Roadmap

WHAT IS DONE. WHAT IS NOT.

Phases, not dates

Work is tracked in phases with exit gates, not calendar dates. A phase is finished when its gate is met, and the gate is written so that it can be failed.

Phases

Updated 13 September 2026

Phase one: prove the claim

In progress

Intake and public split, moderator flow end to end, go-live and chain reset rehearsed on a fresh server, the full test suites green, and the form usable on a phone with one bar of signal.

Gate: a stranger files a report, a moderator approves it, and the proof verifies.

Phase two: make it theirs

Next

Organization scoping, scoped moderator roles, the visibility ceiling enforced in two stages, group dashboards, intake links, import from whatever a group uses today, export, and a per-organization proof bundle.

Gate: one organization runs a full cycle without an archive admin touching anything.

Phase three: make it explainable

Planned

A clickable demo instance with realistic fake data, the lifecycle and roles diagrams, a plain-language explanation of tamper evidence, and an FAQ split between reporters and organizations.

Gate: somebody outside the project can explain the system correctly after reading only these.

Phase four: open it and hand it over

Planned

Public repository, licence file, contributor guide and code of conduct, install documentation good enough for a stranger, and as much operator work as possible through an interface rather than a terminal.

Gate: somebody who has never spoken to us stands up a working instance from the documentation alone.

Known limitations, precisely

Note

Several design questions are open and are listed as open rather than answered early: whether a moderator can undo a lowering, whether a group can claim a report filed without its link, and the final names of the visibility rungs. None of them will be settled quietly.

Phases, not dates.

Want a part of it sooner? Say so.