// the pipeline LIVE

The Roadmap

A steering board, not a wish list

Everything Fulltrace might do next, run as a queue rather than a wish list. Every idea becomes a row in the register with an ID, a risk class, and the guardrails it must respect, and nothing gets built without one. The standout tracks are below, then the full live register. How a row becomes shipped software is the workflow page; what already shipped is the build log.

44 live rows 34 shipped 12 decision gates 06 risk classes
the_headliners [01]

The Headliners

The register does not rank by excitement, but this page can. What is queued next, and the tracks that change what Fulltrace is.

Up next: 5O.5
The fence proves itself on the content path

The injection fence is built and switched on: audited content is treated as data, never instruction. What is left is proving it costs nothing on the content side. Run a real content and website audit through the fenced path and check it against the pre-fence baseline: findings depth, every anchor still resolving, and the verbatim-copy contract surviving source fencing, with the spend bound set before it starts.

Why it is first
The code path already passed

The same check on the code side already came back clean: three targets, about US$0.32 in spend, no quality regression. This content-path check was blocked behind hardcoded drive letters that broke the full test suite, now cleared. A shipped defence with one unverified path is a defence with an asterisk, and this row exists so the asterisk cannot be quietly forgotten.

5W
Chat with real model routing

A Studio chat tab under the same guardrails as everything else: explicit pick, vendor-pinned auto, or full Auto through a two-stage router, with metered API calls and subscription CLIs as parallel execution classes. The design is shipped and adversarially reviewed, with the build cut into four slices.

5V
Approvals from the phone

Push notifications and a read-only mobile triage page over the tailnet already work. The next step is the first off-machine write: approve or reject an inbox item from the phone, issuing the same grant through the same path as the desk.

5G
Unattended operation

The system runs scheduled work on its own: schedule, enqueue, auto-drain. Arming a schedule is a recorded act bound to its content hash, so any edit disarms it until it is re-approved, and a decision-debt cap stops it generating decisions faster than I can review them.

5Q
Node and fleet foundation

Several machines, each running its own copy, push what they are doing to one place I can watch. That place can only look: it never approves, never applies, and holds no authority channel back to a node, a fleet I can watch but never command. The design is shipped, after two external adversarial reviews, with the build cut into four rows behind it.

5X
Local models, lawfully

A five-model Ollama fleet, running on my own machine, costing nothing per use, observed and warmed from Studio > Models. The sequencing is the point: execution-class recording (metered, subscription, local) shipped before the fleet surface existed, so no local call could ever have gone unrecorded. Pipeline participation is refused outright in v1 and gated behind its own design row, rather than allowed by default just because it is free.

5P
A browser that can write, carefully

A browser page that can make changes, wrapped in the same freeze, simulate, approve, apply spine as everything else. Even localhost is treated as hostile-caller territory: a link opened off-machine can reach a read-only triage view at most, never the write API.

5M
The system studies its own runs

Mine run metrics, dispositions, and verifier verdicts for per-workflow signal, then feed it back into prompt, model, and route selection. Descriptive first: nothing changes agent behaviour without its own gated slice.

5T
User-state backup

A code-owned registry of every user-state domain: settings, target registries, memories, skills, commands. Exports to a git-tracked repo with a fail-closed secret scan before anything leaves the machine. Config can narrow the export, never widen it.

5S
Portfolio context serve

Every audit gets the same server-owned slice of my working context: no default slice, no client-picked files, and every use of it traced in the report's evidence. It is the first concrete step towards the system remembering context between runs: memory informs, the spine still decides.

