The single index mapping every journey in this folder to the Playwright spec(s)
that guard it, with a coverage-depth grade. This is the source of truth for "is
this flow tested, and how well". See
../00-conventions.md § E2E test coverage for the
cross-link convention and the depth rubric, reproduced here:
| Depth |
Meaning |
| deep |
Drives the journey's interactions, asserts state transitions + post-conditions, exercises ≥1 failure mode. |
| partial |
Exercises some steps but skips key interactions, failure modes, or post-conditions. |
| shallow |
Smoke only — asserts a heading/URL renders; does not drive the journey's interactions. (The test-equivalent of a stub.) |
| none |
No spec meaningfully covers the journey. |
Specs live under ../../apps/oshun/web/e2e/. Every
journey-backing spec carries a Journey: header comment pointing back here;
every journey doc carries an ## E2E coverage section. When you add or deepen a
spec, update all three: the spec header, the journey's section, and this
row.
Nisaba note (2026-06-26). nisaba-scholarly-read now drives the compact
/nisaba language buttons through Pali, English, and Both, asserting
aria-pressed, active-language attrs, and the reading body swap against the
live passageBodies payload.
Walkability note. The journey docs were written before several backing
routes/endpoints shipped, so a number of "BFF TBD / route does not exist"
open-questions are stale — verified 2026-06-04 against source. Routes that
exist today: /arete/offering, /arete/review, /veritas/retraction,
/atelier, /atelier/image, /aaa-upgrade, /billing/crypto,
/metis/byom, /metis/tutor, /operator/admin/isis/provenance,
/operator/{tenant,metis,incidents,studio,sso,audit}. BFF routes that exist:
customer-message-center.ts, user-reports.ts, telegram.ts,
admin-audit-log.ts, themis.ts, data-deletion.ts, data-export.ts,
living-scenes.ts, admin-tenant-console.ts, SCIM in domain-stubs.ts. The
one genuinely-absent surface is the customer appeal UI
/integrity/<verdictId>/appeal (themis) — that journey's appeal-form step
stays none until the route ships; its verdict + operator-review steps are
walkable.
At a glance (baseline audit 2026-06-04)#
| Depth at baseline |
Count |
| deep |
1 |
| partial |
29 |
| shallow |
11 |
| none |
11 |
| total |
52 |
Progress (2026-06-04). 25 journeys were authored or deepened to real
coverage and verified green against a live web + BFF stack — the entire
MISSING + SHALLOW set plus the six customer-domain entries. A subsequent
deepening wave then added 12 runtime-verified specs (53 tests green,
--workers=1, no stubs/fixtures) that lifted 14 previously cross-linked
baselines into driven, failure-mode coverage: scene-password-and-grants (scene
×3 — multi-context password gate, download-grant redemption/media integrity,
unlock-token tamper, abuse reports, rate-limit), pwa-lifecycle-deepening (PWA
×3 — cache purge, offline banner/retry, deterministic reduced-motion spinner),
notifications-preferences-api, editorial-release-streams,
persona-governance (BFF scope/validation/state-conflict gates),
nyx-event-ics, onboarding-deepening, first-time-visitor-deepening,
first-tara-sit-deepening, assistant-handoff-deepening,
multi-device-handoff-deepening, and sophia-grounded-deepening. The remaining
partial/deep baseline journeys stay bidirectionally cross-linked (their
surface-specs cover the surface; see each journey's ## E2E coverage for
per-step gaps — the baseline suite relies on the config's retries: 1). The two
formerly deferred journeys are now wired A-to-Z:
agentic-pipeline-customer-invocation has a real customer "Run Now" surface on
/arete/review driving the AgentRun lifecycle (request → confirm/discard)
against the live BFF (agentic-pipeline-runnow-arete), atop the BFF execution +
governance core (agentic-pipeline-invocation); only the downstream
tool-execution loop + provenance hash-chain stay executor-bound (fail-closed
without provider creds). themis-assessment-appeal is no longer blocked — the
/integrity/<verdictId>/appeal route + page shipped this session
(integrity-appeal). Every journey now carries an ## E2E coverage section and
every journey-backing spec a Journey: header. Status legend: ✅ verified
(authored + green) · ✅ cross-linked (baseline spec, partial depth) ·
deferred / blocked · render-only (specimen) (the spec is green but the
surface is a server-rendered design specimen with no backend/onClick, so depth
is shallow until the product ships the interaction).
Quality pass (2026-06-05). An adversarial re-audit of all 52 journey specs
(8 parallel read-only auditors) drove a correctness wave — see
../results/journey-e2e-quality-audit-2026-06-05.md:
(1) the one true tautology killed — messages-center faked its inbox via
page.route-fulfill; the producer seam was missing, so a real
POST /v1/admin/customer-messages/dispatch route was added and a real-HTTP
messages-center-bff spec now drives the genuine
deliver→read→archive→unsubscribe→suppressed lifecycle. (2) Dead/misleading
scaffolding removed — the dead stubSso (server-component, never fired) + a
dead 52-line memory conflict helper + false "Run Now not wired"/"unwired
span"/grace-cancel/step-2 headers. (3) Grade honesty —
weekly-review-arete, veritas-retraction-cascade, metis-byom-ingest,
atelier-image corrected deep→shallow (render-only specimens);
sophia-grounded-answer, editorial-review-approval,
citation-drift-resolution, nyx-tonight-observation + the three scene
journeys corrected deep→partial to match reality / the journey docs. (4)
Real depth added — offline /healthz BFF-unreachable probe, user-flag
all-10-categories, veritas→nisaba real-surface destination + reframed failure
mode, tenant-audit bookmark/share legs, tenant-invite invalid-email +
seat-capacity (409), and later invite acceptance/cockpit read-back/reuse guards.
(5) Cross-link triangle reconciled — missing Journey: headers added
(metis-tutor-session, metis-assessment-submit,
nyx-event-pages→nyx-tonight) and every journey doc now carries a
**Coverage depth** line.
Quality pass — Wave 2 (2026-06-05, "address all other gaps"). Drove the
remaining FEASIBLE gaps to real tests and catalogued the rest as product gaps
(documented, never faked — see
../results/journey-e2e-quality-audit-2026-06-05.md
§ "Resolution log — Wave 2"). Killed the nisaba search step-1 tautology with a
real-BFF re-issue (+ a real WCAG fix to the WorkspaceControls count badge);
added SCIM PATCH/DELETE, audit-quota (store unit), agentic approver-gate, themis
appeal min-length, telegram verify-initdata HMAC (→ messages-quiet-hours
binding), lilith-studio failure modes, scene embed/delete/tenant-auth/policy,
metis word-count gate, cookie-accept, memory wrong-step-up-phrase, and
weak-assert tightening. Confirmed PRODUCT gaps (not test gaps): incident static
filter chips + localStorage fake decision panels, absent /scene+/atelier
error.tsx, the citation-drift write-action gap, the tara-daily different-streak-
models inconsistency, the absent operator review UIs, and the Sophia grounding
pipeline. messages-quiet-hours corrected deep→partial (config +
Telegram-HMAC layers, shipped bind→verify→revoke UI, and BFF quiet-hours
dispatch delay/bypass now driven; external-channel replay, persona, and full
revocation cascade remain unbuilt/undriven).
Quality pass — Wave 4 (2026-06-05, independent adversarial re-audit of all 52
journeys). Full fix-list in
../results/journey-e2e-quality-audit-2026-06-05-wave4.md.
(1) Fixed a BROKEN spec — operator-editorial-review-approval asserted the
retired awaiting audit replay string; Wave-3 had rewired the panel to a real
admin-gated BFF write that 403'd under its non-admin session. Re-issued the
decision POST with an admin bearer; asserts the real data-decision-audit-id.
(2) Killed two false-green tests — the pwa-lifecycle cache-purge
(currentCachePresent || staleCacheAbsent, always true in the mock-SW env) is
now a real apply-handshake e2e, a genuine sw.js activate-eviction unit
test, and a later real-browser ServiceWorker + Cache Storage activation proof;
the citation-drift hash-chain core (under if (inspectorVisible), silently
no-op in the default no-ledger env) first moved to visible skips in Wave 4, then
the 2026-06-23 pass replaced those skips with a harness-only Isis fixture ledger
plus clean/broken/unavailable/empty browser assertions. (3) Real depth added
— quiet-hours GET-after-PATCH persistence round-trip (the window genuinely
survives, the patch response only mirrored a different store), user-flag visible
min-length error element (empty-rationale JS guard, not the native gate),
public-scene empty-detail accepted. (4) Cross-link triangle completed —
replaced the generic "Backs the journey" header with accurate per-step Covers:
lines on 33 specs, added the missing nisaba-scholarly-read back-link to
the two split-view/compare specs, the tara-daily-ritual headers to the player
specs (lifting it to a legitimate cross-spec deep), and the
tenant-bulk-member-invite-scim Path-B back-link to tenant-member-actions.
(5) Grade honesty — veritas-evidence-trail deep→partial (now
BFF-backed for the grounded-lead happy path; browser failure mode and static
claim/source drill remain open), veritas-to-nisaba-deeper row reconciled
deep→partial to match its doc, editorial prose de-staled (real audited BFF
write, not localStorage setTimeout), nyx-tonight doc passage=→
topic=night-sky (verified against source + tightened the spec assert).
Confirmed-and-left (verified, not faked): the audit-investigation quota is
already store-unit-covered (a 100-POST e2e would be redundant); the Sophia
grounding pipeline, billing-crypto paywall, and the operator review UIs stay
honestly graded + documented. The formerly open SCIM 201/Postgres path is now
covered by tenant-member-invite-scim (2026-06-24: POST → GET → PATCH → DELETE
→ revive plus canonical mirror).
Quality pass — Wave 5 (2026-06-05, fresh 7-auditor adversarial re-audit of all
52 journeys + fixes verified green on a live web+BFF stack, workers=1). Full
fix-list in
../results/journey-e2e-quality-audit-2026-06-05-wave5.md.
(1) 4 new wireable tests (all green): first-tara-sit-deepening ×2 —
exit-at-<80% → shame-free partially-completed surface, and an offline
reflection queue (navigator offline → tara:reflection:<id> localStorage +
"saved locally, will sync" hint); scene ?error=missing-password gate
render; scene mass-share 429 mass_share_pattern (x-oshun-share-burst-max
burst guard). (2) Two prior-auditor premises were WRONG and a live run caught
them — messages-center mark-read refresh is served by the real unseeded
BFF ("0 unread of 0", not a stubbed "of 2"), and the /nisaba reading desk
renders the SSR unavailable fallback in e2e (the room fetch is
unauthenticated), so the chip test's stale 'Greek' claim and a pinned passage
title were both fictional; both reverted to assert the real rendered state
and the masking ||-disjunction killed. (3) Cookie-consent "rejected
suppresses the PWA prompt" is fiction across 3 PWA journeys — the gate is
cookieConsent !== null, so reject resolves consent; corrected to the
unresolved gate the spec actually drives. (4) Scene studio-card keep/share
are client-only soft-notices on the auth:anon page (no BFF persistence) —
over-claim corrected in the spec header + journey doc; the real
keep→share→viewer lifecycle is the authenticated request-fixture tests. (5)
Assertion tightenings: aaa lang→'en', metis quiz exact 1 of 4 correct,
agentic runStatus→'running', incident heading exact 6 open · 1 critical,
SCIM DELETE 503 SCIM-Error body, nisaba-notebook unconditional format buttons
(vacuous if(count) guards removed), assistant-invocation exact
International Energy Agency. (6) themis appeal-filed
Case(=verdictId)/Status read-back asserted (proves real bridge data, not a
placeholder). (7) Cross-link/doc honesty: explore-blended
Arete→Nisaba/Metis, metis-byom step-7 claim, tenant-onboard Covers 1–3→1–2,
assistant-handoff-deepening outcome applied, two durable-reload tests
relabelled localStorage-rehydrate, lilith-studio two now-covered failure
modes, tenant-scim wired-buttons, citation-drift seeded-ledger prose.
