{"id":"roadmap","relativePath":"roadmap.md","title":"Meta Museum Roadmap","markdown":"# Meta Museum Roadmap\n\nThis is the current, authoritative execution plan. It supersedes\n[development-roadmap.md](development-roadmap.md), which is retained as the legacy\npre-Next.js plan. Completed slice history lives in\n[progress/era-history.md](progress/era-history.md); the strict evidence checklist\nlives in [roadmap-to-10.md](roadmap-to-10.md); open engineering risks live in\n[risk-register.md](risk-register.md).\n\nThe architecture north star is\n[linked-art/LinkedArtSOTAWebApp.md](linked-art/LinkedArtSOTAWebApp.md). Provider,\nschema, protocol, and validation work must map tests to fixture anchors in\n[linked-art/LinkedArtModel1.0-Reference.md](linked-art/LinkedArtModel1.0-Reference.md).\nThis document owns sequencing and stop/go decisions.\n\n---\n\n## Status (as of August 6, 2026)\n\n<!-- BEGIN:PROJECT_STATS -->\n<!-- Generated by `pnpm docs:stats`; do not edit by hand. -->\n\n| Generated project stats | Current value |\n|---|---|\n| Next.js | `16.2.12` |\n| React | `19.2.4` |\n| App page files | root homepage + `41` non-root page files (`42` total) |\n| API route handlers | `149` `app/api` route handlers |\n<!-- END:PROJECT_STATS -->\n\n### Executive Assessment\n\nMeta Museum is a strong, unusually complete Linked Art product and a credible\ncontrolled-beta system. It is not yet defensible as institution-grade or\nrepeatable SaaS. The gap is mostly evidence quality, operational history, and\ncommercial proof rather than missing core product breadth.\n\n| Category | Score | Evidence-based assessment | Immediate implication |\n|---|---:|---|---|\n| Product experience | 6.5/10 for the public; 8.2/10 for museum and research users | The source-backed professional journeys are coherent, but public discovery still exposes workspace language, operational controls, and specialist navigation before establishing a reason to explore or return. | Separate the public museum from the professional workspace and build one curiosity-led discovery loop before adding more platform breadth. |\n| Linked Art and data semantics | 9.0/10 | Canonical JSON-LD, event-centric modeling, rights, provenance, equivalent identities, HAL relations, IIIF, and provider boundaries are deeply implemented and test-backed. | Sustain conformance; do not add another provider until readiness work clears. |\n| Evaluator and trust story | 8.4/10 | `/projects`, `/evidence`, `/datasets`, `/docs`, and machine-readable APIs make the work inspectable. The public evidence ledger currently mixes contradictory artifact baselines. | Repair proof consistency before adding more evaluator copy. |\n| Accessibility | 9.3/10 | `pnpm a11y:check` passed 18 routes with 0 violations on July 12. Auth redirects for protected routes were handled as expected. | Keep zero severe violations and add accessibility checks to any hero or navigation polish. |\n| Engineering architecture | 8.0/10 | Boundaries, contracts, strict TypeScript, storage abstractions, tests, and evidence automation are mature. The route and script surface is large and operationally expensive. | Prefer consolidation and owner clarity over new surface area. |\n| Reproducible local quality gate | 6.5/10 | Direct ESLint passed and the local review-goals gate passed, but the audit began with a stale closeout guard, direct TypeScript failed in generated `.next/dev/types/validator.ts`, and a direct full test run did not finish within 10 minutes. | Re-establish one clean, repeatable canonical gate before feature work. |\n| Documentation and governance | 8.5/10 | The docs surface is rich, agent-readable, and guarded for drift. The previous roadmap had become a completion ledger rather than a decision document. | Keep this file current and concise; send completed detail to history. |\n| Operational readiness | 6.0/10 | Production preflight is 20/20 and launch review is 7/8, but long-window SLO, uptime, KPI, and artifact-coherence proof remain red. | Clear deploy-environment proof, then let time-based evidence accumulate without manufacturing results. |\n| SaaS and business readiness | 5.5/10 | The managed pilot offer and tenant-aware technical foundation are credible. There is no invoice-backed pilot, repeatable onboarding, retention, or margin proof. | Sell and execute one bounded concierge pilot before building self-serve billing. |\n\nOverall decision: **8.1/10 as a local product and portfolio case study; 5.8/10\nfor strict public-production readiness.** The project is safe to keep demoing and\niterating. Broad institution-grade or profitable-SaaS claims remain blocked.\n\nThe July 21 live review confirmed that the primary public journeys render without\nbrowser console errors. The same review found that `pnpm typecheck:diagnostic`\nfailed in test contracts and fixtures. Those type errors are now repaired:\n`pnpm typecheck:diagnostic`, 59 focused tests, `pnpm lint`, and `pnpm build` pass.\nThe full serial `pnpm test` run completed `1,677/1,677` tests in `157.5s` on\nJuly 28 after stale deployment-preflight and documentation-contract expectations\nwere aligned with canonical evidence. `pnpm review:goals:check`\nnow reports `21` production-proof blockers (`0` local-refresh, `0`\ndeployment-environment, and `21` real-world-evidence). Completing the canonical\nlocal test run is no longer a P0 blocker.\nThe July 28 timeout investigation confirmed `1,704/1,704` tests pass in 154\nseconds with a compact reporter. The canonical test script now uses that\nreporter to prevent captured verbose output from stalling the command channel.\n\nAugust 5 quality-gate refresh: P0.2 is green again after the 24-hour closeout\nguard expired. Lint passed in `19.3s`, diagnostic TypeScript in `5.4s`, the full\nserial suite in `150.4s`, and the Next.js production build in `50s`. The repair\nkeeps intentionally untracked `data/source-repos` mirrors out of tracked-text\ndrift scans and anchors synthetic SLO samples to each evaluation timestamp so\nthe gate remains reproducible after the original June fixture window. The three\nnew standalone evaluator briefings are preserved in the same clean worktree.\nThe architecture evaluation briefing now marks the canonical-gate risk closed\nand carries these measured results instead of its earlier stale warning.\n\n### Readiness Boundary\n\n- [ ] **Strict 10/10 readiness is not green yet**: `pnpm review:goals:check`\n  reports `status: external-evidence-required`, `local gate status: passed`, and\n  `strict 10/10 gate status: failed`.\n- [x] The July 10 production deployment preflight passes `20/20`; the latest\n  launch review passes `7/8`, with the launch-review Era C dependency still red.\n- [x] The latest strict handoff reports `0` local-refresh, `0` deployment-environment, and `21` real-world-evidence blockers, or `21` production-proof blockers in total.\n- [x] The evidence ledger, readiness dashboard, Era C, long-term, launch-review, and review-goals artifacts now share the same canonical blocker, SLO, uptime, and ActivityStreams values.\n- [ ] Remaining strict proof includes 30-day SLO/uptime evidence, production KPI exports, durable ActivityStreams syndication including a genuine `Delete`,\n  paid-pilot proof, retention, and gross-margin evidence.\n- [x] Current launch status is governed by `pnpm review:goals:check`.\n- [x] `pnpm review:goals:check` must be green before broad public SaaS claims.\n\nThe allowed claim is: **local gates pass and strong external proof exists; strict\n10/10 production readiness remains blocked by external evidence.**\n\n### Evaluation Findings That Change Priority\n\n1. **Public evidence consistency is repaired and regression-guarded.** The\n   canonical handoff, README, roadmap, and live ledger now agree on `21 = 0 + 3\n   + 18` strict blockers. The ledger also reconciles partner confirmations with\n   generated ActivityStreams evidence, so its pending Delete row cannot repeat\n   confirmed `Create` or `Update` types as missing.\n2. **The local gate is not yet reproducible from one clean command sequence.**\n   The closeout guard, a malformed generated Next dev validator, and a long-running\n   direct test invocation obscure whether a fresh checkout is truly green.\n3. **The product breadth is sufficient.** Fourteen provider lanes, 34 pages, 146\n   API routes, public docs, validation, reconciliation, ActivityStreams, IIIF,\n   agent review, and tenant-aware pilot controls are enough for the next learning\n   cycle. More breadth would dilute the evidence and customer work.\n4. **The next product-polish gain is quality, not more sections.** The current\n   hero can enlarge a low-resolution source image, while Core Web Vitals and\n   primary-journey performance do not yet have a concise public baseline.\n5. **The public product needs a distinct reason to return.** Cross-provider search\n   is useful, but it does not yet turn the underlying data advantage into stories,\n   surprising discoveries, personal collections, or connections that no single\n   museum site can show.\n\n---\n\n## Priority Plan\n\nPriority is determined by trust and dependency, not by implementation novelty.\nDo not start a lower tier while an actionable higher-tier exit condition is red.\nTime-bound external evidence may continue accumulating in parallel.