Skip to content
| Marketplace
Sign in
Visual Studio Code>Other>PSPF CoreNew to Visual Studio Code? Get it now.
PSPF Core

PSPF Core

Toby Harvey

|
1,094 installs
| (0) | Free
Local-first workspace storage, validation, snapshots and controlled exchange for PSPF cyber risk and assurance work.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

PSPF Core

Local-first storage, validation and exchange for cyber risk, assurance and work planning with PSPF and ISM context. Core is the workspace system of record; Pub has its own local people store and Explorer has separate browser-local data.

Role: Local system of record

What this extension does

PSPF Core is the local system of record. It runs entirely inside VS Code, holds the workspace in a local SQLite database at .pspf/core/pspf-core.db, and enforces a single-writer lock so only one editing session touches the data at a time.

  • Owns the canonical entity and link model (Requirements, Evidence, Actions, Risks, Directions, ISM mappings, Suppliers, Contracts, Spend Items).
  • Runs schema-policy validation, snapshots, backup, restore, and integrity checks.
  • Exports the curated manifest-led JSON bundle that Explorer consumes. The export command prompts for the destination file.
  • Applies redaction at publication time: restricted and sensitive fields are excluded from exports and snapshots.

How it fits

Core is the foundation for the rest of the PSPF ecosystem.

  • Workshop is the authoring surface and depends on Core.
  • Assurance provides assessment, finding and verification/retest workbenches and depends on Core.
  • Shop is the commercial planning surface and depends on Core.
  • Pub is the local-only people, role, assignment, and relationship context surface and depends on Core.
  • Explorer supports publication review and browser-local authoring with explicit master-bundle exchange; it is not a live Core client.

Install Core first, then add Workshop, Assurance, Shop and Pub as needed. A publication bundle is not a lossless backup: sensitive fields are excluded.

Design Direction (Not Implemented)

The clean-start workbench brief evaluates one modular extension while retaining useful Core write, validation and recovery mechanisms. Current packaging and storage remain unchanged. There are no active users, so legacy migration and retention are not required for the proposed fresh baseline; safe handling of future work remains essential.

Key commands

  • PSPF: Initialise PSPF Workspace
  • PSPF: Validate Workspace
  • PSPF: Create Snapshot
  • PSPF: Export Master Bundle — prompts for a save location for the JSON bundle.
  • PSPF: Import Master Bundle

Source and docs

  • Repository: https://github.com/MegaTobyOne/Conceptual
  • Ecosystem overview: https://tobyharvey.online
  • Explorer (publication view): https://tobyharvey.online/explorer/

This is an independent project. Not affiliated with the Department of Home Affairs, the Attorney-General's Department, or any other Australian Government entity. Do not enter information classified above OFFICIAL: Sensitive.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft