided and Consumed Interfaces).", "glpi": "source read at 11.0.9: src/Impact.php:91 getTabNameForItem adds the 'Impact analysis' tab (src/Impact.php:80) to every impact enabled itemtype, Appliance and Software included (src/autoload/CFG_GLPI.php:649 and :663), with a list view src/Impact.php:270 displayListView of every related item in both directions. Reached on: Management > Appliances > Impact analysis tab. Driven on the lab at 11.0.9 (2026-09-26): the appliance page carries an Impact analysis tab with Add assets for every impact enabled item type." } @@ -921,7 +1012,7 @@ "note": "No page draws connections. The ArchiMate export can be opened in Archi, but it carries GEMMA views and usages, not the catalogue's connections.", "evidence": { "sap-leanix": "https://help.sap.com/docs/leanix/ea/data-flow: data flow diagrams help 'understand how applications are connected, identify dependencies, and trace data movement between systems' (read 2026-09-26). Reached on: Diagrams > Data Flow Diagram.", - "bluedolphin": "docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models. | docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967472-welcome-to-bluedolphin: 'insight into connections between business processes, applications, and their underlying infrastructure. This way, you can visualize chains and information flows'; https://help.bluedolphin.io/en/articles/11967545-spider-tool adds related objects with 'all existing relationships' to a view (read 2026-09-26). Reached on: Views > architecture view.", "glpi": "source read at 11.0.9: src/Impact.php:252 displayGraphView and src/Impact.php:1559 makeDataForCytoscape draw the relation network, with editing tools add asset, add relation, add group at src/Impact.php:1160. Reached on: Appliance > Impact analysis tab, graph view. Driven on the lab at 11.0.9 (2026-09-26): the Impact analysis tab renders the graph editor with Add assets, Edit group and Edit edge tools.", "stackiq": "No diagram rendering in src/ (no graph library; src/store/modules/view.js GET /api/views has no importer outside itself); lib/Service/ArchiMateExportService.php exports GEMMA views as ArchiMate XML without koppeling objects (no 'koppeling' in lib/Service/ArchiMate*)", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"After you define the relationship between assets, you can use the graphical overview to see a visual representation of their relationship\" (read 2026-09-26). Reached on: Asset card > graphical overview.", @@ -949,7 +1040,7 @@ "providerHow": "read-from-code", "note": "The only way to see what depends on an application is the generic list of objects that reference it, which OpenRegister's relation index fills. There is no impact view or retirement check.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967472-welcome-to-bluedolphin: 'overlapping application functions are quickly made visible, and their impact analyses are available in no time'; spider tool shows derived relationships (https://help.bluedolphin.io/en/articles/11967545-spider-tool) (read 2026-09-26). Reached on: Views > spider tool.", "glpi": "source read at 11.0.9: src/Impact.php:49 class Impact 'Impact analysis', src/Impact.php:713 bfs walks the graph by direction and src/Impact.php:612 buildListData lists what is impacted, with ongoing tickets, problems and changes on impacted items (src/Impact.php:313). Reached on: Tools > Impact analysis (src/Html.php:1309) and the item's Impact analysis tab.", "topdesk": "https://docs.topdesk.com/en/managing-disruptions-in-your-asset-management-process.html: \"you want to know how far the reach of the disruption is ... the operational/impacted status for assets ... Status impacts are also only shown in the graphical overview when a link type is used\" (read 2026-09-26). Disruption impact, not a pre-change dependency analysis. Reached on: Asset card > General widget > Determine status automatically.", "stackiq": "src/manifest.json:502 ModuleDetail md-related (library CnRelatedObjectsWidget: /used lists every object that references this module: usages, connections, suites, services, vulnerabilities); no dependency or impact computation in lib/ or src/", @@ -964,7 +1055,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -981,6 +1072,7 @@ "stackiq": "register.json:3563 connection.type enum (file transfer, digikoppeling, message que, webservices, api, ...) exists, but no connection list page to filter", "topdesk": "unknown: custom link types exist, but filtering relations by type is not described; https://tip.topdesk.com/c/90-graphical-overview-improvements is still under consideration; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: connections carry a standard and \"het soort overdracht\" (upload naar portaal, webservices), but the docs do not name a type filter on the connection list; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967713-governance-insights: 'Objects and Relationships (with metadata): Select a source object definition, a relationship type, and a target object definition'; relationship types follow ArchiMate definitions, not API or file exchange categories (read 2026-09-26). Reached on: Insights > Objects and Relationships (with metadata).", "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: interface subtypes 'Logical interface, API, MCP server' and 'You can capture data flow directions, type of transfer, and frequency with the interface fact sheet'; subtypes and fields are filterable in the inventory (read 2026-09-26). Reached on: Inventory > Interface > filter by subtype or transfer type.", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations has only a free name besides the two endpoints, no connection type (API, file, message), so there is nothing to filter on; the graph settings (src/Impact.php:1167 impact_settings) cover depth and direction." } @@ -992,7 +1084,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "no", @@ -1010,6 +1102,7 @@ "stackiq": "No API/interface schema in register.json (schemas listed at register.json:1034-7920); connection.type 'api' is only a transport label", "topdesk": "unknown: the TOPdesk documentation is about service management and does not cover this; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no register of APIs an application exposes is described; standards are declared instead; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl lists the ArchiMate object definition 'Application Interface' (Applicatie-interface), which can hold an application's APIs as related objects; no API catalogue feature is documented (read 2026-09-26). Reached on: Objects > Application Interface object.", "glpi": "source read at 11.0.9: no API entity in core, grep -ril 'openapi' src/*.php finds no itemtype for exposed APIs; an admin can define an 'API' custom asset type (src/Html.php:1330 Setup > Asset definitions, src/Glpi/Asset/AssetDefinition.php) and attach it to the application as an Appliance item (src/Appliance_Item.php:45) or impact relation (install/mysql/glpi-empty.sql:1247). Reached on: Setup > Asset definitions, then Appliance > Items tab." } }, @@ -1020,7 +1113,7 @@ "origin": "competitor", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "unknown", "stackiq": "no", @@ -1040,6 +1133,7 @@ "stackiq": "src/views/settings/sections/ArchiMateImportExport.vue:571 org export options are Modules, Deelnames, Gebruik only; lib/Controller/SettingsController.php:1685 exportOrgArchiMate; no koppeling handling in lib/Service/ArchiMate*", "topdesk": "unknown: exporting the relation graph is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: \"Pakketten én koppelingen worden in 1 model geëxporteerd ... AMEFF-export\" (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Mijn koppelingen: Knop [Exporteren] op tabblad Koppelingen\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten or Koppelingen > Exporteren > AMEFF-export.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967514-download-a-view: a view downloads as 'PNG, SVG, PDF, and AMEFF format ... You can use AMEFF files to exchange Architecture views between different applications that support ArchiMate'. The graph is exported per drawn view (read 2026-09-26). Reached on: View > Download > AMEFF.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams: diagrams export 'in the following formats: PDF, SVG, PNG, HTML embed code, and XML' and open in draw.io; https://help.sap.com/docs/leanix/ea/exporting-fact-sheet-data-as-excel-file exports fact sheet data. No export of an application's relation graph as data is documented as such (read 2026-09-26). Reached on: Diagrams > Export (XML, draw.io); Inventory > Export." } }, @@ -1050,7 +1144,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "partial", "stackiq": "partial", @@ -1067,6 +1161,7 @@ "stackiq": "src/manifest.d/connection-registry.json:23 Integrations page (register integriq, schema app_connection) with visibleIf appInstalled 'integriq' (:17) and permission admin (:15,:27); Add integration handler leaves for integriq (src/services/connectionRegistry.js:43); rows synced from lib/Settings/connections.json (email, federation, eol-feed); status worked out by integriq", "topdesk": "https://docs.topdesk.com/en/connections.html: \"TOPdesk offers a storage space for usernames, passwords, and authentication tokens used in automated actions ... Better overview: Observe when specific credentials are applied\" (read 2026-09-26); https://docs.topdesk.com/en/using-the-automated-actions-overview.html: \"contains all asset actions, webhooks, scheduled actions ... The last execution status\" (read 2026-09-26). Reached on: Settings > Connections; Action Management > Automated Actions.", "vng-softwarecatalogus": "unknown: no overview of the catalogue's own outside integrations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967779-add-an-integration-in-bluedolphin: 'Click Add integration in the bottom right corner of the Marketplace page' for TOPdesk, ServiceNow and JIRA; 'Marketplace (Integration) is a paid add-on' (read 2026-09-26). Reached on: System settings > Marketplace > Add integration.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/discovering-ai-agents-using-api: 'Go to the Integrations section in the administration area. Choose Add Integration'; https://help.sap.com/docs/leanix/ea/collibra-data-catalog-integration: 'Administration > Integrations > Sync Log' to check each integration (read 2026-09-26). Reached on: Administration > Integrations (Add Integration, Sync Log).", "glpi": "source read at 11.0.9: outside integrations are set up on separate Setup pages, not one overview: src/Html.php:1331 Webhook, src/Html.php:1333 OAuthClient and MailCollector, Auth (LDAP, SSO) on src/Html.php:1332; src/Webhook.php:64 Webhook and src/OAuthClient.php:45 OAuthClient each have their own list. Reached on: Setup > Webhooks, Setup > OAuth clients, Setup > Authentication." } @@ -1094,7 +1189,7 @@ "featureConfidence": "high", "note": "Works end to end but only a Nextcloud admin can import: the endpoint rejects non-admins and the upload control lives only on the admin settings page.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27459 'ArchiMate & BPMN Support' (2026-04-12): Full ArchiMate and BPMN modeling in one platform | Rated yes because full ArchiMate support; import format not named in the reading.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967637-import-ameff-files: 'AMEFF stands for the ArchiMate Model Exchange File Format ... Click the Upload AMEFF file button' with 'Map and import Objects, Map and import Relationships, Import Views' (read 2026-09-26). Reached on: Admin > System > Import.", "stackiq": "appinfo/routes.php:96 POST /api/archimate/import -> lib/Controller/SettingsController.php:1490 importArchiMate (isAdmin check :1496) -> lib/Service/ArchiMateImportService.php (5961 lines); UI src/views/settings/sections/ArchiMateImportExport.vue:32 file input + :791 importArchiMateFile", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: only export to AMEFF is documented; importing an ArchiMate file into the catalogue is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools (read 2026-09-26)", @@ -1126,7 +1221,7 @@ "note": "The export produces a downloadable AMEF XML, but only from the admin settings page; organisation admins may call the API but have no page for it.", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: \"De softwarecatalogus ondersteund een koppeling met architectuurtools. Dit wordt gedaan via de exportfunctionaliteit van een ArchiMate Exchange Format-bestand ... Archi (Open Source), Bizzdesign, Mavim, Sparx, Dragon1 en Value Blue\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Exporteren > AMEFF-export.", - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967514-download-a-view: 'AMEFF Generates an AMEFF export file (only for Architecture views)'. Export is per view, not of the whole catalogue (read 2026-09-26). Reached on: View > Download > AMEFF.", "stackiq": "appinfo/routes.php:97 POST /api/archimate/export -> lib/Controller/SettingsController.php:1615 exportArchiMate (admin or org-admin via verifyOrgExportPermission :1735) -> lib/Service/ArchiMateService.php:232 exportToArchiMate (docblock: organization filter 'currently not implemented'); UI ArchiMateImportExport.vue:591 'Export Base' button", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; exports are PDF, SVG, PNG, HTML and draw.io XML (https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams); no ArchiMate exchange format export is documented, ArchiMate 3.2 is only a visual template (https://help.sap.com/docs/leanix/ea/styles-and-patterns) (read 2026-09-26)", @@ -1159,6 +1254,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools: export file named \"GEMMA_Softwarecatalogus__ameff_model\" (read 2026-09-26); https://www.softwarecatalogus.nl/Archi_modellen_samenvoegen: \"De export van de Softwarecatalogus bevat de GEMMA en alle pakketten en koppelingen van de gemeente\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: \"GEMMA views met daarop geplot de pakketten van de gemeente\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Exporteren > AMEFF-export.", "stackiq": "appinfo/routes.php:98 GET /api/archimate/export/organization/{organizationUuid} -> lib/Controller/SettingsController.php:1685 exportOrgArchiMate -> lib/Service/ArchiMateService.php:302 -> lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications in GEMMA view copies; UI ArchiMateImportExport.vue:602 'Organization Export' with Modules/Deelnames/Gebruik checkboxes", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for GEMMA, no hits; views export to AMEFF (https://help.bluedolphin.io/en/articles/11967514-download-a-view), but an organisation's landscape plotted on GEMMA is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no GEMMA content and no ArchiMate file export are documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'archimate\\|gemma' over src/ templates/ locales/glpi.pot returns nothing; no GEMMA plotting or per entity model export. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43, no model file." } @@ -1189,6 +1285,7 @@ "stackiq": "appinfo/routes.php:107 POST /api/archimate/test-round-trip -> lib/Controller/SettingsController.php:2886 (@NoAdminRequired, any logged-in user) -> lib/Service/ArchiMateService.php:1496 testRoundTrip: reads $importResult['imported_count'] (:1528), a key no import path sets, and compares it to exportToArchiMate's 'exported_count' which is the literal string 'calculated_in_export_service' (:271), so it can never report success; it also imports a test model into the live register", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the merge guide checks the result inside Archi via its status log; the catalogue itself offers no round-trip check; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Archi_modellen_samenvoegen (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; AMEFF import and per view AMEFF export exist (https://help.bluedolphin.io/en/articles/11967637-import-ameff-files, https://help.bluedolphin.io/en/articles/11967514-download-a-view), but a check that a model survives the round trip is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no model file import and export pair (ArchiMate or similar) is documented, so no round trip check exists in the docs (read 2026-09-26)", "glpi": "source read at 11.0.9: there is no model import or export to round trip, grep -ril 'archimate' over src/ templates/ locales/glpi.pot returns nothing. Export formats are src/Glpi/Search/Output/Csv.php:38 and src/Glpi/Search/Output/Pdf.php:43, no model file." } @@ -1219,6 +1316,7 @@ "stackiq": "appinfo/routes.php:103 POST /api/archimate/import/cancel -> lib/Service/SettingsService.php:5200 calls ArchiMateService::cancelArchiMateImport(), which does not exist in lib/Service/ArchiMateService.php (Error, not caught by catch(\\Exception)); routes.php:119-120 /api/progress/{operationId} read ProgressTracker, but the ArchiMate import never writes to it (only SbomImportService gets it, lib/AppInfo/Application.php:507); ArchiMateImportExport.vue:538 shows only a spinner, no cancel button", "topdesk": "unknown: ArchiMate is not mentioned anywhere in the documentation (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no model import is documented; for export only \"Er verschijnt een venster met de melding dat de export gegenereerd wordt\"; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Handleiding%20koppeling%20architectuurtools (read 2026-09-26)", + "bluedolphin": "unknown: https://help.bluedolphin.io/en/articles/11967637-import-ameff-files says only 'When BlueDolphin has completed the action, a checkmark will appear'; progress while running and cancelling are not documented (read 2026-09-26)", "sap-leanix": "https://updates.leanix.net/announcements/product-update-march-2026: 'The new asynchronous import process runs entirely in the background ... A real-time progress widget in the inventory side-panel keeps you informed of import status'. This is the Excel import, not a model import, and cancelling is not described (read 2026-09-26). Reached on: Inventory side panel > import progress widget.", "glpi": "source read at 11.0.9: no model import exists (grep -ril 'archimate' src/ returns nothing), so there is no import to follow; the generic progress endpoint src/Glpi/Controller/ProgressController.php serves other long operations. The progress route is src/Glpi/Controller/ProgressController.php:50 /progress/check/{key}, used by the installer (src/Glpi/Controller/InstallController.php:57)." } @@ -1249,6 +1347,7 @@ "stackiq": "src/manifest.json StandaardDetail /standaarden/:id st-data widget shows all element fields (documentation, gemmaNotes) of a standard; FacetedCatalogIndexView.vue:150 shows reference components by name only", "topdesk": "unknown: GEMMA is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/lexicon: lexicon of catalogue terms (Addendum, Referentiecomponent, Standaard, SaaS); terms in page text link to it (read 2026-09-26); https://www.softwarecatalogus.nl/node/13683: \"Alle referentiecomponenten ... de toelichting bij de referentiecomponenten\" (read 2026-09-26). Reached on: Lexicon; Alle referentiecomponenten.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for GEMMA, no hits; object definitions follow ArchiMate (https://help.bluedolphin.io/en/articles/11967599-object-definitions) but in place definitions of GEMMA terms are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no GEMMA terms and no in-place glossary of reference architecture terms are documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -ril 'gemma\\|glossary' over src/ templates/ locales/glpi.pot returns nothing; no reference term definitions ship in core. The knowledge base (src/KnowbaseItem.php:57) is the only place definitions could be written by hand." } @@ -1277,7 +1376,7 @@ "note": "The mapping to GEMMA reference components exists, but there is no map view in stackiq; you only see it as a facet list or in Archi after an admin export.", "evidence": { "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model: 'A business capability is supported by an application'; https://help.sap.com/docs/leanix/ea/application-portfolio-assessment lists a 'Business capability map' (read 2026-09-26). Reached on: Reports > Landscape Report on Business Capabilities.", - "bluedolphin": "docs, intelligence competitor_features#27460 'Application Portfolio Management' (2026-04-12): Map applications to business goals and functions", + "bluedolphin": "https://bluedolphin.io/capability-based-planning/: 'Drag and drop multi-layer current and future state capability mapping' and 'Drill down instantly from capability scores to the processes, applications, and technologies'; https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'Connect applications to capabilities' (read 2026-09-26). Reached on: Views > capability map.", "stackiq": "module.referenceComponents / usage.usedForReferenceComponents in lib/Settings/softwarecatalogus_register.json hold the application-to-reference-component mapping; lib/Service/ArchiMateExportService.php:2734 draws it only into exported view copies", "topdesk": "unknown: no capability or function map is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30890: view \"RD02 Bedrijfsfuncties ruimtelijk domein met referentiecomponenten\" with the municipality's packages plotted (read 2026-09-26). Mapping runs through fixed GEMMA reference components and business functions, not the organisation's own capability model. Reached on: Mijn softwarecatalogus > Pakketten > kaart kiezen > Toon kaart.", @@ -1306,7 +1405,7 @@ "note": "Models are imported and exported as ArchiMate files; nothing lets a user draw or edit a model inside stackiq.", "evidence": { "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams and https://help.sap.com/docs/leanix/ea/working-with-fact-sheets-in-diagrams: free draw and data flow diagrams edited in the diagram editor, with an ArchiMate 3.2 shape template (https://help.sap.com/docs/leanix/ea/styles-and-patterns) (read 2026-09-26). Reached on: Diagrams > New Diagram (diagram editor).", - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#48968 'Free-form diagramming' (2026-07-23): Freeform diagrams alongside formal models.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967507-create-an-architecture-view and https://help.bluedolphin.io/en/articles/11967516-add-objects-to-architecture-views: users create and edit ArchiMate architecture views in the view editor (read 2026-09-26). Reached on: Views > Create view.", "stackiq": "src/manifest.json has no page for the view or element schema beyond Standaarden; no diagram editor in src/views or src/components", "topdesk": "unknown: no architecture modelling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the docs send users to Archi or other tools for modelling; drawing inside the catalogue is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30890 (read 2026-09-26)", @@ -1334,7 +1433,7 @@ "providerHow": "read-from-code", "note": "Business processes are not modelled; the only link applications have is to GEMMA reference components.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | docs, intelligence competitor_features#27464 'Process Mapping' (2026-04-12): Map processes, applications, data, and technology", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967673-process-linked-to-ea-perspectives: 'The Create BPMN diagram button allows you to create a diagram directly from a business process'; https://help.bluedolphin.io/en/articles/11967500-getting-started-with-process-publication-portal: 'For each application, you will find different processes in which the selected application is involved' (read 2026-09-26). Reached on: Processes > Process browser.", "stackiq": "no process schema in lib/Settings/softwarecatalogus_register.json (20 schemas listed under components.schemas); no process page in src/manifest.json", "topdesk": "unknown: no process modelling linked to applications is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no process modelling is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -1349,7 +1448,7 @@ "origin": "competitor", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -1367,6 +1466,7 @@ "stackiq": "searched src/manifest.json and the register for scenario/future-state/toekomst: nothing; usage.status 'Planned' and plannedReplacement (register) are per-usage fields, not a comparable landscape", "topdesk": "unknown: Long-Term Planning scenarios are for maintenance planning and the module \"will reach end of life ... November 2026\"; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"geplande harmonisaties ... met een status gepland met bijbehorende datum. Zo kan ook het uiteindelijke doel-landschap in 1 overzicht inzichtelijk worden gemaakt\" (read 2026-09-26). No side-by-side comparison of today and target. Reached on: Mijn softwarecatalogus (samenwerking) > Pakketten > status Gepland.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967531-object-lifecycle-state: 'Objects can be either Current (default) or Future state. Select the Future option to reflect how the object will look in the future', shown distinctly on views; https://bluedolphin.io/capability-based-planning/: 'Map current and future state capabilities' (read 2026-09-26). Reached on: Objects and views with Current and Future lifecycle state.", "glpi": "source read at 11.0.9: grep -rli 'future state\\|what-if\\|scenario' over src/*.php returns nothing; the impact graph (src/Impact.php:49) shows only the current relations, with no plateau or target landscape." } }, @@ -1377,7 +1477,7 @@ "origin": "competitor", "vng-softwarecatalogus": "partial", "sap-leanix": "partial", - "bluedolphin": "yes", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -1391,7 +1491,7 @@ "providerHow": "read-from-code", "note": "No report or view lists reference components that no application in your landscape covers.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48967 'Multi-modal analysis (gaps / dependencies)' (2026-07-23): Analyses ArchiMate/BPMN/free-form models to surface gaps and weak dependencies.", + "bluedolphin": "https://bluedolphin.io/capability-based-planning/: 'Run gap analyses to define a clear roadmap' and 'Identify capability gaps'. Gaps are found on the customer's own capability map; no reference architecture such as GEMMA is documented (read 2026-09-26). Reached on: Capability maps.", "stackiq": "grep for uncovered/gap/coverage in lib and src found nothing; lib/Service/FacetService.php counts modules per reference component but never lists components with zero coverage", "topdesk": "unknown: GEMMA reference components are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tile \"Pakketten met meer mogelijkheden: U heeft in uw pakketoverzicht pakketten die geschikt zijn voor referentiecomponenten waarbij u nog geen pakket heeft opgevoerd\" (read 2026-09-26). It lists uncovered components only where an owned package could fill them. Reached on: Dashboard tile Pakketten met meer mogelijkheden.", @@ -1420,7 +1520,7 @@ "providerHow": "read-from-code", "note": "Nothing drafts diagrams.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48970 'AI-powered diagramming' (2026-07-23): AI assists diagram generation. | docs, intelligence competitor_features#27461 'AI-Powered Diagramming' (2026-04-12): Auto-generate BPMN diagrams with built-in AI", + "bluedolphin": "https://help.bluedolphin.io/en/articles/12528662-ai-capabilities-of-bluedolphin: 'Modelling Assistant or BPMN Generator instantly creates BPMN 2.0-compliant process diagrams from a simple prompt or by uploading existing documentation' (read 2026-09-26). Reached on: Processes > Modeling Assistant.", "stackiq": "no diagram generation in lib/Service or src; no AI integration for diagrams", "topdesk": "unknown: the AI features cover tickets and knowledge, not diagrams; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no assistant is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -1454,6 +1554,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle standaarden: Dit overzicht is een opsomming van alle standaarden waaraan pakketten mogelijk moeten voldoen. Alle standaarden hebben een toelichting en indien aanwezig een toelichting op het compliancy-instrument\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle standaarden.", "stackiq": "src/manifest.json page Standaarden /standaarden (index on @resolve:amef_register schema element, filter gemmaType=standaard, columns name/gemmaThema/gemmaStatus/url) and StandaardDetail /standaarden/:id with compliance claims per standard; menu entry Standards (order 50)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no register of standards applications must support is documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/technology-standards-management-capabilities: Technology Risk and Compliance helps 'establish technology standards' for frameworks and languages. These are technology standards for components, not interoperability standards an application must support (read 2026-09-26). Reached on: Technology Risk and Compliance > technology standards.", "glpi": "source read at 11.0.9: no standards itemtype, grep -ril 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing and the word standard in src/Appliance.php occurs only in addStandardTab (src/Appliance.php:100)." } @@ -1465,7 +1566,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", @@ -1484,6 +1585,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.evidence (file, pdf/jpeg/png/doc, 10 MB), compliancy.url, compliancy.evidenceReference; src/manifest.json KompliantieDetail cm-files widget type integration integrationId files 'Evidence documents'", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Door de vakje achter de standaard aan te vinken voor Ondersteuning(gepland) en Compliancy, wordt de optie om een testrapport of auditrapport op te voeren geopend\" (read 2026-09-26). Reached on: Supplier login > productversie > Voeg extra standaarden toe.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967535-object-attachments: 'You can enrich your Blue Dolphin objects with additional information from saved files'. Files attach to the object, not to a specific compliance claim (read 2026-09-26). Reached on: Object > General tab > attachments.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets: 'The Resources tab ... You can upload files up to 10 MB' and links on any fact sheet. Files attach to the fact sheet, not to a specific compliance claim (read 2026-09-26). Reached on: Fact sheet > Resources tab.", "glpi": "source read at 11.0.9: any document can be attached to an appliance through the Documents tab, src/Appliance.php:100 Document_Item tab and src/Document_Item.php:46, stored in install/mysql/glpi-empty.sql:2585 glpi_documents; there is no compliance claim to attach it to. Reached on: Management > Appliances > Documents tab." } @@ -1514,6 +1616,7 @@ "stackiq": "src/utils/complianceMatrix.js:9-17 cell state verified = compliancy record with evidence (hasEvidence :107 checks evidence/evidenceReference/url), claimed = link without evidence; rendered by src/views/ComplianceMatrixView.vue", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C8: \"Gepubliceerde testrapporten voor een aantal standaarden die in de compliancy-monitor staan, worden sinds eind 2016 door VNG Realisatie gecontroleerd en daarna op status goedgekeurd of afgekeurd gezet\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facet \"Standaard met testrapport: Toon alleen pakketversies met compliancy aangetoond in een testrapport\" (read 2026-09-26). Reached on: Alle pakketversies > filter Standaard met testrapport; Compliancy monitor.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no distinction between verified and asserted compliance claims is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a quality seal approves fact sheet data as a whole (https://help.sap.com/docs/leanix/ea/updating-lifecycle-phase-and-approving-quality-seal) but no distinction between verified and supplier asserted compliance claims is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no compliance claim model, grep -rli 'complian' over src/Appliance.php src/Software.php returns nothing; nothing to mark verified or claimed (src/Appliance.php:46 fields are inventory and management fields only)." } @@ -1544,6 +1647,7 @@ "stackiq": "src/manifest.json ComplianceMatrix /compliance-matrix custom page -> src/customComponents.js ComplianceMatrixView -> src/views/ComplianceMatrixView.vue (modules x selected standard versions or BIO measures, src/utils/complianceMatrix.js:270 columns)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/compliancy_monitor: per standard (e.g. \"Betalen en invorderen services 1.0\") a table of Leverancier, Pakketversie, Compliancy \"Ok\" or \"Niet ok\" (read 2026-09-26). Fixed per standard, not a matrix of chosen applications against chosen standards. Reached on: Homepage > Compliancy monitor.