{
  "note": "Which fields are reported verbatim from Microsoft/upstream vs derived by the tracker. Derived fields are heuristic — see /methodology/.",
  "schemaVersion": 2,
  "source": {
    "roadmap": [
      "title",
      "description",
      "status",
      "products",
      "gaTarget",
      "targetDate",
      "cloudInstances",
      "platforms",
      "created",
      "modified"
    ],
    "msrc": [
      "title",
      "cve",
      "severity",
      "cvss",
      "products",
      "patchDate",
      "kb"
    ],
    "cisaKev": [
      "exploited",
      "kev",
      "kevDueDate"
    ],
    "firstEpss": [
      "epss"
    ],
    "graph": [
      "description",
      "ring"
    ]
  },
  "derived": {
    "impact": {
      "origin": "tracker",
      "rule": "exploited/critical/breaking/retiring → high; shipping/important → medium"
    },
    "urgency": {
      "origin": "tracker",
      "rule": "exploited-or-overdue → Immediate; near-deadline/breaking/retiring → Soon; else Monitor"
    },
    "classifications": {
      "origin": "tracker",
      "rule": "confidence-scored from source text w/ action-object detection; see /methodology/"
    },
    "deadline": {
      "origin": "tracker",
      "rule": "normalized from KEV due / retirement / deprecation / breaking / GA target; obligation only at high confidence"
    },
    "applies": {
      "origin": "tracker",
      "rule": "cloud/on-prem/hybrid from product SKUs + cloud instances"
    },
    "adminAction": {
      "origin": "microsoft",
      "rule": "verbatim source sentence selected by the tracker (action cue + date preferred)"
    },
    "editIntent": {
      "origin": "tracker",
      "rule": "edit type from the field-level diff"
    },
    "apiSummary": {
      "origin": "tracker",
      "rule": "counts + entity names parsed from the Graph changelog text"
    },
    "volatility": {
      "origin": "tracker",
      "rule": "edits/slips counted from the item's event history"
    }
  }
}