SASVA
Product Guide
SASVA Canvas 4.0.7
Persistent Systems
Product Documentation

SASVA Canvas β€” Product Guide

Capabilities, architecture overview, and product feature reference for SASVA Canvas.

Internal engineering & process documentation  β€’  Persistent Systems

SASVA Canvas

AI-Powered Product Planning & Business Intelligence Platform

165+
API Routes
25+
AI Agents
20+
Integrations
12+
Operations
3
Platforms

What is SASVA Canvas?

On-premise AI platform for product teams and business analysts β€” connect enterprise systems, run AI operations, and collaborate with multi-agent intelligence

πŸ”—

Enterprise Connectivity

JIRA, GitHub, GitLab, Azure DevOps, Bitbucket, ServiceNow, Confluence, SharePoint, Salesforce, HubSpot, Dynamics, Slack, SerpAPI β€” OAuth 2.0 PKCE with legacy fallback.

πŸ”’

Security & Compliance

Azure AD SSO, RBAC (4 roles), Ed25519 signing, PII masking, rate limiting, account lockout, AUDIT logging, tenant isolation, air-gapped bundles.

πŸ“

Workspaces

Product, Business, and Assessment workspaces β€” independent chat histories, connection slots, LanceDB indexing, sharing (Viewer/Editor/Admin).

πŸ€–

Multi-Agent RAG

Retrieval β†’ Verify β†’ Fact-Check β†’ Latest-Check β†’ role agents. Extended Thinking, citations, fast-path, streaming SSE.

πŸ“‹ Complete Platform Capabilities

  • βœ…
    Release Planning β€” Use cases β†’ EPICs β†’ stories β†’ SASVA or Advanced Estimation Engine β†’ publish to JIRA/Aha!/Asana/Azure DevOps. Planning drafts persist sessions.
  • βœ…
    8-Factor ROI β€” Deterministic NPV, IRR, TCO, payback. Revenue impact, cost reduction, retention, market position, strategic alignment, implementation cost, risk, customer demand. SSE streaming via /api/operations/roi-analysis/stream.
  • βœ…
    Code & Process Assessment β€” Assessment Portal (28 agents, 10 phases): complexity, hotspots, SAST, CVE, SBOM, developer profiling, portfolio reports. Modes: code, security, full.
  • βœ…
    Business Operations β€” Proposals, business analysis, meeting prep, presentations, customer analysis (CRM), competitive research with SerpAPI.
  • βœ…
    Document Intelligence β€” 16+ formats, Python processor (:3302), OCR (Tesseract + vision), 16 classifiers, spaCy NER, knowledge graph, 50K chunk cap per workspace.
  • βœ…
    Collaboration β€” Artifacts with comments, versions, collaborators, approval workflow. In-app notifications. Knowledge chat for follow-up on operation results.
  • βœ…
    Email & Feedback β€” Lifecycle emails (user, workspace, operations). Thumbs up/down. Help Center threads. Admin feedback CSV export.
  • βœ…
    Observability β€” 17 log categories, 6 levels, PostHog (~40 events), gateway telemetry v1.3, lifecycle dashboard, /api/admin/metrics.
  • βœ…
    Billing β€” Stripe + Braintree, Free/Starter/Professional/Enterprise, 24 feature keys, dunning, invoices, webhooks, 3D Secure.
  • βœ…
    Clients β€” Web (:3300), Desktop (Electron 33, ctx-code, safeStorage), Mobile (Expo, voice dictation, business workspaces).

Workspace Types

Product and Business workspaces β€” independent containers with dedicated connectors, operations, personas, and outputs

Each workspace has its own chat history, connection slots, indexed content, operation results, and team sharing. Workspaces are not nested β€” create one per product line, customer, or initiative. Limits per billing plan (Free: 1, Starter: 5, Pro: 20, Enterprise: unlimited).

πŸ’»

Product Workspace

For software development teams β€” release planning, code assessment, backlog, estimation, and ALM push-back.

Project types: Brownfield (existing product) Β· Greenfield (new product)

πŸ’Ό

Business Workspace

For business analysis β€” document RAG, proposals, CRM-aware research, market intelligence, and report generation.

Focus: Business vertical, customer-facing deliverables

πŸ“‹ Feature Comparison

DimensionProduct WorkspaceBusiness Workspace
Primary PersonasProduct Manager, Business Analyst, Architect, Developer, QA Engineer, Security Analyst, Program Manager, UX DesignerBusiness Analyst, Proposal Writer, Sales/Account Manager, Content Writer, Customer Success, Executive Sponsor
OperationsRelease Planning Β· Market Insights Β· ROI & Business Value Β· Backlog Assessment Β· Code Assessment Β· Process Assessment Β· Capacity Planning Β· Technical Debt Review Β· Security Review Β· Genesis DiscoveryCreate Proposal Β· Business Analysis Β· Meeting Preparation Β· Create Presentation Β· Customer Analysis Β· Competitive Research Β· Market Research (SerpAPI)
Connection SlotsprocessManagement β€” JIRA, Asana, Aha!, Azure DevOps, Monday.com
codeRepository β€” GitHub, GitLab, Bitbucket, Azure Repos, Local upload
ticketingSystem β€” ServiceNow, Zendesk, Freshdesk, JIRA Service Desk
documentation β€” Confluence, SharePoint, File Upload
documentSources[] β€” SharePoint (OAuth), Confluence (OAuth), Google Drive, Notion, Local Files, Website crawl
crmSystem β€” Salesforce, HubSpot, Zoho, Dynamics
communication β€” Outlook, Gmail, Slack, Teams
researchWebsites[] β€” URLs + SerpAPI
Indexing SourcesCode repositories (clone/local), connected documentation, PM tool exports, uploaded filesUploaded documents (16+ formats), connected drives, Confluence/SharePoint pages, website URLs, CRM records, pasted images (OCR)
Primary OutputsRelease plans Β· Use cases Β· EPICs & stories Β· Effort estimates Β· ROI reports Β· Backlog items Β· Code/process assessment reports Β· JIRA/Aha!/Asana/Azure DevOps exportsProposals Β· Business analysis reports Β· Meeting prep briefs Β· Presentation outlines Β· Customer insight reports Β· Competitive research reports Β· PDF/HTML/DOCX/PPTX exports
Push to ALM / CRMβœ… Publish release plan, push backlog items, push to JIRA β€” targets JIRA, Aha!, Asana, Azure DevOpsβœ… CRM read context (Salesforce, HubSpot, Dynamics) β€” outputs are documents/reports, not ticket push-back
Estimation Engineβœ… SASVA Models or Advanced Estimation Engine (:8100) β€” EPIC/story breakdown, effort estimation, sprint planningβ€”
Assessment Portalβœ… Code Assessment operation β€” connects to Assessment Portal (:9000) for code/security/full scan modesβ€”
Image / Diagram Genβœ… Mermaid diagrams, architecture diagrams, creative images in chatβœ… Creative images, diagrams, OCR on uploaded images
Knowledge Graphβœ… Entity resolution across code + docsβœ… Entity resolution across documents + web sources
Market Researchβœ… SerpAPI β€” trends, news, scholarβœ… SerpAPI + inline URL fetch
Sharingβœ… Viewer / Editor / Admin permissionsβœ… Viewer / Editor / Admin permissions
Separate Chat Historyβœ… Per workspaceβœ… Per workspace
Artifact Reviewβœ… Draft β†’ in_review β†’ approved workflow with comments & versionsβœ… Draft β†’ in_review β†’ approved workflow with comments & versions

πŸ”— Connection Slot Reference

Slot KeyProductBusinessAuth Mode
processManagementJIRA, Asana, Aha!, Azure DevOpsβ€”OAuth (Atlassian) or PAT/API token
codeRepositoryGitHub, GitLab, Bitbucket, Azure Repos, Localβ€”PAT / token
ticketingSystemServiceNow, Zendesk, Freshdeskβ€”Basic auth / API key
documentationConfluence, SharePoint, File UploadSharePoint, Confluence, drivesOAuth or legacy credentials
documentSources[]β€”SharePoint, Confluence, Drive, Notion, Local, WebsitePer-source OAuth/token
crmSystemβ€”Salesforce, HubSpot, Zoho, Dynamicssalesforce_oauth / microsoft_oauth
communicationβ€”Outlook, Gmail, Slack, TeamsOAuth / bot token
researchWebsites[]β€”Website URLsNone (public fetch)

πŸš€ Workspace Lifecycle

PhaseActivitiesSystem Actions
1 Β· Create & OnboardChoose type, name, project type (brownfield/greenfield), configure connection slotsPersist workspace blueprint; validate connector credentials via POST /api/connectors/test
2 Β· Index & SyncUpload documents or connect live sources; clone code reposDocument processor (:3302) extracts, classifies, chunks, embeds β†’ LanceDB; knowledge graph entities extracted; background clone for large repos
3 Β· OperateRun operations or chat with multi-agent RAGAgent orchestration, SSE streaming, artifact storage, email notifications on completion
4 Β· Review & AssignApprove artifacts, assign remediation workArtifact review workflow; optional push to JIRA/ServiceNow; planning drafts persist sessions
5 Β· Share & CollaborateInvite team members, comment on artifactsPOST /api/workspaces/[id]/share; in-app notifications; email on share events
6 Β· Steady StateMonitor health, re-index on source changesLifecycle dashboard metrics; GET /api/lifecycle/metrics; compliance audit export

AI Agents

25+ coordinated agents β€” retrieval & verification enrich every turn; role agents plan, estimate, and reason over backlog and codebase

Orchestration flow: B1 Data Agents (parallel: Document RAG, KG, Web, Fact) β†’ B2 Fetch Agent β†’ B3 Verification (parallel: Verify, Fact-Check, Latest-Check) β†’ B4 Synthesis (BA/PM/Architect) β†’ B5 LLM Response β†’ parallel: Suggestions | Report | Image. Fast-path bypasses full pipeline for casual queries.

