Last updated: 2026-07-24
Each lifecycle slice follows: gather context → take one typed action → verify provider truth/invariants → persist → repeat. Fireworks drafts and classifies; deterministic code alone confirms payment, proof, deployment, and delivery.
| Checkpoint | Status | Verification |
|---|---|---|
| Repository/spec audit | Complete | Existing proof boundary, Stripe conflict, preview safety, and missing orchestration interfaces mapped. |
| Sourced contract compiler | Complete | Exact transcript/research citations accepted; unsupported facts fail closed (2 tests). |
| PII minimization | Complete | Email/phone + Fireworks spans removed while source offsets remain stable (2 tests). |
| Fireworks orchestration reasoner | Complete | Typed intake/proposal/change tool outputs fail closed when missing or malformed (2 tests + typecheck). |
| Proven-winner policy | Complete | Current project/contract only; pinned Braintrust policy + deterministic tuple fail closed (69 focused tests). |
| Customer email sequence | Complete | Proposal/payment, receipt, proven preview/steering, and final delivery copy (2 tests + typecheck). |
| Voice/email ownership boundary | Backend complete | Voice intake cannot assert email ownership; the normalized boundary accepts dictated contact capture without a verification claim, while durable pre-proposal mail sends a scanner-safe 15-minute project/email-bound verification link. Spoken interaction behavior remains the voice layer's responsibility. |
| Passwordless dashboard access | Backend complete | Fragment token, inert GET exchange page, POST-only verification, atomic one-time digest consumption with ownership event, generic replay failure, and seven-day signed project session are implemented. |
| Bounded access-link reissue | Backend complete | Generic POST .../access/requests accepts only a signed active or at-most-30-days-expired fragment capability, rechecks protected project/email identity, mails only the stored address, applies a durable one-minute per-project send floor, and rotates unsent 15-minute capability generations. |
| Customer dashboard REST + steering | Backend complete | Project/email-bound project and bounded event reads plus session-derived double-submit CSRF, stable idempotency key, expected revision/proposal coordinates, and shared-orchestrator steering are implemented under /v1/orchestration/customer-dashboard/.... |
| Sanitized build observation | Backend complete | Internal per-run observation exposes allowlisted status/stage/slot/tool/proof/timeline fields; raw Daytona surfaces and logs never cross it, and the schema remains explicitly customerRenderable: false. |
| Customer dashboard UI + live visual | UI complete; producer open | Next.js/CopilotKit workspace, opaque aliases, and resumable Last-Event-ID SSE ship in apps/dashboard; the raster gateway has a consumer but no producer. Typed-email requests, server-side revocation/renewal, and edge rate limits stay open. See the audit below. |
| Provider-backed dashboard E2E | Pending | Real Resend link delivery/consumption, browser session, live project read, steering revision, build observation, proven preview, and production handoff have not yet been verified together with configured providers. |
| Secure email-thread routing | Complete | Opaque HMAC-protected project reply addresses reject tampering/wrong domains (2 tests). |
| Sourced proposal versions | Complete | Fireworks plans bind to exact intake/research evidence, quote, contract, strategies, and immutable digests (2 tests). |
| Build handoff compiler | Complete | Distinct 1–4 assignments share one exact contract and exclude protected contact PII (1 integration test + typecheck). |
| Encrypted durable project state | Complete | AES-256-GCM aggregate, immutable redacted events, optimistic revisions, effects, and webhook replay protection (6 tests). |
| Stripe, Resend, safe research adapters | Complete | Signed webhooks, exact Checkout verification, idempotent mail, and consent/SSRF-guarded research (20 tests). |
| Lifecycle engine: intake → paid build | Complete | Revised proposal expires old Checkout; exact paid vN sends confirmation and fans out PII-minimized builds (integration test + typecheck). |
| Frozen proven-preview boundary | Complete | Snapshot-restored private clone, signed-URL readiness/marker probe, identity/TTL checks, cleanup, and idempotent ACK (36 focused tests + lint). |
| Proof → preview → deploy engine | Complete | Current-contract proof ingestion, deterministic winner, durable preview email, review window, exact artifact deploy, health-gated final email (18 focused lifecycle/state/HTTP tests). |
| Paid steering + clarification | Complete | No-op/in-scope/re-quote branches, paid commercial ancestry, cumulative hard requirements, clarification email/reply, and fresh proof fan-out (focused integration tests). |
| Crash recovery + races | Complete | Intake-before-model, clarification-mail replay, paid-revision replay, partial fan-out, proven-event ACK loss, and payment/edit arbitration pass focused lifecycle tests (13/13). |
| HTTP/webhook runtime | Complete | Raw-body Stripe/Resend verification, secure reply routing, authenticated intake/reconcile, strict schemas, and minimized responses (9 tests). |
| Email thread + delivery truth | Complete | Raw-message aligned DKIM, deterministic RFC threading, exact delivery receipts, bounce attention, and stale-version fencing (focused provider/HTTP/lifecycle tests). |
| Fly first-app provisioning | Complete | Exact app/org lookup, idempotent create/race recovery, pre-provisioned app-token path, and fail-closed release fencing (31 focused deploy/runtime tests). |
| Evidence + approval integrity | Complete | Per-item extractive citations, quote rejection checks, deterministic build prompt, and asset clarification pass 18 focused tests. |
| Payment reconciliation | Complete | Lost webhook, exact Checkout/PI polling, edit race, replay, expiration, and replacement-link paths pass 59 focused tests. |
| Ordered edits + paid-work delivery | Complete | Concurrent cumulative replies cannot bypass re-quote; any pending authenticated vN+1 edit fences customer-visible vN delivery (focused tests). |
| Preview freshness | Complete | Stored links refresh before mail unless they cover the full review window plus safety margin. |
| Earlier adversarial audit | Superseded | A later reliability re-audit found additional deadline, effect-attribution, and provider-hang gaps; those are tracked below instead of hidden. |
