Co-Authored-By: Claude Fable 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01VRShc4QhLLU73FLHx9vskh
16 KiB
vibe > PRD > AI back-office > STATUS
STATUS — implementation tracker
Status: 🟢 Current — backlog decomposed into issues (2026-07-11); sharpened with per-issue Execution footers + splits #59/#60 (2026-07-12); execution started — erp#38 shipped, D8 settled (2026-07-15); harness portability proven — erp#63 + #56 closed, Mistral + Ornith admitted to verifier duty (2026-07-18); P1 write-skill + atom sprint — #44/#43 shipped, #39/#40 built awaiting the operator push gate, #54 PR open on its Accept gate (2026-07-19) Last Updated: 2026-07-19 Up: AI back-office hub Related: POC plan · Roadmap (dated plan; actuals and slips land here)
Phase tracker
| Phase | Scope | State |
|---|---|---|
| 0 — Foundations | read skills, sandbox + promote, backups, snapshots, bank reco, email ingest, Telegram gateway MVP | ✅ shipped pre-PRD (ledger below) |
| 1 — Flagship pipeline | POC-1 + POC-5 | 🟡 in progress → erp milestone P1 (erp#38–45, #47 — due 2026-10-09) · #38 ✅ 2026-07-15 (PR erp#62) |
| 2 — Urgent compliance | POC-6 — hard deadline 2026-09-01 | ⬜ decomposed → erp milestone P2 (erp#46 — due 2026-09-01) |
| 3 — Standing fleet | POC-2, queue, digest + approval cards, harness portability | 🟡 in progress → erp milestone P3 (erp#48–50, #59 — due 2026-11-13) + gateway#1/#2 · #63 ✅ 2026-07-18 (PR erp#69: harness home erp:fleet/harness/, Mistral vibe -p + Ornith 35B at verifier parity, builder bench = #56 by Mistral, 0 corrections) |
| Ledger compliance (cross-cutting) | Dolibarr verifications | ⬜ decomposed → erp milestone (erp#51 — due 2026-11-27) |
| 4 — Money loops | POC-3, dunning, cash report | ⬜ decomposed → erp milestone P4 (erp#52–53 — due 2026-12-24) |
| 5 — Fiscal autopilot | POC-4, compliance calendar | ⬜ decomposed → erp milestone P5 (erp#54–55, #60 — due 2027-05-04) |
| 6 — Emission era | e-invoice emission + e-reporting — hard deadline 2027-09-01 | ⬜ not yet decomposed (starts 2027-05; requirements captured by erp#46 deliverable 4) |
Backlog map
Every phase is decomposed into self-contained issues (context, deliverables, acceptance criteria, dependencies, PRD links); since 2026-07-12 each issue also carries an Execution footer — Blocked by / Blocks / Human gates / Start (worktree + first command) / Done means (evidence comment → PR with Closes #N → doc sweep). How a future session resumes: order open milestones by due date, pick the top issue whose "Blocked by" is clear — and skip issues whose only open step is a [HUMAN] gate (surface those in the digest instead of stalling on them; e.g. erp#46 step 1 is operator-owned). Cold-start entry points as of 2026-07-19: erp#41/#42 (write-skill side, independent), erp#51 (startable today), erp#45 (once the operator pushes the #39/#40 branches — the dual-run journals in fleet/atoms/invoice-extract/eval/2026-07-19/ are its raw material). Operator-gated, not session-startable: #39/#40 push, #54 Accept (PR erp#71), #46 step 1 (Qonto UI), #53 July manual invoice ~07-23. Arbitration: one session = one lane — take the entry issue; an orchestrator may fan the independent lanes out in parallel (#39 ∥ #51 ∥ #41–44 touch disjoint directories); everything else follows due-date order (dates in the phase tracker above). The issue body carries everything; on any doubt the trust order is live system > code > STATUS > leaves. Cross-cutting decisions get their ADRs via factory#22.
