DUTY GRAPH · ADVISOR ENABLEMENT

Release 0.3 · Hosted advisor pilot · September 2026

Release 0.3 - hosted advisor pilot

This release adds a Vercel/Neon hosted pilot, private sample workspaces, encrypted account key settings, OpenAI discovery drafts and Resend invitation sending to the human-led advisor journey and training materials. It does not complete the full 90-requirement production target in the supplied handoff. Provider adapters need credentials and live acceptance; enterprise authority and live execution remain unimplemented; independent production acceptance remains open.

Delivered behavior

AreaImplemented in the local application
Scope and kickoffFive-stage guided discovery, contact preparation email, leadership agenda and notes, reviewed team dossiers, personal interviews, proposed task cards and confirmation handoff
Pre-meeting researchOptional Exa source collection, public query preview, bounded requests, durable replay prevention, source snapshots and unreviewed evidence import; no live key configured
People and organizationCSV preview/quarantine, reported managers, teams, explicit duty claims and task responsibilities
Evidence and captureImmutable typed/audio originals, private enrollment, resumable uploads up to 25 MB, on-demand OpenAI transcription, participant edits and advisor recovery for audio-only replies, accepted transcript evidence with original lineage, review/retraction and dependent staleness
WorkVersioned tasks, unresolved proposals, exact owner/performer confirmation, conflict handling, duties and handoff contracts
GraphFocused semantic columns, actual handoff diagrams, team-to-duty maps, recorded-manager chart, register and bounded API; optional encrypted Neo4j Aura metadata projection with current-record fallback
WorkflowsReviewed acyclic definitions, pinned dependencies, manual cases, selected routes, all/any joins, deadlines, failures, retries and history
StrategySixteen specific AI instruction sets and visual canvases, on-demand dependency sequence, exact source/version citations and recursive staleness; advisor analyses, testable hypotheses, measurements, intervention predictions and reviewed outcomes
Weekly reviewEvidence/work exceptions, cases needing attention, owner/action/due-date commitments
Client deliveryFrozen executive/weekly/audit reports, explicit audience approval, current binding checks, printable HTML and checksummed ZIPs
Internal handoffWorkspace, confirmed-work and non-operative agent proposal packages with exclusions
OperationsForced tenant RLS, serialized multi-record commands, immutable history, outbox, versioned migration ledger, encrypted backup and separate-database restore drill
EnablementSearchable help, eight advisor guides, full manual, A-to-Z playbook, workshop/answers, actual synthetic examples, portable HTML/Markdown and PDF

Verified boundaries

The verification record distinguishes pure tests, real API/database tests, the synthetic advisor journey, browser checks, dependency audit, local performance and backup/restore. Passing these does not certify production security, diagnostic accuracy or customer-system execution. See VERIFICATION.md and docs/verification for exact evidence.

The original Cobalt sample remains unchanged by the training journey. Northstar is a separate synthetic company whose scripted local participant confirmations are clearly labeled training. No real customer approval, email, permission grant or business action was created.

Remaining work before production

WorkstreamConcrete remaining acceptance
Identity and data accessVerified enrollment/recovery, SSO/MFA where required, company memberships, evidence ACLs, administrator lifecycle
Ingestion and analysisScanned private storage, document/transcript lineage, provider-backed jobs, reviewed changesets, budgets/cancellation and empirical evaluation
External researchExa project credential and live acceptance, provider spend limits, research retention/cancellation and wider source evaluation; Firecrawl optional
Core production domainsFull operational-model compiler, authority baseline/control context, complete non-record API request/response contract
Customer authority and runtimeEffective-access/policy adapters, authenticated staged approvals, managed Signet keys, exact target action, revocation, idempotent side effects and reconciliation
OperationsOff-host key/backup custody, full recovery cutover, comprehensive deletion/hold, monitoring/SLOs, large-load and distributed-worker evaluation
Independent release assuranceFull accessibility/browser matrix, physical microphone tests, security review/penetration test, blind diagnostic evaluation and owner acceptance
Enterprise expansionSSO/SCIM, deployment/isolation choices, permission-safe portfolio reporting and additional adapters

Exa, OpenAI, Resend and optional Neo4j Aura connections use encrypted account settings. PostgreSQL remains authoritative. Aura is connected for the advisor account: production maintenance copied Cobalt revision 206 with 71 records and 147 relationships on September 6, 2026. The shared graph reader returned a validated Aura snapshot; a repeat rebuild preserved counts without duplicates. See verification/2026-09-06-guided-release.md for the exact acceptance scope and guide/00-hosted-quickstart.md for the current workflow. The 0.2 delivery pack remains a historical local release. The app fails closed for live runtime preflight. INTEGRATIONS.md records other credential needs and live acceptance boundaries.

Requirement traceability

requirements-status.json maps all 90 supplied requirement IDs to implementation evidence and remaining work. Local subset means part of a requirement has working code. Open means the complete behavior is not implemented. No requirement is marked formally production-accepted by this local development run.

The source audit remains a bounded inspection of predecessor projects, not a claim that those repositories were fully executed or verified. The current source, lockfile and GitHub CI run identify this repository's release.