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; heat maps by conditional layout and a Power BI relations cross-table exist (https://help.bluedolphin.io/en/articles/11967711-power-bi-for-bluedolphin-quickstart), but a matrix of applications against standards is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model-dora-extension: 'You can create a regulatory dictionary, categorize DORA requirements, and link DORA obligations directly to specific IT and business architecture elements'; https://help.sap.com/docs/leanix/ea/report-types: Matrix Report maps relations cell by cell. Regulation obligations, not interoperability standards (read 2026-09-26). Reached on: DORA extension + Reports > Matrix Report.", "glpi": "source read at 11.0.9: there are no standards in core (grep -rli 'standaard\\|forum standaardisatie' src/ locales/glpi.pot returns nothing), so no application by standard matrix; search output (src/Glpi/Search/Output/Spreadsheet.php) only tabulates item fields. The spreadsheet output is src/Glpi/Search/Output/Csv.php:38 and siblings." } @@ -1574,6 +1678,7 @@ "stackiq": "appinfo/routes.php:275 POST /api/bulk-sync-standards -> lib/Controller/SettingsController.php:3598 (isAdmin check) -> lib/Service/ModuleComplianceService.php:527 bulkSyncModuleStandards (reads up to 1000 compliancy records and updates module standards); UI src/views/settings/sections/StatisticsOverview.vue:79 button -> src/modals/BulkSyncDialog.vue:321", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: only per-version copying is described (\"opvoer van een nieuwe versies mogelijk als kopie van een op te geven vorige versie\"); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no standards set to refresh across applications is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no action that refreshes the standards set of many applications is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no standards model exists (see comp-standards-register); massive actions (src/MassiveAction.php:666 Update) update item fields only." } @@ -1604,6 +1709,7 @@ "stackiq": "src/manifest.json BioMaatregelen /bio-maatregelen index (columns code,name,thema,bioVersion,bbnNiveau) and BioMaatregelDetail; register property is bbnLevel (lib/Settings/softwarecatalogus_register.json bioMeasure), so the bbnNiveau column is empty; no BIO catalogue is seeded (only 6 demo objects in lib/Settings/stackiq_mock_register.json)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: BIO measures are not in the catalogue docs; BBN views live on GEMMA Online per the news page; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/nieuws (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for BIO and Baseline Informatiebeveiliging, no hits; the only security template is an 'ISO27001 Management System template' for 'an Information Security Management System' (https://help.bluedolphin.io/en/articles/11967582-iso27001-management-system-template), not the BIO measure set (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for BIO and Baseline Informatiebeveiliging, no hits; LeanIX documents DORA and GDPR content only (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'iso 27001\\|27002' and grep -rwi 'bio' over src/ locales/glpi.pot return nothing; no security measure catalogue ships (menus at src/Html.php:1295 onwards list none)." } @@ -1634,6 +1740,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.bioMeasure links a module to a BIO measure; src/manifest.json ModuleDetail md-compliance lists claims incl. bioMaatregel column, BioMaatregelDetail bm-compliance lists modules per measure; compliancy has no status/met-not-met field", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no BIO assessment per application is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for BIO, no hits; recording which BIO measures an application meets is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for BIO, no hits; no BIO measure assessment per application is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no measure catalogue and no assessment itemtype; grep -rli 'iso 27001\\|27002' over src/ locales/glpi.pot returns nothing and Appliance tabs (src/Appliance.php:98 onwards) hold no assessment." } @@ -1664,6 +1771,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json module.dpiaStatus (enum not required/required/executed), dpiaDate, dpiaNextAssessment, dpiaDocumentRef; src/manifest.json ModuleDetail md-data includes the DPIA fields; Modules /modules quick filter 'Without DPIA (BBN2+)'", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no DPIA field is described; the VWO addendum is a supplier-level processing agreement; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/leveranciers (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for DPIA, GDPR and AVG, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for DPIA and data protection impact assessment, no hits; only data classification of data objects for GDPR is documented (https://help.sap.com/docs/leanix/ea/data-object-modeling-guidelines 'classified into personally identifiable data (e.g., to cater to GDPR use cases)') (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'dpia\\|impact assessment\\|gdpr' over src/ returns nothing, locales/glpi.pot:12792 'gdpr-tools' is only an icon name. The GDPR records plugin yild/gdprropa read at tag 1.0.3 has 'PIA required' and 'PIA status' (inc/record.class.php:459, :468) but declares GLPI 10 only, setup.php:56 max 10.99.99, so it does not run on 11.0.9." } @@ -1692,6 +1800,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/inkoopondersteuning%20standaarden: \"De verplichte standaarden zijn: ... de open standaarden die onder het pas-toe-of-leg-uit regime van de overheid binnen het werkingsgebied vallen\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: package version shows \"Verplichte standaarden ... Ondersteuning Compliancy Testrapport\" (read 2026-09-26). Comply-or-explain standards are mixed into the mandatory set, not shown as their own list. Reached on: Package page > Standaarden; Inkoopondersteuning.", "stackiq": "grep for forum standaardisatie / pas toe of leg uit / comply-or-explain in lib and src: no hits; standards come only from the GEMMA AMEF import (element gemmaType=standaard)", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for Forum Standaardisatie, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for Forum Standaardisatie and comply or explain, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'standaard\\|forum standaardisatie\\|comply' over src/ locales/glpi.pot returns nothing relevant; no comply or explain list in core (Setup menu src/Html.php:1330 onwards)." } @@ -1703,7 +1812,7 @@ "origin": "competitor", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -1720,6 +1829,7 @@ "stackiq": "grep for completeness/health score/quality score in lib and src: no hits; lib/Command/ReferencesAuditCommand.php:34 (occ stackiq:references:audit) only audits cross-app uuid references, it is not a scored rule set", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C7: automatic checks and \"Te corrigeren fouten ... Bijvoorbeeld over het ontbreken van pakketversies, of tegenstrijdigheid in de status van een pakketversie en vermelde datum distributie\" (read 2026-09-26); https://www.softwarecatalogus.nl/voortgang-verbeteren: star criteria for completeness (read 2026-09-26). Reached on: Supplier dashboard Te corrigeren fouten; Voortgang sterren.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967713-governance-insights: 'Governance reports will help maintain oversight of object usage, completeness, and relationships', incl. 'Object completeness ... completeness score of each object' and 'Objects not on any view' (read 2026-09-26). Reached on: Insights > Governance reports.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-portfolio-management-dashboard: 'Data Quality KPI ... Overall Completion of Applications ... Broken quality seal ... Missing Business Capability'; completion score weights set by admins (https://help.sap.com/docs/leanix/ea/fact-sheet-completeness) (read 2026-09-26). Reached on: Dashboards > Application Portfolio Management Dashboard > Data Quality KPIs.", "glpi": "source read at 11.0.9: grep -ril 'completeness' over src/ templates/ locales/glpi.pot returns nothing and no rule set scores register quality; the rules engine (src/Glpi/Rules/, src/RuleCollection.php) assigns and imports data, it does not score it. The rules engine base is src/RuleCollection.php:48." } @@ -1731,7 +1841,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "partial", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -1745,7 +1855,7 @@ "providerHow": "read-from-code", "note": "Nothing sends questionnaires to suppliers or stores their answers.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48974 'Questionnaires / data collection' (2026-07-23): Surveys to gather portfolio data from stakeholders. | Rated partial because questionnaires collect portfolio data.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967524-create-a-survey: surveys 'allowing external stakeholders to contribute directly to the Enterprise Architecture repository', sent 'to multiple recipients simultaneously via email' from an object's questionnaire, answers kept on the object (read 2026-09-26). Reached on: Object > Questionnaire tab > Create survey.", "stackiq": "grep for questionnaire/vragenlijst in lib and src: no hits; no questionnaire schema in lib/Settings/softwarecatalogus_register.json", "topdesk": "unknown: standards compliance of applications, BIO and DPIA are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no questionnaire to suppliers is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -1779,6 +1889,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"Deze handleiding is bedoeld voor de leveranciers en legt uit hoe de leveranciers hun productportfolio kunnen aanvullen en beheren ... voeg pakket toe\" (read 2026-09-26). Reached on: Supplier login > Productportfolio.", "stackiq": "src/manifest.json:592 Modules and :647 Diensten are FacetedCatalogIndexView over schema module/catalogService (CnIndexPage, showAdd default true); lib/Settings/softwarecatalogus_register.json:6779 module has provider + publicationDate (visible on form) and public read when publicationDate <= now or registeredBy Supplier", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; BlueDolphin is a per customer EA repository, supplier publication of offerings is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; LeanIX is a customer's internal EA workspace, no supplier facing publication of offerings is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers are records kept by the buying organisation, install/mysql/glpi-empty.sql:7067 glpi_suppliers, with no supplier login or offering page; profiles (src/Profile.php) cover internal users and the self-service helpdesk only." } @@ -1809,6 +1920,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Ik ben op zoek naar een nieuw pakket voor referentiecomponent voor BAG-administratie\" and standards filters combine (read 2026-09-26); https://www.softwarecatalogus.nl/pakketten: facets Referentiecomponent and Standaard (read 2026-09-26). Reached on: Alle pakketten > filters.", "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS referenceComponent, standard, applicationService, domain for schemas module and catalogService (:102); src/views/FacetedCatalogIndexView.vue:108 CnFacetSidebar narrows CnIndexPage; route GET /api/facets/{schema} called from src/services/facets.js", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no market wide software search is documented (read 2026-09-26)", "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/applications-in-reference-catalog: the catalog 'covers SAP applications, SAP AI agents, and SaaS applications' and is used to link your own fact sheets; market search by reference component and standard is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: search covers only the organisation's own records (src/Glpi/Search/SearchEngine.php); there is no market wide catalogue and no reference component or standard to filter on (grep -ril 'gemma\\|reference component' src/ returns nothing). The marketplace (src/Glpi/Marketplace/) lists GLPI plugins, not software for a task. The search engine is src/Glpi/Search/SearchEngine.php:101; the marketplace is src/Glpi/Marketplace/Controller.php:64." } @@ -1837,6 +1949,7 @@ "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization with status filter and OrganisatieCard; register :2022 organization.type is facetable (Municipality/Supplier/Collaboration/Community); public read of Active suppliers in organization authorization (:2467)", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/leveranciers: \"Leveranciers ... Zoek in leveranciers ... 354 resultaten gevonden\", filter \"Met ondertekend addendum\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle leveranciers.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no directory of suppliers across the market is documented (read 2026-09-26)", "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/provider-modeling-guidelines: 'SAP LeanIX has a catalog of 9000 providers' added automatically with IT components; browsing that catalog as a directory with filters is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Supplier.php:46 Supplier list under Management (src/Html.php:1298) with search, filters and a supplier type (install/mysql/glpi-empty.sql:7072 suppliertypes_id), but it holds only the suppliers this organisation entered, not all organisations offering to government. Reached on: Management > Suppliers (front/supplier.php). Driven on the lab at 11.0.9 (2026-09-26): created supplier \"Lab Leverancier BV\" through /front/supplier.form.php; it appears in the Suppliers list." } @@ -1865,6 +1978,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle gemeenten ... inclusief contactgegevens van gemeenten ... U kunt contact onderhouden met deze gemeenten\" (read 2026-09-26). Reached on: Inlogmenu > Alle gemeenten.", "stackiq": "Looked in src/components, src/views and lib/Controller for any contact or messaging between organisations sharing a module: none. Usage read rules (register :3137) hide other organisations' usages from municipalities.", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; a vendor community is referenced in the docs (https://help.bluedolphin.io/en/articles/11967582-iso27001-management-system-template 'a post on the community'), but finding peers who use the same product is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a vendor community exists (https://community.leanix.net/) but no in product way to find organisations using the same product is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: each GLPI instance holds one organisation's data (entities are internal subdivisions, src/Entity.php), so there is no view of other organisations using the same product; grep -rli 'peer' src/*.php matches only relation and network code such as src/CommonDBConnexity.php, no peer organisation feature." } @@ -1895,6 +2009,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle pakketversies en planningen ... gelijk zichtbaar de planning van de diverse pakketversies\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketversies: facet \"Status planning ... Filter op in ontwikkeling en zie de distributie planningsdata\" (read 2026-09-26). Reached on: Wat is er te vinden > Alle pakketversies en planningen.", "stackiq": "register :7651 moduleVersion with status enum in development/in use/end of support/withdrawn and dateInDevelopment/dateInUse/dateEndSupport, read public; src/manifest.json:915 Moduleversies index + ModuleversieDetail", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; roadmap templates are for the customer's own plans (https://help.bluedolphin.io/en/articles/11967586-roadmap), suppliers' declared roadmaps are not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-components-in-reference-catalog: 'The catalog provides standardized IT component data including lifecycle dates, vendor information ... You no longer need to track vendor lifecycle dates manually'. Vendor lifecycle and support dates, not planned releases; needs Technology Risk and Compliance (read 2026-09-26). Reached on: IT Component fact sheet linked to the reference catalog.", "glpi": "source read at 11.0.9: suppliers (install/mysql/glpi-empty.sql:7067 glpi_suppliers) carry address and contact fields only, and software versions (install/mysql/glpi-empty.sql:6900) carry no planned release date; grep -rli 'roadmap' src/*.php returns nothing." } @@ -1925,6 +2040,7 @@ "stackiq": "src/manifest.json:514 ModuleDetail bodyWidget ReviewsPanel; src/components/reviews/ReviewsPanel.vue:63 opens SubmitReviewModal; POST /api/reviews -> lib/Service/ReviewService.php:232 stamps author and forces status pending; rating 1..10 in software-review schema (:3961)", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no reviews are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; user reviews with ratings of applications are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no user review of an application with a rating is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no product review model; satisfaction surveys rate ticket handling only (src/CommonITILSatisfaction.php) and knowledge base comments (src/KnowbaseItem_Comment.php) carry no rating. Ticket satisfaction is src/CommonITILSatisfaction.php:43 and knowledge base comments src/KnowbaseItem_Comment.php:43." } @@ -1955,6 +2071,7 @@ "stackiq": "lib/Service/ReviewAggregateService.php:51 approved-only average + count; GET /api/reviews/aggregate (PublicPage) called from src/utils/reviewAggregate.js imported by src/components/reviews/ReviewsPanel.vue", "topdesk": "unknown: TOPdesk is a single-organisation tool; no market-wide catalogue is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no ratings are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no review ratings exist in the docs to aggregate (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no review ratings exist in the docs to aggregate (read 2026-09-26)", "glpi": "source read at 11.0.9: with no product reviews there is no average rating; the only averages are ticket satisfaction statistics (src/CommonITILSatisfaction.php). Ticket satisfaction is src/CommonITILSatisfaction.php:43." } @@ -1983,6 +2100,7 @@ "stackiq": "register :6856 module.contactPerson -> contactPerson with x-relation-filter organization = @object.provider; catalogService and suite also carry contactPerson; src/manifest.json:500 ModuleDetail md-data include lists 'contactpersoon', 'beschrijvingKort', 'beschrijvingLang', which are not module properties (renamed to contactPerson/shortDescription/longDescription)", "topdesk": "unknown: supplier contacts are registered per supplier (\"Registering a supplier contact\"); contacts per product are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the docs name one contact per supplier (\"Bij elke leverancier is een contactpersoon opgevoerd\"); whether a product can carry its own is not stated; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/30402 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; supplier contact persons per product are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; subscriptions name internal users per fact sheet, but supplier contact persons per product are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: contacts link to a supplier as a whole, src/Contact_Supplier.php:39 (install/mysql/glpi-empty.sql:1429 glpi_contacts_suppliers), not to a product; per application there is only the free text contact field on an appliance (src/Appliance.php:214) and the user or technician in charge. Reached on: Management > Suppliers > Contacts tab; Appliance contact field." } @@ -1994,7 +2112,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "yes", @@ -2012,6 +2130,7 @@ "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier ... The Supplier Card has been created\" and \"Registering a supplier contact\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Create a new preliminary contract or preliminary supplier contract\" (read 2026-09-26). Reached on: Supporting Files > New > Supplier.", "stackiq": "register :2022 organization (one record, type Supplier); module.provider (:6921) and catalogService.provider (:3762) are $ref organization; catalogContract points at service (+usage), register :3252; OrganisatieDetail src/manifest.json:403 lists the supplier's services and applications", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"De verbinding met de leveranciersgegevens garandeert juiste schrijfwijzes van leveranciers- en pakketnamen en juiste versienummering\" (read 2026-09-26); https://www.softwarecatalogus.nl/leveranciers: one record per supplier with contact and addenda (read 2026-09-26). There are no contracts to point to it. Reached on: Alle leveranciers > supplier page.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967745-update-an-object-definition shows 'Supplier' as an object property value on an application definition; a supplier could be a separate ArchiMate actor object, but a vendor record that products and contracts point to is not documented (read 2026-09-26). Reached on: Object property Supplier.", "glpi": "source read at 11.0.9: one Supplier record (src/Supplier.php:46, install/mysql/glpi-empty.sql:7067) is referenced by contracts through install/mysql/glpi-empty.sql:1550 glpi_contracts_suppliers and by the financial record of any item through install/mysql/glpi-empty.sql:3263 glpi_infocoms.suppliers_id. Reached on: Management > Suppliers." } }, @@ -2022,7 +2141,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "yes", @@ -2042,6 +2161,7 @@ "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options: 'The lifecycle filter enables filtering of fact sheets by their lifecycle state: plan, phase-in, active, phase-out, and end-of-life' (read 2026-09-26). Reached on: Application fact sheet > Lifecycle.", "topdesk": "https://docs.topdesk.com/en/managing-disruptions-in-your-asset-management-process.html: built-in \"operational/impacted status for assets\" (read 2026-09-26); lifecycle phases need a self-defined drop-down field (https://docs.topdesk.com/en/creating-new-fields.html). No planned, in use, phase-out model ships. Reached on: Asset card > General widget.", "stackiq": "src/manifest.json LifecycleRoadmap /portfolio-roadmap custom page -> src/views/LifecycleRoadmapView.vue:55 groups the selected organisation's usages by phase, derived from usage dates by src/utils/lifecyclePhase.js derivePhase (:408); usage.status enum Acquisition/Planned/In production/To be phased out/Phased out in lib/Settings/softwarecatalogus_register.json", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967531-object-lifecycle-state: 'Objects can be either Current (default) or Future state'; https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'TIME powered application lifecycle management ... Capture lifecycle'. Only current and future are documented as states, not planned, in use and phasing out (read 2026-09-26). Reached on: Objects > Object lifecycle state.", "glpi": "source read at 11.0.9: appliances carry a status, install/mysql/glpi-empty.sql:8950 glpi_appliances.states_id and src/Appliance.php:350 search option Status, whose values are an admin defined tree dropdown src/State.php:45 (install/mysql/glpi-empty.sql:7027 glpi_states), so phases such as planned, in use and being phased out are set up and filtered on. Reached on: Management > Appliances, Status field; Setup > Dropdowns > Statuses of items." } }, @@ -2052,7 +2172,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "yes", @@ -2072,6 +2192,7 @@ "sap-leanix": "https://help.sap.com/docs/leanix/ea/report-types: 'Roadmap Report Visualizes fact sheets on a timeline to show the evolution of the IT landscape'; https://help.sap.com/docs/leanix/ea/application-rationalization-create-roadmap (read 2026-09-26). Reached on: Reports > Roadmap Report.", "stackiq": "src/views/LifecycleRoadmapView.vue:28 organisation select, :55 phase groups, :96-110 phase-out date, planned replacement and link to the replacing module (:400 plannedReplacement, :423 plannedReplacementDate), ordered by nearest urgency (:428)", "topdesk": "unknown: no replacement roadmap is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967586-roadmap: a roadmap template where 'The first axis shows the years and the second axis shows per business unit what should be done during those years', drawn as a view; https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'Portfolio decisions flow directly into roadmaps' (read 2026-09-26). Reached on: Views > Roadmap template.", "glpi": "source read at 11.0.9: replacements can be planned as projects linked to the appliance, src/Appliance.php:108 Item_Project tab (src/Item_Project.php:45) and src/Project.php:50 Project with Kanban; the Gantt view is the separate gantt plugin (src/Project.php:599 checks isActivated('gantt')). No per organisation application roadmap view exists. Reached on: Tools > Projects, Appliance > Projects tab." } }, @@ -2082,7 +2203,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown", "stackiq": "no", @@ -2100,6 +2221,7 @@ "stackiq": "grep for overlap/redundant in lib and src finds only code comments and the Reports card description (src/manifest.json:1031 'Overlapping and ageing software'); lib/Service/PortfolioReportService.php computes TIME quadrants, EOL exposure, cloud share and cost, no grouping by reference component; the /modules facet counts modules per reference component across the whole catalogue, not your landscape", "topdesk": "unknown: no functional classification to detect overlap is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tile \"Referentiecomponenten met meerdere pakketten: Deze tegel signaleert dat er meer dan 1 pakket(versie) bij eenzelfde referentiecomponent in productie is\" (read 2026-09-26). Reached on: Dashboard tile Referentiecomponenten met meerdere pakketten.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967472-welcome-to-bluedolphin: 'overlapping application functions are quickly made visible'; https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'automatically detect redundancies' and 'Connect applications to capabilities for capability-based rationalization' (read 2026-09-26). Reached on: Application functions and capability maps.", "glpi": "source read at 11.0.9: no reference component model to detect overlap on, grep -rli 'reference component\\|gemma' over src/ locales/glpi.pot returns nothing; appliances only carry a free type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." } }, @@ -2110,7 +2232,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", "stackiq": "partial", @@ -2128,6 +2250,7 @@ "stackiq": "appinfo/routes.php:303 GET /api/portfolio-report -> lib/Controller/PortfolioReportController.php -> lib/Service/PortfolioReportService.php + PortfolioReportDerivation.php; UI src/views/organisaties/PortfolioReport.vue (TIME chart :112, quadrant summary :126 with EOL exposure/cloud/cost, rows :176, CSV export :50)", "topdesk": "unknown: no rationalisation report is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Referentiecomponenten met meerdere pakketten ... per referentiecomponent aan welke pakketversies daaraan gekoppeld zijn\" (read 2026-09-26). Overlap only, ageing not covered. Reached on: Dashboard tile.", + "bluedolphin": "https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'TIME analysis across your entire application portfolio', 'automatically detect redundancies, surface lifecycle risks' and 'Out of the box reports and insights'. No named rationalisation report is described in the help center (read 2026-09-26). Reached on: Insights and APM views.", "glpi": "source read at 11.0.9: the built in report list src/Report.php:77 to src/Report.php:111 holds default, by contract, by year, financial, network, loan and status reports; none covers overlapping or ageing software." } }, @@ -2157,6 +2280,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json usage.moduleVersion ($ref moduleVersion); read by src/views/LifecycleRoadmapView.vue:397 for EOL state; ModuleversieDetail mv-related shows related usages; no usage create/edit page in src/manifest.json", "topdesk": "unknown: versions in use are only possible as a self-defined field; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Pakketversie - selecteer de versie die in gebruik is\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; recording the version an organisation runs is not documented beyond configurable fields (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: version can be captured 'in the Release field of the application fact sheets', which the guide says rarely adds value; IT components carry release per catalog item (https://help.sap.com/docs/leanix/ea/it-components-in-reference-catalog) (read 2026-09-26). Reached on: Application or IT Component fact sheet > Release.", "glpi": "source read at 11.0.9: src/Item_SoftwareVersion.php:39 records which software version is installed on which item (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions with date_install at :1074), filled by hand or by native inventory, and listed on the Software Installations tab (src/Software.php:129). Reached on: Assets > Software > Installations tab." } @@ -2187,6 +2311,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications module-version-published (trigger created, recipients object-acl manage + group software-catalog-admins); no notification code in lib (no INotificationManager use)", "topdesk": "unknown: no supplier version feed is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/suggesties_overnemen: \"Wanneer een leverancier een pakketversie registreert kan deze een suggestie versturen naar de gemeenten en samenwerkingen die dit pakket afnemen\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C2: \"Via de notificatiefunctie krijgt u een signaal zodra het versienummer is toegevoegd\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Suggesties; Inbox.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; notifications about supplier releases are not documented (read 2026-09-26)", "sap-leanix": "unknown: https://updates.leanix.net/announcements/work-with-complete-technology-version-coverage-without-raising-manual-requests (2026-09-17) says the catalog is 'kept current as new versions are released', with version concurrency management planned for Q4; a notification to users about a new version is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: GLPI has no feed of supplier releases; software versions appear only when entered or inventoried (src/SoftwareVersion.php:42), and notification events for software are licence expiry only (src/NotificationTargetSoftwareLicense.php)." } @@ -2216,6 +2341,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json sbomComponent has name/version/purl/licenses/type/hashes/bomRef/vexCveIds, no lifecycle or EOL field; the EOL feed (lib/Service/EolSyncService.php:290) only stamps versions of modules with eolProductSlug; no relation from an application to the platform it runs on", "topdesk": "unknown: no technology lifecycle is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: technologies per version are recorded (\"Pakketversie is beschikbaar voor één of meerdere technologien; databases, OS, SAAS\") but no lifecycle for them is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; technology objects carry only current or future state (https://help.bluedolphin.io/en/articles/11967531-object-lifecycle-state), end of support tracking of technology is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: underlying technology is held as items (database instances src/DatabaseInstance.php, operating systems, software) and each can carry a financial record with warranty and decommission date, install/mysql/glpi-empty.sql:3282 glpi_infocoms.decommission_date; there is no end of support date or lifecycle feed (grep -i 'end_of_support' install/mysql/glpi-empty.sql returns nothing). Reached on: any item > Management tab (Infocom)." } }, @@ -2240,7 +2366,7 @@ "providerHow": "read-from-code", "note": "Strategic goals are not modelled.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#27466 'Strategy Alignment' (2026-04-12): Connect architecture to strategic objectives", + "bluedolphin": "https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'Applications natively connected to BPMN, ERD, strategy, and initiatives' and 'Align applications with strategic initiatives and roadmaps'; https://bluedolphin.io/capability-based-planning/: 'Connect capabilities directly to business objectives' (read 2026-09-26). Reached on: Objects and relationships to strategy elements.", "stackiq": "no goal/strategy schema among the 20 in lib/Settings/softwarecatalogus_register.json; grep for strateg/doel in src/manifest.json: none", "topdesk": "unknown: no strategic goals are described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no strategic goals are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -2274,6 +2400,7 @@ "stackiq": "openspec/features.overlay.json maintenance-and-supplier-roadmap status 'soon'; no maintenance schema in lib/Settings/softwarecatalogus_register.json and no page in src/manifest.json", "topdesk": "https://docs.topdesk.com/en/operations-management.html: \"In TOPdesk you can easily schedule operational activities in the user-friendly planner. If you wish to schedule a recurring activity, you can use a series\" (read 2026-09-26); https://docs.topdesk.com/en/linking-assets-to-cards.html: assets can be linked to \"Operational Activity\" cards (read 2026-09-26). Reached on: Modules > Operations Management > Planner.", "vng-softwarecatalogus": "unknown: no maintenance announcements are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; planned maintenance of applications is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; planned maintenance is documented only for LeanIX's own service status (https://help.sap.com/docs/leanix/ea/status-pages-and-status-emails), not for applications in the inventory (read 2026-09-26)", "glpi": "source read at 11.0.9: no maintenance window on an item ('Maintenance mode' in locales/glpi.pot:7534 is GLPI's own downtime switch); planned work is a change linked to the appliance, src/Appliance.php:107 Change_Item tab, with planned tasks carrying begin and end (install/mysql/glpi-empty.sql:792 glpi_changetasks, :799 begin, :800 end) shown in the planning. Reached on: Appliance > Changes tab; Assistance > Planning." } @@ -2304,6 +2431,7 @@ "stackiq": "lib/Service/ContractStatusService.php:77 shouldExpire and :114 expirePastContracts set Active -> Expired when endDate < now; lib/BackgroundJob/ContractStatusJob.php:57 daily, registered in appinfo/info.xml:99", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Status: Configurable drop-down showing the contract's lifecycle status, e.g. draft, active ... Reminder date\" (read 2026-09-26); https://docs.topdesk.com/en/terminating-a-contract.html: \"The contract will terminate once the end date passes\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; 'Contract' exists as an ArchiMate object definition (https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl) and contract dates appear in an import example (https://help.bluedolphin.io/en/articles/11967633-datacollector-select-tricks), but a contract status that moves by itself is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'The contract fact sheet uses lifecycle phases to represent the current state of a contract': Plan, Phase In, Contract Start Date (active), Contract Notice Period, Contract End Date (expired). Requires the contract extension (read 2026-09-26). Reached on: Contract fact sheet > Lifecycle.", "glpi": "source read at 11.0.9: contract status is a manual dropdown (install/mysql/glpi-empty.sql:1512 glpi_contracts.states_id); expiry is computed, src/Contract.php:654 virtual 'Expiration' column from begin date, duration and renewal, and src/Contract.php:1092 cronContract sends end and notice alerts, but the status itself never moves by itself. Reached on: Management > Contracts list, Expiration column." } @@ -2335,6 +2463,7 @@ "stackiq": "src/components/contracts/ContractApprovalPanel.vue:183 canSubmitRenewal for status Expired; POST /api/contracts/{uuid}/approval/renewal -> ContractApprovalService.php:254 with decisionType contract-renewal; lib/EventListener/DecisionConcludedListener.php projects the outcome (approvalState, status Active) via DECISION_CONCLUDED_EVENTS registered in lib/AppInfo/Application.php:830", "topdesk": "https://docs.topdesk.com/en/extending-a-contract.html: \"Under Create , select Extend contract ... The contract is now a preliminary contract ... Click Validate Contract\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Sequence Number ... goes up by 1 each time the contract is extended ... so you can trace the contract's extension history\" (read 2026-09-26). Reached on: Contract card > Create > Extend contract.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; contract renewal decisions are not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Contract Renewal Status ... Backlog, In Review, In Progress, or Done', 'Contract Renewal Decision ... Renew, Terminate, or No Decision', 'Contract Renewal Comments' (read 2026-09-26). Reached on: Contract fact sheet > Contract Renewal.", "glpi": "source read at 11.0.9: src/Contract.php:60 to :62 renewal kinds never, tacit and express, with the renewal computation in the alert cron (src/Contract.php:1293); there is no renewal decision record or outcome, only the contract's renewal setting and an optional approval through a change. Reached on: Management > Contracts, Renewal field." } @@ -2346,7 +2475,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "no", @@ -2366,6 +2495,7 @@ "stackiq": "src/manifest.json:491 ModuleDetail widgets: md-data, md-files, md-related, md-compliance, md-versions, ReviewsPanel; no catalogContract list. catalogContract points at service and usage (register :3252), not at module, so the one-hop related panel cannot reach it", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: assets link to \"Service cards\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"On the Services tab, link the services that apply to this contract\" (read 2026-09-26). Contract to asset runs through the service. Reached on: Contract > Services tab > Service > Links > Assets.