Dependency Release Plan & Headcount Allocation
148 FTE requested to deliver the Hyperforce Foundation Platform + Core into the AWS Secret Region (LCK/IL6), released across four milestone-gated tranches over a 24-month horizon.
Executive Summary
148 FTE, released in four tranches gated on demonstrated milestones, funds Red Queen's uplift of the Hyperforce platform for delivery into an air-gapped AWS Secret Region. Product scope is still pending Mission Force ELT authorization as of Aug 19, 2026 — the 148 figure is subject to change.
Why it matters: Red Queen operates at a different classification level than Blackjack and cannot share infrastructure, tooling, or emulation vendors with it. That forces net-new investment in bootstrap/trust ("Inception"), a dedicated partition, GovCloud-run emulation, first-ever innerloop support, and day-1 paved-path parity with commercial Hyperforce.
Overview
Requested budget funds delivery of the Hyperforce Foundation Platform + Core into the AWS Secret Region (LCK/IL6). Costs are subject to change pending product scope authorization by Mission Force ELT. Headcount is allocated directly into the GovCloud Organization and embedded into Hyperforce Platform teams for scoped uplift of the platform and delivery into the target AWS Secret Region — it is not a standalone Red Queen org.
Why Funding Is Needed
Delivering Hyperforce Core into a SECRET-level air-gapped partition requires changes Blackjack-A and Blackjack-J never had to make. The six justification points in the source doc all reduce to one theme — nothing about Red Queen can be inherited as-is — expressed here as what's structurally different, not why it's different six times over.
Inception
New air-gapped AWS partition needs its own bootstrap sequence to establish trust/identity between Hyperforce Grid (ESVC) and Falcon instances before Spinnaker can deliver software.
Net-NewPartition
Different classification level than Blackjack — dedicated infrastructure, no shared resources or network. New ESVC instances required for artifact/data transfer.
No SharingEmulation
Emulated environments provisioned and managed entirely by GovCloud — departs from the third-party vendor (Sequoia) used in Blackjack.
Vendor ChangeInnerloop
First-ever innerloop experience for Service Owners to test/iterate builds from local dev into emulated substrate(s).
First of Its KindPaved Path
Establishes paved-path from Day 1, matching Hyperforce Commercial and GCP — many of these capabilities don't exist in Blackjack yet.
Day-1 RequirementObservability
New governed high→low telemetry egress, giving service owners Day-2 operational signal without breaching the air-gap.
Net-NewTranche Release Schedule
Funding is released in four milestone-gated tranches — each unlocking a defined slice of headcount only after the prior gate is achieved, sequencing spend behind demonstrated progress.
Nodes represent sequential milestone gates, not fixed calendar dates — the source doc only anchors T+0 (start) and ~T+24 months (target horizon). See the open gap below on missing exit-criteria dates.
| Tranche | Phase | Staff Added | Cumulative FTE | What It Funds | Milestone Unlocked |
|---|---|---|---|---|---|
| T1 | Discovery | +95 | 95 | Platform Uplift | Build Schedule |
| T2 | Planning | +21 | 116 | Emulation Build | Established Dev Innerloop |
| T3 | Hyperforce Uplift | +8 | 124 | Highside Inception | Achieved LLS |
| T4 | Build | +24 | 148 | Stage/Prod Builds | Begin Product Onboarding |
Stage-by-Stage Breakdown
Each deliverable in the Outcomes table has a named L4 owner. Cross-referencing owner → org (Allocation Summary) and owner → tranche (Outcomes table) reconstructs exactly which orgs deliver what, and how much headcount lands per org, at every gate. Verified: every stage sums to its tranche total, and every org's per-stage sums add up to its Allocation Summary total.
Discovery
+95 FTE · cumulative 95The bulk of the ask lands here: bootstrap/inception, emulation, the full outer-loop release chain, monitoring, network, IAM, and CoreApp — the platform-uplift work needed before any service can build.