\n\n### P0 - Restore A Trustworthy Baseline (Now, 0-7 Days)\n\n| ID | Outcome | Owner | Exit criteria | Verification |\n|---|---|---|---|---|\n| P0.1 | Keep public readiness evidence internally consistent. | Platform + Evidence | `/api/evidence/ledger`, `/evidence`, `/readiness`, review-goals, launch review, and the long-term artifacts agree on SLO sample/day counts, uptime, ActivityStreams observed/missing types, and current blocker scope. Fallbacks disclose missing artifacts instead of substituting incompatible values. | `tests/services/readiness-evidence-consistency.test.ts`; focused evidence-ledger, readiness, review-goals, and documentation-drift tests; `pnpm evidence:ledger:probe:check`. |\n| P0.2 | Restore one clean local quality gate. | Platform | From a fresh generated state, `pnpm session:closeout:check`, `pnpm lint`, `pnpm test`, `pnpm build`, and `pnpm typecheck:diagnostic` all complete successfully. The generated `app/api/vanda/search/route.js` validator fragment is valid after regeneration, and test duration is recorded. | Run the five canonical commands and attach elapsed time plus the first failing test if any. |\n| P0.3 | Clear deployment-environment proof drift. | Operations | Rerun production preflight, launch evidence, launch review, and public Era C evidence with production environment present; reduce the deployment-environment lane from `4` blockers to `0` without changing the real-world claim boundary. | `pnpm launch:preflight:production`; `pnpm launch:evidence:production`; `pnpm launch:review:production`; `pnpm era-c:exit-gate:public`; `pnpm review:goals:check`. |\n| P0.4 | Preserve nightly k6 evidence artifacts. | Platform + Evidence | The Docker fallback writes `artifacts/performance/k6-slo-summary.json` as the host runner user, deletes stale summaries before each run, and fails when no fresh summary is produced. | `pnpm exec tsx --test tests/scripts/k6-slo-runner.test.ts`; confirm the next Era C workflow ingests one fresh SLO sample. |\n\nProduction database SSL drift was repaired on July 27: Vercel now uses the\nexisting `sslmode=verify-full` connection value, the production artifact was\nredeployed, and `/api/ai/query` returned `200` through the public alias.\n\nP0 exit gate: all local commands are reproducibly green, public evidence has no\ncross-surface contradictions, and deployment-environment blockers are zero.\n\n### P1 - Convert Reliability And Demand Into Proof (Next, 1-6 Weeks)\n\n| ID | Outcome | Owner | Exit criteria | Verification |\n|---|---|---|---|---|\n| P1.1 | Complete the 30-day reliability window. | Operations | One canonical source reports 30 distinct UTC days of complete passing deployed SLO samples, including the cold-record scenario, and at least 99.9% public-read uptime with failed rows aged out of the retained window. | Scheduled probes plus `pnpm longterm:evidence:public` and `pnpm era-c:exit-gate:public`. |\n| P1.2 | Produce real SOTA KPI evidence. | Data + Curation | Production/Postgres or warehouse exports meet the reconciliation auto-approve and reviewed-precision thresholds; every capture row identifies its production source. | `pnpm monitoring:kpi-evidence:production`; `pnpm era-c:exit-gate:public`. |\n| P1.3 | Close one invoice-backed managed pilot. | Founder + Product | One real buyer has a signed scope and invoice reference, one collection is activated within seven days, and support, required KPI, retention, and gross-margin rows are captured without placeholders. | `pnpm pilot:buyer-pack`; `pnpm pilot:activation`; `pnpm pilot:support`; `pnpm pilot:kpi`; `pnpm pilot:evidence --check`. |\n\nThe architecture evaluator now participates in the commercial pre-revenue claim control: it must disclose the absent invoice-backed pilot, remain `External evidence required`, and point to `pnpm pilot:buyer-pack` plus the tenant-scoped `pnpm pilot:evidence --check` acceptance gate. This improves the handoff but does not count outreach or local tooling as revenue proof.\n\nAugust 5 ownership and operator-experience pass: the compact public mobile header and product-specific agent sign-in context are implemented and regression-tested. The operations-risk report now covers `35/35` page routes across `7` ownership/consolidation lanes alongside `61/61` API families and fully classified package-script namespaces. `pnpm ops:profile` makes the Next.js + Postgres portable baseline explicit and keeps Python services, AG2, Solr, GraphDB, and publication workers optional until their readiness gates justify enablement. The evaluator marks mobile and authentication closed while keeping broad surface area and specialist topology honestly managed rather than eliminated.\n| P1.4 | Preserve honest ActivityStreams adoption. | Platform + Partnerships | Keep `3/3` real external consumers, `3/3` verified durable callbacks, and zero rejected subscriptions fresh. Add `Delete` only after a genuine upstream `404`/`410` tombstone and partner read; never synthesize it to satisfy the gate. | `pnpm providers:coverage:seed`; `pnpm activity:tombstone:scan`; `pnpm activity:subscriptions:guard`; `pnpm activity:syndication:evidence`. |\n| P1.5 | Raise visible product quality and establish a performance baseline. | Product + Frontend | Home, Explore, one artwork detail, Projects, and Pilot pass mobile/desktop visual review; no hero image is rendered above a defensible intrinsic size; no text overlaps; LCP <= 2.5 s, CLS <= 0.1, and INP <= 200 ms on the agreed production profile. | Refresh public-trust screenshots, run a production performance audit, rerun `pnpm a11y:check`, and retain the metrics artifact. |\n\nP1.5 performance checkpoint (July 28): all ten production cold-load traces pass\nthe agreed lab budgets. Explore mobile is the limiting LCP at `2,286 ms`, Pilot\ndesktop is the largest CLS at `0.0665`, and the representative interaction trace\nis `28 ms`. The route matrix and profile are retained in\n[`docs/ops/frontend-performance-baseline.md`](ops/frontend-performance-baseline.md).\nP1.5 remains open pending the mobile/desktop visual review and fresh axe run.\n\nStep 6 remediation (July 28): the fresh axe run passes `18/18`. The two Home\nblockers are fixed locally: the source band is now a normal full-width sibling\nof the padded content container, and V&A IIIF services are promoted to a\n1,200 px image derivative before thumbnail fallbacks. The repeated local\nproduction-build matrix passes all ten mobile/desktop traces with 0.00 CLS, a\nmaximum 1,628 ms LCP, and 29 ms INP; the 18-route axe gate also remains green.\nRepeat this matrix against the deployed revision to close P1.5.\n\nLinked Art 1.1 watch checkpoint (July 28): the standalone\n[`linked-art-1-1-agenda-impact-tracker.html`](../public/linked-art-1-1-agenda-impact-tracker.html)\nmaps all 26 August 5 agenda issues to current support, expected impact, required\nfixtures or schema changes, and pending community decisions. Update its decision\ncolumn and the canonical Linked Art reference ledger after the meeting before\nchanging validators or production mappings. Issue #637 now has an internal,\nprovenance-bearing\nconfirmed-negative reconciliation contract. It keeps curator-confirmed\nnon-matches separate from unresolved candidates and withholds Linked Art\nprojection until the community settles the property name and assertion pattern.\nIssue #362 now has a provisional internal response-profile contract. Its\nserver-defined brief projection preserves canonical identity, marks itself\nincomplete, and links deterministically to the full record; no new public\nprofile parameter is enabled before the community decision.\nThe pre-meeting implementation evidence packet now combines issues #362, #637,\nand #780 with executable references and decision questions. Use it during the\nAugust 5 discussion, then replace its pending questions with resolution links\nbefore promoting any candidate behavior.\nThe machine-readable meeting decision ledger covers all 26 agenda issues.\nAgenda proposals are recorded separately from outcomes; resolved rows require a\nmatching Linked Art issue URL, target release, and explicit local action before\nthey can drive post-meeting changes.\n\nThe Step 3 conformance pass now covers nine focused patterns under\n`tests/fixtures/linked-art-1.1/`: qualified `AttributeAssignment` ambiguity,\ninscribed `Name` evidence, `Name.created_by`, prototype-level provenance for an\nunenumerated `Set`, member-side Addition and Removal, Person Joining and\nLeaving, and auction selling/purchase separation.\nEndpoint-family inspection now preserves the active terms-ontology inverse links\n`added_member_by` and `removed_member_by`. The lifecycle fixture declares its\nextension context explicitly and stays non-normative until the 1.1 meeting\ndecision is recorded.\n\nThe compatibility pass is now executable through\n`LINKED_ART_1_1_COMPATIBILITY_BOUNDARY` and\n`tests/quality/linked-art-1-1-compatibility-boundary.test.ts`. The audit keeps\nsix representative pending property placements rejected, leaves proposed and\ndeferred classes outside the endpoint map, and documents the post-meeting\npromotion procedure in\n[`docs/linked-art/1.1-compatibility-audit.md`](linked-art/1.1-compatibility-audit.md).\n\nP1 exit gate: 30-day reliability and production KPI rows pass, one real paid\npilot reaches first value, and strict ActivityStreams evidence is either complete\nor explicitly waiting on a genuine upstream tombstone with all other rows fresh.\n\nJuly 27 checkpoint: the three accepted durable callback rows are restored and\n`pnpm activity:subscriptions:guard` passes `3/3`. Syndication remains honestly\nblocked only on a real `Delete` activity read.