{"id":50453966,"url":"https://github.com/mizcausevic-dev/kg-governance-dashboard","last_synced_at":"2026-06-01T01:05:30.824Z","repository":{"id":358132727,"uuid":"1240136910","full_name":"mizcausevic-dev/kg-governance-dashboard","owner":"mizcausevic-dev","description":"Live procurement-reviewer-grade dashboard for the Kinetic Gain audit-stream spine. Tails SSE governance events, renders per-producer rolling counters, walks the hash chain, cites NIST AI RMF per event kind. Deploys to governance.kineticgain.com.","archived":false,"fork":false,"pushed_at":"2026-05-29T03:45:15.000Z","size":91,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-29T05:22:54.016Z","etag":null,"topics":["audit-stream","dashboard","governance","kinetic-gain","nist-ai-rmf","react","typescript"],"latest_commit_sha":null,"homepage":"https://governance.kineticgain.com/","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mizcausevic-dev.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-15T20:04:41.000Z","updated_at":"2026-05-29T03:45:19.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/mizcausevic-dev/kg-governance-dashboard","commit_stats":null,"previous_names":["mizcausevic-dev/kg-governance-dashboard"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/mizcausevic-dev/kg-governance-dashboard","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fkg-governance-dashboard","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fkg-governance-dashboard/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fkg-governance-dashboard/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fkg-governance-dashboard/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mizcausevic-dev","download_url":"https://codeload.github.com/mizcausevic-dev/kg-governance-dashboard/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fkg-governance-dashboard/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33755379,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-31T02:00:06.040Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["audit-stream","dashboard","governance","kinetic-gain","nist-ai-rmf","react","typescript"],"created_at":"2026-06-01T01:05:29.984Z","updated_at":"2026-06-01T01:05:30.809Z","avatar_url":"https://github.com/mizcausevic-dev.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# kg-governance-dashboard\n\n\u003e Live procurement-reviewer-grade dashboard for the Kinetic Gain audit-stream\n\u003e spine. Reads the same hash-chained governance log every other suite repo\n\u003e writes to.\n\n[![CI](https://github.com/mizcausevic-dev/kg-governance-dashboard/actions/workflows/ci.yml/badge.svg)](https://github.com/mizcausevic-dev/kg-governance-dashboard/actions/workflows/ci.yml)\n[![License: Apache 2.0](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](LICENSE)\n\n**Live at:** [governance.kineticgain.com](https://governance.kineticgain.com)\n\n## What it shows\n\nA procurement reviewer / CISO / district CIO opens one tab and can answer\nsix questions about a deployed AI system without leaving the page:\n\n1. **Is anything happening?** — flowing live timeline of every governance\n   event the stack emits, color-coded by severity, with relative timestamps\n   that update in place.\n2. **What's the trend?** — `Overview` tab shows KPI cards plus a 24-hour\n   events-per-hour stacked area chart and a top-10 event-kind distribution\n   bar chart, all derived from the same live event stream.\n3. **Which producer is doing what?** — `Producers` tab renders one large\n   card per producer in the spine, with mini bar charts per event kind +\n   last-seen highlight, color-coded by language ecosystem.\n4. **Is the chain intact?** — one-click `GET /verify` that walks the\n   audit-stream chain end-to-end and reports whether anyone has tampered\n   with the log. NIST AI RMF crosswalks inline.\n5. **Wake me up when X happens.** — in-browser configurable alert rules\n   (stored in localStorage, no auth, no backend) fire either by *match*\n   (any event with kind/source matching a regex) or by *threshold*\n   (N matching events within a rolling window). Hits surface as a\n   pulsing bell badge in the header; optionally a desktop notification\n   (one-click permission grant).\n6. **What's the story for vendor X?** — paste a domain into the vendor\n   filter on the Audit Trail tab and everything narrows to events whose\n   payload mentions that vendor.