Skip to content

Requirements Traceability

Arun Prakash N edited this page Aug 15, 2026 · 10 revisions

Canonical source: docs/project/REQUIREMENTS-TRACEABILITY.md · Snapshot commit: e8130729d005

Life in Days — requirements traceability

Status: planning artifact; no implementation, evaluation execution, credential provisioning, deployment, or production verification is claimed.

This matrix enumerates every requirement identifier currently defined in the Product Requirements Document exactly once. It connects each requirement to the UX Specification, real task identifiers in the Project Tracker, the relevant Implementation Plan section, and planned evidence. Tracker task status remains authoritative if it changes after this snapshot.

Status vocabulary

  • Planning mapped; implementation not started: the behavior is represented in planning artifacts, but no product implementation or test result is claimed.
  • Evaluation gated; execution not started: a protocol exists, but model/integration qualification remains gated and unexecuted.
  • Deferred; intentionally absent from MVP: the item is a controlled backlog boundary, not authorized implementation.

Requirement matrix

Priority Requirement / title UX coverage Tracker tasks Implementation-plan section Planned verification / evidence Planning / implementation status
P0 LID-SCP-001 — Single-user product boundary UX-PRIN-06, UX-PRIN-09, UX-NAV-04, UX-PRIV-07, UX-PRIV-08 SEC-002, SEC-003, DEP-008, QAE-006 §4.1 Context and trust boundaries; §10.1 Human application routes; §15.2 Required controls Negative access tests cover HTML, APIs, media, search, and exports; route/UI scan proves no sharing, public-link, invitation, or coaching surface. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SCP-002 — Journal Day and time semantics UX-GEN-03, UX-GEN-11, UX-GEN-12, UX-GEN-13, UX-GEN-14 DOM-001, DOM-005, OPS-007, QAE-002 §7.1 Core records; §7.2 Required invariants; §12.2 Job catalog Boundary/property tests cover Asia/Kolkata midnight, immutable timestamps, en-IN display, backdating, and future-date rejection. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SCP-003 — Source/derived separation UX-PRIN-01, UX-GEN-01, UX-GEN-02, UX-DAY-11, UX-HIST-03 DOM-002, DOM-003, TXT-008, LFC-001, QAE-002 §7.1 Core records; §7.2 Required invariants; §13.1 Text derivation Schema, UI, export, and API tests prove sources, revisions, Corrections, and derived versions remain typed, separately labeled, and source-bound. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SCP-004 — Journal Day visibility UX-IA-04, UX-CAL-07, UX-REDATE-04, UX-HIST-05 DOM-008, REF-004, REF-009, QAE-002 §7.2 Required invariants; §10.1 Human application routes; §14.2 Trash and suppressions Transition tests remove/restore/redate the last live source and verify Calendar, Monthly Almanac, default Search, and exact-date History behavior atomically. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-TG-001 — Telegram authorization UX-TG-01, UX-TG-02, UX-FIRST-04 TEL-001, TEL-002, SEC-004, DEP-009, QAE-006 §10.2 Machine callbacks; §11.1 Telegram; §15.2 Required controls Contract/security tests reject missing or wrong webhook secret, sender, chat, and group before download; configuration and log scans reject hard-coded or exposed IDs/tokens. Planning mapped; implementation not started; task dossier, approved secret delivery, private authority, and deployment remain gated.
P0 LID-TG-002 — Telegram message forms UX-TG-01, UX-TG-07, UX-DAY-10 TEL-004, MED-002, QAE-003 §9.1 Capture pipeline; §11.1 Telegram Telegram fixtures verify highest photo rendition, exact document bytes, accepted message provenance, and accurate compression/original-quality guidance. Planning mapped; implementation not started; Telegram contract tests remain unexecuted.
P0 LID-TG-003 — Image validation and limits UX-TG-03, UX-GEN-04, UX-STATE-07 MED-001, MED-003, TEL-004, TEL-009, QAE-007 §9.1 Capture pipeline; §15.2 Required controls; §17 Capacity and performance Malformed, oversized, over-dimensioned, animated, decompression-bomb, unsupported-format, and accepted-format fixtures run under measured resource limits with no partial source. Planning mapped; implementation not started; decoder/runtime choice remains gated.
P0 LID-TG-004 — Durable capture acknowledgement UX-GEN-04, UX-TG-05, UX-TG-06 MED-006, TEL-003, TEL-008, TEL-009, QAE-009 §7.3 Transaction boundaries; §9.1 Capture pipeline; §11.1 Telegram Crash/replay/failure-injection tests prove success or preservation acknowledgement follows encrypted-original, thumbnail, metadata, and holding/source commit; retries remain idempotent. Planning mapped; implementation not started; transaction/storage ADR remains gated.
P0 LID-TG-005 — Photo dating and media groups UX-TG-01, UX-TG-04, UX-GEN-13 TEL-005, TEL-006, DOM-001, QAE-009 §11.1 Telegram; §12.3 State machines Parser and album-settling tests cover anchored leading dates, whitespace, caption remainder, default receipt date, late/replayed group members, and immutable timestamps. Planning mapped; implementation not started; Telegram behavior remains to be contract-tested.