\n\nThe nightly Actions environment now supplies all three production consumer IDs\nto `activity:adoption:matrix`. Its production verification passed `12/12` feed\nprobes and resolved `3/3` declared consumers; `Delete` remains the sole missing\nobserved activity type.\n\nA write-enabled July 27 tombstone scan checked 68 canonical upstream targets\nacross 14 provider lanes with zero errors and found no genuine `404`/`410`.\nAccordingly, no `Delete` was minted; the scheduled scan must continue until a\nreal upstream removal can be observed and read by the three consumers.\n\nThe nightly workflow now runs the durable callback guard exactly once through\n`activity:syndication:evidence`; the redundant standalone guard step was removed\nwithout weakening its failure behavior.\n\nCollection and readiness now have separate Actions semantics. The nightly\nevidence workflow succeeds when probes and artifact generation work even if the\nrecorded status is red. The following `Era C Readiness Gate` workflow reports\nthose known external-evidence blockers without producing a failed scheduled job;\na manual dispatch remains fail-fast and owns strict Era C thresholds, durable\ncallback enforcement, and production launch review.\nThe Actions matrix now uses `actions/setup-node@v7`; execution-policy tests own\nthat major consistently, and runtime file metadata no longer depends on an\noverload-derived Node type that can become optional in newer type packages.\n\n### Public Discovery Product Track (Next, staged behind the P0 gate)\n\nGoal: turn Meta Museum's cross-provider data advantage into a welcoming public\nmuseum built around curiosity, storytelling, and repeat visits. The professional\nworkspace remains available, but it must no longer dominate the anonymous public\njourney. The defining promise is **connections no single museum website can\nshow**.\n\nThis track does not authorize a new provider, runtime dependency, or autonomous\npublishing path. Each phase ships behind the existing rights, provenance,\naccessibility, performance, citation, and human-review controls. Do not advance\nwhen the preceding phase's measured exit condition is red.\n\n| Phase | Outcome | Initial scope | Exit criteria | Verification |\n|---|---|---|---|---|\n| PD0 | Establish the public baseline and content boundary. | Record first-time task completion, artwork-to-artwork continuation, return visits, public-domain downloads, and share events. Define the minimum quality bar for public records: usable image, intelligible title/date, source, attribution, and resolved reuse message. | Baseline artifact exists; public and professional audiences, routes, vocabulary, and analytics events are explicitly separated; records below the quality bar cannot enter featured feeds. | Public-route inventory, analytics event contract, quality-filter fixtures, privacy review, and five non-specialist usability sessions. |\n| PD1 | Separate the public museum from the professional workspace. | Public navigation becomes Home, Explore, Stories, Connections, My Collection, and About. Evidence, APIs, agents, imports, annotations, org status, and operational controls move behind one clearly labeled “For museums and researchers” entry point. Rewrite the homepage in plain language around art and discovery. | A first-time visitor can explain the product and reach an artwork without encountering workspace status or specialist implementation language; professional routes remain directly reachable and unchanged in capability. | Mobile and desktop visual review, keyboard pass, `pnpm a11y:check`, public-navigation tests, and moderated five-second comprehension checks. |\n| PD2 | Ship the minimum delightful discovery loop. | Add `Surprise me`, a rights-safe Artwork of the Day with a stable dated URL, and public artwork pages led by image, essential facts, “Why this is interesting,” related works, and previous/next discovery. Collapse technical metadata and researcher feedback below the public story. | The complete loop works: entry point → artwork → short story → related discovery → another artwork. Featured records never have broken media or ambiguous reuse messaging. | Deterministic selection tests, record-quality tests, mobile/desktop E2E, share-preview checks, and measured artwork-to-artwork continuation. |\n| PD3 | Launch Connections as the signature feature. | Start with three evidence-backed types: the same subject across cultures, works made in the same period on different continents, and recurring symbols or materials across institutions. Label documented relationships separately from algorithmic suggestions and expose sources plus confidence. | At least three curated connection journeys span two or more providers, contain no unsupported causal claims, and pass human editorial review. Visitors can move from a work to a connection and into another institution's work. | Connection contract tests, citation completeness, confidence-label checks, curator review checklist, and journey E2E. |\n| PD4 | Add source-backed Stories and guided exploration. | Publish short image-led stories using reusable formats such as “One artwork, three details,” “Same year, different worlds,” “A disputed identity,” and “How an object changed hands.” Add exploration by subject, place, century, and color; add mood only as clearly labeled interpretation. Hide empty maps and timelines. | A minimum viable editorial cadence is sustainable; every factual claim resolves to a source; guided filters return useful results; empty analytical surfaces do not appear publicly. | Story-schema and citation tests, filter-quality samples, editorial review log, structured-data/share-card validation, and completion-rate measurement. |\n| PD5 | Make trustworthy reuse and participation useful. | Add public-domain image download with source, rights, attribution, and metadata. Add “What changed?” with plain-language record version comparisons. Allow local-first saved collections, then optional account sync and read-only sharing after demand is observed. | Downloads package correct rights context; record changes identify source, time, and change origin; a visitor can save and share a coherent collection without being forced to sign in first. | Rights/download fixtures, version-diff tests, local-storage and account-migration tests, privacy review, and collection share E2E. |\n| PD6 | Prove retention before expanding. | Evaluate artwork continuation, Surprise Me use, story completion, connection opens, downloads, collections created/shared, and 7-day return visits. Improve the strongest loop; retire or revise weak entry points. | Two consecutive measurement windows show a credible repeat-use signal and no regression in accessibility, performance, rights, or citation quality. Any further personalization or recommendation work has a measured hypothesis. | Analytics review, usability replay, public performance/a11y matrix, editorial quality audit, and a written continue/change/stop decision. |\n\nRecommended first release: **PD0 + PD1 + PD2 + three PD3 journeys**. It must\ndemonstrate one complete public loop:\n\n> Interesting entry point → beautiful artwork → understandable source-backed\n> story → unexpected cross-museum connection → another discovery → save or share.\n\nPublic discovery stop conditions: pause expansion if featured-record quality\ncannot be guaranteed, if connection evidence cannot support the displayed claim,\nif rights context is separated from a download, if public pages regress the\nagreed accessibility or performance budgets, or if measured use shows no\nimprovement after two iterations.\n\nPD1 implementation checkpoint (August 6): the primary public navigation is now\nHome, Explore, Stories, Connections, My Collection, About, and one quiet “For\nmuseums and researchers” entry. Anonymous Explore and artwork journeys no longer\nrender organization status or professional workspace chrome, and public Explore\nsuppresses import prompts, roadmap language, and provider implementation notes.\nThe homepage now leads with cross-museum discovery in plain language; dedicated\nStories, Connections, My Collection, and professional-workspace landing pages\nmake every navigation destination intentional. Automated navigation, homepage,\nworkspace-boundary, and Explore acceptance tests are green. The local production\nbuild passes, the 18-route accessibility matrix reports zero severe violations,\nand a 375 px browser review finds no horizontal overflow. A fresh deployed visual\nreview and non-specialist comprehension sessions remain PD1 evidence tasks rather\nthan reasons to reopen its implementation scope.\n\nPD2 implementation checkpoint (August 6): `/surprise` selects from the same\nimage-backed, publication-eligible local artwork pool as the homepage and sends\nvisitors directly into a public artwork journey. `/today` resolves to a stable\nUTC-dated `/today/YYYY-MM-DD` page whose selection is deterministic for that date.\nThe homepage exposes both entry points. Anonymous artwork pages now lead with\n“Why this is interesting,” keep facts and source detail in an expandable section,\noffer previous, next, Surprise Me, and related-artwork paths, and withhold\nresearcher annotations and operational relationship tools. Signed-in researchers\nretain the complete professional view. Selection and surface acceptance tests are\ngreen. The production build passes, the 18-route accessibility matrix reports\nzero severe violations, Surprise Me resolves into an eligible local artwork, and\nhomepage, daily, and artwork routes show no horizontal overflow at 375 px. A\ndeployed review remains necessary before promoting this local checkpoint to\nproduction proof.