Owner decisions 2026-08-31, formalizing what B2-2 (2026-08-29, "shipped slim") and HP-2 (condition 1 accepted at that scope) already record: - BPR-032 states the single-current-epoch beta policy with a dated amendment; the N/N-1/N-2 window returns by decision when a real epoch bump needs one. Traceability row matched, with the slim-scope evidence (TestAuth_ProtocolEpoch, TestEpoch1Fixtures, TestReleaseProtocolEpoch). - Roadmap B6 ws16 / B8 ws12+14 / B10 item 5 no longer imply B2-2 shipped GET /api/v1/server-info or a three-epoch matrix: B6 adds the endpoint, B10 re-runs the accepted epochs. The B2 exit bullet gets a dated note instead of a rewrite (closed-phase history stays legible). - B1 exit gate reworded: integration evidence is the required matrix on the PR head plus strict:true tree identity with the squash commit (scripts/verify-integration-tree.sh; the strict selftest pin rides the companion CI PR). - BPR-051's non-developer comprehension read becomes B10 qualification item 15 (an R-08 scorecard row); the traceability row points at it. - plans README: BPR/roadmap rows carry the amendment notes; the stale sweep sentence is dated and scoped to the records then open; the roadmap row no longer claims B3 has not started. Claude-Session: https://claude.ai/code/session_01B8dwVLEihnGZYtH9X631F4 Co-authored-by: Claude <noreply@anthropic.com>
18 KiB
Plan index
Closes G-04. Historical plans are kept at their existing paths — links from audits and commit messages must keep resolving — so status is recorded here rather than by moving or rewriting them.
A plan's own header can drift out of date after its table is updated in place. Where that has happened it is called out below, and this index is the authority.
Active — these drive current work
| Plan | State |
|---|---|
| beta-product-requirements-2026-08-23 | Approved beta scope, frozen. 57 BPR-* requirements. Amended 2026-08-31: BPR-032 reworded to the slim single-current-epoch policy (owner decision; the scope HP-2 accepted). |
| repo-health-roadmap-2026-08-23 | Phase order and gates, B0–B10. B0, B1 and B2 complete (HP-0, HP-1 and HP-2 all accepted); B3 in progress — the B3 plan row below tracks it. B4–B10 not started. Amended 2026-08-28: dated lines in B3–B10, a "Phase execution pattern" section, and a truthful status header. Amended 2026-08-29: B3/B7/B9 lines binding the layout-refactor supplement below; current slice updated for B2-2. Amended 2026-08-31: B1 exit reworded to identical-tree integration evidence; B6/B8/B10 server-info and epoch-window lines aligned with the B2-2 slim decision; B10 gains the BPR-051 comprehension-read row (owner decisions 2026-08-31). |
| repo-health-issue-register-2026-08-23 | 88 planning rows. Public-safe; not a replacement for the ledger. |
| beta-requirements-traceability-2026-08-23 | Requirement → phase → evidence map. No row is release-qualified. |
| b0-baseline-2026-08-25 | Supersedes the roadmap's "current evidence snapshot." B0 measurements and dispositions. |
| b1-repository-foundation-2026-08-25 | B1-0 through B1-8 all done. B1 execution plan. Re-verifies every RL-* claim against HEAD; several are refuted. |
| hp-0-scorecard-2026-08-25 | HP-0 accepted 2026-08-25. The single baseline-acceptance artifact. Part-closes R-08. |
| hp-1-scorecard-2026-08-27 | HP-1 accepted 2026-08-27. Structural-diff proofs for the flatten and module rename, plus the B1 exit gate. |
| b2-protocol-trust-compat-2026-08-28 | B2 complete — HP-2 accepted 2026-08-29. B2-0, B2-1, B2-8 done 2026-08-28; B2-2 (B2-3/B2-4 folded in), B2-5, B2-6, B2-7, B2-9 done 2026-08-29. Scorecard below. |
| hp-2-scorecard-2026-08-29 | HP-2 accepted 2026-08-29. Seven questions answered with commands; B2 exit gate, nine conditions met (1 at the slim epoch scope, 4 with one E2EE gap disclaimed). Owner follow-ups that do not gate B3: BPR-051 reader line, SEC-01/SEC-04 advisory IDs. |