P0 LID-TG-006 — Needs Date Review for invalid/future dates UX-TG-06, UX-DATE-01, UX-DATE-03, UX-DATE-05 DOM-006, TEL-006, TEL-008, REF-009, QAE-004 §7.1 Core records; §7.2 Required invariants; §11.1 Telegram End-to-end tests preserve encrypted media without a Journal Day, exclude it from reflection views, show the reason, and atomically assign a valid non-future date. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-TG-007 — Daily Photo gallery and real cover UX-CAL-04, UX-DAY-04, UX-DAY-05, UX-DAY-06, UX-DAY-07 DOM-004, REF-006, REF-007, ART-008, QAE-002 §7.1 Core records; §7.2 Required invariants; §10.1 Human application routes Property and end-to-end tests cover unlimited references, chronology, persistent reorder, explicit real cover, and deterministic cover repair after delete/redate/restore. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-TG-008 — Global checksum deduplication UX-DUP-01, UX-DUP-02, UX-DUP-03, UX-DUP-05 DOM-007, TEL-007, MED-009, QAE-002 §7.1 Core records; §9.1 Capture pipeline; §14.2 Trash and suppressions Checksum/race tests prove same-day acknowledgement, explicit Add Anyway, cross-day warning/permission, one physical encrypted asset, and distinct source references. Planning mapped; implementation not started; encryption/checksum implementation remains gated.
P0 LID-TG-009 — Photo Captions UX-TG-04, UX-DAY-05, UX-SEARCH-01, UX-SEARCH-09 TEL-006, SRH-003, PRV-007, QAE-005 §8.2 Lexical search; §11.1 Telegram; §15.3 Photo-to-AI structural prohibition Search tests find caption literals; redating/correction retain captions; AI payload canaries prove captions and caption-derived fields never serialize. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-TG-010 — Local image derivatives UX-DAY-10, UX-RESP-03, UX-PRIV-02, UX-PRIV-03 MED-002, MED-004, MED-007, PRV-007, QAE-005 §9.1 Capture pipeline; §9.2 Read path; §15.3 Photo-to-AI structural prohibition Fixture checks preserve Original checksum, correct orientation, strip EXIF/IPTC/XMP from derivatives, enforce authorized streaming, and reject every photo field at AI boundaries. Planning mapped; implementation not started; media/encryption ADR remains gated.
P0 LID-VN-001 — Synthetic integration gate UX §19.1 Journal and integrations; UX-FIRST-02, UX-FIRST-03 VNO-001, VNO-002, VNO-003, VNO-004, VNO-005 §11.2 VoiceNotes; §18.3 Synthetic data; §22 Open gates and architectural risks A zero-personal-content spike report records identity mapping, auth refresh, pagination, rate limits, webhook behavior, revisions, tags, deletion, and transcript completeness; failing branches return for decision. Evaluation gated; execution not started; task dossier and Product Council readiness are required; credentialed VoiceNotes access remains owner-controlled.
P0 LID-VN-002 — Webhook wake signal and authoritative MCP retrieval UX-HEALTH-01, UX-FIRST-02; UX Flow A VNO-002, VNO-005, VNO-008, VNO-009, QAE-003 §10.2 Machine callbacks; §11.2 VoiceNotes; §12.2 Job catalog Synthetic contract tests bind webhook/MCP identity, acknowledge wakeups promptly, paginate authoritative reads, recover missed events, and record failure without trusting webhook text as source truth. Evaluation gated; execution not started; integration contract is not yet proven.
P0 LID-VN-003 — Exact tag and Integration Activation UX-SET-01, UX-FIRST-03, UX-SEARCH-03 VNO-006, VNO-007, DEP-010, QAE-004 §7.1 Core records; §11.2 VoiceNotes; §21.2 Deployment sequence Eligibility fixtures prove exact case-sensitive configured tag behavior, immutable activation instant, pre-activation exclusion after later edit/tag, post-activation inclusion, and no fuzzy/additional-tag path. Planning mapped; implementation not started; VoiceNotes spike and production activation remain gated.
P0 LID-VN-004 — Voice Journal dating UX-DAY-17, UX-DAY-18, UX-DATE-04, UX-DATE-05 DOM-001, DOM-006, VNO-010, VNO-011, QAE-002 §7.1 Core records; §11.2 VoiceNotes; §12.3 State machines Timestamp fixtures use authoritative VoiceNotes creation time for Journal Date, preserve it as Original Timestamp, and route absent/unreliable creation time to Needs Date Review without using webhook receipt. Planning mapped; implementation not started; authoritative timestamp behavior remains to be proven.
P0 LID-VN-005 — Replay-safe reconciliation UX-HEALTH-01, UX-HEALTH-07, UX-STATE-08 VNO-008, VNO-009, VNO-010, OPS-006, QAE-009 §11.2 VoiceNotes; §12.1 Queue protocol; §12.2 Job catalog Restart, replay, reordering, pagination, checkpoint, missed-event, and partial-listing tests prove idempotence, complete repair, retained revisions, and sanitized repeated-failure alerting. Planning mapped; implementation not started; VoiceNotes contract and scheduler ADR remain gated.
P0 LID-VN-006 — Upstream lifecycle UX-CONFLICT-01, UX-HIST-02, UX-HIST-07 VNO-010, LFC-001, LFC-004, QAE-002 §7.1 Core records; §11.2 VoiceNotes; §14.1 Corrections and conflicts Synthetic edit/untag/delete sequences retain every revision, expose upstream status, never erase local content automatically, and preserve provenance through export/restore. Planning mapped; implementation not started; VoiceNotes lifecycle behavior remains to be proven.
