Everything Fulltrace might do next, run as a queue rather than a wish list. Every idea becomes a row in the register with an ID, a risk class, and the guardrails it must respect, and nothing gets built without one. The standout tracks are below, then the full live register. How a row becomes shipped software is the workflow page; what already shipped is the build log.
The register does not rank by excitement, but this page can. What is queued next, and the tracks that change what Fulltrace is.
Unattended operation is live. Schedules are committed config with no enabled field: enablement is a recorded act, hash-bound to everything the schedule references, so any edit disarms it. Nothing ticks until four spend caps are set by hand, because the caps file ships blank and unbounded is a state the code refuses. The decision cap counts what the night puts in front of me by morning, not what it spends, and every due tick ends as ran, skipped or capped, never silence.
The accountability sweep behind it just landed: a mistyped flag no longer buys a model call (it is refused, naming the near miss), a solo agent run finally writes a run record, and a census of all eighteen CLI entry points forces every path to declare where its spend lands. Three metered paths still record nothing, and closing them is the row in flight rather than a footnote.
A Studio chat tab under the same guardrails as everything else: explicit pick, vendor-pinned auto, or full Auto through a two-stage router, with metered API calls and subscription CLIs as parallel execution classes. The design is shipped and adversarially reviewed, with the build cut into four slices.
Push notifications and a read-only mobile triage page over the tailnet already work. The next step is the first off-machine write: approve or reject an inbox item from the phone, issuing the same grant through the same path as the desk.
Shipped in two increments: first the schedule and the arming act with nothing allowed to run, then the tick loop under four hand-set spend caps. A tick is keyed to a calendar date rather than an instant, so daylight saving cannot fire it twice or never, and a machine off for a week can name exactly which nights it missed. What remains is 5G.3: seeing and arming schedules from Studio rather than the CLI.
Several machines, each running its own copy, push what they are doing to one place I can watch. The foundation shipped in July: node identity, the push publisher, and a centre that can only look. It never approves, never applies, and holds no authority channel back to a node: a fleet I can watch but never command.
A five-model Ollama fleet, running on my own machine, costing nothing per use, observed and warmed from Studio > Models. Its first real job shipped: a local embeddings index over the project's own docs, searched from the assistants' tools at $0 a query, storing vectors and never corpus text. Pipeline participation stays refused: the stage-scope rule was ruled, and the answer is still no.
A browser page that can make changes, wrapped in the same freeze, simulate, approve, apply spine as everything else. The read surface shipped, and the write-session foundation shipped with zero verbs on it. Even localhost is treated as hostile-caller territory: the first real write verb is its own gated row.
Declarative workflow authoring, designed and adopted: behaviour is code, selection is data. A definition may choose which code runs and in what order; it can never determine what any code does, and every definition needs a live accept act binding its content hash. It is also the row that hardens the factory claim: once the production rules are data rather than prose, the word needs no qualifier.
A code-owned registry of every user-state domain: settings, target registries, memories, skills, commands. Exports to a git-tracked repo with a fail-closed secret scan before anything leaves the machine. Config can narrow the export, never widen it. The design is adopted; the build carries an external review before code.
Every audit now gets the same server-owned slice of my working context: no default slice, no client-picked files, and every use traced in the report's evidence. Shipped across the website audit, the code audit and its challenger, with a Studio panel showing what framed each run. Memory informs, the spine still decides.
A new track drawing one line around egress: adopt the rule that nothing leaves the machine except through named channels, census those channels with locks in both directions, teach the push tool to refuse a foreign remote, and give the client plane a deny set for shell egress. The boundary ruling comes first; the hygiene rows ride behind it.
Quality per workflow measured on a fixed task set with bounded spend and a results ledger, born display-only. Which model actually audits better, with receipts. The design is adopted; the harness waits until it earns its spend.