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl lists the object definition 'Contract', which can be related to an application and then shows in its Relationships tab (https://help.bluedolphin.io/en/articles/11967550-working-with-object-relationships); https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'Capture lifecycle, technical debt, business value, risk, cost, contracts' (read 2026-09-26). Reached on: Application object > Relationships tab (Contract objects).", "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: relation 'Attached to Contract - Application Many-to-Many Links the contract to the applications it licenses or supports' (read 2026-09-26). Reached on: Application fact sheet > Contracts relation." } }, @@ -2376,7 +2506,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "yes", @@ -2396,7 +2526,8 @@ "glpi": "source read at 11.0.9: contract costs have a period and a budget, install/mysql/glpi-empty.sql:1458 glpi_contractcosts with begin_date, end_date, cost and budgets_id; the contract list sums them in the 'Total cost' column (src/Contract.php:773) and a budget with a period shows spend per entity and type (src/Budget.php:537 showValuesByEntity). Reached on: Management > Contracts (Total cost column); Management > Budgets.", "stackiq": "lib/Service/PortfolioReportDerivation.php:163 annualisedCost (Monthly x12, Annually x1, One-off separate); lib/Service/PortfolioReportService.php:337 sumContractCost per quadrant; src/views/organisaties/PortfolioReport.vue:167 and :248 show annualised cost; src/utils/contractCost.js:111 totalAnnualisedCost used by src/views/LicensePostureView.vue per vendor", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Costs (Services) ... Total internal cost, based on the service levels linked\" (read 2026-09-26); https://docs.topdesk.com/en/obtain-insights-with-asset-type-report.html: \"do you need an overview of the total costs of new assets? Use the Asset Type Report\" (read 2026-09-26). Reached on: Contract card > Financial; Asset Type Report.", - "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967733-quick-start-guide shows a questionnaire field 'Estimate of annual application costs' of type currency; https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'portfolio analysis from cost, risk, lifecycle' (read 2026-09-26). Reached on: Application questionnaire > annual cost field." } }, { @@ -2426,6 +2557,7 @@ "stackiq": "register :6937 module.licentietype enum Closed source/Open source and module.licence (five open-source licence names); catalogContract.contractType enum SLA/Licence/Maintenance (:3341)", "topdesk": "unknown: licence cards hold number, code, purchase and expiration date; a licence model is only possible as a self-defined field; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/nieuws: \"is er de leverancier Open Source Pakketten aangemaakt. Onder deze leverancier staat nu een aantal veelgebruikte open source pakketten geregistreerd\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: Archi listed under supplier \"Open Source pakketten\", version \"Open source\" (read 2026-09-26). Other licence models are not recorded. Reached on: Alle pakketten > Leverancier Open Source pakketten.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; licence data appears only as example source columns ('Monthly License Costs', https://help.bluedolphin.io/en/articles/11967633-datacollector-select-tricks), a licence model field is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Contract Pricing Type Single select Consumption Based, Yearly Commitment, or Perpetual Licenses'. No open source or per user licence model field on the application is documented (read 2026-09-26). Reached on: Contract fact sheet > Contract Pricing Type." } }, @@ -2453,6 +2585,7 @@ "stackiq": "src/views/LicensePostureView.vue:11 open-source vs closed-source share weighted by in-production usage, :64 per-vendor rollup, per-organisation open-source-first report; derived in src/utils/licensePosture.js", "topdesk": "unknown: no portfolio licence posture is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; a portfolio licence posture view is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; licence analysis exists only for SBOM components of self-built software (https://help.sap.com/docs/leanix/ea/sbom-explorer 'assess license risks by filtering for unpermitted licenses'), not a portfolio share of open source applications (read 2026-09-26)", "glpi": "source read at 11.0.9: licences can be listed and filtered by type in search (install/mysql/glpi-empty.sql:6775 softwarelicensetypes_id), but the dashboard's per type charts cover asset types and Software only (src/Glpi/Dashboard/Grid.php:1452), not licences, and no portfolio share view exists. Reached on: Management > Licenses, filtered by type." } @@ -2484,6 +2617,7 @@ "stackiq": "grep for seat/licence count across lib/, src/ and the register finds no seat or quantity field on catalogContract (:3252), module or usage", "topdesk": "https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"add fields to fill the number of licences you have purchased and still have left ... the Relationship grid widget on the software cards will display details about the licences\" (read 2026-09-26). Reached on: Asset Management > software card > Relationship grid.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; licences bought against used are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for seats and licence counts, no hits; the contract fact sheet has cost fields but no licence quantity (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) (read 2026-09-26)" } }, @@ -2511,6 +2645,7 @@ "stackiq": "No entitlement or consumption fields exist (see ctr-seat-count); no service computes a licence position in lib/Service/", "topdesk": "https://docs.topdesk.com/en/managing-licences-in-asset-management.html: \"Knowing which software tools are used by whom ... the legal implications of using a tool without being licensed\" (read 2026-09-26). Entitlement against linked users, no measured consumption. Reached on: Asset Management > licence cards.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no entitlement against consumption computation is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no entitlement against consumption computation is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: entitlement is compared with licence assignments (src/SoftwareLicense.php:158 computeValidityIndicator), while measured installations are counted separately (src/Item_SoftwareVersion.php:39); core has no computed effective licence position report reconciling the two for an audit. Reached on: Assets > Software > Licenses and Installations tabs." } @@ -2540,6 +2675,7 @@ "stackiq": "grep for budget across lib/, src/ and lib/Settings finds no budget schema or field; catalogContract has cost + costPeriod only (register :3363)", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Budget holder: Cost-accounting owner of the contract\" and \"Applicable to ... Budget holder\" (read 2026-09-26). No budget with a period is described. Reached on: Contract card > Financial.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for budget, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; the contract has a 'Contract Cost Center' string (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) but charging costs against a budget with a period is not documented (read 2026-09-26)" } }, @@ -2568,6 +2704,7 @@ "stackiq": "grep for depreciation/afschrijving finds nothing in lib/, src/ or the register", "topdesk": "unknown: depreciation is not mentioned (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for depreciation, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for depreciation and amortisation, no hits (read 2026-09-26)" } }, @@ -2578,7 +2715,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "yes", @@ -2598,6 +2735,7 @@ "stackiq": "src/manifest.json:567 ContractDetail ct-files integration 'files' (Documents panel); catalogContract.documentReference text field (register :3252)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"You can view the contracts in a variety of formats, including PDF\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Archive Number (Free text) Reference to a physical or external archived copy of the contract document\" (read 2026-09-26). Reached on: Contract card.", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967535-object-attachments: files can be uploaded to any object, which covers a Contract object (https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl); no contract record with a document slot is documented (read 2026-09-26). Reached on: Contract object > attachments.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets: 'Files : You can upload files up to 10 MB. Uploaded files are then visible in the Resources tab', which applies to the contract fact sheet of the contract extension (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model) (read 2026-09-26). Reached on: Contract fact sheet > Resources tab.", "glpi": "source read at 11.0.9: src/Contract.php:126 adds the Documents tab (Document_Item) to every contract, storing the signed file in install/mysql/glpi-empty.sql:2585 glpi_documents. Reached on: Management > Contracts > Documents tab." } @@ -2627,6 +2765,7 @@ "stackiq": "usage.cloudDienstverleningsmodel (register :3050) plus contract cost; lib/Service/PortfolioReportService.php:302 per-usage annualised cost and cloud-transition share; src/views/organisaties/PortfolioReport.vue:166 cloudTransitionLabel per row", "topdesk": "unknown: no SaaS spend tracking is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: contracts, licences and costs are not described anywhere in the public docs (the 2021 user survey asks which other tool municipalities use for contract management); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersonderzoek%202021 (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for SaaS and spend, no SaaS subscription tracking is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -i 'saas' over src/ returns nothing; spend is only what is entered on contracts and financial records (install/mysql/glpi-empty.sql:1458 glpi_contractcosts), with no discovery of subscriptions bought outside IT." } }, @@ -2654,6 +2793,7 @@ "vng-softwarecatalogus": "unknown: no vulnerability register is described; the docs do not state its absence either (the IBD-foto export only hands CPE identifiers to the IBD); searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Hoe%20maak%20je%20een%20ICT-foto%20voor%20de%20IBD%3F (read 2026-09-26)", "stackiq": "src/views/KwetsbaarhedenView.vue:378 reportVulnerability opens the generic ObjectModal for 'vulnerability'; register.json:1619 vulnerability schema with cveCode (pattern CVE-yyyy-n, :1679) and cvssScore 0-10", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for vulnerability and CVE, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no vulnerability record with CVE code and score exists, vulnerabilities are handled by searching SBOM components (https://help.sap.com/docs/leanix/ea/searching-for-sbom-library-components-by-package-url 'after a CVE alert') (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'cve\\|vulnerab\\|cvss' over src/ templates/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74 (a PHP version warning) and a session comment at src/Session.php:1085; no vulnerability itemtype exists." } @@ -2682,6 +2822,7 @@ "stackiq": "register.json:1701 vulnerability.modules links to module (applications), not moduleVersion; version level only via read-time SBOM match (src/utils/sbomVulnerabilityMatch.js, sbomComponent.vexCveIds register.json:8024) on the ModuleversieDetail Components tab", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for vulnerability and CVE, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a PURL search finds services using a given library version, but linking a vulnerability record to affected versions is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no vulnerability model (see src/Glpi/System/Requirement/PhpSupportedVersion.php:74 as the only 'vulnerabilities' hit), so nothing links to software versions (install/mysql/glpi-empty.sql:6900)." } @@ -2710,6 +2851,7 @@ "stackiq": "src/components/sbom/SbomComponentsPanel.vue:53-90 upload control (.json) -> POST /api/moduleversies/{uuid}/sbom (appinfo/routes.php:92) -> lib/Controller/SbomController.php:129 importSbom -> lib/Service/SbomParserService.php:77 parse (CycloneDX JSON) and :127 parseSpdx (SPDX 2.x JSON)", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for SBOM, CycloneDX and SPDX, no hits (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/uploading-sboms-from-fact-sheets: 'select a CycloneDX or SPDX file in JSON or XML format' on a microservice fact sheet; also through the Self-Built Software Discovery API. Technology Risk and Compliance product (read 2026-09-26). Reached on: Microservice fact sheet > SBOM > Upload SBOM.", "glpi": "source read at 11.0.9: grep -ril 'sbom\\|cyclonedx\\|spdx' over src/ templates/ locales/glpi.pot returns nothing; inventory import (src/Glpi/Inventory/) takes glpi-agent JSON only. Inventory import is src/Glpi/Inventory/Inventory.php:106." } @@ -2738,6 +2880,7 @@ "stackiq": "src/utils/sbomVulnerabilityMatch.js header: 'no HTTP request to an external advisory feed is ever made'; lib/Service/EolSyncService.php syncs endoflife.date support dates, not CVEs", "topdesk": "unknown: no CVE matching is described; the roadmap card https://tip.topdesk.com/c/186-automated-asset-scanning-tool (under consideration) mentions monitoring \"security vulnerabilities\" as a future idea; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue does not match CVEs itself; its \"IBD-foto\" export lists supplier, product and CPE so the IBD can do so; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Hoe%20maak%20je%20een%20ICT-foto%20voor%20de%20IBD%3F (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for CVE, no hits (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/api-updates-sbom-async-processing: 'Switching to asynchronous processing will allow us to add additional post-processing mechanisms in the future, such as vulnerability checks. Though there's no established timeline for these enhancements' (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'cve' over src/ templates/ finds no feed matching (only src/Glpi/System/Requirement/PhpSupportedVersion.php:74 text); no pluginsGLPI cve repository exists (git ls-remote https://github.com/pluginsGLPI/cve: repository not found)." } @@ -2767,6 +2910,7 @@ "stackiq": "src/utils/vulnerabilitySeverity.js derives a severity band per vulnerability from CVSS; no per-application risk score in lib/ or src/ (searched risk)", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; risk can be captured in questionnaires ('Risk Assessment' example in https://help.bluedolphin.io/en/articles/11967710-using-the-odata-feed), but a risk score from vulnerabilities and support status is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: with no vulnerability data (only hit src/Glpi/System/Requirement/PhpSupportedVersion.php:74) and no support status field on software (install/mysql/glpi-empty.sql:6856 glpi_softwares), no risk score is computed; grep -i 'risk' over src/Appliance.php src/Software.php returns nothing." } }, @@ -2794,6 +2938,7 @@ "stackiq": "register.json:1619 vulnerability has no fixed-in version field; src/utils/vulnerabilityExposure.js computeExposure carries the deployed moduleVersion per usage but nothing compares it to a fix", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for patch and vulnerability, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no per vulnerability patch status is documented, and vulnerability checks are a future item (https://help.sap.com/docs/leanix/ea/api-updates-sbom-async-processing) (read 2026-09-26)", "glpi": "source read at 11.0.9: installed versions are known (src/Item_SoftwareVersion.php:39) but no vulnerability or fixed in version exists to compare against (grep -rli 'cve' src/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74)." } @@ -2822,6 +2967,7 @@ "stackiq": "src/manifest.json:969 Kwetsbaarheden custom page -> src/views/KwetsbaarhedenView.vue table with severity tabs; row click openDetail (:417) opens the record in the generic ObjectModal", "topdesk": "unknown: vulnerabilities are not mentioned (0 hits for \"vulnerab\"); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability, SBOM or risk functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for vulnerability, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no vulnerability list exists, only the SBOM explorer of components (https://help.sap.com/docs/leanix/ea/sbom-explorer) (read 2026-09-26)", "glpi": "source read at 11.0.9: no vulnerability itemtype and no such entry in any menu (src/Html.php:1295 to :1334 list Management, Tools, Administration and Setup types)." } @@ -2833,7 +2979,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "yes", "stackiq": "yes", @@ -2850,6 +2996,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Als leverancier kunt u zich aanmelden door de volgende gegevens te sturen naar softwarecatalogus@vng.nl\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C4 roles for gemeente and samenwerking accounts (read 2026-09-26); organisation types gemeente, samenwerking, leverancier. Reached on: Registration via VNG helpdesk.", "stackiq": "src/manifest.json:386 Organisaties type:index over schema organization (Add form); register :2022 organization.type enum Municipality/Supplier/Collaboration/Community, required contactsUid + type", "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier ... In the Tasks block, specify whether first or second line incidents, or services or changes, may be assigned to the supplier\" (read 2026-09-26); branches are registered as Branch cards (https://docs.topdesk.com/en/drop-down-lists-settings.html \"the Person and Branch cards\"). Reached on: Supporting Files > New > Supplier / Branch.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967491-business-units: business units 'represent more or less standalone parts of your organization, such as sales, marketing, OpCo France'; outside organisations can be ArchiMate business actor objects. No register of municipalities, suppliers or cooperations with a type is documented (read 2026-09-26). Reached on: System settings > Business Units.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines: organization subtypes 'Business Unit, Customer, Region, Legal Entity, Team' for 'your hierarchical business architecture'; suppliers are separate provider fact sheets. No municipality or cooperation types for outside organisations (read 2026-09-26). Reached on: Inventory > Organization fact sheet.", "glpi": "source read at 11.0.9: external organisations are suppliers with a type dropdown (src/Supplier.php:46, install/mysql/glpi-empty.sql:7072 suppliertypes_id); the organisation's own units are entities (src/Entity.php:58). There is no generic organisation register covering municipalities or cooperations. Reached on: Management > Suppliers; Administration > Entities." } @@ -2880,6 +3027,7 @@ "stackiq": "src/views/settings/StackiqSettings.vue:92 ModerationQueue (type organisation) -> src/utils/adminApi.js -> GET /api/moderation/pending, POST /api/moderation/{uuid}/approve|reject; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; lib/Service/ModerationService.php:230 approval sets registrationStatus active and stamps publicationDate (:173)", "topdesk": "unknown: no review queue for organisations is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Om te kunnen deelnemen aan de softwarecatalogus controleren wij of de leverancier voldoet aan de richtlijnen van de softwarecatalogus\" (read 2026-09-26). Manual review by e-mail, no queue described.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; organisations do not self register, so no moderation queue is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; organisations do not self register, so no moderation queue is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers are created by staff (src/Supplier.php:75 sets is_active on a new record) and there is no self registration or approval queue for organisations; grep -i 'moderat' over src/Supplier.php src/Entity.php returns nothing." } @@ -2908,6 +3056,7 @@ "stackiq": "register organization.status enum Draft/Active/Inactive is visible:false (:2022); src/manifest.json:403 OrganisatieDetail overrides status editable:false; src/modals/object/ChangeOrganisatieStatusDialog.vue:211 is never opened (no setDialog('changeOrganisatieStatus') in src); src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters status 'concept' and :129 writes 'actief', neither an enum value", "topdesk": "unknown: cards can be archived; concept, active, inactive states for organisations are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: suppliers carry a \"heeft geldig convenant\" flag and may be removed, but no concept, active, inactive status is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/leveranciers (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; concept, active and inactive states for organisations are not documented (read 2026-09-26)", "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines does not describe concept, active and inactive states for organizations; only archiving of fact sheets in general (https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets) (read 2026-09-26)", "glpi": "source read at 11.0.9: a supplier is active or inactive, src/Supplier.php:365 is_active search option (install/mysql/glpi-empty.sql:7087 glpi_suppliers.is_active); there is no concept state. Reached on: Management > Suppliers, Active field." } @@ -2936,6 +3085,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30402: \"Bij elke leverancier is een contactpersoon opgevoerd. Deze persoon is verantwoordelijk voor de inhoud\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E4 contact details of municipalities (read 2026-09-26). One contact, no roles. Reached on: Supplier page header.", "stackiq": "src/manifest.json:418 OrganisatieDetail org-contactpersonen object-list (role, roles) with rowRoute ContactpersoonDetail; register :1788 contactPerson (contactsUid, role, organization, roles enum of catalogue roles)", "topdesk": "https://docs.topdesk.com/en/managing-external-relations.html: \"Registering a supplier contact ... The Supplier card where the contact person is active must be registered first\" (read 2026-09-26). Roles per contact are not described. Reached on: Supporting Files > New > Supplier Contact.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; contact persons with roles per organisation are not documented beyond generic questionnaire fields (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/subscription-roles: users subscribe to any fact sheet, including organization fact sheets, with roles 'such as application owner, project manager'. Contacts must be workspace users; external contact persons are not documented (read 2026-09-26). Reached on: Organization fact sheet > Subscriptions.", "glpi": "source read at 11.0.9: contacts (src/Contact.php:45, install/mysql/glpi-empty.sql:1390 glpi_contacts) carry a contact type and a title (:1402 contacttypes_id, :1405 usertitles_id) and are linked to suppliers through src/Contact_Supplier.php:39. Reached on: Management > Contacts; Supplier > Contacts tab." } @@ -2947,7 +3097,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "partial", "stackiq": "yes", @@ -2965,6 +3115,7 @@ "stackiq": "src/components/organisations/OrganisationSwitcher.vue:48 'Manage members' (isBeheerder) opens src/modals/GrantOrganisationAccessModal.vue; POST /api/organisations/{uuid}/members -> lib/Controller/OrganisationMembersController.php:108 authorizeBeheerder then OpenRegister joinOrganisation (:123)", "topdesk": "https://docs.topdesk.com/en/step-2, operator-import-with-a-linked-person.html: \"Create new operators via import\" (read 2026-09-26); permissions via permission groups (https://docs.topdesk.com/en/automated-actions.html). Administrators create accounts; no invitation flow. Reached on: Supporting Files > Operators.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/gebruikersbeheer: \"Beheerders van gemeenten, samenwerkingen of leveranciers kunnen voor collega's een account aanmaken ... ontvangt deze nieuwe gebruiker een e-mail met daarin de inloginstructies\" (read 2026-09-26). Reached on: Menu > Gebruikersbeheer > Gebruiker toevoegen.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967616-user-management: admins 'Add new users' and BlueDolphin sends 'An invitation with a link to activate the account'; business units scope what users see (https://help.bluedolphin.io/en/articles/11967491-business-units) (read 2026-09-26). Reached on: Admin > Users.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/users-overview: 'Invited users who haven't yet accepted the invitation request. You can reinvite a user'; https://help.sap.com/docs/leanix/ea/virtual-workspaces-configuration: 'Set up virtual workspaces to manage access for custom user groups' (read 2026-09-26). Reached on: Administration > Users > Invite.", "glpi": "source read at 11.0.9: an administrator gives a user a profile on an entity, install/mysql/glpi-empty.sql:5917 glpi_profiles_users with profiles_id and entities_id, set on the user's Authorizations tab or automatically by authorisation rules (src/RuleRight.php:297 profiles_id action, :273 entities_id action). There is no emailed invitation link. Reached on: Administration > Users > Authorizations tab." } @@ -2976,7 +3127,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "unknown", "stackiq": "yes", @@ -2994,6 +3145,7 @@ "stackiq": "src/components/organisations/OrganisationSwitcher.vue:197 POST /apps/openregister/api/organisations/{uuid}/set-active; mounted in src/App.vue:55", "topdesk": "unknown: one account acting for several organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4: \"Een account kan ook beide rollen gekregen hebben. In het inlogmenu kan dan van rol gewisseld worden ... Gecombineerde rollen kunnen alleen door VNG Realisatie aangemaakt worden\" (read 2026-09-26). Reached on: Inlogmenu > rol wisselen.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967491-business-units: 'When there are multiple business units, you can switch between them by selecting a business unit from the dropdown'. Switching is between parts of one tenant, not between separate organisations (read 2026-09-26). Reached on: Top menu > business unit dropdown.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/manage-workspace-access: 'Provide users with access to exactly their relevant workspaces ... direct URL, base URLs or the workspace chooser to access available workspaces' (read 2026-09-26). Reached on: Workspace chooser.", "glpi": "source read at 11.0.9: one user can hold several profile and entity pairs (install/mysql/glpi-empty.sql:5917 glpi_profiles_users) and switch between them in the session, src/Session.php:461 changeActiveEntities and src/Session.php:592 changeProfile. Reached on: user menu, entity and profile selector." } @@ -3022,6 +3174,7 @@ "stackiq": "src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail; POST /api/organisaties/{uuid}/merge -> lib/Controller/MergeController.php:142 isAdmin; lib/Service/MergeOrganisatieService.php:111 re-points usage.consumer/participants, contactPerson.organization, connection.provider and @self.organisation of catalogContract/compliancy; module.provider and catalogService.provider are not re-pointed", "topdesk": "unknown: merging organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; objects can be copied or moved between business units and workspaces (https://help.bluedolphin.io/en/articles/11967491-business-units), but merging two organisations with their relations is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for merge of fact sheets or organizations, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: entities cannot be merged, src/Entity.php:202 forbids the dropdown merge action for Entity; records can be moved into another entity with src/Transfer.php:50 Transfer (massive action add_transfer_list, src/MassiveAction.php:598), keeping or cleaning linked items per transfer options. Reached on: Administration > Entities; list Actions > Add to transfer list." } @@ -3051,6 +3204,7 @@ "stackiq": "src/components/organisations/OrganisationMergePanel.vue:324 organisatieStore.dryRunMerge shows dryRunCounts before execute; POST /api/organisaties/{uuid}/merge/dry-run -> lib/Service/MergeOrganisatieService.php:160 dryRun", "topdesk": "unknown: merging organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no merge of organisations is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no merge preview is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no merge, so no merge preview is documented (read 2026-09-26)" } }, @@ -3061,7 +3215,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -3079,6 +3233,7 @@ "stackiq": "src/views/settings/StackiqSettings.vue:80 UserGroupsConfiguration -> GET/POST /api/user-groups/config (src/store/modules/settings.js:830); lib/Controller/SettingsController.php:3379; lib/Service/Stackiq/GroupHandler.php:103 generic groups, :167 fixed role groups (aanbod-beheerder, gebruik-beheerder, ...), group choice by organisation type (:471)", "topdesk": "https://docs.topdesk.com/en/automated-actions.html: \"Assign these permissions via Supporting Files > Permission Groups > [Permission Group]\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: permission tables per module (read 2026-09-26). Reached on: Supporting Files > Permission Groups.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C4 roles gemeentebeheerder, raadpleger, samenwerkingsbeheerder; \"Er is géén rol voor het raadplegen van een samenwerking\" (read 2026-09-26). Fixed roles, no mapping onto groups. Reached on: Gebruikersbeheer.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967624-manage-roles-and-permissions: 'BlueDolphin uses Role-Based Access Control (RBAC). Every user is linked to one or more roles ... Add and delete custom roles' (read 2026-09-26). Reached on: Admin > Roles.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/sso-attribute-overview: 'The role to be assigned to the user. Required values: ADMIN, MEMBER, or VIEWER' and 'customer_roles ... The custom role to be assigned', mapped from identity provider groups (read 2026-09-26). Reached on: Administration > Users; SSO role attributes." } }, @@ -3089,7 +3244,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "no", @@ -3107,6 +3262,7 @@ "topdesk": "https://docs.topdesk.com/en/automatic-login-methods.html: \"Single Sign-on via SAML requirements TOPdesk uses OpenSAML 3 for authentication. You can connect all common IdP solutions which support SAML 2.0\" (read 2026-09-26). Reached on: Settings > Login Settings.", "stackiq": "No OIDC/SAML code in lib/ or src/; stackiq creates local Nextcloud users with a password (lib/Service/Stackiq/ContactPersonHandler.php:292)", "vng-softwarecatalogus": "unknown: login is by username and password (\"Vul uw GEMMA Softwarecatalogus-gebruikersnaam in\"); no identity provider sign-in is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/user/login (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967579-configure-single-sign-on-sso-with-okta-saml and https://help.bluedolphin.io/en/articles/11967575-configure-single-sign-on-sso-with-office-365-openid: SSO setup guides for Okta SAML, ADFS and Office 365 OpenID (read 2026-09-26). Reached on: Admin > Identity providers.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/managing-users: 'SSO : You manage access through your identity provider (IdP) system. Users sign in through your IdP'; guides for Entra ID, Okta, OneLogin (read 2026-09-26). Reached on: Administration > Single Sign-On." } }, @@ -3117,7 +3273,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "no", @@ -3135,6 +3291,7 @@ "stackiq": "lib/Service/OrganizationSyncService.php and the 'Organization synchronization' admin section sync catalogue organisations to OpenRegister organisation entities, not users from a directory; no LDAP code in lib/", "topdesk": "https://docs.topdesk.com/en/manual-login-with-ldap.html: \"This is also required if you want to import persons from your AD via Supporting files import\" (read 2026-09-26); https://tip.topdesk.com/c/242-support-scim-when-importing-users-from-entra-id-to-topdesk: roadmap card in column \"Launched\", \"Support SCIM when importing users from Entra ID to TOPdesk\" (read 2026-09-26). Reached on: Settings > Import settings > Supporting Files imports.", "vng-softwarecatalogus": "unknown: no directory sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967618-automatic-user-provisioning-with-scim-2-0: 'BlueDolphin supports automatic user provisioning ... manage BlueDolphin users and their role assignments', with guides for Entra ID, Okta and SailPoint (read 2026-09-26). Reached on: Admin > SCIM provisioning.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/scim-provisioning: 'SCIM facilitates the transfer of user information from a source system, such as an external identity provider (IdP), to a target system, such as SAP LeanIX'; setup guides for Entra ID and Okta (read 2026-09-26). Reached on: Administration > SCIM provisioning." } }, @@ -3145,7 +3302,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -3162,6 +3319,7 @@ "stackiq": "src/components/ContactpersonenList.vue:115 'Change Password' opens src/dialogs/ChangePasswordDialog.vue -> POST /api/contactpersonen/change-password -> lib/Controller/ContactpersonenController.php:718, self-reset allowed at :753; GET /api/me (:1578) used only by src/App.vue and OrganisationSwitcher", "topdesk": "https://docs.topdesk.com/en/editing-your-personal-profile.html: \"Click on Personal Profile . In the General and Private section, you can edit your personal information. In the Change password section, you can change your password\" (read 2026-09-26). Reached on: Profile picture > Personal Profile.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/wachtwoord-vergeten: \"Op het inlogscherm ... staat een link om een nieuw wachtwoord aan te vragen\" (read 2026-09-26). Reset by mail; viewing own account details is not described. Reached on: Inloggen > Vraag een nieuw wachtwoord aan.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967481-user-profile: users see 'Profile > Personal information'; https://help.bluedolphin.io/en/articles/11967487-forgotten-password: 'To have your password reset, you need to contact your BlueDolphin administrator' and change the temporary password after login (read 2026-09-26). Reached on: Account > Profile.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/user-profile: 'Manage your user profile settings. Change or reset your password if needed' on the My Settings profile page (read 2026-09-26). Reached on: User menu > My Settings.", "glpi": "source read at 11.0.9: front/preference.php renders the user's own form through src/User.php:3105 showMyForm (template pages/admin/user/user.html.twig), whose preference variant shows a 'Change password' button to front/updatepassword.php at templates/pages/admin/user/user.html.twig:277 to :279; the new password form is templates/password_form.html.twig:79." } @@ -3173,7 +3331,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", @@ -3191,6 +3349,7 @@ "stackiq": "lib/Service/SymfonyEmailService.php:466 registration, :553 activation, :641 user creation mails from templates; src/views/settings/sections/EmailConfiguration.vue:902 saveTemplate is a stub that logs 'not yet implemented in the backend' and still shows success; backend POST /api/email/templates/{templateName} (lib/Controller/SettingsController.php:2194) has no caller in src/; lib/Settings/connections.json email adapter reports the 'null' transport as simulated", "topdesk": "unknown: email designs are editable for automated actions, but account activation mails are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: new users receive a login mail, but administrator-editable templates are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967616-user-management: BlueDolphin sends 'An invitation with a link to activate the account' and temporary credentials; editing the mail templates is not documented (read 2026-09-26). Reached on: Admin > Users > send invites.