πŸ“š Chat, Retrieval & Verification Agents

AgentImplementationFunction
Document RAG AgentLanceDB retrievalSemantic search across indexed workspace documents and chunks
Knowledge Graph Agentgraph-store.tsEntity/relationship lookup, cross-document connections, entity resolution (spaCy NER)
Web Search AgentSerpAPIReal-time web search for temporal/competitive queries (trends, news, scholar)
Fact Service AgentExternal verified KB URLPrioritized source-of-truth queries from curated knowledge base
Fetch Agentfetch-agent.tsBuilds RetrievedContext from query, chunks, metadata for verification
Verify Agentctx-code / SASVA Native CLIRelevance and sufficiency of retrieved context
Fact-Check Agentctx-codeCross-references claims against source documents
Latest-Check Agentctx-codeRecency and timeliness assessment of information
Knowledge AgentLLM reasoning layerReasoning over conversation context and retrieved information
Orchestratorrun-agents.tsRuns Verify + Fact-Check + Latest-Check in parallel

πŸ’» Product Development Role Agents

AgentFocusUsed In
Business AnalystMarket trends, competitors, ROI framingRelease planning, market analysis, ROI
Product ManagerUser needs, feature prioritization, roadmapRelease planning, backlog assessment
Program ManagerTimelines, dependencies, resource allocationRelease planning, capacity planning
ArchitectScalability, structure, technical trade-offsRelease planning, code assessment
DeveloperCode quality, effort signals, implementationCode assessment, estimation
QA EngineerTest strategy, coverage, quality risksRelease planning
Security AnalystRisk, compliance, security requirementsRelease planning, security review
UX DesignerExperience patterns, design considerationsRelease planning
Market Insights AgentTrends, competitors, innovations, analyst reportsMarket analysis, backlog assessment
Backlog Assessment AgentBacklog generation & prioritizationBacklog assessment
Technical Debt AgentCode quality, debt quantificationCode assessment
Security Review AgentVulnerability detection, complianceCode assessment (security mode)
Process Assessment AgentWorkflow optimization, delivery healthProcess assessment
ROI Analysis AgentDeterministic 8-factor NPV/IRR/TCO/paybackROI analysis (zero LLM for numbers)
Comprehensive ROI AgentMulti-dimensional ROI with streaming SSEROI analysis comprehensive mode

πŸ’Ό Business Workspace Agents

AgentFocusOperations
Proposal Writer AgentProposals, RFP responsesCreate Proposal
Business Analyst AgentSWOT, strategic planningBusiness Analysis
Meeting Prep AgentAgendas, talking points, customer backgroundMeeting Preparation
Customer Insights AgentCustomer profiling, opportunity scoringCustomer Analysis
Presentation AgentSlide outlines, storytellingCreate Presentation
Content Writer AgentEmail drafting, document formattingCreate Presentation, proposals

πŸ“Š Analysis, Formatting & Output Agents

Report Generation Agent

Executive-grade downloadable reports. PPT-canonical pipeline β†’ DOCX/PDF/XLSX/PPTX exports.

Formatter Agent

Canonical presentation β€” htmlPresentation, htmlExecutive, markdown with brand consistency.

Reviewer Agent

Automated quality review: Structure, Completeness, Tone, Density, Consistency, Accuracy, No duplicates (max 3 iterations).

Image Generation Agent

Creative images (DALL-E 3 / SASVA), architecture diagrams (LLM→JSON→Puppeteer), Mermaid flowcharts with provenance metadata.

βš™οΈ CLI-Backed Verification (ctx-code)

Verify, Fact-Check, and Latest-Check agents run via ctx-code / SASVA Native CLI. Configured in Settings β†’ AI Runtime (sasvaCli scopes: canvas, estimation, assessment). Desktop bundles platform-specific ctx-code binaries. Project overlay via cli.json.

Ecosystem Integrations

20+ connectors with OAuth 2.0 PKCE β€” connect enterprise systems for unified AI-grounded analysis

πŸ“‹ Integration Catalog

CategorySupported (Production)Planned / Expanding
Project ManagementJIRA, Asana, Aha!, Azure DevOpsMonday.com, Trello
Code RepositoriesGitHub, GitLab, Bitbucket, Local uploadAzure Repos, SVN
TicketingServiceNow, Zendesk, Freshdesk, JIRA Service Deskβ€”
DocumentationConfluence, SharePoint, File UploadNotion, Google Drive
CRMSalesforce, HubSpot, Zoho CRM, Microsoft DynamicsPipedrive
CommunicationSlackTeams, Outlook, Gmail
Market ResearchSerpAPI (Google Trends, News, Scholar)β€”
AssessmentAssessment Portal API (:9000)β€”
EstimationAdvanced Estimation Engine (:8100)β€”

πŸ” OAuth 2.0 Connectors (Recommended)

Modern connectors use OAuth 2.0 with PKCE. Tokens stored server-side per user/tenant connection ID β€” never in workspace JSON.

ProviderStart EndpointPurposeLegacy Fallback
Microsoft Entra/api/integrations/microsoft/oauth/startSharePoint, Dynamics 365Client credentials / app-only
Atlassian/api/integrations/atlassian/oauth/startJIRA Cloud, ConfluenceEmail + API token (PAT)
Salesforce/api/integrations/salesforce/oauth/startCRM delegated accessPassword grant
Browser MSAL/api/integrations/microsoft/register-from-browserMSAL browser flow registrationβ€”

πŸ“‚ Workspace Connection Slots

SlotProduct WorkspaceBusiness Workspace
processManagementJIRA, Asana, Aha!, Azure DevOpsβ€”
codeRepositoryGitHub, GitLab, Bitbucket, Azure Repos, Localβ€”
ticketingSystemServiceNow, Zendesk, Freshdeskβ€”
documentationConfluence, SharePoint, File UploadSharePoint, Confluence, Google Drive, Notion, Local
crmSystemβ€”Salesforce, HubSpot, Zoho, Dynamics
communicationβ€”Outlook, Gmail, Slack, Teams
documentSources[]β€”SharePoint (OAuth), Confluence (OAuth), Drive (service account), Notion (token), Local, Website (URL crawl)
researchWebsites[]β€”Website URLs for market research

πŸ”§ Integration Manager Classes

TypeClient / Integration ClassAuth Mode
JIRAJiraIntegration, JiraClientatlassian_oauth or PAT
GitHubGitHubIntegration, GitHubClientPersonal access token
GitLabGitLabIntegration, GitLabClientPersonal access token
BitbucketIntegration manager wrapperApp password / token
Azure DevOpsIntegration manager wrapperPAT
ServiceNowServiceNowIntegration, ServiceNowClientBasic auth
Aha!AhaIntegration, AhaClientAPI key
AsanaAsanaIntegration, AsanaClientPersonal access token
SalesforceSalesforceClient + OAuth token storesalesforce_oauth
HubSpotHubSpotClientAPI key / OAuth
DynamicsDynamicsClientmicrosoft_oauth
SlackSlackClientBot token

πŸ“€ Push-Back & Data Extraction

  • πŸš€
    Publish Release Plan β€” POST /api/operations/publish-release-plan β†’ JIRA, Aha!, Asana, Azure DevOps
  • πŸ“‹
    Push Backlog Items β€” POST /api/operations/push-backlog-items β†’ connected PM tools
  • 🎫
    Push to JIRA β€” POST /api/operations/push-to-jira β€” export release plan items
  • πŸ”—
    Extract Ecosystem β€” POST /api/extract-ecosystem β€” pull data from all connected systems
  • βœ…
    Connector Test β€” POST /api/connectors/test β€” validate credentials before save
  • πŸ“Š
    JIRA Release Items β€” GET /api/jira/release-items β€” fetch release items from JIRA

Operations

12 formal workspace operations plus extended capabilities β€” each grounded in workspace connections and multi-agent orchestration

πŸ’» Product Workspace Operations

OperationIDRequired ConnectionPrimary AgentsKey APIs
Release Planningrelease-planningProcess ManagementPM, Architect, Security Analyst, QA, UXgenerate-usecases, breakdown-epic, estimate-effort, publish-release-plan
Market Insightsmarket-analysisβ€”Market Insights Agent/api/market-research
ROI & Business Valueroi-analysisβ€”ROI Analysis, Comprehensive ROIroi-analysis, roi-analysis-v2, roi-analysis/stream
Backlog Assessmentbacklog-assessmentβ€”Backlog Assessment, Market Insightsgenerate-backlog, backlog
Code Assessmentcode-assessmentCode RepositoryTechnical Debt, Security ReviewAssessment Portal direct + /api/repository/clone
Process Assessmentprocess-assessmentProcess ManagementProcess Assessment Agentextract-ecosystem, PM tool APIs