Confirmed product gaps (documented, not faked): the messages-center
unsubscribe test carries a pre-existing form-submit/route-capture timing flake
(passes on retry). The earlier Arete streak-heatmap a11y gap was closed later:
cells now carry date + state labels and are covered in arete-streak-recovery.
Quality pass — Wave 6 (2026-06-05, fresh 8-auditor adversarial re-audit of all
52 journeys; doc
../results/journey-e2e-quality-audit-2026-06-05-wave6.md;
all green, branch+main). The audit's headline finding: several journey docs
declared real, registered BFF routes "absent / product-blocked / canned" — they
exist and were simply untested. 11 new real-HTTP BFF specs now drive them
(probed live before asserting): arete-habits-bff (POST /v1/arete/habits
persist + GET round-trip + 422 — replaces arete-full-journey's page.route mock
with the genuine engine), metis-ingest-bff (/v1/metis/ingest +
/v1/metis/courses — disproves "no POST route"), sophia-answer-bff
(/v1/sophia/answer envelope + the no-sources abstention contract — never
fabricates), entitlements-aaa-bff (/v1/entitlements/aaa tier gate — the
aaa-upgrade open-question #4), psyche-tutor-memory-bff
(/v1/metis/tutor-session-memories mastery-posterior fold — disproves "route
absent"), nisaba-notebook-bff (notebook create→rename→GET CRUD — disproves "no
write endpoint"), library-shared-resolution (recipient share-link
resolution grant/wrong-403/ revoked-403 — the headline opt-out invariant
collection-share created links for but never resolved), tenant-invite-role-bff
(invite roleIds round-trip + 403 non-admin), telegram-binding-bff
(login-widget iris binding scopes + step-up gate), persona-rehearsal-bff
(rehearsal lifecycle + tone-calibration on seeded persona-zen-guide + gates),
admin-auth-policy-bff (auth-policy evaluate verdicts — honest sibling of the
tenant-SSO journey, NOT its claim-mapping panel). Plus deepenings: tara
Begin-sit telemetry contract (tara-full-journey), multi-device handoff-write
failure mode (workspace-multi-panel). Test-hygiene fixes: repointed
veritas-nisaba-bridge's source-directory test off the unmounted
SourceDirectoryOverlay dead code onto the live
VeritasSourceDirectory → SourceProfile affordance (it now drives + navigates
to the real Nisaba surface); killed silent-pass conditionals in pwa-smoke
(theme-color/apple-meta unconditional, /sw.js served, skip-link count≥1) and the
vacuous cardCount===0 escape hatch in library-save-collection-share. Stale
doc claims struck in psyche / sophia / metis-byom / nisaba-notebook journey
docs. metis-byom-ingest lifted shallow→partial (real ingest/course BFF now
covered; 2026-06-29 browser proof added for /metis/ingest text outline and
/metis/courses/new proposal → /metis draft hydrate). Strict-read grade
note (transparency, not churned): the audit graded
first-time-anonymous-visitor, install-as-pwa, offline-first-time-use,
pwa-update-flow, and multi-device-workspace-handoff partial on a strict
reading (a key step + several failure modes are product-blocked — email
verify/Mailpit, SW-reg-fail, BFF round-trip); they retain deep on the
rubric's "exercises ≥1 failure mode" bar, with the uncovered steps documented in
each journey doc. Confirmed product gaps (documented, not faked): onboarding
has no inline-error UI on patchProfilePreferences failure; nisaba notebook
item-capture needs a resolvable refId; veritas /v1/veritas/briefing/home 500s
on an upstream fetch in e2e; telegram payments settlement is provider-env-gated.
Wave 7 (2026-06-06) — BUILT the wave-6 "deferred product-feature backlog" (the
user directed "all locally-actionable, 0 deferral; build the local seam
fail-closed for external-cred parts, use expert judgment for inert-button
behaviors"). All shipped real + e2e-verified green, branch+main. Product
features wired A-to-Z (each: a lightweight BFF store+route over a real concept +
a client island + a web→real-BFF e2e):
- arete close-the-week (
arete-review-close): "Close the week"/"Save as
private letter" → POST /v1/arete/review/close (week-closed / kept-private)
plus /arete continuity read-back through /v1/arete/room.
weekly-review-arete shallow→partial.
- arete recovery offers (
arete-streak-recovery): the inert offers + "Begin
· 6 min" now navigate to faithful targets (a calming /tara/sit, /arete/plan) —
closes step 5.
- arete living-offering keep/send (
arete-offering-actions): Save draft /
Send → POST /v1/arete/offerings/keep (draft-kept / delivered).
- atelier save + cast (
atelier-plate-actions): Save plate → web library
(generated-artifact); "Cast twelve more" → POST /v1/atelier/cast, a REAL
fail-closed Stability image seam (503 provider_not_configured without creds).
atelier-image-to-library shallow→partial.
- metis operator BYOM decision (
metis-byom-decision):
approve/request-changes/reject → POST /v1/admin/metis/byom/decision (audited,
admin-scoped). 2026-06-30 addendum: the browser spec now drives the reject
branch through /operator/metis, and the BFF assertions require non-empty
audit ids for all three decision outcomes.
- AdminInbox selection-reactive (
incident-triage +new selection test):
clicking a queue row swaps the detail card + binds the decision panel to that
incident (was hardcoded to INC-2041).
- onboarding finish-error (
onboarding-lifecycle): a genuine 5xx
preferences-sync failure is now surfaced non-blockingly
(syncProfilePreferences discriminates 5xx from offline-first 401/404).
- OperatorSso/Audit empty-branch unit tests (server-component test pattern
established).
- lilith-studio scene publish (
lilith-scene-publish): publish → POST
/v1/admin/studio/scenes/publish (dedicated, studio:editorial-scoped — the
release-stream route was scope-mismatched). Hard-won gotcha (documented for
future builds): importing the LBtn component into a 'use client'
island BREAKS the client boundary (the page renders blank) — islands use plain
<button>/<a> + barrel CONSTANTS only (L/SERIF_L/SANS_L). Honesty:
public-scene-abuse steps 5-7 remain blocked — public reports land in a
separate abuse queue, not the operator inbox (the selection-reactive console
covers incident-triage, not the report→inbox surfacing).
Reconciliation pass — 2026-06-22 (adversarial completeness re-grade of all 52
journeys + 8 new route walkthroughs; full audit at
../results/v1-completeness-audit-2026-06-22.md
§3). The re-grade compared each row's CLAIMED depth against the TRUE depth a
careful reading of the backing specs supports, and the matrix + journey docs
were brought into agreement with reality:
- 3 over-claims regraded DOWN to partial.
pwa-update-flow
(deep→partial): the real sw.js stale-cache purge is now browser-driven
in pwa-lifecycle-deepening, and pwa-smoke now drives the reading-mode
mid-passage scroll-restore branch; pwa-lifecycle-deepening also now drives
the multi-tab controllerchange reload sequence and backgrounded-PWA
cold-start no-prompt behavior plus the in-flight BFF write/read-back leg;
offline-background-sync drives the service-worker queue/replay substrate,
and pwa-lifecycle-deepening now renders the real queued service-worker write
count in the update prompt. 2026-06-26 telemetry deepening now asserts
pwa_update_applied for both Refresh-now and silent cold-start paths plus
pwa_sync_queued, so the current matrix row below is back to deep.
tenant-sso-config-saml-oidc-claim-mapping (deep→partial): the SSO CRUD
surface, successful/fail-closed BFF OIDC probe outcomes,
metadata-XML/OIDC-discovery import parsing, operator import UI, editor-driven
persistence of all seven claim slots plus all four transform options, and live
OIDC callback transform/failure paths are covered. The dedicated tenant-admin
/identity cockpit now has real-infra browser coverage for anonymous gating,
tenant-scoped live SSO roster read-back, read-only sample identity-engine
evidence, and axe, but the journey's remaining setup spine — the tenant-admin
import/upload controls, the per-tenant auth-policy edit panel, sandbox-probe
UI verdicts, and the draft→enabled state machine — is uncovered. The stale
contradictory SSO_FIXTURE comment flagged in audit §4 #30 is closed.
offline-first-time-use (deep→partial): the /healthz BFF-unreachable
probe, PwaOfflineFallback shell/deep-route recovery controls, local offline
library edit, search-result offline-save local persistence + sync hint, Tara
reflection offline queue + sync dot, and service-worker queue/replay substrate
are browser-driven, and real-SW uncached deep navigation now falls through to
the cached shell with service-worker fallback controls that hydrate when the
client is available. The Nisaba lexicon/morphology offline degradation hint is
now browser-driven after live BFF passage hydration: cached term forms remain
visible and the online-only lookup control is disabled with "Available when
online" copy. Natural sync scheduling for the search/Tara writes remains
undriven. The customer-visible network-only denial copy is now covered by
profile Active devices refresh while offline, and the Nisaba 24-hour cache
window is now covered by real-service-worker fresh/expired BFF cache responses
plus component-level expired-cache workspace copy.
- 5 under-claims regraded UP.
scene-public-viewer-anonymous
(partial→deep): the doc undersold its own coverage — reduced-motion
and tenant-auth ARE driven; after the later unlock-token TTL deepening,
only PWA cold-launch is genuinely uncovered. account-deletion-and-dsar
(partial→deep): the deletion/export/DSAR lifecycle is driven over the real
BFF with the signed per-service receipt rows; only the deploy-bound
cross-service fan-out + anon email-link verification remain. incident-triage
(partial→deep): the inbox decision panel, filter chips, selection
reactivity, and the acknowledge→escalate→resolve lifecycle verbs (incl. the
rationale-floor bad-actor block) are all real audited BFF writes.
lilith-studio-tara-scene-publish (partial→deep): the authoring layer is
driven deeply — state transitions, the a11y-blocked publish gate, the
single-room sim-fail + viewer-role access-denied failure modes, and the
publish→persisted release-stream lifecycle (201/401/403/400); only
cross-surface steps 11–12 deduct. metis-byom-ingest-to-course
(shallow→partial): metis-ingest-bff + metis-byom-decision carry real
ingest/course/operator-decision depth, even though the /metis/byom specimen
page's upload affordances stay display-only.