| Repo | Issues |
|---|---|
| erp | P1: #38 fleet scaffold ✅ 2026-07-15 (D8 settled, PR erp#62) · #39 golden set+injection fixtures (built 2026-07-18 — 16 invoices + 6 injection + 1824 mails + scorer, local branch arcodange/golden-set; push+PR = operator step, #39 evidence) · #40 invoice-extract atom (built 2026-07-19 — critical-field 100 %, 6/6 injections quarantined pre-model, local branch stacks on #39's, #40 evidence) · #41 provenance checker · #42 compliance linter · #43 GED attach op ✅ 2026-07-19 (PR erp#72) · #44 idempotency keys ✅ 2026-07-19 (PR erp#70 — the 2026-07-11 manifest-B replays 5/5 deduped) · #45 POC-5 routing bench (D5) · #47 POC-1 exit gate (umbrella) — P2: #46 POC-6 Qonto-as-PA (D4; step 1 = [HUMAN] Qonto UI) — P3: #48 T13 drift watchdog · #59 T14 backup freshness+drill · #49 T17 second-brain hooks (D7; meeting lane D9 parked) · #50 POC-2 Pi sentinel (D6) — Compliance: #51 Dolibarr verifications (FEC/BlockedLog, startable today) — P4: #52 POC-3 reco+payments · #53 T05 client invoice (D3, ⚠️ July manual ~07-23) · #65 client-dossier ops (phase 1 ✅ 07-15) · #67 official-doc drafting skill (T18) — P5: #54 fiscal profile+calendar files+ADC register (PR erp#71 open — merging it = Accepting adc-001…005, operator act) · #60 T11 reminder loop · #55 POC-4 TVA dry-runs — Ops (post-replay): #57 bucket C + document gaps (#56 ✅ 2026-07-18, PR erp#68 — authored by the Mistral builder bench) |
| telegram-gateway | #1 Postgres durable queue (D1) · #2 daily digest + approval cards |
| factory | #22 ADRs as decisions close (D1/D2/D4/D6/D7) |
Closure protocol — per milestone
The resume protocol tells a session where to pick up work; this one keeps the doc surface currently true when work lands. Docs describe intent; this file + git describe reality. A Gitea milestone is closed only after the sweep — and the sweep starts with QA, because nothing gets documented as done before it is proven done:
- QA gate — verify before documenting, and never by yourself. The gate is run by an independent verifier subagent: context-free (no conversation inherited from the closer), prompted to refute — "find why this milestone is NOT actually done" — with the repo, the issues and the run journals as its only inputs (no self-grading). It checks: (a) every closed issue's acceptance criteria re-verified with evidence linked (eval scores, run journals, exit-gate results — not memory of them); (b) the milestone's test suites green: golden-set regressions at their bars, injection fixtures quarantined, linter suites behaving (forbidden manifests rejected, seeded-wrong provenance fixtures FAIL), idempotency replay no-op, watchdog/heartbeat checks where the milestone ships standing loops (QA strategy); (c) any 🧪→✅ flip in the agent-catalog backed by its proving-protocol evidence. Its verdict is posted on the milestone before closure; a refutation the closer cannot resolve with evidence blocks. A milestone that can't pass its own QA doesn't close — it sheds scope back into open issues.
- Flip the phase row above (✅ + date + PR links) and prune the backlog map of closed issues.
- Re-baseline the roadmap at the boundary: mark the stream done, re-date downstream engineering bars if they slipped — regulatory diamonds never move; slips shed scope instead. Bump its Last Updated.
- Truth-pass the affected leaves (no-tombstone — rewrite as currently true, no "previously/now"): the task inventory
Today:/Target:lines the milestone changed; the agent-catalog matrix;not yet/candidate claims in architecture, model-fleet, compliance. Bump Last Updated only on files whose claims changed. - Sweep the orientation layer: repo
AGENTS.mdfiles (map rows, "not yet landed" pointers), touchedSKILL.mds, and any guidebook page mapping a changed component (house same-change rule). - Doc-surface QA — mechanical + fresh-reader. (a) Run the link/anchor/convention check over the PRD tree (the
prd_checkpattern: every relative link + heading anchor resolves, breadcrumbs, stamps) — zero broken; (b) deprecation grep: list the claims the milestone retired (read them off the closed issues — e.g.frequency=0, "not yet landed", "no fleet wiring") and grepvibe/+ the repos'AGENTS.md/SKILL.mdfor them — zero hits or fixed; (c) fresh-reader smoke test: a context-free subagent reads only STATUS + the repoAGENTS.mdand must answer "what shipped, what's next, what would you verify before trusting?" correctly — if it lands on a stale claim, real sessions will too. - Close the loop outward: ADRs for decisions the milestone settled (factory#22), agent memories updated or pruned, a REX note into the second brain (T17 once live).
