# V10 Product Review — The Rail

**Status:** independent implementation-state product review

**Reviewer:** Codex (product and source-boundary review)

**Date:** 2026-07-22

**Scope:** `V10/V_SERIES_AMBIENT_RAIL.md`, the requirement ledger,
`V10/V10_features.md`, `V10/V10_ARCHITECTURE.md`, all V10 integration records,
the V10 contracts/kernel/channels/apps, the Tauri shell, the V1 BFF bindings,
and the shared live-media substrate used by the Rail.

**Method:** reconcile the product promise against current source, tests,
generated audit evidence, and explicit human/deployment gates. A local test or
fixture is never treated as a production content or release receipt.

---

## 1. Executive summary

The Rail is the portfolio's calm ambient companion: a narrow surface designed to
live beside work, not replace it. V1–V9 remain destination products and publish
through one strict channel contract; V10 owns attention policy, dayparts,
arbitration, rendering, native window behavior, and the shared companion
experience. V1 still owns identity and all account-shaped state.

The implementation is much stronger than the original proposal status implied.
The repository now contains a real policy kernel, a production channel
directory, persisted per-user loudness and discretion state, one-holder audio
and video lanes, native Tauri controls, calendar-aware dayparts, the morning
Thread, web/PWA and satellite projections, deep browser coverage, and a
tenant-neutral live-media substrate with local four-tenant equivalence. The most
important product principles—loudness is granted, absence is free, adult content
is structurally walled, autoplay is forbidden, and unavailable content is never
fabricated—are executable invariants rather than presentation copy.

The remaining risk is not basic product architecture. It is release truth and
content operations. The required week-long human dogfood exit test is open.
Several first-party content paths have strict authorities and local release
gates but no deployed scheduler, catalog population, or retained production
receipt. Veritas and V3 Stage rights/operations remain human gates. The product
must resist converting abundant technical capability into a misleading
"always-live" promise before real daily programming exists.

**Verdict:** the Rail is a credible product with a distinctive, defensible
posture. Keep the calm constraints non-negotiable; prove habitual usefulness in
the human exit test; and make production content freshness, not engagement
volume, the next release frontier.

---

## 2. Product identity and customer promise

V10 has a coherent job: occupy the sidebar slot with company, context, and small
invitations that never demand a session. Its customer promise has four parts:

1. the surface progresses without punishing absence;
2. every channel is reconstructible at a glance;
3. audio, video, and interruption rights remain user-granted and globally
   arbitrated;
4. every item is honest about source, availability, and action consequence.

The native desktop shell is the authoritative form because tray presence,
always-on-top, edge docking, screen-share discretion, and a durable narrow
window are core behavior. The shared web/PWA frontend is useful as a fallback
and satellite surface, but it cannot substitute for those OS-level promises.

The product is neither a universal feed nor a tenth content studio. Channels
retain authority over their facts and media. V10 composes, schedules, meters,
and presents their outputs. This boundary is especially important for the
Thread: it is one ordered morning program over Tara, Veritas, Case Files,
Wonder, and Nyx—not a synthetic channel and not a second timeline.

---

## 3. What is genuinely strong

### 3.1 Calm is enforced in code

The loudness ladder, global daypart ceilings, batch windows, elevation budgets,
ring walls, discretion rules, and no-absence-punishment vocabulary are shared
kernel policy. Channel packages cannot silently acquire a lane or promote
themselves. Phase A invariants scan both behavior and ownership boundaries,
including the ban on a second streaming stack.

This is the product's most defensible feature. Competitors can copy a narrow
layout; they cannot easily copy an architecture that makes attention capture a
policy violation.

### 3.2 The surface tells the truth about content

Ready tiles and drips are projections of canonical channel material. Missing
editions remain unavailable. Stage fixtures and declared drills cannot become
catalog inventory. Future-dated Thread material is rejected. Veritas claims
retain proof and correction semantics. The product repeatedly chooses a quiet
empty state over a plausible fake, which is exactly right for a trust-led
companion.

### 3.3 Shared lanes prevent ambient chaos

Audio and video are single-holder resources with explicit offer, selection,
replacement, and release semantics. Channels cannot autoplay or independently
seize playback. Coupled Stage media is committed as one identity, and the
Thread's Veritas briefing starts only in the user's press handler. This keeps a
multi-channel surface from becoming a competition between embedded players.

### 3.4 The shell posture is product-specific, not a wrapper afterthought

The Tauri host owns tray/menu behavior, keep-on-top state, docking, restore,
close-versus-quit semantics, launch behavior, and native discretion bridges.
Those capabilities are tested at their available boundaries and documented with
the remaining macOS Accessibility gate called out explicitly.

### 3.5 The portfolio reuse strategy is real

V10 reuses V1 identity and persistence, channel-owned domain authorities, V4/V5
direction and commentary machinery, and the canonical `@oshun/live-media`
substrate. Aphrodite remains a tenant with its adult policy; Veritas, V3 Stage,
and Rail compositions fix their own tenant identities. The consolidation guard
makes "build it once" mechanically enforceable.

