# AEGIS CYBER — Navigation Re-Group Proposal (PAPER PROPOSAL — react before any code change)

**Track:** Product / UX. **Status:** paper proposal, **HELD at paper for one more look** (operator
decision 2026-06-11) — **no nav code has been changed.** Implementation is a separate light frontend
cycle, only after you release the hold.

**Boundary (advisor-set):** entirely separate from the verification arc. Must not touch, reference, or
get entangled with VF-S7 (CLOSED), KYC (held), the file-trim track, or the Docker track — and the
eventual implementation must touch **only** nav grouping/ordering, never routing, page logic, or the
regulated PAM/JIT/audit-chain code.

**Source of truth for the nav:** `client/src/components/app-sidebar.tsx` (arrays `mainNavItems`,
`deepTechNavItems`, `platformServicesNavItems`, `commercialSaasNavItems`, `adminNavItems`); routes
registered in `client/src/App.tsx` (wouter).

---

## RESOLVED DECISIONS (advisor, 2026-06-11) — baked into this version

1. **AI Governance is its own top-level group** (a justified exception to the ≤7-groups rule). For a
   sovereign-AI platform pitching a BoU-regulated bank, "how do you govern the AI itself" is a
   first-class regulator question; burying it under Security Operations would undersell it as a
   sub-concern of security tooling. **Substance confirmed** (the advisor's caveat — a group must be
   real, not one thin tab dressed up): **6 distinct governance/oversight/accountability surfaces**
   (see Group 6). Promoted → now **Group 6**; "Platform & Commercial" becomes **Group 7**.
2. **Deep-tech engines: scatter by function in the operator nav (done) + a separate curated investor
   showcase view — NOT a permanent nav group.** Operators navigate by the *job* ("transaction
   monitoring"), and the engine powering it is an implementation detail under that function. The
   investor showcase (IBA, WEF) is a real but *different* audience → a presentation view layered on
   top, not a menu group.
3. **Standing principle (handed to the agent as a rule going forward):** the everyday nav serves
   **operators** (job-based groups); **pitch audiences get curated views layered on top** (bank
   story-path, investor showcase). Don't contort the operator nav to serve pitch audiences. **Test
   for any straddler:** does an *operator* navigate by it, or only a *pitch audience*? Governance
   passes (operators and regulators both navigate by it → group); deep-tech fails (only the pitch
   audience → view).

---

## 0. The headline finding — read this first

**There are ~172 navigation tabs.** ~100 of them sit under a single "Operations" group. This is not
primarily a *grouping* problem — it is a *sprawl* problem. No top-level scheme makes 172 tabs
navigable. Two things actually fix it, and grouping is only the second:

1. **Consolidate the big redundant clusters into hubs** (drills, regulator engagement, reports) and
   **archive the dead milestone tabs** (Wave-*). This alone removes ~40 tabs from the top level.
2. **Then** group the remainder by stakeholder mental model.
3. For the bank demo specifically, **ignore the full nav** and walk the curated **demo path** (§4).

I have NOT smoothed the awkward cases to make the scheme look tidy — they are surfaced in §3.

---

## 1. Proposed top-level groups (stakeholder mental model)

Ordered so walking top-to-bottom tells the pitch as a story: *detect → stop crime → prove compliance
→ control access → assure & survive → govern the AI → run the platform.*

1. **Compliance & Regulatory** — "Am I meeting the rules? Can the regulator see what they need?"
2. **Financial Crime & Transaction Risk** — "Are you actually stopping fraud, AML, sanctions?"
3. **Security Operations** — "How do you detect and respond to attacks?"
4. **Identity, Access & Cryptography** — "Who can do what, and how are secrets protected?"
5. **Audit, Assurance & Resilience** — "Can you prove it — and survive failure?"
6. **AI Governance & Model Accountability** — "How do you govern the AI itself?" *(new — pitch pillar)*
7. **Platform & Commercial** — operator/investor concerns, *not* the bank-security story.