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/users-overview: users are invited 'individually or in bulk' with a 'Send Invitation Email' option; editing the text of account mails is not documented (read 2026-09-26). Reached on: Administration > Users > Invite." } }, @@ -3220,6 +3379,7 @@ "stackiq": "lib/Controller/PublicationController.php:87 publish/depublish (routes.php:208-209, PUT/DELETE /api/publication/{objectType}/{uuid}) with an IDOR guard; lib/Service/PublicationService.php:51 publishable types catalogService, module, connection, organization. No src/ caller of /api/publication (only a comment in src/utils/openDataProjection.js). The publish buttons in src/modals/object/ViewObject.vue:4854 are unreachable: Modals.vue renders ViewObject only for modal 'viewOrganisatie'/'viewContactpersoon', which nothing sets. Workaround: publicationDate/depublicationDate are visible, editable fields on module/catalogService/organization/connection (lib/Settings/softwarecatalogus_register.json:6777 schema).", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: supplier data is public by default and municipal data is never public; publishing or withdrawing one entry is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: https://help.bluedolphin.io/en/articles/11967513-publish-a-view publishes a read-only view to 'all BlueDolphin users in your tenant'; publishing an entry as open data is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; publishing a single entry as open data is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'open data\\|opendata' over src/ locales/glpi.pot returns nothing; items have no publish state, the closest is is_helpdesk_visible (install/mysql/glpi-empty.sql:8956 on glpi_appliances), which only shows the item to helpdesk users of the same instance." } @@ -3250,6 +3410,7 @@ "stackiq": "src/utils/openDataProjection.js:36 STRIPPED_FIELDS (PII projection) is imported by nothing in src/ and has no PHP counterpart (grep 'projection' in lib/ finds none). Usage schema read rule lib/Settings/softwarecatalogus_register.json:3150 has no public group; lib/Controller/GebruikController.php:102 returns an empty result to anonymous callers.", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Beschikbare%20downloads: public CSV downloads of packages, versions and compliance (read 2026-09-26); https://www.softwarecatalogus.nl/pakket/archi: \"Ingevuld door (28) Aantal gemeenten met een versie van het pakket in productie\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: C5 contact details \"alleen als contactgegevens voor andere ingelogde gebruikers\" (read 2026-09-26). Reached on: Beschikbare downloads; package page.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; no open data publication is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no open data publication is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no open data publication exists (grep -rli 'open data' src/ returns nothing); anonymisation settings cover ticket actors only (install/mysql/glpi-empty.sql:2824 anonymize_support_agents on entities)." } @@ -3280,6 +3441,7 @@ "stackiq": "lib/Service/Federation/FederationService.php:215 announce() calls OpenCatalogi BroadcastService->broadcast(directory URL); only caller is lib/BackgroundJob/FederationSyncJob.php:73. Off by default: lib/Service/Federation/FederationConfig.php:56 federation_enabled=false; lib/Settings/connections.json lists federation as switch-only via occ. isAvailable() is class_exists('OCA\\\\OpenCatalogi\\\\Service\\\\DirectoryService') (FederationService.php:95).", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; announcing a catalogue in a shared directory is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no shared directory of catalogues or federation between workspaces is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'federat\\|activitypub' over src/ returns nothing; every instance is standalone and the only outbound registration is the plugin marketplace client (src/Glpi/Marketplace/). The marketplace client is src/Glpi/Marketplace/Controller.php:64." } @@ -3310,6 +3472,7 @@ "stackiq": "lib/Service/Federation/FederationService.php:434 fetchPeerCatalog() calls OpenCatalogi DirectoryService->getDirectory(['url' => $peerUrl]); OpenCatalogi's getDirectory (opencatalogi lib/Service/DirectoryService.php:2409, also on origin/development) reads only filters/limit/offset/include-federated and ignores 'url', so it returns this instance's own directory listings, not the peer's published entries. Provenance marking itself is built: lib/Service/Federation/FederationMerger.php:239 stamps _source.instance. Mirrors are written into the organization schema (FederationService.php:56 PEER_MIRROR_TYPE). No src/ code reads _source, so no page shows where an entry came from.", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; AMEFF files can move views between BlueDolphin tenants (https://help.bluedolphin.io/en/articles/11967636-import-bluedolphin-ameff-files), but pulling published entries from peer catalogues with provenance is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; pulling entries from peer catalogues is not documented, only integrations with named tools (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'federat' over src/ returns nothing; data enters only through the UI, the APIs (src/Glpi/Api/APIRest.php:60, src/Glpi/Api/HL/Router.php) and inventory, never from peer catalogues." } @@ -3340,6 +3503,7 @@ "stackiq": "lib/Controller/FederationController.php:86 addPeer / removePeer (routes.php:246-247), #[AuthorizedAdminSetting(StackiqAdmin)]; lib/Service/Federation/FederationService.php:157/191 with an SSRF host guard; UI src/views/settings/sections/FederationSettings.vue:283 (POST) and :307 (DELETE), mounted from src/views/settings/StackiqSettings.vue:114.", "topdesk": "unknown: open data publication and catalogue federation are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no exchange with peer catalogues is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; peer catalogue management is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; no peer catalogue management is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'federat' over src/ returns nothing; there is no peer list in the Setup menu (src/Html.php:1330 onwards)." } @@ -3366,7 +3530,7 @@ "note": "Read and write through a REST API is live through OpenRegister, with stackiq's own role-scoped endpoints on top.", "evidence": { "sap-leanix": "https://help.sap.com/docs/leanix/ea/sap-leanix-apis: 'These APIs are ideal for integration with systems that support RESTful interactions' and 'The GraphQL API enables you to retrieve and update fact sheets and related data' (read 2026-09-26). Reached on: Developer Guide > SAP LeanIX APIs.", - "bluedolphin": "docs, intelligence competitor_features#48972 'REST API' (2026-07-23): Programmatic integration with other systems.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967730-about-the-bluedolphin-api: 'The BlueDolphin Public API is available by default for all tenants ... based on REST principles', with create, update, retrieve and delete endpoints for objects and relationships (read 2026-09-26). Reached on: Admin > Public API keys.", "glpi": "source read at 11.0.9: legacy REST API src/Glpi/Api/APIRest.php:60 (documented in apirest.md) and the v2 high level API, src/Glpi/Api/HL/Controller/AssetController.php:149 /Assets with GET list (:2825), GET item (:2839) and POST create (:2988), Appliance and Software included (src/Glpi/Api/HL/Controller/AssetController.php:39, :133). Reached on: /apirest.php and /api.php/v2. Driven on the lab at 11.0.9 (2026-09-26): the legacy API answers \"There isn't an active API client matching your IP address\" until an administrator adds an API client, and the v2 API is off until enabled in Setup > General > API.", "topdesk": "https://docs.topdesk.com/en/required-knowledge.html: \"basic knowledge of REST API requests (see developers.topdesk.com )\" (read 2026-09-26); https://docs.topdesk.com/en/details-about-certain-permissions.html: \"API access > REST API : this permission is necessary for operator cards that are used for accessing the TOPdesk API\" (read 2026-09-26). Reached on: developers.topdesk.com.", "stackiq": "Every catalogue entity is an OpenRegister object (src/manifest.json pages read register @resolve:voorzieningen_register), so OpenRegister's /apps/openregister/api/objects/{register}/{schema} CRUD applies, gated by the schema authorization rules (lib/Settings/softwarecatalogus_register.json:6777 module and others). Stackiq adds its own routed endpoints in appinfo/routes.php (e.g. :202 /api/aanbod, :255-261 /api/aangeboden-gebruik, :298 /api/gebruik, :303 /api/portfolio-report).", @@ -3380,7 +3544,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -3399,6 +3563,7 @@ "stackiq": "openapi.json at repo root has an info block and 0 paths. Hand-written JSON docs: lib/Controller/ViewController.php:373 (GET /api/views/docs, routes.php:186) and lib/Controller/AangebodenGebruikController.php:866 (GET /api/aangeboden-gebruik/docs, routes.php:261). The views docs endpoint is login-only; the aangeboden-gebruik docs endpoint is @PublicPage (AangebodenGebruikController.php:860), so anyone can read it (corrected 2026-09-26). Hand-written markdown in docs/API_REFERENCE.md and docs/View_API.md on the docs site. No src/ caller of either docs endpoint.", "topdesk": "https://developers.topdesk.com/: TOPdesk API reference site, linked from the docs as \"TOPdesk API documentation\" (read 2026-09-26); https://docs.topdesk.com/en/generate-a-document.html: \"see FreeMarker and the TOPdesk API documentation\" (read 2026-09-26). Reached on: developers.topdesk.com.", "vng-softwarecatalogus": "unknown: no API documentation for the current catalogue was found; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967733-quick-start-guide: 'Open API Documentation EU https://public-api.eu.bluedolphin.app /swagger/index.html' and per endpoint reference articles in the help center (read 2026-09-26). Reached on: Swagger at https://public-api.eu.bluedolphin.app/swagger/index.html.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/sap-leanix-apis: 'we provide the OpenAPI explorer . This tool enables you to explore APIs, send requests, and view responses directly in your browser' (read 2026-09-26). Reached on: Workspace > OpenAPI explorer." } }, @@ -3409,7 +3574,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -3429,6 +3594,7 @@ "glpi": "source read at 11.0.9: every search list exports to CSV, PDF, ODS and XLSX through src/Glpi/Search/Output/Csv.php, Pdf.php, Ods.php and Xlsx.php, plus impact CSV (front/impactcsv.php) and the APIs (src/Glpi/Api/HL/Controller/AssetController.php:2825). Reached on: any list, Export menu. Driven on the lab at 11.0.9 (2026-09-26): the Appliances list exported to CSV (/front/report.dynamic.php display_type 3) with the created record.", "stackiq": "ArchiMate export lib/Controller/SettingsController.php:1615 (POST /api/archimate/export) and :1685 per-organisation export (GET /api/archimate/export/organization/{uuid}), called only from src/views/settings/sections/ArchiMateImportExport.vue (admin settings, StackiqSettings.vue:86). CSV export of the portfolio report: lib/Controller/PortfolioReportController.php:105, button src/views/organisaties/PortfolioReport.vue:567. No index page opts into the library's CSV/Excel export (no allowExport in src/manifest.json).", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: tile actions \"Export to .CSV Export to Excel\" (read 2026-09-26); https://docs.topdesk.com/en/create-odata-reports-for-asset-management.html: \"generate reports by using the TOPdesk OData feed ... Microsoft Power BI, or Microsoft Excel\" (read 2026-09-26). Reached on: Asset dashboard; OData feed.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967710-using-the-odata-feed: 'working with the data available through the BlueDolphin OData service'; views export as AMEFF (https://help.bluedolphin.io/en/articles/11967514-download-a-view) (read 2026-09-26). Reached on: OData feed; view download.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/exporting-fact-sheet-data-as-excel-file: 'export fact sheet data as an Excel file'; https://help.sap.com/docs/leanix/ea/exporting-workspace-snapshots: 'Export snapshots of your workspace data through the Pathfinder REST API' (read 2026-09-26). Reached on: Inventory > Export; snapshot API." } }, @@ -3454,7 +3620,7 @@ "note": "No integration with a service management tool exists.", "evidence": { "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: 'ServiceNow integration An integration that connects the subscription services to the customer's ServiceNow subscription to synchronize infrastructure and software asset information'; Jira Service Management integration at https://help.sap.com/docs/leanix/ea/jira-service-management-integration-faqs (read 2026-09-26). Reached on: Administration > Integrations > ServiceNow.", - "bluedolphin": "docs, intelligence competitor_features#48973 'TOPdesk integration' (2026-07-23): Connector to TOPdesk asset/service data. | docs, intelligence competitor_features#27465 'TOPdesk Integration' (2026-04-12): Available on TOPdesk Marketplace for IT landscape insights", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967779-add-an-integration-in-bluedolphin: 'out-of-the-box integrations with ITSM platforms like TOPdesk, ServiceNow, and JIRA'; https://help.bluedolphin.io/en/articles/11967782-bluedolphin-to-topdesk-integration and https://help.bluedolphin.io/en/articles/12148500-bluedolphin-to-servicenow-integration (read 2026-09-26). Reached on: System settings > Marketplace (paid add on).", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"Go to Links > Assets . Click Link asset\" (read 2026-09-26) on calls and changes; TOPdesk is itself the service management tool. Reached on: Call card > Links > Assets.", "stackiq": "No ITSM connector: lib/Settings/connections.json lists only email, federation and eol-feed; grep for topdesk/servicenow/itsm in lib/ and src/ finds nothing.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: C19: \"Met de exportfunctie kunt u de gegevens in andere tools synchroon houden ... We verwachten in 2019 een pilot met Topdesk ... Een import vanuit die tools naar de Softwarecatalogus ... is vooralsnog niet voorhanden\" (read 2026-09-26); https://www.softwarecatalogus.nl/RID%20de%20Liemers: RID de Liemers signals updates through its TOPdesk change process by hand (read 2026-09-26)", @@ -3483,7 +3649,7 @@ "note": "As a Nextcloud app it runs on whatever infrastructure hosts the Nextcloud instance.", "evidence": { "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf describes 'The SaaS services' and a customer 'workspace'; https://www.leanix.net/hubfs/Legal/Operational-Terms-Exhibit-v.2.0.pdf defines 'the data center utilized by LeanIX to host Customer's Data' with maintenance windows per hosting region. Only a vendor hosted subscription is offered (read 2026-09-26)", - "bluedolphin": "docs, intelligence competitor_features#27467 'SaaS Platform' (2026-04-12): Cloud-native SaaS, no installation required", + "bluedolphin": "https://help.bluedolphin.io/en/articles/15603627-microsoft-copilot-to-bluedolphin-with-mcp: 'BlueDolphin is a SaaS enterprise architecture and business design repository'; tenants run on the vendor's EU and US clusters (https://help.bluedolphin.io/en/articles/11967733-quick-start-guide) (read 2026-09-26)", "glpi": "source read at 11.0.9: GPL 3 source distributed for installation on own servers (LICENSE, INSTALL.md, install/mysql/glpi-empty.sql schema and the web installer src/Glpi/Controller/InstallController.php). The version is src/autoload/constants.php:43 GLPI_VERSION 11.0.9, the installer controller src/Glpi/Controller/InstallController.php:57, the licence LICENSE:1 GNU GPL version 3.", "topdesk": "https://docs.topdesk.com/VA2026R3/index.html: \"TOPdesk Virtual Appliance documentation\", releases VA 2023 R2 to VA 2026 R3 (read 2026-09-26); https://tip.topdesk.com/c/255-va-release-q4-2026: roadmap card in column \"Planned\", \"VA Release Q4 2026\" in section \"On premise - VA releases\" (read 2026-09-26). Reached on: Virtual Appliance.", "stackiq": "appinfo/info.xml: a Nextcloud app (id stackiq, EUPL-1.2) installed on the customer's own Nextcloud with OpenRegister; stackiq-compose.yaml at repo root for a local stack.", @@ -3497,7 +3663,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "partial", "stackiq": "partial", @@ -3517,6 +3683,7 @@ "glpi": "source read at 11.0.9: every list has a criteria builder, src/Glpi/Search/Input/QueryBuilder.php:72 showGenericSearch, over all search options, for example manufacturer on appliances (src/Appliance.php:229 region, glpi_manufacturers) and status (src/Appliance.php:350); there are no counted facets and no reference component to filter on. Reached on: Management > Appliances, search criteria.", "stackiq": "lib/Service/FacetService.php:109 DIMENSIONS = referenceComponent, standard, applicationService, domain (GET /api/facets/{schema}, routes.php:195); src/views/FacetedCatalogIndexView.vue renders CnFacetSidebar with these plus search, on the Applications and Services pages. Supplier is only a column (src/manifest.json Modules config columns 'provider'), not a facet, although the module schema marks provider facetable.", "topdesk": "https://docs.topdesk.com/en/the-asset-management-module-page.html: \"Asset overview : view all your assets in a filterable list\" (read 2026-09-26). Facets with counts are not described. Reached on: Asset Management > Asset overview.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967727-add-filters-to-the-data: 'narrow down repository data based on object properties' with 'Created by, Created on, Changed by, Changed on, and Completeness' and related objects (read 2026-09-26). Reached on: Repository > filters.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options: inventory filters by lifecycle, subscription, tags and fields, and https://help.sap.com/docs/leanix/ea/filtering-in-report-urls: 'Apply a filter using the facet filter column' (read 2026-09-26). Reached on: Inventory > facet filter column." } }, @@ -3527,7 +3694,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "yes", @@ -3545,6 +3712,7 @@ "stackiq": "src/views/FacetedCatalogIndexView.vue:68 Saved views menu (save current filters, list, apply); src/store/modules/facets.js:404 saveCurrentAsView POSTs to OpenRegister /apps/openregister/api/views (:61), fetchSavedViews :361 reads them back.", "topdesk": "https://tip.topdesk.com/c/83-share-saved-overviews-with-operators-and-operator-groups: roadmap card in column \"Launched\", \"User is able to share saved overviews with operators and operator groups - Rename the saved overview\" (read 2026-09-26)", "vng-softwarecatalogus": "unknown: only VNG-defined \"Marktscans-voorgedefinieerde filters\" are described; users saving their own view is not; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Marktscans (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967727-add-filters-to-the-data: 'You can now save any set of filters as a reusable Quick filter'; https://help.bluedolphin.io/en/articles/14996415-custom-insights: 'You can save, rename, and share report configurations' (read 2026-09-26). Reached on: Repository > Save Query (Quick filter).", "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options mentions 'creating saved searches' and shareable filtered URLs; the feature list says 'Reports can be saved and shared with user to retrieve the specific view later' (https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf) (read 2026-09-26). Reached on: Inventory > Saved searches." } }, @@ -3555,7 +3723,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "yes", @@ -3573,7 +3741,8 @@ "glpi": "source read at 11.0.9: src/Glpi/Dashboard/Grid.php:1400 adds a 'Number of %s' card for every menu itemtype, so suppliers, appliances, software and contracts are counted (menu types src/Html.php:1298 to :1300); dashboards are stored by src/Glpi/Dashboard/Dashboard.php:66 and shown on the central page (src/Central.php:135). Reached on: Home > Dashboard; Assets > Dashboard.", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"open the Asset dashboard to see statistics and visualised information regarding your registered assets\" (read 2026-09-26); https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub\" (read 2026-09-26). Reached on: Asset Management > Asset dashboard.", "stackiq": "src/manifest.json:72 Dashboard page with stat widgets kpi-organisations, kpi-modules, kpi-services, kpi-contracts (source metric count on organization/module/catalogService/catalogContract) plus catalog-panels.", - "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tiles for logged-in municipalities (read 2026-09-26); https://www.softwarecatalogus.nl/: \"Voortgang gemeenten Aantal gemeenten per voortgangscategorie ... Aantal ingelogde gemeenten in 2026: 69\" (read 2026-09-26). No contracts. Reached on: Dashboard; homepage." + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: dashboard tiles for logged-in municipalities (read 2026-09-26); https://www.softwarecatalogus.nl/: \"Voortgang gemeenten Aantal gemeenten per voortgangscategorie ... Aantal ingelogde gemeenten in 2026: 69\" (read 2026-09-26). No contracts. Reached on: Dashboard; homepage.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/14600459-home-page-guide: 'The traditional dashboard has been replaced by a new Home page'; count dashboards come as Power BI templates, 'the Basic Dashboard and the Governance Dashboard' (https://help.bluedolphin.io/en/articles/11967711-power-bi-for-bluedolphin-quickstart) (read 2026-09-26). Reached on: Power BI template dashboards over OData." } }, { @@ -3600,6 +3769,7 @@ "stackiq": "lib/Dashboard/ConceptOrganisatiesWidget.php registered at lib/AppInfo/Application.php:760; src/views/widgets/ConceptOrganisatiesWidget.vue:100 filters organisations on status === 'concept', but the status enum is Draft/Active/Inactive/merged (lib/Settings/softwarecatalogus_register.json:2321) after lib/Repair/RenameDutchCatalogValues.php:76 renamed 'Concept' to 'Draft'. Accept writes status 'actief' (:129), which is not in the enum either.", "topdesk": "unknown: not a Nextcloud app; no such widget applies; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: the catalogue is not a Nextcloud app; no such widget applies; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; organisations in concept and a Nextcloud dashboard are not covered (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; organisations have no concept state and there is no Nextcloud dashboard, so this is not covered (read 2026-09-26)", "glpi": "source read at 11.0.9: GLPI is not a Nextcloud app and has no concept organisation state (suppliers only have is_active, install/mysql/glpi-empty.sql:7087), so no such widget exists in its own dashboards (src/Glpi/Dashboard/Grid.php:67)." } @@ -3611,7 +3781,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "yes", @@ -3629,6 +3799,7 @@ "stackiq": "src/manifest.json:1021 Reports page (type reports) with one card, Portfolio rationalization, routing to src/manifest.json PortfolioReport /portfolio-report (PortfolioReportView, GET /api/portfolio-report routes.php:303).", "topdesk": "https://docs.topdesk.com/en/reporting.html: \"Introducing the Reporting Hub ... So far, you could find dashboards and reports in different places\" (read 2026-09-26); https://tip.topdesk.com/c/20-reporting-hub: roadmap card in column \"Launched\", \"Reporting Hub\" (read 2026-09-26). Reached on: TOPdesk menu > Reporting Hub.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/rapportages: \"Regelmatig worden er rapportages gemaakt over het gebruik van de Softwarecatalogus\" (read 2026-09-26); compliancy monitor and digital accessibility monitor pages. Reached on: Rapportages; Compliancy monitor.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967713-governance-insights: 'Access the Insights from the Main menu under the Visualization section. When you open Insights, the column lists all available reports' (read 2026-09-26). Reached on: Main menu > Visualization > Insights.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/report-types lists ready report types such as 'Landscape Report', 'Matrix Report', 'Roadmap Report'; the feature list names 'Pre-configured reports with adjustable filters' (https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf) (read 2026-09-26). Reached on: Reports." } }, @@ -3639,7 +3810,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "no", @@ -3659,7 +3830,8 @@ "glpi": "source read at 11.0.9: any itemtype list takes arbitrary criteria (src/Glpi/Search/Input/QueryBuilder.php:72), selectable columns, and exports to CSV, PDF, ODS or XLSX (src/Glpi/Search/Output/Xlsx.php); the result can be saved (src/SavedSearch.php:52) and charted on a dashboard (src/Glpi/Dashboard/Grid.php:67). Reached on: any list with criteria, column selection and export.", "stackiq": "No report builder in src/ or lib/. The only report is the fixed Gartner TIME portfolio report (lib/Controller/PortfolioReportController.php, CSV at :105). The overlay lists portfolio-reporting as status 'soon'.", "topdesk": "https://docs.topdesk.com/en/reporting.html: \"The Report Wizard is not available for the Asset Management module. Further reporting can be done with the Asset Type Report or the OData feed\" (read 2026-09-26). Reached on: Asset Type Report; OData.", - "vng-softwarecatalogus": "unknown: only CSV exports for use in a spreadsheet are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)" + "vng-softwarecatalogus": "unknown: only CSV exports for use in a spreadsheet are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/14996415-custom-insights: save configurations of supported built in reports; for deeper reports 'you need to use our OData feed and connect it to a BI tool of your choice' (https://help.bluedolphin.io/en/articles/11967711-power-bi-for-bluedolphin-quickstart) (read 2026-09-26). Reached on: Insights > Custom insights; OData with Power BI." } }, { @@ -3669,7 +3841,7 @@ "origin": "competitor", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -3689,6 +3861,7 @@ "stackiq": "Portfolio report CSV: lib/Controller/PortfolioReportController.php:105 (DataDownloadResponse text/csv), button src/views/organisaties/PortfolioReport.vue:567. No index page sets the library's allowExport (grep allowExport/exportable in src/manifest.json and the register finds nothing), so Applications, Contracts and the other lists have no export.", "topdesk": "https://docs.topdesk.com/en/asset-dashboard.html: \"Export to .CSV Export to Excel\" (read 2026-09-26). Reached on: Asset dashboard tile menu.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/pakketversies: \"Export to CSV\" on the filtered package-version list (read 2026-09-26); https://www.softwarecatalogus.nl/Beschikbare%20downloads: \"Ook beschikbaar via knop [Export to csv] op pagina Alle pakketten\" (read 2026-09-26). Reached on: Alle pakketversies > Export to CSV.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967708-connect-power-bi-and-excel-to-the-odata-feed-windows-os connects Excel to the OData feed; the DataCollection 'Export is no longer supported' (https://help.bluedolphin.io/en/articles/11967630-install-and-configure-datacollection-frontend-and-service). A direct export of a filtered list is not documented (read 2026-09-26). Reached on: Excel via OData feed.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/exporting-fact-sheet-data-as-excel-file: 'In the inventory, apply filters to narrow down to the fact sheets that you need to export ... export fact sheet data as an Excel file' (read 2026-09-26). Reached on: Inventory > table view > Export." } }, @@ -3716,6 +3889,7 @@ "stackiq": "No scheduled report or report mail job: lib/BackgroundJob/ holds only ContractStatusJob, EolSyncJob, FederationSyncJob and OrganizationContactSyncJob; grep for report scheduling in lib/ and src/ finds nothing.", "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"Reports & Selections > Schedule reports with my own authorizations : the operator can schedule reports to be regularly saved or sent to contact persons\" (read 2026-09-26). Reached on: Reports & Selections.", "vng-softwarecatalogus": "unknown: no scheduled reports are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; surveys can be scheduled (https://bluedolphin.io/application-portfolio-management-application-rationalization/ 'Keep data current by scheduling surveys'), but sending reports on a schedule is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; scheduled notification digests (https://help.sap.com/docs/leanix/ea/notifications-center) and scheduled snapshot exports by API (https://help.sap.com/docs/leanix/ea/export) exist, but mailing a report to named people on a schedule is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: saved search alerts, src/SavedSearch_Alert.php:45 with count conditions (src/SavedSearch_Alert.php:53 to :58) and a frequency, run by src/SavedSearch_Alert.php:307 cronSavedSearchesAlerts and sent through the notification system to configured recipients; they notify on a result count rather than sending the report itself. Reached on: Tools > Saved searches > Alerts tab." } @@ -3747,6 +3921,7 @@ "stackiq": "src/views/LicensePostureView.vue:84 per-vendor rollup with annual cost from contracts (src/utils/licensePosture.js perVendorRollup); src/views/organisaties/PortfolioReport.vue:143 annualised and one-off cost per TIME quadrant for one selected organisation (lib/Service/PortfolioReportService.php via GET /api/portfolio-report).", "topdesk": "https://docs.topdesk.com/en/obtain-insights-with-asset-type-report.html: \"do you need an overview of the total costs of new assets?\" (read 2026-09-26); call cost fields in https://docs.topdesk.com/en/fields-for-call-management-reports.html. Reached on: Asset Type Report.", "vng-softwarecatalogus": "unknown: costs are not recorded; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; cost is a questionnaire field (https://help.bluedolphin.io/en/articles/11967733-quick-start-guide) but no cost report per organisation or domain is documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-portfolio-management-dashboard: 'application run cost broken down by business capability'; https://help.sap.com/docs/leanix/ea/dashboard-modeling: 'Report on cost per business capability' (read 2026-09-26). Reached on: Dashboards > Application Portfolio Management Dashboard." } }, @@ -3774,6 +3949,7 @@ "stackiq": "src/manifest.json:1048 FeaturesRoadmap page (type roadmap, line 1050), footer menu entry FeaturesRoadmapMenu; content from openspec/features.overlay.json statuses stable/beta/soon.", "topdesk": "https://docs.topdesk.com/en/topdesk-labs.html: \"As a SaaS user, you can turn on the labs features you are curious about through Functional Settings > Labs\" (read 2026-09-26); https://docs.topdesk.com/en/ai-features.html: \"On your settings page, you can find an overview of all the AI features currently available in your environment\" (read 2026-09-26). Coming-soon items live on the external roadmap, not in the app. Reached on: Functional Settings > Labs.", "vng-softwarecatalogus": "unknown: FAQ E14 points to a homepage block \"Binnenkort in de Softwarecatalogus\", but today's homepage shows no such block; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/ (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; an in app view of available, beta and coming features is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/ai-governance-extension: 'Go to Administration > Optional Features and Early Access' to activate extensions; the public roadmap is outside the app at https://roadmap.leanix.net/ (read 2026-09-26). Reached on: Administration > Optional Features and Early Access.", "glpi": "source read at 11.0.9: grep -rli 'coming soon' over src/ templates/ returns no in app feature status page; src/Glpi/Features/ holds item traits (for example src/Glpi/Features/Kanban.php), not feature flags. src/Glpi/Features/Kanban.php:45 is a trait, typical of that directory." } @@ -3785,7 +3961,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", @@ -3803,6 +3979,7 @@ "stackiq": "lib/Controller/SettingsController.php:1289 getProgress and :1360 streamProgress (routes.php:119-120) serve lib/Service/ProgressTracker.php, used only by lib/Service/MergeOrganisatieService.php; no src/ caller of /api/progress. The admin ArchiMate import shows a spinner then the final objects-processed count (src/views/settings/sections/ArchiMateImportExport.vue:103). Organisation sync shows a status block with last sync time and organisations to process (src/views/settings/sections/OrganizationSynchronization.vue:211).", "topdesk": "unknown: import errors can be downloaded as logs; following progress of a running import is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no progress display for sync or import is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967642-source-processing: the source processing module shows when 'the system is currently handling multiple items simultaneously' and items ready for processing; AMEFF import only shows a checkmark when done (https://help.bluedolphin.io/en/articles/11967637-import-ameff-files) (read 2026-09-26). Reached on: Source processing module.", "sap-leanix": "https://updates.leanix.net/announcements/product-update-march-2026: 'A real-time progress widget in the inventory side-panel keeps you informed of import status'; integration runs are followed in 'Administration > Integrations > Sync Log' (https://help.sap.com/docs/leanix/ea/collibra-data-catalog-integration) (read 2026-09-26). Reached on: Inventory side panel import progress; Administration > Integrations > Sync Log." } }, @@ -3831,6 +4008,7 @@ "topdesk": "https://docs.topdesk.com/en/knowledge-management.html: \"The Knowledge Base is set up and managed by your organization's knowledge managers. Every operator is able to use information from the Knowledge Base\" (read 2026-09-26). Reached on: Modules > Knowledge Management.", "stackiq": "No knowledge-article schema among the register's schemas (sector, suite, catalogService, vulnerability, contactPerson, organization, usage, catalogContract, connection, software-review, element, view, model, property-definition, relation, module, compliancy, bioMeasure, moduleVersion, sbomComponent in lib/Settings/softwarecatalogus_register.json); ModuleDetail only has a Documentation files panel.", "vng-softwarecatalogus": "unknown: the FAQ and manuals are site help, no knowledge base about applications is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; the Knowledge AI Assistant 'only uses Bluedolphin's publicly available documentation' (https://help.bluedolphin.io/en/articles/12528662-ai-capabilities-of-bluedolphin), a customer knowledge base of articles about applications is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; fact sheets hold links and files in a Resources tab (https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets), but no searchable knowledge base of articles is documented (read 2026-09-26)" } }, @@ -3859,6 +4037,7 @@ "stackiq": "No discovery agent or agent-ingest endpoint in lib/ or appinfo/routes.php. The nearest capability is SBOM import per module version (lib/Controller/SbomController.php:129), which records components of a known release, not installed software.", "topdesk": "https://docs.topdesk.com/en/taking-inventory-with-configuration-management.html: \"TOPsis will scan the workstations in your network and import the data into TOPdesk\" (read 2026-09-26) (old Configuration Management); https://docs.topdesk.com/en/migration-status.html: \"For network scanning purposes, we advise you to use other solutions that are available via the TOPdesk Marketplace: Lansweeper integration Microsoft Endpoint Manager integration\" (read 2026-09-26)", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; the DataCollector uploads data from databases and files (https://help.bluedolphin.io/en/articles/11967629-import-and-export-options-with-bluedolphin), an installation discovery agent is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; LeanIX has no own installation agent, software assets come in through the ServiceNow integration (https://help.sap.com/docs/leanix/ea/obsolescence-risk-management-import-software-assets) (read 2026-09-26)" } }, @@ -3887,6 +4066,7 @@ "stackiq": "No network scanning code in lib/ or routes (appinfo/routes.php).", "topdesk": "https://docs.topdesk.com/en/creating-a-new-import.html: \"Connecting to Lansweeper as Asset Management import source\" (read 2026-09-26); https://tip.topdesk.com/c/186-automated-asset-scanning-tool: roadmap card in column \"Under consideration\", \"The asset discovery tool constantly monitors the entire network for new devices\" (read 2026-09-26)", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; network discovery is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; network device discovery is not documented (read 2026-09-26)" } }, @@ -3915,6 +4095,7 @@ "stackiq": "No SaaS or SSO-log discovery code in lib/; lib/Settings/connections.json has no such source.", "topdesk": "unknown: SaaS discovery is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for SaaS discovery, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: inventory handlers under src/Glpi/Inventory/Asset/ (Software.php, Process.php, VirtualMachine.php and others) read what the agent sees on devices; grep -i 'saas' over src/ returns nothing, so cloud subscriptions nobody registered are not discovered. The software handler is src/Glpi/Inventory/Asset/Software.php:56." } }, @@ -3925,7 +4106,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "no", @@ -3943,6 +4124,7 @@ "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"Think of a router that provides a computer with access to your network, or a printer\" (read 2026-09-26); any asset type via templates. Reached on: Asset Management.", "stackiq": "No hardware schema in lib/Settings/softwarecatalogus_register.json (schemas are software, organisation, contract and GEMMA model types only).", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl lists 'Device' and 'Node' object definitions, and the welcome page names 'servers, applications' as assets (https://help.bluedolphin.io/en/articles/11967472-welcome-to-bluedolphin). Modeled as architecture objects, not as an asset register (read 2026-09-26). Reached on: Objects > Device or Node object.