Legacy modernization review handoff
Move from static legacy evidence to owner questions without upgrading the claim.
This concept page gives managers, reviewers, architects, and engineers a public-safe handoff boundary. It carries deterministic static repository evidence into modernization review questions while keeping rule families, evidence tiers, coverage labels, limitations, proof paths, owners, allowed wording, and stop conditions attached.
Public claim level: concept. No public conclusion without evidence. The page is a review handoff, not a modernization decision, runtime telemetry report, migration tool, service ownership record, or release approval surface.
Static evidence can start the review; it cannot finish the modernization decision.
TraceMap public copy may say that a checked-in repository snapshot contains static evidence that raises a review question. The handoff stops there until a human owner brings the missing proof: runtime context, migration planning, service accountability, test strategy, or release governance. If a proof field is missing, the public wording must stay at question level with the limitation still visible.
Handoff matrix
Each modernization question keeps its proof fields and stop condition.
| Review question | Static evidence to bring | Required proof field | Limitation to keep attached | Owner to involve | Allowed wording | Stop condition |
|---|---|---|---|---|---|---|
| Framework/runtime age question | Project metadata, target framework clues, package files, generated-file hints, or toolchain diagnostics with rule ID/rule family and evidence tier. | Coverage label, proof path, commit SHA, and extractor version that show where the static clue came from. | Static age clues do not prove compatibility, support status, deployment state, or migration feasibility. | Architect, platform owner, and engineering lead. | Static repository evidence raises a framework/runtime review question. | Stop if the clue lacks rule context, tier, coverage label, or a limitation for reduced analysis. |
| Route/API question | Controller, route attribute, handler, service-reference, or syntax fallback evidence with path spans and rule family. | Evidence tier, proof path, coverage label, and owner question for source review. | Static route evidence does not prove live endpoint existence, reachability, production traffic, latency, or user behavior. | Service owner, API reviewer, and test owner. | Static evidence identifies a route/API review surface. | Stop if wording drifts into runtime behavior, endpoint performance, or operational safety. |
| Data surface question | ORM mapping, query-facing reference, data metadata, configuration shape, or Tier3SyntaxOrTextual clue without raw SQL or values. | Rule family, evidence tier, coverage label, proof path, and data-owner follow-up. | Static data clues do not prove database connectivity, execution, schema compatibility, permissions, or contents. | Data owner, application owner, and reviewer. | Static evidence raises a data surface owner question. | Stop if the handoff needs raw SQL, config values, connection strings, database contents, or hidden validation detail. |
| Package/dependency question | Manifest, project reference, package reference, lockfile, or dependency surface evidence with deterministic extractor context. | Rule ID/rule family, evidence tier, package proof path, and coverage label. | Static dependency evidence does not prove exploitability, compatibility, installability, runtime loading, or upgrade success. | Dependency owner, architect, and build owner. | Static evidence shows a dependency review item. | Stop if the claim implies package compatibility, vulnerability outcome, or migration success. |
| Config/deployment clue question | Checked-in project, config, environment-shape, publish-profile, or deployment clue summarized without raw values. | Static proof path, rule family, coverage label, and redaction confirmation. | Checked-in clues do not prove deployed state, active environment, secret validity, service binding, or release posture. | Deployment owner, security reviewer, and application owner. | Static evidence raises a config/deployment review question. | Stop if raw config values, private URLs, secrets, tokens, remotes, or local paths would be exposed. |
| Validation/reduced coverage question | AnalysisGap facts, failed project load labels, syntax fallback notes, unsupported file notes, or validation route context. | Coverage label, Tier4Unknown or weaker-tier explanation, proof path, and limitation text. | Reduced coverage is useful context, not a clean repository result and not absence-of-evidence proof. | Reviewer, build owner, and validation owner. | Analysis is partial and needs owner follow-up before stronger wording. | Stop if a failed build or partial scan is described as complete coverage or clean analysis. |
| Migration/test planning question | Static route, dependency, data, and validation clues bundled as planning inputs with limitations. | Proof paths, rule families, evidence tiers, coverage labels, non-claims, and owner questions. | TraceMap evidence does not choose migration tooling, guarantee migration success, replace tests, or approve release. | Manager, architect, test owner, release owner, and engineering lead. | Static evidence can seed a modernization review checklist. | Stop if the handoff becomes approval language, success language, or a substitute for tests and owner decisions. |
Boundary map
Keep TraceMap static evidence separate from decisions and operations.
Non-claims and stop conditions
The handoff stops before the evidence becomes a stronger claim.
- No runtime behavior, production traffic, endpoint performance, outage cause, release safety, operational safety, migration success, schema compatibility, database connectivity, database execution, raw data access, or complete coverage proof.
- No AI impact analysis, LLM analysis, embeddings, vector databases, prompt classification, autonomous review, autonomous approval, or replacement of human judgment.
- Do not publish raw facts, raw SQLite content, analyzer logs, raw source snippets, raw SQL, raw config values, secrets, tokens, connection strings, database contents, raw remotes, local paths, generated scan directories, private sample names, raw command output, private URLs, hidden validation details, or credential-like values.
- Stop when the proof path is missing, the evidence tier is unclear, the coverage label is reduced but unlabeled, the owner is unknown, the limitation is detached, or the wording would imply approval, execution, compatibility, or live behavior.