First-time & PWA infrastructure#
| Journey |
Primary spec(s) |
Depth |
Status |
| first-time-anonymous-visitor |
auth-entry-flows (anonymous redirect preservation, sign-up/sign-in/recover submit, onboarding completion handoff, returning sign-in/recovery), email-verify-mailpit (real SMTP→Mailpit verification link, exact subject, next=/tara onboarding auto-handoff, fresh-browser verify-link session minting with HttpOnly cookies), email-verify-roundtrip (verify-email page states plus safe next, unsafe next fallback, and 44 px Continue target), welcome-marketing (crawler root preflight, root + /welcome OpenGraph/Twitter image route handlers, canonical metadata, conversion CTA telemetry), public-marketing (2026-06-30: /landing fixture-backed rooms/letters/tiers, all tier CTA entry/tier hrefs, text-only footer boundary, Hearth tier-click telemetry, mobile standalone no-overflow + 44 px CTAs, real-SW offline replay, social metadata/PNG previews, sitemap), pwa-smoke, cookie-consent-compliance, first-time-visitor-deepening (JSON-LD featureList, expired re-entry, landing CTA, signed-in /welcome continuation), first-time-deepening-2 (reauth re-entry + WebApplication/Offer JSON-LD), public-legal-pages (public legal branch: standard + Lilith legal routes, legal nav matrix, TOC/back-to-top/print controls, mobile no-overflow and 44 px targets, offline-after-load stability, DPA mailto/profile/EDPB link semantics, no telemetry hooks, axe, non-clickable Lilith footer markers), onboarding-lifecycle (abandoned draft resume + returning sign-in resume) |
deep |
✅ verified |
| first-tara-sit |
tara-full-journey (hub Begin link telemetry + /tara/sit/<id> play/pause/scrub/back), tara-session-player (immersive player transcript, speed, ambient, share/export, audio-load fallback, completion/reflection, Nisaba/Metis/Arete/Nyx/assistant handoffs), home-tara-centering-continuity (Home Tara rail placement, primary action keyboard open, companion ordering, outage routing), tara-daily-ritual (home rail anchors + anonymous /tara redirect), first-tara-sit-deepening (first-time fallback vs live Resume ritual rail, Lilith player idle/running/paused/scrub/transcript/captions/large-text controls, unknown-id app 404 with search/browser-back recovery, clock-controlled 90-second long-idle drift + scrub-to-paused recovery + resume telemetry, reduced-motion transport transition, voice speed/ambient slider keyboard aria-valuenow, partial-completion humane copy, offline reflection queue + LSyncDot + reconnect non-drain) |
deep |
✅ verified |
| install-as-pwa |
pwa-smoke (manifest/assets, SW asset, mobile metadata, /welcome/download install education including Safari Add to Home Screen copy, native install-prompt trigger, authenticated and unauthenticated standalone relaunch, reading-route update apply/deferral), pwa-install-update-offline (install dismissal cooldown, standard update deferral/re-prompt/ready transition, consent-unresolved update suppression, offline recent-content fallback, uncached deep-route fallback controls), pwa-lifecycle-deepening (refresh-now apply, multi-tab route-preserving update, real cache purge, silent cold-start telemetry, in-flight write durability, queued-write update note, offline banner/retry, reduced-motion spinner), pwa-failure-modes (SW blocked normal-web fallback, update/offline overlay co-mount, captive-portal false-online rejection, stuck-apply manual reload, controllerchange one-reload guard), offline-shell-routes / offline-write-deepening / offline-background-sync (offline shell availability, real-SW uncached fallback, local offline writes, sync hints, real service-worker queue replay), push-registration / nyx-service-worker-notification (web-push device registration and actual public/sw.js push/click routing) |
deep |
✅ verified |
| offline-first-time-use |
offline-shell-routes (cached shell navigation, BFF-unreachable /healthz probe, captive-portal 200 HTML false-online rejection, genuine BFF health recovery, real-SW uncached deep-route document fallback to cached shell + service-worker fallback controls that hydrate when the client is available, real-SW auth/session cache denial while offline, /operator/personas poisoned-cache document denial proving operator routes stay network-only, profile Active devices refresh surfacing the exact network-only denial copy, Nisaba fresh/expired 24h BFF cache responses), nisaba-split-view (live passage hydration → lexicon/morphology inspector → browser offline → cached term forms remain visible + online-only lookup disabled with Available-when-online copy), offline-write-deepening (browser-offline library collection mutation persists to local store for a server-hydrated item; live Nisaba search result save while offline persists to oshun.web.library.saved-items.v1 and renders the local sync hint), first-tara-sit-deepening (Tara reflection save under context.setOffline(true) queues tara:reflection:<id> and renders LSyncDot queued state + will-sync hint; reconnect currently leaves the queue intact because no drain exists), offline-background-sync (real sw.js IndexedDB queue survives offline reload, Chromium sync event replays same-origin Arete check-in through live BFF, queue drains), pwa-install-update-offline (offline recent-content fallback + deep-route retry/shell shortcuts), pwa-lifecycle-deepening (new) |
partial |
✅ verified |
| pwa-update-flow |
pwa-install-update-offline, pwa-smoke (2026-06-25: reading-mode prompt + Keep-reading deferral + explicit refresh preserving mid-passage scroll on the live Nisaba passage route, with stale offline snapshots cleared and /v1/nisaba/passages/:id BFF hydration asserted before/after refresh), pwa-lifecycle-deepening (apply handshake + pwa_update_applied refresh-now telemetry + two-tab controllerchange reload/route-preservation/no-stale-chunk leg + cold-start active-worker/no-prompt leg + pwa_update_applied silent-cold-start telemetry + Arete in-flight BFF write/reload/read-back leg + real sw.js stale-cache purge + real service-worker queued-write update-prompt note + pwa_sync_queued telemetry + reduced-motion spinner), offline-background-sync (service-worker queued-write persistence/replay substrate), pwa-failure-modes (lost skip-waiting manual reload, prompt/offline-banner co-mount, controllerchange one-reload loop guard) |
deep |
✅ verified |
| onboarding-ten-steps |
auth-entry-flows, onboarding-lifecycle (abandon/resume, returning sign-in resume, skip→edit→revisit, completed-user bare /onboarding behavior, required-step gates, browser + in-wizard reduced-motion suppression, delayed real /v1/preferences PATCH Saving state, 5xx Finish failure, browser-offline Background Sync replay), onboarding-depth-introduction, onboarding-deepening (deep-link memory step, zero-domain guard, interest→domain chips, 2026-06-26 sensitive-context opt-in → Memory-step reconciliation → real /v1/preferences PATCH, no-redirect first-run target branches for structured-learning → /domains/metis?origin=home plus Tara-only general practice → /domains/tara?origin=home, 2026-06-28 browser-offline Finish → real service-worker IndexedDB queue → Chromium Background Sync replay → BFF preferences read-back + queue drain) |
deep |
✅ verified |
Customer-domain entries#
| Journey |
Primary spec(s) |
Depth |
Status |
| tara-daily-ritual |
tara-daily-ritual, tara-full-journey, tara-session-player (now cross-linked), domain-readability (2026-06-25: authenticated-shell Tara reflection route keeps readable guidance/input measure after player completion) |
deep |
✅ verified |
| arete-create-habit |
arete-create-habit (Cue→Routine→Reward wizard → real POST /v1/arete/habits, identity line in whyItMatters, BFF id local persistence, browser arete_habit_created telemetry with persisted habit id + loop metadata, selected identity id local persistence + IdentityPanel read-back, real POST /v1/arete/habits/:habitId/check-in, polished /arete Done-today/streak/KPI read-back, second-device /arete BFF read-back with no Arete localStorage, Home Arete local streak read-back, Home footing practice-streak pending-local increment, seeded sample toggle local-only/no-BFF-write boundary, polished /arete/habits Propose-a-habit link → /arete/habits/new form field contract → same payload real BFF POST held-for-review response + authenticated GET read-back with zero streak/no kept-today state + browser /arete/habits live row read-back, /arete/streak live BFF zero/first-check-in count + single today heatmap marker), arete-habits-bff (2026-06-27: real POST persist/list/422 plus create/check-in 401 gates, invalid check-in 422, owner-only non-enumerating 404, no-store check-in, durable done→streak/todayKept read-back, and same-day skip/grace amendment) |
partial |
✅ verified |
| veritas-evidence-trail |
veritas-evidence-trail (claim rail + source-id drill + Save→saved-items BFF metadata readback + clean-device Library hydrate; 2026-07-02: grounded /veritas hub renders from the real /v1/veritas/briefing/home path, "Read sources" jumps to the real on-page #veritas-evidence-rail, and direct /veritas/claim remains the claim-mode fallback; 2026-07-02: veritas-retraction-cascade covers the /veritas next-visit private-correction trigger from the BFF personal-letter route, its privacy-preserving lead-page copy, and another-reader no-leak state; 2026-06-29: /veritas/topic masthead/settled/open/reading-history/source/gap/follow row-cell anchors, now including polished follow→BFF readback→reload persistence→unfollow cleanup, plus claim/source/counterclaim citation-band/provenance/reviewer/hash consistency; 2026-06-30: /veritas/story trajectory SVG path and point metadata derive from timeline entries, including current and retracted marker labels), veritas-full-journey (real BFF non-Veritas-scope no-lead render), veritas-home-outage (dedicated real BFF downstream-503 browser render), veritas-route (BFF home success/outage + followed-topic read/write routing), domain-readability (2026-06-25: authenticated-shell Veritas reader keeps the article constrained to the 62ch reading lane with annotation/context cues) |
partial |
✅ verified |
| nyx-tonight-observation |
nyx-tonight-observation (event detail → persisted observation row + eventId back-reference + real /v1/nyx/observations POST/GET + local-cleared observation-log reload + Home Nyx support-card + current-week Home footing KPI read-back + Observation Log Equipment tab versus Telescope Control Add Profile boundary), nyx-observations-bff (2026-06-27: real field-log BFF 401 read/write gates, 422 target validation, no-store POST, default unlinked/clear rows, owner-only list isolation, and durable POST→GET read-back), nyx-full-journey (event-calendar direct/hydrated close routing), nyx-event-pages (save/follow/reminder + focused sky chart + unknown event recovery + Veritas/Tara/Metis event-detail target click-throughs; 2026-06-25: Nyx→Nisaba overlay and concept-graph links run without stubNisabaWorkspaceApi, seed/read a real /v1/nisaba/notebooks record, and wait for live daily/notebook BFF hydration before asserting landed workspace views; assistant explainer actions open text/voice assistant modes) |
deep |
✅ verified |
| nisaba-scholarly-read |