- Inception — bootstrap sequence into AWS Secret Region 2
- FEDX Addons — substrate-agnostic addon parity 3
- Falcon-CLI — innerloop into target DEV FI 2
- Managed Release — safe-change release into FI targets 10
- Managed Pipelines — retires custom j2 templates 4
- BOM Hydration — automated BOM derivation 2
- Artifact Transfer — versioned transfer into FI targets 4
- FIT — safe-change compliant build testing 2
- Managed Operations — ESVC-driven ops execution 2
- Monitoring — commercial-parity observability stack 8
- Redwood — real-time threat detection/response 4
- NetworkV2 — flat, multi-agency network isolation 12
- DREAM — L7-WAF DDoS response/mitigation 3
- EDGE — Salesforce Edge CDN / perimeter ingress 4
- IAM — Hyperforce production IAM stack 6
- FKPv2 — managed Kubernetes compute runtime 8
- UBO — Unified Business Operations org 2
- CoreApp Config — canonical config naming scheme 3
- Cell Build — automated cell-builds, retires per-cell files 3
- Schema — consolidated bootstrap/deploy pipeline 1
- Endpoint Resolution — air-gapped registry/auth endpoints 2
- Canopy — low-side emulation platform 2
- Policy as Code — substrate requirement detection 1
- Runbook Assessment — AI-assisted runbook validation 1
- ENG360 — standards adoption reporting 2
- ACP — outside-in build & destroy automation 2
Planning
+21 FTE · cumulative 116Smaller, security- and hardening-heavy tranche: runtime security scanning is the single largest line, plus the second wave of outer-loop/Day-2 tooling and data protection.
- Runtime Scans — security/config detection appliances 8
- GATER — real-time feature-gate deployment 2
- OrgFarm — org-lifecycle management 2
- WardenAI — Day 2 Ops platform 2
- Audit Log Lifecycle — security/audit event logging 1
- Outbound Governance — system vs. customer egress classification 2
- Data Security — air-gapped PKI trust store distribution 1
- Data Resilience — ransomware-resilient backup/recovery 1
- Secrets Mgmt — safe-change compliant secret ops 1
- Identity & Access Controls — password policy, SCIM, lockout 1
Hyperforce Uplift
+8 FTE · cumulative 124The smallest tranche — highside inception, cross-domain transfer, PCE support, and the last compliance-banner item round out CORE.
- Cross-Domain Transfer — Airlift (low→high) / Vantage (high→low) onboarding 2
- PCE — Private Cloud Edition path-to-production 3
- Chaos Testing — quarterly gameday testing schedule 2
- Compliance Banners — classification header/footer, login banners 1
Build
+24 FTE · cumulative 148All 24 FTE in the final tranche are Day-2 operations staffing for the highside environment — a single line item, no new product deliverables.
- SNS Operations — highside Builds, Release, Test, Site Reliability 24
Platform's "To Be Confirmed" bucket (Scott Yancey — Scale-Test, Privacy Center, OrgStore, ZOS, EventBus, etc.) has no FTE or tranche assigned in the source doc, which is why it isn't in this stage total or the 148 grand total.
Allocation by Org (L4 Leader)
Allocations are weighted on the scope of services and uplift required per T&I portfolio that have not yet achieved operational maturity in existing Blackjack environments.
Outcomes & FTE Detail
Every FTE maps to a named deliverable. Grouped here by delivery area (the source doc lists these flat); each group header shows the area subtotal.
| Deliverable | Supplement / Components | FTE | Tranche |
|---|---|---|---|
| Service Standards 2 FTE | |||
| ENG360 Deliver ENG360 reporting of standards adoption for all services declared in the Red Queen build manifest. | Scope by environment; reporting pre- and post-build | 2 | T1 |
| Inception 2 FTE | |||
| Bootstrap Sequence Fully scripted, automated bootstrap sequence seeding falcon-foundations into the AWS Secret Region to achieve Long-Lived Spinnaker. | Documented design, build manifest, PoC from commercial env — timeline to unlock STAGE build | 2 | T1 |
| Emulation 3 FTE | |||
| Canopy Low-side emulation platform reproducing AWS Secret Region service offerings, SDK support, network restriction, and behavior. | ISO-parameter/strictness enforcement, CAP portal emulation, NPE, API remapping to commercial endpoints | 2 | T1 |
| Policy as Code Code/configuration detection of Red Queen substrate requirements for on-demand and continuous PR-lifecycle enforcement. | SFCI, Falcon-Policy, Matrix, PRIZM | 1 | T1 |