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/it-component-modeling-guidelines: IT component subtype 'Hardware ... (e.g., servers, mainframe computers, storage devices)'. Modeled as technology types an application depends on, not individual laptops as assets (read 2026-09-26). Reached on: IT Component fact sheet, subtype Hardware." } }, @@ -3953,7 +4135,7 @@ "origin": "competitor", "vng-softwarecatalogus": "no", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -3971,6 +4153,7 @@ "glpi": "source read at 11.0.9: configuration items are the asset types (src/autoload/CFG_GLPI.php:208) plus appliances, with relations recorded as appliance membership (src/Appliance_Item.php:45), impact relations (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and network port links. Reached on: Assets menu; item > Impact analysis tab.", "topdesk": "https://docs.topdesk.com/en/linking-assets-to-other-assets.html: \"You register these functionalities as custom link types, and these link types are shown in the graphical overview of assets\" (read 2026-09-26). Reached on: Asset card > Relationships widget.", "stackiq": "Applications (module lib/Settings/softwarecatalogus_register.json:6777), versions (moduleVersion :7649), suites (suite :1135) and application-to-application connections (connection :3563) with relations; ModuleDetail and SuiteDetail show a Related panel. No manifest page has register+schema 'connection' or 'usage', so connections are not listed or created on their own page.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967472-welcome-to-bluedolphin lists 'Configuration management' among configurable application areas, with objects such as servers and their relationships; CMDB data comes in from ServiceNow and TOPdesk (https://help.bluedolphin.io/en/articles/11967783-servicenow-to-bluedolphin-integration). An architecture repository rather than an operational CMDB (read 2026-09-26). Reached on: Objects and relationships; ServiceNow integration.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/jira-service-management-integration: 'Use the Jira Service Management integration to synchronize data between your configuration management database (CMDB) and SAP LeanIX ... Configuration items from Jira Service Management can be mapped to various fact sheet types'. LeanIX consumes a CMDB, it does not act as one (read 2026-09-26). Reached on: Jira Service Management and ServiceNow integrations." } }, @@ -3981,7 +4164,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", @@ -3998,6 +4181,7 @@ "stackiq": "Organisation merge: src/manifest.json:430 OrganisationMergePanel on OrganisatieDetail, calling /api/organisaties/{uuid}/merge/dry-run and /merge (src/store/modules/organisatie.js:486/524, lib/Controller/MergeController.php:106, admin-only body guard). Federation mirrors are reconciled per peer by lib/Service/Federation/FederationMerger.php.", "topdesk": "unknown: deduplication across sources is not described; https://tip.topdesk.com/c/239-ai-cmdb-monitoring- (duplicates) is under consideration; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967635-four-things-you-need-to-know-before-you-start-importing-sources: 'for each record an object will be created or merged with an already existing object'; https://help.bluedolphin.io/en/articles/11967644-use-datasource-to-enrich-objects enriches objects from a second source (read 2026-09-26). Reached on: Admin > Sources; Source processing.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/aggregation-and-linkage-of-software-records: 'import software records from ServiceNow as aggregated software fact sheets'; https://help.sap.com/docs/leanix/ea/matching-rules: custom matching to avoid 'duplicate fact sheets'; SaaS discovery links the same SaaS found in several SSOs (https://help.sap.com/docs/leanix/ea/saas-discovery) (read 2026-09-26). Reached on: ServiceNow integration > aggregation; matching rules; SaaS discovery inbox.", "glpi": "source read at 11.0.9: src/RuleImportAsset.php:46 import and link rules decide whether an incoming inventory record matches an existing asset (by serial, UUID, MAC and similar) or creates one; src/RuleDictionnarySoftware.php:44 normalises software names and publishers from different sources; duplicates can be merged afterwards (src/Software.php:1011). Reached on: Administration > Rules > Rules for import and link equipments; Dictionaries." } @@ -4027,6 +4211,7 @@ "topdesk": "https://docs.topdesk.com/en/linking-assets-to-cards.html: \"On Call, Change (Activity) ... cards, you can link multiple assets\" (read 2026-09-26). Reached on: Call card > Links > Assets.", "stackiq": "No incident or request schema or endpoint in lib/Settings/softwarecatalogus_register.json or appinfo/routes.php.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; incidents stay in the ITSM tool, logging them against an application in BlueDolphin is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/portals: an Application Portal 'accessible to everyone to order software, issue support tickets' through configurable links to the helpdesk; incidents themselves stay in the ITSM tool (read 2026-09-26). Reached on: Portals > links to helpdesk." } }, @@ -4055,6 +4240,7 @@ "topdesk": "https://docs.topdesk.com/en/requesting-a-change.html: \"A Preliminary Request for Change can only be dealt with as a Request for Change after it is authorized\" (read 2026-09-26). Reached on: Modules > Change Management.", "stackiq": "No change-request workflow for applications. The only approval flow is for contracts: src/components/contracts/ContractApprovalPanel.vue on ContractDetail via /api/contracts/{uuid}/approval (routes.php:35-37), delegated to decidiq.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; a change approval workflow on an application is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; architecture decisions have a review process (https://help.sap.com/docs/leanix/ea/architecture-decisions) but a change approval workflow on an application is not documented (read 2026-09-26)" } }, @@ -4083,6 +4269,7 @@ "topdesk": "https://docs.topdesk.com/en/track-when-you-respond-to-calls, response-times.html: \"you register and track how quickly your operators need to respond ... you need a Contract Management and SLM license\" (read 2026-09-26). Reached on: Contract Management and SLM.", "stackiq": "catalogContract.contractType enum includes 'SLA' (lib/Settings/softwarecatalogus_register.json:3344) as a label only; no service-level target, measurement or breach fields in any schema.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for SLA and service level, no hits (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: 'Service Level Agreement (SLA) Single Select Corporate-Level SLA, Customer-Level SLA, Service-Level SLA' and an SLA description on the contract. No tracking of targets against results (read 2026-09-26). Reached on: Contract fact sheet > Governance and Regulations." } }, @@ -4110,6 +4297,7 @@ "topdesk": "https://docs.topdesk.com/en/mobile-access-to-the-self-service-portal.html: \"The SSP layout is suited to be displayed in a mobile interface\" (read 2026-09-26); https://tip.topdesk.com/c/86-webshop-is-connected-with-asset-management: roadmap card in column \"Building\", \"End-user can order items which are in Asset Management\" (read 2026-09-26); pricing lists \"Self-Service Portal\" and \"Webshop\". Reached on: Self-Service Portal.", "stackiq": "No software-request flow. The only public intake is organisation self-registration (lib/Controller/IntakeController.php, POST /api/intake/register, routes.php:214), which no src/ page calls.", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; the process portal publishes processes (https://help.bluedolphin.io/en/articles/11967500-getting-started-with-process-publication-portal), but requesting software is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/portals: 'create an Application Portal that is accessible to everyone to order software ... Action button: Perform an action, in this case \"Request new Application\"' (read 2026-09-26). Reached on: Portals > Application Portal.", "glpi": "source read at 11.0.9: the 11.0 service catalog src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45 lists native forms for self service users (menu src/Html.php:1283), and a form question can offer software items to pick, src/Glpi/Form/QuestionType/QuestionTypeItem.php:180 Software::class, creating a ticket from the answer. Reached on: Self service > Service catalog. Driven on the lab at 11.0.9 (2026-09-26): /ServiceCatalog shows the service catalog with \"Report an issue\" and \"Request a service\"." } @@ -4120,7 +4308,7 @@ "name": "Use the product from a native mobile app.", "origin": "competitor", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "no", "bluedolphin": "unknown", "glpi": "no", "topdesk": "yes", @@ -4138,7 +4326,8 @@ "topdesk": "https://docs.topdesk.com/en/installing-the-topdesk-mobile-store-application.html: \"Scan the QR code to download the app from the Play store\" (read 2026-09-26). Reached on: TOPdesk Mobile app.", "stackiq": "No mobile app or mobile-specific surface in the repo; the app is the Nextcloud web UI (src/manifest.json).", "vng-softwarecatalogus": "unknown: operational IT management functions are not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for mobile app, iOS and Android, no hits; only a Microsoft Teams app is documented (https://help.sap.com/docs/leanix/ea/sap-leanix-app-for-microsoft-teams) (read 2026-09-26)", + "bluedolphin": "unknown: https://help.bluedolphin.io/en/articles/11967477-minimum-system-requirements lists desktop browsers (Chrome, Firefox, Edge) and says Safari 'is not supported'; a native mobile app is not documented (read 2026-09-26)", + "sap-leanix": "https://updates.leanix.net/announcements/explore-portals-on-mobile-devices (2025-09-18): 'Since the mobile app was decommissioned in June 2023, we planned to make portals mobile responsive'; only portals are mobile friendly (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'android\\|ios app\\|mobile app' over src/ templates/ returns nothing; the repository ships only the responsive web interface (templates/) and APIs (src/Glpi/Api/HL/Controller/CoreController.php:322 docs), no native mobile client." } }, @@ -4149,7 +4338,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "partial", "stackiq": "partial", @@ -4168,6 +4357,7 @@ "stackiq": "lib/BackgroundJob/OrganizationContactSyncJob.php:75 TimedJob every 300 s calling performScheduledSync; admin section src/views/settings/sections/CronjobConfiguration.vue:56 shows each job's interval and an enable switch; src/views/settings/sections/OrganizationSynchronization.vue:211 shows Last Sync from app config last_sync_time (lib/Service/OrganizationSyncService.php:1609, written by recordSyncTime :1674).", "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"when tracking imports/Exchange exports via system events ... on a schedule\" (read 2026-09-26); https://tip.topdesk.com/c/116-support-for-importing-persons-and-operators-directly-from-local-active-directory: roadmap card in column \"Launched\", person import from AD (read 2026-09-26). Reached on: Settings > Import settings.", "vng-softwarecatalogus": "unknown: only \"De kaart wordt dagelijks bijgewerkt\" is stated; no organisation or contact sync is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/node/17042 (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967472-welcome-to-bluedolphin: 'This data can then be synchronized with BlueDolphin based on a scheduled task, periodically (for example, every hour)'; https://help.bluedolphin.io/en/articles/11967629-import-and-export-options-with-bluedolphin: 'Automatically via interval' (read 2026-09-26). Reached on: DataCollection Service; Admin > Sources.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/configuring-automated-nightly-runs-for-inbound-processors: 'enable automated nightly runs for an inbound Integration API processor'; SaaS discovery retrieves data 'usually twice a day' (https://help.sap.com/docs/leanix/ea/saas-discovery); runs visible in 'Administration > Integrations > Sync Log' (read 2026-09-26). Reached on: Administration > Integrations > Sync Log.", "glpi": "source read at 11.0.9: automatic actions are scheduled and show their last run, src/CronTask.php:59 with install/mysql/glpi-empty.sql:1610 glpi_crontasks.lastrun, but LDAP user and group synchronisation is not one of them (grep -i ldap over the cron seed in install/empty_data.php:438 finds none); it is the CLI src/Glpi/Console/Ldap/SynchronizeUsersCommand.php:79 ldap:synchronize_users, which must be scheduled by the system cron. Organisation (supplier) records have no sync at all. Reached on: Setup > Automatic actions; CLI bin/console ldap:sync. Driven on the lab at 11.0.9 (2026-09-26): /front/crontask.php lists automatic actions with run mode, frequency and last run." } @@ -4193,13 +4383,13 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the Gemeentelijk Gegevensmodel is not mentioned; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, GGM and Gemeentelijk Gegevensmodel, no hits; data objects exist (https://help.sap.com/docs/leanix/ea/data-object-modeling-guidelines) but no GGM content (read 2026-09-26)", + "bluedolphin": "https://github.com/Gemeente-Delft/Gemeentelijk-Gegevensmodel/blob/master/README.md (third party, maintained by Gemeente Delft): 'Een aantal gemeenten gebruikt het GGM inmiddels ook met ... Blue Dolphin' and 'hiervoor gebruik je het AMEFF-bestand van het GGM uit de GEMMA-repository voor de Architectuur module van BlueDolphin'; AMEFF import at https://help.bluedolphin.io/en/articles/11967637-import-ameff-files. Not a vendor feature (read 2026-09-26). Reached on: Admin > System > Import (GGM AMEFF), then relationships.", "glpi": "source read at 11.0.9: grep -rli 'gegevensmodel\\|ggm' over src/ templates/ locales/glpi.pot returns nothing; appliances have no data entity model to relate to (install/mysql/glpi-empty.sql:8935 glpi_appliances).", "topdesk": "unknown: the Gemeentelijk Gegevensmodel is not mentioned (0 hits); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "sap-leanix": "unknown", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown" }, @@ -4224,13 +4414,13 @@ "vng-softwarecatalogus": "partial", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"Download de kaart met de knop [download SVG] ... De kaart volledig schaalbaar\" (read 2026-09-26). A map is downloaded as SVG for printing; placing it in Word or PowerPoint is a manual step. Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart > download SVG.", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/using-reports: 'Using the HTML Embed Code, you can embed and have live data from the SAP LeanIX inside a tool such as Confluence and PowerPoint (using a Web Viewer add-ins)'; diagrams export as PDF, SVG, PNG (https://help.sap.com/docs/leanix/ea/importing-and-exporting-diagrams). No direct Word or PowerPoint export (read 2026-09-26). Reached on: Reports > Export > HTML embed; Diagrams > Export.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967514-download-a-view: 'To use the image of a view, for example, in a document, you can download the view as a file in PNG, SVG, PDF'. No direct Word or PowerPoint insertion is documented (read 2026-09-26). Reached on: View > Download.", "glpi": "source read at 11.0.9: the only diagram is the impact graph, whose Download writes PNG or JPEG (js/impact.js:2539, :2546); grep -rli 'docx\\|pptx\\|powerpoint' over src/ finds no Office export of views, only XLSX and ODS list output (src/Glpi/Search/Output/Xlsx.php).", "topdesk": "unknown: architecture views and Word or PowerPoint are not mentioned (0 hits for PowerPoint); searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, - "sap-leanix": "unknown", - "bluedolphin": "unknown", + "sap-leanix": "partial", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown" }, @@ -4254,13 +4444,13 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: no data modelling is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/data-object-modeling-guidelines: 'we capture data in the data object fact sheet', related to applications and classified; entity relationship or UML diagrams of data entities are not documented (read 2026-09-26). Reached on: Inventory > Data Object fact sheet.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967570-keys-and-relationships: 'Primary keys are unique identifiers for a data object and can be used to create a relationship between data objects'; https://help.bluedolphin.io/en/articles/11967568-logical-data-dictionary; views of type 'Logical Data' (https://help.bluedolphin.io/en/articles/11967483-views-button-explanation) (read 2026-09-26). Reached on: Views > Logical Data view.", "glpi": "source read at 11.0.9: grep -rli 'entity.relationship\\|uml' over src/ templates/ locales/glpi.pot returns nothing; databases are inventoried as instances and names (src/DatabaseInstance.php:43, src/Database.php:41, install/mysql/glpi-empty.sql:9468 glpi_databases) without entities or relations.", "topdesk": "unknown: no data entity or UML modelling is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, - "sap-leanix": "unknown", - "bluedolphin": "unknown", + "sap-leanix": "partial", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown" }, @@ -4284,13 +4474,13 @@ "vng-softwarecatalogus": "partial", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/gebruikersbeheer: \"Er opent zich een overzicht met alle geregistreerde gebruikers van uw organisatie ... inclusief wanneer zij voor het laatst hebben ingelogd\" (read 2026-09-26); https://www.softwarecatalogus.nl/: tip \"Controleer of alle gebruikers nog werkzaam zijn bij de gemeente of samenwerking\" (read 2026-09-26). A manual check, no review cycle. Reached on: Menu > Gebruikersbeheer.", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for access review and recertification, no hits; user statuses are listed in https://help.sap.com/docs/leanix/ea/users-overview but periodic access review is not documented (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/13714834-power-bi-for-bluedolphin-governance: the Basic Governance dashboard 'supports access reviews and permission audits'. A Power BI template; withdrawing access is a manual admin step (read 2026-09-26). Reached on: Power BI governance dashboard; Admin > Users.", "glpi": "source read at 11.0.9: grep -rli 'recertif\\|access review' over src/ templates/ locales/glpi.pot returns nothing; users carry last_login and validity dates (install/mysql/glpi-empty.sql:7813 last_login, :7866 begin_date, :7867 end_date) that an admin can search on, but there is no periodic review campaign.", "topdesk": "https://docs.topdesk.com/en/operator-licence-overview.html: the list of operators shows \"When the given operator was last active (meaning their last login)\" (read 2026-09-26). Input for a review; no periodic review process is described. Reached on: Operator licence overview." }, "sap-leanix": "unknown", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "partial" }, @@ -4315,8 +4505,8 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: no link to a register of processing activities is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for processing activities, ROPA and Article 30, no hits (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for processing activities and verwerkingsregister, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'processing activit\\|gdpr' over src/ returns nothing; the records of processing plugin yild/gdprropa (tag 1.0.3, setup.php:56) supports GLPI 10 only.", "topdesk": "unknown: no register of processing activities is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4346,8 +4536,8 @@ "vng-softwarecatalogus": "yes", "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"De leveranciersinformatie in de Softwarecatalogus is openbaar\" (read 2026-09-26); https://www.softwarecatalogus.nl/inkoopondersteuning%20standaarden: \"De gegenereerde bestekstekst kunt u gebruiken in uw offerte-uitvraag ... Als informatiebron is de GEMMA softwarecatalogus gebruikt\" (read 2026-09-26). Reached on: Supplier login > Productportfolio; Inkoopondersteuning.", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; suppliers keeping public product information in the catalogue is not documented (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; public supplier product information is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers have no account or public product page (install/mysql/glpi-empty.sql:7067 glpi_suppliers); anonymous access covers only the FAQ (src/KnowbaseItem.php:131 use_public_faq).", "topdesk": "unknown: TOPdesk is a single-organisation tool; public supplier product information is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4377,13 +4567,13 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: no value, cost or risk scoring is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/application-rationalization: baseline data points 'Business criticality', 'Functional and technical fit'; TCO per application (https://help.sap.com/docs/leanix/ea/application-total-cost-of-ownership-extension) and obsolescence risk feed TIME classification (https://help.sap.com/docs/leanix/ea/time) (read 2026-09-26). Reached on: Application fact sheet > Business criticality, Functional fit, Technical fit.", + "bluedolphin": "https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'Capture lifecycle, technical debt, business value, risk, cost, contracts, ESG, and security data' and 'multidimensional portfolio analysis from cost, risk, lifecycle, and business criticality perspectives' with TIME analysis (read 2026-09-26). Reached on: APM questionnaires and TIME analysis.", "glpi": "source read at 11.0.9: grep -rli 'business value' over src/ locales/glpi.pot returns nothing; appliances carry no value, cost or risk score fields (install/mysql/glpi-empty.sql:8935 glpi_appliances), only the software ticket_tco figure (install/mysql/glpi-empty.sql:6872).", "topdesk": "unknown: no value, cost and risk scoring of applications is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, - "sap-leanix": "unknown", - "bluedolphin": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", "glpi": "no", "topdesk": "unknown" }, @@ -4406,13 +4596,13 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #136 'Als CISO wil ik ons gemeentelijk pakketoverzicht kunnen controleren en vervolgens fiatteren'; no approval step for the landscape appears in the incumbent manuals (https://www.softwarecatalogus.nl/node/19703). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/quality-seal: the quality seal 'assigns accountability to the responsible or accountable user to approve the quality of a fact sheet'; https://help.sap.com/docs/leanix/ea/subscription-roles lists a default 'Security officer' role as Observer. Approval is per fact sheet, not a sign off of the whole list (read 2026-09-26). Reached on: Fact sheet > Quality seal.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; a security officer sign off of the application list is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: approvals exist only on ITIL objects (src/CommonITILValidation.php:49, children TicketValidation and src/ChangeValidation.php:39); there is no sign off of the appliance list itself. A change could be used to carry an approval, which is not a catalogue sign off.", "topdesk": "unknown: a sign-off of the application list is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown" @@ -4436,8 +4626,8 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #82 'Als gebruik-raadpleger wil ik een register van verwerkingen kunnen genereren'; the incumbent exports only package, connection and IBD-foto files (https://www.softwarecatalogus.nl/Beschikbare%20downloads). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for register of processing activities, no hits (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; generating a register of processing activities is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'processing activit\\|gdpr' over src/ returns nothing, so there is no register to generate; the report list (src/Report.php:77 to :111) has no such report.", "topdesk": "unknown: no register of processing activities is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4466,8 +4656,8 @@ "vng-softwarecatalogus": "partial", "evidence": { "vng-softwarecatalogus": "Open PvE wens #50 (search) and #48 (register collective agreements incl. AVG and BIO terms); the incumbent lists signed addenda per supplier with a filter (https://www.softwarecatalogus.nl/addenda), which covers part of it. (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; collective or framework agreements for all municipalities are not covered (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; collective agreements for municipalities are not covered (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'collective agreement\\|raamovereenkomst' over src/ locales/glpi.pot returns nothing; contracts (install/mysql/glpi-empty.sql:1483) belong to the instance's own entities and nothing is shared across organisations.", "topdesk": "unknown: collective agreements across organisations are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4496,8 +4686,8 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #41 'relevante documenten zoals DPIA's, verwerkersovereenkomsten en pentesten kunnen delen zodat andere gemeenten hier eenvoudig gebruik van kunnen maken'; the incumbent only holds supplier test reports (https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; files attach to fact sheets inside one workspace (https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets), sharing them with other organisations is not documented (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; attachments stay on objects inside one tenant (https://help.bluedolphin.io/en/articles/11967535-object-attachments), sharing them with other organisations is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: documents (src/Document.php:67) are visible only inside the instance through entities and profiles; anonymous access is limited to FAQ attachments when use_public_faq is on (src/Document.php:717), and there is no sharing with other organisations.", "topdesk": "unknown: assets hold documents in a Documents widget, but sharing them with other organisations is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4526,8 +4716,8 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #46 'Als CISO wil ik de pakketten in mijn pakketoverzicht van een BBN classificatie voorzien'; BBN exists only as a GEMMA view per reference component per the news page (https://www.softwarecatalogus.nl/nieuws). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for confidentiality, integrity and availability levels; only data objects are classified by sensitivity (https://help.sap.com/docs/leanix/ea/data-object-modeling-guidelines 'public, sensitive, restrictive, and confidential') (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; availability, integrity and confidentiality levels per application are not documented beyond generic questionnaires (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'confidentialit' over src/ templates/ locales/glpi.pot returns nothing and appliances have no availability, integrity or confidentiality fields (install/mysql/glpi-empty.sql:8935 glpi_appliances); only a repurposed dropdown or a custom asset field could hold it.", "topdesk": "unknown: no availability, integrity and confidentiality classification is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4556,8 +4746,8 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #31 'meerdere pakketten kunnen selecteren en deze in een overzichtelijke tabel naast elkaar vergelijken'; the incumbent offers filtered lists only (https://www.softwarecatalogus.nl/node/13683). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a side by side product comparison table is not documented, only inventory table views (https://help.sap.com/docs/leanix/ea/adding-and-editing-data-in-fact-sheets) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; comparing products side by side is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: any list can be narrowed to chosen entries with criteria (src/Glpi/Search/Input/QueryBuilder.php:72) and shows the chosen columns in one table, with installation counts per software on the software list; there is no dedicated compare view across products and no market data to compare (src/Glpi/Search/SearchEngine.php:101 searches own records only). Reached on: Assets > Software list with chosen columns.", "topdesk": "unknown: no product comparison table is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4586,8 +4776,8 @@ "vng-softwarecatalogus": "unknown", "evidence": { "vng-softwarecatalogus": "unknown: the live softwarecatalogus.nl does not describe this and does not state its absence; the open PvE wens on the successor repository is not evidence about the incumbent (ruling 2026-09-26). Live page searched: Open PvE wens #104 'Als functioneel beheerder wil ik me kunnen voordoen als een ander account'; not in the incumbent FAQ (https://www.softwarecatalogus.nl/node/16564). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; impersonation is mentioned only for an integration user when building ServiceNow filters (https://help.sap.com/docs/leanix/ea/fact-sheet-mapping-between-servicenow-and-sap-leanix), not for admins viewing as another user (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; viewing the tool as another account is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Session.php:2054 startImpersonating and :2113 stopImpersonating, allowed by src/Session.php:1995 canImpersonate for users with fewer rights and the Impersonate right (src/User.php:6235); the button 'Impersonate' is on the user form (src/User.php:2974). CHANGELOG.md 11.0.0 adds the dedicated right. Reached on: Administration > Users > user form, Impersonate.", "topdesk": "unknown: acting as another user is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4616,8 +4806,8 @@ "vng-softwarecatalogus": "partial", "evidence": { "vng-softwarecatalogus": "Open PvE wens #147; the incumbent shows whether a supplier signed the Groeipact Common Ground addendum (https://www.softwarecatalogus.nl/leveranciers), a supplier-level signal, not per product. (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for Common Ground, no hits (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for Common Ground, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'common ground' over src/ templates/ locales/glpi.pot returns nothing; software and appliances carry no principle or goal declarations (install/mysql/glpi-empty.sql:6856 glpi_softwares).", "topdesk": "unknown: Common Ground is not mentioned; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, @@ -4646,13 +4836,13 @@ "vng-softwarecatalogus": "partial", "evidence": { "vng-softwarecatalogus": "2021 user survey suggestion 'Koppelingen automatisch bijwerken bij een nieuwe versie van pakket'; release 4.1 added a manual copy of a version including its connections (https://www.softwarecatalogus.nl/node/16564, FAQ A1). (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/creating-fact-sheets: 'Cloning fact sheets is particularly useful when you need to create a successor fact sheet ... A cloned fact sheet includes ... All relations, except one-to-one relations', and the clone can be linked as successor. The carry over happens when a user clones (read 2026-09-26). Reached on: Fact sheet > Clone (as successor).", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; carrying relationships to a new version is not documented; objects can be copied (https://help.bluedolphin.io/en/articles/11967529-welcome-to-the-objects) without a stated relation copy (read 2026-09-26)", "glpi": "source read at 11.0.9: installations can be moved to another version by the massive action src/Item_SoftwareVersion.php:179 move_version, but impact relations (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) point at the item and are never copied to a replacing version or appliance; grep -n 'Impact' src/SoftwareVersion.php returns nothing.", "topdesk": "unknown: versions of applications are not modelled; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from vng-softwarecatalogus (featureRequest) on 2026-09-26.", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown" @@ -4677,13 +4867,13 @@ "evidence": { "topdesk": "Card 'More control over card & file removal' in Launched (updated 2026-02-09); docs https://docs.topdesk.com/en/file-maintenance.html: 'you can set how many days after closing or archiving a card its uploaded files and linked emails should be removed'. (read 2026-09-26)", "vng-softwarecatalogus": "unknown: retention cleanup is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/archiving-deleting-and-recovering-fact-sheets: an archived fact sheet 'remains recoverable for 90 days ... After the retention period, the archived fact sheet is automatically and permanently deleted'. Retention covers archived records as a whole, not files and mails after closure (read 2026-09-26). Reached on: Archive > automatic deletion after retention period.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for retention, only questionnaire data retention on BPMN configuration is mentioned (https://help.bluedolphin.io/en/articles/15874771-questionnaires-for-bpmn-elements); timed removal of files is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: closed tickets are purged after a per entity delay, src/Ticket.php:5363 cronPurgeTicket using install/mysql/glpi-empty.sql:2777 autopurge_delay, and documents left without any linked item are removed by src/Document.php:1713 cronCleanOrphansDocument (described at src/Document.php:1700); catalogue records such as appliances or contracts have no closed state or retention delay. Reached on: Administration > Entities > Assistance tab (automatic purge); Setup > Automatic actions." }, "note": "Mined from topdesk (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "glpi": "partial" }, @@ -4707,8 +4897,8 @@ "evidence": { "topdesk": "Card 'Field Dependencies (brand/type/model)' in Under consideration: 'User can set up dependencies between fields'; not in the field docs (https://docs.topdesk.com/en/editing-fields.html). (read 2026-09-26)", "vng-softwarecatalogus": "unknown: dependent fields are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; dependent fields appear only in transformation templates (https://help.sap.com/docs/leanix/ea/creating-custom-transformation-templates), not for fact sheet field options (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; questionnaire field options depending on another field are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: native forms show or hide questions on conditions (src/Glpi/Form/Condition/Engine.php:138, src/Glpi/Form/Condition/VisibilityStrategy.php:39), but options of one field do not filter by another on item forms; the open requests github.com/glpi-project/roadmap/discussions/414 (cascading filters) and /240 (custom field conditions) ask for it. Reached on: Administration > Forms, question conditions." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", @@ -4737,8 +4927,8 @@ "evidence": { "topdesk": "Card 'Changing the type of an asset' in Under consideration: 'User can change the type of an exiting asset'. (read 2026-09-26)", "vng-softwarecatalogus": "unknown: changing an entry type is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; changing the fact sheet type or subtype of an existing entry is not documented as such (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; changing the type of a BPMN element is documented (https://help.bluedolphin.io/en/articles/11967561-add-an-object), changing the object definition of an existing repository object is not (read 2026-09-26)", "glpi": "source read at 11.0.9: the type of an appliance is an editable dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id), changeable in place or by massive update (src/MassiveAction.php:666); changing the itemtype itself (for example a custom asset to another definition) is not possible, since each custom asset class is bound to one definition (src/Glpi/Asset/Asset.php:113), and the open request github.com/glpi-project/roadmap/discussions/232 asks for it. Reached on: Management > Appliances, Type field." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", @@ -4767,8 +4957,8 @@ "evidence": { "topdesk": "Card 'Audit Logging for TOPdesk - MCP Server' in Building: 'you should be able to see exactly what that AI did, which actions it took, when, and on what data'. (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no AI assistant is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; the fact sheet change log records user and time (https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets), but a view of actions taken by an AI assistant is not documented (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; the MCP server is read only (https://help.bluedolphin.io/en/articles/15602927-add-bluedolphin-mcp-server-to-an-ai-assistant) and AI credit usage is reported, but a log of AI actions on records is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: there is no AI assistant in core (grep -rliw 'llm\\|mcp' over src/ returns nothing); the history log (src/Log.php:48) records changes per user or API client, without any AI actor." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", @@ -4798,10 +4988,10 @@ "topdesk": "Card 'Support Multi-Factor Authentication (MFA)' in Under consideration; today MFA only comes from the identity provider behind SAML SSO (https://docs.topdesk.com/en/topdesk-mobile.html: 'We test the store application with the Microsoft two-step authentication (2FA) for the SSO'). (read 2026-09-26)", "glpi": "source read at 11.0.9: CHANGELOG.md:277 11.0.0 added Two-Factor Authentication via TOTP; implemented by src/Glpi/Security/TOTPManager.php:60, with the disable action on the user's settings page (front/preference.php).", "vng-softwarecatalogus": "unknown: login is by username and password (https://www.softwarecatalogus.nl/user/login); a second factor is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for multi factor and two factor, no hits; strong sign in is left to the identity provider through SSO (https://help.sap.com/docs/leanix/ea/managing-users) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for multi factor and two factor, no hits; strong sign in is left to the SSO identity provider (read 2026-09-26)" }, - "note": "Mined from topdesk (roadmap) on 2026-09-26. Also shipped in GLPI 11.0.0 (https://github.com/glpi-project/glpi/releases/tag/11.0.0).", + "note": "Mined from topdesk (roadmap) on 2026-09-26. Also mined from glpi (changelog, https://github.com/glpi-project/glpi/releases/tag/11.0.0).", "glpi": "yes", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", @@ -4827,13 +5017,13 @@ "evidence": { "topdesk": "Card 'Enforce strong passwords' in Under consideration: 'By setting rules for things like minimum length, numbers, symbols, or uppercase letters, weak passwords are blocked'. (read 2026-09-26)", "vng-softwarecatalogus": "unknown: a password policy is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/password-rules: 'We offer two options for password rules: regular and strict', set through support for the workspace (read 2026-09-26). Reached on: Workspace password rules (via support).", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; local passwords are managed in 'BlueDolphin's private Active Directory' (https://help.bluedolphin.io/en/articles/11967616-user-management) but no password policy setting is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: Setup > General > Security enables a password policy (templates/pages/setup/general/security_setup.html.twig:46 use_password_security, :56 password_min_length, :63 password_need_number, :70 password_need_letter), enforced by src/User.php:7187 validatePassword with checks for length, digits, letters, capitals and symbols (src/User.php:7196 onwards), plus expiry settings (install/empty_data.php:380 password_expiration_delay). Reached on: Setup > General > Security." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "glpi": "yes" }, @@ -4857,8 +5047,8 @@ "evidence": { "topdesk": "Card 'AI - Risk & prediction' in Under consideration: 'Change risk prediction helps change managers assess how risky a planned change is before it's approved'. (read 2026-09-26)", "vng-softwarecatalogus": "unknown: change management is not covered; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; a risk score for a planned change from past outcomes is not documented (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; change risk scoring is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: changes carry manual urgency, impact and priority (install/mysql/glpi-empty.sql:659 urgency, :660 impact, :661 priority) and a free text impact analysis (:663 impactcontent); no score is computed from past outcomes or dependencies, and grep -rli 'risk' over src/Change.php returns nothing." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", @@ -4887,14 +5077,14 @@ "evidence": { "glpi": "source read at 11.0.9: open request #336 (2026-05-22) asks to add all connected assets to the impact analysis at once; in core every impact relation is added by hand through src/Impact.php:1161 'Add relation' into install/mysql/glpi-empty.sql:1247 glpi_impactrelations, and the inventory (src/Glpi/Inventory/Inventory.php:106) does not create impact relations.", "vng-softwarecatalogus": "unknown: connections are entered by hand per the iJw and iWmo manual; automatic filling is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/jira-service-management-integration: 'Dependencies and relationships identified in Jira Service Management are automatically documented in SAP LeanIX'; SAP Cloud ALM 'Discovered flows' suggest missing interfaces (https://help.sap.com/docs/leanix/ea/enabling-discovered-flows) (read 2026-09-26). Reached on: Integrations and discovery inbox.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967645-use-datasource-to-create-relationships: 'how to automatically create relationships between objects based on a loaded datasource', for example application component to node (read 2026-09-26). Reached on: Admin > Sources > relationship creation.", "topdesk": "unknown: relations are created by hand in the Relationships widget; automatic filling is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", + "sap-leanix": "yes", + "bluedolphin": "yes", "topdesk": "unknown" }, { @@ -4917,8 +5107,8 @@ "evidence": { "glpi": "source read at 11.0.9: open request #182 (2026-03-27) states contracts cannot be linked in GLPI 11; install/mysql/glpi-empty.sql:1536 glpi_contracts_items links a contract to items, and Contract is not among the linkable item types there, with no parent contract column in install/mysql/glpi-empty.sql:1483 glpi_contracts.", "vng-softwarecatalogus": "unknown: contracts are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model lists contract relations to providers and applications only; contract to contract links such as call offs are not documented (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; links between contracts such as call offs are not documented (read 2026-09-26)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"TOPdesk allows you to link your services to supplier services, so that the duration of your services will always be in line with the duration of supplier services\" (read 2026-09-26). Linking runs through underpinning services, not contract to contract. Reached on: Contract Management and SLM > Service card." }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", @@ -4947,13 +5137,13 @@ "evidence": { "glpi": "source read at 11.0.9: open request #290 (2026-05-07) asks for contract assignees as notification recipients; install/mysql/glpi-empty.sql:1483 glpi_contracts has no users_id or groups_id column, so contract alerts (src/NotificationTargetContract.php:47) go to configured global recipients only.", "vng-softwarecatalogus": "unknown: contracts are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/step-2-set-up-contract-lifecycle-automations: automations 'notify contract owners at key milestones' and 'Ensure data quality by prompting for required ownership information', owners set through subscriptions (read 2026-09-26). Reached on: Contract fact sheet > Subscriptions; contract automations.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; a contract owner who receives expiry warnings is not documented (read 2026-09-26)", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Operator The TOPdesk operator responsible for managing the contract ... Reminder date Date on which an operator should be reminded about the contract, e.g. ahead of expiry\" (read 2026-09-26); https://docs.topdesk.com/en/events-that-trigger-actions.html: \"notify a manager that a contract will expire in a month\" (read 2026-09-26). Reached on: Contract card > Management > Operator." }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "topdesk": "yes" }, @@ -4977,8 +5167,8 @@ "evidence": { "glpi": "source read at 11.0.9: request #457 (2026-07-27, open) asks to tie dates to status; core already lets an entity fill financial dates when an item enters a chosen status, install/mysql/glpi-empty.sql:2800 autofill_use_date and :2822 autofill_decommission_date on glpi_entities, applied by src/Infocom.php:505 autofillDates, but only for the financial record's dates.", "vng-softwarecatalogus": "unknown: statuses and planning dates are entered separately; automatic dates are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; lifecycle phases are set by dates (https://help.sap.com/docs/leanix/ea/advanced-filter-options), filling dates automatically when a status changes is not documented (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; dates filled automatically on a lifecycle state change are not documented (read 2026-09-26)", "topdesk": "unknown: automated actions can update cards, but dates following a lifecycle status are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from glpi (featureRequest) on 2026-09-26.", @@ -5007,13 +5197,13 @@ "evidence": { "glpi": "source read at 11.0.9: CHANGELOG.md:281 11.0.0 added 'View assigned' and 'Update assigned' rights; src/Glpi/Features/AssignableItem.php:68 grants read when the user or group is assigned and src/Glpi/Features/AssignableItem.php:79 checks UPDATE_ASSIGNED; Appliance uses this trait (src/Appliance.php:46 implements AssignableItemInterface).", "vng-softwarecatalogus": "unknown: roles are beheerder and raadpleger per organisation; rights per assigned application are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/subscription-roles: admins 'control what users can do within a fact sheet based on their subscription type'; virtual workspaces restrict visibility by group (https://help.sap.com/docs/leanix/ea/virtual-workspaces-configuration). Seeing only one's own assigned entries is not documented (read 2026-09-26). Reached on: Administration > Subscription permissions.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; permissions are per role and object definition (https://help.bluedolphin.io/en/articles/11967624-manage-roles-and-permissions) and views can be private, but limiting users to entries assigned to them is not documented (read 2026-09-26)", "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"To restrict access to specific data, link the operator to branch, operator, or category filters\" (read 2026-09-26); https://docs.topdesk.com/en/reservations-management-and-other-modules.html: \"Operator filter: operators can see all reservations, but can only edit reservations that are created by them or their operator group\" (read 2026-09-26). Filters by branch, operator or category; not shown for assets assigned to a person. Reached on: Operator card > filters." }, "note": "Mined from glpi (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "partial", "bluedolphin": "unknown", "topdesk": "partial" }, @@ -5037,13 +5227,13 @@ "evidence": { "glpi": "source read at 11.0.9: CHANGELOG.md:276 11.0.0 added custom palette and theme support; src/Glpi/UI/ThemeManager.php:103 getCustomThemesDirectory and :112 getCustomThemes load admin supplied themes, offered in src/Config.php:1612 getPalettes.", "vng-softwarecatalogus": "unknown: the catalogue is one VNG-branded site; organisation styling is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/branding-settings: 'Personalize your workspace's appearance to reflect your brand identity' and upload 'a custom logo to be used in exported reports and diagrams' (read 2026-09-26). Reached on: Administration > Branding.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; a colour palette for objects and shapes exists (https://help.bluedolphin.io/en/articles/11967691-using-the-color-palette-for-objects-and-free-shapes) but interface branding is not documented (read 2026-09-26)", "topdesk": "https://docs.topdesk.com/en/self-service-portal-278632.html: \"you can create several SSP designs, with different colours, logos, and search bar backgrounds, to show a distinct look and feel to different branches\" (read 2026-09-26). Self-Service Portal only; operator interface styling is not described. Reached on: Self-Service Portal designer." }, "note": "Mined from glpi (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", + "sap-leanix": "yes", "bluedolphin": "unknown", "topdesk": "partial" }, @@ -5067,15 +5257,345 @@ "evidence": { "glpi": "source read at 11.0.9: CHANGELOG.md:285 and :286 11.0.0 added cloning of templates and creating a template from an existing item; appliances are clonable (src/Appliance.php:49 use Clonable) together with their items, contracts, documents and financial record (src/Appliance.php:62 getCloneRelations).", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: FAQ A1 \"opvoer van een nieuwe versies mogelijk als kopie van een op te geven vorige versie ... Gegevens van die vorige versie worden overgenomen in de nieuwe versie, ook koppelingen worden overgenomen\" (read 2026-09-26). Copies a version of the same package with its connections, not a new application. Reached on: Mijn softwarecatalogus > Pakketten > kopie-symbool.", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/creating-fact-sheets: 'Cloning a Fact Sheet ... A cloned fact sheet includes the following data from the original fact sheet: All attributes All relations, except one-to-one relations' and attachments (read 2026-09-26). Reached on: Fact sheet > Clone.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967529-welcome-to-the-objects: on the Object properties tab you can 'create a copy of the object with a different name'; whether relationships are copied is not stated (read 2026-09-26). Reached on: Objects > object > Object properties > copy.", "topdesk": "https://docs.topdesk.com/en/copying-assets.html: \"you can save time by copying an existing asset ... Dataset content will not be copied during this action ... Read permissions for any linked asset type\" (read 2026-09-26). Whether links are copied is implied by the permission note, not stated. Reached on: Asset card > More > Copy." }, "note": "Mined from glpi (changelog) on 2026-09-26.", "vng-softwarecatalogus": "partial", - "sap-leanix": "unknown", - "bluedolphin": "unknown", + "sap-leanix": "yes", + "bluedolphin": "partial", "topdesk": "partial" + }, + { + "id": "land-ai-agent-inventory", + "area": "landscape", + "name": "Register the AI agents and AI models the organisation uses and link them to the applications and processes they support.", + "origin": "changelog", + "originUrl": "https://updates.leanix.net/announcements/discover-verify-and-govern-ai-assets-with-sap-ai-agent-hub", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no schema for AI agents or models in lib/Settings/softwarecatalogus_register.json (20 schemas, none for AI systems)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "sap-leanix": "yes", + "evidence": { + "sap-leanix": "Announcement of 2026-05-12: 'We have expanded the AI Agent Hub ... New discovery sources: ServiceNow and SAP AI Core ... automatically populate your workspace with AI assets'; AI agent is an application subtype and AI model an IT component subtype (https://help.sap.com/docs/leanix/ea/application-modeling-guidelines) (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from sap-leanix (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "arch-decision-register", + "area": "architecture", + "name": "Record architecture decisions with a status and review flow, and link each decision to the applications it affects.", + "origin": "changelog", + "originUrl": "https://updates.leanix.net/announcements/classify-architecture-decisions-with-dropdown-fields", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "the only decisions are contract approval and renewal decisions delegated to decidiq (catalogContract.decisions, lib/Settings/softwarecatalogus_register.json, and lib/Service/ContractApprovalService.php); no architecture decision record", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "sap-leanix": "yes", + "evidence": { + "sap-leanix": "Announcement of 2026-07-13: admins 'add single-select and multi-select dropdown fields to architecture decision templates'; https://help.sap.com/docs/leanix/ea/architecture-decisions: 'Document decisions about enterprise architecture in a structured, template-driven format ... Track decisions through a review process with defined statuses', shown on linked fact sheets (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from sap-leanix (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "ins-natural-language-query", + "area": "insight", + "name": "Ask a question about the landscape in plain language inside the tool and get an answer that cites the entries it used.", + "origin": "changelog", + "originUrl": "https://updates.leanix.net/announcements/answer-your-questions-in-seconds-with-the-enterprise-architecture-assistant", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no assistant in stackiq lib/ or src/ (see share-ai-assistant, where only OpenRegister's generic MCP endpoint exists outside the app)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "sap-leanix": "yes", + "evidence": { + "sap-leanix": "Announcement of 2026-06-23: 'Ask a question in plain language, and the assistant provides a sourced answer from your workspace ... Every answer is attributed to its source'. A premium AI feature needing AI units (read 2026-09-26)", + "bluedolphin": "Product news entry of 2026-09-01 'Communicate in natural language to find business information in BlueDolphin'; https://help.bluedolphin.io/en/articles/12528662-ai-capabilities-of-bluedolphin: 'AI Navigator answers questions asked in plain language ... Answers are grounded in your BlueDolphin repository and include direct links to relevant content' (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from sap-leanix (changelog) on 2026-09-26. Also mined from bluedolphin (changelog, https://bluedolphin.io/product-news/).", + "bluedolphin": "yes", + "vng-softwarecatalogus": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "comp-ai-act-classification", + "area": "compliance", + "name": "Classify the AI systems in the landscape by EU AI Act risk category and keep the evidence the act requires.", + "origin": "roadmap", + "originUrl": "https://roadmap.leanix.net/c/812-meta-model-eu-ai-act-extension", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no AI system or AI Act risk property on module or any other schema in lib/Settings/softwarecatalogus_register.json", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "sap-leanix": "partial", + "evidence": { + "sap-leanix": "Roadmap card 'Meta model: EU AI Act extension' is In progress (read from the portal data on 2026-09-26); today the legacy AI agent extension already has an 'AI Risk ... according to the EU AI Act' single select (https://help.sap.com/docs/leanix/ea/ai-agent-extension-to-meta-model), so a basic risk field exists but the full extension is not shipped (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from sap-leanix (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "life-version-tolerance", + "area": "lifecycle", + "name": "Set how many releases behind the latest version a technology may run, and flag the components that fall outside that window.", + "origin": "roadmap", + "originUrl": "https://roadmap.leanix.net/c/830-ea-assistant-technology-successor-planning", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "the end-of-life feed only stamps support end dates on module versions (lib/Service/EolSyncService.php:145, EolMatcherService); no rule for how many releases behind a version may run", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "sap-leanix": "no", + "evidence": { + "sap-leanix": "Roadmap card 'EA Assistant: Technology Successor Planning' is On roadmap; https://updates.leanix.net/announcements/work-with-complete-technology-version-coverage-without-raising-manual-requests (2026-09-17): 'version concurrency management, which we plan to implement in Q4. You will be able to define version tolerance windows' (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from sap-leanix (roadmap) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "arch-diagram-version-compare", + "area": "architecture", + "name": "Compare two saved versions of an architecture diagram and see what was added, removed or changed.", + "origin": "changelog", + "originUrl": "https://updates.leanix.net/announcements/compare-the-content-of-different-diagram-versions", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "stackiq renders no architecture view (see arch-gemma-views), so there is nothing to compare; ArchiMate files are imported and exported whole", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "sap-leanix": "yes", + "evidence": { + "sap-leanix": "Announcement of 2025-09-03: 'Selecting Compare Changes ... on a prior diagram version shows color-coded highlighting (green for additions, red for removals, yellow for modifications), a side-by-side view of differences, and an additional text-based summary' (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from sap-leanix (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "bluedolphin": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "share-lifecycle-conditional-sync", + "area": "sharing", + "name": "Send entries to connected outside systems only once they reach a chosen lifecycle state.", + "origin": "changelog", + "originUrl": "https://bluedolphin.io/blog/november-2025-product-updates-effortless-enterprise-architecture-management/", + "stackiq": "unknown", + "built": { + "state": "none", + "evidence": "stackiq has no sync code of its own; outgoing events go through OpenRegister flows authored on the Flows page (src/manifest.json:1057, see share-webhooks), and whether a flow can gate on a lifecycle status was not traced", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "openregister", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "bluedolphin": "yes", + "evidence": { + "bluedolphin": "November 2025 update (2025-11-13): 'Conditional Syncing for Integrations and Webhooks' lets teams 'control exactly what data syncs to third-party systems based on lifecycle state' (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from bluedolphin (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "ins-usage-analytics", + "area": "insight", + "name": "See which views and pages of the catalogue are actually used, and which guest users can reach them.", + "origin": "changelog", + "originUrl": "https://bluedolphin.io/blog/february-2026-bluedolphin-updates-more-visibility-better-governance-smarter-insights/", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no page view or usage tracking in lib/ or src/ (grep analytics, pageview)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "bluedolphin": "yes", + "evidence": { + "bluedolphin": "February 2026 update (2026-02-10): new reports show 'which guest users have access to BlueDolphin' and 'which views are being used across the platform'; https://help.bluedolphin.io/en/articles/13868249-usage-insights (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from bluedolphin (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "land-move-between-workspaces", + "area": "landscape", + "name": "Move one or many entries to another workspace or section without recreating them.", + "origin": "changelog", + "originUrl": "https://bluedolphin.io/blog/june-2026-bluedolphin-updates/", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "entries belong to an organisation through OpenRegister multitenancy (see org-data-segregation); no stackiq page or action moves an entry to another organisation or register", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "bluedolphin": "yes", + "evidence": { + "bluedolphin": "June 2026 update (2026-06-11): 'You can move one or multiple objects to another workspace directly from the Repository without leaving your current view', skipping objects already in the target (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from bluedolphin (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "arch-process-step-fields", + "area": "architecture", + "name": "Record structured fields on individual process steps, such as risk level or a compliance check.", + "origin": "changelog", + "originUrl": "https://bluedolphin.io/blog/july-2026-bluedolphin-updates/", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "stackiq models no processes (see arch-process-mapping)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "bluedolphin": "yes", + "evidence": { + "bluedolphin": "July 2026 update (2026-07-09): customers can 'define questionnaires directly on BPMN elements such as tasks and events'; https://help.bluedolphin.io/en/articles/15874771-questionnaires-for-bpmn-elements: 'centralize documentation like risk levels, compliance checks, and technical specifications' (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from bluedolphin (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "glpi": "unknown", + "topdesk": "unknown" + }, + { + "id": "arch-view-tags", + "area": "architecture", + "name": "Tag saved diagrams and views and filter the view list by tag, owner or status to find them again.", + "origin": "changelog", + "originUrl": "https://help.bluedolphin.io/en/articles/16096602-discover-and-manage-views-in-the-views-list", + "stackiq": "no", + "built": { + "state": "none", + "evidence": "no page lists or tags views (src/store/modules/view.js defines a view store nothing imports, see arch-gemma-views)", + "owner": "ConductionNL/stackiq" + }, + "reachedOn": "nothing reaches it", + "provider": "stackiq", + "providerHow": "read-from-code", + "featureConfidence": "medium", + "bluedolphin": "yes", + "evidence": { + "bluedolphin": "Product news entry of 2026-09-08 'Bring structure to your Views list with tags' (https://bluedolphin.io/product-news/); the linked article lists view filters 'Owner Contributors Tags Favorited Private Project Status Type' (read 2026-09-26)", + "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + }, + "note": "Mined from bluedolphin (changelog) on 2026-09-26.", + "vng-softwarecatalogus": "unknown", + "sap-leanix": "unknown", + "glpi": "unknown", + "topdesk": "unknown" } ], "pending": [ @@ -5104,7 +5624,7 @@ "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: municipality adds the supplier's package and version to its own landscape (\"om het pakket toe te voegen aan je omgeving\") (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E1 \"Leveranciers onderhouden de gegevens van hun producten ... Gemeenten en Samenwerkingen onderhouden de gegevens van het eigen applicatieportfolio\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/meta-model: 'An organization uses an application' as a relation between organization and application fact sheets; https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines: 'Organizations are intended to address who is using certain applications' (read 2026-09-26). Reached on: Application fact sheet > Organizations relation.", - "bluedolphin": "docs, intelligence competitor_features#48965 'Application Portfolio Management' (2026-07-23): APM integrated with the overall EA repository.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967550-working-with-object-relationships: relationships between objects, such as an actor or business unit using an application, carry a type and lifecycle state; https://help.bluedolphin.io/en/articles/11967604-manage-relationship-questionnaires adds details to a relationship. No usage record separate from the product is documented as such (read 2026-09-26). Reached on: Relationships between actor and application objects.", "stackiq": "register.json:2654 usage schema (consumer, module, moduleVersion, status); no manifest page has schema usage (src/manifest.json pages list); src/views/LifecycleRoadmapView.vue:339 and src/views/KwetsbaarhedenView.vue:316 only READ usage; lib/Controller/AangebodenGebruikController.php:654 setGebruikSelfToActiveOrg (PUT /api/aangeboden-gebruik/{id}/set-self) has no caller in src/", "topdesk": "unknown: one organisation per environment; a separate usage record is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "glpi": "source read at 11.0.9: use is recorded as installations separate from the software product, src/Item_SoftwareVersion.php:39 (install/mysql/glpi-empty.sql:1064 glpi_items_softwareversions) per device, and licence assignments per item or user; there is no usage record of a module by an organisation as such. Reached on: Assets > Software > Installations tab." @@ -5118,7 +5638,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "no", @@ -5135,6 +5655,7 @@ "stackiq": "lib/Repair/* only migrate stackiq's own old slugs/keys (e.g. lib/Repair/MigrateRegisterSlug.php, RenameDutchCatalogValues.php); lib/Service/ArchiMateImportService.php imports GEMMA/AMEF ArchiMate models, not catalogue registrations; src/modals/object/MigrationObject.vue is only mounted for modal 'migrationOrganisatie' (src/modals/Modals.vue:10), which nothing sets", "topdesk": "unknown: no import from the VNG Softwarecatalogus is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: this is the previous catalogue itself; no import of an earlier registration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967629-import-and-export-options-with-bluedolphin: import from 'Access databases, Excel files, and CSV files'; https://help.bluedolphin.io/en/articles/11967637-import-ameff-files for ArchiMate models. No importer for a specific previous catalogue (read 2026-09-26). Reached on: Admin > Sources; Admin > System > Import.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/importing-fact-sheet-data-through-excel-file and https://help.sap.com/docs/leanix/ea/integration-api: bulk import from spreadsheets and a JSON based Integration API; no importer for a specific previous catalogue is documented (read 2026-09-26). Reached on: Inventory > Import; Integration API.", "glpi": "source read at 11.0.9: data from earlier GLPI versions is carried over by src/Update.php:172 doUpdates with the chain in install/migrations/ (update_0.85.x_to_0.90.0.php up to the 11.0 steps); data from another catalogue needs the separate datainjection plugin (pluginsGLPI/datainjection tag 2.15.11, inc/backendcsv.class.php). Reached on: web installer update; plugin Data injection." }, @@ -5147,7 +5668,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "partial", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "partial", "stackiq": "partial", @@ -5165,7 +5686,7 @@ "evidence": { "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Selecteer vervolgens de betreffende pakketversie. De richting van het berichtenverkeer ... Selecteer vervolgens de betreffende standaard en versie\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen > toevoegen.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/interface-modeling-guidelines: 'Interfaces should have one provider application and could have multiple consumer applications', data flow direction incl. 'Bi-Directional', and 'type of transfer' (read 2026-09-26). Reached on: Inventory > Interface fact sheet.", - "bluedolphin": "docs, intelligence competitor_features#48964 'ArchiMate & BPMN modeling' (2026-07-23): Standards-based enterprise architecture and process modeling. | Rated partial because ArchiMate flow relations.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967604-manage-relationship-questionnaires: a relationship carries 'a source and a target object, a type of the relationship, a lifecycle state, and a free text label', and relationship questionnaires add fields such as the standard used (read 2026-09-26). Reached on: Objects > Relationships tab; relationship questionnaire.", "stackiq": "register.json:3563 connection schema: moduleA (:3689), moduleB, dataExchangeDirection AtoB/BtoA/bi-directional (:3676), standardVersions (:3735), type; no manifest page has schema connection; src/modals/Modals.vue:39 accepts 'connection' but nothing opens it", "topdesk": "https://docs.topdesk.com/en/hierarchy-of-relationships.html: \"When assets are linked with a link type , one of the assets often supplies a certain feature to another asset. The supplying asset therefore is the parent asset\" (read 2026-09-26). Direction via parent and child; no standard per relation. Reached on: Asset card > Relationships widget.", "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1247 glpi_impactrelations stores a directed link from a source item to an impacted item with a name, added via src/Impact.php:1161 'Add relation'; there is no field for the standard or protocol used. Reached on: Appliance > Impact analysis tab, Add relation." @@ -5198,6 +5719,7 @@ "stackiq": "register.json:3020 usage.koppelingen (connections used within this usage); no page for usage or connection; lib/Controller/AangebodenGebruikController.php:208 /api/koppelingen-gebruik/{uuid} returns koppelingen+gebruiken, no src caller", "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Opvoeren%20koppeling%20iJw%20en%20iWmo: \"Geef bij status in productie of gepland aan\"; connections are registered in the organisation's own landscape (read 2026-09-26). Reached on: Mijn softwarecatalogus > Koppelingen.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; recording that an organisation runs a connection, separate from its existence, is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; interfaces belong to one workspace, and a usage of a connection separate from its existence is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: an impact relation (install/mysql/glpi-empty.sql:1247) is a single fact in one instance; there is no separate usage record saying the organisation runs it, and grep -n 'usage' src/ImpactRelation.php returns nothing." }, @@ -5229,6 +5751,7 @@ "stackiq": "register.json:2718 usage.participants; lib/Controller/AangebodenGebruikController.php:578 GET /api/aangeboden-gebruik/deelnemers (usages where the active org is a participant) and :208 /api/koppelingen-gebruik/{uuid}; no caller in src/", "topdesk": "unknown: usage of relations across organisations is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: A10: \"Een Samenwerking geeft aan welke gemeenten gebruik maken van een betreffende koppeling. Die gemeentenamen worden getoond\" (read 2026-09-26). Reached on: Alle koppelingen.