\n\nAugust 7 deployed checkpoint: PD1/PD2 is live on the production alias. The full\nserial test suite, lint, diagnostic typecheck, local and Vercel builds,\nproduction 18-route axe audit, 66-check crawler preview, 20/20 deployment\npreflight, public Explore smoke, repeated public-trust screenshot baseline, and\nzero-advisory dependency audit pass. Ten retained Lighthouse captures report\n100 accessibility and 0 CLS; the desktop routes pass the LCP budget, while the\nstricter Lighthouse mobile profile reports 3.7-5.9 second LCP and keeps P1.5\nopen for remediation and an agreed-profile recapture. The refreshed adoption\nmatrix passes 12/12 operator-run endpoint probes for all three named consumer\nIDs and remains blocked on genuine `Delete`. Those probes do not substitute for\nfresh reads made by the external consumers themselves: the retained declared\nconsumer reads are outside the 30-day adoption window, so Era C correctly\nreports `0/3`. Production preflight is 20/20 with zero deployment-environment\nfailures; the remaining launch-review blockers are time-bound SLO samples and\nreal-world adoption/KPI evidence.\n\nThe concrete production preflight is zero-failure on deployment\n`dpl_2WH2w1hrM4zftM84kn3ouU3xu4N4`. The broader `review:goals:local` roll-up now\nalso reports zero deployment-environment blockers: aggregate launch-review and\nEra C wrappers inherit real-world-evidence scope, while concrete preflight,\nauth, smoke, IIIF, and k6 failures remain deployment-scoped when present. The\nremaining 21 strict blockers are explicitly time-bound or human/external\nevidence rather than deployment configuration failures.\n\nAugust 7 PD0/PD3 checkpoint: the five public outcome events now have a typed,\nconsent-gated contract that excludes direct identifiers and professional\nroutes. First artwork completion, artwork continuation, 24-hour return,\nrights-qualified download selection, and successful share are instrumented.\nA dated baseline artifact and five-session non-specialist\nprotocol are present, while production observation and the five human sessions\nremain open. PD3 has exactly one curated journey—Flowers across two centuries—\nspanning Getty and Met records with citations, a high-confidence metadata\nlabel, an explicit no-influence boundary, contract tests, and an editorial\ndecision packet awaiting attributable human sign-off. Do not expand to three until this first\njourney is deployed and the measurement/editorial evidence is reviewed.\nAugust 8 cultural-intelligence checkpoint: the first journey now produces three\nsynchronized representations from one typed contract: a public visual story, a\nresearch dossier exposing fact/inference labels, method, uncertainties, rejected\nhypotheses, novelty status, and rights boundary, plus an evaluation-only JSON\nrecord with the same claim/citation graph and human-review state. Consent-gated\nstory-completion and reuse-interest signals are instrumented outside the five PD0\noutcomes. Institutional usefulness, agent/editorial minutes, independent novelty\nverification, five usability sessions, and attributable editorial approval remain\nexternal evidence gates; the one-journey expansion stop is unchanged.\nThe expansion gate is now executable through `pnpm connections:evidence`: its\nprivacy-safe artifact requires observed completion plus sharing/reuse, qualified\neditorial sign-off, institutional usefulness, agent/editorial labor and cost,\nindependent novelty review, a real price response, and the valid synchronized\nmachine record. It reports tested gross value before labor separately from labor\nminutes and cannot call that result profit. No real evidence has been imported,\nso expansion remains unauthorized.\nInternal hidden-pattern work can now proceed without violating that public gate:\n`pnpm connections:patterns` emits a review-only collection-intelligence report\nfrom normalized records plus explicit source rows. Deterministic candidates cover\nequivalent-record conflicts, possible entity reconciliation, shared materials,\nowner/custodian or set references, structured-provenance coverage gaps, and\ngeographic contrasts. Every lead carries citations, confidence, and a refusal\nboundary; uncited records are rejected and unsupported demographic or market\nconclusions are listed as refused analyses. No second public journey was added.\nThe review-only report now also consumes explicit Linked Art event evidence:\nmatching exhibition identifiers, `used_specific_object` groupings, structured\nacquisition/transfer parts, dated event places, and shared activity actors. Its\nevent graph preserves source-record IDs on every edge. Geographic sequences are\nmovement candidates rather than transport claims; ownership histories do not\nassert completeness, authenticity, custody, or legal title.\nAdditional explicit-evidence candidates now cover alternative maker assignments,\nreversed event timespans, repeated technique identifiers, separate `represents`\nand `about` iconographic concepts, and unidentified depicted people. Boundaries\nprevent authorship resolution, invented corrected dates, workshop/influence\nclaims, collapsed depiction semantics, or demographic/underrepresentation\ninference from these candidates.\nThe machine layer now also exposes `/api/cultural-intelligence` as a lifecycle-\naware collection feed. Each item preserves revision, production provenance,\nreview history, corrections, and separate editorial/licensing decisions. The\nfeed currently reports one evaluation item and zero licensable items; approval\nmetadata must be complete and all corrections resolved before eligibility can\nchange. Underlying source-record and media rights remain explicitly separate.\nFive derivative formats now compile from the same versioned claim graph:\nnewsletter, daily feed, narrated visual essay, classroom package, and licensed\narticle. Evidence sections preserve claim/citation IDs and all formats repeat the\nrights boundary. The derivative endpoint returns only an HTTP 409 release\nmanifest—not internal copy—while the first record lacks editorial and licensing\napproval. Format availability is therefore implemented but audience demand,\nquality, labor, accessibility, and price remain unproven external evidence.\nValue-based pricing now has an executable evidence ladder through\n`pnpm connections:pricing`: hypothesis, tested-no-signal, market signal, one\ninvoice-validated delivery, and repeatable price evidence. Repeatability requires\nthree scoped offers and two paid, accepted, value-confirmed, positive-contribution\ndeliveries across buyer segments. Labor is fully costed at an attributable rate;\ninterest is never revenue. No real offer artifact exists yet, so pricing remains\nunvalidated.\nThe `pd0:evidence` intake command now validates a real GA4 export and moderated\nsession records, rejects direct identifiers or invented counts, and derives\ncompletion only from five sessions plus attributable product-owner approval.\nIts package namespace, script, artifact directory, and product-governance owner\nare registered in the executable evidence-ownership and operations-risk controls.\nResponsive browser review found the initial action block below the full image on\nmobile; it now precedes the image and remains overflow-free at 390 px and 1440 px.\nThe Vercel ignore contract excludes local provider source mirrors, the `.tools`\nbinary cache, and the upstream `linked.art` checkout except its required schema\nsubtree. However, deployment `dpl_GiNFmNpo2UZs4uGEm4Y3B54Bya3b` still archived\n79,077 files (669.1 MB), so CLI archive filtering remains an open packaging\noptimization; the deploy itself completed and passed its runtime build.\n\n### P2 - Productize Only After The Pilot Loop Works (Later, 6-12 Weeks)\n\n| ID | Outcome | Trigger | Exit criteria |\n|---|---|---|---|\n| P2.1 | Guided organization onboarding and first-value dashboard. | One invoice-backed pilot completes activation and its friction is documented. | A new managed org can be provisioned with a sample or customer dataset in under 15 minutes; progress and first value are visible without engineering inspection. |\n| P2.2 | Repeatable subscriptions and usage visibility. | Pricing, support load, and gross margin are validated on at least one pilot. | Checkout or invoice-backed subscription sync, webhook/audit evidence, quotas, usage, billing state, cancellation reason, and customer portal are supportable. |\n| P2.3 | Institution procurement package. | A buyer starts security/legal review. | Deployment-specific subprocessors, DPA/legal artifacts, access review, incident drill, retention controls, backup/restore proof, status reporting, and SLA/SLO packet are buyer-reviewable. |\n| P2.4 | Production agent bridge decision. | A named operator accepts the review workload and risk boundary. | AG2 bridge has explicit sign-off, eval evidence, rollback, auditability, and human-publication approval. A2A/AG-UI remain deferred. |\n\n---\n\n## Readiness Scorecards\n\n### Launch Readiness\n\n| Lane | Score | Decision | Next evidence |\n|---|---:|---|---|\n| Internal development and portfolio demo | 9.0/10 | Safe to use and present with the strict-readiness caveat. | Reproduce the canonical local gate and resolve the public evidence inconsistencies. |\n| Controlled public beta | 8.4/10 | Technically credible on Vercel + Neon, but the formal beta gate remains evidence-red. | Clear P0, then maintain narrow acceptance criteria while the 30-day window accumulates. |\n| General public production | 6.5/10 | Do not claim complete readiness. | Passing long-window SLO/uptime, production KPI, and coherent launch evidence. |\n| Institution-grade / strict 10/10 | 5.5-6.0/10 | Blocked by external and time-based proof. | `pnpm review:goals:check` passes with no production-proof blockers. |\n\n### SaaS Readiness\n\n| Lane | Score | Decision | Next evidence |\n|---|---:|---|---|\n| Technical SaaS foundation | 7.0/10 | Strong enough for concierge pilots. | Prove onboarding, support load, usage, and tenant operations with one buyer. |\n| Paid pilot readiness | 8.2/10 | The offer and operator path are ready; revenue proof is not. | Reply or qualified follow-up, signed scope, invoice-backed entitlement, real activation. |\n| Self-serve SaaS readiness | 3.0/10 | Deferred. | Start only after the pilot validates pricing and activation friction. |\n| Profitable SaaS business | 4/10 | Credible wedge, but repeatable revenue is not proven yet. | Retention, support minutes, infrastructure cost, conversion, and gross-margin evidence. |\n\nThe primary wedge remains the **Managed Linked Art Launch Pilot** for small and\nmid-size museums, archives, galleries, digital-humanities labs, and artist estates\nthat need standards-compliant collection publication without a semantic-web team.