πŸ’Ό Business Workspace Operations

OperationIDRequired ConnectionPrimary Agents
Create Proposalcreate-proposalβ€”Proposal Writer, Market Insights
Business Analysiscreate-business-analysisβ€”Business Analyst, Market Insights
Meeting Preparationcreate-meeting-prepβ€”Meeting Prep, Customer Insights
Create Presentationcreate-presentationβ€”Presentation, Content Writer
Customer Analysiscustomer-analysisCRM SystemCustomer Insights, Market Insights
Competitive Researchcompetitive-researchβ€”Market Insights, Business Analyst

πŸ”„ Extended Capabilities

CapabilityDescriptionAPI / UI
Discovery & Planning (Genesis)Embedded discovery iframe with workspace contextGET /api/runtime-config
Capacity PlanningTeam capacity and resource allocation narrativesPOST /api/operations/capacity-planning
Technical Debt ReviewMode within code assessment chatCode Assessment UI
Security ReviewSAST/vulnerability mode (code | security | full)Code Assessment UI
Image / Diagram GenerationDALL-E 3, Mermaid, architecture diagrams (LLM→JSON→Puppeteer)/api/workspace/generated-image
Report GenerationPDF, HTML, DOCX, PPTX, MD, XLSX, CSV β€” Formatter + Reviewer pipeline/api/documents/generate, /api/tools/generate-file
Lifecycle DashboardSDLC phase mapping, operation usage (7d/30d/90d/all)GET /api/lifecycle/metrics
Knowledge ChatFollow-up on Market Insights & ROI resultsPOST /api/knowledge-chat
Website ResearchInline URL analysis in chatPOST /api/research/website
Team CollaborationShare AI responses, comments, versions, approvals/api/workspaces/[id]/artifacts/*

πŸš€ Release Planning Flow (5 Steps)

1 Β· Use Cases

AI generates use cases from workspace context, connected PM data, and codebase.
POST /api/operations/generate-usecases

2 Β· EPIC / Story Breakdown

Break down use cases into EPICs and user stories.
POST /api/operations/breakdown-epic, breakdown-detailed

3 Β· Estimate

SASVA Models β€” new/greenfield projects.
Advanced Estimation Engine (:8100) β€” brownfield with cloned repo.
POST /api/operations/estimate-effort, /api/estimation/*

4 Β· Assign

Assignable users from connected PM tool.
GET /api/operations/process-management/assignable-users

5 Β· Publish

Push to JIRA, Aha!, Asana, Azure DevOps.
POST /api/operations/publish-release-plan, push-backlog-items, push-to-jira

πŸ’° ROI Analysis β€” 8 Factors

Deterministic scoring engine (zero LLM for numeric calculations). Factors: Revenue Impact, Cost Reduction, Customer Retention, Competitive & Market Position, Strategic Alignment, Implementation Cost, Risk Assessment, Customer Demand.

Outputs: ROI %, Payback (months), NPV, IRR, Annual Benefit, 3-year TCO, industry benchmark percentile. Scenarios: Conservative / Moderate / Optimistic. What-if levers and adjustable factor weights.

Chat & Collaboration

Streaming multi-agent chat with RAG, citations, extended thinking, PII masking, and workspace-grounded context

πŸ’¬ Chat Endpoints

ModeEndpointDescription
Workspace ChatPOST /api/workspace/chatSingle/multi-turn chat grounded in workspace documents, code, integrations
Streaming (SSE)POST /api/workspace/chat/streamToken-by-token delivery, source citations, agent progress events
Multi-AgentPOST /api/workspace/multi-agent-chatBA, PM, Architect collaborate with retrieval pipeline
Multi-Agent StreamPOST /api/workspace/multi-agent-chat/streamSSE streaming multi-agent collaboration
Knowledge ChatPOST /api/knowledge-chatFollow-up on Market Insights & ROI results (retry, resume, help, reset)
General ChatPOST /api/chatNon-workspace scoped chat

🧠 Intelligence Features

Extended Thinking

Visible AI reasoning ("Thought for Xs"). Enable via enableThinking: true. Reasoning blocks shown before final response.

Source Citations

Document, code, web, and knowledge-graph sources with chunk references. Agent verification reports via GET /api/workspace/agent-report.

Fast-Path Queries

Casual messages bypass full RAG pipeline for instant responses when no retrieval needed (web + desktop).

Stop Generation

Abort in-flight streaming via AbortController. Partial response preserved in chat history.

PII Masking

Business workspace: query-time redaction of EMAIL, PHONE, SSN, PAN, Aadhaar, CREDIT_CARD, IP, PERSON before LLM processing. Default ON.

Image & OCR

Upload/paste images in business chat. Tesseract OCR + vision model fallback. Image extraction in chat flow.

Voice Dictation

Mobile app speech-to-text via useVoiceRecording hook.

Inline URL Analysis

Website research in chat. POST /api/research/website for structured URL fetch and analysis.

Web Search Tool

LLM function calling via lib/tools/web-search.ts for real-time SerpAPI queries during chat.

File Generation

LLM tool β†’ /api/tools/generate-file for in-chat document creation. Download via /api/tools/download-file.

πŸ“œ Chat History, Indexing & Reports

FeatureAPI
Chat historyGET+POST /api/chat-history, GET+PUT+DELETE /api/chat-history/[id]
Message feedbackPOST /api/chat-history/[id]/feedback
Document uploadPOST /api/workspace/upload, POST /api/documents/upload
Index workspacePOST /api/workspace/index, GET /api/workspace/index-status
Customize reportPOST /api/workspace/customize-report
Derive formatPOST /api/workspace/derive-format
Generated imagesGET /api/workspace/generated-image
LLM providersSASVA (default), AWS Bedrock β€” Settings β†’ AI Provider

πŸ“‘ SSE Event Types

event: agent_start # Agent begins processing event: agent_progress # Retrieval/verification progress event: thinking # Extended thinking content event: token # Streaming text token event: sources # Citation sources attached event: done # Stream complete with conversationId event: error # Error with message

System Architecture

Five-layer on-premise architecture β€” clients, API, AI orchestration, platform services, data storage

SASVA Canvas deploys on-premise or air-gapped. Clients connect to Next.js (:3300) exposing 165+ API routes with SSE streaming, which orchestrates the AI agent layer, integration manager, document processor, and LanceDB/PostgreSQL stores. Data never leaves the organisation.

ClientsWeb (Next.js 14) Β· Desktop (Electron 33) Β· Mobile (Expo)
β†’
API Layer165+ routes Β· auth Β· RBAC Β· multi-tenancy Β· SSE
β†’
Agent Orchestrator25+ agents Β· retrieval Β· verification Β· synthesis
LLM ClientSASVA (default) Β· AWS Bedrock
+
Integration Manager20+ connectors Β· OAuth 2.0 PKCE
+
Document ProcessorPython FastAPI :3302
SQLite / PostgreSQLUsers Β· sessions Β· billing
+
File System.canvas-data/
+
LanceDBSharded vectors + knowledge graph

πŸ—οΈ Five Architecture Layers

1 Β· Client / Access Layer
Web AppNext.js 14 Β· browser Β· :3300
Desktop AppElectron 33 Β· PKCE SSO Β· ctx-code
Mobile AppExpo / React Native Β· :3301
Authenticationpassword Β· Azure AD SSO Β· session cookie
β–Ό
2 Β· Application & API Layer
Next.js App Router165+ REST routes Β· SSE streaming
Auth & RBAC4 roles Β· Ed25519 Β· rate limiting
Multi-Tenancytenant isolation Β· per-tenant settings
BillingStripe/Braintree Β· feature gating
β–Ό
3 Β· AI Orchestration Layer
Business Workspacedocument RAG Β· proposals Β· PII masking
Product Workspacecode Β· release planning Β· ROI Β· assessment
Agent OrchestratorRAG Β· KG Β· Web Β· Fact Β· Verify Β· Fact-Check Β· Latest-Check Β· BA/PM/Architect Β· ROI Β· Formatter/Reviewer Β· Image
β–Ό
4 Β· Platform Services Layer
LLM ClientSASVA Β· AWS Bedrock
Integration Manager20+ connectors (OAuth / API keys)
Document ProcessorFastAPI :3302 Β· OCR Β· NER Β· classify
Email ServiceSMTP Β· lifecycle notifications
Report & Image GenPDF/PPTX/DOCX Β· Mermaid Β· DALL-E
Assessment PortalExternal :9000 Β· 28 agents
Estimation EngineExternal :8100 Β· Advanced estimation
β–Ό
5 Β· Data & Storage Layer
Relational DBSQLite / PostgreSQL + PgBouncer
LanceDBsharded vectors (15 shards default)
Knowledge GraphJSON entity store per workspace
File System.canvas-data/tenants/{id}/

