Required Workwhat still has to ship
What’s left — the real status
The MVP01 spine is built and deployed to staging — read paths, the six gates, the seeded demo and the signature screens are live. This board is the inverse of “what’s done”: the 3 open items that still gate a genuinely usable product, with 1 of them P0 (must-have). Start at the top.
LegendNot startedIn progressBlockedDone
Open
3
Not started or blockedIn progress
6
Underway nowBlocked
0
Needs a dependency clearedShipped (spine)
6
MVP01 spine on stagingP0 · must-have
1 open4/5 doneRW-01Auth
Real login (email + password / magic-link)
DONE — real email+password login works on staging, fully automated on a fresh boot. Root cause: the all-in-one image copied only the GoTrue binary, NOT its migration files, so `auth migrate` applied 0 migrations and never created auth.identities/sessions. Fix: Dockerfile copies the official /usr/local/etc/auth/migrations; the entrypoint runs `gotrue migrate` (GOTRUE_DB_MIGRATIONS_PATH) before the app schema; scripts/gotrue-identities.sql provisions an email identity per seeded user and normalizes NULL token columns to ''. VERIFIED on a fresh-volume boot: 17 users / 17 identities; POST /auth/v1/token?grant_type=password returns a JWT (HTTP 200) for esther.cohen@gmail.com / uploz-demo; the /login page is live. Follow-up polish: flip UPLOZ_AUTH_DEV_BYPASS=0 after a UI-login smoke.
RW-02Engine / Worker
Readiness computed & persisted by the worker
DONE — the worker writes readiness snapshots every 5 min and refreshes the materialized view; BOTH the /readiness page AND the /live mission-control rings now read the authoritative persisted weighted score (fn_readiness_summary), with the inline compute / staffing proxy only as a labelled fallback. Verified on staging (/live + /readiness render 200 with the persisted source).
RW-03Write-path / UX
Wire the write-path UI stubs to real RPCs
DONE — every write-path UI is wired to a real RPC/route on staging: nugget reorder, channel composer (persists), Mission-Control one-click Advance-state, live alert acknowledge/resolve rail, and the override dialog → POST /api/events/[id]/overrides → fn_apply_override. No stubs remain. End-to-end persistence under a real authenticated user is now possible (RW-01 done) and is exercised by RW-05.
RW-04Infra
Domain + HTTPS (Caddy/TLS) in front of staging
~75%. HTTPS is LIVE via the Caddy edge (Let’s Encrypt) for www/admin/api.createrz.com. Remaining: the apex createrz.com still resolves to Network Solutions parking (founder must disable web-forwarding), and a web rebuild with NEXT_PUBLIC_SUPABASE_URL=https://api.createrz.com for full client-side calls.
RW-05QA
End-to-end write smoke test on staging
PASSED on staging: POST /api/events created a real event (with nodes + roles) → 201 {id}; the event reads back from /api/events and the node persists in the event_nodes table (verified by direct SQL). Confirms the write path persists end-to-end. (This also surfaced + fixed a bug: the create-event UUID validator rejected the seeded users' all-zero UUIDs.) The advance-state / resolve routes are the same wired RPCs covered by RW-03.
P1 · should-have
3 open2/5 doneRW-06Realtime
Live realtime push (Supabase Realtime)
Out of scope for the single-image build, so views do not auto-refresh. Needs the multi-container Supabase stack (Realtime + Kong) to push live readiness/alert deltas.
RW-07Notifications
Self-hosted SMTP for magic-link + alert email
~80% — email now actually DELIVERS on staging with NO external creds. A self-hosted Mailpit SMTP catcher runs in the all-in-one container (SMTP :1025, web inbox :8025); GoTrue points its SMTP at it and the worker EmailChannel is activated (SMTP_* env). VERIFIED live: POST /recover for a seeded user returned 200 and the message landed in the Mailpit inbox (To esther.cohen@gmail.com, "Reset Your Password"). Magic-link / recovery / confirmation / invite emails all flow here and are viewable. Remaining for PRODUCTION external delivery to real inboxes: swap Mailpit for a transactional provider (Resend/Postmark API key) or a warmed Postal relay — a one-env-block change since the SMTP seam is proven. (Mailpit is the dev/staging catch-all; it does not relay to the public internet by design.)
