G GTM Intelligence Loop
Release roadmap snapshot · 2026-07-29 · owner A+B+C approved · corrective RC pending

Product completion map / cloud release active

From evidence to defensible action.

The approved product is locally implemented with full local gates passing. Owner decisions A+B+C are approved. Exact RC SHA 132b644 completed its release-candidate workflow, but it remains intentionally unpromoted after independent review identified runtime least-privilege and organization-bootstrap defects. The least-privilege API/worker guard, tenant-safe bootstrap repair and Clerk membership synchronization corrections are now locally complete and independently reviewed. A final corrective RC, hosted A+B+C evidence, exact-SHA worker proof, promotion and roadmap publication remain before this can be called the final release.

Corrective release candidate pending Local implementation complete Least-privilege corrections local PASS Owner A+B+C approved One-push Actions budget
100% Local PRD implementation coverage · repair candidate verified
158/158 Local Playwright journeys passing
10/10 Live local RLS proof · concurrent bootstrap PASS
89% Weighted release readiness · 11% remains

Programme anatomy

Every phase. One honest status language.

“Local coverage” means implementation and local evidence exist. It does not mean hosted exact-deployment, real-provider, or private-pilot proof.

Done local00

Architecture baseline

Repository, product, quality and executable contracts.

Done local01

Tenant + evidence model

Persistence, migrations, tenancy and RLS contracts.

Done local02

Workspace + onboarding

Secure organization setup and recoverable readiness flows.

Done local03

Source ingestion

Authorized, durable ingestion with provenance and recovery.

Done local04

Market Memory

Queryable facts, conflicts, corrections and citations.

Done local05

Buyer Belief Map

Reviewable beliefs, uncertainty and immutable decisions.

Done local06

GTM Eval engine

Versioned rubrics, scoring history and human overrides.

Done local07

Trust Graph

Explainable semantic nodes, edges, baselines and deltas.

Done local08

Recommendations

Action queue, approvals, ownership and outcome history.

Done local09

API + read-only MCP

Tenant-authorized product access and agent parity.

Done local10

Incremental refresh

Idempotent refresh, retained history and explainable change.

Done local11

Synthetic rehearsal

Measured local quality, rollback and stable surface evidence.

Done local12

Internal pilot protocol

Consent, readiness and supervised operating protocol.

Stabilizing13

Production-shaped release

Local product and corrective security work complete; final corrective RC, hosted A+B+C proof and promotion remain gated.

Local coverage14

Runtime quality baseline

Runtime contracts, golden data and intelligence metrics.

Local coverage15

Event journal

Artifacts, capture APIs, idempotency and projection foundations.

Local coverage16

Agent Gateway

API, MCP, CLI and SDK access with delegated identity.

Local coverage17

Context Compiler

Persisted context packs, ranking, policy filters and quality.

Local coverage18

External-agent loop

End-to-end intelligence retrieval, decision and outcome cycle.

Local coverage19

Decision Rooms

Collaborative rooms and GTM pull-request review contracts.

Local coverage20

Missing Evidence

Proof gaps, capture requests and completion burden.

Local coverage21

Continuous Monitor

Material change, suppression and operator delivery.

Local coverage22

Native connectors

Reconciliation, publication and outcome capture boundaries.

Local coverage23

Buying Groups

Stakeholder intelligence and Decision Defence Packs.

Local coverage24

Outcome learning

Experiments, observed results and adaptive recommendations.

Local coverage25

Hosted workspace

Agent-native inbox, registry and operating-mode contracts.

Local coverage26

Ecosystem + SDKs

Connector templates, interoperability and developer tooling.

Local coverage27

Enterprise autonomy

Policy control, residency, retention and governed capacity.

Release ladder

Built is not the same as proven live.

Product Quality OS keeps local, environment, hosted and owner evidence separate.

Readiness by evidence layer

Local implementation
0 gaps
Browser journeys
158/158
Disposable Postgres
PASS
Hosted exact deploy
first RC held
Real pilot evidence
owner
Release continuation active

Corrections complete locally. Final RC is next.