home-nisaba-continuation (Home Nisaba live continuation seeds a real /v1/nisaba/notebooks record, verifies the browser reads that exact notebook card, and clicks notebook/library/support/primary action targets; unavailable primary + endpoint-failure fallback covered; daily passage remains a deterministic fixture because no Home seed writer exists), nisaba-scholarly-read (2026-06-27: real-BFF search result → live /domains/nisaba workspace header/signal/reading/action/quick-action anchors, compact /nisaba reading-desk page/header/language/section/marginalia/body/graph/related row-cell anchors for live room or honest fallback, section hash-anchor navigation with static current-section boundary, desk LSubNav click into legacy scholar mode, scholar header/toolbar/marginalia/highlight/apparatus/witness/crossref/concept row-cell anchors, legacy lexicon/manuscript/notebook/plan route anatomy, notebook robots/display-only boundary, legacy plan static boundary, browser-back desk return), nisaba-split-view (2026-06-25: authenticated shell without workspace route stubs; real notebook + annotation seed/readback; live daily/detail Dhammapada BFF hydration across compare, grounded, manuscript, annotation update/archive, notebook note, citation/export, scholar, notebook, concept, lexicon, timeline, influence, collections, study-plan, mobile lineage, and mobile note routes), domain-readability (2026-06-25: authenticated shell without stubNisabaWorkspaceApi; real notebook seed/readback and live daily/detail Dhammapada BFF waits prove the 62ch focused study lane, support, notes, compare, grounded evidence, and note inspector routes), viewport-fit (2026-06-25: live authenticated /compare route without stubNisabaWorkspaceApi; waits for real daily-passage BFF hydration and asserts compare workspace mode, responsive split/stacked layout, compare deck, and evidence/notebook inspector posture across breakpoints), redesigned-surface-breakpoints (2026-06-25: authenticated shell without stubNisabaWorkspaceApi; real notebook seed/readback plus live daily/detail BFF waits prove compare, passage, and notebook reading-desk posture across tablet/laptop/desktop breakpoint widths), visual-regression-pages (2026-06-25: Nisaba passage/compare/notebook/evidence/note/mobile lineage screenshots now run without stubNisabaWorkspaceApi, seed/read a real /v1/nisaba/notebooks record, and wait for live daily/detail BFF hydration before capture), nisaba-dashboard (2026-06-25: authenticated shell without workspace route stubs; live curated overview, study shelf, six-domain shared concept graph to Metis objective URL, and ranked domain recommendations), nisaba-reading-accessibility (2026-06-25: authenticated shell without workspace route stubs; service workers blocked; real /v1/nisaba/notebooks seed/readback drives the mobile note-sheet route; live daily/detail BFF responses back desktop/mobile axe scans for reading, compare, manuscript, annotations, concept, lexicon, timeline, influence, collections, study-plan, citations, scholar, and mobile home) |
partial |
✅ verified |
| metis-lesson-completion |
metis-lesson-completion (2026-06-27: Home Metis continuation handoff, schoolroom hub, course-card click-through, lesson footer-nav, quiz choose→submit→retry, reload durability), metis-assessment-submit (real BFF assessment submit→Themis verdict read-back + appeal handoff), metis-tutor-session (tutor transcript anatomy, citation chip → Nisaba, local composer queue, no-live-voice negative assertion) |
deep |
✅ verified |
Customer follow-ons & cross-domain bridges#
| Journey |
Primary spec(s) |
Depth |
Status |
| arete-living-offering-create |
arete-living-offering-create (2026-06-27: page/masthead/composition anchors, editable intention textarea feeding scene preview copy, scene label derived from sceneTimeline[0], score click-to-select state, selected-material Move earlier / Move later reorder controls, recipient/occasion sharing edits updating the masthead summary + send target, and cue-privacy full-promise reveal), arete-coach-bff (new: step-4 framework scoring, real BFF), arete-coach-ui (2026-06-27: direct /domains/arete/coach browser submit to real BFF reflective response + forced 503 honest fallback), arete-offering-coach-preview (2026-06-27: actual /arete/offering framework selector posts current intention to real /v1/arete/coach/responses, renders Stoic dichotomy-of-control response + four suggestions, then forced 503 clears stale preview and retries into a live ACT response), arete-offering-actions (2026-06-27: keep/send first pre-screen the browser-entered intention through real Lilith safety assessment, block a crisis-like intention with 988 resources + no keep write, fail closed on a safety-assessment 503 before any keep write, carry clean intention plus edited recipient/occasion into the real BFF, read back private member-scoped preview from /sent, reload /arete/offerings to prove live draft/sent gallery rows, cover forced keep 503s with visible alert + enabled retry into live draft-kept / delivered, and open the BFF-backed C2PA/cue-privacy receipt envelope with private-intent hash and no raw intent rendering) |
partial |
✅ verified |
| weekly-review-arete |
arete-weekly-review (2026-06-25: page/masthead/count anchors, all four act body-part/list cells, KPI value/color cells, mood chart/caption, journal row day/text cells, footer action region, no-shame floor), arete-review-close (close/save → real BFF + arete_weekly_review_closed telemetry + /arete continuity read-back), profile-notifications-index (2026-06-30: account notification index exposes the Arete weekly-review reminder category from the real Arete domain reminder preference; browser PATCH to /v1/notifications/preferences/domains/arete proves the category turns off while general reminders stay on), arete-review-reminder (2026-07-02: /arete in-app fallback reminder is derived from the same real Arete reminder preference, emits arete_review_reminder_shown, links to /arete/review, and disappears after preference opt-out) |
partial |
✅ verified |
| veritas-retraction-cascade-customer-view |
veritas-retraction-cascade (private letter through authenticated BFF personal-letter route, /veritas next-visit private-correction trigger from that same route with another-reader no-leak state, per-user 404/no-leak direct URL, read-once acknowledgement POST + same-reader reload hidden state, re-open-to-story link, saved-claim banner with corrected-source/recourse/remove affordances, item_unsaved analytics for the remove action, and /nisaba/notebook retraction disclosure → per-citation drill-down → corrected Veritas source profile with keep-with-marker placeholder honesty), veritas-retraction-cascade-bff (live source retract → Postgres/Redis durable cascade + audit marker → Sophia re-grounding verdict) |
partial |
✅ verified |
| metis-byom-ingest-to-course |
metis-upload-alias (legacy /metis/upload signed-in raw 308 with query preservation, signed-in browser landing, standalone PWA landing, and anonymous proxy gate before alias redirect), metis-byom-ingest (2026-06-25: customer /metis/byom page/header/material count/table-column/row-cell/drop-zone/guide-outline/provenance/action anchors; operator route page/header/KPI/review-row/side-panel anchors + anonymous redirect-before-render; 2026-06-29: live browser /metis/ingest text source → real BFF outline + /metis/courses/new proposal → real BFF → /metis drafted-course hydrate; 2026-06-30: /metis/byom Paste URL → real BFF awaiting-source job, Browse/drop Markdown bytes → real BFF completed outline), metis-ingest-bff (wave6: real ingest/course BFF, including URL/PDF awaiting-source references), metis-byom-decision (wave7 + 2026-06-30 addendum: real admin-scoped BFF approve/request-changes/reject decisions, browser-driven approve/request-changes/reject states from /operator/metis, and non-empty audit-event ids for all three HTTP branches) |
partial |
✅ verified |
| psyche-tutor-live-session-to-graded-record |
metis-tutor-session (2026-06-27: /metis/tutor page/header/transcript turn/citation/context/disclosure/session-note/composer row-cell anchors, local queue send/cmd-enter, citation click → /nisaba, no-live-voice negative assertion, plus real BFF tutor-session-memory seed → /v1/metis/room → browser /metis tutor nudge/week-stat read-back), psyche-tutor-memory-bff (2026-06-27: mastery-posterior fold, live-voice runtime/recovery/governance/Iris resume metadata, GET round-trip, learner-isolated newest-first list, 401/403/400/404 gates) |
partial |
✅ verified |
| tara-to-nisaba-handoff |
tara-session-player (2026-06-28: play-to-completion → Nisaba companion action → real /domains/nisaba?...stack=tara,veritas... handoff, then browser-back restores /domains/tara?...&taraSessionState=complete with the Tara completion surface and same companion card mounted), tara-to-nisaba-handoff-destination (2026-06-28: authenticated-shell Nisaba destination with no workspace route mock + real Sophia citation trail status/derivation steps + exact URL locator highlight + source-trail Canonical source chapter/paragraph/sentence locator drilldown) |
deep |
✅ verified |
| nyx-to-tara-bridge |
nyx-event-pages (fixed event-detail card + five static relationship buckets + source-only telemetry attributes → Tara timer player with stack-derived nyx_event_handoff metadata → accelerated local completion → generic Nyx suggestion; no hub cue, event envelope, audio-byte proof, emitted analytics, durable receipt, or exact event return) |
partial |
✅ verified |
| veritas-to-nisaba-deeper |
veritas-nisaba-bridge (landed Nisaba citation marker → matching source inspector; saved claim state survives browser-back; counterclaim tab inspection telemetry → open-nisaba-counterclaim-lineage → real Nisaba source-lineage surface; 2026-06-29: claim-ai-governance-adoption retracted-source confidence band → soft-correction href → real /nisaba/notebook correction notice → /nisaba/compare edition-update diff → corrected Veritas source), veritas-retraction-cascade-bff (backend retraction fan-out) |
partial |
✅ verified |
| arete-streak-recovery |
arete-streak-recovery (recovery navigation, Tara recovery-origin start receipt -> BFF session read-back + partial completion -> real BFF Arete engagement read-back, written one-sentence return -> /v1/arete/recovery/journal partial engagement read-back, real /v1/arete/streak trigger-engine timing for two missed windows still grace_window/intact and three missed windows crossing to freeze_window/protected, heatmap a11y, streak Adjust/Begin navigation-only no-mutation guard, coach decision BFF read-back, approved coach adjustment -> /arete/plan invitation + next intention row) |
partial |
✅ verified |
Discovery, messages, library#
| Journey |
Primary spec(s) |
Depth |
Status |
| messages-center-deliver-and-unsubscribe |
messages-center (2026-06-26: live browser /messages path seeds real BFF dispatch to the browser token subject, renders real /api/messages/inbox rows/receipts, follows through the Next proxy, mark-read/archive/unsubscribe/resubscribe through live /api/messages/* with success-idle/no-alert assertions, proves same channel+category re-dispatch is 422 suppressed, then proves restored dispatch renders after reload; 2026-07-02: shell bell badge reads customer-message unread count from /api/messages/inbox, /v1/notifications projects customer-message:* rows from the same store, drawer click writes /v1/notifications-write mark_read, and badge converges after inbox and drawer mutations; fixture cases remain for component edge states), messages-center-bff (real-HTTP dispatch→follow clicked receipt/no implicit read→mark-read→archive + repeated-archive idempotency→unsubscribe→suppressed→resubscribe→restored lifecycle, bounded 28-message snapshot → newest 25 default / newest 5 explicit limit with full aggregates, dedupe, cross-user inbox/follow/read/archive isolation with owner row non-mutation, and auth/error gates) |
deep |
✅ verified |
| messages-quiet-hours-and-channel-binding |