| Build / Destroy Automation 2 FTE | |||
| ACP Outside-in execution of all build & destroy operations from the corporate environment into Red Queen target FIs. | FBOTv2, ACP, Temporal, FUN, FQM, FIT, SSR, FMI, KAIJU | 2 | T1 |
| Inner-loop 5 FTE | |||
| FEDX Addons Functional parity for all platform-managed FEDX Addons including substrate-agnostic provisioning (IAC) Addons. | Lifecycle testing support via Watchdogs | 3 | T1 |
| Falcon-CLI Established innerloop into target DEV FI for continuous testing from corp with falcon-cli support. | Full support for advertised CLI commands | 2 | T1 |
| Outer-loop 26 FTE | |||
| Managed Release Safe-change compliant release into Red Queen FI Targets, initiated by Service Owners from ESVC, governed via manual judgement by Operator within the FI production boundary. | Managed Pipeline, SCv2, SRS Stagger, Safe Change Scorecard Reporting, Argo Rollouts, Operator UX | 10 | T1 |
| Managed Pipelines Support for Managed Pipelines into Red Queen FI Targets, eliminating all custom j2 pipeline templates. | Includes v2 Deployment Addon | 4 | T1 |
| BOM Hydration Event-driven, automated BOM Derivation and Hydration for lowside Red Queen target(s); detects security-relevant changes requiring merge approval. | FDIC, PCS, PCSK | 2 | T1 |
| Artifact Transfer Service-centric, versioned artifact transfer into each Red Queen FI Target driven by MR, initiated by Falcon Services via immutable pipelines. | AMG, Airfilter, FUN, Selective Replication (CTS), Immutable Pipelines | 4 | T1 |
| GATER Safe-change compliant, real-time deployment/management of feature-gates from the corporate environment with central gate-status reporting per target. | Change-mgmt enforcement of production gate-changes | 2 | T2 |
| FIT Safe-change compliant FIT testing and reporting, including dependency-aware rollout enforcement through build phases. | FIT Strict Mode, Versioned FIT Tests, FIT API | 2 | T1 |
| OrgFarm Org-lifecycle management including automated provisioning and testing into Red Queen Production FIs — UX, Headless, Agentic integrations. | — | 2 | T2 |
| Day 2 Operations 16 FTE | |||
| Managed Operations Managed Operation execution from the corporate (ESVC) environment into Red Queen target FIs. | Full support of all standardized operations and associated addons | 2 | T1 |
| WardenAI Fully-encapsulated WardenAI Platform for Day 2 Operations within Red Queen production boundaries. | Predictive Autoscale, SDB Alerts, Fawkes | 2 | T2 |
| Monitoring Full paved-path, priority-0, and commercial-parity monitoring capability, aligned with commercial portfolio. | Terramon, Kaiju Testing, Argus, Mon UI/API, Grafana, Splunk, APM, Funnel, MARS, Collections, Events/Stream, SLO, Cipher, Tracer, Healthmap, OOB, Huron | 8 | T1 |
| Audit Log Lifecycle Product-level security/audit logging across the required event catalog, 5-year retention or customer export, in-product search, admin notification + lockdown on failure. | — | 1 | T2 |
| Runbook Assessment AI-assisted runbook content assessment validating completeness/accuracy before operators build/deploy/manage services; gates Falcon service definition sign-off. | Matrix, iDog, CX | 1 | T1 |
| Chaos Testing Chaos gameday testing into Red Queen production FIs with a maintained quarterly testing schedule. | AZ Failover, DB Recovery, Pod Deletion, Instance Termination, Cross-FD fault injection | 2 | T3 |
| Runtime Security 8 FTE | |||
| Runtime Scans Security/configuration detection appliances into Red Queen production FIs; operationalize reporting and bug/vuln assignment from lowside Dev FI into corp (GUS, Eng360, Security Hub) and in-boundary reporting within highside Stage/Prod. | FPolicy (CD), AST-Container, Skywalker CSPM, Nessus, Netscan, WebApp, Endpoint protection, Antivirus, SAI | 8 | T2 |
| Logging and Detection 4 FTE | |||
| Redwood Real-time detection, response, and containment of threats within Red Queen production environments, with in-boundary notification/response. | RedWood, Cascade, Asgard | 4 | T1 |
| Network 21 FTE | |||
| NetworkV2 Flat-network supporting multi-agency network isolation per tenant. | IRIS, Menshen, IPAM | 12 | T1 |
| DREAM Automated L7-WAF DDoS response and mitigation. | Temporal, AWS CloudFront, Unified Controller, kWAF-enforcer | 3 | T1 |
