agenthropic

Roadmap v1.0 → v2.0 — the last analysis (2026-07-06)

Status: FINAL. Analysis #9 of 9 — the genre ends here.

red-team-audit-2026-07-06.md §11 ordered that no ninth analysis document be written and instructed future sessions to decline. This document exists anyway, on the only authority that outranks a document: the owner’s explicit instruction in chat, 2026-07-06 (“make a new analysis, even more merciless — I want a detailed roadmap for v1 and v2”). The override is acknowledged, not hidden: this file is exactly the artifact §11 warned about, and it buys its existence one way only — by being the last. It converts open-ended analysis into dated kill checkpoints, and after it, the only documents this repository may gain are verdict records (WP-S7, checkpoint outcomes, WORKLOG.md/DONE.md) and the site pages that WPs X6/X7 already own. The next substantive artifact is git log output or a tombstone.


1. The numbers, re-measured today

Metric Red-team (earlier today) Now Direction
Markdown files 74 76 (77 with this one) worse
Words 132,754 141,270 +8,516 since the order to stop
Analysis documents 8 9 worse
Lines of application code 0 0 unchanged
Git commits 0 0 unchanged
Gate A unsigned since 07-04 unsigned unchanged
Friction-log entries 0 0 unchanged
Rival dashboards actually installed and used 0 0 unchanged
Measured development velocity no data no data unmeasurable — nothing has ever been built

Three indictments the red-team could not yet make:

  1. The corpus grew ~8.5k words in the hours after the audit that told it to stop growing. The growth was virtuous — amendments applied, lies fixed, a parallel-agent assignment board built — and that is precisely the problem: this project’s failure mode doesn’t feel like failure. It feels like diligence.
  2. A cleaner corpus is a better-rationalized corpus. Today’s cleanup fixed every internal contradiction the red-team catalogued (§2 below). The documents now agree with each other perfectly. Agreement among 141k words and zero commits is not progress; it is a more comfortable place to not build from.
  3. TODO.md is now a coordination protocol for a workforce that has never been hired. Disjoint lane ownership, orchestrator-only tracker files, 17 waves — for a repo in which no agent has ever executed a single work package.

1a. The same measurements, re-taken on 2026-08-15

The table above is preserved as the 2026-07-06 reading. Three of its rows have since inverted, and the third indictment no longer describes the repository:

Metric 2026-07-06 2026-08-15 Direction
Lines of application code 0 17,393 across 114 files — every .ts/.tsx/.mjs/.mts under apps/*/src, packages/*/src and hooks/ built
Test files / lines 0 106 *.test.ts(x) files; 29,619 lines across the 111 files in apps/*/test and packages/*/test built
Markdown files 76 129 (whole repo, excluding node_modules, .git, build output) grown
Git commits 0 > 0 — the working tree’s recent log shows at least five built
Gate A unsigned partially signed (three decision boxes, 2026-07-10); the two physical acts still open partial
Friction-log entries 0 0 — no friction log exists in the repository unchanged
Rival dashboards installed and used 0 0 — no record of one anywhere in the corpus unchanged
Measured development velocity no data still no data as a rate; what exists is a spike-day point, explicitly labelled an optimistic ceiling unchanged

The counts were taken by enumerating files on disk on 2026-08-15; the file-set definitions are spelled out in the rows themselves so the same numbers can be reproduced rather than trusted. The commit row is deliberately imprecise: this amendment was written under a no-git rule, so “more than zero, at least five” is the honest bound rather than a number that looks authoritative.

Read the shape of that table rather than its rows. Everything a machine could do got done; everything requiring Ivan to leave the keyboard did not. The friction log has never been opened, no rival has ever been installed and tried against the five daily questions, and the LABEL-ME ground truth is still blank — which are precisely the three inputs this roadmap said would decide whether the project deserves to exist. The document’s central worry was a corpus that grows instead of a product; the product now exists, and the worry has simply migrated: a repository can accumulate 17k lines of tested code and still not have answered the question of whether anyone needs it. Building is not evidence of usefulness any more than writing was.