profile-notifications-index (2026-06-30: /profile/notifications authenticated /v1/profile/notifications projection from profile + notification-preferences + Telegram state, profile-email readback, real /v1/preferences push-disable reflected on reload, real Arete domain reminder PATCH reflected in the arete-weekly-review category on reload, invalid-bearer fail-closed empty copy, "Change delivery settings" → /profile?path=notifications quiet-hours editor, footer no-telemetry, standalone/mobile/no-overflow, and real-SW offline replay), notifications-preferences-api (quiet-hours PATCH→GET persistence, narrowed activeDays mask normalization [5,1,5,0,6,2] → [0,1,2,5,6], Tara push false→true gate, and 2026-06-29 full launch-domain × delivery-modality × category-kind matrix: every shipped domain tara/veritas/nyx/arete/nisaba/metis receives a unique {enabled, priorityOnly, modalities, kinds} PATCH and final GET proves exact top-level + nested preferences.domains persistence with no cross-domain bleed), messages-center-bff (2026-06-24: real-BFF quiet-hours dispatch 202 dispatch.delayed.quiet_hours, after-window replay via /v1/admin/customer-messages/replay-due with sent/delivered receipts, critical incident bypass; 2026-06-26: live operator crisis-frame activation + member projection read-back, non-essential 202 dispatch.suppressed.crisis_frame with empty inbox, delayed quiet-hours replay held with dispatch.suppressed.crisis_frame, and critical incident bypass), profile-notification-preferences (2026-06-26: browser quiet-hours weekday chips expose pressed state, narrow Sun/Sat out through real PATCHes, reload with persisted start time and active-day mask), telegram-webhook-delivery (new: Telegram HMAC binding gate), telegram-binding-bff (wave6: login-widget scopes + step-up), profile-channel-bindings (2026-06-29: real-service-worker browser pass through /profile Notification channels; email bind→pending BFF read-back→verify→verified BFF read-back→full route reload→remove→typed channel-revoke step-up phrase→unbound BFF read-back→reload, 390 px no-overflow/44 px controls, plus wrong SMS code stays pending in UI and BFF; 2026-06-30: direct BFF DELETE without x-oshun-channel-revoke-step-up rejects 428 step_up_required), push-registration (2026-06-10: web push DEVICE registration — "This device" row register/unregister → real /v1/device-tokens wire shape (stringified subscription, web-push), BFF-failure honesty, no-VAPID fail-closed; Push API stubbed at the browser boundary) |
partial |
✅ verified |
| telegram-bot-assistant-delivery |
telegram-webhook-delivery (real-BFF webhook secret gate, route-level rate-limit trigger, slash-command shortcuts, crisis persona swap + hotline buttons, real seeded-source grounded answer, honest abstention, 2026-06-26: below-minimum-citations and non-grounded-render throw paths both return honest abstention instead of 500/fabrication, fail-closed voice STT reply, successful voice-transcript crisis interrupt via production-disabled local transcript map, persisted Postgres admin_audit_event audit-sink rows for telegram.send and telegram.crisis-suppression, my_chat_member, callback_query save), profile-telegram-bridge (2026-06-28: customer /profile/telegram DOM route mints live nonce, client-side expiry removes the stale deep-link anchor and renders the disabled recovery state, refresh-link server action rotates the rendered t.me href through real POST /v1/telegram/link, real webhook /start link-<nonce> completes it, linked page render, 390 px no-overflow/static route/44px targets/no-telemetry-hook contract, offline-after-load stability, anonymous redirect), telegram-route (2026-06-28: real BFF GET reuses valid Telegram link nonce, POST rotates an unlinked nonce with 202 no-store, and rotated nonce completes through webhook) |
deep |
✅ verified |
| library-save-collection-share |
library-save-collection-share (2026-06-27: real-BFF saved-items seed/readback for asserted rows, library resume rail, saved queue filters/snooze/complete/resume, collection share-control mount, saved-item unsave, and anonymous→signed-in guest save migration through real /welcome sign-in → /v1/library/saved-items/sync → clean second-device /library hydrate; 2026-06-28: direct /domains/nisaba?path=/library/passage/... non-search save producer writes through the live saved-items BFF, verifies persisted passage metadata, and hydrates from clean second-device Library), veritas-evidence-trail (2026-06-29: direct /veritas non-search Save to notebook writes through the live saved-items BFF, verifies persisted Veritas passage metadata, and hydrates from clean second-device Library), search-saved-and-recent (2026-06-26: device-A real-BFF Nisaba search save → in-domain unsave/resave de-dupe → device-B cache-free /library hydrate/resume; Veritas claim/story + Tara practice + Nyx sky-event + Metis course search-result saves → saved-items BFF → cache-free Library hydrate → canonical resumes), explore-real-search-continuity (2026-06-29: live Explore-dashboard Nisaba result save → saved-items BFF metadata read-back → clean second-device Library hydrate), sophia-grounded-answer-page (2026-06-29: direct /sophia grounded-answer save → saved-items BFF query/primary-witness/trust metadata read-back → clean second-device Library hydrate), atelier-plate-actions (2026-06-27: non-search Atelier generated-artifact save → saved-items BFF metadata read-back → clean second-device Library hydrate), library-entitlement-and-save (+ cross-device saved-items: POST→GET propagation, LWW /sync+conflictsResolved, tombstone delete, per-user isolation; 2026-06-10: + the saved-cap limit-hit leg — a real free member at 25 server saves sees the inline paywall with the Pro CTA on /library), library-cross-device-render (new: device-B /library renders a server-saved item via store hydrate), library-collection-management (2026-06-27: collection CRUD/deep-link coverage plus legacy oshun.library.collections.v1 version:0 migration to current version:1, duplicate/stale item-id sanitization, and direct collection hydrate against BFF-seeded saved items), library-save-analytics, collection-share (2026-06-27: A-to-Z tokenized invite/referral link → real BFF, revoke/private, plus visible named-users grant and public-profile slug/tier controls with live BFF policy read-back), library-shared-resolution (wave6: recipient resolution grant/403), library-shared-web-view (2026-06-27: generated /share/:token recipient route resolves granted and insufficient-permission states through the real BFF and proves no recipient local collection fallback; 2026-07-02: walkthrough source reconciled so the old localStorage shared-link hard-gap is marked closed) |
partial |
✅ verified |
| search-explore-deep-read-library-save |
search-saved-and-recent (saved/recent UI + browser recent panel six-row newest-first eviction and case-insensitive duplicate promotion + real-BFF recent-query suggestions newest-eight cap/dedupe + real-BFF saved-search full advanced state restore for domain/kind/sort/score/saved/scope + server-initialized cold-start deep-link hydration with no no-query flicker + live-BFF 403 domain_scope_missing fetch-failure error state + same-query Retry reissue + long-list Browser Back scroll restoration from Nisaba deep-read + real BFF Nisaba nisaba-passage-speech result click → exact passage-mode id/reference/source/title/body + compare/support/workflow rails + real BFF Veritas claim result click → claim-detail evidence workspace + real BFF Veritas story result click → story timeline workspace + real BFF Tara practice result click → immersive session player + real BFF Nyx sky-event click → canonical event-detail workspace + real BFF Metis course click → active study destination preview + real search-result save → saved-items BFF → Nisaba in-domain unsave/resave de-dupe → cache-free Library hydrate → exact Nisaba resume URL + passage workspace; Veritas claim/story + Tara practice + Nyx sky-event + Metis course saves → saved-items BFF → cache-free Library hydrate → canonical destination resumes; 2026-07-02: walkthrough source reconciled so the real saved-items BFF endpoint, seeded destination handoffs, and cross-device Library hydrate are no longer listed as aspirational gaps), explore-real-search-continuity (2026-06-29: live /explore query/result hydration, domain-tab live refetch, and Explore-dashboard result save → saved-items BFF metadata read-back → clean-device Library hydrate), explore-blended-discovery, search-result-analytics |
partial |
✅ verified |
| nyx-event-calendar-sync-reminder |
nyx-event-pages, nyx-event-ics, nyx-event-actions-bff (real-HTTP PUT→GET reminder-state mirror + scope gates; cadence/channel route reconstruction; invalid body, event-id mismatch, missing-reminder-time 400s with no snapshot mutation), profile-calendar-sync (2026-06-10: per-user two-way surface — profile "Calendar sync" section: OAuth consent round-trip simulated at the Google boundary → connected banner + connection row; real-schedule preview; export with honest per-item failure outcomes + browser timeZone on the wire; disconnect; 503→"not configured" fail-closed), calendar-connectors-bff (real-BFF admin connector runtime: seeded OSHUN_CALENDAR_CONNECTORS, 401/403 gates including import/export admin-only mutation routes, secret-free Google connector roster, retained unsupported Apple descriptor, unknown connector import/export 404, import failed-run no-refresh-token issue, malformed export 400, provider export 502 fail-closed), nyx-service-worker-notification (2026-06-26: actual public/sw.js runtime receives a Nyx push payload, preserves the event actionPath in showNotification, cold-opens /domains/nyx/events/jupiter-venus-conjunction, and focuses/posts OSHUN_NOTIFICATION_TAP to an existing app window) |
partial |
✅ verified |
| nisaba-notebook-capture-and-cite |
nisaba-notebook-new (2026-06-30: authenticated browser create form against real /v1/nisaba/notebooks; CSRF header, visibility radio roving focus, BFF create/readback contract, mobile containment, text-safe submit/success telemetry), nisaba-split-view (2026-06-25: authenticated shell without workspace route stubs; real /v1/nisaba/notebooks + /v1/nisaba/passages/:id/annotations seed/readback; live daily/detail Dhammapada BFF hydration; notebook note capture, citation clipboard, annotation update/archive, collection creation, study-plan checkpoint progress, and mobile lineage/note routes), nisaba-reading-compare-annotate (2026-06-25: authenticated shell without workspace route stubs; real /v1/nisaba/notebooks seed/readback, live Dhammapada reading desk/workflow-map/compare URL, real BFF annotation seed → browser update/archive/show-archived, citation format selector), nisaba-notebook-capture-cite (2026-06-25: authenticated shell with no workspace route stub; waits for live /v1/nisaba/passages/nisaba-passage-attention, verifies Dhammapada citation formats, live source-inspector primary source + manuscript witness trail, citation download labels, copy status, private notebook export/print, robots meta, and 2026-07-03 browser Blob payload capture for Markdown/BibTeX/PDF export filenames, MIME types, and notebook contents), nisaba-annotation-bff (new: real-HTTP annotation lifecycle + gates), nisaba-notebook-bff (wave6: notebook CRUD; 2026-06-24: real-HTTP POST /:id/items passage capture, duplicate idempotency, GET hydration, unknown-ref 404), nisaba-analytics (2026-06-25: authenticated browser workspace seeds + reads a real /v1/nisaba/notebooks record and asserts persisted study-note plus nisaba_note_saved telemetry use that exact notebook), nisaba-metis-study-prompts (2026-06-25: authenticated shell direct-passage lesson handoff + collections prompts seed/read a real /v1/nisaba/notebooks record and prove source-backed Metis tutoring carries the seeded notebook ID) |
partial |
✅ verified |
Lilith policy#
| Journey |
Primary spec(s) |
Depth |
Status |
| crisis-aware-tone-policy |