P0 LID-VN-007 — Source Suppression and re-import control UX-TRASH-03, UX-TRASH-04, UX-SUP-01, UX-SUP-02 VNO-009, LFC-006, LFC-007, QAE-002 §12.2 Job catalog; §14.2 Trash and suppressions Delete/reconcile/restore/purge/reimport tests prove upstream is untouched, suppression prevents resurrection, restore clears it, purge retains only opaque identity, and Allow re-import is explicit. Planning mapped; implementation not started; task dossier, Product Council readiness, and lifecycle architecture gates remain open.
P0 LID-UP-001 — Manual journal upload UX-IA-02, UX-UPLOAD-01, UX-UPLOAD-02, UX-UPLOAD-03 UPL-001, UPL-002, REF-008, QAE-004 §10.1 Human application routes; §11.3 Manual uploads Global and day-inline end-to-end tests cover required/preselected editable date, one UTF-8 .txt/.md file, 1 MiB limit, keyboard/touch picker, and clear failures without partial source. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-UP-002 — Uploaded Journal preservation UX-UPLOAD-04, UX-UPLOAD-06, UX-DAY-19 UPL-003, UPL-005, PRV-004, QAE-004 §7.1 Core records; §9.1 Capture pipeline; §11.3 Manual uploads Original-file checksum/download, filename/source-title, timestamp, safe Markdown rendering, multiple-per-day, redating, search, Trash, export, backup, and restore round-trip tests pass. Planning mapped; implementation not started; storage/encryption ADR remains gated.
P0 LID-UP-003 — Uploaded Journal duplicate handling UX-UPLOAD-05, UX-GEN-08, UX-STATE-08 UPL-004, DOM-007, QAE-002 §7.2 Required invariants; §11.3 Manual uploads Exact-byte duplicate tests warn without creating by default; explicit Add Anyway creates a distinct Uploaded Journal with retained duplicate provenance and no race duplication. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SRC-001 — Corrections and immutable revisions UX-DAY-18, UX-DAY-19, UX-DAY-20, UX-CONFLICT-01, UX-HIST-02 DOM-002, LFC-001, LFC-002, QAE-002 §7.1 Core records; §14.1 Corrections and conflicts Revision/Correction tests preserve source bytes/text, authorship/time/base revision, selected displayed version, and audit history; no local action mutates VoiceNotes or original upload. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SRC-002 — Source/Correction conflict resolution UX-CONFLICT-02, UX-CONFLICT-03, UX-CONFLICT-04, UX-CONFLICT-05, UX-A11Y-16 LFC-001, LFC-002, LFC-003, QAE-004 §14.1 Corrections and conflicts; §18.2 Critical scenario matrix Accessible diff and end-to-end tests offer exactly keep Correction, display newest upstream revision, or create new Correction based on both; no auto-merge/deletion; result is audited. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SRC-003 — Atomic redating UX-DAY-02, UX-REDATE-01, UX-REDATE-02, UX-REDATE-03, UX-REDATE-04 DOM-005, LFC-005, REF-008, QAE-002 §7.2 Required invariants; §7.3 Transaction boundaries; §14.1 Corrections and conflicts Transaction/failure tests move one Source Item all-or-nothing, retain Original Timestamp, and recompute visibility, covers, order, search, derived staleness, and links on both days. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-SRC-004 — Source-set binding UX-REVIEW-05, UX-ART-12, UX-REDATE-05, UX-HIST-06 DOM-003, TXT-006, TXT-007, LFC-005, LFC-009, QAE-009 §7.1 Core records; §12.3 State machines; §13.1 Text derivation; §13.2 Artwork Source-hash race and redating tests prevent obsolete output becoming current, mark retained artifacts stale, remove no-longer-belonging art from active views, and retain complete binding/provenance. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P3 LID-UP-004 — Deferred composition/import UX-DAY-20, UX-UPLOAD-02; UX §33 Explicitly out of scope UPL-006, BLG-005, BLG-012, QAE-010 §11.3 Manual uploads; §20 Phase 4 capture scope Scope/UI/route tests prove no blank browser composer and reject unsupported document formats with .txt/.md guidance; backlog entries remain gated by new decisions. Deferred; intentionally absent from MVP implementation.
P0 LID-REF-001 — Image-first month calendar UX-CAL-01, UX-CAL-03, UX-CAL-04, UX-CAL-06, UX-CAL-11 REF-003, REF-004, ART-008, UXD-005, QAE-008 §3.4 Product and UX drivers; §10.1 Human application routes; §20 Phase 5 Synthetic-day visual/state tests cover Monday-first current month, image-first covers, neutral missing image, generated labels, empty days, keyboard grid, and accessible names. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-REF-002 — Monthly Almanac UX-TIME-01, UX-TIME-02, UX-TIME-03, UX-TIME-04, UX-TIME-05 REF-005, REF-010, QAE-004, QAE-008 §3.4 Product and UX drivers; §10.1 Human application routes; §20 Phase 5 End-to-end and accessibility tests verify reverse chronology, shared cover truth, source counts, labels, deterministic pagination, stable focus/scroll, and no source-journal feed excerpts. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-REF-003 — Lexical search UX-SEARCH-01, UX-SEARCH-02, UX-SEARCH-03, UX-SEARCH-04, UX-SEARCH-09 SRH-001, SRH-002, SRH-003, SRH-004, SRH-005, SRH-006 §8.2 Lexical search; §10.1 Human application routes Deterministic index/query tests cover displayed journal text, generated fields, exact tags/dates/captions, Include history, transactional updates/purge, safe snippets, and zero AI/network search calls. Planning mapped; implementation not started; database/search choice remains gated.