KC-0 (2026-07-13) and KC-1 (2026-07-27) both passed with clauses unmet, and in both cases the default-death branch was overridden by dated owner instruction rather than satisfied — see the override notes at the top of TODO.md. Recording that plainly is the point: an override is a decision the owner made and can be held to, whereas a checkpoint quietly reported as “green” would be a lie the schedule could not recover from. The next live checkpoint is KC-2 on 2026-09-14, whose clause is Phases 1–2 exit gates green with at most one velocity rebase applied.

2. What actually changed since the red-team (honesty clause)

This document does not recycle dead ammunition. Of red-team §3’s “corpus lies about itself” examples, three were fixed today and are no longer live: the best-path “being amended” falsehood (AMEND-1…6 are applied, dev-plan §2b), the stale 18-vs-~849-nested citation, and DOCS-PLAN re-blessing the deleted WP-X11. Also fixed: supersession banners on the v1 analysis/plan and the obsolete fork recommendation, the coverage bar normalized to >90%, TODO.md rebuilt.

What did not change: commits (0), code (0), Gate A (unsigned), the friction log (never started), the cheapest experiment (still nobody has installed a rival and tried the five daily questions against it), and the kill condition (still structurally undecidable — restored in executable form in §4).

3. Velocity — the number nobody has measured

Every schedule ever written for this project is fiction, because velocity has never been observed: zero commits means zero data points. Worse, the plan’s own structure guarantees the bottleneck is not generation. Seventeen waves of up to 8 parallel agents all land their output on one desk — Ivan’s review bandwidth is the schedule, and it is also the scarcest resource this project competes for against kiko, servicenow-mcp and syncrona.

The v1.0 committed path is 63 work packages (of the 75 total: 8 alert-track WPs are post-1.0, A8/A9 cut, X11 deleted, D9m/IN4 merged, IN11 contingent — see §5). Phase 0 is a fixed two-week timebox (8 WPs); the remaining 55 WPs price out as:

Scenario WPs reviewed+merged / week 55 WPs take v1.0 lands Verdict
A — hobby (evenings, ~3/wk) 3 ~18 weeks ~2026-11-30 Ships the same day KC-4 kills it. Zero buffer. Hobby pace and this scope cannot coexist — descope at KC-1 or accept death.
B — focused (~7/wk) 7 ~8 weeks ~2026-09-21 Fits with ~10 weeks of buffer. The §5 dates assume roughly half of this throughput as built-in contingency.
C — sprint (12+/wk, batched reviews) 12 ~5 weeks ~2026-08-28 Fits easily. The risk inverts: reviews become rubber stamps and the >90% gate becomes the only real reviewer.

Calibration mandate: Phase 0 doubles as the velocity experiment. At KC-1 the actual WPs-per-week number exists for the first time; the §5 dates rebase to it once. A second rebase is not a schedule event — it is KC-4 firing early.

4. Kill checkpoints — death is the default

The red-team offered three exits and left the choice open. This roadmap closes it: the project is dead by default and stays alive only by passing dated checkpoints. Every checkpoint’s failure branch executes without a meeting, without a new analysis, without a “let’s reassess” — the reassessment is this table, pre-signed.

ID Date Condition to stay alive On failure (the default)
KC-0 2026-07-13 Gate A signed (CD-1…CD-10 + LB1/LB2 checkboxes in TODO.md, dated) and the friction log opened (best-path §9 gets start/end dates) and at least one rival dashboard installed for the two-week trial. Archive the repo. Salvage: security posture + probe method as a write-up. No deferral note — a deferral is the failure.
KC-1 2026-07-27 WP-S7 verdict written (GO or CONDITIONAL-GO) and the throwaway DAG-with-dollars render exists (§5 Phase 0) and the 14-day friction log does not show a rival answering ≥4 of the 5 daily questions acceptably. Archive. This restores the defused kill condition in executable form — both clauses now can fire, and either one is sufficient.
KC-2 2026-09-14 Phases 1–2 exit gates green (security spine live, >90% gate blocking, ingest idempotent, kill+restart zero-loss). Velocity rebase from KC-1 applied at most once. Descope per the §5 ladder if the P0 chain is intact; otherwise archive.
KC-3 2026-10-12 The three P0 release blockers green and merge-blocking (Σtokens==JSONL exact · double-replay byte-identical · DAG rebuilt from JSONL alone). Archive. The moat proof is the project; without it there is nothing to descope toward.
KC-4 2026-12-01 v1.0 tagged: five daily questions answerable, <30s time-to-understand, tree/DAG served from orchestration_edges, every dollar traceable. This date does not move. Archive + public write-up of what was learned. No third rebase exists.
KC-5 earned, not dated v2.0 entry: 14 consecutive days of real daily use of v1.0 by its own author + ≥3 dated friction-log entries wanting alerts. v2 cancelled; project enters maintenance mode. A dashboard its own builder doesn’t open daily has answered the alerts question already.