---

## 4. Product gaps and risks

### 4.1 Human usefulness is not yet proven

The repository cannot close HG-1. A person must actually leave the Rail docked
beside daily work for a week and inspect the dogfood report. The decisive
questions are qualitative as well as operational: Did the Rail become company?
Was it calmer than a browser tab? Did the user return voluntarily? Which
channels stayed useful after novelty faded?

Until that trial happens, "code-complete Phase A" must not become "validated
product-market behavior."

### 4.2 Production programming is thinner than the architecture

The source boundaries are strict, but several paths still require deployed
authorities, seeded canonical rows, or retained runtime receipts. V3 Stage has a
real local UE5.5/FFmpeg boundary without a production performance catalog.
Veritas first-party coverage remains an operations and rights decision. A Rail
with many implemented adapters but few fresh editions will feel empty.

The release metric should therefore be **fresh canonical programming coverage
per promised daypart**, with explicit unavailable time, rather than raw channel
count.

### 4.3 The product can still accrete too much

The roadmap spans desktop, PWA, mobile, watch, TV, games, worlds, an adult ring,
and a narrator. Every new surface increases policy and operational load. V10
should keep the narrow customer job visible: calm peripheral presence. A feature
belongs only if it improves that job without creating obligation, attention
debt, or a second destination UI.

### 4.4 Cross-product identity raises explanation cost

V10 is its own product while V1 owns account state and six house channels. That
is the correct governance boundary, but it can confuse customers and operators.
Product copy, support tooling, and incident ownership need to state clearly
whether an issue belongs to the Rail shell, the V1 account graph, a channel
authority, or shared live media.

### 4.5 Business gates are real release dependencies

Third-party Stage programming, first-party Veritas coverage, adult-ring policy,
app-store strategy, final naming, and Ori default-on behavior require human
decisions. The implementation correctly fails closed around them. Roadmaps and
demos must preserve that distinction instead of treating a configurable seam as
permission.

---

## 5. Autonomous-content audit finding

V10 changes the portfolio audit in an important way: it is primarily a
**consumer and composition layer**, not another unconstrained generator.

- Channel authorities own generation, verification, provenance, and publication.
- V10 accepts only contract-valid, source-bound material and applies scheduling,
  batching, discretion, and lane policy.
- The Thread composes exact references and cannot invent a substitute edition.
- Stage and live-media paths require verified bytes and resource-exact tenant
  authority; metadata plans are not playable media.
- Ori-generated recaps and greetings are separate, consented, budgeted,
  grounded, filtered paths and never write memory during read-only generation.

The canonical autonomous-content verification record therefore includes the
bounded V10 apps, all V10 packages, and the canonical V10 contract files as a
distinct check. The content-coverage seed now ingests the V10 ledger alongside
V1–V9. Neither mechanism promotes local tests into a production release claim.

---

## 6. Prioritized recommendations

### P0 — prove the product

1. Run HG-1 with the instrumented seven-day dogfood report and retain the human
   decision as release evidence.
2. Define a freshness/readiness report for every Phase A channel and the Thread,
   distinguishing configured authority, current canonical edition, and empty
   state.
3. Keep first-party-live disabled until a deployed tenant path and real retained
   media receipt prove the production claim.

### P1 — make the daily ritual reliable

1. Operationalize the morning Thread authority with observable, source-specific
   failure states and freshness SLOs.
2. Seed only rights-cleared, verified Stage programming; preserve premiere/VOD
   wording until live delivery is genuinely configured.
3. Use calm-SLO and voluntary-return review in every iteration; do not introduce
   click-through, streak, debt, or urgency optimization.

### P2 — expand only after the narrow loop works

1. Advance Ghost Dojo, Realm, period-world, and match channels only from their
   real persistent simulations and verified results.
2. Treat mobile/watch/TV as projections of the same policy kernel, never looser
   product forks.
3. Keep Ori's default-on decision behind its human gate and measured inference
   ceiling.

---

## 7. Review and audit cadence

V10 now participates in the same machine-derived product registry,
content-coverage seed, canonical verification record, generated portfolio map,
and autonomous-content audit views as V1–V9. This review should be refreshed
when any of the following materially changes:

- the Phase A human exit decision;
- a production first-party-live flip;
- the canonical channel or Thread programming set;
- a new satellite becoming a supported release surface;
- final naming or adult-ring policy approval; or
- a release claim moving from local evidence to deployed evidence.

The legacy `evidence/v1-v9` directory and dated audit filename remain stable
evidence locators. Their generated contents and verification manifest are now
explicitly V1–V10 in scope; path compatibility is not used to hide V10.

---

## 8. Closing note

The Rail's strongest idea is restraint with teeth. It gives the portfolio a
daily surface without demanding that every product become a daily destination,
and it makes quietness, source truth, and user-granted attention executable. The
next milestone is not more breadth. It is evidence that a real person wants this
narrow companion beside them after the novelty wears off—and that the content
operations can keep it honestly alive.