P0 LID-REF-004 — Journal Day detail UX-DAY-01, UX-DAY-04, UX-DAY-11, UX-DAY-17, UX-DAY-21 REF-006, REF-008, UPL-005, QAE-004 §3.4 Product and UX drivers; §10.1 Human application routes; §20 Phase 5 End-to-end tests render full date, cover/gallery, labels, complete source journals, timestamps, generated artifacts, provenance, corrections, upload, redating, history, Trash, and conflict actions. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-REF-005 — Visual system and motion UX-PRIN-06, UX-PRIN-07, UX-SET-09, UX-SET-10, UX-A11Y-13 REF-002, UXD-002, UXD-006, UXD-007, UXD-009 §3.4 Product and UX drivers; §10.1 Human application routes; §18.1 Test layers Council/owner visual review plus measured contrast and reduced-motion tests cover light/dark themes, quiet photographic hierarchy, generated distinction, no coercive patterns, and no protected-expression copying. Planning mapped; implementation not started; design validation remains unexecuted.
P0 LID-REF-006 — Responsive/browser/accessibility support UX-RESP-01, UX-RESP-02, UX-RESP-07, UX-A11Y-02, UX-A11Y-05, UX-A11Y-12 REF-010, UXD-005, UXD-006, UXD-007, UXD-008, QAE-008 §3.4 Product and UX drivers; §18.1 Test layers; §20 Phase 8 Recorded WCAG 2.2 AA, keyboard, screen-reader, focus, contrast, zoom/reflow, motion, 320px, 200%/400%, and supported desktop/mobile browser matrix with owned defects. Planning mapped; implementation not started; accessibility/browser validation remains unexecuted.
P0 LID-REF-007 — Management safety UX-GEN-08, UX-GEN-10, UX-HIST-04, UX-TRASH-04, UX-HEALTH-03 REF-009, LFC-006, LFC-007, LFC-008, EXP-006, UXD-003, QAE-004 §10.1 Human application routes; §14 Lifecycle, export, and recovery; §16 Observability and System Health Usability and end-to-end tests distinguish reversible/permanent actions, require consequence copy, preserve history/suppressions, avoid false recovery claims, and keep dangerous actions explicit and authenticated. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-AIT-001 — Text-model evaluation gate UX-SET-02, UX-SET-03, UX-SET-04; UX §31 Validation plan AIQ-001, AIQ-002, AIQ-003, AIQ-004, AIQ-008, AIQ-009, AIQ-010 §11.4 AI providers; §18.3 Synthetic data; §22 Open gates and architectural risks Frozen 32-fixture manifest, fact inventories, must-not-claim lists, repeated outputs, blinded scorecards, hard-gate results, cost/latency/variance evidence, and approved or returned selection under $15. Evaluation gated; execution not started; task dossier and Product Council readiness are required; evaluation credential delivery remains owner-controlled.
P0 LID-AIT-002 — Text and Artwork Provider settings UX-SET-02, UX-SET-03, UX-SET-04, UX-SET-05, UX-SET-07 AIQ-009, AIQ-010, TXT-009, OPS-008, QAE-003 §11.4 AI providers; §13 AI orchestration; §16.2 System Health projections Settings/adapter tests expose only approved typed configurations, keep roles independent, preserve existing provenance after change, show credential/lifecycle state, and forbid arbitrary IDs or silent fallback. Planning mapped; implementation not started; exact models remain deliberately unselected pending evaluation.
P0 LID-AIT-003 — Text output contract UX-DAY-11, UX-DAY-16, UX-DAY-22, UX-GEN-01 TXT-004, TXT-006, TXT-008, QAE-003 §13.1 Text derivation; §12.3 State machines Typed-schema and adversarial fixture tests require one concise title, factual 80–140-word summary, 3–7 unique short tags, and atomic rejection of invalid/unsupported/coaching/diagnostic output. Planning mapped; implementation not started; selected adapters remain gated.
P0 LID-AIT-004 — Quiet period and final refresh UX-DAY-11, UX-GEN-05, UX-GEN-06; UX Flow I TXT-003, TXT-007, OPS-007, QAE-009 §12.2 Job catalog; §12.3 State machines; §13.1 Text derivation Deterministic clock/restart/race tests cover 15-minute source quiet, 01:00 final refresh, late source changes, per-field eligibility, stale job rejection, idempotence, and missed-run repair. Planning mapped; implementation not started; scheduler/queue architecture remains gated.
P0 LID-AIT-005 — Per-field protection and replacement review UX-DAY-12, UX-DAY-13, UX-DAY-14, UX-DAY-15, UX-REVIEW-01, UX-REVIEW-03 DOM-003, TXT-005, TXT-006, REF-008, QAE-002 §7.2 Required invariants; §12.3 State machines; §13.1 Text derivation Field-state/property and accessible review tests prove independent edit/accept protection, stale marking, preserved current values, suggested replacement review, and field-specific Resume automatic updates. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-AIT-006 — Text request privacy boundary UX-PRIN-10, UX-PRIV-02, UX-PRIV-04, UX-SET-04 TXT-002, PRV-007, PRV-008, QAE-005 §11.4 AI providers; §13.1 Text derivation; §15.3 Photo-to-AI structural prohibition Typed allowlist/canary tests prove only eligible displayed journal text crosses the selected provider boundary and exclude photos, metadata, captions, private descriptions, IDs, secrets, and unrelated history. Planning mapped; implementation not started; provider selection and privacy review remain gated.