5B
Model evals with receipts

Quality per workflow measured on a fixed task set with bounded spend and a results ledger. Which model actually audits better, with receipts.

the_full_register [02]

The Full Register

All 44 live rows, straight off the steering board. Role says why a row exists: boundary rows lock or open a constitutional line, keystones are load-bearing, unlocks enable a later step, hygiene keeps the runtime honest. Risk sets how much design happens before code. Shipped rows leave this table at closeout: 34 so far, narrated in the build log, so a prereq you cannot find below has already shipped.

full_registerid · role · risk · status
IDTitleRoleRiskPrereqStatus
5P.1Browser-on-node operate surface: design gateboundaryR4nonein progress
5O.5Injection fence content-path before/after live checkvalidationR3noneup next
5O.4Injection fence red-team eval corpusvalidationR1noneproposed
5N.1Decision inbox: the "what needs me" projectionkeystoneR05Q.4, 5Q.5deferred
5W.2Chat tab v1: explicit pick, metered classunlockR35W.1proposed
5W.3Subscription execution class for chatunlockR35W.2proposed
5W.5Model provenance in authority-plane recordsboundaryR1noneproposed
5W.4Tiers and Auto routing for chatboundaryR35W.3, 5W.5proposed
5V.4Remote decision surface: design gateboundaryR05V.2, 5V.3 + demonstrated demandproposed
5X.4Local provider seam, v1 pipeline refusal, route validationboundaryR15X.3proposed
5X.5Chat local execution classunlockR35W.2, 5X.4proposed
5X.6Embeddings capability designunlockR05X.4, 5O.2proposed
5X.7Local pipeline participation designboundaryR05X.4proposed
5G.1Unattended operation design: schedule, enqueue, auto-drainboundaryR0noneproposed
5G.2Unattended operation implementationunlockR35G.1proposed
5G.3Schedule controls in StudiounlockR45G.2proposed
5Q.2Node identity and origin stampingkeystoneR1noneproposed
5Q.3Testimony contract and payload shapingunlockR15Q.2proposed
5Q.4Push publisherunlockR45Q.3proposed
5Q.5Centre v1: enrolment registry, ingest, observatoryboundaryR55Q.3proposed
5R.1Declarative workflow authoring designboundaryR0noneproposed
5S.1Portfolio context serve: slice registry and gateway endpointkeystoneR2noneproposed
5S.2Runner context module and content-audit migrationunlockR15S.1proposed
5S.3Code-audit executor and challenger voice slicesunlockR15S.1proposed
5S.4Studio context strip and degraded warningpolishR25S.2, 5S.3proposed
5T.1User-state registry and scheduled backup designboundaryR0noneproposed
5T.2Backup implementation and Settings tab controlsunlockR45T.1proposed
5M.1Workflow self-improvement from run data: designboundaryR05H.2proposed
5B.1Model evaluations and benchmarks designvalidationR0noneproposed
5C.1Projects tab design, onboarding interview firstunlockR0noneproposed
5D.1Slack outbound notifications designunlockR0noneproposed
5E.1Goals interface designunlockR0noneproposed
5J.1Studio UX review and IA redesignunlockR0noneproposed
5J.2IA restructure implementationunlockR25J.1proposed
5J.3Run-completion notifications in the IDEpolishR2noneproposed
5J.4SSE live updates in StudiounlockR2noneproposed
5J.5Open-source jump in the content-audit panelpolishR2noneproposed
5A.2Webview render harness: state-to-HTML snapshot testshygieneR15A.1proposed
5A.3Tier 1 extraction: sensitive pure helpershygieneR15A.1proposed
5A.4Tier 3 webview decompositionhygieneR25A.2, 5A.3proposed
5I.2Register drift checkhygieneR1noneproposed
5K.5Remaining machine-path pins outside the suitehygieneR1noneproposed
4G.6Studio launch of the website-audit graphunlockR2noneproposed
4E.30Ledger enrichment design: category, type, anchor contextunlockR0noneproposed
One row is deferred rather than dead: the decision inbox shipped five of its six slices, then stopped by an explicit call, because the last slice (the fleet tier) needs a node foundation that did not exist yet. It was flipped from in-progress to deferred for a precise reason: in-progress is what the dashboard's Current section reads, and a paused row sitting there would misreport work still in flight. Twelve decision gates bind the rows above before they can kick off; the gates, the eighteen guardrails, and the slice protocol all live on the workflow page.