From discussion in the 7/28 Security Architecture meeting (with additional comments from Evan):
- The Personas page for individual roles is sort of a project-dump rather than providing some guidance about what problems that role may be looking to solve. I'm not sure if this is a new YAML file or fits in one of the existing files, but I don't see this data in the source content today.
- Feedback we heard from a few people was the personas don't necessarily intuitively identify the value of the problem solutions. We probably need to back up a little bit and do a better job explaining the risks that the problem solutions address. e.g. talking with Scala devs, they didn't understand the intrinsic value of signing & verification, but were willing to trust an expert from the OpenSSF because they were already working together. Explaining the risks could help bridge that credibility gap.
- I see we have some threats enumerated already (and @CRob has opinions here), but maybe a higher-level risk-focused version could be helpful, particularly if we don't end up with a dense matrix of every risk, every persona, every project.
From discussion in the 7/28 Security Architecture meeting (with additional comments from Evan):