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; each tenant is one customer's repository, and connections run jointly with other organisations are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; each workspace is one customer's own, and connections run jointly with other organisations are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: relations live inside one instance (install/mysql/glpi-empty.sql:1247 glpi_impactrelations) and entities are subdivisions of one organisation (src/Entity.php:58); no cross organisation sharing of connections exists (grep -rli 'federat' src/ returns nothing)." }, @@ -5260,6 +5783,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: \"Referentiecomponenten aangegeven door leverancier ... Toegevoegde referentiecomponenten\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > toevoegen.", "stackiq": "lib/Settings/softwarecatalogus_register.json module.referenceComponents (array of element $ref, hideOnForm:true) and usage.usedForReferenceComponents; src/manifest.json ModuleDetail md-data include list omits referenceComponents; src/services/facets.js:31 + lib/Service/FacetService.php:659 read the mapping for the referenceComponent facet on /modules", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for GEMMA, no hits; a third party README (https://github.com/Gemeente-Delft/Gemeentelijk-Gegevensmodel/blob/master/README.md) says municipalities load the GGM data model into BlueDolphin via AMEFF, but GEMMA reference components as a mapping target are not documented by the vendor (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, VNG and municipal, no hits; the reference catalog offers business capability blueprints by industry (https://help.sap.com/docs/leanix/ea/reference-catalog) but GEMMA reference components are not mentioned (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'gemma\\|reference component' over src/ locales/glpi.pot returns nothing; the only classification of an appliance is its type dropdown (install/mysql/glpi-empty.sql:8941 appliancetypes_id)." }, @@ -5291,6 +5815,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Hoe%20print%20ik%20een%20kaart%3F: \"de pakketten die getoond worden in het pakketoverzicht te plotten op een GEMMA architectuurkaart ... [Toon kaart]\" (read 2026-09-26). Reached on: Mijn softwarecatalogus > Pakketten > Toon kaart.", "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/{viewId}; lib/Service/ViewService.php:415 enrichViewNodes adds modules/usage/deelnames per node; lib/Service/ArchiMateExportService.php:2734 copyAndEnrichViews nests the org's applications inside copies of GEMMA views in the org ArchiMate export", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for GEMMA, no hits; GEMMA views with own applications drawn in are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -rli 'gemma\\|archimate' over src/ templates/ locales/glpi.pot returns nothing; the only diagram is the impact graph (src/Impact.php:252 displayGraphView)." }, @@ -5322,6 +5847,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/30355: cooperation packages: \"kies bij Organisaties welke gemeenten ... de betreffende applicatie gebruiken ... Het pakket verschijnt dan ook alleen op de lijst en kaart van de samenwerking en niet bij de gemeenten\" (read 2026-09-26). Drawing shared apart from own is not described. Reached on: Samenwerking > Pakketten > Organisaties.", "stackiq": "lib/Service/ViewService.php:1187 getDeelnamesGebruikData + :924 tags shared usage with _type='deelnames' and _sourceOrganization; lib/Service/ArchiMateExportService.php:3005 org export gives every nested application the same green fillColor, deelnames only get their own folder (:3086)", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for GEMMA, no hits (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, no hits; no partner overlay on a reference view is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no GEMMA views (grep -rli 'gemma' src/ returns nothing) and no partner sharing; the impact graph (src/Impact.php:1559 makeDataForCytoscape) draws one instance's items only." }, @@ -5353,6 +5879,7 @@ "stackiq": "appinfo/routes.php:185-187 GET /api/views, /api/views/docs, /api/views/{viewId} -> lib/Controller/ViewController.php:82,218 (@NoAdminRequired) -> lib/Service/ViewService.php:108,166 read views from the AMEF register; GEMMA elements are element objects in the AMEF register, readable through the OpenRegister objects API", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no API over GEMMA in the catalogue is documented; GEMMA overviews are copied from GEMMA Online tables; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for GEMMA, no hits; the public API serves the tenant's own objects (https://help.bluedolphin.io/en/articles/11967730-about-the-bluedolphin-api) (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea for GEMMA, no hits (read 2026-09-26)", "glpi": "source read at 11.0.9: the v2 API controllers (src/Glpi/Api/HL/Controller/, for example AssetController.php:149 /Assets) expose GLPI itemtypes only; grep -rli 'gemma' src/ returns nothing." }, @@ -5384,6 +5911,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier: \"via de optie Voeg extra standaarden toe de gewenste standaard te selecteren ... Ondersteuning(gepland) en Compliancy\" (read 2026-09-26). Reached on: Supplier login > productversie > standaarden.", "stackiq": "lib/Settings/softwarecatalogus_register.json compliancy.standardVersion ($ref element, queryParams gemmaType=standaardversie) + compliancy.module + compliancy.standardGemma (string); src/manifest.json Komplianties /komplianties index on the voorzieningen register; ModuleDetail md-compliance object-list has allowCreate:false; module.standardVersions is hideOnForm", "topdesk": "unknown: GEMMA and standards are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; declaring support for a version of a standard per application is not documented beyond generic questionnaire fields (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; technology standards apply to tech stack items (https://help.sap.com/docs/leanix/ea/technology-standards-management-capabilities), declaring support for a version of an interoperability standard per application is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no standards model (grep -rli 'standaard' src/ locales/glpi.pot returns nothing); software versions (install/mysql/glpi-empty.sql:6900) carry no supported standard." }, @@ -5415,6 +5943,7 @@ "stackiq": "lib/Controller/AanbodController.php:200 acceptAanbod and :303 denyAanbod, lib/Service/AanbodService.php:289 checks the active organisation is aanbieder or afnemer then re-owns the object; routes appinfo/routes.php PUT /api/aanbod/{uuid}/accept, DELETE /api/aanbod/{uuid}/deny; also /api/aangeboden-gebruik/{id}/set-self and /deny", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: suppliers see \"Mijn gemeenten\" (who registered their packages) but accepting or declining a usage is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; suppliers have no role in a customer tenant, so accepting a claimed usage is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; suppliers have no role in a customer workspace, so accepting a claimed usage is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers have no login or role (install/mysql/glpi-empty.sql:7067 glpi_suppliers is a plain record; profiles in src/Profile.php:55 are for users), so no supplier can accept or decline a claimed usage." }, @@ -5446,6 +5975,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/13683: \"Alle gemeenten helpt bijvoorbeeld in het verkrijgen van inzicht welke gemeenten dezelfde pakketten gebruiken ... Ook met betrekking tot een bepaald beleidsthema, referentiecomponent of standaard\" (read 2026-09-26). Reached on: Inlogmenu > Alle gemeenten / Alle pakketoverzichten.", "stackiq": "lib/Controller/ViewController.php (routes GET /api/views, /api/views/{viewId}) enriches GEMMA views with shared usage (deelnames); src/store/modules/view.js:89 calls it but no component imports that store", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; comparison with other customers' landscapes is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; comparison with other customers' landscapes is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: no reference components (grep -rli 'reference component' src/ returns nothing) and no data from comparable organisations, since each instance is standalone (src/Entity.php:58 entities are internal)." }, @@ -5458,7 +5988,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", @@ -5477,6 +6007,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Marktscans: \"kunnen ingelogde gemeenten of samenwerkingen zien bij welke collega-gemeenten betreffende pakketversie in het applicatielandschap staat (klik daarvoor op het getal boven Ingevuld door)\" (read 2026-09-26). Reached on: Package page > Ingevuld door.", "stackiq": "register :2656 usage (consumer, module); usage read rule lets aanbod-beheerder read usages where provider = own organisation (:3137); ModuleDetail md-related widget src/manifest.json:491; GET /api/koppelingen-gebruik/{uuid} and /api/gebruik in lib/Controller/AangebodenGebruikController.php, lib/Controller/GebruikController.php", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967550-working-with-object-relationships: an application's Relationships tab shows related actors and business units, inside one customer's tenant; which outside organisations use a product is not documented (read 2026-09-26). Reached on: Application object > Relationships tab.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/organization-modeling-guidelines: 'Organizations are intended to address who is using certain applications', within one customer's own business units, regions and legal entities, not across outside organisations (read 2026-09-26). Reached on: Application fact sheet > Organizations relation.", "glpi": "source read at 11.0.9: within one instance the version Summary tab shows installations per entity, src/Item_SoftwareVersion.php:850 showForVersionByEntity, and the installation list carries the entity column (src/Item_SoftwareVersion.php:484); organisations outside the instance are not visible. Reached on: Assets > Software > version > Summary tab." }, @@ -5508,6 +6039,7 @@ "stackiq": "lib/Service/ReviewService.php:232 forces pending; lib/Controller/ModerationController.php:81 AuthorizedAdminSetting; src/views/settings/StackiqSettings.vue:98 ModerationQueue type=software-review via src/utils/adminApi.js; lib/Settings/register.d/catalog-ratings.json public read only matches status approved but every catalogue group reads all reviews and may create them", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no reviews are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; there are no reviews, so no review moderation is documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; there are no reviews, so no review moderation is documented (read 2026-09-26)", "glpi": "source read at 11.0.9: there are no product reviews (see mkt-reviews); the only moderation is knowledge base publication by rights on src/KnowbaseItem.php:57, unrelated to reviews." }, @@ -5520,7 +6052,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "unknown", "stackiq": "partial", @@ -5538,6 +6070,7 @@ "stackiq": "register usage authorization (:3137) reads scoped to _organisation or consumer; aanbod-beheerder also reads usages where provider = own organisation; connection read (:3855) public when published and by provider; openspec/specs/vendor-visibility-rbac", "topdesk": "unknown: TOPdesk is a single-organisation tool; cross-organisation market functions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E2: \"Leveranciers kunnen alleen hun eigen applicatieversies die in gebruik zijn bij gemeenten en samenwerkingen zien ... overigens ziet de leverancier geen status-informatie. Die is vertrouwelijk\" (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967624-manage-roles-and-permissions: 'BlueDolphin uses Role-Based Access Control (RBAC)' within the customer's own tenant; users are added only by admins (https://help.bluedolphin.io/en/articles/11967616-user-management) (read 2026-09-26). Reached on: Admin > Users and Roles.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/manage-workspace-access: 'If a workspace has activated Invitation Only: Visible if the user is invited to this workspace and has a role'; the workspace is 'a self-contained, customer-specific environment' (https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf) (read 2026-09-26). Reached on: Administration > Workspace access.", "glpi": "source read at 11.0.9: suppliers are records without accounts (install/mysql/glpi-empty.sql:7067 glpi_suppliers) and all data is visible only through the profiles and entities assigned to users (install/mysql/glpi-empty.sql:5917 glpi_profiles_users), so a supplier sees nothing unless given an account. Reached on: Administration > Profiles." }, @@ -5550,7 +6083,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "no", - "bluedolphin": "unknown", + "bluedolphin": "no", "glpi": "yes", "topdesk": "no", "stackiq": "partial", @@ -5569,7 +6102,8 @@ "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: usage metric 'Application' counted for the subscription, add on products 'subject to additional subscription fees'; https://help.sap.com/docs/leanix/ea/application-modeling-guidelines: 'Application fact sheets are counted for pricing calculations' (read 2026-09-26)", "glpi": "source read at 11.0.9: LICENSE:1 GNU General Public License version 3, so any municipality or supplier can run it without licence fees; there is no free hosted public service, the paid cloud is GLPI Network by Teclib. Reached on: self hosted install.", "stackiq": "LICENSE (EUPL-1.2) and appinfo/info.xml: the app is free open source; catalogService and organization carry public read rules for published entries; module's public read also admits every object with registeredBy Supplier, a rule with no publication-date or status condition (lib/Settings/softwarecatalogus_register.json:7322-7327, corrected 2026-09-26); public intake POST /api/intake/register", - "topdesk": "https://www.topdesk.com/en/pricing/: \"Essential ... £51 Per agent/month\", \"Engaged ... £72\", \"Excellent ... £101\" (read 2026-09-26)" + "topdesk": "https://www.topdesk.com/en/pricing/: \"Essential ... £51 Per agent/month\", \"Engaged ... £72\", \"Excellent ... £101\" (read 2026-09-26)", + "bluedolphin": "https://bluedolphin.io/pricing/: plans 'Tactical', 'Strategic' and 'Enterprise', with 'Contact sales for pricing' and a free trial only on the Strategic plan, after which 'your workspace continues with limited access unless upgraded' (read 2026-09-26)" }, "pendingQuestion": "Is a hosted, free-of-charge stackiq instance offered to municipalities and suppliers (the competitor offer is a public service, not software)?" }, @@ -5600,6 +6134,7 @@ "sap-leanix": "https://help.sap.com/docs/leanix/ea/obsolescence-risk-management-monitor-mitigation: 'You can use automation features to initiate an end-of-life process for applications and alert the responsible individuals well before the end-of-life of an IT component' (read 2026-09-26). Reached on: Administration > Automations (end of life process).", "stackiq": "src/views/LifecycleRoadmapView.vue:73-86 EOL passed/approaching/withdrawn badges with EOL_WINDOW_DAYS=180 (:143); lib/Settings/softwarecatalogus_register.json moduleVersion x-openregister-notifications eol-approaching (scheduled, dateEndSupport withinNext P180D, recipients software-catalog-admins + object-acl manage) is a declaration only; no notification code in lib (no INotificationManager use)", "topdesk": "https://docs.topdesk.com/en/events-that-trigger-actions.html: \"…when a card date will be reached within a particular period of time\" (read 2026-09-26). Works on any date field, e.g. a self-defined end-of-support date; no built-in end-of-support. Reached on: Action Management > events.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; end of life dates appear only in an import example (https://help.bluedolphin.io/en/articles/11967633-datacollector-select-tricks '[End-of-Life Date]'), warnings before end of support are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: alerts exist for dates GLPI stores, licence expiry (src/NotificationTargetSoftwareLicense.php:46 'Alarms on expired licenses'), contract end and notice (src/NotificationTargetContract.php:47) and warranty expiry (src/Infocom.php:651 cronInfocom); no end of support date exists on an application or version (install/mysql/glpi-empty.sql:6900 glpi_softwareversions). Reached on: Setup > Notifications; Setup > Automatic actions." }, "pendingQuestion": "Does the installed OpenRegister dispatch the scheduled x-openregister-notifications rule 'eol-approaching' on moduleVersion, and to whom?" @@ -5631,6 +6166,7 @@ "stackiq": "lib/BackgroundJob/EolSyncJob.php (registered appinfo/info.xml:101) + appinfo/routes.php:292-295 /api/eol-sync/* -> lib/Service/EolSyncService.php:145 run() reads eol_cycle objects via OpenRegister ObjectService (:328), stamps dateEndSupport on module versions via EolMatcherService; enabled defaults to false (lib/Service/SettingsService.php:7211); lib/Settings/connections.json eol-feed is a switch, off until enabled; the cycles are fetched by integriq's endoflife-date source", "topdesk": "unknown: no end-of-life feed is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: end-of-support comes from supplier input; no public feed is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; filling end of support dates from a public feed is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -i 'end_of_support\\|endoflife' over install/mysql/glpi-empty.sql and src/ returns nothing; no external lifecycle feed is read (the only outbound catalogues are the plugin marketplace, src/Glpi/Marketplace/). The marketplace client, the only outbound catalogue, is src/Glpi/Marketplace/Controller.php:64." }, "pendingQuestion": "Is integriq's endoflife-date source (eol_product/eol_cycle register) provisioned on a default install, so that switching the sync on actually finds cycles?" @@ -5661,6 +6197,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json usage.plannedReplacement ($ref module) + plannedReplacementDate; read by src/views/LifecycleRoadmapView.vue:400; no usage page in src/manifest.json and navigationStore.setModal('usage') is never called (src/modals/Modals.vue:38 lists usage but nothing opens it)", "topdesk": "unknown: no replacement link is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"geplande harmonisaties ... status gepland met bijbehorende datum ... de uit te faseren applicaties van die status worden voorzien inclusief datum\" (read 2026-09-26). No explicit replaces link. Reached on: Mijn softwarecatalogus > Pakketten > Planning.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; future state objects exist (https://help.bluedolphin.io/en/articles/11967531-object-lifecycle-state), but a replaced by relation between applications is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/advanced-filter-options: 'analyze your target architecture landscape, provided that you have also modeled successors effectively'; roadmap report option 'showSuccessors' (https://help.sap.com/docs/leanix/ea/report-url-parameter-reference) (read 2026-09-26). Reached on: Fact sheet > Successor relation; Roadmap Report.", "glpi": "source read at 11.0.9: a software can be flagged as an 'Upgrade from' another software, templates/pages/assets/software.html.twig:46 to :50 (is_update with softwares_id, install/mysql/glpi-empty.sql:6864 and :6865); this records succession after the fact, with no planned replacement link for appliances. Reached on: Assets > Software form, Upgrade from." }, @@ -5673,7 +6210,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "unknown", "stackiq": "partial", @@ -5691,6 +6228,7 @@ "stackiq": "lib/Settings/softwarecatalogus_register.json usage.timeClassification enum Tolerate/Invest/Migrate/Eliminate + timeRationale + timeReviewDate; read by lib/Service/PortfolioReportService.php and rendered in src/views/organisaties/PortfolioReport.vue:112 quadrant chart; src/modals/object/ObjectModal.vue:178 has the enum select but is never opened for usage", "topdesk": "unknown: no TIME classification is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no TIME classification is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://bluedolphin.io/application-portfolio-management-application-rationalization/: 'TIME powered application lifecycle management' and 'TIME analysis across your entire application portfolio' (read 2026-09-26). Reached on: APM, TIME analysis.", "glpi": "source read at 11.0.9: grep -rli 'tolerate\\|eliminate' over src/ locales/glpi.pot returns nothing; a TIME class can only be held in a repurposed single choice dropdown such as the appliance status (install/mysql/glpi-empty.sql:8950 states_id, values from src/State.php:45) or type (install/mysql/glpi-empty.sql:8941). Reached on: Management > Appliances, Status or Type field." }, "pendingQuestion": "Is the external VNG frontend or OpenRegister's generic object editor the intended place to set timeClassification, and does it count here?" @@ -5702,7 +6240,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -5722,6 +6260,7 @@ "glpi": "source read at 11.0.9: install/mysql/glpi-empty.sql:1483 glpi_contracts with name, num (contract number), contracttypes_id, begin_date, duration, notice and renewal, and costs in install/mysql/glpi-empty.sql:1458 glpi_contractcosts. Reached on: Management > Contracts. Driven on the lab at 11.0.9 (2026-09-26): created \"Lab contract\" with number C-001, start date, 12 month duration and 1 month notice.", "topdesk": "https://docs.topdesk.com/en/creating-a-contract.html: \"Contract Number (mandatory) ... Type ... Start Date (mandatory) ... End Date (mandatory) ... Costs (Services)\" (read 2026-09-26). Reached on: Modules > Contract Management and SLM > New.", "stackiq": "src/manifest.json:527 Contracten type:index over catalogContract (contractNumber, contractType, startDate, endDate, cost, status); register :3252 catalogContract requires service AND usage; no manifest page has schema usage (grep src/manifest.json)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967596-archimate-annotation-translation-en-nl lists the object definition 'Contract', which takes admin defined questionnaire fields (https://help.bluedolphin.io/en/articles/11967603-manage-object-questionnaires); an import example carries contract start and end dates (https://help.bluedolphin.io/en/articles/11967633-datacollector-select-tricks) (read 2026-09-26). Reached on: Objects > Contract object.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model: contract fact sheet with 'Contract Number', 'Contract Pricing Type', lifecycle phases for start, notice and end, and licensing, maintenance and support costs, linked to applications and providers (read 2026-09-26). Reached on: Inventory > Contract fact sheet (contract extension)." }, "pendingQuestion": "Does the installed OpenRegister accept a catalogContract without the required usage (schema hardValidation false), and can the related-object picker create a usage inline?" @@ -5754,6 +6293,7 @@ "sap-leanix": "https://help.sap.com/docs/leanix/ea/step-2-set-up-contract-lifecycle-automations: 'Prevent missed renewals through proactive notification workflows ... Enable timely decisions with escalation alerts before notice periods' (read 2026-09-26). Reached on: Administration > Automations (contract lifecycle).", "stackiq": "lib/Settings/softwarecatalogus_register.json:3255 x-openregister-notifications contract-expiry filters status equals 'Actief' but the status enum is Active/Expired/In negotiation (:3428), and the subject uses {{contractNummer}}/{{eindDatum}} while fields are contractNumber/endDate; Contracten quick filter 'Expiring / expired' filters status Expired only (src/manifest.json:527)", "topdesk": "https://docs.topdesk.com/en/managing-your-service-and-supplier-contracts.html: \"To prevent the accidental extension of unwanted contracts, TOPdesk warns you when contracts are about to expire\" (read 2026-09-26); https://docs.topdesk.com/en/creating-a-contract.html: \"Reminder date Date on which an operator should be reminded about the contract, e.g. ahead of expiry\" (read 2026-09-26). Reached on: Contract card > Reminder date.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; notifications cover mentions and project deliverables (https://help.bluedolphin.io/en/articles/11967481-user-profile), contract expiry warnings are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: src/Contract.php:1092 cronContract computes end and notice dates and sends the events of src/NotificationTargetContract.php:47 (end of contract, notice, periodicity, periodicity notice); install/mysql/glpi-empty.sql:1508 glpi_contracts.alert sets which alerts apply. Reached on: Management > Contracts, Email alarms field; Setup > Notifications." }, "pendingQuestion": "Does the installed OpenRegister dispatch scheduled x-openregister-notifications, and does it compare the filter value case/locale-insensitively (it cannot map 'Actief' to 'Active')?" @@ -5785,6 +6325,7 @@ "stackiq": "lib/Service/ContractApprovalService.php:254 submitForApproval dispatches OCA\\Decidiq\\Event\\DecisionRequestedEvent (fail-closed), :412 projectOutcome sets status Active only on approved; src/manifest.json:579 ContractApprovalPanel on ContractDetail; but register :3428 status enum incl. Active is an editable form field and approvalState (register.d/contracts-to-decidesk.json) is not readOnly; the declared x-openregister-lifecycle uses Dutch states 'In onderhandeling'/'Actief' that match no enum value", "topdesk": "https://docs.topdesk.com/en/registering-and-validating-contracts.html: \"Create a new Preliminary Contract card ... Validate the contract. You have created an active contract\" (read 2026-09-26). A validation step, no recorded approval decision. Reached on: Contract card > Validate Contract.", "vng-softwarecatalogus": "unknown: contracts are not described in the public docs; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; approval gating of a contract is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; contracts carry a renewal decision field and fact sheets a quality seal approval (https://help.sap.com/docs/leanix/ea/contract-extension-to-meta-model), but gating a contract's activation on a recorded approval is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: grep -n 'alidation' src/Contract.php returns nothing and no ContractValidation class exists; approvals exist only for ITIL objects (src/ChangeValidation.php:39), and the contract status is a free dropdown (install/mysql/glpi-empty.sql:1512 states_id)." }, @@ -5814,6 +6355,7 @@ "stackiq": "src/utils/vulnerabilityExposure.js:54 in-production join vulnerability.modules -> usage.module -> usage.consumer; count shown in the list (src/views/KwetsbaarhedenView.vue:111); per-organisation rows in VulnerabilityExposurePanel on KwetsbaarheidDetail tab (src/manifest.json:997), but a list row opens the edit modal, not the detail page (KwetsbaarhedenView.vue:417)", "topdesk": "unknown: vulnerabilities are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for vulnerability, no hits (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/searching-for-sbom-library-components-by-package-url: 'Vulnerability remediation tracking: Retrieve the business applications linked to a vulnerable component ... assess the blast radius of a pkg:maven/org.apache.logging.log4j/log4j-core vulnerability'. Only for self-built software with SBOMs (read 2026-09-26). Reached on: SBOM explorer and component search API (Technology Risk and Compliance).", "glpi": "source read at 11.0.9: no vulnerability data exists (grep -rli 'cve' src/ hits only src/Glpi/System/Requirement/PhpSupportedVersion.php:74), so exposure cannot be derived even though installations per entity are known (src/Item_SoftwareVersion.php:850)." }, @@ -5845,6 +6387,7 @@ "stackiq": "register.json:1622 x-openregister-notifications 'vulnerability-reported' on vulnerability, trigger created, channels nc-notification + email, recipients group software-catalog-admins and object-acl manage (a declaration only)", "topdesk": "unknown: vulnerabilities are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no vulnerability functions are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/ for vulnerability and CVE, no hits (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/api-updates-sbom-async-processing: asynchronous SBOM processing 'will allow us to add additional post-processing mechanisms in the future, such as vulnerability checks. Though there's no established timeline' (read 2026-09-26)", "glpi": "source read at 11.0.9: no vulnerability events among notification targets; software notifications are licence expiry only (src/NotificationTargetSoftwareLicense.php:46)." }, @@ -5876,6 +6419,7 @@ "stackiq": "lib/Controller/IntakeController.php:74 PublicPage + AnonRateLimit(5/h) on POST /api/intake/register; lib/Service/IntakeService.php:146 forces registrationStatus pending, publicationDate null; no caller in src/. Separately, organization authorization.create includes 'public' (register :2467)", "topdesk": "unknown: organisations signing themselves up is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-leverancier-aanmelden: \"Als leverancier kunt u zich aanmelden door de volgende gegevens te sturen naar softwarecatalogus@vng.nl\" (read 2026-09-26); https://www.softwarecatalogus.nl/hoe-kan-ik-me-als-gemeente-aanmelden: cooperations without an account \"vraag deze dan aan door een mail te sturen\" (read 2026-09-26). Sign-up by e-mail, no online form.", + "bluedolphin": "unknown: https://bluedolphin.io/pricing/ offers a free trial workspace on the Strategic plan, which is a customer tenant sign up; organisations signing themselves into a shared catalogue is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; workspaces are provisioned per customer (https://help.sap.com/docs/leanix/ea/sap-for-me-super-cloud-admin-for-workspace-provisioning), self sign up of organisations is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: suppliers are created by staff only (src/Supplier.php:75 sets is_active on add from the staff form) and there is no public sign up page among front/ pages (front/lostpassword.php and front/initpassword.php are the only anonymous account pages)." }, @@ -5907,6 +6451,7 @@ "stackiq": "lib/Controller/ContactpersonenController.php:393 convertToUser -> lib/Service/Stackiq/ContactPersonHandler.php:292 createUserAccount reads objectData['email'] (:299); automatic path lib/EventListener/StackiqEventListener.php -> lib/Service/ContactpersoonService.php:128 also reads contactData['email']; contactPerson schema (:1788) declares no email (identity moved to Nextcloud Contacts via contactsUid); UI: src/components/ContactpersonenList.vue:97 'Convert to User' inside OrganisatieCard", "topdesk": "https://docs.topdesk.com/en/step-2, operator-import-with-a-linked-person.html: \"To create operators with a person card linked via the Supporting Files import\" (read 2026-09-26); https://docs.topdesk.com/en/assigning-or-editing-self-service-portal-login-data.html: \"select the TOPdesk field Has access to Self-Service Portal and map it\" (read 2026-09-26). Reached on: Supporting Files imports.", "vng-softwarecatalogus": "unknown: no conversion of contact persons into accounts is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/gebruikersbeheer (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; users are added by admins or SCIM (https://help.bluedolphin.io/en/articles/11967616-user-management), turning a contact person into an account is not documented (read 2026-09-26)", "sap-leanix": "https://help.sap.com/docs/leanix/ea/users-overview: 'You can also invite contacts from the Subscriptions tab on a specific fact sheet'; roles come from the invitation or SSO, not automatically from the contact's role (read 2026-09-26). Reached on: Fact sheet > Subscriptions > Invite.", "glpi": "source read at 11.0.9: contacts (src/Contact.php:45) and users are separate itemtypes with no conversion action; user accounts come from manual creation, LDAP import (src/AuthLDAP.php:59) or authorisation rules (src/RuleRight.php:297 profile action)." }, @@ -5938,6 +6483,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/19703: \"Handleiding beheer gemeente-samenwerking ... Samenwerkingsverbanden die als doel hebben om de applicatielandschappen van de aangesloten gemeenten te harmoniseren\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/30355: cooperation selects the member municipalities per package (read 2026-09-26). Reached on: Samenwerking account > Pakketten.", "stackiq": "register organization.type 'Collaboration' + participants/deelnames (:2236); usage.participants (:2718); shared landscape endpoint GET /api/aangeboden-gebruik/deelnemers (lib/Controller/AangebodenGebruikController.php) has no caller in src/", "topdesk": "unknown: cooperations of organisations are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; cooperations of organisations sharing a landscape are not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; cooperations of separate organisations sharing a landscape are not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: entities form a tree (src/Entity.php:58 extends CommonTreeDropdown) and records flagged recursive are shared with all child entities (src/Appliance.php:325 is_recursive), so a parent entity can hold a landscape shared by several subordinate units; there is no cooperation of independent organisations. Reached on: Administration > Entities; Appliance Child entities field." }, @@ -5950,7 +6496,7 @@ "origin": "own-code", "vng-softwarecatalogus": "partial", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "partial", @@ -5969,6 +6515,7 @@ "stackiq": "register authorization.read rules with {match: {_organisation: $organisation}} on catalogContract (:3474), contactPerson (:1788), usage (:3137), connection (:3855); public reads only for published entries; lib/Controller/ContactpersonenController.php:293 org guard on the custom endpoint", "topdesk": "https://docs.topdesk.com/en/details-about-certain-permissions.html: \"To restrict access to specific data, link the operator to branch, operator, or category filters\" (read 2026-09-26). Reached on: Operator card > filters.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Alle gegevens ingevoerd door de gemeenten en samenwerkingen zijn alleen zichtbaar voor gemeentelijke raadplegers en beheerders\"; E2 \"Ingelogde gemeenten en samenwerkingsverbanden kunnen de applicatielandschappen en koppelingen van collega-gemeenten ... bekijken\" (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967491-business-units: business units 'organize content (objects and views)' and 'The selected business unit then acts as a filter for navigation'; role permissions apply per object definition (https://help.bluedolphin.io/en/articles/11967624-manage-roles-and-permissions) and views can be private. Per organisation record isolation is not documented (read 2026-09-26). Reached on: Business units; roles; private views.", "sap-leanix": "https://www.leanix.net/hubfs/Legal/Metrics-and-Feature-List-EAM-SAP-LeanIX-v3.1.pdf: 'Virtual workspaces to control users' read and edit permissions for fact sheets and their content in a federated organization'; https://help.sap.com/docs/leanix/ea/virtual-workspaces-configuration (read 2026-09-26). Reached on: Administration > Virtual Workspaces." }, "pendingQuestion": "Does the installed OpenRegister evaluate authorization.read match rules with $organisation on the generic object list and detail endpoints the stackiq pages use?" @@ -5999,6 +6546,7 @@ "stackiq": "lib/Service/Stackiq/ContactPersonHandler.php:646 first contact of an organisation gets the organisation-admin groups; lib/Service/Stackiq/HierarchyHandler.php:79 ensureOrganizationBeheerder and :130 setupManagerRelationships make later users report to the primary beheerder", "topdesk": "unknown: first-user administrator rules are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/17042: \"Vanuit de gemeente is minimaal één gebruiker aangewezen als beheerder. Deze gebruiker kan nieuwe accounts aanmaken voor collega's\" (read 2026-09-26). Reached on: Gebruikersbeheer.