profile-safety-crisis-recovery (2026-06-25: signed-in no-frame empty state; live operator activation → Redis worker projection → browser /profile/safety reads /v1/safety/crisis-frames/mine with no route mock; stillness suspend/lift, re-entry accept/decline, 24h deliver/dismiss, 7d opt-out, anonymous redirect; 2026-06-30: real BFF frames[] timeline across assistant/iris/lilith-video/psyche/tara plus expandable assistant-frame detail; 2026-06-30: surfaced us-988 link target and lilith_safety_resource_opened telemetry from the live safety record), crisis-safety-policy-bff (2026-06-27: real 13-rule classifier + public crisis-resources + live audit API 401/no-store empty record + activation 403/400 guards + operator activation → Redis worker projection → member-visible /v1/safety/crisis-frames/mine read-back across assistant/iris/lilith-video/psyche/tara), arete-offering-actions (2026-06-29: active /arete/offering typed distress sends a direct browser→live-BFF Lilith safety-assessment request with auth-context bearer, swaps the action region into the safety interrupt with 988 resources and /profile/safety handoff, and proves no keep/send write occurs) |
partial |
✅ verified |
Account, billing, identity#
| Journey |
Primary spec(s) |
Depth |
Status |
| account-deletion-and-dsar |
profile-customer-data-deletion (2026-06-23: real Redis fan-out voice-profile signed receipt rendered from live BFF data; 2026-06-26: browser /profile?path=data-rights generated_artifacts deletion seeds Isis generated_outputs, renders signed generated_artifact receipt, and verifies hard-delete; snapshot mock retained only for unattested negative row), profile-data-rights, profile-customer-data-export, profile-data-readback (2026-06-24: standalone /profile/data read surface seeded by live BFF export/deletion POSTs; 2026-06-25: consent read moved to real consent-store projection, anonymous gate, 50-row export cap, download aria label, and mobile 44px controls; 2026-06-27: real Chromium service-worker online warm → offline /profile/data document replay keeps live-BFF export/deletion rows visible while navigator.onLine === false and no generic fallback card is used), data-rights-dsar-bff (2026-06-25: live BFF export/deletion/admin DSAR, signed voice-profile receipt, and real Isis generated_artifact erasure receipt) |
deep |
✅ verified |
| memory-edit-pause-forget |
profile-memory-controls (+ edit/pause/export/hard-delete/full-clear grace; 2026-06-27: browser analytics assertions for edit, pause header/banner source, hard-delete, full-clear request/cancel, with no raw memory content in payloads), memory-edit-pause-forget (2026-06-25: real Next auth bridge + real Iris empty review → explicit empty ledger/inspector/no fabricated facts; real consents + remember write → review readback → /profile/memory sync notice/row/inspector/export projection; filters, detail-pane provenance/recalls/reference metadata, pause-banner resume, tenant-scope rejection; 2026-06-26: server-authoritative pause gate over live BFF PATCH /v1/iris/adapter/pause, continuity indicator: "off" read-back, 409 iris_memory_paused no-write guard, review absence for the blocked sentence, and post-resume write read-back; 2026-06-27: /profile/memory pause toggle persists to live Iris pause, emits memory_pause_toggled with persisted: "bff", assistant dock context handoff + memory disclosure switch to off, collapsed dock summary carries the persisted memory-off state, banner Resume persists pause back off, anonymous direct /profile/memory redirects to /welcome?redirect=/profile/memory, and browser-offline signed-in cached rows stay readable while BFF pause writes fail closed without committing local pause; 2026-06-28: two isolated browser contexts share one real BFF session so device B's /profile assistant dock reads memory scope off after device A pauses and session after A resumes; 2026-06-30: transient Iris review read failure shows data-profile-memory-bff-status, preserves cached rows, then clears after retry reaches the real BFF; 2026-06-30: synced profile-memory hard delete calls live DELETE /v1/iris/adapter/memory/:memoryId and review read-back excludes the deleted memory id/content; 2026-06-30: same-origin two-tab edit conflict keeps tab A's stale dirty draft after tab B saves a replacement, shows data-profile-memory-edit-conflict, resolves through both keep-remote and overwrite buttons, and asserts both conflict telemetry events; 2026-06-30: synced export posts to live /v1/iris/adapter/export?role=settings, asserts JSON/consent/metadata options, renders the returned export id/count/checksum receipt, and still exposes the local signed JSON artifact) |
partial |
✅ verified |
| sign-up-and-pay-crypto |
billing-index (2026-06-25: signed-in /billing directory, anonymous gate, crypto/profile/AAA/mailto rails, mobile 44px/no-overflow), billing-crypto-paywall (2026-06-28: anonymous /billing/crypto redirect, pending/sanitization gate with return/support actions, 44px targets, return-to-billing navigation, and noindex, nofollow metadata; real BFF-issued BTC and USDC/Base invoices rendered through /billing/crypto -> live by-id fetch -> <CryptoPaywall> with visible disclosure version, asset/network controls, trust-tier badge, QR/address block, copy interaction, issued-paywall support actions in BTC address-visible, USDC disclosure-gated, and USDC post-ack states, and disclosure ack; signed settlement webhook flips the invoice to confirmed, grants purchaser plan pro, records purchaser-scoped txId, hides the stale browser address on reload, proves idempotent webhook re-delivery, and 2026-07-03 failed settlement receiver paths reject invalid HMAC/malformed signed/unknown-invoice POSTs with no invoice status/txId or purchaser-plan mutation), entitlements-aaa-bff (wave6: entitlement gate /v1/entitlements/aaa) |
partial |
✅ verified |
| aaa-upgrade-entitlement-bounce |
aaa-upgrade-entitlement-bounce (new; 2026-06-30: /aaa-upgrade view telemetry plus both CTA click telemetry events with safe source/destination payloads; 2026-07-02: mobile standalone no-overflow/touch-target state and real service-worker offline document replay), entitlements-aaa-bff (wave6: /v1/entitlements/aaa tier gate, open-Q#4) |
deep |
✅ verified (4/4) |
Scene & atelier authoring#
| Journey |
Primary spec(s) |
Depth |
Status |
| scene-keep-and-share |
living-scene-card (public share → playable viewer, share-settings iframe/oEmbed copy, oEmbed JSON, playable embed, revoke tombstone, delete cascade), scene-password-and-grants (password-protected share/gate/unlock, password-protected embed break-out card, explicit-consent 400, tenant-policy public-share 403, crisis-private-only 422, non-crisis Lilith safety-frame 422 + share_denied audit, download-grant APNG redemption + C2PA media-hash integrity, operator originating-user takedown cascade over two public shares + embed denial + existing grant 410 + tenant audit, tamper/rate-limit/revoked-report edges), scene-stored-tenant-policy via playwright.living-scenes-stored-policy.config.ts (override-off stored tenant policy: spoofed public share denied, audit share_denied, tenant-internal still allowed), scene-viewer-deepening (lost-response retry returns same share with idempotentReplay and one tenant-audit create row) |
partial |
✅ verified |
| public-scene-abuse-report |
public-scene-abuse-report (anonymous report form → real BFF 202, empty-detail accept, signed-in report stamps bearer reporter and appears on /profile/safety as open→resolved, self-harm report → live S1 "critical" auto INC on /operator/admin with /scene deep link, admin resolve/dismiss write verbs with persisted status read-back), scene-password-and-grants (rate-limit + revoked-share report edges; operator takedown cascade tombstones all share links and invalidates a prior download grant) |
deep |
✅ verified |
| scene-public-viewer-anonymous |
living-scene-card, scene-password-and-grants (password gate, unlock-token replay, expired-token cookie fallback, tamper, embed break-out, download-grant integrity), scene-viewer-deepening (OpenGraph/Twitter/robots metadata, high-contrast viewer, idempotent public-link retry) |
deep |
✅ verified |
| atelier-image-to-library |
atelier-image-to-library (2026-06-26: /atelier room-grid/house-rule anchors, /atelier/image plate-head/live-step-rail/editable-prompt/selectable-contact-sheet/specimen/plate-field/provenance/action-row anchors; prompt edit, aspect/style changes, seed-lock toggle, p.03 selection → step 4 + plate detail, Compare side-by-side panel, and 390 px index/image stacking with no horizontal overflow), atelier-plate-actions (2026-06-27: save idle→saved state advances step 5, reads generated-artifact metadata from the saved-items BFF, hydrates the row in a clean second-device /library?kind=generated-artifact; 2026-06-28: saved Atelier plate carries trustState.provenanceState='partial' through the BFF and renders the Library provenance badge + lineage note on first and second devices; 2026-07-02: save emits atelier_plate_saved telemetry with room id, prompt hash, seed, seed-lock state, and source-set size; cast and refine POST browser-entered prompt + selected specimen + aspect/style/seed-lock state to real /v1/atelier/cast and surface provider-not-configured fail-closed state) |
partial |
✅ verified |
| atelier-video-render-queue |
atelier-video-render-queue (2026-06-28: authenticated /atelier/video route anchors, all 12 fixture storyboard labels/times/titles/states, coherent sh 06 rendering + sh 07-10 queued state, three render queue rows with progress/ETA, selected shot-card metadata, read-only storyboard/queue/preview click non-mutation, disabled-placeholder Cut timeline action, reduced-motion zero-animation subtree, offline-stable loaded markup, and 390 px no-overflow stack) |
deep |
✅ verified |
| atelier-motion-to-cinematheque |
atelier-motion-to-cinematheque (2026-06-28: authenticated /atelier/motion route anchors, five fixture timeline tracks/keyframes/frame-72 selection, bake 41% / 59 of 144 frames, take 02 kept state, read-only viewport/ruler/keyframe click non-mutation, disabled-placeholder New take/Re-target rig controls, real /atelier/video Cinematheque handoff; 2026-06-30: explicit URL-scoped motion→Cinematheque handoff context plus inbound panel assertions; reduced-motion zero-animation subtree, offline-stable loaded markup, and 390 px no-overflow stack) |
deep |
✅ verified |
| lilith-studio-tara-scene-publish |
lilith-scene-editor-smoke, lilith-scene-editor-deep (2026-07-01: every scene-editor control, all asset handles and placement buttons, browser drag/drop, graph selection, all lighting/audio/binding/capacity/sharding/accessibility controls, readiness rows, provenance selection, publish manifest, real-BFF publish, re-edit-to-draft, exact-route real-SW offline replay, and mobile standalone no-overflow), lilith-studio-shell-smoke, lilith-scene-publish (wave7: publish → persisted release stream), studio-review-approval-workflows (supporting V1 workflow route: real approval-workflow catalog/evaluate BFF, stage table, quick-action targets, validation/error/pending/unauthorized/anonymous branches) |
deep |
✅ verified |
Operator, studio, cross-surface#
| Journey |
Primary spec(s) |
Depth |
Status |
| editorial-review-approval |
operator-editorial-review-approval (2026-07-03: /operator/admin shared decision panel reject/retract branch now proves no/short rationale leaves the action placeholder-disabled with no browser POST, valid rationale records rejected-retract through the audited BFF route, and BFF GET rehydrates the same rationale/audit id), operator-admin-evidence-queue, editorial-release-streams (release-stream BFF API/audit, invalid blocked-without-blocker and post-terminal mutation guards with no state/audit mutation, plus /operator/studio admin-scoped decision-row approve/request-changes POST/PATCH, visible release-stream receipt, reload durability, and audit-event read-back), operator-studio-surface (/operator/studio page-DOM coverage: operator bar/breadcrumb, seven review queue rows, selected TR-047 artifact pane, waveform/transcript, decision-row entry point, review notes, citation statuses, static queue-row boundary, anonymous redirect) |