P0 LID-AIT-007 — Text generation failures and provenance UX-DAY-11, UX-GEN-06, UX-HIST-06, UX-STATE-06, UX-STATE-07 TXT-006, TXT-007, OPS-008, QAE-003, QAE-009 §12.3 State machines; §13.1 Text derivation; §16.2 System Health projections Contract/failure tests distinguish auth, quota, rate, timeout, invalid schema, billing, refusal, and source race; bounded retry creates no duplicate current artifact and provenance/cost/status remain inspectable. Planning mapped; implementation not started; selected adapters remain gated.
P0 LID-AIA-001 — Artwork evaluation gate UX-SET-02, UX-SET-03, UX-SET-04, UX-SET-06; UX §31 Validation plan AIQ-001, AIQ-005, AIQ-006, AIQ-007, AIQ-008, AIQ-009, AIQ-010 §11.4 AI providers; §18.3 Synthetic data; §22 Open gates and architectural risks Stage-0 contract/privacy/lifecycle/4:5 gates, frozen ten-prompt manifest, uncurated originals, provenance/randomization, blind Stage 1/2 scorecards, cost/latency, and passing selection or owner return under $15. Evaluation gated; execution not started; task dossier and Product Council readiness are required; evaluation credential delivery remains owner-controlled.
P0 LID-AIA-002 — Read-only Visual Brief UX-ART-05, UX-ART-06, UX-ART-07, UX-HIST-06 ART-001, TXT-004, PRV-007, QAE-005 §13.1 Text derivation; §13.2 Artwork; §15.3 Photo-to-AI structural prohibition Token/schema and serializer tests enforce 150–300 tokens, source revision binding, versioning, read-only UI, explicit brief regeneration, and sole artwork-provider personal input with no raw journal/photo/caption/ID. Planning mapped; implementation not started; text/artwork adapters remain gated.
P0 LID-AIA-003 — Manual Artwork Request UX-ART-01, UX-ART-02, UX-ART-03, UX-ART-04 ART-003, OPS-004, REF-008, QAE-004 §10.1 Human application routes; §12.3 State machines; §13.2 Artwork UI/domain tests cover disabled below 5 words, sparse warning at 5–19, direct request at 20+, availability with photos/prior art, provider/model/cost confirmation, and safety/credential/budget blocks. Planning mapped; implementation not started; selected artwork configuration remains gated.
P0 LID-AIA-004 — 01:00 Artwork Sweep UX-ART-13, UX-ART-14, UX-HEALTH-07 ART-004, OPS-007, QAE-009 §12.2 Job catalog; §13.2 Artwork; §20 Phase 6 Clock/restart/outage tests scan every eligible post-activation day, require 20 words/no photo/no art/no suppression/eligible model/budget, repair missed runs idempotently, and expose skips without reminders. Planning mapped; implementation not started; scheduler and approved model remain gated.
P0 LID-AIA-005 — Artwork style and labeling UX-CAL-05, UX-DAY-08, UX-ART-16, UX-RESP-03, UX-A11Y-03 ART-002, ART-006, REF-004, UXD-003, UXD-006 §9.1 Capture pipeline; §13.2 Artwork; §18.2 Critical scenario matrix Frozen-style/prompt review and output fixtures verify painterly non-photorealistic 4:5 treatment, prohibited elements, preserved provider original, non-destructive display, metadata/provenance, and visible/accessible AI label everywhere. Planning mapped; implementation not started; artwork model/style evaluation remains gated.
P0 LID-AIA-006 — Artwork failure and safety behavior UX-ART-06, UX-ART-09, UX-ART-10, UX-STATE-07 ART-005, TXT-007, QAE-003, QAE-009 §12.3 State machines; §13.2 Artwork; §16.1 Allowlisted operational events Synthetic refusal/timeout/rate/auth/quota/invalid-response tests show neutral states, no source mutation, no safety relaxation/provider switch, no refusal auto-retry, bounded transient retry, explicit brief/regeneration retry, and safe logs. Planning mapped; implementation not started; selected adapter behavior remains gated.
P0 LID-AIA-007 — Artwork version lifecycle UX-DAY-08, UX-ART-11, UX-ART-17, UX-HIST-06 ART-006, ART-007, LFC-008, EXP-002, QAE-004 §7.1 Core records; §9.1 Capture pipeline; §13.2 Artwork; §14.3 Portable export Generation/regeneration/history/export/restore tests preserve downloaded original/checksum, derivatives, source/config/usage/safety/cost provenance, newest-success default, prior selection, failures excluded as versions, and no count cap. Planning mapped; implementation not started; selected adapter and storage architecture remain gated.