πŸ”Œ Services & Ports

ServicePortTechnologyNotes
Web App3300Next.js 14 / Node.jsWEB_PORT override
Mobile (Expo)3301React NativeDev server
Document Processor3302Python FastAPIRequired for RAG indexing
PostgreSQL5432PostgreSQLOptional (SQLite default)
Estimation Engine8100External serviceAdvanced estimation
Assessment Portal9000External serviceCode assessment API
Pipeline Events5050Event streamEstimation progress
Pipeline Visualizer5173Web UIEstimation progress UI

πŸ“ Project Structure

sasva-canvas/ β”œβ”€β”€ app/api/ # 165+ API route modules β”‚ β”œβ”€β”€ auth/ # Login, SSO, signup, permissions β”‚ β”œβ”€β”€ workspace/ # Chat, stream, index, upload β”‚ β”œβ”€β”€ workspaces/ # CRUD, share, artifacts, comments β”‚ β”œβ”€β”€ operations/ # Release planning, ROI, backlog, JIRA push β”‚ β”œβ”€β”€ billing/ # Stripe/Braintree subscriptions β”‚ β”œβ”€β”€ integrations/ # OAuth start/callback (MS, Atlassian, SF) β”‚ β”œβ”€β”€ assessment/ # Legacy proxies (mostly 410) β”‚ β”œβ”€β”€ estimation/ # Advanced Estimation Engine proxy β”‚ β”œβ”€β”€ email/ # SMTP config & notifications β”‚ β”œβ”€β”€ support/ # Help Center threads β”‚ β”œβ”€β”€ maintenance/ # Admin maintenance tools β”‚ └── lifecycle/ # SDLC metrics dashboard β”œβ”€β”€ components/ # React UI (chat, workflow, settings) β”œβ”€β”€ lib/ # Agents, integrations, LLM, billing, logging β”‚ β”œβ”€β”€ agents/ # 25+ agent implementations β”‚ β”œβ”€β”€ integrations/ # Integration manager + clients β”‚ β”œβ”€β”€ billing/ # Stripe/Braintree gateways β”‚ β”œβ”€β”€ logging/ # Structured logger (17 categories) β”‚ β”œβ”€β”€ telemetry/ # PostHog + gateway telemetry β”‚ └── privacy/ # PII redactor β”œβ”€β”€ services/document-processor/ # Python FastAPI :3302 β”œβ”€β”€ desktop-app/ # Electron 33 + ctx-code β”œβ”€β”€ mobile-app/ # Expo React Native └── .canvas-data/ # Runtime: DB, uploads, logs, shards

API Reference

165+ REST API route modules across 31 categories β€” authentication, workspaces, operations, billing, support, and more

Base URL: https://<deployment-host> (local: http://localhost:3300).
Auth: HTTP-only session_token cookie or Authorization: Bearer <token>.
Multi-tenant: X-Tenant-ID header when applicable.

πŸ“Š API Categories (31 Β· 165 routes)

CategoryRoutesKey Endpoints
System & health3GET /api/ping, GET /api/health/database, GET /api/runtime-config
Authentication11POST /api/auth/login, sso, signup, credential-key, permissions, studio-token
Users3GET+POST /api/users, GET+PUT+DELETE /api/users/[id], POST /api/users/[id]/approve
Tenants3GET+POST /api/tenants, GET+PUT+DELETE /api/tenants/[id], GET /api/tenants/public
Workspaces6GET+POST /api/workspaces, share, shareable-users, extract-process-management
Workspace AI & indexing11POST /api/workspace/chat/stream, multi-agent-chat/stream, index, upload, agent-report
Chat history3GET+POST /api/chat-history, PATCH /api/chat-history/[id]/feedback
General chat1POST /api/chat
Documents4POST /api/documents/upload, generate, parse, fetch
Operations & planning19roi-analysis/stream, generate-usecases, breakdown-epic, estimate-effort, publish-release-plan, push-to-jira, capacity-planning
Jira1POST /api/jira/release-items
Estimation8POST /api/estimation/breakdown, sync, events, status, results
Planning drafts4GET+POST /api/planning/drafts, estimations, fetch-results
Release plans2GET+POST /api/release-plans, GET+PUT+DELETE /api/release-plans/[id]
Assessment7POST /api/assessment/analyze (410 deprecated), check, status, events, results
Repository4POST /api/repository/clone, clone-background, pull, upload-local
Connectors & integrations9OAuth start+callback (MS/Atlassian/Salesforce), POST /api/connectors/test
Settings & system config4GET+PUT /api/settings, system-config, database config
Email3GET+PUT /api/email/config, logs, notifications
Artifacts & collaboration9Artifact CRUD, comments, collaborators, versions, review workflow
Billing & payments23plans, subscriptions, payment-methods, invoices, webhooks, cron, reports
Knowledge chat1POST /api/knowledge-chat
AI, LLM & tools5POST /api/llm/generate, agents/generate-questions, tools/generate-file
Research2POST /api/market-research, POST /api/research/website
Admin & notifications3GET /api/admin/metrics, feedback, notifications
Lifecycle analytics1GET /api/lifecycle/metrics
Support4GET+POST /api/support/threads, messages, unread
Maintenance6cleanup, database, files, logs, reindex, migrate-tenant-data, shards
Debug3GET /api/debug/env, database, index-status
Extract ecosystem1POST /api/extract-ecosystem
Development-only1POST /api/dev/test-image-extract

πŸ”‘ Authentication Patterns

  • πŸͺ
    Session cookie β€” HTTP-only session_token (opaque server-side token, not JWT)
  • πŸ”
    Bearer fallback β€” Authorization: Bearer <token> for API clients
  • πŸ”’
    Encrypted credentials β€” RSA-OAEP client-side encryption via GET /api/auth/credential-key
  • ✍️
    Ed25519 signing β€” Cryptographic permission verification on session restore
  • πŸ‘€
    Role hierarchy β€” Super Admin β†’ Tenant Admin β†’ Analyst β†’ Viewer. 106 auth-required routes.

βš™οΈ Operations API Endpoints

EndpointPurpose
POST /api/operations/generate-usecasesAI use case generation for release planning
POST /api/operations/transform-to-usecasesTransform inputs to use cases
POST /api/operations/breakdown-epicEPIC β†’ stories breakdown
POST /api/operations/breakdown-detailedDetailed story/task breakdown
POST /api/operations/estimate-effortEffort estimation (SASVA or Advanced Engine)
POST /api/operations/generate-backlogGenerate backlog items
POST /api/operations/roi-analysisStandard ROI analysis
POST /api/operations/roi-analysis-v28-factor deterministic ROI
POST /api/operations/roi-analysis/streamStreaming ROI with per-item progress (SSE)
POST /api/operations/capacity-planningTeam capacity planning
POST /api/operations/publish-release-planPublish plan to PM tool
POST /api/operations/push-to-jiraExport items to JIRA
POST /api/operations/push-backlog-itemsPush to JIRA/Aha!/Asana/Azure DevOps
POST /api/operations/format-reportReport formatting via Formatter agent
GET /api/operations/ticketsFetch ticketing system data

⚠️ Error Response Format

{ "success": false, "error": "message", "code": "ERROR_CODE", "details": {} }

Setup & Deployment

Development quick start and production deployment for Ubuntu and RHEL β€” SASVA Canvas 4.0.7

πŸš€ Development Quick Start

# 1. Install dependencies npm install # 2. Configure environment cp .env.example .env # Edit .env β€” SASVA token, SerpAPI key, integration credentials # 3. Start all services ./sasva-canvas.sh start # Web: http://localhost:3300 | Mobile: :3301 | Doc Processor: :3302 # 4. First login β€” first user becomes Super Admin # 5. Configure Settings β†’ AI Provider, System Config, Email

🏭 Production Deployment (8 Steps)

  1. Install prerequisites β€” Node.js 18+ (v20 recommended), Python 3.11+, lsof, unzip; optionally PostgreSQL
  2. Transfer & unzip production bundle to install path (e.g. /opt/sasva-canvas); set ownership chown -R appuser:appgroup
  3. Set permissions β€” chmod +x sasva-canvas.sh
  4. Firewall β€” Ubuntu: ufw allow 3300/tcp 3302/tcp; RHEL: firewall-cmd --add-port=3300/tcp --add-port=3302/tcp --permanent
  5. Start β€” ./sasva-canvas.sh start; verify curl http://localhost:3300/api/ping
  6. First login β€” Super Admin credentials from SASVA support (secure channel)
  7. Configure Settings β€” AI Provider, tenancy, SMTP, database, Assessment Portal, telemetry, workspace types
  8. Rotate password β€” Change default Super Admin password immediately

πŸ’» Supported Platforms & Hardware

RequirementMinimumRecommended
CPU4 cores8 cores
RAM8 GB16 GB
Disk40 GB free100 GB+
Ubuntu20.04, 22.04, 24.0422.04 LTS
RHEL familyRHEL 8/9, Rocky, Alma, Oracle Linux 8/9RHEL 9

πŸ”Œ Services & Ports

ServiceDefault PortOverride
Web App (Next.js)3300WEB_PORT or PORT
Mobile (Expo)3301β€”
Document Processor3302DOC_PORT
PostgreSQL5432Optional (SQLite default)
Estimation Engine8100Settings β†’ Estimation
Assessment Portal9000Settings β†’ Assessment Engine
Pipeline Events5050Estimation progress stream
Pipeline Visualizer5173Estimation UI progress

πŸ“¦ Production Bundle Contents

PathDescription
sasva-canvas.shLauncher β€” start, stop, status, logs, restart, app-logs
web/Next.js standalone production build
doc-processor/Document Processor binary (Python FastAPI)
node/Bundled Node.js runtime (optional)
.canvas-data/Created on first run β€” DB, uploads, logs, tenant data
.sasva-runtime/PID files, service stdout/stderr logs

Build scripts: scripts/installer/build-production-bundle-ubuntu.sh, build-production-bundle-rhel.sh. Flags: --output-dir, --skip-doc, --skip-node.