---

## 2. Full mapping (every tab → one primary home)

Markers: **🔁** = part of a redundant cluster that should be consolidated (see §3.1). **⚠** = genuine
straddler; primary home is my call but listed in §3.2 for your decision. **[A]** archive candidate.

### Group 1 — Compliance & Regulatory
- **1a. Regulatory reporting & filings:** PDPO Reports · BoU Reporting Pack · Compliance Docs ·
  Compliance Reports 🔁 · Cross-Border Transfers · SAR Filing Tracker ⚠ · CTR Filings ⚠
- **1b. Regulator engagement** (🔁 → "Regulator Hub", see §3.1): Regulator Welcome · Regulator Tour ·
  Regulator Inbox · Regulator Observer · Regulator Challenge · Regulator Push Hook ·
  Regulator Gateway · BoU Regulatory Demo · BoU Sandbox · Mock Supervisory Exam ·
  Public Verifier · Public Trust Portal · Trust Dashboard
- **1c. Data protection & privacy (PDPO):** Consent Ledger · Sub-Processor Register · PIA Generator ·
  Customer Protection Hub · Data Retention ⚠ · UBO Registry ⚠
- **1d. Compliance posture & scoring:** Compliance Score · SOC2 Compliance · Sovereign Readiness ⚠ ·
  Open Banking Readiness ⚠ · Security Scorecard ⚠
- **1e. Sandbox / pilot milestones** ([A] archive — see §3.3): Pilot Readiness ·
  Wave-8 Examiner Suite · Wave-9 Pilot Perfection · Wave-10 Sandbox Perfection ·
  Wave-11 Pilot-Readiness · Wave-13 Sandbox Closer

### Group 2 — Financial Crime & Transaction Risk
- **2a. Transaction & fraud monitoring:** MoMo Fraud Suite · Transaction Scoring · Fraud Calculator ·
  SWIFT Integrity · NPS Settlement · Behavioral Biometrics ⚠
- **2b. AML / sanctions / KYC:** AML Typology Matrix · Sanctions / PEP Screening · Agentic KYC ·
  Vendor DNA & PKYC ⚠ · Entity Resolution ⚠
- **2c. Risk scoring & forecasting:** Threat Forecast ⚠ · Macro Stress Tests ⚠ · Insider Threat Pack ⚠

### Group 3 — Security Operations
- **3a. SOC & incident response:** Threat Dashboard (`/`, the home) · SOC Command Center ·
  Incident Report · Breach Management · Runbook Executor · Shift Handover · Signal Governance ·
  Enterprise Alerting ⚠ · Event Stream ⚠
- **3b. Threat detection & intelligence:** APT Detection · Zero-Day Detection · DLP Monitor ·
  OS Vuln Scanner · Vulnerabilities 🔁 · Supply Chain Shield · ZK Threat Exchange · Forensic Brain ·
  Digital Twin War Room · Observer Agent · AI Analyst ⚠ · Ghost Core ⚠
- **3c. Offensive testing:** Pentest · Pentest Locker · Business-Logic Pentest · AI Red-Team ·
  Bug Bounty · Vulnerability Disclosure (VDP) · Segmentation Proof
- **3d. Drills & exercises** (🔁 → "Drills Hub", see §3.1): Breach Drill · Chaos Drill ·
  Chaos Sentinel · Backup Test · Restore Drill · Breach SLA Drill · Breach Notification Drill ·
  Failover Demo · DR Failover Drill · Capacity / Load Drill · Load Test · Ransomware Drill ·
  Phishing Sim · Tabletop Exercise · Tamper Demo · Exit Drill · Training Simulation ·
  Synthetic Canary

### Group 4 — Identity, Access & Cryptography
- **4a. Identity & access:** Identity Bio-Vault · Identity Shield ⚠ · SSO Configuration ·
  Session Management · IP Policies · Geo-Fencing · API Keys ⚠
- **4b. Privileged access:** **Privileged Access (JIT)** — *the VF-S7 subject; now prod-verified*
- **4c. Encryption & key management:** Encryption · Key Rotation · HSM Management · PQC Status