The owner approved A+B+C and the first exact RC succeeded, but promotion is deliberately held until the independently reviewed security corrections receive one final corrective RC and hosted proof.

  • Full local CI and 158/158 Playwright journeys PASS.
  • Honest Start/Load/Retry control states integrated.
  • Live local tenant RLS 10/10 and concurrent bootstrap PASS.
  • Clerk client identity gates and the production gtm-api JWT template are configured; protected public identity bindings are aligned and the static RC build verifies the embedded Clerk configuration.
  • Initial merged SHA e4cdda9 passed migration and the original smoke gate, but independent browser proof found a paired-RC CORS block. Repair SHA 1747dcb then passed workflow 30396067093, exact-origin hosted preflight, independent CORS/security checks, and immutable web/API deployment.
  • Render worker deploy dep-d9kh4f5bedkc73do5mpg is live; public /health and /ready return 200 with exact TEMPORAL_BUILD_ID=1747dcb….
  • gtm.semawork.com is DNS/TLS verified and points to the exact repaired web artifact. Clerk now uses clerk.semawork.com directly; owner sign-in, authenticated reload, and Home/Onboarding/Audit/Report pass.
  • Decisions A+B+C are approved. The free Sentry tracing trial is active and the serverless exporter repair is locally verified; the pre-release baseline remains zero spans. ADR-0023 membership sync, least-privilege runtime enforcement, tenant-safe organization bootstrap, database guards and rollback controls now pass local verification and independent review.
  • Exact RC SHA 132b644 succeeded in workflow 30432992134. Its immutable web and API artifacts are preserved, but the RC is intentionally unpromoted and superseded for final release by the local corrective security batch.

Evidence ledger

What the current claim rests on.

All links point to local, checked-in evidence.

Evidence Verdict What it proves Source
Whole-PRD scan Complete Zero known local implementation gaps at the prior checkpoint. fresh gap scan
Local browser suite 158/158 Desktop/mobile mocked and local customer journeys passed. agent handoff
Requirement ledger WARN Implementation exists; ten functional areas still need hosted evidence. traceability
Postgres migrations PASS Full local migration gates, membership/bootstrap corrections and tenant RLS isolation are independently verified. A live pooled-Neon probe also proves a non-bypass LOGIN, inherited gtm_app usage, denied privileged role switching, zero no-context organization visibility, denied raw receipt reads and cleared tenant GUCs after rollback/reuse. programme queue
Release proof Partial PASS SHA 132b644 completed its exact RC workflow but is intentionally unpromoted. Corrective least-privilege, bootstrap and Clerk work is locally complete; final corrective RC, hosted A+B+C evidence, worker exact-SHA/environment proof, promotion, live connectors, observability proof and pilot remain gated. release checkpoint

Roadmap honesty rule: local PASS is never relabeled as hosted PASS. “Complete” on this page refers to safe local implementation coverage unless the evidence row explicitly says hosted or live.

Next gates

The shortest path from WARN to release proof.

Expand each gate for its exact boundary.

1 — PASS, HELD: first exact A+B+C RC

SHA 132b644 completed workflow 30432992134, producing immutable web …web-prod-5rwcay40x… and API …api-prod-km9iw4i1j… artifacts. It is intentionally unpromoted because independent review required the corrective least-privilege and bootstrap batch now complete locally.

2 — NEXT: final corrective RC and hosted A+B+C proof

Deploy the corrective SHA once. Then create the approved labelled synthetic identities and tenants, prove restricted and cross-tenant behavior, Clerk membership create/update/deactivation and duplicate delivery safety, hosted Temporal start/retry/replay, and bounded Sentry telemetry without customer data or paid commitment.

3 — NEXT: worker exact-SHA/environment and promotion

Deploy the worker from the same corrective SHA with the guarded non-bypass runtime login, prove public health/readiness and Temporal environment alignment, then promote only the independently verified immutable web/API pair. Publish this roadmap after evidence is reconciled.

4 — DEFERRED: live connectors and supervised pilot

Decision D remains deferred. Run live connector or supervised pilot work only after the owner separately approves the provider/account scope, cost cap and authorized data. Keep pricing, legal and customer commitments human-controlled.