P0 LID-AIA-008 — Calendar Cover precedence UX-PRIN-02, UX-CAL-04, UX-CAL-05, UX-DAY-07, UX-DAY-08 DOM-004, ART-008, REF-007, QAE-002 §7.2 Required invariants; §12.3 State machines; §13.2 Artwork Property/concurrency tests cover upload, art success, reorder, selection, redating, Trash, restore, and deletion; any live photo forces a selected real cover and art becomes eligible only with none. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-AIA-009 — Artwork Suppression UX-ART-15, UX-SUP-01, UX-SUP-03 ART-009, LFC-008, EXP-003, QAE-002 §12.3 State machines; §13.2 Artwork; §14.2 Trash and suppressions Lifecycle/restart/export/restore tests prove deliberate all-art removal creates suppression, automatic sweep recreation stays blocked until Allow generation, a manual request remains available under its normal gates without silently clearing suppression, and Source Suppression remains independent. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-AIA-010 — Artwork staleness after text change UX-ART-12, UX-REDATE-05, UX-HIST-04, UX-HIST-06 ART-010, LFC-005, LFC-009, QAE-009 §7.2 Required invariants; §12.3 State machines; §13.2 Artwork Source-change/redating/race tests mark bound artwork stale, never auto-regenerate solely due to late text, retain old versions, remove no-longer-belonging art from active gallery/cover, and require explicit restoration/action. Planning mapped; implementation not started; task dossier and Product Council readiness gates remain open.
P0 LID-AIA-011 — Approved model configuration UX-SET-02, UX-SET-04, UX-SET-05, UX-SET-06, UX-SET-07 AIQ-009, AIQ-010, ART-002, TXT-009, OPS-008, QAE-003 §11.4 AI providers; §13.2 Artwork; §16.2 System Health projections Configuration-schema/adapter tests require exact provider/model/snapshot/endpoint/region/size/quality/format/safety/cost/lifecycle/enabled/sweep fields, reject moving/unreviewed UI values, disable unhealthy configurations, and keep premium manual-only. Planning mapped; implementation not started; exact configurations remain deliberately unselected pending evaluation.
P0 LID-OPS-001 — Human authentication UX-PRIV-01, UX-PRIV-07, UX-PRIV-08, UX-STATE-05 SEC-002, SEC-003, DEP-008, QAE-006 §4.1 Context and trust boundaries; §10.1 Human application routes; §15.2 Required controls Access/origin negative tests prove exact first-party account membership, MFA, seven-day session, signed assertion validation, no app password store, and denial of anonymous/other identities across all private resources. Planning mapped; implementation not started; Cloudflare validation and deployment remain gated.
P0 LID-OPS-002 — Callback boundary UX-SET-11, UX-FIRST-04, UX-TG-02, UX-PRIV-07 ARC-006, SEC-004, DEP-007, DEP-009, DEP-010, QAE-006 §4.1 Context and trust boundaries; §10.2 Machine callbacks; §15.2 Required controls Route/edge tests prove opaque authenticated Telegram/VoiceNotes callback paths only, separate rate limits, no human/session/journal/media/export route, and no reusable secret leakage. Planning mapped; implementation not started; callback configuration and deployment remain gated.
P0 LID-OPS-003 — Secret management UX-SET-07, UX-FIRST-05, UX-PRIV-04 SEC-005, SEC-006, DEP-003, SEC-009, QAE-006 §15.2 Required controls; §19.1 Environments; §21.1 Release package Secret/config scans, permission tests, rotation/revocation drill, client/export/backup/log exclusion, startup fail-closed behavior, and runtime-only reference inventory provide evidence without exposing values. Planning mapped; implementation not started; secret provisioning is not authorized.
P0 LID-OPS-004 — Application-controlled encryption at rest UX-PRIN-09, UX-PRIV-01, UX-PRIV-02, UX-HEALTH-01 ARC-005, PRV-001, PRV-002, PRV-003, PRV-004, PRV-006, QAE-005 §8.3 Encryption ADR input; §9.1 Capture pipeline; §14.4 Backups and disaster recovery; §15.2 Required controls Reviewed ADR, crypto test vectors, at-rest inspection, wrong/missing/key-version tests, recovery-key restore, original/DB/artifact encryption, backup/export compatibility, and accurate non-E2EE disclosure. Planning mapped; implementation not started; encryption/key ADR and Recovery Ceremony remain gated.
P0 LID-OPS-005 — Secure media staging UX-HEALTH-01, UX-HEALTH-05, UX-STATE-06 PRV-005, MED-003, MED-006, QAE-007 §9.1 Capture pipeline; §15.2 Required controls; §17 Capacity and performance Host-profile tests enforce bounded memory-backed plaintext, one decode at a time, no unencrypted swap/disk/temp persistence, cleanup after crash/cancel, backpressure, and no durable acknowledgement before encrypted commit. Planning mapped; implementation not started; host and encryption ADR validation remain gated.
P0 LID-OPS-006 — Live media storage and watermarks UX-HEALTH-04, UX-HEALTH-05, UX-HEALTH-07 MED-005, MED-008, OPS-005, QAE-007 §9.3 Root capacity and R2 migration; §16.2 System Health projections; §17 Capacity and performance Measured quota/free-space tests cover planning/provision/copy/new-write/emergency thresholds, projected exhaustion, truthful health, clear media rejection at emergency, and no deletion/downsampling of originals. Planning mapped; implementation not started; current host capacity remains to be revalidated.
P0 LID-OPS-007 — R2 migration target and verified cutover UX-HEALTH-04, UX-HEALTH-05; UX §20 System Health R2M-001, R2M-002, R2M-003, R2M-004, R2M-005, R2M-006, R2M-007, R2M-008, R2M-009 §9.3 Root capacity and R2 migration; §20 Conditional Phase 11 Conditional evidence requires private EU R2, app ciphertext, complete paginated inventory, dual-write/copy ledger, count/size/hash reconciliation, R2-to-Restic restore, atomic reversible cutover, seven-day observation, and verified eviction. Planning mapped as conditional M11; implementation/provisioning not started or authorized.
