The planned scenario

Municipal Services brings citizen accounts, permits, payments, and GIS information into one scenario. Its private context covers resident identity, dispatch records, court metadata, and tax data. These categories create an exercise about systems serving the same population without exposing the same information.

Use a permit or parcel lookup as the starting context. Then distinguish the information needed for that public task from identity and internal service records. The exercise can focus on access classification and evidence quality without borrowing data from an actual municipality.

Public surfaces

These reference routes describe possible entry points in the scenario model. They are not live customer services or a guarantee of the routes in a particular product release. Use your configured exercise inventory as the authoritative scope.

Public routes declared in the Municipal Services catalog
RouteSurfaceContext
/citizen-portalCitizen services portal and account workflow.
/permitspermitsPermits, inspections, and application tracking facade.
/paymentspaymentsMunicipal payment workflow simulation.
/gisgisPublic GIS map and parcel data facade.

Private systems

These service names and segments describe the internal context of Municipal Services. They help define exercise boundaries and interpret the generated records.

identity-registry

Private identity and resident registry representation. Catalog segment: private application.

dispatch-data

Emergency dispatch and service request data plane. Catalog segment: private data.

court-records

Municipal court workflow and case metadata. Catalog segment: private data.

tax-data

Tax, parcel, and assessment data store. Catalog segment: private data.

Configure your exercise

Choose a question for the assignment and define the evidence participants should collect.

  • What distinguishes public parcel or permit information from the resident identity context behind it?
  • Which records should remain separate when citizen services, payments, and internal departments refer to the same person or property?
  • How would an investigator support a claim about exposed dispatch or court context without treating a facade label as proof of a live backend?

What to hand in

Deliver a public versus restricted information map for the represented municipal services. Explain each category’s intended audience, the evidence observed, and the boundary that requires a supporting observation.

Records and evidence

Synthetic residents, permits, payments, GIS layers, dispatch events, and court cases support discussion of departmental access and public information. Review each category against its intended audience, then record the sources supporting that access classification.

  • residents-synthetic
  • permits
  • payments
  • gis-layers
  • dispatch-events
  • court-cases

Preserve the scenario and product version, the record or observation, and its source with each finding. Distinguish what a participant observed from what the reviewer inferred. Use synthetic data and your defined evidence-retention rules.

Public self-service at launch

Managed Verse is planned for 1 January 2027. Users will create an account, choose a scenario and configure their own authorized exercise boundaries. Vulnverse will host and operate the platform and cloud; users will not need to provision or maintain an exercise cloud.

Managed Verse is planned to replace all previous services. All new inquiries are paused during the transition. Read Managed Verse →.