Release truth
What the current release actually makes available.
Implementation is not the same as availability. This page is built directly from the API capability registry so public wording follows the same release gate as the product.
1Available
5Bounded pilot
14Currently gated
| Capability | Status | Release evidence and open gates |
|---|---|---|
| API health and readiness checkshealth-checks | Available | Release integration test: GET /health |
| JWT authentication and role-based accessauthentication | Bounded pilot | Implemented; full authorization matrix verification is pending |
| Creator, brand, and deal recordscreator-brand-deal-records | Bounded pilot | Implemented; agency contract-to-cash workflow verification is pending |
| GST calculation and GSTIN validationgst-validation | Bounded pilot | Effective-dated catalogue resolution, immutable invoice-line rule passports, bounded external-CA override evidence, PostgreSQL RLS/deferred issue controls, and accessible client states pass locally; every seeded rule remains PendingCAReview and exact-SHA CA, role, browser, and assistive verification are pending |
| Approved, sequential, immutable invoice issuancecontrolled-invoice-issuance | Currently gated | Transactional financial-year sequencing, idempotency, immutable tax/rule passports, bounded CA override application, audit/outbox, delivery/correction commands, PostgreSQL concurrency tests, and the complete dedicated lifecycle pass locally against disposable PostgreSQL and Chrome with automated accessibility checks; legacy-number, finance, independent CA, exact-SHA role/assistive, and staging review remain release gates |
| Versioned contract lifecycle and e-signingcontract-lifecycle | Currently gated | Immutable contract and deliverable versions, structured clause decisions, exact-version internal/external/client approvals, replay-safe external review, prepared signature and scanned external-sign evidence, revision history, and exact publication URL/time/file/hash evidence with publication-gated delivery and billing have local API/client/PostgreSQL coverage; no exact-SHA browser, approved provider adapter, legal, scanner, role-denial, or assistive-technology verification is complete |
| Evidence-based accounts-receivable workbenchaccounts-receivable | Currently gated | Append-only case, promise, dispute, preference, policy, attempt, suppression, provider acceptance, and authenticated delivery/failure evidence plus the responsive client workbench pass locally; browser validation, approved vendor adapters, credentials, and staging delivery remain release gates |
| Tenant-scoped external provider adaptersexternal-integrations | Currently gated | Versioned provider configuration, opaque runtime secret aliases, allowlisted HTTPS endpoints, public callback validation, signed e-sign and reminder webhooks, exact-version delivery/failure evidence, durable idempotent dispatch, retry-after and circuit controls, and provider-free-text redaction are implemented for the JSON bridge protocol; no vendor selection, production credential, sender/template, or external certification is approved |
| Durable reminders and business-event notificationsautomated-notifications | Currently gated | The general notification client surface is removed from the production graph and the API fails closed; collection reminder evidence remains separately contained until all promotion contracts are verified |
| Authoritative operational analyticsanalytics | Currently gated | Direct evidence-derived operational and counterparty projections and the source/freshness/exclusion-aware client dashboard are implemented without samples; a complete local signed-in real-backend pass verifies exact INR and historical USD separation, formulas, sources, exclusions, insufficient-data behavior, invoice trace, responsive accessibility, and role denial; independent representative-data reconciliation, privacy approval, exact-SHA CI, and staging rehearsal remain release gates |
| Host-controlled pilot enrollment and success metricspilot-metrics | Bounded pilot | Append-only cohort enrollment, source-labelled baseline evidence, privacy-filtered usage outcomes, and versioned metric formulas are implemented; five design partners and baseline evidence are not yet collected |
| Reconciled accountant financial-year packagesaccountant-exports | Currently gated | Dedicated versioned CSV/XLSX packages plus expiring and revocable External Accountant invitations, restricted sessions, source references, hashes, append-only evidence, tenant/database boundaries, and a complete local signed-in generation/download/per-file reconciliation/role-denial browser pass have automated coverage; CA review, configured email delivery, human assistive, exact-SHA, and two-role staging verification remain release gates |
| Counsel-controlled privacy and retention operationsprivacy-operations | Currently gated | Authenticated user request/grievance intake with server-bound notice and deadline, bounded hash-manifested access packages, and preview-bound identity-profile anonymization with retained-class disclosure now extend the immutable governance, consent, request, and retention evidence model; the capability remains disabled pending counsel-approved policies, exact-SHA staging drills, role/browser/accessibility evidence, and independent security review |
| MFA-protected bounded tenant support accesssupport-access | Currently gated | A separate host-only Support role, ticket/purpose/actor/scope-bound 15 to 240 minute grants, bounded health and hashed snapshot exports, append-only host RLS evidence, explicit revocation and no tenant session or impersonation are implemented; Product and Security approval, PostgreSQL bypass tests, signed-in role/browser/accessibility evidence, an operator drill and exact-SHA staging evidence remain release gates |
| Evidence-based tenant incident operationsincident-operations | Currently gated | Append-only incident references, response timelines, notification decisions, recovery, and review evidence are implemented; platform-wide incidents, on-call runbooks, alerting, browser validation, and staging exercises remain release gates |
| Host recovery exercises and restore evidencerecovery-operations | Bounded pilot | Host-only immutable recovery plans, objective-derived results, and disposable PostgreSQL restore verification are implemented; provider backup automation, point-in-time recovery, and a staging exercise remain release gates |
| Versioned TDS assistance and reconciliationtds-compliance | Currently gated | Effective-dated fail-closed rules, benefit/perquisite evidence, source certificate file hashes, append-only Form 26AS comparisons, variance resolution and accountant-export v2 handoff datasets are implemented; independent practising-CA approval plus signed-in staging and assistive-technology evidence remain release gates |
| Payment gateway processingpayment-gateway | Currently gated | No approved gateway adapter or verified webhook flow is implemented |
| Evidence-based payment reconciliationpayment-reconciliation | Currently gated | Receipt capture, atomic multi-invoice allocation, append-only corrections, bounded audit snapshots, API authorization, PostgreSQL concurrency, derived client projections, and the complete dedicated desktop/360/320 real-backend browser pass with automated accessibility checks are implemented; legacy disposition, two-tenant role denial, human assistive, exact-SHA, and staging evidence remain release gates |
| User-confirmed advertising disclosure evidenceadvertising-disclosure-assistance | Currently gated | Immutable relationship, rule-version, label, placement, confirmation, and scanned proof evidence is implemented with explicit non-certification language; legal and product approval of the rule catalogue and wording is pending |
How to read this
Available means release-verified for the stated scope. Bounded pilot means operable only inside the documented pilot limits. Currently gated means runtime access stays fail closed; code or local tests alone do not make it a released feature.