βœ… Post-Install Settings Checklist

#SettingDefault / Notes
1My ProfileChange default Super Admin password
2AI ProviderSASVA Config Server URL, Token, Model (sasva-expert-model), Embedding (sasva-embedding-v1)
3System ConfigurationTenant mode (single/multi), organization name
4DatabaseSQLite (evaluation) or PostgreSQL (production) + optional PgBouncer
5Email (SMTP)Required for password reset and lifecycle notifications
6Assessment Portalhttp://localhost:9000 if using code assessment
7Estimation Enginehttp://localhost:8100 for Advanced Estimation
8TelemetryPostHog key/host, gateway telemetry URL (optional)
9Workspace TypesEnable per license: Market Research, Estimation, Assessment, Business, etc.
10OAuth / SSOAzure AD app registration, integration OAuth apps (see Security tab)

βš™οΈ systemd Service (Optional)

# /etc/systemd/system/sasva-canvas.service [Unit] Description=SASVA Canvas Platform After=network.target [Service] Type=forking User=appuser WorkingDirectory=/opt/sasva-canvas ExecStart=/opt/sasva-canvas/sasva-canvas.sh start ExecStop=/opt/sasva-canvas/sasva-canvas.sh stop Restart=on-failure [Install] WantedBy=multi-user.target

Configuration

Environment variables, settings files, OAuth/SSO setup, and configuration priority

πŸ”§ Core Environment Variables

# Server PORT=3300 NODE_ENV=production NEXT_PUBLIC_APP_URL=https://canvas.yourcompany.com # SASVA LLM (default provider) LLM_PROVIDER=sasva SASVA_SERVER_URL=https://infgw.accelerite.com SASVA_TOKEN=your-token SASVA_MODEL=sasva-expert-model SASVA_EMBEDDING_MODEL=sasva-embedding-v1 # AWS Bedrock (alternative) AWS_ACCESS_KEY_ID=AKIAXXXXX AWS_SECRET_ACCESS_KEY=xxxxx AWS_REGION=us-east-1 BEDROCK_MODEL=anthropic.claude-3-5-sonnet-20241022-v2:0 # Integration token encryption (required for OAuth) INTEGRATION_TOKEN_SECRET=min-16-characters-secret # Market Research SERPAPI_API_KEY=xxxxx # Logging LOG_LEVEL=INFO LOG_CONSOLE=true LOG_FILE=true

πŸ”— OAuth & SSO Environment Variables

ProviderVariablesScopes / Notes
Azure AD (login)AZURE_AD_CLIENT_ID, AZURE_AD_TENANT_ID, client secretopenid, profile, email, offline_access. Redirect: /auth/callback or /private/setting
Microsoft (integrations)AZURE_AD_CLIENT_ID, AZURE_AD_TENANT_IDSharePoint: Sites.Read.All, Files.Read.All. Dynamics: user_impersonation
AtlassianATLASSIAN_OAUTH_CLIENT_ID, ATLASSIAN_OAUTH_CLIENT_SECRETOAuth 2.0 3LO + PKCE for JIRA/Confluence
SalesforceSALESFORCE_OAUTH_CLIENT_ID, SALESFORCE_OAUTH_CLIENT_SECRETapi, refresh_token, offline_access

OAuth callback URIs (append to public base URL): /api/integrations/microsoft/oauth/callback, /api/integrations/atlassian/oauth/callback, /api/integrations/salesforce/oauth/callback, popup completion at /auth/integration-complete.

πŸ“ Settings Files

FileLocationContents
settings.json.canvas-data/tenants/{id}/LLM provider, model, embedding, feature flags, Assessment/Estimation URLs
database-config.json.canvas-data/SQLite or PostgreSQL connection settings
email-config.json.canvas-data/SMTP host, auth, notification toggles per event
system-config.json.canvas-data/config/Tenant mode, org name, branding, demo workspace toggle
billing_settingsDatabase tableStripe/Braintree gateway credentials (admin UI, not env vars)

βš™οΈ Configuration Priority

  1. Tenant settings.json β€” highest priority per-tenant overrides
  2. Environment variables (.env or system env)
  3. Default configuration β€” built-in defaults (model: sasva-expert-model, embedding: sasva-embedding-v1, assessment: :9000, estimation: :8100)

πŸ”Œ Integration Auth Modes (per workspace connection)

ConnectionOAuth FieldAuth Mode
SharePointmicrosoftConnectionIdmicrosoft_oauth
ConfluenceatlassianConnectionIdatlassian_oauth
JIRAatlassianConnectionIdatlassian_oauth
DynamicsmicrosoftConnectionIdmicrosoft_oauth
SalesforcesalesforceConnectionIdsalesforce_oauth
GitHub/GitLabβ€”Personal access token (PAT)
Google Driveβ€”Service account key JSON

Storage & Database

Data persistence, vector indexing, knowledge graph, and file storage architecture

πŸ’Ύ Database Options

SQLite (Default)

  • βœ…
    Embedded, zero external DB config
  • βœ…
    Per-tenant database files in multi-tenant mode
  • βœ…
    Automatic schema creation and migrations
  • βœ…
    Ideal for single-server evaluation deployments

PostgreSQL (Production)

  • βœ…
    Enterprise-grade with connection pooling
  • βœ…
    Optional PgBouncer (pgbouncer/ config)
  • βœ…
    Tenant-scoped rows in shared database
  • βœ…
    Configure via Settings β†’ Database or database-config.json

πŸ“ File System Layout

.canvas-data/ β”œβ”€β”€ tenants/{tenantId}/ β”‚ β”œβ”€β”€ settings.json # Tenant LLM & feature settings β”‚ β”œβ”€β”€ uploads/{workspaceId}/ # Raw uploaded documents β”‚ └── shards/shard-{NN}/ # LanceDB vector shards β”‚ └── vectordb/{workspaceId}/ β”œβ”€β”€ config/ β”‚ └── system-config.json # Platform-wide config β”œβ”€β”€ logs/ # Structured application logs β”‚ β”œβ”€β”€ {category}-{date}-v{N}.log β”‚ β”œβ”€β”€ audit/audit-{date}.jsonl β”‚ └── critical/ └── database-config.json .sasva-runtime/ β”œβ”€β”€ logs/ # Service stdout/stderr β”‚ β”œβ”€β”€ web-app.log β”‚ β”œβ”€β”€ doc-processor.log β”‚ └── mobile-app.log β”œβ”€β”€ data/graph/{ownerId}/{workspaceId}/ # Knowledge graph JSON └── pids/

πŸ” Vector Store (LanceDB)

PropertyValue
TechnologyLanceDB β€” sharded per tenant
Path.canvas-data/tenants/{tenant}/shards/shard-{NN}/vectordb/{workspaceId}/
Embedding modelsasva-embedding-v1 (default, via SASVA embedding server)
Chunk size1500 chars (processor default), 1000/2000 (JS fallback)
Max chunks/workspace50,000 (MAX_CHUNKS_PER_WORKSPACE)
ReindexPOST /api/maintenance/reindex or POST /api/workspace/index

πŸ•ΈοΈ Knowledge Graph

Entity and relationship extraction via spaCy NER during document processing. Stored as JSON at .sasva-runtime/data/graph/{ownerId}/{workspaceId}/. Queried by Knowledge Graph Agent for cross-document entity resolution and relationship lookup.

πŸ“„ Document Ingestion Pipeline

StepDetails
1 Β· ReceiveSave raw file to uploads/{workspaceId}/. Max 10 MB web upload, 500 MB via processor multipart.
2 Β· ExtractPython processor (:3302): pdfplumber, python-docx, openpyxl, python-pptx, BeautifulSoup, Tesseract OCR
3 Β· Classify16+ format classifiers (financial_data, invoice, sales_pres, etc.)
4 Β· HandleSpecialized handlers per document type
5 Β· GraphspaCy NER β†’ entities & relationships
6 Β· Chunk & EmbedIntelligent chunking β†’ SASVA embedding server
7 Β· IndexStore vectors in LanceDB shard for workspace

Additional index sources: SharePoint, Confluence, Google Drive, GitHub, CRM, tickets, Slack, websites β€” via workspace connection slots and POST /api/workspace/index.