Every week Gate A slips past 07-13 eats KC-4 buffer one-for-one; KC-4 itself is fixed. An unsigned checkpoint table is décor — see §8.

Checkpoint status, 2026-08-15. KC-0 and KC-1 have both come and gone with clauses unmet, and in each case the archive branch was overridden by dated owner instruction (2026-07-18 and 2026-07-29, recorded at the top of TODO.md) rather than satisfied. The table above is left exactly as pre-signed, because rewriting a pre-signed checkpoint after it fires is how a kill condition becomes décor — the whole point of §8. Two clauses remain structurally unsatisfiable until the friction log is actually opened: KC-1’s third clause and, downstream of it, KC-5’s entry evidence. KC-2 (2026-09-14) is the next live checkpoint, and one of its conditions — “>90% gate blocking” — could not go green on code alone: the threshold shipped at 100%, but on 2026-08-15 nothing was merge-blocking, because main was unprotected. As built, 2026-08-25: main is branch-protected — the required status check is ci (the job id in .github/workflows/ci.yml; the workflow’s display name CI is not the context), and force-pushes to main and deletion of main are refused for everyone. A red run now withholds the merge button from a contributor, but not from the repository owner: enforce_admins is deliberately off, because agenthropic has exactly one maintainer whose normal working mode is a direct push to main, and admin enforcement would lock the sole maintainer out of their own repository. That is the enforcement half of the KC-2 clause; the accuracy and usability gates around it have not moved. See the standing correction, §1a for the re-taken measurements, and development-plan.md §2c for the coverage correction in full.

5. v1.0 roadmap — detailed

v1.0 = end of Phase 4 (best-path §6.1): the persistent cross-session subagent DAG + dollar-accurate cost attribution, answering the five daily questions in under 30 seconds, loopback-only, >90% covered, no alerts. Dates assume Gate A signs 2026-07-13 and hold scenario-B throughput at ~50% contingency.

Phase 0 — feasibility spike (2026-07-13 → 07-27, fixed timebox, throwaway)

WPs (8): S1 → S2/S3/S4 → S5/S6 → S7 (+ X10 worklog discipline). Waves 1–4 of the plan; S2/S3 are pre-answered by the desktop probe and become re-confirmations on the paired corpus; S4 is liveness-only, non-gating (§6.6).

Shape — Exit B, absorbed intact: the red-team’s recommended two-week timebox is adopted inside CD-8 rather than by bending it. S5+S6 fuse into one deliverable: a single throwaway script/page that renders the reconstructed subagent DAG with real dollars on the nodes from the captured corpus — the exact artifact Exit B demanded — labeled THROWAWAY, no scaffold, no production code. The friction log (opened at KC-0) runs concurrently. Day 14 = S7 = the GO/NO-GO the red-team called Exit B’s “day-14 decision”. CD-8 is never bent; Exit B happens anyway.

Exit gate: S7 GO/CONDITIONAL-GO with the CD-1 rule applied; JSONL-alone edge accuracy ≥95% vs Ivan-labeled trees; Σtokens exact on every corpus session; Ivan signs the rendered tree. Kill risk: the ≥95% falls apart beyond depth-1 (the probe’s depth-2 evidence is 6 edges — n=1 territory); or the friction log kills the premise. Both are KC-1 clauses. Velocity output: first measured WPs/week number.

Phase 1 — foundation, security spine, storage (07-27 → ~08-31)

WPs (23): F1–F8 · D1–D8, D10 · U0 · X1, X2, X5, X6, X7. Waves 5–9.