partial |
✅ verified |
| incident-triage |
incident-triage (new; wave7: + row-select → detail/decision swap; +lifecycle verbs: acknowledge→escalate→resolve + rationale-floor block; 2026-06-25: direct /operator/incidents page/masthead/lane/list/row-cell/footer anchors, exact 1-open/1-closed tally, lane/list counts, real incident-id assertions, direct /operator/admin page/header/row-cell/detail/drift-source anchors, opt-in BFF lifecycle reseed, and anonymous redirect-before-render for both operator routes) |
deep |
✅ verified |
| citation-drift-resolution |
citation-drift-resolution (harness ledger: clean/broken/unavailable/empty + 16-field bundle detail; 2026-06-25: provenance tenant-scope, bundle-row metadata/timestamps, tenant-preserving detail navigation, unknown-bundle fallback, generated-artifact inspector, and anonymous redirect-before-render; 2026-06-30: terminal recheck/re-render/retract controls post to real /v1/admin/citation-drift/:incidentId/resolutions, block short rationales, read per-operator resolution receipts back, verify drift.* audit-log events, and prove broken-ledger actions are disabled; 2026-07-01: per-source classification UI posts all three drift sources to real /v1/admin/citation-drift/:incidentId/source-classifications, blocks short classification rationales, reads classification receipts back, verifies drift.source_classified audit-log events, and now drives a chosen retract decision through shared INC-2041 resolution with created→resolved incident-history read-back plus linked incident.resolved audit evidence) |
partial |
✅ verified |
| lms-connectors-operator (new 2026-06-10) |
lms-connectors (pure-BFF list/validate/CRUD over real HTTP: seeded valid connector + retained invalid descriptor reasons, 401/403/200 envelope, dry-run invalid/valid verdicts, managed create/delete, managed override over env, delete-to-restore-env, env tombstone fail-closed login, LTI login→launch JWKS fail-closed) + operator-lms (browser page DOM: 2026-06-25 generatedAt/count/card/field anchors; seeded roster + invalid panel via admin access cookie; exact Canvas connector metadata/capability/LTI fields; exact source badges; exact Moodle invalid issue count/code/path/severity anchors; wrong-scope fail-soft empty; malformed JSON zero-POST; real-BFF 400/invalid/valid dry-run legs; browser managed connector save/delete through the real BFF bridge; 503 failure copy) — unit: lms-route.test.ts, operator/lms page.test.tsx, LmsConnectorValidateForm |
deep |
✅ verified (env list/validate plus managed create/override/restore/delete path covered; durable production storage/audit remains product hardening) |
| tenant-onboard |
operator-surfaces (2026-06-25: /operator surface links + keyboard route into /operator/tenant, direct /operator/tenants roster rows/sort/footer/anonymous gate, tenant KPI/member table/page-dialog layer; row-cell addendum: all 8 fixture rows cell-by-cell + no hidden row link/menu; export-control idle/row-count anchors; index route-state addendum: operator bar/title/rule/count/description/open-label/focus/mobile-grid anchors), tenant-onboard (2026-06-25: Export CSV downloads pacific-theological-members.csv with canonical columns and rendered roster rows), tenant-member-actions (operator Invite/+Add member UI→real BFF write→real tenant-console cockpit read→visible live invited/active roster row refresh; tenant.member_invite and tenant.member_create audit cockpit read-back; signed-in /tenant/invite browser accept page against the live BFF; tenant-console cockpit read-back; token-reuse 409, wrong-token 403, invalid-email, and seat-capacity guard), tenant-invite-role-bff (wave6: roleIds round-trip + 403) |
partial |
✅ verified (remaining gaps: branded outbound email link/root-link handoff, invite-link SSO/MFA/onboarding completion/first action, elevated-permission gate UI, CSV import, and audit-chain reconciliation) |
| user-flag-to-review |
user-flag-to-review (Veritas lead article, Veritas claim-detail, Tara sitting, Nisaba passage, Metis lesson, and Metis tutor TrustSafetyFlagButton target kind/id/label metadata, 44 px report-button target, and shared dialog/category/rationale controls; Nisaba all-10-categories unique rationale → /api/trust-safety/flags → POST /v1/user-reports; admin moderation workspace read-back via real BFF GET /v1/admin/workspaces/moderation, live cust-ur-* report assertions, under-length rationale gate, real-BFF customer report → moderator decision → trust_safety.user_report.decided audit-search read-back → reporter-scoped /v1/user-reports/mine receipt update and cross-reporter isolation → browser /profile/safety submitted-report receipt row rendered as actioned/content_removed → browser /messages in-app report-decision row with delivery receipts → normal-click /api/messages/<id>/follow returns to /profile/safety?reportId=<id> → BFF inbox clicked receipt read-back) |
deep |
✅ verified |
| sophia-grounded-answer |
sophia-educational-grounding, assistant-invocation-source-inspection, sophia-grounded-deepening (VeritasRAG drill-down/pin UI over canned data), sophia-answer-bff (2026-06-23: real /v1/sophia/answer grounded citations + abstention; 2026-06-24: cautious/partial branch; 2026-07-03: real /v1/sophia/{answer,grounded} confidence-meter projection for grounded/partial/ungrounded/abstained states plus GET q/question/query aliases, private cache policy, and route-wide claim-honesty invariants proving no live model-only, dangling-citation, stale citationMap, or attributed-abstention responses), sophia-grounded-answer-page (2026-06-23: /sophia page submits to live BFF and renders grounding/citations/claims; 2026-06-24: partial-state render; 2026-06-26: citation target normalization plus live Nisaba passage reading-frame handoff plus real saved-items Library readback plus cited-locator highlight/back restore for grounded answer; 2026-06-26: /search input submits a live Nisaba /v1/search query and renders grounded preview evidence context; 2026-06-27: idle/typed/pending form contract, visible keyboard focus, touch targets, live ungrounded/no-citation abstention, and non-2xx/offline query-retaining alerts; 2026-06-29: grounded-answer save now verifies exact saved-items query/primary-witness/surface/trust metadata before clean-device Library hydrate; 2026-07-03: live cautious/partial answer is persisted to sessionStorage["oshun.web.sophia.last-answer.v1"], reload restores the answer card/citation/claim/status, and no second /v1/sophia/answer POST is made) |
partial |
✅ verified |
| themis-assessment-appeal |
integrity-appeal (2026-06-25: /integrity/<verdictId>/appeal verdict/form/submit/filed row-cell anchors, blocked→ready submit state, optional policy link, due-process summary, filed status/case/adjudicator field assertions; A-to-Z appeal route + real BFF; teacherOverride → overturned/inconclusive + audit read-back; matching teacherOverride → upheld/violation + audit read-back; teacher-cleared appealAllowed=false branch blocks the customer form and direct POST; 2026-06-26: learner-safe audit detail renders real decision rationale, signal metadata, evidence excerpt, policy binding, and classifier provenance), metis-assessment-submit (2026-06-26: rubric-gated learner submit posts to real /v1/metis/assessment-submissions, renders clear Themis verdict read-back, persists the submitted result, and drives suspicious submit→appealable verdict→/integrity/<verdictId>/appeal handoff plus audit-detail read-back), operator-metis-themis-review (2026-06-26: /operator/metis reads live BFF appeal queue, renders dispute/evidence/timeline/due-process detail, exposes Uphold/Revise/Dismiss/Escalate verdict controls, blocks blank decision submit, posts outcome=uphold to real /v1/metis/integrity/appeals/<appealId>/decision without raw teacherOverride, reads back status=closed plus verdict.status=upheld, renders the gradebook correction pending → violation with version/correctsVersion, reads GET /v1/metis/gradebook/<assessmentId>/latest, then opens /messages as the learner to verify the real decision notification row, appeal-record deep-link follow, clicked receipt, and mark-read state; BFF route tests cover inconclusive, clear, and severe outcome mappings) |
deep |
✅ verified |
| persona-voice-avatar-approval-workflow |
lilith-saraswati-persona-dossier-smoke, lilith-avatar-costume-smoke, persona-governance (new), persona-rehearsal-bff (wave6: rehearsal lifecycle + tone-calibration), persona-lifecycle-bff (2026-06-10: full drafted→released canonical chain over the REAL BFF — per-step status+audit advance, rollback-plan live-exposure gate 409, illegal-event 409 + no-mutation, scope gates; 2026-07-03: missing/duplicate/future-dated signoff and rollback-MTTR semantic envelope refusals with no status/audit mutation; resume-aware), persona-session-picker (2026-06-10: consumer round-trip over the REAL BFF — honest consent gate → real voice consent grant → browse/select/active/clear + not-in-catalog honesty), personas-picker (2026-06-23: /personas page DOM with real browser→BFF blocked roster, voice-consent unlock, select→active reload read-back, clear persistence + deterministic 401/500 UI branches), profile-persona-readback (2026-06-25: /profile/persona server readback against real /v1/persona/voice, no-consent empty, selected active voice, registry metadata, anonymous gate, mobile/axe) |
deep |
✅ verified |
Assistant, tenant — extended#
| Journey |
Primary spec(s) |
Depth |
Status |
| assistant-handoff-context-carry |
assistant-session-bff (new: real-HTTP session→turnCount→list + gates; real Iris bridge bootstrap/profile-memory posture + assistant-turn persistence into /v1/iris/adapter/review; 2026-06-26: consented profile + notebook /remember facts are recalled through the live assistant message route, exposed in response.memoryRecall, and folded into the returned answer text; route-level customer Veritas handoff accepted while mismatched admin.review-package artifact is sanitized out before continuity merge; operator crisis-frame activation → assistant projection read-back → benign message suppressed as source='operator-frame' with turnCount=0; persona handoff recommendation endpoint returns canonical customer/admin candidates and enforces fallback + authz branches), assistant-continuity-journey (customer shell handoff/disclosure plus real-BFF preference patch → memoryScope=off session-create payload, BFF continuity, transcript, first-turn state, selected-text PII redaction in the live session-create handoff, browser-visible /explore null-artifact handoff copy: data-assistant-context-artifact="none" + "Artifact: no current artifact", browser-visible /search entity-mismatch sanitization: session-create entity: null + artifact.metadata.entitySanitization='entity-shell-mismatch' + "Entity: removed (shell mismatch)" chip, browser Tara→Veritas domain-shortcut navigation depth with assistant session-create payload and return links preserving origin=explore&stack=tara, browser Nisaba notebook handoff metadata → profile/notebook Iris response.memoryRecall → mounted transcript "Remembered context" copy with Memory: profile, and 2026-06-26 live Veritas assistant message → grounded response.grounding envelope → browser Inspect evidence → VeritasInspectionOverlay source/citation/support-count drill-down), shell-utility-dock (desktop dock mode localStorage expanded/collapsed/closed, same-tab reload transcript restore from oshun-web-assistant-thread, and second-tab sessionStorage isolation), shell-boundary, assistant-handoff-deepening (2026-06-26: profile/library/Tara customer tool-grant policy) |