\n\nEvery event kind carries its [NIST AI RMF crosswalk](https://suite.kineticgain.com/docs/nist-rmf-crosswalk.md)\ncitation right next to it (MAP 2.2, MEASURE 2.5, MANAGE 1.2, etc.) so a\ncompliance reviewer never has to leave the page to map a governance moment\nto a framework subcategory.\n\n## Architecture\n\n```\naudit-stream-py     --SSE--\u003e     kg-governance-dashboard\n   /events/stream                  React 19 SPA\n                                   (deployed as static HTML/JS to a CDN)\n```\n\nPure SPA. Zero backend. Three runtime data sources:\n\n- `GET {AUDIT_STREAM_URL}/events?limit=50` — initial backfill on cold load.\n- `GET {AUDIT_STREAM_URL}/events/stream` — long-lived SSE for the live tail.\n  Browser auto-reconnects on drop; the UI shows the connection state.\n- `GET {AUDIT_STREAM_URL}/verify` — on demand, when the user clicks the\n  \"Verify the chain\" button.\n\nWhen `AUDIT_STREAM_URL` is unset the dashboard runs against a built-in\n**demo stream** that synthesises realistic events at ~1.5/sec across all\nnine known producer kinds. Visitors see a working dashboard even when\nthere's no real backend pointing at it yet.\n\n## Config\n\nThe audit-stream URL is loaded at **runtime** from `/config.js` so you\ncan repoint a deployed dashboard at a different backend without\nrebuilding:\n\n```js\n// public/config.js\nwindow.__KG_GOVERNANCE_CONFIG__ = {\n  AUDIT_STREAM_URL: \"https://audit-stream.your-domain.com\",\n};\n```\n\nLeave `AUDIT_STREAM_URL` as the placeholder `__AUDIT_STREAM_URL__` to\nstay in demo mode.\n\nCORS: your `audit-stream-py` instance must allow the dashboard's\norigin. The relevant CORS headers for `/events`, `/events/stream`, and\n`/verify` are `Access-Control-Allow-Origin: https://governance.kineticgain.com`\n(or `*` for the demo).\n\n## Producers in scope\n\nNine producers across two language ecosystems, 21 event kinds total.\nEvery one of these emits to the same `audit-stream-py` endpoint with\nthe same `{kind, source, payload}` envelope:\n\n| Producer | Lang | Event kinds |\n|---|---|---|\n| `procurement-decision-api` | Python | `decision_card_drafted` |\n| `aeo-validator-service` | Python | `watch_created`, `watch_drifted`, `watch_validity_flipped` |\n| `policy-as-code-engine` | Python | `policy_bundle_registered`, `request_allowed`, `request_denied` |\n| `data-contract-registry` | Python | `contract_promoted`, `contract_deprecated`, `contract_compatibility_failed` |\n| `slo-budget-tracker` | Python | `slo_burn_started`, `slo_recovered` |\n| `hash-attestation` | Rust | `attestation_signed`, `attestation_verified`, `attestation_failed` |\n| `incident-correlation` | Rust | `incident_correlated`, `incident_correlation_failed` |\n| `aeo-graph-explorer` | Rust | `graph_ingested`, `graph_ingest_failed` |\n| `reliability-toolkit` | Rust | `breaker_opened`, `breaker_recovered` |\n\n## Develop locally\n\n```bash\nnpm install\nnpm run dev       # vite dev server on http://localhost:5173\nnpm run test      # vitest run\nnpm run lint      # eslint (max-warnings 0)\nnpm run typecheck # tsc --noEmit\nnpm run build     # production build into dist/\nnpm run preview   # serve the production build locally\n```\n\n## Deploy\n\nThe repo ships with two GitHub Actions workflows:\n\n- `.github/workflows/ci.yml` — runs lint + typecheck + test + build on\n  every push, matrix on Node 20 + 22.\n- `.github/workflows/deploy.yml` — builds + FTPs `dist/` to `/governance/`\n  on every push to `main`. Configure repo secrets `FTP_HOST`, `FTP_USER`,\n  `FTP_PASS`.\n\nSame pattern as the other `*.kineticgain.com` properties.\n\n## Composes with\n\n- [audit-stream-py](https://github.com/mizcausevic-dev/audit-stream-py) — the upstream this dashboard subscribes to.\n- [audit-stream-prometheus](https://github.com/mizcausevic-dev/audit-stream-prometheus) — the sibling consumer that re-exposes the same events as Prometheus counters. This dashboard is the *human-facing* read-side; audit-stream-prometheus is the *machine-facing* one.\n- All 9 producers above — every one writes to `audit-stream-py` using the same opt-in `AUDIT_STREAM_URL` contract.\n\n## License\n\nApache-2.0. See [LICENSE](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fkg-governance-dashboard","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmizcausevic-dev%2Fkg-governance-dashboard","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fkg-governance-dashboard/lists"}