Security

Authentication, authorization, data protection, and connector security β€” enterprise-grade by design

πŸ” Authentication Methods

MethodImplementationDetails
Email / PasswordPOST /api/auth/loginRSA-OAEP client-side encryption via GET /api/auth/credential-key. Signup requires admin approval.
Azure AD SSOMSAL + PKCEScopes: openid, profile, email, offline_access. Server validates ID token. Desktop uses Electron safeStorage.
SessionHTTP-only cookieOpaque session_token (not JWT). Bearer fallback for API clients. Configurable timeout/idle extension.
Password ResetEmail token flowPOST /api/auth/forgot-password, POST /api/auth/reset-password
Studio TokenPOST /api/auth/studio-tokenEmbedded app authentication
Account LockoutRate limiterFailed attempt tracking with lockout period

πŸ‘₯ Role-Based Access Control

RoleScopeCapabilities
Super AdminPlatform-wideAll tenants, system config, maintenance, destructive ops, billing admin, cross-tenant support
Tenant AdminSingle tenantUser management, AI provider, integrations, email config, tenant settings, feedback review
AnalystOwn + sharedCreate/manage workspaces, run operations, share workspaces, chat
ViewerShared onlyRead-only access to shared workspaces and artifacts

Workspace sharing permissions: Viewer (read), Editor (read + operate), Admin (full control including sharing). Ed25519 cryptographic signing on permissions and session restore. HMAC signature on auth endpoints.

πŸ”’ Data Protection

FeatureImplementationDetails
PII Maskingpii-redactor.tsQuery-time redaction: EMAIL, PHONE, SSN, PAN, Aadhaar, CREDIT_CARD, IP, PERSON. Business workspace chat (default ON).
Credential Maskingworkspace-credential-mask.tsAPI responses show β€’β€’β€’β€’β€’β€’β€’β€’ for stored secrets
OAuth Token StorageServer-side encrypted storesTokens never in workspace JSON. INTEGRATION_TOKEN_SECRET (β‰₯16 chars).
Encryption at RestElectron safeStorageDesktop credential encryption. AES-256-GCM for billing card tokens.
Tenant IsolationPer-tenant DB/files/logsMulti-tenant mode scopes all data by tenantId
Upload Validationupload-validation.tsFile type, size limits (default 10 MB web, 500 MB processor)
Email Domain Validationemail-domain-validator.tsTenant email domain restrictions
Audit LoggingAUDIT levelPII_MASKED events, sensitive operations in audit/*.jsonl
Report SigningEd25519Cryptographic report signing with client-side verification

πŸ”— Integration OAuth & SSO

Two auth layers: (1) User session β€” Microsoft Entra via MSAL; (2) Integration OAuth β€” popup to Microsoft/Atlassian/Salesforce β†’ encrypted refresh tokens per tenant/user.

ProviderOAuth StartUse CasesLegacy Fallback
Microsoft Entra/api/integrations/microsoft/oauth/startSharePoint (Sites.Read.All, Files.Read.All), Dynamics (user_impersonation)Client credentials
Atlassian/api/integrations/atlassian/oauth/startJIRA Cloud, Confluence (OAuth 2.0 3LO + PKCE)Email + API token
Salesforce/api/integrations/salesforce/oauth/startCRM delegated OAuth (api refresh_token offline_access)Password grant

Required: NEXT_PUBLIC_APP_URL (exact origin, no trailing slash). Callback URIs: /api/integrations/{provider}/oauth/callback, popup completion at /auth/integration-complete.

πŸ›‘οΈ AI Transparency & Responsible Use

  • πŸ“‹
    Input disclaimer β€” shown before first chat message in workspace
  • 🏷️
    AI-generated labels β€” on operation results and generated documents
  • πŸ“„
    Artifact review workflow β€” draft β†’ in_review β†’ changes_requested β†’ approved before download
  • πŸ“–
    Responsible Use page β€” AI limitations and appropriate use guidance

CLI Tools & Service Manager

sasva-canvas.sh β€” unified launcher for development and production deployments

πŸš€ Service Manager Commands

CommandDescription
./sasva-canvas.sh start [web|mobile|doc]Start services (all or specific). Web :3300, Mobile :3301, Doc :3302
./sasva-canvas.sh stop [web|mobile|doc]Stop services
./sasva-canvas.sh restartRestart all services
./sasva-canvas.sh statusService status and URLs
./sasva-canvas.sh logs [web|mobile|doc]Last 50 lines of runtime log
./sasva-canvas.sh logs-f [web|mobile|doc]Follow runtime logs in real-time
./sasva-canvas.sh app-logs [category] [lines]Structured application logs (e.g. app-logs api 100)
./sasva-canvas.sh app-logs-f [category]Follow structured logs (e.g. app-logs-f auth)
./sasva-canvas.sh app-logsList all application log files

πŸ”§ Utility Scripts

ScriptPurpose
scripts/installer/build-production-bundle-ubuntu.shBuild air-gapped Ubuntu production bundle
scripts/installer/build-production-bundle-rhel.shBuild air-gapped RHEL production bundle
scripts/migrate-shards.tsLanceDB shard migration
scripts/test-pii-redactor.tsPII redaction testing
scripts/load-tests/*Load testing (auth, chat, planning, file upload)
scripts/sasva-canvas-bundle.shBundle launcher wrapper
restart-server.shQuick dev server restart

πŸ€– ctx-code / SASVA Native CLI

Verify, Fact-Check, and Latest-Check agents run via ctx-code CLI. Configured in Settings β†’ AI Runtime with scopes: canvas, estimation, assessment. Desktop app bundles platform-specific binaries in desktop-app/ctx-code/. Project-level overlay via cli.json.

πŸ“¦ Production Bundle Flags

./build-production-bundle-ubuntu.sh --output-dir /path/to/output --skip-doc # Skip document processor binary --skip-node # Skip bundled Node.js runtime

Desktop Application

Native desktop experience β€” Electron 33 with full web UI parity and Azure AD SSO

πŸ–₯️

Electron 33 + electron-vite

Cross-platform desktop app (macOS DMG, Windows EXE, Linux AppImage) via electron-builder.yml.

πŸ”

Azure AD SSO (PKCE)

Native MSAL flow with Electron safeStorage for credential encryption. @azure/msal-browser integration.

🌐

Full Web UI Parity

All web workflows: release planning, ROI, assessments, lifecycle dashboard, billing, settings, artifact review, plan selection.

⚑

Fast-Path Queries

Casual messages bypass full RAG pipeline for instant responses.

🎯 Desktop Features

FeatureDetails
Bundled ctx-codePlatform-specific CLI binaries in resources/ for Verify/Fact-Check agents
OS notificationsElectron Notification API for operation completion
Native file dialogsOpen/save via IPC handlers
Connection statusBackend connectivity indicator in UI
Keyboard shortcutsuseKeyboardShortcuts hook
ViewsWorkspaces, all operation flows, settings, metrics, user-feedback, help, lifecycle, artifact-review, plan-selection

πŸ“¦ Build Commands

cd desktop-app # Bundle ctx-code into desktop-app/ctx-code/ first npm run dev # Development npm run package # All platforms npm run package:mac # macOS DMG npm run package:win # Windows EXE npm run package:linux # Linux AppImage

Mobile Application

React Native / Expo app for iOS and Android β€” business workspace focus with AI chat

πŸ“±

Platforms

iOS and Android via EAS cloud builds (dev/preview/production profiles).

πŸ’Ό

Business Workspaces

Create, list, and manage Business workspaces with full document access.

πŸ’¬

AI Chat

RAG-powered multi-agent chat with SSE streaming and Extended Thinking.

🎀

Voice Dictation

Speech-to-text via useVoiceRecording hook.

🎯 Mobile Features

FeatureDetails
AuthenticationEmail/password + Microsoft SSO
Document accessConnected document sources and uploaded files
Extended ThinkingVisible reasoning blocks in chat
Dark modeSupported
PostHog telemetryOptional analytics (disabled by default)
Secure storageExpo Secure Store for tokens
Real-time syncSame backend APIs as web (:3300)
State managementZustand + Expo Router navigation

Not in mobile (by design): Product workspace full parity, release planning workflows, desktop-only admin tools.

πŸš€ Development & Build

cd mobile-app npm install # Configure API in constants/app-config.ts # iOS Simulator: http://localhost:3300 # Android Emulator: http://10.0.2.2:3300 # Physical device: http://YOUR_IP:3300 npm start # Expo dev server (:3301) npm run ios # iOS Simulator npm run android # Android Emulator # Production builds npm install -g eas-cli eas login eas build --platform ios eas build --platform android

πŸ“¦ Tech Stack

TechnologyPurpose
React NativeCross-platform mobile framework
Expo SDK 51Development platform & build tools
Expo RouterFile-based navigation
ZustandState management
Expo Secure StoreSecure token storage

Code & Process Assessment

Deep intelligence from source code to strategy β€” Assessment Portal with 28 specialized agents and 10-phase pipeline

Architecture: Canvas frontend calls Assessment Portal directly (default http://localhost:9000). Canvas proxy routes (POST /api/assessment/analyze) return 410 Deprecated. Configure portal URL in Settings β†’ Assessment Engine.