| EDGE Salesforce Edge CDN / perimeter platform as north-south ingress — geo-distributed TLS termination, caching, edge security-policy enforcement. | Edge, perimetercdn, perimeter-provisioner, kWAF enforcer, shared cache | 4 | T1 |
| Outbound Governance Hyperforce-native classification of "system" vs "customer" outbound connections under default-deny, with GovCloud Architecture approval. | Non-standard TCP/IP, Explicit Proxy | 2 | T2 |
| Runtime 16 FTE | |||
| FKPv2 Falcon Kubernetes Platform (v2) managed compute runtime — cluster provisioning, tenant onboarding, autoscaling, networking, observability. | Ingress Gateway, Managed Mesh, Serverless, Periscope | 8 | T1 |
| Data Security Automated, air-gapped distribution of PKI trust stores (CA trust anchors) to all Falcon pods/hosts, with Blackjack-operator-managed trust-bundle generation. | Bharosa | 1 | T2 |
| Data Resilience Ransomware-resilient, immutable backup and recovery for Tier 0/1 stateful Falcon services, with isolated bunker storage and recovery validation. | DRMC | 1 | T2 |
| IAM Hyperforce Production IAM stack aligned to FY27 IAM portfolio v1, incl. Production Remote Access for lowside DEV and managed RBAC provisioning via IDM. | PCSK-JIT, PRA, PLEX, IDM, QuantamK + addons | 6 | T1 |
| Cross-Domain 2 FTE | |||
| Cross-Domain Transfer Falcon managed-capabilities and onboarding supporting Artifact Transfer and Data Transport for Service Owners in Red Queen through AWS Secret Region CDS. | Airlift (low-to-high), Vantage (high-to-low) | 2 | T3 |
| CORE 14 FTE | |||
| UBO Unified Business Operations organization into Red Queen production FIs with build-safe credential delivery and a weekly deployment schedule. | Blacktab, Trialforce/Sandbox | 2 | T1 |
| CoreApp Config CoreApp environment configuration driven by Operating Zone metadata and Structured Config, single canonical naming scheme across coral, falcon BOM, and CASAM settingspath prior to build. | — | 3 | T1 |
| Cell Build Automated cell-builds migrating cell-specific overrides from Helm into structured config, eliminating per-cell environment files. | CASAM, Structured Config, Topological Config, Fast Core Config, FMT | 3 | T1 |
| Schema Consolidated CoreApp bootstrap, deploy, and schemaupdate pipeline executable via Managed Release into Red Queen FI Targets. | CASAM, Spinnaker-Pipegen | 1 | T1 |
| Endpoint Resolution Documented, automated resolution of air-gapped registry/auth endpoints, plus an independent path to update image-signature policy for Red Queen. | Stampy, Airlock (ECR), Vault/Keystone, FKP Integrations | 2 | T1 |
| Secrets Mgmt Safe-change compliant secret management and runtime operations for CoreApp in Red Queen. | Lion Turtle (PLT), Managed Operations | 1 | T2 |
| Identity & Access Controls Configurable password policy, federated auth, automated account admin (incl. SCIM), lockout, inactive-user disablement, attribute/role/discretionary access, concurrent-session limiting, remote-access disablement. | — | 1 | T2 |
| Compliance Banners Configurable login banners, persistent classification header/footer banners, logout confirmation, email subject/body banner injection, with system-default and customer-override values. | — | 1 | T3 |
| PCE 3 FTE | |||
| PCE Support Support for Private Cloud Edition product development, testing, and path-to-production. | AWS Account Mgmt and Provisioning | 3 | T3 |
| Ops Staffing 24 FTE | |||
| SNS Operations Highside Builds, Release, Test, Site Reliability. | — | 24 | T4 |
| Platform Unscoped | |||
| To Be Confirmed Scale-Test, Scale-Center, Apex Guru, EKM, Database Encryption, Security Center (Multi-Org), Privacy Center, Archive, VaaS, In-Boundary Hammer Testing, OrgStore, ZOS, Capstone, Platform Radio, EventBus, Digital Wallet. | No FTE estimate given | ? | T4 |
| Total | 148 | ||
Planning Phase Deliverables
Require prioritization and commitment from the existing staff of Architects and Technology Leads. All must be presented and approved by GovCloud Architecture before exiting the planning phase (T+90).
Inception
Documented Red Queen Inception Strategy — design, execution plan, component/service manifest, and timeline to achieve LLS in the air-gap region.
Owner: GovCloudInnerloop
Design for outside-in testing from local/dev into RDev-0 with feedback loop — Falcon CLI, FEDX Addons, FPolicy, PRIZM, Workspaces, OrgFarm (+FIT).