\nManual invoicing is correct for the first 1-3 pilots. Creator-side provenance and\nself-serve billing stay deferred until the B2B pilot loop produces evidence.\n\n---\n\n## Evidence Workstreams\n\n| Workstream | Current state | Completion condition |\n|---|---|---|\n| Local quality | Review-goals local status passes and direct ESLint passes; full canonical reproducibility was not demonstrated in the July 12 audit. | P0.2 is green from a clean generated state. |\n| Deployment | Preflight `20/20`, both Render probes, all public smokes, and deployed k6 pass; launch review is `7/8`. The strict handoff has zero deployment-environment blockers because its remaining launch and Era C wrappers depend only on real-world evidence. | Preserve the green concrete deployment matrix while the real-world evidence windows mature. |\n| Long-window SLO and uptime | The latest strict handoff reports `11` retained deployed SLO samples across `10/30` distinct UTC days, with `11` passing samples and no failed or incomplete rows in the active report window; the Era C artifact still reports only `15/30` samples toward its exit gate. | Continue distinct-day collection until the complete 30-day threshold is genuinely met. |\n| ActivityStreams | Operator endpoint probes pass for three named IDs, but the retained real external consumer evidence is stale and therefore counts as `0/3`; genuine `Delete` evidence is pending. | Collect three fresh real external consumers covering `Create`, `Update`, and `Delete`, with verified callbacks. |\n| Production KPI | Local enrichment is promising; production reconciliation distribution and reviewed precision are incomplete. | P1.2 passes the SOTA KPI acceptance rows from named production sources. |\n| Managed pilot | The offer, runbook, entitlement, activation, support, and evidence tooling exist. The latest no-pricing buyer pack is specific to the recorded Te Papa outreach and has a real account, organization, and owner, but no paid-pilot tenant or invoice-backed entitlement exists. | Obtain a real buyer reply plus signed scope or invoice reference, provision the tenant, then use P1.3 tooling to record activation, retention, support load, and margin evidence. |\n\nThe buyer-review surface now includes a standalone ten-record demonstration at\n`/museum-linked-art-pilot-demonstration.html`. It uses traceable public API records\nto show source preservation, event-centric Linked Art JSON-LD, rights review\nboundaries, validation findings, and museum questions. It proves a review pattern,\nnot a completed customer engagement or permission to reuse source images.\n\nA one-page buyer brief at `/managed-linked-art-pilot-brief.html` now packages the\nproblem, five-day process, required inputs, deliverables, privacy and security\nboundaries, and post-pilot decision into a printable pre-call handout. It links to\nthe ten-record demonstration and preserves the same evaluation-only claim boundary.\n\nThe first-call workflow now has a timed guide at\n`/museum-pilot-discovery-call-guide.html`: a one-minute permission-based opening,\nfive fit questions, a boundary recap, three explicit decision paths, and a\nfollow-up record. The call qualifies a bounded pilot before any product tour and\nlinks directly to the buyer brief and demonstration when supporting proof is useful.\n\nThe post-call handoff now has a public-data request at\n`/museum-pilot-data-request-template.html`. It supplies a copy-ready museum message,\naccepts CSV, JSON, XML, LIDO, or a public API, distinguishes minimum from optional\nfields, excludes credentials and restricted material, and records the reviewer,\npublication boundary, transfer method, receipt evidence, and agreed deletion date.\n\nThe conversion and delivery packet now adds a counsel-review sample agreement,\nfour-level introductory pricing, and a reusable results report. The public pilot\noffer uses the same `$0` evaluation, `$3,500` fixed paid pilot, implementation from\n`$12,000`, and ongoing service from `$1,250` monthly hypothesis, so buyer surfaces\nno longer conflict. These remain unvalidated prices until invoice-backed delivery,\nacceptance, retention, and gross-margin evidence exists.\n\nThe refined demonstration presents one primary path on desktop and mobile:\ncollection record, Linked Art mapping, validation, then reviewable result. Source\nevidence is collapsed beneath the interaction, and the final state names open\nmuseum decisions and the human publication gate.\n\nThe current outreach ledger records the eight user-confirmed August 5 submissions,\ntheir real recipient or form channel, zero assumed replies, and August 12 follow-up\ndates. `docs/sales/museum-outreach-pipeline.md` contains eight unsent follow-up\ndrafts plus a second official-source-researched group of eight prospects that must\nremain `research_only` until first-round feedback is reviewed and sending is\nauthorized. `docs/ops/paid-pilot-commercial-evidence-process.md` closes the\ninvoice-to-margin capture design without treating placeholders as proof.\n\n### Standing Evidence Controls\n\n- **Public docs metadata freshness:** `/api/docs/manifest` must keep response\n  `generatedAt` separate from source `sourceUpdatedAt` and `sourceUpdatedDoc`\n  checksum metadata.\n- **ActivityStreams onboarding ledger:** partner rows must keep\n  `wikidataexplorer-metamuseum-prod` and the other real consumers distinct,\n  retain durable callback evidence, and preserve the zero rejected subscriptions\n  state without allowing placeholders to satisfy strict proof.\n- **Performance evidence:** the cold-record budget, 30-day SLO depth, and\n  `pnpm longterm:evidence:public` output remain strict gates; a frontend Core Web\n  Vitals baseline is added in P1.5 rather than inferred from API SLO evidence.\n- **Claim boundary:** local success, deployment success, and real-world success\n  remain separate scopes. No aggregate badge may silently promote one scope into\n  another.\n\n---\n\n## Product And Engineering Guardrails\n\n1. Linked Art JSON-LD remains canonical; UI DTOs are projections at boundaries.\n2. Preserve rights, source attribution, provenance, multi-value arrays, event\n   semantics, carrier/content/surrogate separation, and opaque URI handling.\n3. Adapters do not import each other; provider parsing stays in adapters;\n   cross-provider mapping stays in `src/utils/artwork-builder.ts`; contracts remain\n   leaf modules.\n4. AIDD + TDD remains mandatory for behavior changes. Standards-critical work\n   cites reference rounds and fixture anchors before implementation.\n5. Public publication and agent-generated claims require citations, refusal paths,\n   audit evidence, and human approval.\n6. Keep Next.js, React, TypeScript, custom CSS, Postgres/JSONB, Solr, GraphDB, and\n   canonical ID decisions locked as documented in [CLAUDE.md](../CLAUDE.md).\n7. No new runtime dependency, provider, service, database, or architecture era is\n   started while P0 is red without explicit approval.\n\n### Deliberately Deferred\n\n- New provider integrations beyond the current 14 production lanes.\n- Self-serve signup, checkout, billing portal, and growth automation before pilot\n  economics and activation are real.\n- Synthetic ActivityStreams `Delete` evidence.\n- Broad production agent autonomy or public publishing without operator sign-off.\n- A microservice, triple-store, vector-store, or framework expansion not justified\n  by measured scale or customer evidence.\n\n---\n\n## Cadence And Ownership\n\n| Cadence | Required action |\n|---|---|\n| Every behavior change | Red-green-refactor tests, focused smoke/evidence, README + roadmap update, and `pnpm session:closeout`. |\n| Every 72 hours during active shipping | Canonical local gate plus fresh P0 evidence checks. Stop expansion when a required gate is missing. |\n| Weekly | Refresh long-window evidence, inspect failed-sample age-out dates, review pilot pipeline, and update only changed roadmap decisions. |\n| Monthly or before a buyer review | Refresh production preflight, launch evidence/review, procurement packet, access/DR evidence, and the strict handoff. |\n\nThe roadmap records current decisions and measurable outcomes, not every merged\nchange. Completed implementation detail belongs in\n[progress/era-history.md](progress/era-history.md), specialized docs, generated\nartifacts, and git history.