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; making an organisation's first user its administrator is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; admins invite and manage users (https://help.sap.com/docs/leanix/ea/managing-users), but making an organisation's first user its administrator is not documented (read 2026-09-26)", "glpi": "source read at 11.0.9: an administrator can delegate user management per entity with a profile holding user rights, and GLPI stops a delegate from granting a profile stronger than their own, src/Profile.php:744 currentUserHaveMoreRightThan and src/Profile.php:679 getUnderActiveProfileRestrictCriteria; nothing makes the first user of an organisation its administrator automatically. Reached on: Administration > Users > Authorizations tab." }, @@ -6011,7 +6559,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", "stackiq": "partial", @@ -6030,6 +6578,7 @@ "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/node/16564: E6: \"Iedereen kan de softwarecatalogus raadplegen ... De gegevens ingevoerd door de leveranciers zijn openbaar\" (read 2026-09-26); https://www.softwarecatalogus.nl/pakketten: package list readable without login (read 2026-09-26). Reached on: Alle pakketten.", "stackiq": "lib/Settings/softwarecatalogus_register.json:7307 module authorization.read grants group public on publicationDate<=$now (and, separately, on registeredBy=Supplier); lib/Settings/softwarecatalogus_register.json:1559 catalogService same; suite read is plain 'public' (lib/Settings/softwarecatalogus_register.json:1270). No stackiq route is #[PublicPage] except intake/review aggregate/gebruik (lib/Controller/GebruikController.php:102 returns an empty envelope to anonymous callers). The app's pages are all behind Nextcloud login (appinfo/routes.php:313 SPA catch-all).", "topdesk": "unknown: the Self-Service Portal requires a login per the SSP login settings; public browsing of assets is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967628-guest-login-for-process-publications: 'SSO login works for non-BlueDolphin users in the Process Portal (Published BPMN 2.0 diagrams)'. Readers without an account still sign in through the organisation's SSO, and only processes are published (read 2026-09-26). Reached on: Process Portal (guest SSO).", "sap-leanix": "https://help.sap.com/docs/leanix/ea/portal-faqs: portals make data 'available to a broad audience outside the IT organization ... an Application Portal that is accessible to everyone'. Whether portal visitors must sign in is not stated (read 2026-09-26). Reached on: Administration > Self Service Portal.", "glpi": "source read at 11.0.9: the only anonymous content is the public FAQ, gated by use_public_faq (src/KnowbaseItem.php:131, src/Document.php:717); asset, appliance and software lists all require a session (src/Glpi/Controller/GenericListController.php checks canView)." }, @@ -6060,6 +6609,7 @@ "stackiq": "Anonymous read of the supplier offering depends on declared rules: lib/Settings/softwarecatalogus_register.json:7307 module read includes public on publicationDate<=$now and on registeredBy=Supplier; lib/Settings/softwarecatalogus_register.json:1559 catalogService public on publicationDate. Stackiq's own offering endpoint lib/Controller/AanbodController.php (routes.php:202) is authenticated-only (@NoAdminRequired + in-body guard). Rate limit only on GebruikController (#[AnonRateLimit]).", "topdesk": "unknown: the REST API requires an operator or API account; a public API is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no public API is documented; public data is offered as CSV downloads; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/api, https://www.softwarecatalogus.nl/Beschikbare%20downloads (read 2026-09-26)", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; all API calls need an x-api-key and tenant (https://help.bluedolphin.io/en/articles/11967730-about-the-bluedolphin-api), a public API over a supplier offering is not documented (read 2026-09-26)", "sap-leanix": "unknown: docs searched at https://help.sap.com/docs/leanix/ea; all APIs authenticate with workspace tokens (https://help.sap.com/docs/leanix/ea/authentication-to-sap-leanix-services), a public API over a supplier offering is not documented (read 2026-09-26)" }, "pendingQuestion": "Does the installed OpenRegister execute the module/catalogService public read rules for anonymous API callers, and is any API key or rate limit applied to that public surface?" @@ -6071,7 +6621,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "unknown", "stackiq": "partial", @@ -6088,6 +6638,7 @@ "stackiq": "lib/Portal/PortalContributionProvider.php:130 getContribution() declares read-only, organisation-scoped collections (catalogService, usage, catalogContract, compliancy) for the vendor-org and participant-org audiences. Portaliq discovers it by FQCN from the Stackiq in appinfo/info.xml (portaliq lib/Contribution/PortalProviderLocator.php:49/77). No info.xml dependency; inert without portaliq.", "topdesk": "unknown: no shared external portal is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no external portal integration is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967500-getting-started-with-process-publication-portal: the process portal shows processes and, 'For each application, you will find different processes in which the selected application is involved'. Process content on BlueDolphin's own portal, not embedded in a shared external portal (read 2026-09-26). Reached on: Process Portal.", "sap-leanix": "https://updates.leanix.net/announcements/embed-reports-diagrams-into-portals (2025-12-22): 'Portals can also serve as the primary entry point for business users ... diagrams and reports ... can now be added to portals'; https://help.sap.com/docs/leanix/ea/portals (read 2026-09-26). Reached on: Portals.", "glpi": "source read at 11.0.9: no embeddable widget or external portal integration for catalogue content; the self service interface (src/Glpi/Form/ServiceCatalog/ServiceCatalog.php:45) is GLPI's own helpdesk portal and grep -rli 'iframe embed\\|oembed' over src/ returns nothing." }, @@ -6100,7 +6651,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "no", "topdesk": "no", "stackiq": "partial", @@ -6117,6 +6668,7 @@ "stackiq": "No MCP, tool-provider, TaskProcessing or ContextChat code in stackiq lib/ or src/ (grep 'mcp|ToolProvider|assistant|TaskProcessing|ContextChat' in lib/ finds nothing). OpenRegister ships a generic MCP endpoint (openregister appinfo/routes.php:1969 /api/mcp/v1/discover and the JSON-RPC endpoint) over all registers.", "topdesk": "https://tip.topdesk.com/c/200-ai-mcp-based-service-: roadmap card in column \"Building\", \"Model Context Protocol (MCP-based service) allows secure, controlled connectivity between your TOPdesk environment and LLM-powered assistants\" (read 2026-09-26); the shipped TOPdesk Robin works inside tickets (https://docs.topdesk.com/en/td-robin-for-operators.html).", "vng-softwarecatalogus": "unknown: no assistant or tool interface is described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/15602927-add-bluedolphin-mcp-server-to-an-ai-assistant: 'This feature enables the third-party AI assistant to query data from BlueDolphin. BlueDolphin MCP can only retrieve data. It cannot create, update, or delete anything' (read 2026-09-26). Reached on: System settings > Integration > MCP API key.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/mcp-server-toolsets: toolset 'inventory ... Get fact sheet information', with create tools for surveys, architecture decisions, diagrams and automations; no tool to update fact sheet fields is listed (read 2026-09-26). Reached on: MCP server (https://mcp.leanix.net/services/mcp-server/v1/mcp).", "glpi": "source read at 11.0.9: grep -rli 'mcp\\|model context\\|openai\\|llm' over src/ returns nothing; AI tool access would go through the generic v2 API (src/Glpi/Api/HL/Controller/AssetController.php:149) with no tool interface of its own." }, @@ -6129,7 +6681,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -6146,6 +6698,7 @@ "stackiq": "Stackiq has no webhook code. The Flows page (src/manifest.json:1057, settings-section menu entry FlowsMenu) authors OpenRegister's native flows scoped to app stackiq; OpenRegister's flow event catalogue has object.created/object.updated (openregister lib/Service/Flow/EventCatalogService.php:53-54), and OpenRegister has its own webhooks admin (openregister appinfo/routes.php:1909).", "topdesk": "https://docs.topdesk.com/en/let-your-topdesk-talk-to-other-applications.html: \"Send a request from TOPdesk to another program ... This way you can create an integration with almost any software that has an API\" (read 2026-09-26) triggered by card events (https://docs.topdesk.com/en/events-that-trigger-actions.html). Reached on: Action Management > action sequences.", "vng-softwarecatalogus": "unknown: notifications go to people by mail and inbox, no system webhooks are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/12310569-introduction-to-subscriptions: 'Subscriptions provide webhook functionality that allows the notification of external services about specific events in BlueDolphin via HTTP requests', for ObjectCreated, ObjectUpdated and ObjectArchived (read 2026-09-26). Reached on: Public API > subscriptions.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/webhooks: 'Webhooks let you receive updates about events as they happen in near real time ... PUSH webhooks : As events occur in SAP LeanIX , they're sent through HTTP POST requests to the specified target URL' (read 2026-09-26). Reached on: Administration > Webhooks.", "glpi": "source read at 11.0.9: src/Webhook.php:64 Webhook sends HTTP calls on new, update and delete events (src/Webhook.php:311 getDefaultEventsList) for management itemtypes including Appliance, Budget, Contact and others (src/Webhook.php:398). Reached on: Setup > Webhooks (src/Html.php:1331). Driven on the lab at 11.0.9 (2026-09-26): Setup > Webhooks (/front/webhook.php) lists webhooks with type, event and category." }, @@ -6158,7 +6711,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "yes", "topdesk": "yes", "stackiq": "partial", @@ -6178,6 +6731,7 @@ "topdesk": "https://docs.topdesk.com/en/designing-templates-for-assets.html: \"History widget : shows both present and past changes that have been made to an asset\" (read 2026-09-26); https://docs.topdesk.com/en/cards-in-call-management.html: \"Audit trail tab Previous events while processing this call\" (read 2026-09-26). Reached on: Asset card > History widget.", "stackiq": "src/manifest.json:436 (and 10 more detail pages: ContactpersoonDetail, ModuleDetail, ContractDetail, SuiteDetail, StandaardDetail, BioMaatregelDetail, ReviewDetail, KompliantieDetail, ModuleversieDetail, KwetsbaarheidDetail) declare a sidebar tab History with widget type audit, which reads OpenRegister's audit trail for that one object.", "vng-softwarecatalogus": "unknown: only a \"Laatst gewijzigd\" date on supplier pages and a mutation date in exports are shown; who changed what is not described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier, https://www.softwarecatalogus.nl/Beschrijving%20exportbestanden (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967537-object-history: 'The History tab shows the information about when the object was created, changed, or deleted. It is also made clear by whom the change was made'; view history at https://help.bluedolphin.io/en/articles/11967523-view-history (read 2026-09-26). Reached on: Object > History tab.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/collaborating-and-managing-data-in-fact-sheets: the fact sheet change log shows 'Old Value / New Value', 'User', 'Time' and 'Entries in the log cannot be deleted manually' (read 2026-09-26). Reached on: Fact sheet > History log." }, "pendingQuestion": "Is OpenRegister's audit trail enabled for the voorzieningen register on a default install, so the History tab shows entries?" @@ -6189,7 +6743,7 @@ "origin": "own-code", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", - "bluedolphin": "partial", + "bluedolphin": "unknown", "glpi": "no", "topdesk": "unknown", "stackiq": "partial", @@ -6204,7 +6758,7 @@ "providerHow": "read-from-code", "note": "Five custom pages subscribe to collection events and refetch on a change. Whether the event ever arrives depends on OpenRegister and the push transport, which this repo cannot show.", "evidence": { - "bluedolphin": "docs, intelligence competitor_features#48969 'Real-time collaboration' (2026-07-23): Multiple stakeholders collaborate on models. | Rated partial because real-time collaboration on models.", + "bluedolphin": "unknown: docs searched at https://help.bluedolphin.io/en/; views can be shared for collaboration (https://help.bluedolphin.io/en/articles/11967512-collaborate-on-an-architecture-view), but a list that refreshes by itself when another user changes an entry is not documented; the earlier intelligence citation alone is a claim (read 2026-09-26)", "stackiq": "src/composables/useLiveCollections.js:40 subscribes via the library's useObjectSubscription; used in src/views/KwetsbaarhedenView.vue:197, LicensePostureView.vue:209, LifecycleRoadmapView.vue:184, ComplianceMatrixView.vue:326, PortfolioReport.vue:323. The standard index pages (Contracts, Organisations and others) rely on whatever the library's CnIndexPage does.", "topdesk": "unknown: live list updates are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)", "vng-softwarecatalogus": "unknown: no live list updates are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", @@ -6220,7 +6774,7 @@ "origin": "own-code", "vng-softwarecatalogus": "yes", "sap-leanix": "partial", - "bluedolphin": "unknown", + "bluedolphin": "yes", "glpi": "partial", "topdesk": "partial", "stackiq": "partial", @@ -6240,6 +6794,7 @@ "stackiq": "Only declarations: x-openregister-notifications on vulnerability (lib/Settings/softwarecatalogus_register.json:1622), usage (:2662), catalogContract (:3253), software-review (:3962), module (:6781), moduleVersion (:7652). Stackiq has no INotifier or notification code of its own (grep in lib/). The contract-expiry rule filters status equals 'Actief' (lib/Settings/softwarecatalogus_register.json:3255) while the enum is Active/Expired/In negotiation, so it can never match.", "topdesk": "https://docs.topdesk.com/en/topdesk-mobile.html: \"change your notification settings\" in the mobile app (read 2026-09-26); https://docs.topdesk.com/en/action-management.html: \"specific mobile alerts for operators\" (read 2026-09-26). Mostly email and mobile alerts, no in-app inbox described. Reached on: TOPdesk Mobile; Action Management.", "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/Releasebrief%20GEMMA%20Softwarecatalogus%20versie%204.1: \"Gemeenten, samenwerkingen, en leveranciers hebben nu rechtsboven bij het inlogmenu een inbox-symbool met daarbij het aantal nieuwe berichten\" (read 2026-09-26); https://www.softwarecatalogus.nl/node/16564: E17 \"De softwarecatalogus bevat een notificatievoorziening en een inbox voor gemeenten en samenwerkingen\" (read 2026-09-26). Reached on: Inlogmenu > Inbox.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967493-notification-bell: 'The notification bell alerts you when a message on an object or a view has been placed for you'; email notices on deliverable status changes (https://help.bluedolphin.io/en/articles/11967481-user-profile) (read 2026-09-26). Reached on: Top bar > notification bell.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/notifications: 'Notification Channels ... Email : This is the primary channel for notifications ... Microsoft Teams', for fact sheet updates, subscriptions, to-dos and surveys; no in-app channel is listed (read 2026-09-26). Reached on: User menu > My Settings > Notifications." }, "pendingQuestion": "Does the installed OpenRegister dispatch the x-openregister-notifications rules on vulnerability, software-review, moduleVersion and the scheduled rules on catalogContract/usage/module, as Nextcloud notifications to the listed recipients?" @@ -6251,7 +6806,7 @@ "origin": "competitor", "vng-softwarecatalogus": "unknown", "sap-leanix": "yes", - "bluedolphin": "unknown", + "bluedolphin": "partial", "glpi": "yes", "topdesk": "partial", "stackiq": "partial", @@ -6269,6 +6824,7 @@ "topdesk": "https://marketplace.topdesk.com/: \"Showing all 133 results\" of integrations (read 2026-09-26); https://docs.topdesk.com/en/exporting-and-importing.html: \"import an action sequence example from the TOPdesk Marketplace\" (read 2026-09-26). Integrations and action-sequence templates, not installable plugins. Reached on: TOPdesk Marketplace.", "stackiq": "src/manifest.json:225 Store page (type store, footer menu StoreMenu) over the OpenRegister store plane, with store.types openregister.configset and openregister.flows; its own note says that with no registry configured it shows only the app's built-in items.", "vng-softwarecatalogus": "unknown: no plugins are described; searched https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967779-add-an-integration-in-bluedolphin: 'Click Add integration in the bottom right corner of the Marketplace page', with 'Marketplace (Integration) is a paid add-on'. The marketplace holds vendor connectors, not third party plugins (read 2026-09-26). Reached on: System settings > Marketplace.", "sap-leanix": "https://help.sap.com/docs/leanix/ea/extension-hub: 'The SAP LeanIX extension hub is a centralized location where you can discover and install ready-to-use extensions for your SAP LeanIX workspace. These include meta model extensions, surveys, and custom reports'; public hub at https://exthub.leanix.net/en (read 2026-09-26). Reached on: Extension Hub." }, "pendingQuestion": "Is a store registry configured on a default install, and are any stackiq configuration sets published to it?" @@ -6293,14 +6849,14 @@ "evidence": { "topdesk": "Card 'Permission for fields and/or widgets' in Under consideration: 'User can set up permission for any fields or widgets'. (read 2026-09-26)", "vng-softwarecatalogus": "unknown: field-level permissions are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", - "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "sap-leanix": "https://help.sap.com/docs/leanix/ea/tags-and-custom-fields: custom attributes when data 'Needs access control, allowing you to restrict read or write permissions to specific users or roles'; https://help.sap.com/docs/leanix/ea/using-reports: 'if a user lacks permission to view or edit a specific field in the metamodel' (read 2026-09-26). Reached on: Administration > Meta Model Configuration > field permissions.", + "bluedolphin": "https://help.bluedolphin.io/en/articles/11967624-manage-roles-and-permissions: each role defines 'which actions the user with this role is allowed to perform with the objects and their properties, relationships, questionnaires, and views, for each object definition'. Scoped per object definition and questionnaire, not per single field (read 2026-09-26). Reached on: Admin > Roles > Permissions.", "glpi": "source read at 11.0.9: custom fields of custom asset types can be made read only or hidden per profile, src/Glpi/Asset/CustomFieldType/AbstractType.php:79 'Readonly for these profiles' and :80 'Hidden for these profiles'; ITIL templates hide or lock ticket fields (src/ITILTemplateHiddenField.php:43, src/ITILTemplateReadonlyField.php:43). Core Appliance and Software fields have rights per itemtype only (src/Appliance.php:59 rightname). Reached on: Setup > Asset definitions > Fields; Assistance templates." }, "note": "Mined from topdesk (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", - "sap-leanix": "unknown", - "bluedolphin": "unknown", + "sap-leanix": "yes", + "bluedolphin": "partial", "glpi": "partial" } ] From 1a807f88fe1dd59bc0e3039694d98d82758c8d70 Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:55:52 +0200 Subject: [PATCH 11/12] chore(parity): batch-2 back-fill VNG and TOPdesk --- openspec/parity/capabilities.json | 96 +++++++++++++++---------------- 1 file changed, 48 insertions(+), 48 deletions(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index de87c34c..deaa4175 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -5286,15 +5286,15 @@ "sap-leanix": "yes", "evidence": { "sap-leanix": "Announcement of 2026-05-12: 'We have expanded the AI Agent Hub ... New discovery sources: ServiceNow and SAP AI Core ... automatically populate your workspace with AI assets'; AI agent is an application subtype and AI model an IT component subtype (https://help.sap.com/docs/leanix/ea/application-modeling-guidelines) (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: AI agents and models are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: no AI system itemtype (grep -rli 'artificial intelligence' over src/ locales/glpi.pot returns nothing); an admin can define an 'AI model' custom asset type (src/Html.php:1330 Setup > Asset definitions, src/Glpi/Asset/AssetDefinition.php) and link it to applications as an Appliance item (src/Appliance_Item.php:45) or impact relation (install/mysql/glpi-empty.sql:1247). There is no process model to link to. Reached on: Setup > Asset definitions, then Appliance > Items tab.", + "topdesk": "unknown: AI agents and models as registered items are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from sap-leanix (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "partial", "topdesk": "unknown" }, { @@ -5316,15 +5316,15 @@ "sap-leanix": "yes", "evidence": { "sap-leanix": "Announcement of 2026-07-13: admins 'add single-select and multi-select dropdown fields to architecture decision templates'; https://help.sap.com/docs/leanix/ea/architecture-decisions: 'Document decisions about enterprise architecture in a structured, template-driven format ... Track decisions through a review process with defined statuses', shown on linked fact sheets (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: architecture decisions are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: grep -rli 'architecture decision' over src/ locales/glpi.pot returns nothing; the only status and review flow is ITIL approval on changes (src/ChangeValidation.php:39), not a decision record linked to applications.", + "topdesk": "unknown: architecture decisions are not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from sap-leanix (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -5347,15 +5347,15 @@ "evidence": { "sap-leanix": "Announcement of 2026-06-23: 'Ask a question in plain language, and the assistant provides a sourced answer from your workspace ... Every answer is attributed to its source'. A premium AI feature needing AI units (read 2026-09-26)", "bluedolphin": "Product news entry of 2026-09-01 'Communicate in natural language to find business information in BlueDolphin'; https://help.bluedolphin.io/en/articles/12528662-ai-capabilities-of-bluedolphin: 'AI Navigator answers questions asked in plain language ... Answers are grounded in your BlueDolphin repository and include direct links to relevant content' (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "vng-softwarecatalogus": "unknown: no plain-language question function is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", + "glpi": "source read at 11.0.9: grep -rli 'openai\\|llm\\|artificial intelligence' over src/ returns nothing; search is criteria based only (src/Glpi/Search/Input/QueryBuilder.php:72).", + "topdesk": "https://docs.topdesk.com/en/td-robin-for-operators.html: \"Chat: Ask TOPdesk Robin a question. TOPdesk Robin searches your organization's knowledge base for an answer\" (read 2026-09-26); https://docs.topdesk.com/en/ai-answer-assistant.html: \"The Knowledge Base is the only source for the AI\" (read 2026-09-26). Answers cite knowledge items, not asset or landscape entries. Reached on: Call card > TOPdesk Robin panel." }, "note": "Mined from sap-leanix (changelog) on 2026-09-26. Also mined from bluedolphin (changelog, https://bluedolphin.io/product-news/).", "bluedolphin": "yes", "vng-softwarecatalogus": "unknown", - "glpi": "unknown", - "topdesk": "unknown" + "glpi": "no", + "topdesk": "partial" }, { "id": "comp-ai-act-classification", @@ -5376,15 +5376,15 @@ "sap-leanix": "partial", "evidence": { "sap-leanix": "Roadmap card 'Meta model: EU AI Act extension' is In progress (read from the portal data on 2026-09-26); today the legacy AI agent extension already has an 'AI Risk ... according to the EU AI Act' single select (https://help.sap.com/docs/leanix/ea/ai-agent-extension-to-meta-model), so a basic risk field exists but the full extension is not shipped (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: the EU AI Act is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: grep -rli 'ai act\\|artificial intelligence' over src/ locales/glpi.pot returns nothing; appliances have no risk category field (install/mysql/glpi-empty.sql:8935 glpi_appliances).", + "topdesk": "unknown: the AI Act is mentioned only for TOPdesk's own AI features (\"post-market monitoring procedures ... in accordance with the AI Act\"), not for classifying the customer's AI systems; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from sap-leanix (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -5406,15 +5406,15 @@ "sap-leanix": "no", "evidence": { "sap-leanix": "Roadmap card 'EA Assistant: Technology Successor Planning' is On roadmap; https://updates.leanix.net/announcements/work-with-complete-technology-version-coverage-without-raising-manual-requests (2026-09-17): 'version concurrency management, which we plan to implement in Q4. You will be able to define version tolerance windows' (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: no version tolerance rule is described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: software versions have no order or release date to measure distance from the latest (install/mysql/glpi-empty.sql:6900 glpi_softwareversions: name, states_id, arch, comment); grep -rli 'releases behind' over src/ returns nothing.", + "topdesk": "unknown: no version tolerance rule is described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from sap-leanix (roadmap) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -5436,15 +5436,15 @@ "sap-leanix": "yes", "evidence": { "sap-leanix": "Announcement of 2025-09-03: 'Selecting Compare Changes ... on a prior diagram version shows color-coded highlighting (green for additions, red for removals, yellow for modifications), a side-by-side view of differences, and an additional text-based summary' (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: diagram versions are not described; maps are generated on request; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: impact graphs are not versioned; src/ImpactRelation.php:39, src/ImpactItem.php:42 and src/ImpactContext.php:40 set no dohistory, so no saved diagram versions exist to compare.", + "topdesk": "unknown: architecture diagrams are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from sap-leanix (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "bluedolphin": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -5466,16 +5466,16 @@ "bluedolphin": "yes", "evidence": { "bluedolphin": "November 2025 update (2025-11-13): 'Conditional Syncing for Integrations and Webhooks' lets teams 'control exactly what data syncs to third-party systems based on lifecycle state' (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: no outgoing sync to other systems is described, only CSV and AMEFF exports; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: webhooks carry search criteria filters (src/Webhook.php:64 implements FilterableInterface, src/Glpi/Search/FilterableTrait.php:45) and are only sent when the changed item matches them, src/Webhook.php:1228 itemMatchFilter; filtering on the Status field (src/Appliance.php:350) sends an appliance only once it reaches the chosen state. Reached on: Setup > Webhooks > Filter tab.", + "topdesk": "https://docs.topdesk.com/en/creating-events.html: \"Edit card is triggered when a card is modified. Fill in the conditions ... Conditions check the current value of the card\" (read 2026-09-26); https://docs.topdesk.com/en/let-your-topdesk-talk-to-other-applications.html: \"Send a request from TOPdesk to another program\" (read 2026-09-26). The customer builds it as an automated action; no ready-made lifecycle sync. Reached on: Action Management > events and action sequences." }, "note": "Mined from bluedolphin (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", - "glpi": "unknown", - "topdesk": "unknown" + "glpi": "yes", + "topdesk": "partial" }, { "id": "ins-usage-analytics", @@ -5496,16 +5496,16 @@ "bluedolphin": "yes", "evidence": { "bluedolphin": "February 2026 update (2026-02-10): new reports show 'which guest users have access to BlueDolphin' and 'which views are being used across the platform'; https://help.bluedolphin.io/en/articles/13868249-usage-insights (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "https://www.softwarecatalogus.nl/rapportages: per month \"Aantal actieve gemeenten\", \"Aantal ingelogde gebruikers van gemeenten\", \"Aantal zoekopdrachten door gemeenten\" (read 2026-09-26). Usage totals only; which pages or views are used and guest reach are not shown. Reached on: Rapportages.", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: the event log (src/Glpi/Event.php:63) records logins and item actions, not which lists or pages are viewed; grep -rli 'page view' over src/ returns nothing, and there are no guest users apart from the public FAQ (src/KnowbaseItem.php:131).", + "topdesk": "https://docs.topdesk.com/en/setting-up-the-self-service-portal.html: \"Only when users click Allow analytics, their page usage is synchronized with your Google Analytics account\" (read 2026-09-26). Self-Service Portal page usage in an outside tool only. Reached on: Self-Service Portal settings > Analytics." }, "note": "Mined from bluedolphin (changelog) on 2026-09-26.", - "vng-softwarecatalogus": "unknown", + "vng-softwarecatalogus": "partial", "sap-leanix": "unknown", - "glpi": "unknown", - "topdesk": "unknown" + "glpi": "no", + "topdesk": "partial" }, { "id": "land-move-between-workspaces", @@ -5526,15 +5526,15 @@ "bluedolphin": "yes", "evidence": { "bluedolphin": "June 2026 update (2026-06-11): 'You can move one or multiple objects to another workspace directly from the Repository without leaving your current view', skipping objects already in the target (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: workspaces are not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: selected records are moved to another entity with their links by src/Transfer.php:50 Transfer, queued through the massive action add_transfer_list (src/MassiveAction.php:598), for one or many entries at once. Reached on: any list, Actions > Add to transfer list; Administration > Entities > transfer.", + "topdesk": "unknown: workspaces are not described; changing an asset's type is still an idea at https://tip.topdesk.com/c/89-changing-the-type-of-an-asset; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from bluedolphin (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", - "glpi": "unknown", + "glpi": "yes", "topdesk": "unknown" }, { @@ -5556,15 +5556,15 @@ "bluedolphin": "yes", "evidence": { "bluedolphin": "July 2026 update (2026-07-09): customers can 'define questionnaires directly on BPMN elements such as tasks and events'; https://help.bluedolphin.io/en/articles/15874771-questionnaires-for-bpmn-elements: 'centralize documentation like risk levels, compliance checks, and technical specifications' (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: processes are not modelled; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: grep -rli 'business process\\|process step' over src/ locales/glpi.pot returns nothing; 'Processes' in inventory (src/Glpi/Inventory/Asset/Process.php) are operating system processes, not business process steps.", + "topdesk": "unknown: process modelling is not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from bluedolphin (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" }, { @@ -5586,15 +5586,15 @@ "bluedolphin": "yes", "evidence": { "bluedolphin": "Product news entry of 2026-09-08 'Bring structure to your Views list with tags' (https://bluedolphin.io/product-news/); the linked article lists view filters 'Owner Contributors Tags Favorited Private Project Status Type' (read 2026-09-26)", - "vng-softwarecatalogus": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", + "vng-softwarecatalogus": "unknown: the GEMMA maps are chosen from a fixed list; tagging views is not described; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "sap-leanix": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "topdesk": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet" + "glpi": "source read at 11.0.9: saved searches, the only saved views, have type, itemtype, owner and privacy but no tags (install/mysql/glpi-empty.sql:232 glpi_savedsearches, :237 users_id, :238 is_private), and impact graphs are not saved as named views (src/ImpactContext.php:40 holds display settings only). The list can be filtered by owner, not by tag.", + "topdesk": "unknown: saved overviews can be renamed and shared, but tagging them is not described; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from bluedolphin (changelog) on 2026-09-26.", "vng-softwarecatalogus": "unknown", "sap-leanix": "unknown", - "glpi": "unknown", + "glpi": "no", "topdesk": "unknown" } ], From e33196224911f79b18562060e7ceb7f36a5a996b Mon Sep 17 00:00:00 2001 From: Ruben van der Linde Date: Sat, 26 Sep 2026 23:56:11 +0200 Subject: [PATCH 12/12] chore(parity): batch-2 back-fill GLPI --- openspec/parity/capabilities.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openspec/parity/capabilities.json b/openspec/parity/capabilities.json index deaa4175..fc289e17 100644 --- a/openspec/parity/capabilities.json +++ b/openspec/parity/capabilities.json @@ -5438,7 +5438,7 @@ "sap-leanix": "Announcement of 2025-09-03: 'Selecting Compare Changes ... on a prior diagram version shows color-coded highlighting (green for additions, red for removals, yellow for modifications), a side-by-side view of differences, and an additional text-based summary' (read 2026-09-26)", "vng-softwarecatalogus": "unknown: diagram versions are not described; maps are generated on request; searched the public manuals and FAQ at https://www.softwarecatalogus.nl/node/16564, https://www.softwarecatalogus.nl/node/13683, https://www.softwarecatalogus.nl/node/19703, https://www.softwarecatalogus.nl/Gebruikershandleiding_leverancier (read 2026-09-26)", "bluedolphin": "not checked: row added in wave 5 (2026-09-26), no reading of this system for it yet", - "glpi": "source read at 11.0.9: impact graphs are not versioned; src/ImpactRelation.php:39, src/ImpactItem.php:42 and src/ImpactContext.php:40 set no dohistory, so no saved diagram versions exist to compare.", + "glpi": "source read at 11.0.9: impact graphs are not versioned; src/ImpactContext.php:40 stores only positions, zoom and colours (install/mysql/glpi-empty.sql:1293 glpi_impactcontexts) and CommonDBTM defaults dohistory to false (src/CommonDBTM.php:104). Relation adds and removals (src/ImpactRelation.php:39 extends CommonDBRelation) appear in each linked item's history (src/CommonDBRelation.php:844), but there is no saved diagram version and no compare view.", "topdesk": "unknown: architecture diagrams are not covered; searched the full-text search index of docs.topdesk.com (https://docs.topdesk.com/en/js/fuzzydata.js, 987 pages) (read 2026-09-26)" }, "note": "Mined from sap-leanix (changelog) on 2026-09-26.",