### Group 5 — Audit, Assurance & Resilience
- **5a. Audit trail & provenance:** Audit Logs · Audit Chain · Auditor Read-Only ⚠ · Code Provenance ·
  Build Manifest · Immutable Build · SBOM (CycloneDX)
- **5b. SLA / SLO / health assurance:** Service SLA · SLO Report · SLA Breach Tracker ·
  Incident SLA ⚠ · System Pulse · Platform Health ⚠ · NTP / Time-Sync · Perf & A11y Budget ·
  Accessibility Audit
- **5c. Resilience / DR / backups:** Resilience Monitor · Backup & Recovery · Sovereign Edge ⚠
- **5d. Assurance & value:** Quarterly Attestation · Security Posture ⚠ · ROI Report ·
  Cost-of-Control · Peer Analysis

### Group 6 — AI Governance & Model Accountability  *(new — promoted from straddler, substance confirmed)*
> **Substance check (advisor caveat):** 6 distinct governance/oversight/accountability surfaces, each a
> different job — not one tab dressed up as a group. This is the regulator-facing "we govern our AI"
> pillar, and it pairs naturally next to Audit & Assurance.
- **Bias Drill** — test/audit AI decisioning for bias
- **Model Drift** — monitor model accuracy/performance degradation
- **AI Model Cards** — documented model purpose, training, risks
- **AI Decision Appeals** — manage appeals against automated decisions (accountability)
- **Explainable AI** — model interpretability & fairness monitoring
- **Right-to-Explanation** — generate AI decision explanations (regulator/customer right)
- *(straddler — your call:* **AI Thresholds / Settings** *could sit here as the AI-control lever, or
  stay in Admin §7b as the global settings page. Primary = Admin.)*

### Group 7 — Platform & Commercial (operator / investor — NOT the bank-security story)
- **7a. Platform services & infrastructure:** Infrastructure · FinOps · Rate Limits · API Analytics ·
  Webhook Management · Notification Center · BFT Console · Gulu Mesh · Continuous Scheduler ·
  Customer Languages
- **7b. Tenant / multi-tenant admin:** Tenant Admin · Tenant Portal · SaaS Governance ·
  White-Label Config · Feature Flags · Integrations · AI Thresholds (Settings) ⚠
- **7c. Commercial / SaaS / billing:** Revenue Analytics · Customer Success · Contracts & Licenses ·
  Tenant Billing · Commercial Features
- **7d. Investor & strategic** (⚠ wrong audience for a bank demo — surface only to investor/strategic
  roles, and see the showcase note below): Investor Pitch · Series B Roadmap · Data Room ·
  Whitepaper · Board Report · Executive Report

> **Deep-Tech Engines — RESOLVED (decision 2 + standing principle):** the old "Deep-Tech Engines"
> group was a *technology-org* grouping, not a *stakeholder* one. Its members are now **scattered by
> function** into SecOps / Identity / Platform by what they *do* (Forensic Brain → SecOps, PQC →
> Crypto, Gulu Mesh/BFT → Infra, etc.) — right for the **operator** nav. The **investor** value is
> served separately by a **curated "Deep-Tech Showcase" presentation view layered on top**, *not* a
> permanent nav group. Same pattern as the bank demo-path (§4): pitch audiences get curated views, the
> operator menu stays job-based.

---

## 3. Awkward cases, overload, and consolidation — surfaced, not smoothed

### 3.1 Redundant clusters → consolidate into hubs (biggest win, ~40 tabs removed)
- **Drills Hub** — ~18 drill/simulation tabs (§3d) collapse into **one** "Drills & Exercises" page
  with an internal list. They share a shape (trigger a simulation, read a result) and individually
  bury the real product. **Highest-impact single change.** *(Implementation note: this is slightly
  more than menu regrouping — it likely needs a new container/hub page. Earns a touch more care than
  the pure regroup.)*
- **Regulator Hub** — ~13 regulator-facing tabs (§1b) collapse into **one** "Regulator Engagement"
  page with sub-tabs.
- **Reports** — PDPO / Compliance / Board / Executive / ROI / SLO / BoU reports are scattered across
  groups; consider a shared "Reports" surface (or at least consistent naming).