\n\n---\n\n## History And References\n\n- [progress/era-history.md](progress/era-history.md): full Era A, B, and C slice\n  history, including the milestones consumed by `/api/roadmap`.\n- [roadmap-to-10.md](roadmap-to-10.md): executable strict-readiness checklist and\n  artifact handoff.\n- [risk-register.md](risk-register.md): open engineering and operating risks.\n- [ops/review-goals.md](ops/review-goals.md): review-goals policy and command\n  contract.\n- [ops/evidence-script-ownership.md](ops/evidence-script-ownership.md): evidence\n  command ownership and preferred entry points.\n- [linked-art/LinkedArtModel1.0-Reference.md](linked-art/LinkedArtModel1.0-Reference.md):\n  standards rounds and fixture anchors.\n- [linked-art/LinkedArtSOTAWebApp.md](linked-art/LinkedArtSOTAWebApp.md): target\n  architecture and SOTA acceptance criteria.\n","sections":[{"level":2,"heading":"Status (as of August 6, 2026)","anchor":"status-as-of-august-6-2026"},{"level":3,"heading":"Executive Assessment","anchor":"executive-assessment"},{"level":3,"heading":"Readiness Boundary","anchor":"readiness-boundary"},{"level":3,"heading":"Evaluation Findings That Change Priority","anchor":"evaluation-findings-that-change-priority"},{"level":2,"heading":"Priority Plan","anchor":"priority-plan"},{"level":3,"heading":"P0 - Restore A Trustworthy Baseline (Now, 0-7 Days)","anchor":"p0-restore-a-trustworthy-baseline-now-0-7-days"},{"level":3,"heading":"P1 - Convert Reliability And Demand Into Proof (Next, 1-6 Weeks)","anchor":"p1-convert-reliability-and-demand-into-proof-next-1-6-weeks"},{"level":3,"heading":"Public Discovery Product Track (Next, staged behind the P0 gate)","anchor":"public-discovery-product-track-next-staged-behind-the-p0-gate"},{"level":3,"heading":"P2 - Productize Only After The Pilot Loop Works (Later, 6-12 Weeks)","anchor":"p2-productize-only-after-the-pilot-loop-works-later-6-12-weeks"},{"level":2,"heading":"Readiness Scorecards","anchor":"readiness-scorecards"},{"level":3,"heading":"Launch Readiness","anchor":"launch-readiness"},{"level":3,"heading":"SaaS Readiness","anchor":"saas-readiness"},{"level":2,"heading":"Evidence Workstreams","anchor":"evidence-workstreams"},{"level":3,"heading":"Standing Evidence Controls","anchor":"standing-evidence-controls"},{"level":2,"heading":"Product And Engineering Guardrails","anchor":"product-and-engineering-guardrails"},{"level":3,"heading":"Deliberately Deferred","anchor":"deliberately-deferred"},{"level":2,"heading":"Cadence And Ownership","anchor":"cadence-and-ownership"},{"level":2,"heading":"History And References","anchor":"history-and-references"}],"html":"<h1 id=\"meta-museum-roadmap\">Meta Museum Roadmap</h1>\n<p>This is the current, authoritative execution plan. It supersedes</p>\n<p>development-roadmap.md(development-roadmap.md), which is retained as the legacy</p>\n<p>pre-Next.js plan. Completed slice history lives in</p>\n<p>progress/era-history.md(progress/era-history.md); the strict evidence checklist</p>\n<p>lives in roadmap-to-10.md(roadmap-to-10.md); open engineering risks live in</p>\n<p>risk-register.md(risk-register.md).</p>\n<p>The architecture north star is</p>\n<p>linked-art/LinkedArtSOTAWebApp.md(linked-art/LinkedArtSOTAWebApp.md). Provider,</p>\n<p>schema, protocol, and validation work must map tests to fixture anchors in</p>\n<p>linked-art/LinkedArtModel1.0-Reference.md(linked-art/LinkedArtModel1.0-Reference.md).</p>\n<p>This document owns sequencing and stop/go decisions.</p>\n<p>---</p>\n<h2 id=\"status-as-of-august-6-2026\">Status (as of August 6, 2026)</h2>\n<p>&lt;!-- BEGIN:PROJECT_STATS --&gt;</p>\n<p>&lt;!-- Generated by `pnpm docs:stats`; do not edit by hand. --&gt;</p>\n<p>| Generated project stats | Current value |</p>\n<p>|---|---|</p>\n<p>| Next.js | `16.2.12` |</p>\n<p>| React | `19.2.4` |</p>\n<p>| App page files | root homepage + `41` non-root page files (`42` total) |</p>\n<p>| API route handlers | `149` `app/api` route handlers |</p>\n<p>&lt;!-- END:PROJECT_STATS --&gt;</p>\n<h3 id=\"executive-assessment\">Executive Assessment</h3>\n<p>Meta Museum is a strong, unusually complete Linked Art product and a credible</p>\n<p>controlled-beta system. It is not yet defensible as institution-grade or</p>\n<p>repeatable SaaS. The gap is mostly evidence quality, operational history, and</p>\n<p>commercial proof rather than missing core product breadth.</p>\n<p>| Category | Score | Evidence-based assessment | Immediate implication |</p>\n<p>|---|---:|---|---|</p>\n<p>| Product experience | 6.5/10 for the public; 8.2/10 for museum and research users | The source-backed professional journeys are coherent, but public discovery still exposes workspace language, operational controls, and specialist navigation before establishing a reason to explore or return. | Separate the public museum from the professional workspace and build one curiosity-led discovery loop before adding more platform breadth. |</p>\n<p>| Linked Art and data semantics | 9.0/10 | Canonical JSON-LD, event-centric modeling, rights, provenance, equivalent identities, HAL relations, IIIF, and provider boundaries are deeply implemented and test-backed. | Sustain conformance; do not add another provider until readiness work clears. |</p>\n<p>| Evaluator and trust story | 8.4/10 | `/projects`, `/evidence`, `/datasets`, `/docs`, and machine-readable APIs make the work inspectable. The public evidence ledger currently mixes contradictory artifact baselines. | Repair proof consistency before adding more evaluator copy. |</p>\n<p>| Accessibility | 9.3/10 | `pnpm a11y:check` passed 18 routes with 0 violations on July 12. Auth redirects for protected routes were handled as expected. | Keep zero severe violations and add accessibility checks to any hero or navigation polish. |</p>\n<p>| Engineering architecture | 8.0/10 | Boundaries, contracts, strict TypeScript, storage abstractions, tests, and evidence automation are mature. The route and script surface is large and operationally expensive. | Prefer consolidation and owner clarity over new surface area. |</p>\n<p>| Reproducible local quality gate | 6.5/10 | Direct ESLint passed and the local review-goals gate passed, but the audit began with a stale closeout guard, direct TypeScript failed in generated `.next/dev/types/validator.ts`, and a direct full test run did not finish within 10 minutes. | Re-establish one clean, repeatable canonical gate before feature work. |</p>\n<p>| Documentation and governance | 8.5/10 | The docs surface is rich, agent-readable, and guarded for drift. The previous roadmap had become a completion ledger rather than a decision document. | Keep this file current and concise; send completed detail to history. |</p>\n<p>| Operational readiness | 6.0/10 | Production preflight is 20/20 and launch review is 7/8, but long-window SLO, uptime, KPI, and artifact-coherence proof remain red. | Clear deploy-environment proof, then let time-based evidence accumulate without manufacturing results. |</p>\n<p>| SaaS and business readiness | 5.5/10 | The managed pilot offer and tenant-aware technical foundation are credible. There is no invoice-backed pilot, repeatable onboarding, retention, or margin proof. | Sell and execute one bounded concierge pilot before building self-serve billing. |</p>\n<p>Overall decision: **8.1/10 as a local product and portfolio case study; 5.8/10</p>\n<p>for strict public-production readiness.** The project is safe to keep demoing and</p>\n<p>iterating. Broad institution-grade or profitable-SaaS claims remain blocked.</p>\n<p>The July 21 live review confirmed that the primary public journeys render without</p>\n<p>browser console errors. The same review found that `pnpm typecheck:diagnostic`</p>\n<p>failed in test contracts and fixtures. Those type errors are now repaired:</p>\n<p>`pnpm typecheck:diagnostic`, 59 focused tests, `pnpm lint`, and `pnpm build` pass.</p>\n<p>The full serial `pnpm test` run completed `1,677/1,677` tests in `157.5s` on</p>\n<p>July 28 after stale deployment-preflight and documentation-contract expectations</p>\n<p>were aligned with canonical evidence. `pnpm review:goals:check`</p>\n<p>now reports `21` production-proof blockers (`0` local-refresh, `0`</p>\n<p>deployment-environment, and `21` real-world-evidence). Completing the canonical</p>\n<p>local test run is no longer a P0 blocker.</p>\n<p>The July 28 timeout investigation confirmed `1,704/1,704` tests pass in 154</p>\n<p>seconds with a compact reporter. The canonical test script now uses that</p>\n<p>reporter to prevent captured verbose output from stalling the command channel.</p>\n<p>August 5 quality-gate refresh: P0.2 is green again after the 24-hour closeout</p>\n<p>guard expired. Lint passed in `19.3s`, diagnostic TypeScript in `5.4s`, the full</p>\n<p>serial suite in `150.4s`, and the Next.js production build in `50s`. The repair</p>\n<p>keeps intentionally untracked `data/source-repos` mirrors out of tracked-text</p>\n<p>drift scans and anchors synthetic SLO samples to each evaluation timestamp so</p>\n<p>the gate remains reproducible after the original June fixture window. The three</p>\n<p>new standalone evaluator briefings are preserved in the same clean worktree.</p>\n<p>The architecture evaluation briefing now marks the canonical-gate risk closed</p>\n<p>and carries these measured results instead of its earlier stale warning.</p>\n<h3 id=\"readiness-boundary\">Readiness Boundary</h3>\n<p>  reports `status: external-evidence-required`, `local gate status: passed`, and</p>\n<p>  `strict 10/10 gate status: failed`.