πŸ”¬ Capability Groups

πŸ’»

Code & Developer Intelligence

Cyclomatic complexity, hotspot detection, AI-powered PR review, developer profiling, commit velocity, sprint cadence, throughput analysis.

πŸ›‘οΈ

Security & Compliance

CVE scanning across dependencies/containers, SAST anti-pattern detection, SBOM generation, license compliance, supply chain risk assessment.

πŸ“ˆ

Market & Org Intelligence

Competitive landscape analysis, org sentiment, geographic team distribution, reputation indicators, developer health metrics.

πŸ€–

AI Synthesis & Reporting

Cross-concern impact assessment, strategic recommendations, product classification, portfolio reporting across repositories.

βš™οΈ 10-Phase Assessment Pipeline

PhaseNameTasksModeAgents
1Repository Setup2SequentialClone, validate, index
2Code Analysis2ParallelComplexity, hotspots
3Security Analysis3ParallelCVE, SAST, SBOM
4AI Analysis1ParallelAI-powered code review
5Developer & Impact2ParallelProfiling, velocity
6Product Classification1SequentialStack categorization
7Project Aggregation10ParallelCross-repo metrics
8Insight Synthesis2ParallelStrategic recommendations
9Deep Research2SequentialMarket/org intelligence
10Reporting3SequentialHTML/PDF portfolio reports

28 specialized agents orchestrated via dependency-driven DAG for maximum parallel throughput. Multi-provider LLM for code review and research.

πŸ”— Assessment Portal API (Frontend β†’ Portal)

EndpointPurpose
POST /api/v2/analyzeStart analysis job
GET /api/v2/assessment/check/{repoName}Check existing assessment
GET /api/v2/jobs/{jobId}Job status
GET /api/v2/jobs/{jobId}/pipeline-tokenPipeline visualizer token
GET /api/v2/monitor/eventsReal-time SSE events
GET /api/v2/monitor/pipeline/{repoName}Pipeline progress
GET /api/repositories/{repoId}/insightsLegacy insights
/workspace/results/{repoId}/{repoId}_assessment_report.htmlHTML assessment report

πŸ“Š Analysis Types & UI Modes

Analysis Types

  • πŸ“Š
    ext_codeQualityAnalysis β€” complexity distribution
  • πŸ›‘οΈ
    ext_vulnerabilityAnalysis β€” dependency CVEs
  • πŸ”
    ext_sastAnalysis β€” static security testing
  • πŸ”§
    ext_techStack β€” technology detection
  • πŸ”₯
    int_hotspotAnalysis β€” code hotspots
  • πŸ“ˆ
    int_functionComplexityAnalysis β€” function-level
  • πŸ“œ
    int_repositoryHistoryAnalysis β€” git history
  • 🏷️
    int_commitClassificationAnalysis β€” commit types

Code Assessment UI Modes

  • πŸ’»
    Code β€” technical debt & quality themes
  • πŸ›‘οΈ
    Security β€” vulnerability/SAST review
  • πŸ”¬
    Full β€” comprehensive combined scan

Repository input: remote Git URL (POST /api/repository/clone), background clone with polling, or local upload (POST /api/repository/upload-local).

Observability & Logging

Structured logging, telemetry, admin dashboards, and diagnostic tooling β€” production-grade observability for on-premise deployments

πŸ“Š Log Severity Levels

LevelPriorityUse
DEBUG0Development tracing, verbose diagnostics
INFO1Normal operational messages
WARN2Degraded conditions, retries
ERROR3Failed operations
CRITICAL4System-critical failures (dedicated critical log)
AUDIT5Security/compliance β€” always recorded regardless of LOG_LEVEL

Environment: LOG_LEVEL (DEBUG dev / INFO prod), LOG_CONSOLE, LOG_FILE, LOG_COLORS

πŸ“‚ Log Categories (17)

CategoryTypical Contents
apiHTTP requests, responses, status codes, latency
product-wsRelease planning, ROI, backlog, estimation operations
business-wsProposals, presentations, business analysis operations
workspaceIndexing, RAG queries, document processing triggers
chatChat sessions, streaming events, conversation lifecycle
agentsMulti-agent orchestration, verify/fact-check rounds
authLogin, SSO, session, permission checks, lockouts
integrationsOAuth flows, connector tests, SASVA/Estimation/Assessment/SerpAPI calls
documentsUpload, parse, classify, chunk, embed pipeline
databaseDB queries, migrations, vacuum, health checks
settingsConfiguration changes, tenant settings updates
usersUser CRUD, approval workflow, role changes
tenantsTenant provisioning, isolation events
cacheCache hits/misses, invalidation
performanceTiming, throughput, resource metrics
securityPII masking events, credential access, rate limiting
systemStartup, shutdown, service health, maintenance

πŸ“ Log Locations & Retention

TypePathNotes
Runtime stdout.sasva-runtime/logs/web-app.logNext.js process output
Doc processor.sasva-runtime/logs/doc-processor.logPython FastAPI service
Mobile.sasva-runtime/logs/mobile-app.logExpo dev server
Structured app logs.canvas-data/logs/{category}-{date}-v{N}.logPer-category rotating files
Tenant-scoped.canvas-data/logs/tenants/{tenantId}/Multi-tenant isolation
Audit trail.canvas-data/logs/audit/audit-{date}.jsonlJSON Lines compliance log
Critical events.canvas-data/logs/critical/CRITICAL-level dedicated logs

Rotation: 5 MB or daily; 10 files per category (~50 MB cap). Gzip on service restart. Format: [TIMESTAMP] [LEVEL] [CATEGORY] [T:tenant] [U:user] [ACTION] MESSAGE | Meta: {...} | Duration: Nms

Logging and Monitoring Stack Enablement and Customer Responsibility

Purpose

The Logging and Monitoring Stack is provided as an optional operational capability to enhance observability, monitoring, troubleshooting, and operational reporting for the SASVA platform components, including Canvas and IDE deployments. This capability is not a mandatory prerequisite for the deployment or operation of the core SASVA product stack.

Customer Opt-In Requirement

Implementation and enablement of the Logging and Monitoring Stack within the customer environment shall be performed only upon the customer’s explicit decision to adopt the solution. The deployment of monitoring components, including but not limited to Prometheus, Grafana, Loki, Node Exporter, and/or Grafana Alloy, is considered an optional infrastructure enhancement beyond standard SASVA product deployment.

Customers may choose to:

  • Enable the complete Logging and Monitoring Stack.
  • Enable selected monitoring components based on their operational requirements.
  • Operate the SASVA platform without the optional Logging and Monitoring Stack.

The decision to implement or not implement this capability remains solely with the customer.

Infrastructure Dependency and Provisioning Responsibility

The Logging and Monitoring Stack requires dedicated infrastructure resources in addition to the resources allocated for the core SASVA platform components.

The customer is responsible for provisioning and maintaining the required infrastructure resources, including but not limited to:

  • Virtual Machines (VMs) or equivalent compute resources.
  • CPU, memory, and storage capacity.
  • Network connectivity and firewall configurations.
  • Backup and retention storage (if applicable).
  • Operating system and platform prerequisites.
  • High availability and disaster recovery configurations (where required).

Infrastructure sizing requirements may vary depending on factors such as:

  • Number of application instances being monitored.
  • Log generation volume.
  • Metrics collection frequency.
  • Data retention requirements.
  • Availability and performance objectives.

Ownership and Operational Responsibility

Where the Logging and Monitoring Stack is enabled, operational ownership of the underlying infrastructure remains with the customer unless otherwise agreed through a separate managed services engagement.

The customer is responsible for ensuring that adequate infrastructure capacity is available to support:

  • Metrics collection and retention.
  • Log ingestion and retention.
  • Dashboard visualization and reporting.
  • User access management and authentication.
  • Ongoing operational monitoring of the monitoring platform itself.

Summary

For audit and governance purposes, it is important to note that:

  • The Logging and Monitoring Stack is an optional add-on capability and is not part of the mandatory SASVA product deployment baseline.
  • Non-deployment of the Logging and Monitoring Stack by the customer does not constitute product deficiency or non-compliance of the SASVA platform.
  • Any limitations in monitoring, observability, alerting, log retention, troubleshooting visibility, or operational reporting resulting from the customer’s decision not to implement the Logging and Monitoring Stack shall be outside the scope of the SASVA product responsibilities.
  • The customer acknowledges that implementation of the Logging and Monitoring Stack requires additional infrastructure resources and associated operational support.

πŸ“‘ Telemetry & Analytics

PostHog Analytics

Settings β†’ Telemetry. ~40 named events: auth, workspace, chat, documents, integrations, errors. Session recording and autocapture disabled by default.

Gateway Telemetry

SDLC task telemetry spec v1.3 β€” async to external gateway. Token counts, timing, agent rounds, workspace context. Never blocks core workflows.

Platform Metrics

GET /api/admin/metrics β€” users, workspaces, conversations, DB stats, LLM token usage, billing summary.

Lifecycle Analytics

GET /api/lifecycle/metrics β€” SDLC phase mapping, operation/agent usage, backlog breakdown. Time ranges: 7d, 30d, 90d, all.