### 3.2 Genuine straddlers — primary call + why (review the reasoning; flag any to overturn)
Each has a primary home with the reasoning shown. **AI Thresholds is the one I'd most want your eye
on** — it's a true governance-vs-tuning judgment. Anything you don't overturn, the primary stands.
- **AI Thresholds (Settings)** ⭐ *your-eye* — Admin global-settings page **vs** AI-Governance control
  lever. **Primary = Admin §7b**, *why:* it's the platform Settings page (a config UI), not a
  governance/oversight *view*; Group 6 is accountability surfaces, not the tuning knob. But if you read
  "who sets the AI's sensitivity" as itself a governance act, it moves to Group 6 — your call.
- **SAR Filing Tracker / CTR Filings** — Compliance reporting **vs** Financial Crime. **Primary =
  Compliance (§1a)**, *why:* they're regulator *filings*; the financial-crime *detection* lives in
  Group 2, the *report to the regulator* lives in Group 1.
- **Insider Threat Pack** — FinCrime/Risk **vs** SecOps. **Primary = FinCrime/Risk (§2c)**, *why:* it's
  framed as a risk-scoring/forecasting pack, not a live SOC response surface.
- **Threat Forecast** — Risk forecasting **vs** Threat intel (SecOps). **Primary = Risk (§2c)**, *why:*
  forward-looking projection sits with the other forecasting/stress surfaces, not live detection.
- **AI Analyst** — SecOps tooling **vs** AI Governance. **Primary = SecOps (§3b)**, *why:* it's an
  AI-*powered* analysis *tool*, not governance *of* the AI — fails the Group-6 substance test.
- **Behavioral Biometrics** — Fraud (FinCrime) **vs** Identity. **Primary = FinCrime (§2a)**, *why:*
  used here for transaction-fraud signal, not for login/identity proofing.
- **Vendor DNA & PKYC** — FinCrime (KYC) **vs** Identity. **Primary = FinCrime (§2b)**, *why:* it's
  perpetual-KYC / vendor-risk — an AML/KYC surface.
- **Identity Shield** — Identity **vs** SecOps. **Primary = Identity (§4a)**, *why:* it protects *the
  actor*, so it sits with access.
- **API Keys / Geo-Fencing / IP Policies** — Identity/Access **vs** Platform. **Primary = Identity
  (§4a)**, *why:* they gate *who/where* can act (access controls), even though they're configured like
  platform settings.
- **Security Posture / Security Scorecard** — Audit/assurance **vs** SecOps **vs** Compliance.
  **Primary = Audit & Assurance (§5d)**, *why:* they're "prove our posture" scorecards (assurance
  artefacts), not live detection or a specific regulation.
- **Data Retention** — Privacy (Compliance) **vs** functional. **Primary = Compliance/Privacy (§1c)**,
  *why:* it's a PDPO obligation surface.
- **UBO Registry** — Privacy (Compliance) **vs** FinCrime. **Primary = Compliance/Privacy (§1c)**,
  *why:* beneficial-ownership record-keeping reads as a regulatory register. *(Weakest call — it has a
  strong AML home in §2b too; flag if you'd rather it sit with KYC.)*
- **Sovereign Readiness** — Compliance posture **vs** Resilience. **Primary = Compliance (§1d)**,
  *why:* it's a readiness/attestation scorecard.
- **Sovereign Edge** — Resilience **vs** Platform. **Primary = Resilience (§5c)**, *why:* it's about
  surviving/operating at the edge (offline, failover) — resilience.
- *(RESOLVED — no longer straddlers: the AI-governance set is promoted to Group 6; deep-tech is
  scattered-by-function + a separate showcase view.)*

### 3.3 Archive candidates — confirm before keeping
- **Wave-8 / 9 / 10 / 11 / 13 suites** (§1e) read as *point-in-time milestone dashboards*. For a live
  bank/investor audience they're noise and likely stale. Recommend **archive = de-nav only** (remove
  from the menu, **keep the routes/pages**) unless one is still actively used. **Your confirm.**
  *(Implementation note: "archive" here means de-nav-only — pages still exist and remain
  route-reachable, just not in the menu. No page deletion.)*
- **Demo-only tabs** (BoU Regulatory Demo, Tamper Demo, Failover Demo, Training Simulation) — keep,
  but tag them as demo/sandbox so they don't read as production controls.