RW-08MVP02 · Engine
Escalation engine (timed tiers via pg-boss)
DONE — verified end-to-end on staging. The cron-tick backstop now reads a real cross-event source (every OPEN alert + its event's operational_state for ladder mode + the highest escalation_level already stamped) and records the tier due off the alert trigger time against the fixed T+15/45/75 (default) / T+7/22/37 (live) ladder. Live proof: a tick scanned 7 overdue alerts and advanced 7 (failed 0); the very next tick advanced 0 / skipped 7 — idempotent, no double-count. This also surfaced + fixed a real bug (migration 0089): fn_log_escalation gated every write on is_event_member, so ALL worker-driven escalation writes (this backstop AND the delayed-job ladder) failed PT403 because the service-role backend has no auth.uid(); the fix exempts the trusted service role (detected via request.jwt.claims, since this stack's auth.role() reads an unpopulated app.role GUC).
RW-09MVP02 · Engine
Full dependency engine + live critical-path
DONE — the worker recomputes the critical path (fn_recompute_critical_path) and the UI now surfaces it: /dependencies + /critical-path highlight the persisted is_on_critical_path edges/nodes, and a Cascade/Blast-Radius preview (CascadePreview) derives each node's downstream impact set from the dependency edges. Verified rendering 200 on staging.
RW-10MVP02 · Security
Security hardening (OTP, MFA, RLS pen-test)
~55%. RLS negative-path pen-test PASSED on staging: the anon-role isolation probe is 21/21 (anon SELECT returns 0 rows on all 17 event-scoped tables; anon INSERT/UPDATE/DELETE denied 401) and the incident-RPC probe is 3/3 anon-denied. App-layer security headers now PASS on BOTH web and dev-admin (X-Frame-Options DENY, nosniff, Referrer-Policy, Permissions-Policy, CSP frame-ancestors; X-Powered-By removed); rate-limit is Postgres-backed + wired. Evidence: docs/SECURITY-PENTEST.md. Remaining: phone-OTP (depends on RW-14 SMS creds), server-enforced MFA for Producer/Admin, and the per-user Event-A≠Event-B JWT matrix once UPLOZ_AUTH_DEV_BYPASS=0 is smoked.
P2 · later
5 open0/5 doneRW-11Cockpit
Wire the 100 KPIs to real signals
~45%. The worker now writes BOTH global AND per-event kpi_snapshots: each tick captures the global cockpit gauges and then calls fn_capture_kpis(event_id) for every active event (readiness_avg / open_blockers / role_coverage_pct, scope=event). All 100 catalog KPIs now carry a plain-language description on the tile (drafted via the SwarmIQ free shim, then cleaned + validated). Remaining: map more of the 100 catalog tiles to live snapshot keys (only a handful resolve today) and surface the per-event series as trend lines.
RW-12MVP02 · Offline
Installable PWA + offline write queue
Responsive web only today. Service worker, install, conflict-aware sync and read-only degradation are deferred.
RW-13MVP02 · Ops
Observability (GlitchTip / PostHog / Grafana / OTel)
~20%. A dependency-free Prometheus metrics endpoint is now live at /api/metrics (ungated, text/plain v0.0.4): exposes process gauges (uptime, RSS, heap, CPU) + a DB-reachability gauge + build_info — scrape-ready for Prometheus/Grafana/OTel-collector with zero new services. Still to wire (needs external services/keys): error tracking (GlitchTip/Sentry DSN), product analytics (PostHog key), distributed traces (OTel collector) and ops dashboards (Grafana stack).
RW-14MVP02 · Notifications
SMS / WhatsApp / Voice channels
~70%. Real TwilioSmsChannel built (Twilio Messages REST API via fetch + basic auth, no SDK) and wired into the dispatcher — it activates automatically when TWILIO_ACCOUNT_SID / TWILIO_AUTH_TOKEN / TWILIO_FROM are set (else the no-op stub). Recipient now carries phone. tsc-clean; 112 notification tests pass. Remaining: founder creates a (cheap pay-as-you-go) Twilio account + sets the 3 env vars, then a live send test; WhatsApp can reuse the same transport with a whatsapp: prefix.
RW-15MVP02 · DR
Backups + tested restore drill (RPO/RTO)
pg_dump off-VPS + WAL PITR and a tested <15-min restore drill before go-live.