[{"data":1,"prerenderedAt":474},["ShallowReactive",2],{"navigation":3,"\u002Freference\u002Fplan-coverage":250,"\u002Freference\u002Fplan-coverage-surround":469},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":231,"body":252,"description":462,"extension":463,"links":464,"meta":465,"navigation":466,"path":232,"seo":467,"stem":233,"__hash__":468},"docs\u002F8.reference\u002F1.plan-coverage.md",{"type":253,"value":254,"toc":455},"minimark",[255,264,269,429,433,441,444],[256,257,258,259,263],"p",{},"This index maps all ",[260,261,262],"strong",{},"31 sections"," of the supplied “intrnl.cloud v1 — system architecture and implementation plan” into maintained documentation. Section numbers refer to the original plan; page headings use descriptive names.",[265,266,268],"h2",{"id":267},"section-coverage","Section coverage",[270,271,272,279,284,289,294,299,304,309,314,319,324,329,334,339,344,349,354,359,364,369,374,379,384,389,394,399,404,409,414,419,424],"ol",{},[273,274,275,278],"li",{},[276,277,10],"a",{"href":6}," — Product definition.",[273,280,281,283],{},[276,282,12],{"href":13}," — Locked architectural decisions.",[273,285,286,288],{},[276,287,67],{"href":68}," — One important security refinement: separate app and control-plane domains.",[273,290,291,293],{},[276,292,34],{"href":30}," — Top-level architecture.",[273,295,296,298],{},[276,297,36],{"href":37}," — Trust zones.",[273,300,301,303],{},[276,302,40],{"href":41}," — Central control plane.",[273,305,306,308],{},[276,307,44],{"href":45}," — Organization tenancy.",[273,310,311,313],{},[276,312,63],{"href":64}," — Identity architecture.",[273,315,316,318],{},[276,317,98],{"href":99}," — AI and MCP architecture.",[273,320,321,323],{},[276,322,102],{"href":103}," — Source-control architecture.",[273,325,326,328],{},[276,327,106],{"href":107}," — Build architecture.",[273,330,331,333],{},[276,332,110],{"href":111}," — Runtime contract.",[273,335,336,338],{},[276,337,124],{"href":125}," — Runtime-cluster architecture.",[273,340,341,343],{},[276,342,71],{"href":72}," — Ingress, network, and egress.",[273,345,346,348],{},[276,347,75],{"href":76}," — Access policy and WAF-lite.",[273,350,351,353],{},[276,352,132],{"href":133}," — Data architecture.",[273,355,356,358],{},[276,357,79],{"href":80}," — Secrets and integrations.",[273,360,361,363],{},[276,362,128],{"href":129}," — Deployment pipeline.",[273,365,366,368],{},[276,367,83],{"href":84}," — Governance.",[273,370,371,373],{},[276,372,24],{"href":25}," — Economics and metering.",[273,375,376,378],{},[276,377,48],{"href":49}," — Core data model.",[273,380,381,383],{},[276,382,114],{"href":115}," — API architecture.",[273,385,386,388],{},[276,387,142],{"href":143}," — Observability and audit.",[273,390,391,393],{},[276,392,87],{"href":88}," — Security threat model.",[273,395,396,398],{},[276,397,20],{"href":21}," — Organization v1 pilot.",[273,400,401,403],{},[276,402,52],{"href":53}," — Codebase organization.",[273,405,406,408],{},[276,407,170],{"href":171}," — all ten phases, each with full scope and exit criteria.",[273,410,411,413],{},[276,412,216],{"href":217}," — Test strategy.",[273,415,416,418],{},[276,417,146],{"href":147}," — Operational model.",[273,420,421,423],{},[276,422,16],{"href":17}," — Explicit v1 non-goals.",[273,425,426,428],{},[276,427,220],{"href":221}," — v1 definition of done.",[265,430,432],{"id":431},"editorial-treatment","Editorial treatment",[256,434,435,436,440],{},"Extraction was checked against the supplied plan on 2026-09-21: all 31 sections, all ten implementation phases and their exit criteria, and all 28 definition-of-done requirements are preserved. The maintained pages are self-contained; the temporary root-level ",[437,438,439],"code",{},"project-plan.md"," is not required to build or use this site.",[256,442,443],{},"All original major sections and phase exit criteria are retained. Citation tokens are replaced by official references. Section numbers are removed from subheadings. The artifact contract date is aligned with the illustrative runtime configuration date; neither declares a shipped version. Signature verification precedes workload startup. Migration availability is conditional on schema compatibility. Customer and industry examples are generalized. Enterprise system integrations remain future scope.",[256,445,446,447,450,451,454],{},"The ",[276,448,449],{"href":236},"decision register",", ",[276,452,453],{"href":240},"glossary",", contributor guide, and operational runbooks add navigation and implementation guidance. Runbooks are procedure specifications pending implementation-specific commands and rehearsal. No additional feature is promoted into v1, and no phase is marked complete.",{"title":456,"searchDepth":457,"depth":458,"links":459},"",1,2,[460,461],{"id":267,"depth":458,"text":268},{"id":431,"depth":458,"text":432},"A mapping from all 31 source-plan sections to this documentation.","md",null,{},true,{"title":231,"description":462},"-Y-Qc86F5FDedfv3ymWFM1mljlQYfZg5yYOpVOHeE5g",[470,472],{"title":220,"path":221,"stem":222,"description":471,"children":-1},"The 28 acceptance requirements that must be evidenced before v1 is complete.",{"title":235,"path":236,"stem":237,"description":473,"children":-1},"Locked architecture and the evidence required to close open implementation gates.",1790019414382]