πŸ”§ CLI & Debug Commands

# Runtime service logs ./sasva-canvas.sh logs # All services (last 50 lines) ./sasva-canvas.sh logs web # Web app only ./sasva-canvas.sh logs-f # Follow in real-time # Structured application logs ./sasva-canvas.sh app-logs # List all log files ./sasva-canvas.sh app-logs api 100 # Last 100 API log lines ./sasva-canvas.sh app-logs-f auth # Follow auth logs # Admin maintenance GET /api/maintenance/logs # Log viewer (admin UI) GET /api/debug/env # Environment diagnostics GET /api/debug/index-status # Vector index health GET /api/ping # Liveness check GET /api/health/database # DB health

πŸ” Debug Quick Reference

InvestigateLog Category
HTTP/API errorsapi-*.log
Release planning, ROI, backlogproduct-ws-*.log
Proposals, business opsbusiness-ws-*.log
SASVA, Estimation, Assessment, SerpAPIintegrations-*.log
Login, SSO, sessionsauth-*.log
Indexing, RAG retrievalworkspace-*.log, chat-*.log
Multi-agent pipelineagents-*.log
Compliance auditaudit/audit-*.jsonl
Service crashes.sasva-runtime/logs/*.log

Email Notifications & User Feedback

Lifecycle email notifications, in-chat feedback, Help Center support threads, and in-app collaboration notifications

πŸ“§ Email Configuration

Configure in Settings β†’ Email (Super Admin / Tenant Admin).

SettingOptions / Details
SMTP PresetsGmail, Outlook/Office 365, SendGrid, Mailgun, Amazon SES, Custom
Auth typesnone, plain, login, oauth2 (XOAUTH2)
TLSPort 465 (implicit TLS) or 587/25 (STARTTLS)
Rate limitingConfigurable max/hour (default 100) and max/day (default 1000)
Global kill switchnotifications.enabled β€” disable all outbound email
Audit logLast 1000 sends; view via GET /api/email/logs
APIsGET+PUT /api/email/config, POST /api/email/notifications, POST /api/billing/email/send

πŸ”” Notification Categories (Toggleable Per Event)

CategoryEventsRecipients
User / AccountWelcome, pending approval, approved, deactivated, password reset/changed, account locked, admin approval noticeUser + tenant admins
SystemSystem alerts, maintenance noticesAdmins
WorkspaceCreated, updated, deleted, shared/invitation, source addedOwner / invitee; admins on create/delete; collaborators BCC on source added
OperationsStarted, completed, failedOperator; collaborators BCC on completed

Operation emails triggered for: Market Research, ROI Analysis, Generate Backlog, Publish Release Plan, and Breakdown Estimations.

πŸ‘ In-Chat Feedback

  • βœ…
    Thumbs up/down on assistant messages in workspace chat
  • βœ…
    API β€” POST /api/chat-history/[id]/feedback (values: positive, negative, null)
  • βœ…
    Admin console β€” Header β†’ User Feedback; filters by rating, workspace, user, date range
  • βœ…
    CSV export β€” GET /api/admin/feedback with enriched user/workspace context

πŸ’¬ Help Center & Support Threads

FeatureDetails
Create threadHelp Center β†’ Contact Support. Categories: feedback, suggestion, issue, question, other
Status workflowopen β†’ in_progress β†’ resolved β†’ closed
MessagesGET+POST /api/support/threads/[id]/messages
Unread badgeGET /api/support/unread in app header
Staff inboxTenant admins see tenant threads; super admins see cross-tenant with scope=admin

Support SLAs for customer-reported issues

These SLAs apply to issues that Canvas users raise to the platform support team (email, Help Center β†’ Contact Support, or the support channel). Support files a ticket for each request. All targets are expressed in hours. They do not apply to security-finding remediation or to other internal operational SLAs.

Priority is set when the ticket is triaged: Urgent, High, Normal, or Low. A target of 0h means no SLA is committed for that metric at that priority.

Reply metrics β€” how quickly we respond to a customer’s request.

SLA targetUrgentHighNormalLow
First reply time0.5h2h4h8h
Next reply time1h12h48h0h

Update metrics β€” how frequently we keep customers updated.

SLA targetUrgentHighNormalLow
Pausable update12h45h84h0h

Resolution metrics β€” how long we should take to solve a request.

SLA targetUrgentHighNormalLow
Requester wait time96h384h1080h0h

πŸ”” In-App Notifications (Artifacts)

Collaboration notifications for artifact comments, shares, and approval requests.

  • βœ…
    GET+PUT /api/notifications β€” list, mark read, mark all read
  • βœ…
    Stored in artifact_notifications table with unread count in header

Administration & Platform Management

Super Admin and Tenant Admin tools β€” users, tenants, billing, maintenance, privacy

πŸ‘₯ User & Tenant Management

  • βœ…
    User approval workflow β€” New signups require admin approval; first registrant becomes Super Admin. POST /api/users/[id]/approve
  • βœ…
    4 roles β€” Super Admin, Tenant Admin, Analyst, Viewer with server-side RBAC enforcement and Ed25519 permission signing
  • βœ…
    Multi-tenant mode β€” Single-tenant or multi-tenant; per-tenant data isolation; configurable email domain. GET+POST /api/tenants
  • βœ…
    Tenant settings β€” Per-tenant settings.json overrides for LLM, features, branding
  • βœ…
    Demo workspaces β€” Pre-configured Product/Business showcase instances; toggle in Settings β†’ Demo Workspaces

πŸ’³ Billing Plans & Entitlements

Stripe and Braintree payment gateways β€” hot-swappable via admin UI. Gateway credentials stored in billing_settings table (not env vars). AES-256-GCM card tokenization; 3D Secure / SCA for Stripe.

PlanTierPriceUsersWorkspacesKey Features
Free0$0/mo11Product workspace, release planning, market analysis β€” no Business, no integrations
Starter1$29/mo55+ ROI, code assessment, JIRA & GitHub β€” no Business workspace
Professional2$79/mo2020+ Business workspace, CRM, proposals, presentations, advanced estimation β€” no SSO
Enterprise3$199/moUnlimitedUnlimitedAll features, SSO, all integrations, priority support, custom branding
Feature KeyFreeStarterProEnterprise
product_workspaceβœ“βœ“βœ“βœ“
business_workspaceβœ—βœ—βœ“βœ“
release_planningβœ“βœ“βœ“βœ“
roi_analysisβœ—βœ“βœ“βœ“
code_assessmentβœ—βœ“βœ“βœ“
create_proposalβœ—βœ—βœ“βœ“
advanced_estimationβœ—βœ—βœ“βœ“
jira_integrationβœ—βœ“βœ“βœ“
github_integrationβœ—βœ“βœ“βœ“
crm_integrationβœ—βœ—βœ“βœ“
sso_accessβœ—βœ—βœ—βœ“
workspace_sharingβœ—βœ“βœ“βœ“

24 feature keys total. Billing APIs: /api/billing/plans, subscriptions, payment-methods, invoices, webhooks/stripe, webhooks/braintree, cron/process, reports. Subscription statuses: Active, Trial, Past Due (7-day grace), Cancelled. Dunning service for failed payments.

πŸ”§ Maintenance Tools (Super Admin)

ToolAPIPurpose
CleanupPOST /api/maintenance/cleanupBulk delete users, workspaces, indexes, uploads; complete reset
DatabaseGET+PUT+DELETE /api/maintenance/databaseDB health, vacuum, reindex, analyze, query viewer
FilesGET+PUT+DELETE /api/maintenance/filesData directory file browser
LogsGET+DELETE /api/maintenance/logsStructured log viewer and purge
ReindexGET+POST /api/maintenance/reindexVector index rebuild across workspaces
Tenant migrationGET+POST /api/maintenance/migrate-tenant-dataMigrate tenant data between shards
ShardsGET /api/maintenance/shardsLanceDB shard management

🀝 Collaboration & Artifacts

FeatureAPI
Artifact CRUD/api/workspaces/[id]/artifacts
Inline comments.../artifacts/[id]/comments
Collaborators.../artifacts/[id]/collaborators
Version history.../artifacts/[id]/versions
Workspace sharingPOST /api/workspaces/[id]/share β€” email + permission (viewer/editor/admin)
In-app notificationsGET+PUT /api/notifications β€” artifact comments, shares, approvals

πŸ“„ Document Processor Service

Python FastAPI on port 3302 β€” required for document upload and RAG indexing.

# Supported formats XLSX, XLS, DOCX, DOC, PPTX, PPT, PDF, HTML, JSON, MD, CSV, TSV, TXT Images: PNG, JPG, JPEG, GIF, WEBP, BMP, TIFF (Tesseract OCR + vision fallback) # Pipeline Extract β†’ Classify (16+ format classifiers) β†’ Specialized handlers β†’ Knowledge graph (spaCy NER) β†’ Chunk (1500 chars default) & embed β†’ LanceDB indexing # APIs GET /health POST /process # Base64 JSON (<20 MB) POST /process/upload # Multipart (up to 500 MB) POST /extract