AlphaSwarm Organization Audit
Status: internal draft generated from a read-only audit on 2026-07-14.
Intended publication target: Alpha-Swarm-ai/alphaswarm_docs, preferably under docs/internal/org-audit/.
This documentation centralizes the current AlphaSwarm repository map, architecture, deployment posture, identity model, AI/ML and agent ecosystem, operations guidance, and technical health assessment.
Evidence and scope
- Audited all 39 accessible repositories in the
Alpha-Swarm-aiGitHub organization as of 2026-07-14. Two repositories —alphaswarm_internalandalphaswarm_qap— were created afterward and are not covered by this audit pass (current org total: 41); see the agentic workflows enhancement plan, which does cover them. - Shallow-cloned repositories into session scratch for static inspection only.
- Reviewed repository metadata, README files, package manifests, GitHub Actions workflow files, Docker/Kubernetes/Helm/Terraform artifacts, security/auth markers, AI/ML markers, and open issue titles.
- Did not mutate GitHub, Kubernetes, Terraform state, Cloudflare, AWS, Helm releases, container registries, or live service configuration.
- Did not inspect or print secret values. Findings reference file paths, repository names, and issue titles only.
Document set
| Page | Purpose |
|---|---|
| Repository map | Canonical repo catalog, ownership domain, service role, branch/status, and traceability links. |
| Architecture | Global architecture model and Mermaid service-interaction diagrams. |
| Deployment and stack | Languages, frameworks, manifests, CI/CD, orchestration, and environment configuration. |
| Security and identity | AuthN/AuthZ, OIDC/JWT, Entra, WebAuthn, device identity, RBAC, RLS, and security gaps. |
| AI/ML and agent ecosystem | Agent runtime, LLMOps, MLOps, model/eval/RL/knowledge flows, and training/inference diagrams. |
| Operations guide | Usage, admin workflows, deployment operations, observability, and troubleshooting runbooks. |
| Technical health | Current service status, issue-derived debt, critical gaps, and prioritized follow-up plan. |
| Agentic workflows enhancement plan | Gap analysis, workstreams, and measurement program for agentic development workflows across the estate (2026-07-19; governing decision: ADR 030). |
Architecture domains
AlphaSwarm is organized around seven practical domains:
- Hosted platform and edge —
alphaswarm_platform,alphaswarm_api,alphaswarm_controller,alphaswarm_config,alphaswarm_core,alphaswarm_local,alphaswarm_worker. - User and staff surfaces —
alphaswarm_ui,alphaswarm_website,alphaswarm_client,alphaswarm_admin,alphaswarm_ide,alphaswarm_cli,alphaswarm_ops_console. - Identity and tenancy —
alphaswarm_auth, tenant router inalphaswarm_platform, controller auth APIs, Entra tenant-link flows, device/WebAuthn/CA flows. - Data and knowledge plane —
alphaswarm_data,alphaswarm_ingest,alphaswarm_catalog,alphaswarm_graph,alphaswarm_kb,alphaswarm_kb_federation,alphaswarm_index,alphaswarm_research. - Agent and bot runtime —
alphaswarm_agents,alphaswarm_assistant,alphaswarm_bots,alphaswarm_mcp,alphaswarm_orchestration. - AI/ML governance and execution —
alphaswarm_mlops,alphaswarm_models,alphaswarm_eval,alphaswarm_rl,alphaswarm_learning,alphaswarm_viz. - Observability, billing, and documentation —
alphaswarm_observe,alphaswarm_observe_js,alphaswarm_finops,alphaswarm_docs.
Top current risks
The strongest issue-derived risk themes are:
- Tenant isolation/RLS readiness: several open monolith issues reference missing RLS policies, context-less writers, and strict-mode rollout validation.
- Go-live readiness: platform, UI, IDE, MCP, and client repos have P0 go-live or production-hardening tasks.
- Boundary cleanup: generated artifacts, monolith imports, package-boundary drift, and stale docs need reconciliation.
- Test drift: multiple repos report failing tests or constructor/schema drift.
- Observability coverage: retrieval/federation/research paths still need additive spans and recall telemetry.
See Technical health for prioritized actions.