This file identifies public project roles and responsibilities. It does not assert organization permissions that have not been confirmed by the project lead.
| Role | Account | Responsibilities |
|---|---|---|
| Project lead and release owner | @Vishnu2707 | Direction, final governance decisions, releases and organization administration |
| Co-project lead | @m-khan-97 | Engineering direction, security and enterprise-readiness, contributor coordination and project delivery |
| Co-project lead | @H-Sihan | Technical leadership, contributor coordination and project delivery |
| Scanner and playbook maintainer | @TFT444 | Azure scanner rules, remediation playbooks, tests and review |
| Scanner and compliance maintainer | @SHAURYAKSHARMA24 | Scanner rules, playbooks and compliance mappings |
| API and AI maintainer | @ritiksah141 | API, AI layer, CI/infra review and backend tests |
| Frontend maintainer | @vogonPrayas | Dashboard implementation and frontend review |
| Test maintainer | @parthrohit22 | Test suite and documentation review |
Path-specific review assignments are maintained in .github/CODEOWNERS.
Private security reports are coordinated using .github/SECURITY.md.
Before OpenShield claims the OpenSSF continuity criteria, the project lead must confirm that at least two people can perform issue administration, merge approved changes and publish a release if any one maintainer becomes unavailable. Public role assignment alone is not proof of administrative access.