P0 LID-OPS-008 — Media delivery and caching UX-DAY-10, UX-PRIV-03, UX-PRIV-06, UX-RESP-03 MED-007, SEC-007, PRV-005, QAE-005 §9.2 Read path; §10.1 Human application routes; §15.2 Required controls Authorization/cache/header tests cover same-origin bounded decrypting streams, private no-store behavior, no public/signed object URLs, range/abort safety, explicit original download, and no shared/offline cache dependence. Planning mapped; implementation not started; media/encryption architecture remains gated.
P0 LID-OPS-009 — Media Asset reference lifecycle UX-DUP-02, UX-DUP-03, UX-TRASH-05, UX-HIST-02 DOM-007, MED-009, MED-010, LFC-006, QAE-002 §7.1 Core records; §9.1 Capture pipeline; §14.2 Trash and suppressions Concurrent Add Anyway/redate/Trash/restore/purge tests prove one asset can back multiple Daily Photos, referenced bytes survive, unreferenced live bytes delete safely, and inventory/database reference counts reconcile. Planning mapped; implementation not started; storage architecture remains gated.
P0 LID-OPS-010 — Trash and permanent live deletion UX-GEN-10, UX-TRASH-01, UX-TRASH-03, UX-TRASH-04, UX-HIST-02 LFC-006, LFC-007, LFC-008, MED-009, QAE-002 §12.2 Job catalog; §14.2 Trash and suppressions Clock/lifecycle tests cover 30-day recoverability, ordinary-view exclusion, atomic restore, explicit permanent deletion, retained suppression intent, reference-safe media purge, audit events, and honest backup-retention copy. Planning mapped; implementation not started; task dossier, Product Council readiness, and lifecycle architecture gates remain open.
P0 LID-OPS-011 — Backup and restore UX-HEALTH-01, UX-HEALTH-03, UX-HEALTH-10, UX-FIRST-02 BKP-001, BKP-002, BKP-003, BKP-004, BKP-005, BKP-006, BKP-007, BKP-008, BKP-009, BKP-010 §14.4 Backups and disaster recovery; §16.2 System Health projections; §21 Deployment, migration, and rollback Authorized B2/Restic setup, consistent-snapshot abort rules, 48/30/12 retention, every-backup verification, monthly sampled restore, quarterly fresh-host drill, loss runbooks, measured duration/cost, and limitation disclosure. Planning mapped; implementation/provisioning not started or authorized.
P0 LID-OPS-012 — Recovery Ceremony UX-HEALTH-09, UX-FIRST-02; UX §20 Recovery Ceremony PRV-006, BKP-006, BKP-007, DEP-012, QAE-010 §14.4 Backups and disaster recovery; §20 Phase 9; §23 Definition of Technical Ready Launch evidence contains two independently accessible off-server recovery-key copies, a representative encrypted restore/decrypt/render, recorded custody and results, and explicit owner go/no-go; backup upload alone does not pass. Planning mapped; implementation not started; launch remains blocked until ceremony evidence exists.
P0 LID-OPS-013 — Restorable export UX-EXPORT-01, UX-EXPORT-02, UX-EXPORT-04, UX-EXPORT-06, UX-EXPORT-08 ARC-009, EXP-001, EXP-002, EXP-003, EXP-004, EXP-005, EXP-006, EXP-007 §10.1 Human application routes; §12.2 Job catalog; §14.3 Portable export Independent validator and full round-trip prove versioned manifest/checksums, current/history/Trash/suppressions, originals/artwork/provenance, AES-256 ZIP default, warned unencrypted path, ephemeral passphrase/artifact, expiry, and exclusions. Planning mapped; implementation not started; export/download ADR remains gated.
P0 LID-OPS-014 — System Health UX-HEALTH-01, UX-HEALTH-02, UX-HEALTH-03, UX-HEALTH-06, UX-HEALTH-08 OPS-002, OPS-003, OPS-005, OPS-008, QAE-004 §16.1 Allowlisted operational events; §16.2 System Health projections Synthetic state/time tests verify factual last-success/failure/staleness for capture, reconciliation, jobs, providers, spend, storage, backup, restore, cache/swap/key safety; no content, secrets, or inferred green recovery. Planning mapped; implementation not started; observability architecture remains gated.
P0 LID-OPS-015 — Telegram operational alerts only UX-TG-08, UX-HEALTH-07, UX-PRIN-06 TEL-009, OPS-006, BKP-005, QAE-005 §12.2 Job catalog; §16.1 Allowlisted operational events Failure-threshold and payload tests send sanitized Telegram alerts only after repeated photo-ingestion, VoiceNotes-reconciliation, or backup failures, suppress storms, expose recovery, and prove no reminders/content/identifiers/secrets. Planning mapped; implementation not started; alert thresholds and integrations remain unexecuted.
P0 LID-OPS-016 — Logging and analytics boundary UX-PRIV-04, UX-HEALTH-08, UX-HEALTH-11 OPS-001, OPS-002, SEC-009, QAE-005 §15.2 Required controls; §16.1 Allowlisted operational events Canary/log scans prove allowlisted timestamps, opaque IDs, classes, bounded metrics only; 30-day purge; no journal/prompt/caption/media/response/secret/signed URL; dependency/network scan proves no third-party analytics/crash SDK. Planning mapped; implementation not started; logging/retention implementation remains unstarted.