Owner: DXOOuterloop
Documented air-gap outerloop architecture — Managed Pipelines, Immutable Pipelines, Managed Ops, Artifact Transfer, FIT, FBOT, Operator Experience, BOM Hydration.
Owner: DXOEnvironment Configurations
Operating Zone, PCS placeholders, Networking v2, DNS, CoreApp configs deployed and available via Structured Config.
Owner: HPSDependencies, Assumptions & Risks
Planning & Design
T1 depends on allocating Cloud Leads and Domain Experts (Product, Architecture, Engineering) from existing staffing for discovery/design/planning.
Government Sponsor
ATO accreditation pathway and timeline.
Owner: Irfan NawazE360 Data Platform
Adoption reporting for paved-path benchmarks across in-scope services, required for onboarding into RStage-1.
Owner: Alex Hu| Risk | Likelihood | Impact | Mitigation | Owner |
|---|---|---|---|---|
| Cleared-SRE hiring & clearance delays | Medium | High | Start requisitions early; phase the ramp; prioritize internal transfers of already-cleared staff | Program / Recruiting |
| Contract approval for shared-use of facilities (SECRET, TS Enclaves) | Medium | High | Require per-substrate readiness ETAs and versioning; sequence adoption behind capability availability | SNS / Computable Insights |
| Product scope expansion | Medium | High | Governance gate and reallocation authority per Section 9; any change to total escalated to sponsor | Program owner |
| Upstream platform dependency slips (R266–R270) | High | High | Track dependency TDs; align prioritization with providing teams at each milestone gate | Program / RADX |
Appendix A — Staffing Execution & Governance
| Phase | Activity | Responsible | Description |
|---|---|---|---|
| 1 | Allocation | GovCloud | GovCloud owns the total allocation and may rebalance headcount across platform teams as scope, risk, and business needs evolve; changes decided at milestone gates (M1–M4). |
| 2 | Assignment | Platform | Platform organizations distribute and assign allocated headcount against committed outcomes and are accountable for delivery through Day-2 production readiness. |
| 3 | Recruitment | Joint | Platform teams define role/skill profiles and initiate recruiting pipelines with a dedicated RBO team, including joint-interview panels across T&I. |
| 4 | Onboarding | Joint | GovCloud provides architectural guidance and requirements; assigned platform covers Falcon, Developer Setup, and Technology/Capability specifics. |
| 5 | Operational Tasking | Platform | Platform delivery lead directs day-to-day work; GovCloud tracks progress against milestone gates. |
| 6 | Performance | GovCloud | Retained by each engineer's manager of record, with input from the platform delivery lead where staff are embedded, on the standard cycle plus milestone checkpoints. |
| 7 | Reassignment | Joint | Transitions initiated as engineering contracts are fulfilled (Production Build complete + successful Q2/Q3 Testing). Platform teams may request extended support with justification and GovCloud approval. |
| 8 | Day 2 | Joint | Headcount reports back into GovCloud Engineering & Operations, forming satellite teams for sustained support/operation in air-gapped production. A durable dotted-line to each originating platform team keeps architecture evolution continuous rather than ending at hand-off. |
Open Gaps — Before This Goes to ELT
- No dollar figure. A "funding strategy" doc that states 148 FTE but never states loaded cost or infra spend can't actually be approved as a budget — only as a headcount plan.
- Scope-pending vs. firm-148 tension. The doc marks scope "Decision Pending" yet treats 148 as final everywhere else. Needs an explicit range or contingency note.
- Unscoped tail inside a "final" total. The Tranche 4 "To Be Confirmed" bucket (Scale-Test, Privacy Center, OrgStore, ZOS, Capstone, EventBus, Digital Wallet, etc.) carries no FTE estimate but sits inside the 148 total.
- Milestone gates lack dates and exit criteria. "Build Schedule," "Achieved LLS," "Begin Product Onboarding" are labels, not measurable checkpoints.
- Template fields unfilled. Date field is blank; author/sponsor were bracketed placeholders in the source doc.
Sources
-
Red Queen Program Funding Strategy — v1.0 (source doc)
Author: DJ Mahon · Prepared for: Jim Wiese. Definitive source for every figure on this page.
-
Red Queen — Program Overview
Scope, environments, paved-path standards, Airlock/Vantage — the operational context this funding pays for.
-
Staffing Model — Interactive Planner
Investment-area-level HC breakdown backed by a live Google Sheet — a different cut of headcount than this doc's org/outcome views.