</p>\n<p>  launch review passes `7/8`, with the launch-review Era C dependency still red.</p>\n<p>  paid-pilot proof, retention, and gross-margin evidence.</p>\n<ul><li>[ ] <strong>Strict 10/10 readiness is not green yet</strong>: `pnpm review:goals:check`</li><li>[x] The July 10 production deployment preflight passes `20/20`; the latest</li><li>[x] The latest strict handoff reports `0` local-refresh, `0` deployment-environment, and `21` real-world-evidence blockers, or `21` production-proof blockers in total.</li><li>[x] The evidence ledger, readiness dashboard, Era C, long-term, launch-review, and review-goals artifacts now share the same canonical blocker, SLO, uptime, and ActivityStreams values.</li><li>[ ] Remaining strict proof includes 30-day SLO/uptime evidence, production KPI exports, durable ActivityStreams syndication including a genuine `Delete`,</li><li>[x] Current launch status is governed by `pnpm review:goals:check`.</li><li>[x] `pnpm review:goals:check` must be green before broad public SaaS claims.</li></ul>\n<p>The allowed claim is: **local gates pass and strong external proof exists; strict</p>\n<p>10/10 production readiness remains blocked by external evidence.**</p>\n<h3 id=\"evaluation-findings-that-change-priority\">Evaluation Findings That Change Priority</h3>\n<ol><li><strong>Public evidence consistency is repaired and regression-guarded.</strong> The</li></ol>\n<p>   canonical handoff, README, roadmap, and live ledger now agree on `21 = 0 + 3</p>\n<p>   + 18` strict blockers. The ledger also reconciles partner confirmations with</p>\n<p>   generated ActivityStreams evidence, so its pending Delete row cannot repeat</p>\n<p>   confirmed `Create` or `Update` types as missing.</p>\n<ol><li><strong>The local gate is not yet reproducible from one clean command sequence.</strong></li></ol>\n<p>   The closeout guard, a malformed generated Next dev validator, and a long-running</p>\n<p>   direct test invocation obscure whether a fresh checkout is truly green.</p>\n<ol><li><strong>The product breadth is sufficient.</strong> Fourteen provider lanes, 34 pages, 146</li></ol>\n<p>   API routes, public docs, validation, reconciliation, ActivityStreams, IIIF,</p>\n<p>   agent review, and tenant-aware pilot controls are enough for the next learning</p>\n<p>   cycle. More breadth would dilute the evidence and customer work.</p>\n<ol><li><strong>The next product-polish gain is quality, not more sections.</strong> The current</li></ol>\n<p>   hero can enlarge a low-resolution source image, while Core Web Vitals and</p>\n<p>   primary-journey performance do not yet have a concise public baseline.</p>\n<ol><li><strong>The public product needs a distinct reason to return.</strong> Cross-provider search</li></ol>\n<p>   is useful, but it does not yet turn the underlying data advantage into stories,</p>\n<p>   surprising discoveries, personal collections, or connections that no single</p>\n<p>   museum site can show.</p>\n<p>---</p>\n<h2 id=\"priority-plan\">Priority Plan</h2>\n<p>Priority is determined by trust and dependency, not by implementation novelty.</p>\n<p>Do not start a lower tier while an actionable higher-tier exit condition is red.</p>\n<p>Time-bound external evidence may continue accumulating in parallel.</p>\n<h3 id=\"p0-restore-a-trustworthy-baseline-now-0-7-days\">P0 - Restore A Trustworthy Baseline (Now, 0-7 Days)</h3>\n<p>| ID | Outcome | Owner | Exit criteria | Verification |</p>\n<p>|---|---|---|---|---|</p>\n<p>| P0.1 | Keep public readiness evidence internally consistent. | Platform + Evidence | `/api/evidence/ledger`, `/evidence`, `/readiness`, review-goals, launch review, and the long-term artifacts agree on SLO sample/day counts, uptime, ActivityStreams observed/missing types, and current blocker scope. Fallbacks disclose missing artifacts instead of substituting incompatible values. | `tests/services/readiness-evidence-consistency.test.ts`; focused evidence-ledger, readiness, review-goals, and documentation-drift tests; `pnpm evidence:ledger:probe:check`. |</p>\n<p>| P0.2 | Restore one clean local quality gate. | Platform | From a fresh generated state, `pnpm session:closeout:check`, `pnpm lint`, `pnpm test`, `pnpm build`, and `pnpm typecheck:diagnostic` all complete successfully. The generated `app/api/vanda/search/route.js` validator fragment is valid after regeneration, and test duration is recorded. | Run the five canonical commands and attach elapsed time plus the first failing test if any. |</p>\n<p>| P0.3 | Clear deployment-environment proof drift. | Operations | Rerun production preflight, launch evidence, launch review, and public Era C evidence with production environment present; reduce the deployment-environment lane from `4` blockers to `0` without changing the real-world claim boundary. | `pnpm launch:preflight:production`; `pnpm launch:evidence:production`; `pnpm launch:review:production`; `pnpm era-c:exit-gate:public`; `pnpm review:goals:check`. |</p>\n<p>| P0.4 | Preserve nightly k6 evidence artifacts. | Platform + Evidence | The Docker fallback writes `artifacts/performance/k6-slo-summary.json` as the host runner user, deletes stale summaries before each run, and fails when no fresh summary is produced. | `pnpm exec tsx --test tests/scripts/k6-slo-runner.test.ts`; confirm the next Era C workflow ingests one fresh SLO sample. |</p>\n<p>Production database SSL drift was repaired on July 27: Vercel now uses the</p>\n<p>existing `sslmode=verify-full` connection value, the production artifact was</p>\n<p>redeployed, and `/api/ai/query` returned `200` through the public alias.</p>\n<p>P0 exit gate: all local commands are reproducibly green, public evidence has no</p>\n<p>cross-surface contradictions, and deployment-environment blockers are zero.</p>\n<h3 id=\"p1-convert-reliability-and-demand-into-proof-next-1-6-weeks\">P1 - Convert Reliability And Demand Into Proof (Next, 1-6 Weeks)</h3>\n<p>| ID | Outcome | Owner | Exit criteria | Verification |</p>\n<p>|---|---|---|---|---|</p>\n<p>| P1.1 | Complete the 30-day reliability window. | Operations | One canonical source reports 30 distinct UTC days of complete passing deployed SLO samples, including the cold-record scenario, and at least 99.9% public-read uptime with failed rows aged out of the retained window. | Scheduled probes plus `pnpm longterm:evidence:public` and `pnpm era-c:exit-gate:public`. |</p>\n<p>| P1.2 | Produce real SOTA KPI evidence. | Data + Curation | Production/Postgres or warehouse exports meet the reconciliation auto-approve and reviewed-precision thresholds; every capture row identifies its production source. | `pnpm monitoring:kpi-evidence:production`; `pnpm era-c:exit-gate:public`. |</p>\n<p>| P1.3 | Close one invoice-backed managed pilot. | Founder + Product | One real buyer has a signed scope and invoice reference, one collection is activated within seven days, and support, required KPI, retention, and gross-margin rows are captured without placeholders. | `pnpm pilot:buyer-pack`; `pnpm pilot:activation`; `pnpm pilot:support`; `pnpm pilot:kpi`; `pnpm pilot:evidence --check`. |</p>\n<p>The architecture evaluator now participates in the commercial pre-revenue claim control: it must disclose the absent invoice-backed pilot, remain `External evidence required`, and point to `pnpm pilot:buyer-pack` plus the tenant-scoped `pnpm pilot:evidence --check` acceptance gate. This improves the handoff but does not count outreach or local tooling as revenue proof.</p>\n<p>August 5 ownership and operator-experience pass: the compact public mobile header and product-specific agent sign-in context are implemented and regression-tested. The operations-risk report now covers `35/35` page routes across `7` ownership/consolidation lanes alongside `61/61` API families and fully classified package-script namespaces. `pnpm ops:profile` makes the Next.js + Postgres portable baseline explicit and keeps Python services, AG2, Solr, GraphDB, and publication workers optional until their readiness gates justify enablement. The evaluator marks mobile and authentication closed while keeping broad surface area and specialist topology honestly managed rather than eliminated.</p>\n<p>| P1.4 | Preserve honest ActivityStreams adoption. | Platform + Partnerships | Keep `3/3` real external consumers, `3/3` verified durable callbacks, and zero rejected subscriptions fresh. Add `Delete` only after a genuine upstream `404`/`410` tombstone and partner read; never synthesize it to satisfy the gate. | `pnpm providers:coverage:seed`; `pnpm activity:tombstone:scan`; `pnpm activity:subscriptions:guard`; `pnpm activity:syndication:evidence`. |</p>\n<p>| P1.5 | Raise visible product quality and establish a performance baseline. | Product + Frontend | Home, Explore, one artwork detail, Projects, and Pilot pass mobile/desktop visual review; no hero image is rendered above a defensible intrinsic size; no text overlaps; LCP &lt;= 2.5 s, CLS &lt;= 0.1, and INP &lt;= 200 ms on the agreed production profile. | Refresh public-trust screenshots, run a production performance audit, rerun `pnpm a11y:check`, and retain the metrics artifact. |</p>\n<p>P1.5 performance checkpoint (July 28): all ten production cold-load traces pass</p>\n<p>the agreed lab budgets. Explore mobile is the limiting LCP at `2,286 ms`, Pilot</p>\n<p>desktop is the largest CLS at `0.0665`, and the representative interaction trace</p>\n<p>is `28 ms`. The route matrix and profile are retained in</p>\n<p>`docs/ops/frontend-performance-baseline.md`(ops/frontend-performance-baseline.md).