# Preview Feedback Vault Prospector Preview feedback is voluntary and user initiated. The application does not automatically submit analytics, telemetry, diagnostics, or issue reports. ## Choose the right channel - [Report a Preview bug](https://github.com/Hybrid-Solutions-Cloud/vault-prospector-releases/issues/new?template=bug.yml) for a reproducible, non-sensitive failure. - [Request an experience improvement](https://github.com/Hybrid-Solutions-Cloud/vault-prospector-releases/issues/new?template=feature.yml) after trying a core task. - Follow the [security policy](SECURITY.md) for a suspected vulnerability, disclosure, or report that may require sensitive evidence. Never open a public security issue. GitHub issues are public and are processed under GitHub's privacy terms. Submission is explicit: Vault Prospector never creates an issue or uploads data for you. By submitting after reading this notice, you voluntarily choose to publish the information entered. For experience feedback, place this sanitized measurement block in the feature form's problem field: ```text Vault Prospector version: Install method: Direct MSI | WinGet | Chocolatey | Portable ZIP | Built from source Windows edition/version/build/architecture: Task attempted: Install/update | Setup/sign-in | Discover/sync | Search/filter | Reveal/copy | Cache/purge | Remove identity/data | Accessibility Outcome: Completed without help | Completed with documentation/workaround | Partially completed | Could not complete Ease: Very easy | Easy | Neutral | Difficult | Very difficult Biggest friction: ``` Use the standard Bug, Feature, or Task issue type and the native Priority and Effort fields. HCS workflow uses only the reserved `needs-triage` label for new intake; product category, severity, and priority are not encoded as custom labels. ## Sanitize before submitting Use synthetic or non-production data. Do not include: - credentials, tokens, passwords, private keys, certificates, or secret values; - tenant, subscription, account, vault, secret, key, or certificate names or identifiers; - unreviewed diagnostic files, screenshots, crash dumps, database files, or clipboard contents; or - information your organization does not permit you to publish. Replace resource details with stable placeholders such as `tenant-a`, `vault-1`, and `secret-x`. Describe an error category instead of pasting an unreviewed log. If maintainers need more evidence, they will request a safe transfer method; they will not ask for a live credential or secret. ## What happens next Maintainers target initial triage within three business days. Each report is classified by severity, reproducibility, affected version, and release impact. Public updates contain sanitized status only. Release-blocking defects are tracked in the private engineering repository and must be resolved or explicitly accepted under the release-readiness process before promotion. The detailed, measurable Preview-to-GA criteria are maintained with the private source repository. At minimum, GA requires a stable observation window, successful core-task feedback, all Preview reports triaged, no unresolved release-blocking defects, and proven upgrades across every supported Preview version.