The Idea Pipeline
How new offering ideas get scored, promoted, or set aside — so resources follow evidence.
New ideas are cheap. Engineering time is not. Every candidate offering goes through the same scorecard. It earns promotion with evidence, or it waits in the backlog with its reasoning saved — so settled calls never get reopened.
The App Build Qualifier
Every build idea is scored on five weighted criteria (0–5 each, from discovery questions) before it gets resources:
| Criterion | Weight | What it measures |
|---|---|---|
| Pain | 0.30 | Operational problems, manual effort, engineers affected |
| Cost | 0.25 | Engineer-hours consumed, licensing overruns, downtime dollars |
| Risk | 0.20 | Compliance exposure, SLA breaches, outage potential |
| Status quo | 0.15 | Cost and fragility of the current workaround |
| Urgency | 0.10 | Renewal dates, mandates, allocated budget |
| Weighted total | Decision |
|---|---|
| 3.5 – 5.0 | Build it — complete the app spec and select a managed-service tier |
| 2.0 – 3.4 | Qualify further — run a deeper discovery on the lowest-scored criteria |
| 0.0 – 1.9 | Pass — archive and revisit in 90 days |
A GO decision also picks a managed-service wrapper tier (Standard / Enhanced / Premium) with its SLA, deployment model, and pricing.
The scored portfolio
The two committed products came out on top. Everything else is backlog. It waits for a real decision, for incubation, or for the set-aside list below.
| Idea | Score | Status |
|---|---|---|
| Health-Check AI | 4.55 | Shipped as X10 Dividend |
| Token Tracker / Token Cop | 4.30 | Caveated Phase 2 candidate — vendor-neutral AI-spend observability (#108) |
| Pipeline Topology Mapper | — | Backlog — CLI maps data flow source to destination for audits and migrations (#109) |
| GoatOptimize | 4.30 | Folds into agentic delivery unless a customer asks |
| Alert Fatigue Assassin | 3.95 | Archived — Splunk AI Assistant 2.0 covers it natively |
| Medallion Mapper | 3.80 | Incubate |
| Config Audit Bot | 3.75 | Runtime-AI risk; incubate only |
| Prompt Firewall | 3.60 | Incubate with AI governance, never standalone |
| GoatRoute | 3.55 | Runtime-AI risk; hold |
| Runbook Generator | 3.50 | Incubate as a managed-service attach |
| CIS Compliance Whisperer | 3.40 | Qualify further; mature GRC competition |
| Collector Forge | 3.35 | Qualify further; Cribl roadmap risk |
| SOW Accelerator | 2.75 | Internal-use first |
| Telemetry Data Co-op | 2.10 | Deferred; regulatory and data-access risk |
Promotion rule
A backlog idea moves onto a worklist only when all five hold:
- A decision is recorded in the decisions register.
- A named owner accepts it.
- A customer or internal-delivery use case gives evidence.
- There is a clear answer to "what if the vendor builds this in?"
- It offers unique value beyond X10 Dividend, Vizzy, or agentic delivery.
Set aside, with reasoning preserved
Prompt Firewall
What it was: A gateway between customer users and outside LLMs. It strips PII, secrets, and injection attempts before a prompt leaves the company.
Why it was proposed: Companies worry about engineers pasting API keys or customer data into public AI tools.
Why it is set aside: Cloudflare (AI Gateway), Microsoft, and Palo Alto Networks build this right into enterprise network gear. Competing with big security vendors on a firewall product is not where VisiCore's value lies.
GoatRoute
What it was: LLM-generated Cribl routing logic — JavaScript and regex rules from plain English.
Why it was proposed: Writing Cribl routing rules by hand is slow, specialized, and easy to get wrong.
Why it is set aside: This is a runtime-AI feature the platform already owns — Cribl Copilot covers it. An outside version would just copy the vendor, not add to it.
Alert Fatigue Assassin
What it was: SOC/NOC noise reduction — dedupe, correlate, and quiet alert noise without missing true positives.
Why it was proposed: Analyst burnout is real, and a missed breach buried in false-positive noise costs millions.
Why it is set aside: Splunk AI Assistant 2.0 with Agent Mode handles this on its own, built right into Splunk Enterprise Security. An outside tool would just copy a feature the platform already has.