P0 LID-OPS-017 — AI budget enforcement UX-SET-08, UX-ART-04, UX-HEALTH-06 AIQ-008, OPS-004, TXT-001, ART-002, QAE-007 §13.3 Budget ledger; §16.2 System Health projections Deterministic attempt-ledger/concurrency/retry tests warn at 80%, reserve $0.50 text, cap art at $4.50 and total at $5, block predicted overage/manual bypass, reconcile estimates/actuals, and keep non-AI features available. Planning mapped; implementation not started; exact provider pricing/configurations remain gated.
P0 LID-OPS-018 — Best-effort availability and failure isolation UX-PRIN-03, UX-GEN-05, UX-STATE-02, UX-STATE-06, UX-STATE-07 ARC-004, OPS-009, DEP-002, QAE-007, QAE-009 §3.3 Operational drivers; §12 Durable jobs and schedules; §17 Capacity and performance; §21.3 Rollback rules Host-profile/failure-injection evidence covers restart, provider/network/thumbnail/job/storage degradation and proves durable capture where possible, continued authentic reading/search/export/backup per policy, bounded queues, recovery status, and no HA/SLA claim. Planning mapped; implementation not started; host/runtime architecture remains gated.
P3 LID-DEF-001 — Historical import deferred UX-SET-01, UX-FIRST-03; UX §33 Explicitly out of scope BLG-001, VNO-006, VNO-007, QAE-010 §11.2 VoiceNotes; §20 Phase 4 prospective capture only Release scope/route/job/config tests prove no bulk or automatic pre-activation enumeration/import; activation remains fixed; manual individual upload/backdating stays available; backlog requires a new approved requirement. Deferred; intentionally absent from MVP implementation.
P3 LID-DEF-002 — Reflection features deferred UX-PRIN-06, UX-CAL-07, UX-TIME-06, UX-HEALTH-07; UX §33 BLG-002, BLG-003, BLG-008, BLG-016, QAE-010 §3.4 Product and UX drivers; §20 MVP phase sequence UI/job/notification/provider-payload scope audit proves no On This Day, weekly themes/reports, coaching, diagnosis, streaks, pressure reminders, or longitudinal personal-history analysis. Deferred; intentionally absent from MVP implementation.
P4 LID-DEF-003 — Advanced search deferred UX-SEARCH-01, UX-SEARCH-09; UX §33 Explicitly out of scope BLG-009, SRH-001, SRH-006, PRV-007, QAE-010 §8.2 Lexical search; §20 Phase 5 Search/network/privacy tests prove lexical/date/exact-tag behavior only, no vectors/semantic similarity/conversation/Q&A, and no search query or corpus is sent to AI; backlog remains separately gated. Deferred; intentionally absent from MVP implementation.
P4 LID-DEF-004 — Additional views deferred UX-CAL-02, UX-TIME-06, UX-STATE-01, UX-RESP-02; UX §33 BLG-007, BLG-010, BLG-011, BLG-018, QAE-010 §3.4 Product and UX drivers; §20 MVP phase sequence Milestone/package/route/cache/data-source audit proves no year mosaic, media wall, maps/location enrichment, native package, or offline capture/browse/sync engine; Calendar/Monthly Almanac/detail remain the delivered surfaces. Deferred; intentionally absent from MVP implementation.
P4 LID-DEF-005 — Format extensions deferred UX-UPLOAD-02, UX-EXPORT-01, UX-EXPORT-04; UX §33 BLG-005, BLG-006, BLG-013, UPL-002, EXP-007, QAE-010 §11.3 Manual uploads; §14.3 Portable export Unsupported-format tests reject PDF/Word/OCR/scans with .txt/.md guidance; export/package review proves no PDF book/printing or immutable/ransomware-resistant claim while normal restorable export remains complete. Deferred; intentionally absent from MVP implementation.
P4 LID-DEF-006 — Tag expansion deferred UX-SET-01, UX-FIRST-03, UX-SEARCH-03; UX §33 BLG-014, BLG-015, VNO-007, QAE-010 §11.2 VoiceNotes; §20 Phase 4 Eligibility/configuration tests prove only exact life-in-days, with no wildcard, substring, fuzzy, broad, or additional-tag path; future configurable exact tags remain blocked on a new privacy/product decision. Deferred; intentionally absent from MVP implementation.

Current evidence boundary

All implementation, integration, security, accessibility, recovery, and deployment evidence in this matrix is planned evidence. No passing result exists yet. The Product Council charter and Project Tracker now use the same G0–G9 sequence, Artwork Suppression now consistently blocks only the automatic sweep, and the Implementation Plan links this matrix from its corrected family summary.

Validation contract

  • Canonical source: the requirement rows in docs/product/PRODUCT-REQUIREMENTS.md.
  • Expected requirement count at this planning snapshot: 78.
  • Every canonical requirement ID must occur exactly once in the matrix; no matrix-only requirement ID is permitted.
  • Every referenced UX-*, tracker task/backlog ID, and implementation-plan section must resolve to a current artifact. Ranges are intentionally avoided so references can be checked mechanically.
  • Any PRD identifier addition, deletion, or rename requires this matrix and QAE-001 to be updated in the same planning change.

Life in Days

Home

Product, experience, architecture, and delivery

Discovery and research

Governance and council

Prototype handoffs

Prototype run guides

Prototype councils

QA and audits

Repository and project record

Evidence and maintenance

Clone this wiki locally