deep |
✅ verified (profile/notebook recall copy variant, dock/thread storage boundary, per-domain customer tool-grant policy, and persona recommendation BFF endpoint are now real-infra covered) |
| tenant-bulk-member-invite-scim |
tenant-member-invite-scim (real-HTTP SCIM bearer/tenant gates + Postgres POST→GET→PATCH→DELETE→revive lifecycle and canonical v1_identity_scim_identity change-log/tombstone assertions; real /v1/scim/v2/Groups create/list/read/patch/delete membership sync; real /v1/scim/v2/Bulk ordered create/group-sync/patch/delete sequencing; real admin audit-log read-back for tenant.scim_provision.*; operator action bar with Export CSV download content), tenant-member-actions (Path B Invite/+Add member UI→real BFF + signed-in /tenant/invite accept-page spot-check + invalid-email/seat-cap), tenant-invite-role-bff (roleIds round-trip + non-admin 403) |
partial |
✅ verified (Path C now proves the live Postgres SCIM provisioning lifecycle, Groups membership sync, Bulk request sequencing, and SCIM audit-event feed; remaining gaps are CSV bulk import, IdP callback, outbound invite email, full SSO/MFA/onboarding first-login, operator-table refresh from IdP-created rows, and downstream role/callback/first-login audit reconciliation) |
| tenant-bulk-operations-export |
tenant-bulk-operations-export-bff (real-BFF admin bulk-ops/export spine: operation/export 401/403 gates, clean users operation draft→validate→dry-run→stage→commit, row-level commit outcomes through the users commit executor, entitlements operation commit → customer /v1/profile plan free→premium read-back, rosters operation commit → /v1/admin/lms/oneroster commit/tenant totals read-back, persona assignments commit → /v1/personas/active persona/surface read-back, unsupported content commit → terminal failed with null committedAt, duplicate commit 409, validation-error dry-run block, operator isolation, content JSON export manifest creation/read/verify, approval-gated raw file download with retention/hash/residency headers, unsupported rights/OneRoster 400, mismatched record-kind 422, per-record residency metadata violation 422, audit-search read-back, and structured /v1/admin/audit-log/events target/payload read-back for committed/failed operation lifecycle, successful export manifest, release approval, and file download), tenant-bulk-operations-export-ui (operator /operator/tenant bulk-export panel with admin-scoped browser auth, live export-list load, UI-driven content export create request/header/body assertions, manifest/file hash rendering, verify action, release approval request/body assertions, released-file response hash/residency headers, downloaded content rendering, and structured audit-log read-back) |
partial |
✅ verified (local API spine, executor side effects, loud failure contract, export integrity, browser-visible release/download controls, residency metadata checks, universal search, and structured audit-log payloads covered; remaining gaps are tenant/operator upload-preview UI, CSV parsing/resumable upload, future multi-actor approval separation, and real commit executors for content/taxonomy beyond the loud-failure contract) |
| tenant-integrations-api-keys-webhooks |
tenant-integrations-api-keys-webhooks-bff (real-BFF integrations registry spine: snapshot 401/403/200, tenant-console-only mutation 403s across key/webhook/simulator/dispatch/replay/receipt/connector routes, API key create/rotate/revoke with raw-token non-leakage, downstream x-oshun-api-key tenant-resource auth probe with tenant/scope/IP/revoked failure modes and lastUsedAt read-back, duplicate revoke 409, malformed create 400, webhook create with signing-secret non-leakage, signed sandbox simulator delivery, topic-mismatch failed delivery without signed request, inactive simulator failure without signed request, non-sandbox simulator 409, signed outbound dispatch handoff, transient partner receipt retry backoff, replay-due worker tick regenerating the signed request and moving the same delivery back to in_flight, dead-letter exhaustion, success receipt, connector upgrade, connector health-probe healthy/failing registry mutation, universal audit-search read-back, and structured /v1/admin/audit-log/events taxonomy/payload read-back for API-key, webhook, simulator, dispatch, replay, receipt, and connector mutations), tenant-integrations-ui (operator /operator/tenant integrations panel with admin-scoped browser auth, live snapshot load, UI-driven API-key create payload/header assertions, raw-token one-time surfacing plus snapshot non-leakage, UI-driven webhook create payload/header assertions, signing-secret one-time surfacing plus snapshot non-leakage, and signed simulator matched/success/signatureVerified read-back) |
deep |
✅ verified (local API spine, mutation scope gates, secret safety, downstream auth probe, simulator failure modes, outbound dispatch, replay-due worker tick plus opt-in server interval, partner receipt retry/dead-letter/success outcomes, connector upgrade, connector health probes, universal search, structured audit-log taxonomy, and shipped operator tenant-console UI controls covered) |
| tenant-oneroster-roster-sync |
tenant-oneroster-provisioning-bff (real-BFF OneRoster dry-run/apply/pull spine: tenant-console scope gates, clean dry-run report, username + missing-user conflict report, malformed dry-run 400, apply commit + list read-back, tenant.oneroster.commit.applied audit-log read-back, periodic SIS pull reconciliation with derived pull:{tenantId}:{pullId} commit id and roster read-back, duplicate pull 409 without extra success audit, pull conflict 422 with no roster mutation plus tenant.oneroster.pull.conflicts_detected audit read-back, duplicate commit 409 without extra audit emission, conflict apply 422 with no roster mutation/no audit event, malformed apply 400), tenant-oneroster-metis-card (real BFF apply -> admin /operator/metis render; OneRoster card source/count attributes and committed tenant summary row read back through the browser), operator-lms (browser-visible /operator/lms OneRoster diff preview table: real BFF apply seed, browser /v1/admin/lms/oneroster/preview bridge, clean user-create/user-update/enrollment-create rows, blocked conflict rows, and roster read-back proving preview does not mutate committed counts) |
deep |
✅ verified (local API spine, operator diff preview table, periodic SIS pull handoff, conflict/drift audit behavior, and Metis roster-card read-back covered against real dev infra) |
| tenant-sso-config-saml-oidc-claim-mapping |
tenant-sso-config (2026-06-10: + editor-driven EDIT/DELETE legs — real BFF writes via the admin-bearer bridge, claim-mapping edit persisted + API read-back; 2026-06-24: editor persists all seven claim slots and all four transform options through the live BFF; 2026-06-24: browser Test action renders successful local OIDC probe + fail-closed JWKS verdicts from real BFF; 2026-06-25: + direct /operator/sso page/masthead/roster/card/field/footer anchors, generatedAt/count attributes, live seeded SAML/OIDC row-cell assertions, anonymous gate, and browser New-connection create leg with API read-back; 2026-06-26: browser Import metadata form persists SAML XML and OIDC discovery through live POST /v1/admin/sso/import, reloads the editor roster, and reads parsed fields back), tenant-sso-crud-bff (2026-06-10: dedicated pure-BFF CRUD — create→list→PATCH→fail-closed test-connection→delete→404, validation 400, 401/403; 2026-06-24: successful real local OIDC discovery+JWKS probe; 2026-06-24: real-HTTP SAML metadata XML import + OIDC discovery import via POST /v1/admin/sso/import; 2026-06-28: fail-closed import matrix for invalid SAML XML, OIDC discovery 404/503, closed-port discovery, and missing jwks_uri, with live roster read-back proving no draft connection writes; 2026-06-26: tenant.sso.connection.created/updated/deleted + tenant.sso.probe.completed audit-log read-back and duplicate-delete no-extra-audit guard), tenant-sso-oidc-login-bff (2026-06-24: real-HTTP OIDC login callback with signed id_token + local JWKS; proves lowercase email and first-only display-name transforms, plus missing_email_claim and jit_provisioning_disabled callback failures; 2026-06-28: missing non-email required claim, flow-toggle race, and wrong-signing-key id_token_verification_failed failures), admin-auth-policy-bff (wave6: auth-policy evaluator — honest sibling, not the SSO panel), tenant-admin-identity (2026-06-29: dedicated tenant-admin app real-infra browser pass — anonymous redirect-before-render, live BFF-seeded tenant-scoped SSO roster read-back, cross-tenant no-leak, read-only SSO probe/auth-challenge/federation evidence, axe) |
partial |
✅ verified (CRUD surface, BFF contract, metadata import parsing, successful/fail-closed BFF OIDC probe outcomes, fail-closed import validation with no draft writes, direct route/anonymous gate, SSO CRUD/probe audit-event taxonomy, full editor create/import/edit/delete/test and claim-slot/transform persistence, operator Test verdict UI, and live callback transform/failure paths including required-claim, JIT, flow-toggle, and signature verification failures, plus tenant-admin /identity anonymous gating, live tenant-roster read-back, read-only engine evidence, and axe; the journey's remaining spine — tenant-admin import/upload controls, per-tenant auth-policy edit panel, tenant-admin sandbox sign-in per-verdict UI, the draft→enabled state machine — is uncovered; tenant-admin edit/probe/enable controls + external IdP sign-in stay external) |
| tenant-audit-log-investigation |
tenant-audit-log-investigation (2026-06-10: + the explorer UI round-trip — filters on the real wire, create→list→Export-JSON Blob download→delete via the UI with API read-back, admin-bearer bridge; /operator/admin entry point closed; 2026-06-25: + direct /operator/audit page-DOM anchors, generatedAt/cursor anchors, exact 3-row masthead/table count, newest-first row-cell assertions, footer targets, and anonymous redirect-before-render; 2026-06-26: + browser Export-Markdown Blob download through the live BFF bridge with downloaded .md body assertions for title, provenance, and matched-events section; 2026-06-26: + real-HTTP audit.investigation.created/updated/shared/exported/deleted read-back, invalid/duplicate no-phantom-audit guard, and share-token non-leak assertion) |
deep |
✅ verified |
Agentic pipelines#
| Journey |
Primary spec(s) |
Depth |
Status |
| agentic-pipeline-customer-invocation |
agentic-pipeline-runnow-arete (new: customer Run Now A-to-Z), agentic-pipeline-invocation (execute + governance), agentic-runs-lifecycle-route.test (BFF) |
deep |
✅ verified (customer surface + BFF) |
Workspace shell#
| Journey |
Primary spec(s) |
Depth |
Status |
| multi-device-workspace-handoff |
workspace-multi-panel (all 8 panels, Iris send, failed-write no false success/no storage receipt, URL/tab/side-panel state, export flows, real-BFF Nisaba notebook seed + live /v1/search readback; remaining Veritas saved-article fixture documents the missing writer), profile-preference-sync, multi-device-handoff-deepening (mobile-viewport deep-link restore + active evidence-source equality; Home continuity syncing/Sync delayed/retry states), multi-device-deepening (tab-cap eviction, no-stale mobile handoff payload after eviction, Iris write-count equality, and real-BFF Nisaba notebook anchors restored across URL + localStorage reload) |
deep |
✅ verified |