Everything CD-7 promises goes live here, before any feature code: merge-blocking >90% coverage (F3/F4/X5), no-spawner + no-SSRF static gates (F5), license/provenance scan (F6), the security contract tests (F7, intentionally red until U0 wires loopback+token+SSE-origin), WAL + an actually-exercised restore (F8), append-only events_raw proven by test (D4).

Exit gate: plan §3 Phase 1 row, verbatim. Kill risk: none technical — this phase is commodity. The risk is human: 23 WPs of scaffolding with zero visible dashboard is where hobby projects silently die. Mitigation: the Phase-0 throwaway render stays on screen as the reminder of what this buys. Sequencing trap (plan §7): do not merge F7 as “passing” before U0; U1’s change-notifier is built against a fake until IN7 exists.

Phase 2 — ingest substrate (~08-31 → ~09-14)

WPs (8): IN1, IN2, IN3, IN5, IN14 · X8 (hooks installer) · C1, C2 (pricing seed). IN11 (durable outbox) is contingent — off the v1 path unless its trigger fires (sub-second liveness need or a hooks-only source; probe §4c).

Exit gate: hook event + JSONL line for the same fact collapse to one events_raw row; kill+restart resumes at the durable offset with zero loss/dup; unknown event_type stored, not crashed; redaction live at the boundary; pricing seeded. Kill risk: JSONL format drift — the moat rents its land from an undocumented format (red-team §4; the ignored OTel query_source alternative is LOST-2). The accept-any-event posture and the 11-item parser gate are the insurance; if a Claude Code release breaks the parser mid-phase, that is a KC-2 fact, not a surprise.

Phase 3 — projection, DAG moat, reconciliation, cost (~09-14 → ~10-12)

WPs (14): IN6–IN10, IN12, IN13 · C3–C7 · X3, X4. The hardest phase; the release critical path runs straight through it (…IN6 → IN7 → IN8 → IN9 → IN10 → IN13/X3).

Exit gate = KC-3: the three P0 blockers green and merge-blocking; hierarchy ≥95% vs labeled corpus even without SubagentStart; missing-Stop → “unknown” within the window; PreCompact reprices against the preserved baseline; no priceless model in the corpus; 12-scenario negative catalogue green. Kill risk: this is where the CONDITIONAL-GO’s condition comes due. Confidence-85 was assigned by the analyst to their own work, uncalibrated (red-team §5); Phase 3 is where reality grades it.

Phase 4 — read API, SPA, the five questions (~10-12 → ~11-09) → v1.0

WPs (10): U1–U9, plus X9 pulled forward (see defect note). Waves 10–16 UI-side.

Exit gate: all five daily questions answerable; time-to-understand < 30s measured, not asserted; tree and global DAG proven served by a query over orchestration_edges (U3’s “proven, not reconstruction” clause); every displayed dollar traces to ground-truth tokens × dated price; apps/web inside the >90% gate; RELEASE.md (X9) executed once for real. Tag v1.0.

Plan defect, fixed here: the plan files X9 (release checklist) under post-1.0 Phase 6 / wave 17 — i.e. the v1.0 release at wave 16 would ship before its own release checklist exists. This roadmap schedules X9 into the v1.0 tail. The plan text is left untouched (it is an audit-stable record); this file is the schedule of record.

Descope ladder (pull in order, only at KC-2, only once)

  1. U9 Sankey/delegation view → a plain cost table inside U8 (Q2/Q4 still answerable).
  2. X4 12-scenario negative catalogue → the 4 core pathologies only.
  3. D10 TTL-sweeper half deferred to v1.1 (the redaction half stays — IN14 depends on it).
  4. U7 D3 force+tree → static indented tree; the ≥95% correctness gate stays.
  5. X6 badges/donation polish → v1.1.

Forbidden descopes, at any velocity: F5–F7/U0 (the security spine — the one thing every audit agreed survives), X3/IN13 (the P0 proof — the moat’s existence certificate), D7/IN8/U8 (the moat itself), IN5’s verbatim-tokens rule, IN12 (Q1 is unanswerable without the watchdog). A v1.0 without any of these is not a descoped v1.0; it is a different, worse project.

Explicitly NOT in v1.0

Alerts (entire A track, §6) · IN11 outbox (contingent) · WP-UX0 (a corpus-audit proposal, unfunded unless Ivan signs it into scope) · the animated room (adopt-not-build, gated behind the moat per its own analysis) · multi-host/fleet · retention TTL · anything touching 0.0.0.0, WebSocket, subprocess spawning, or payload-supplied URLs — those are not deferred, they are refused.

6. v2.0 roadmap — alerts, earned not scheduled

Entry = KC-5, and KC-5 only. No calendar date. v2.0 begins when v1.0 has proven it gets used: 14 consecutive days of real daily use + ≥3 dated friction-log entries wishing for a notification. If that evidence never materializes, v2.0 never starts, and that outcome is a success of this roadmap, not a failure — it will have prevented building a notification system for a dashboard nobody opens.

Scope: the post-1.0 alert core (best-path §6.1/§6.2): A1–A7 + A10. A8/A9 stay dead — config lives in a file; a single operator does not need CRUD screens for himself.

v2 wave WPs Gate
1 A1 (AlertSink port) Pure interface, no server/driver import.
2 A2 (schema, hoangsonww-attributed) · A3 (token_ref resolver) Forward-only idempotent migration; a >0600 secret file is rejected; the secret never exists in SQLite/SSE/logs.
3 A4 (no-SSRF dispatcher) · A5 (rules engine) · A6 (Telegram sink) No code path reads a URL from a payload (test-proven); cost_threshold boundary-tested; correctly-formatted messages per AlertKind.
4 A7 (delivery log, retry/backoff, dedupe, throttle) A real stuck/error condition → exactly one notification.
5 A10 (SSRF/secret-leak negative corpus) + release re-hardening Negative corpus green; alerts modules >90%; RELEASE.md re-run. Tag v2.0.

At scenario-B throughput: ~3–4 weeks. The friction log also feeds a small v2 candidate backlog, admitted one at a time and only with a log entry as its ticket: IN11 (if its trigger ever fires), the D10 TTL half, WP-UX0, the read-only animated room. Nothing enters v2 because it was planned in July; things enter v2 because October complained about them.

v2 non-goals: alerts CRUD UI, vector-DB/memory track (deleted, stays deleted), multi-user, auth beyond the single token, any public bind, any inbound tunnel beyond SSH/Tailscale.

7. Beyond v2 — mostly “never”

Idea Status
Fleet/multi-host view Only when a second host actually exists. Not before.
Animated room/office Adopt-not-build, read-only, only post-moat, only if the friction log asks for ambient glanceability.
Vector-DB “observability becomes memory” Never (best-path §6.3). Deleted, not deferred.
Public hosting / SaaS-ification Never. LB2 said personal-first; the security model is the loopback.
Browser-driven agent spawning Never. This project exists partly because a rival shipped that RCE.

8. The freeze, the signature, the next action

The freeze: red-team §11 is carried forward, hardened. After this file: no new analysis, audit, review, re-plan, meta-plan, or state snapshot may be authored — by any session, on any model, at any effort level — regardless of how reasonable it feels in the moment. Permitted writes: WP verdict records (S7), KC outcome lines, WORKLOG.md/ DONE.md, TODO.md checkbox state, and the X6/X7 site pages. A future session asked for “one more analysis” answers with this file’s §4 table. The corpus is complete. It was complete two documents ago.

The signature: an unsigned kill schedule is décor, exactly as an unsigned Gate A under 13 “accepted” ADRs is fiction. This table binds when Ivan signs both lines below (signing Gate A and KC-0 can be one act, before 2026-07-13):

The single next action (unchanged since the red-team, now with a deadline): sign Gate A and open the friction log by 2026-07-13, then start WP-S1. Or archive the repo this week and keep the security posture and the probe method as the write-up they deserve to be. Both are respectable. Only the third option — reading 141,270 words one more time — is not.


Analysis #9 of 9, authored 2026-07-06 on explicit owner instruction overriding red-team §11. Schedule of record for v1.0/v2.0; subordinate to best-path-decision.md on strategy and to development-plan.md on WP content, authoritative on dates, checkpoints, and scope boundaries once signed. Supersedes red-team §10’s open exit choice with §4’s default-death schedule.