### 3.4 Overloaded-group flags (honest)
- Even after grouping, **Group 1 (Compliance)** and **Group 3 (SecOps)** stay heavy. The §3.1 hubs +
  §3.3 archive are what bring them to a navigable size — grouping alone does not. I am flagging this
  rather than padding the scheme with extra groups to hide the count. (The 7th group, AI Governance,
  was added on *merit* per decision 1 — not to absorb overflow.)

---

## 4. Curated demo path for a BoU / bank presentation (8–10 tabs)

Tells the AEGIS story end-to-end. Each tagged **SAFE** (read-only/monitoring — safe to click live) or
**SHOW-DON'T-TOUCH** (write/action page — display it, do not trigger on stage). This doubles as the
"don't break it on stage" map and agrees with the read-only-favouring demo-safety discipline.

| # | Tab | Story beat | Live-demo safety |
|---|-----|-----------|------------------|
| 1 | **Threat Dashboard** (`/`) | Open on the live cognitive-security picture | **SAFE** (monitoring) |
| 2 | **MoMo Fraud Suite** | Mobile-money fraud detection — locally resonant for Uganda | **SAFE** (monitoring) |
| 3 | **AML Typology Matrix** | AML risk-pattern coverage | **SAFE** (read-only) |
| 4 | **KYC (manual attestation + sanctions/PEP)** | Live: OFAC **sanctions/PEP screening** (fail-closed on a stale list) + identity verification by **human operator attestation** (`method=MANUAL_ATTESTATION`; allowlist `["none","manual"]`). **NOT "agentic"** and **NOT automated NIRA** — both the 4-agent workforce (`193a400`) and automated NIRA national-ID lookup are **roadmap, not in this build** (`routes.ts:10221` explicitly stamps "NOT an automated NIRA register match"). Do not present agentic KYC *or* automated national-ID verification on stage. | **REMOVED FROM DEMO 2026-07-24** |
| 5 | **Insider Threat Pack** | Insider-behaviour monitoring — a key AEGIS angle | **SAFE** (monitoring) |
| 6 | **Regulator Observer** | "The regulator sees this in real time" — the BoU hook | **SAFE** (monitoring) |
| 7 | **Compliance Score** | One number for "are we compliant?" (PDPO) | **SAFE** (monitoring) |
| 8 | **Audit Logs** | Immutable, tamper-evident trail (mention Audit Chain integrity) | **SAFE** (read-only) |
| 9 | **Resilience Monitor** | Uptime / failover — sovereign resilience story | **SAFE** (monitoring) |
| 10 | **Privileged Access (JIT)** | Just-in-time admin control — *the path we just prod-verified* | **SHOW-DON'T-TOUCH** (action) |

**Regulator-weighted variant:** for an audience leading on AI accountability, swap in an **AI
Governance** beat — **Explainable AI** or **AI Model Cards** (both **SAFE**, read-only) — e.g. in place
of #5 or #9. This is exactly why AI Governance earned its own group: it's a live selling point.

**Deliberately CUT from the demo path (and why):**
- **All Drills / Simulations** — impressive to engineers, but they dilute the exec narrative and most
  are trigger pages risky to run live. They live in the Drills Hub, not the pitch.
- **Wave-8/9/10/11/13** — internal milestone dashboards; meaningless to a bank audience.
- **Deep-tech engines** (Ghost Core, Gulu Mesh, BFT Console, PQC…) — fascinating but
  technical-due-diligence material; reserve for the separate investor "Deep-Tech Showcase" view, not
  the compliance/fraud story a bank *buyer* wants.
- **Commercial / Investor** (Revenue Analytics, Investor Pitch, Series B Roadmap, Data Room) — wrong
  audience for a bank security demo.
- **Platform infra** (Infrastructure, FinOps, Rate Limits…) — operator-detail.
- **Sanctions/PEP, BoU Reporting Pack, Audit Chain verify** — strong content but **action** pages;
  show them as pre-generated views or as backup slides rather than exercising them live.