All 41 live rows, straight off the steering board. Role says why a row exists: boundary rows lock or open a constitutional line, keystones are load-bearing, unlocks enable a later step, hygiene keeps the runtime honest. Risk sets how much design happens before code. Shipped rows leave this table at closeout: 127 so far, narrated in the build log, so a prereq you cannot find below has already shipped.
| ID | Title | Role | Risk | Prereq | Status |
|---|---|---|---|---|---|
| 5S.13 | Three metered paths still write no run record | hygiene | R1 | 5S.10 | in progress |
| 5A.2 | Webview render harness: state-to-HTML snapshot tests | hygiene | R1 | 5A.1 | proposed |
| 5A.3 | Tier 1 extraction: sensitive pure helpers | hygiene | R1 | 5A.1 | proposed |
| 5A.4 | Tier 3 webview decomposition | hygiene | R2 | 5A.2, 5A.3 | proposed |
| 5M.5 | Absolute anchor paths in code-audit reports | hygiene | R1 | none | proposed |
| 5C.2 | Development methodology as data: per-project descriptor | unlock | R1 | none | proposed |
| 5C.3 | Roadmap-authoring interview: design | unlock | R0 | 5C.2 | proposed |
| 5C.7 | Website machinery to config | unlock | R4 | none | proposed |
| 5D.1 | Slack outbound notifications design | unlock | R0 | none | proposed |
| 5E.1 | Goals interface design | unlock | R0 | none | proposed |
| I2w | Public website flip to Fulltrace (this site) | hygiene | R1 | none | proposed |
| 5G.3 | Schedule controls in Studio | unlock | R4 | 5G.2 | proposed |
| 5I.2 | Register drift check | hygiene | R1 | none | proposed |
| 5J.1 | Studio UX review and IA redesign | unlock | R0 | none | proposed |
| 5J.2 | IA restructure implementation | unlock | R2 | 5J.1 | proposed |
| 5J.3 | Run-completion notifications in the IDE | polish | R2 | none | proposed |
| 5J.5 | Open-source jump in the content/website audit panel | polish | R2 | none | proposed |
| 5O.4 | Injection fence red-team eval corpus | validation | R1 | none | proposed |
| 5S.6 | The website audit's challenger gets the owner's voice | polish | R1 | 5S.3 | proposed |
| 5U.2 | The launch press owns the in-progress flip | unlock | R4 | 5U.1 | proposed |
| 5U.6 | Closeout steps that can never tick honestly | unlock | R2 | 5U.4 | proposed |
| 5EG.1 | Adopt G19 and the outside definition | boundary | R0 | none | proposed |
| 5EG.2 | The egress census and its both-directions locks | boundary | R1 | 5EG.1 | proposed |
| 5EG.3 | The push tool refuses a foreign remote | hygiene | R1 | 5EG.2 | proposed |
| 5EG.4 | Client-plane deny set for shell egress | hygiene | R1 | 5EG.1 | proposed |
| 5S.9 | A flag that takes a value swallows the next flag | hygiene | R1 | 5S.8 | proposed |
| 5S.5 | The context serve cannot name the run it framed | hygiene | R1 | 5S.2 | proposed |
| 5T.2 | Backup implementation and Settings tab controls | unlock | R4 | 5T.1 | proposed |
| 5V.4 | Remote decision surface: design gate | boundary | R0 | 5V.2, 5V.3 + demand | proposed |
| 5W.2 | Chat tab v1: explicit pick, metered class | unlock | R3 | 5W.1 | proposed |
| 5W.3 | Subscription execution class for chat | unlock | R3 | 5W.2 | proposed |
| 5W.5 | Model provenance in authority-plane records | boundary | R1 | none | proposed |
| 5W.4 | Tiers and Auto routing for chat | boundary | R3 | 5W.3, 5W.5 | proposed |
| 5X.5 | Chat local execution class | unlock | R3 | 5W.2, 5X.4 | proposed |
| 5Z.2 | Wall-clock term in the graph budget | boundary | R0 | 5Z.1 | proposed |
| 5Y.6 | Tool-call subject on the trace | boundary | R1 | none | proposed |
| 5Z.16 | Filter the Runs page by model | unlock | R2 | 5Z.15 | proposed |
| 5Z.17 | A spend surface: what did the runs cost | unlock | R2 | none | proposed |
| 5M.6 | Findings over time: new, persisting, resolved per target | unlock | R2 | none | proposed |
| 5V.5 | A weekly digest: the week in counts | unlock | R2 | 5EG.1 | proposed |
| 5Z.18 | Run comparison: two runs side by side | unlock | R2 | none | proposed |