| b3-server-architecture-guardrails-2026-08-29 | B3 in progress from 2026-08-29. Execution plan: B3-0 inventory → B3-1/B3-2 auth slice → HP-3 → lifecycle, hub options, ws split, families; guardrails and the alpha dataset beside the slice. B3-0 (inventory + db-import-boundary rule) and B3-1 (auth characterization) merged 2026-08-29; B3-2 (auth vertical slice) merged 2026-08-30; B3-9 (five of the six B3-tagged findings; OC-0323 rides B3-8) merged 2026-08-30; HP-3 accepted 2026-08-30; B3-3 (lifecycle extraction into Server/internal/app/, one composite close, hub construction out of api.NewRouter) is PR #1464, opened 2026-08-30 — B3-4 next. |
| hp-3-scorecard-2026-08-29 | HP-3 accepted 2026-08-30 by the owner. Five questions on the auth vertical slice answered with commands: frozen set green at every pre-squash SHA, api db importers 12 → 10, B2 contracts unchanged, the pattern written as D4 in server.md, guardrails as they exist. |
| b3-bench-baseline-2026-08-30 | Recorded 2026-08-30, not gated. The six B3-6 Benchmark* through benchstat at ec8ef24a, produced by make bench-baseline. Nothing in CI reads these numbers; the performance gate is B6's. Regenerating writes a new dated file — replace this row and delete the superseded document, so only the newest baseline is kept. |
| audit-2026-08-19-remediation | Phases 1–6 done 2026-08-20; phase 7 pending. Its header still reads "in progress 2026-08-19" — stale; the phase table is correct. |
Partially implemented
| Plan | State |
|---|---|
| bug-detection-improvements | Tier 1a (make fuzz) and Tier 2 (five ESLint rules) shipped 2026-08-08. Remaining tiers open. |
Design only — not implemented
| Plan | State |
|---|---|
| developer-experience-layout-refactor-2026-08-29 | Draft, not started. Implementation supplement bound into the roadmap 2026-08-29: B3 workstream 17 (Phases 1–3, auth slice → HP-3), B7 workstream 16 (Phases 4–6), B9 workstream 11 (CSS split). Nothing starts before HP-2. |
| slash-commands | Design only. No implementation; not in beta scope. |
Shipped — kept for history, do not use as current status
| Plan | Shipped |
|---|---|
| audit-2026-07-19-decisions | Decisions recorded; greenlit items implemented through 2026-07-23. |
| channel-visibility-unification | 2026-07-20 (D9), re-verified 2026-08-04. |
| v2-dispatch-migration | 2026-07-20 (D10), re-verified 2026-08-04. |
| tauri-capability-narrowing | 2026-07-20, re-verified 2026-08-04. |
| http-tofu-proxy | 2026-07-19, re-verified 2026-08-04. |
| permission-middleware-consolidation | 2026-07-23 (D13), re-verified 2026-08-04. |
| security-hardening-remediation | 2026-07-23, re-confirmed 2026-08-04. |
| security-scan-2026-07-22-remediation | All 8 findings F1–F8 closed, verified 2026-08-04. |
| sqlc-adoption | Shipped, verified 2026-08-04. |
| discord-parity | Phases 1–6 complete, verified 2026-08-04. Phase 1's table reads as a gap list but every row shipped. |
| infrastructure-roadmap | 2026-08-15, with two recorded leftovers (TOTP persister seam; published capacity numbers). |
Where status actually lives
Planning documents are not trackers. Do not read a defect count out of one.
| Concern | Source of truth |
|---|---|
| Defect status | .superpowers/findings-ledger.json (FINDINGS.md is rendered from it) |
| Security-sensitive defects | Private GitHub Security Advisories |
| Product scope | beta-product-requirements-2026-08-23 |
| Phase order and gates | repo-health-roadmap-2026-08-23 |
| Current measured baseline | b0-baseline-2026-08-25 |
Ledger at 2026-08-30: 320 fixed / 54 open / 3 declined / 1 duplicate = 378
(B3-9, PR #1454, closed the five B3-tagged records).
The 2026-08-25 sweep resolved every record then open to a live file:line at
5cc0888964e26276d1aca145e83270a2c1b9febd — a manual pass, not something a
command reproduces, and not repeated for records opened since. What the
tooling does check:
node .superpowers/render-ledger.mjs --check # the ledger's schema is valid
node scripts/check-doc-counts.mjs # documents agree with it, and
# FINDINGS.md is not stale
Adding a plan
- Give it a
**Status:**line with a date, and update that line — not only the phase table — when it changes. - Add a row here. A plan absent from this index has no recorded status.
- Mark a superseded plan here; leave it at its path so existing links resolve.