| Compiler + lint checkpoint | Complete | Strict TypeScript and zero-warning ESLint pass on the combined tree. |
| Current-proof event isolation | Complete | Outbox polling filters to exact active run UUIDs; 45 focused backend/HTTP/adapter tests pass. |
| Orchestration decision tracing | Complete | Fireworks intake, proposal, and edit decisions fail closed through redacted Braintrust traces. |
| Real-provider composition | Complete | Production uses concrete provider adapters only; live Stripe and real domains are mandatory. |
| Provider readiness | Code complete; live pending | Read-only probes cover all providers, webhook registrations, backend identity, and snapshot; credential smoke awaits API keys. |
| Production startup | Complete | One supervisor starts/stops both backends; individual service commands remain available. |
| Integrated repository suite | Complete | npm run check passes formatting, lint, strict typecheck, production build, coverage thresholds, 56 test files, and 676 tests. |
| Docs + GitHub handoff | Documentation updated | README, CLAUDE, product/dashboard/runtime, and progress documents describe all four services (build backend, orchestrator, dashboard, voice intake) and distinguish the implemented slices from the pending WIP frame producer, session operations, and provider-backed E2E. |
| Transactional provider inbox | Complete | Verified inbox receipt + aggregate CAS commit/rollback are atomic; duplicate/conflict and lifecycle integration pass. |
| Bounded effect recovery | Complete | Persisted exponential retry, capped attempts, safe errors, stable idempotency, and dead-letter/operator-attention paths pass focused tests. |
| Preview delivery gate | Complete | Lost Resend webhooks reconcile through authoritative provider status; deployment waits for actual preview delivery and starts its review clock there. |
| Reliability re-audit checkpoint | Complete | Node 24 strict typecheck plus 5 focused files / 84 tests pass after re-checking the original lifecycle requirements. |
| Terminal attention boundary | Complete | Authenticated customer mail is retained/inboxed but cannot bypass a dead-lettered or verification-failed project (4/4 retry tests). |
| Fly last-known-good rollout | Complete | Trusted blue/green strategy + service health check keep the prior healthy Machines serving until replacement readiness (30/30 deploy tests). |
| Stripe mutation response recovery | Complete | Authoritative already-expired Checkout evidence completes the same durable effect without a second mutation or duplicate replacement link (28 focused tests). |
| Exact retry attribution | Complete | Only the effect immediately bound to a failing provider call spends retry budget; unrelated pending work stays unchanged (5/5 retry tests, 24/24 lifecycle tests). |
| Build/proof liveness | Complete | Persisted build and proof-event deadlines cancel stalled peers, rank available proven work, or stop in no-proven; legacy batches backfill safely (28/28 lifecycle tests). |
| Hung-operation containment | Complete | Per-project worker deadlines keep later projects/cycles moving, and Braintrust trace flushes fail closed within a bound (13 runtime + 10 trace tests). |
| Required-mail liveness | Complete | Persisted delivery deadline stops unverifiable preview/final mail; API/webhook races terminalize one exact effect atomically (42 focused lifecycle/runtime tests). |
| Build mutation recovery | Complete | Per-run cancellation and per-proof ACK effects recover lost responses with stable backend idempotency and bounded dead-lettering (31 lifecycle tests). |
| Latest-version delivery fence | Complete | Authenticated edits/clarifications fence older paid work from preview, Fly deploy, and final email; only the latest settled contract can become customer-visible (31 lifecycle tests). |
| Provider-deadline accounting | Complete | Operation-specific artifact/preview/Fly ceilings fit inside a 32-minute worker bound; aborted attempts spend the exact effect retry (focused runtime/deploy tests). |
| Stripe verification recovery | Complete | Checkout/PaymentIntent reconciliation has a durable effect, explicit verification-failed state, and normalized authoritative settlement receipt (41 focused lifecycle/store tests). |
| Deadline evidence outage | Complete | Build/status outbox outages cannot bypass stored build/proof ceilings; trusted stored evidence retires or fails closed with an explicit receipt (34 lifecycle tests). |
| Project action linearization | Complete | One active orchestrator serializes inbound edits, reconciliation, payment, and mail receipts per project across customer-visible provider calls (52 lifecycle/HTTP tests). |
| Frozen-preview replay safety | Complete | POST idempotency, deterministic Daytona name/labels, provider recovery, serialized replay, TTL refresh, and exact proof identity pass 48 focused tests. |
| Research + paid-scope grounding | Complete | Owned-domain authority, provisional research confirmation, ISO quote evidence, hard proof coverage, and bounded paid change briefs pass 88 focused tests + lint. |
| One-time quote integrity | Complete | Recurring, staged-payment, tax, and fee qualifiers fail closed before one-time Stripe Checkout; focused policy and lifecycle tests pass. |
| Signed inbound-mail recovery | Complete | Minimal signed envelopes persist before enrichment; bounded retry, operator recovery, attachment/oversize rejection, and release fences pass 76 focused tests + lint. |
| Rejected-webhook security audit | Complete | Missing/invalid Stripe and Resend signatures produce immutable digest-only receipts, bounded overflow summaries, and a protected count-only view (34 focused tests + lint). |
| Operator evidence + proof summary | Complete | Internal evidence is paginated; final mail is bound to an encrypted immutable proof snapshot with crash recovery, revocation, bounded capability reads, uniform failures, and fail-closed PII/secret publication checks (91 focused tests + typecheck). |
- Intake from transcript/email/text, name + PII: complete through the core lifecycle; voice-surface dictation UX remains outside this backend
- Passwordless email ownership: backend complete with durable verification mail, fragment-only 15-minute capability, scanner-safe GET, atomic POST consumption/ownership event, and project/email-bound seven-day signed session.