- Only then close the Gitea milestone.
Between milestones, the continuous rule stands: a PR that makes any documented claim false updates that doc in the same PR — a change that leaves its docs stale is an incomplete change.
Reader's half — trust order. Any session, before acting on a versionable claim (a path exists, a flag's value, a status emoji): verify against live system > code/git log > this STATUS > PRD leaves > agent memories/plans. A page whose Last Updated predates the newest closed milestone in its area is suspect — verify before relying on it.
Foundation ledger (shipped pre-PRD)
The bricks this PRD builds on, in the erp, factory and tools repos:
| Brick | What it gives the fleet | Key PRs |
|---|---|---|
Read-only skill catalogue + bin/arcodange CLI |
invoices, payments, TVA (collectée/déductible/summary), thirdparty completeness, recurring templates, snapshots — the fleet's A3 read layer | erp (V1–V8 skill series) |
Multi-env: erp-sandbox live in-cluster |
the rehearsal environment (ADR 0002) | factory #15–#18, erp #11–#12, tools #2–#3 |
| Sandbox write skill (fiches, invoices, payments, avoirs) | the A2 write layer, host-guarded to the sandbox | erp #21, #22, #25 |
| Promote flow (manifests, business-key lookup, prod gate) | the ADR-0003 capstone: rehearse → review → human-gated prod apply (ADR 0003, factory #19) | erp #23, #24 |
| Deterministic payment↔bank linkage | transaction_id end-to-end: record with the feed id, reconcile by id (PASS 0) |
erp #26–#28 |
| Sandbox checkpoint lifecycle + CLI | iso-prod refresh, write-agent provisioning, .env relink |
erp #29, #30, #35 |
| Dedicated Dolibarr backup (daily CronJob, 10 y retention, tested restore) | the evidence/recovery floor | erp #31–#34, tools #5 |
| Bank reco + email ingest skills | Qonto/Wise feeds, Zoho books@/bureaux@ ingestion (read-only) |
erp (skill series) |
| telegram-gateway MVP | the human channel's transport (webhook echo proven; queue + async handlers roadmapped) | telegram-gateway repo |
| Second brain (Obsidian vault + automation) | the fleet's knowledge layer: PARA vault git-synced, sb.py jobs (digest / inbox triage / daily / Gitea-ingest) on the hermes cron ticker, local Ornith runtime, mcp-obsidian access |
SecondBrain repo |
PR log (this PRD)
| Date | PR | What shipped |
|---|---|---|
| 2026-07-11 | factory#21 | PRD authored: hub + task inventory + agent architecture + model fleet + challenges + POC plan + QA strategy. |
| 2026-07-18 | erp#68 | #56 known-patterns fix — authored end-to-end by the Mistral runtime (vibe -p) under the builder bench; acceptance bank match clean (0 UNKNOWN). |
| 2026-07-18 | erp#69 | #63 harness portability: fleet/harness/ (verifier tests, run-verifier.sh, vibe-builder.sh) + parity/bench evidence — Mistral + Ornith admitted to verifier duty (blind-judged, 16/16 unanimous). |
| 2026-07-18 | factory#31 | Cross-family verification rule codified in the qa-strategy; STATUS truth-pass for #56/#63/#39. |
| 2026-07-19 | erp#70 | #44 idempotency keys — replay is a no-op, proven live (historic manifest-B 5/5 deduped). |
| 2026-07-19 | erp#71 (open) | #54 fiscal profile + calendar + ADC register — awaiting the operator Accept gate. |
| 2026-07-19 | erp#72 | #43 GED attach op — idempotent by (object, filename, sha256), rehearsed live (4 created → 4 deduped). |
| 2026-07-19 | this PR | STATUS truth-pass for #43/#44/#40/#54; entry points re-baselined. |