---

## 5. What happens next (HELD at paper — no code yet)
**Status: held at paper for one more look (operator, 2026-06-11).** Decisions 1–3 above are baked in.
When you release the hold:
1. Resolve any remaining §3.2 straddlers you care about, and confirm the §3.1 hubs + the §3.3
   archive-as-de-nav. Anything you don't flag, I take my primary call.
2. Then a **light** frontend cycle editing **only** `app-sidebar.tsx` grouping/ordering (+ "hub"
   wrapper pages if you approve consolidation — the slightly-heavier piece), proven to touch no
   routing/page-logic and nothing in the regulated code, with a clean boot-check after.
3. The bank demo-path and the investor "Deep-Tech Showcase" are **curated views layered on top** — not
   part of the operator-nav change; they can be built as a later, separate step.

---

## 6. Implementation & decision record (2026-06-11)

Hold released; the light frontend cycle of §5 was implemented. Scope held to `app-sidebar.tsx`
grouping + two new hub pages + their routes — no page logic, no routing changes to existing pages,
nothing in regulated server code.

### 6.1 What shipped
- **7 job-based groups**, rendered by a single data-driven loop over a `navGroups` table (the five
  legacy `*NavItems` arrays are preserved as the item pool; groups reference items by URL).
- **2 hub pages** — Drills Hub (`/drills-hub`) and Regulator Hub (`/regulator-hub`) — collapsing the
  drills/exercise and regulator-engagement clusters into one menu entry each. Member pages stay
  route-reachable; the hubs are grids of links.
- **"Unsorted" safety net** — any pool item not placed in a group/hub/archive falls into a visible
  "Unsorted" group rather than vanishing. **Verified empty** (all 183 pool URLs accounted for:
  group-placed + hub members + archived).

### 6.2 Wave cross-check verdict (the §3.3 question, answered with evidence — not name-guessing)
A per-suite code cross-check (not name inference) split the five Wave suites:
- **Wave-8 / 9 / 10 → SUPERSEDED.** Concrete dead-scaffolding signals: `Math.random`-driven simulated
  load tests, hardcoded pass/fail scenarios, static OWASP findings. Their real function now lives in
  Wave-11/13 + the report-scheduler.
- **Wave-11 (Pilot-Readiness) → LIVE.** Builds real forensic ZIP bundles from actual logs, real SLA
  evaluation, wired into the active pilot-pack-scheduler.
- **Wave-13 (Sandbox Closer) → LIVE.** Real database erasure drills (`DELETE … RETURNING`), driven by
  the report-scheduler daily sweep.

### 6.3 Operator decision (2026-06-11): "please archive"
- **Wave-8/9/10 ARCHIVED (de-nav only).** Removed from the menu; **pages NOT deleted and routes NOT
  touched** — still reachable by URL. Listed in `ARCHIVED_URLS` in `app-sidebar.tsx` so the Unsorted
  safety net does not pull them back in.
- **Wave-11 / Wave-13 KEPT VISIBLE**, re-homed by function into the Compliance & Regulatory group.

### 6.4 Revival path (how to undo the archive)
Reversible in one line: move a URL out of `ARCHIVED_URLS` and into the appropriate group's
`navItemsFor([...])` list in `app-sidebar.tsx`. No page or route work needed — the routes already
exist in `App.tsx` and were never removed.

### 6.5 Build note
A pre-existing latent trap surfaced during this cycle: `Map` was imported from `lucide-react` as an
icon, shadowing the global `Map` constructor that the new URL-lookup uses at module scope — this
crashed the whole app on load (`TypeError: Map is not a constructor`). Fixed by aliasing the icon
import to `MapIcon`. Clean boot verified after the fix.