- Bounded link reissue: backend complete for signed active/recently-expired
capability proof, 30-day grace, generic
202, protected identity recheck, stored-address-only delivery, durable one-minute per-project send floor, and unsent-capability generation rotation. Typed-email requests and edge-wide rate limiting remain open. - Post-payment dashboard access: backend complete with one durable
send_dashboard_accesseffect after the exact requested build batch is fully dispatched. - Customer dashboard reads and steering: backend complete for project snapshot, bounded REST events, safe build-observation join, last-known-good preview/production retention, and CSRF/idempotency/version-bound steering.
- Customer dashboard experience: complete for the Next.js/CopilotKit
frontend (
apps/dashboard/app/dashboard/projects/[projectAlias],app/api/copilotkit/*), opaqueprj_/bld_/frm_aliases sealed into a session-bound cookie (apps/dashboard/lib/server/aliases.ts), and resumableLast-Event-IDSSE that fans the orchestrator's bounded event window out astext/event-stream(apps/dashboard/lib/server/customer-stream.tswithapps/dashboard/components/use-customer-project.ts; 9 focused tests inapps/dashboard/tests/customer-sse.test.ts). - Customer-renderable raster WIP gateway: consumer only. The dashboard
accepts, sanitizes to a blurred layout-only PNG, watermarks, and serves frames
(
apps/dashboard/lib/server/wip-raster.ts), but every ingest requires asanitizationPolicyDigestplus an HMAC sanitization receipt, and nothing insrc/produces one — no builder or controller captures or attests a frame. The build backend's projection is still schema-pinned tocustomerRenderable: false, so no customer can receive a frame today. The producer side is the remaining work. - Remaining dashboard gaps: open for the typed-email public link request (no
email-entry surface exists), server-side session revocation and renewal —
logout clears the dashboard-origin cookies and projection state but returns
globalRevocation: false, leaving the orchestrator-signed session valid until it expires — and edge-wide dashboard rate limits. - Caller-provided, consented own-business URL research with citations: complete for explicitly owned/authorized URLs; findings stay provisional until customer-confirmed; business-name discovery/assets remain open
- Versioned summary + Stripe link + pre-payment email edits: complete
- Verified payment + confirmation email: complete
- End-to-end prompt + free-slot build dispatch: complete
- Proven preview + email steering loop: complete
- Proof-gated Fly.io deploy + final email: complete in the lifecycle engine
- Concrete Fireworks/Braintrust/Stripe/Resend/Daytona/CodeRabbit/Fly wiring: complete; configured-provider smoke and dashboard end-to-end verification remain pending
- Durable tracking, fixed-interval recovery, idempotency, and failure states: complete for the implemented lifecycle, including retry/dead-letter, build/proof/mail deadlines, exact effect attribution, healthy provider poll cadence, all required-mail reconciliation, and signed inbound recovery
- Protected operator evidence and customer-readable, exact-deployment proof summary: complete
- Invalid provider signatures fail closed with bounded, minimized durable security-audit receipts and a protected summary; repository-wide retention policy remains open.
- Field-approved customer contact content for generated sites: open; all customer contact PII currently stays out of builders
- Patch Model dataset/RFT/evaluation/promotion pipeline: open; the current runtime uses the configured base Fireworks model
Safety decision: raw work-in-progress Daytona builds remain operator-only. An
authenticated customer may receive only the implemented, allowlisted structured
observation, currently with customerRenderable: false. The dashboard can
already serve watermarked, layout-only raster frames, but only for frames posted
through its attested internal ingest; until a builder-side producer exists, no
frame is ever available and the customer surface stays non-renderable. Customer
review links remain frozen proven revisions; every requested edit creates a new
contract revision and must pass the complete proof gate again.