Source: qdash /teams — c67 expansion round, 2026-08-15
The lever strip is settled; this round widens the aperture: what additional data exists (or could cheaply exist), and what windows of insight it opens — including the less-defensible territory, explored honestly. Every window carries a tier, a named danger, and a persona. One line gets drawn on purpose. All schema claims verified against qcontrol source (db.rs · normalize.rs · web.rs) this session.
The schema knows more than the page
Five discoveries from reading the ingest and schema code — each one re-tiers windows we had filed as unbuildable.
Path, category (e.g. secret_file), severity, opens, first/last seen — normalize.rs projects sensitive file.opens into it. File-level sensitivity classification exists; only repo-level is missing.
unlocks: sensitive-touch surface ✓ · secret dwell context
agent_instances.quota_5h/quota_7d/quota_status from provider rate-limit metadata, with an explicit overage_rejected promotion. A capacity gauge nobody is reading.
unlocks: quota headroom / seat rightsizing ◐
metric · direction (at_most/at_least) · target · window · baseline · baseline_at. The budget object runway needs already exists, snapshotted baseline included.
unlocks: spend runway ✓ (was ◐)
Per-pack requirement rows with pending|attested, owner, reviewed_at. The maturity checklist has literal backend receipts waiting for a surface.
unlocks: maturity-as-checklist ✓ (was concept)
message/tool-call counts, durations, tool_kind (builtin|mcp|skill), reasoning tokens, cache read/write, runs.exit_code, egress TLS flags — and proc:<pid> entity ids marking observed-but-uninstrumented AI processes.
unlocks: practice profiles ◐ · shadow-process delta ✓ · friction tax ✓ · blowout ledger ✓
Twenty-one windows
| Window | The insight, spoken | Tier | Danger | For | Lives |
|---|---|---|---|---|---|
| Friction tax | "Support-Ops was denied 41 tool calls — 38 by one un-allowlisted MCP server" | ✓ | inverse Goodhart — pair with dividend | enablement · platform | focus card · controls (ship with dividend) |
| Policy dividend | "policy enforced 38 actions this week — enforced, never "prevented"" | ✓ | counterfactual phrasing | CISO · exec | controls · verdict line |
| Sensitive-touch surface | "core-banking agents opened 6 secret-class files — five were the same repo .env" | ✓ | privacy (paths at floor only) | CISO | focus card · controls |
| Shadow-process delta | "3 AI processes visible on instrumented machines are running outside instrumentation" | ✓ | small-N noise | CISO · platform | Coverage receipt · hygiene block |
| Secret dwell | "the same AWS key has appeared in prompts for 11 days — it lives in a dotfile" | ✓ | counterfactual temptation | CISO | /identity · focus card |
| Blowout ledger | "one ci-pool session cost $212 — 5% of the month in 40 minutes" | ✓ | session-splitting Goodhart | FinOps | Cost Center · Spend receipt |
| Unattended autonomy | "6 sessions ran unattended overnight with approval=never; 2 reached hosts first seen that night" | ✓ | privacy unless agent-framed | CISO | Auto lens · verdict line |
| Spend runway | "Research breaches its ceiling ~Aug 24 at the current 7d rate" | ✓ | label the projection, always | FinOps | verdict line on breach · Cost Center |
| Maturity checklist | "7 of 9 controls attested · coverage 91% · SLA held — receipts, not a number" | ✓ | composite temptation (someone WILL average it) | exec · CISO | overview card, not /teams |
| New-joiner ramp | "chen reached the team band on day 8" | ✓ | mild Goodhart · new-hire scrutiny | enablement · eng mgr | focus card |
| Bus-factor | "one person carries 71% of the team's tokens — say the ratio, never a Gini index" | ✓ | composite-in-disguise | eng mgr | focus-card sub-line |
| Harness currency | "4 machines run claude-code ≥3 versions behind fleet-max" | ✓ | staleness of the comparator | CISO · platform | hygiene block |
| Quota headroom | "Research's 5h bucket hit 94% by 2pm three days running — work is waiting on a quota" | ◐ | fabrication-by-sampling (print the reporting denominator) | FinOps · platform | focus card · Cost Center |
| Behavioral drift | "r.vance's codex ran 4× its baseline at 03:00, to a host first seen tonight" | ◐ | privacy · false-positive fatigue | CISO | alert + focus card (held for daily aggregates) |
| Practice profiles | "ML-Infra runs marathons (few, long, cache-heavy); Support-Ops runs Q&A (many, short)" | ◐ | privacy — team-level only | enablement | focus card interior |
| Posture regression | "d.reyes's codex ran approval=never for the first time; her previous 61 runs were sandboxed" | ◐ | privacy framing — config fact, not accusation | CISO | focus card · /identity |
| Offboarding risk | "an identity deactivated in the IdP ran 3 sessions yesterday" | ▲→✓ | none structural — gated on one read-only IdP call, not SCIM | CISO | verdict line · /identity |
| SCIM-day unlocks | "manager rollups, department views, joiner/leaver flows" | ▲ | scope creep into HR analytics | eng mgr | projected mocks |
| Outcome coupling | "what does a token buy — spend joined to shipped work" | ▲ | Goodhart · correlation-as-productivity | exec | separate page, never the strip (first rung: spend-per-repo) |
| Peer benchmarking | "your retention is p38 of orgs your size" | ✗ | fabrication — synthetic percentiles are the vendor fantasy | exec | nowhere without disclosed N |
| Prompt-topic mining | "what your people ask AI to do, classified" | ▲/✗ | privacy, maximal — THE DRAWN LINE | enablement · exec | nowhere yet — see the line below |
Explored, named, declined: prompt-topic mining
The most tempting window on the board: classify what people actually ask their agents to do (debugging vs boilerplate vs docs vs analysis) and profile team practice. Technically it's a small step — the DLP pipeline already reads message content. Socially it's a cliff: DLP reads content to protect the author; topic mining reads it to characterize them. The chilling effect — people self-censoring what they ask AI because the dashboard is watching — would suppress exactly the adoption qdash exists to make safe. Per-person, it's surveillance (✗). Team-level with k≥5 suppression and a published taxonomy, it's merely corrosive (▲).
The defensible cousin ships instead: practice profiles at repo grain — capture the git remote basename beside the cwd the agent already reads. "40% of ML-Infra's tokens go to the training repo" is a project fact, not a person profile — and it's the first honest rung of outcome coupling (spend per repo) with near-zero privacy cost.
Growth is depth, not width
Four to the roadmap, with faces
Same table (tool_calls decision/decision_source + egress_decisions), two lenses. Either alone is propaganda; the pair is receipts. ✓ today, zero capture work.
The campaigns table already holds target/window/baseline — no surface consumes it. A labeled linear projection, threshold printed: an argued estimate, not a fabricated series.
The Coverage lens finally gets what the portal law owes it: click the gap, land on the named machines and processes. All ✓ from existing inventory tables.
Sessions/day since first_seen against the team's steady band. The positive-direction window — the counterweight that makes the CISO windows socially survivable. ✓ today.