/home/techb158/cosmic.abdallabala.com/docs
Edit: /home/techb158/cosmic.abdallabala.com/docs/13-step-6-1-microsoft-planner-integration.md (2335B)
# Step 6.1: Microsoft Planner Integration
## Purpose
This step adds Microsoft Planner as a fourth project-management application in the shared COSMIC AI-Risk integration layer. Trello, Jira, Asana, and Microsoft Planner now use the same adapter interface.
## Planner mapping
| COSMIC AI-Risk object | Microsoft Planner object | Notes |
|---|---|---|
| Project | Plan | A plan belongs to a Microsoft 365 group in the live Microsoft Graph model. |
| Risk | Task | Each COSMIC risk can be represented as one Planner task. |
| Lifecycle phase | Bucket or progress state | The prototype stores this as external status. |
| Risk score | Category, description, or task details | The prototype stores this in field mapping metadata. |
| Mitigation action | Checklist item | Mitigations can be represented as checklist items on the task. |
| Evidence | Task reference or checklist evidence | Evidence is modeled as a traceable external reference. |
| Owner | Assignee | Live Graph integration would require Microsoft 365 user IDs. |
| Due date | Task due date | The prototype keeps the mapping metadata. |
## Implementation changes
- Added `Microsoft Planner` to `SUPPORTED_PM_PROVIDERS`.
- Added a seeded Microsoft Planner integration in `data/database.json`.
- Added provider-specific status mapping.
- Updated UI text and summary cards from three providers to four providers.
- Updated OpenAPI provider enums.
- Updated UML, use case, sequence, ER, and SQL artifacts.
- Updated API and integration workflow tests.
## Current boundary
The prototype does not call live Microsoft Graph. It creates deterministic local mappings and sync history. This is intentional for the academic prototype because it avoids OAuth configuration and keeps instructor testing simple.
## Production note
A live Microsoft Planner connector should use Microsoft Graph OAuth. Planner tasks are created inside plans, and plans are commonly contained by Microsoft 365 groups. Live update and delete requests must handle Microsoft Graph Planner etags.
## Acceptance criteria
- `/api/integration-providers` returns Microsoft Planner.
- `/api/projects/{projectId}/integrations` returns four integrations.
- Planner sync creates one external mapping per COSMIC risk.
- Planner mappings use `Task` as the external work-item type.
- Tests pass with `npm test`.