/
home
/
techb158
/
cosmic-risk.abdallabala.com
/
docs
/
/home/techb158/cosmic-risk.abdallabala.com/docs
mkdir
upload
Name
Size
Mode
Actions
00-design-study.md
3678
0644
edit
dl
rm
01-uml-class-diagram.puml
11869
0644
edit
dl
rm
02-use-case-diagram.puml
3763
0644
edit
dl
rm
03-sequence-diagrams.puml
9732
0644
edit
dl
rm
04-database-entity-model.mmd
7051
0644
edit
dl
rm
05-database-schema.sql
13372
0644
edit
dl
rm
06-diagram-preview.html
5021
0644
edit
dl
rm
07-design-checklist.md
3256
0644
edit
dl
rm
08-step-2-storage-layer.md
5325
0644
edit
dl
rm
09-step-3-risk-crud-ui.md
3380
0644
edit
dl
rm
10-step-4-mitigation-workflow.md
3996
0644
edit
dl
rm
11-step-5-deployment-gate-workflow.md
2292
0644
edit
dl
rm
12-step-6-multi-pm-integration.md
3770
0644
edit
dl
rm
13-step-6-1-microsoft-planner-integration.md
2335
0644
edit
dl
rm
14-step-7-reporting-export.md
4158
0644
edit
dl
rm
15-step-7-1-oauth-live-connectors.md
4545
0644
edit
dl
rm
16-step-8-user-roles-access-control.md
3297
0644
edit
dl
rm
17-step-9-production-deployment-security.md
4228
0644
edit
dl
rm
18-step-10-final-academic-submission.md
3199
0644
edit
dl
rm
19-final-report-draft.md
6814
0644
edit
dl
rm
20-instructor-submission-checklist.md
3639
0644
edit
dl
rm
21-demo-script.md
3948
0644
edit
dl
rm
22-traceability-matrix.md
4847
0644
edit
dl
rm
23-testing-evidence.md
2961
0644
edit
dl
rm
24-evaluation-rubric-mapping.md
2910
0644
edit
dl
rm
25-final-deployment-runbook.md
3214
0644
edit
dl
rm
26-known-limitations-and-future-work.md
2632
0644
edit
dl
rm
27-final-qa-checklist.md
2893
0644
edit
dl
rm
28-demo-rehearsal-script.md
3618
0644
edit
dl
rm
29-submission-freeze-report.md
2769
0644
edit
dl
rm
30-final-known-issues.md
1876
0644
edit
dl
rm
31-saas-rebuild-implementation.md
2573
0644
edit
dl
rm
application-documentation.md
27515
0644
edit
dl
rm
conversation-log.md
18503
0644
edit
dl
rm
dashboard-spec.md
3691
0644
edit
dl
rm
database-guide.md
37826
0644
edit
dl
rm
development-summary.md
7070
0644
edit
dl
rm
github-architecture.svg
6288
0644
edit
dl
rm
integration-pull-push-plan.md
7384
0644
edit
dl
rm
Edit:
/home/techb158/cosmic-risk.abdallabala.com/docs/09-step-3-risk-crud-ui.md
(3380B)
# Step 3: Risk CRUD UI Workflow ## Purpose Step 3 connects the dashboard interface to the backend storage layer. Users can now manage risks and mitigation actions from the browser instead of using only API calls. This step implements the use cases defined in the design package: - Register AI risk. - Update AI risk. - Delete AI risk. - Add mitigation action. - Recalculate risk dashboard. - Evaluate deployment gate. ## Source alignment Source-derived concepts used by this step: - AI risk must be measurable. - Risk dimensions are organizational, technical, and human. - Indicators, evidence, and interpretation rules support risk assessment. - The software prototype should expose a REST API and integrate with project-management workflows. Implementation extensions added by this step: - Browser-based create, edit, delete forms. - Score preview in the risk form. - Action buttons inside the risk register. - Toast notifications. - Gate evaluation button. - API workflow test. ## User workflows ### Create risk 1. User opens the Risk register page. 2. User clicks Add risk. 3. User enters title, dimension, domain, lifecycle phase, probability, impact, detectability, owner, status, approval state, due date, and evidence. 4. UI displays a score preview. 5. User saves. 6. API creates the risk in `data/database.json`. 7. Dashboard reloads and recalculates scores, top risks, lifecycle counts, and gate status. ### Edit risk 1. User clicks Edit in a risk row. 2. Existing risk values are loaded into the form. 3. User changes values. 4. API updates the risk. 5. Dashboard reloads and recalculates. ### Delete risk 1. User clicks Delete in a risk row. 2. UI asks for confirmation. 3. API deletes the risk and linked score, mitigation, evidence, and Trello mapping rows. 4. Dashboard reloads. ### Add mitigation 1. User clicks Mitigate in a risk row. 2. User enters mitigation title, owner, status, progress, effectiveness, due date, and description. 3. API creates the mitigation action. 4. Dashboard reloads. 5. Residual risk is recalculated from mitigation progress and effectiveness. ### Evaluate deployment gate 1. User opens the Deployment gate page. 2. User clicks Evaluate and persist gate. 3. API calculates the gate status. 4. API stores gate, criteria, decision, and risk score records. 5. Dashboard reloads. ## Files changed - `public/index.html` - `public/app.js` - `public/styles.css` - `server.js` - `package.json` - `README.md` - `openapi.yaml` - `tests/api-workflow.test.js` ## Acceptance criteria | Check | Expected result | |---|---| | Add risk | Risk appears in the risk register after saving | | Edit risk | Changed fields persist after reload | | Delete risk | Risk is removed and dashboard total decreases | | Add mitigation | Mitigation count appears and residual score recalculates | | Evaluate gate | Gate result is persisted to the JSON database | | Tests | `npm test` passes risk engine, storage, and API workflow tests | ## Test result ```text All COSMIC AI-Risk engine tests passed. All COSMIC AI-Risk storage layer tests passed. All COSMIC AI-Risk API workflow tests passed. ``` ## Development note This is still a prototype storage design. The JSON database is acceptable for Step 3 because it preserves traceability and keeps the domain model visible. A later step should move this structure to SQLite or PostgreSQL.
Save
cmd:
run