</p>\n<p>P1.5 remains open pending the mobile/desktop visual review and fresh axe run.</p>\n<p>Step 6 remediation (July 28): the fresh axe run passes `18/18`. The two Home</p>\n<p>blockers are fixed locally: the source band is now a normal full-width sibling</p>\n<p>of the padded content container, and V&amp;A IIIF services are promoted to a</p>\n<p>1,200 px image derivative before thumbnail fallbacks. The repeated local</p>\n<p>production-build matrix passes all ten mobile/desktop traces with 0.00 CLS, a</p>\n<p>maximum 1,628 ms LCP, and 29 ms INP; the 18-route axe gate also remains green.</p>\n<p>Repeat this matrix against the deployed revision to close P1.5.</p>\n<p>Linked Art 1.1 watch checkpoint (July 28): the standalone</p>\n<p>`linked-art-1-1-agenda-impact-tracker.html`(../public/linked-art-1-1-agenda-impact-tracker.html)</p>\n<p>maps all 26 August 5 agenda issues to current support, expected impact, required</p>\n<p>fixtures or schema changes, and pending community decisions. Update its decision</p>\n<p>column and the canonical Linked Art reference ledger after the meeting before</p>\n<p>changing validators or production mappings. Issue #637 now has an internal,</p>\n<p>provenance-bearing</p>\n<p>confirmed-negative reconciliation contract. It keeps curator-confirmed</p>\n<p>non-matches separate from unresolved candidates and withholds Linked Art</p>\n<p>projection until the community settles the property name and assertion pattern.</p>\n<p>Issue #362 now has a provisional internal response-profile contract. Its</p>\n<p>server-defined brief projection preserves canonical identity, marks itself</p>\n<p>incomplete, and links deterministically to the full record; no new public</p>\n<p>profile parameter is enabled before the community decision.</p>\n<p>The pre-meeting implementation evidence packet now combines issues #362, #637,</p>\n<p>and #780 with executable references and decision questions. Use it during the</p>\n<p>August 5 discussion, then replace its pending questions with resolution links</p>\n<p>before promoting any candidate behavior.</p>\n<p>The machine-readable meeting decision ledger covers all 26 agenda issues.</p>\n<p>Agenda proposals are recorded separately from outcomes; resolved rows require a</p>\n<p>matching Linked Art issue URL, target release, and explicit local action before</p>\n<p>they can drive post-meeting changes.</p>\n<p>The Step 3 conformance pass now covers nine focused patterns under</p>\n<p>`tests/fixtures/linked-art-1.1/`: qualified `AttributeAssignment` ambiguity,</p>\n<p>inscribed `Name` evidence, `Name.created_by`, prototype-level provenance for an</p>\n<p>unenumerated `Set`, member-side Addition and Removal, Person Joining and</p>\n<p>Leaving, and auction selling/purchase separation.</p>\n<p>Endpoint-family inspection now preserves the active terms-ontology inverse links</p>\n<p>`added_member_by` and `removed_member_by`. The lifecycle fixture declares its</p>\n<p>extension context explicitly and stays non-normative until the 1.1 meeting</p>\n<p>decision is recorded.</p>\n<p>The compatibility pass is now executable through</p>\n<p>`LINKED_ART_1_1_COMPATIBILITY_BOUNDARY` and</p>\n<p>`tests/quality/linked-art-1-1-compatibility-boundary.test.ts`. The audit keeps</p>\n<p>six representative pending property placements rejected, leaves proposed and</p>\n<p>deferred classes outside the endpoint map, and documents the post-meeting</p>\n<p>promotion procedure in</p>\n<p>`docs/linked-art/1.1-compatibility-audit.md`(linked-art/1.1-compatibility-audit.md).</p>\n<p>P1 exit gate: 30-day reliability and production KPI rows pass, one real paid</p>\n<p>pilot reaches first value, and strict ActivityStreams evidence is either complete</p>\n<p>or explicitly waiting on a genuine upstream tombstone with all other rows fresh.</p>\n<p>July 27 checkpoint: the three accepted durable callback rows are restored and</p>\n<p>`pnpm activity:subscriptions:guard` passes `3/3`. Syndication remains honestly</p>\n<p>blocked only on a real `Delete` activity read.</p>\n<p>The nightly Actions environment now supplies all three production consumer IDs</p>\n<p>to `activity:adoption:matrix`. Its production verification passed `12/12` feed</p>\n<p>probes and resolved `3/3` declared consumers; `Delete` remains the sole missing</p>\n<p>observed activity type.</p>\n<p>A write-enabled July 27 tombstone scan checked 68 canonical upstream targets</p>\n<p>across 14 provider lanes with zero errors and found no genuine `404`/`410`.</p>\n<p>Accordingly, no `Delete` was minted; the scheduled scan must continue until a</p>\n<p>real upstream removal can be observed and read by the three consumers.</p>\n<p>The nightly workflow now runs the durable callback guard exactly once through</p>\n<p>`activity:syndication:evidence`; the redundant standalone guard step was removed</p>\n<p>without weakening its failure behavior.</p>\n<p>Collection and readiness now have separate Actions semantics. The nightly</p>\n<p>evidence workflow succeeds when probes and artifact generation work even if the</p>\n<p>recorded status is red. The following `Era C Readiness Gate` workflow reports</p>\n<p>those known external-evidence blockers without producing a failed scheduled job;</p>\n<p>a manual dispatch remains fail-fast and owns strict Era C thresholds, durable</p>\n<p>callback enforcement, and production launch review.</p>\n<p>The Actions matrix now uses `actions/setup-node@v7`; execution-policy tests own</p>\n<p>that major consistently, and runtime file metadata no longer depends on an</p>\n<p>overload-derived Node type that can become optional in newer type packages.</p>\n<h3 id=\"public-discovery-product-track-next-staged-behind-the-p0-gate\">Public Discovery Product Track (Next, staged behind the P0 gate)</h3>\n<p>Goal: turn Meta Museum&#39;s cross-provider data advantage into a welcoming public</p>\n<p>museum built around curiosity, storytelling, and repeat visits. The professional</p>\n<p>workspace remains available, but it must no longer dominate the anonymous public</p>\n<p>journey. The defining promise is **connections no single museum website can</p>\n<p>show**.</p>\n<p>This track does not authorize a new provider, runtime dependency, or autonomous</p>\n<p>publishing path. Each phase ships behind the existing rights, provenance,</p>\n<p>accessibility, performance, citation, and human-review controls. Do not advance</p>\n<p>when the preceding phase&#39;s measured exit condition is red.</p>\n<p>| Phase | Outcome | Initial scope | Exit criteria | Verification |</p>\n<p>|---|---|---|---|---|</p>\n<p>| PD0 | Establish the public baseline and content boundary. | Record first-time task completion, artwork-to-artwork continuation, return visits, public-domain downloads, and share events. Define the minimum quality bar for public records: usable image, intelligible title/date, source, attribution, and resolved reuse message. | Baseline artifact exists; public and professional audiences, routes, vocabulary, and analytics events are explicitly separated; records below the quality bar cannot enter featured feeds. | Public-route inventory, analytics event contract, quality-filter fixtures, privacy review, and five non-specialist usability sessions. |</p>\n<p>| PD1 | Separate the public museum from the professional workspace. | Public navigation becomes Home, Explore, Stories, Connections, My Collection, and About. Evidence, APIs, agents, imports, annotations, org status, and operational controls move behind one clearly labeled “For museums and researchers” entry point. Rewrite the homepage in plain language around art and discovery. | A first-time visitor can explain the product and reach an artwork without encountering workspace status or specialist implementation language; professional routes remain directly reachable and unchanged in capability. | Mobile and desktop visual review, keyboard pass, `pnpm a11y:check`, public-navigation tests, and moderated five-second comprehension checks. |</p>\n<p>| PD2 | Ship the minimum delightful discovery loop. | Add `Surprise me`, a rights-safe Artwork of the Day with a stable dated URL, and public artwork pages led by image, essential facts, “Why this is interesting,” related works, and previous/next discovery. Collapse technical metadata and researcher feedback below the public story. | The complete loop works: entry point → artwork → short story → related discovery → another artwork. Featured records never have broken media or ambiguous reuse messaging. | Deterministic selection tests, record-quality tests, mobile/desktop E2E, share-preview checks, and measured artwork-to-artwork continuation. |</p>\n<p>| PD3 | Launch Connections as the signature feature. | Start with three evidence-backed types: the same subject across cultures, works made in the same period on different continents, and recurring symbols or materials across institutions. Label documented relationships separately from algorithmic suggestions and expose sources plus confidence. | At least three curated connection journeys span two or more providers, contain no unsupported causal claims, and pass human editorial review. Visitors can move from a work to a connection and into another institution&#39;s work. | Connection contract tests, citation completeness, confidence-label checks, curator review checklist, and journey E2E. |</p>\n<p>| PD4 | Add source-backed Stories and guided exploration. | Publish short image-led stories using reusable formats such as “One artwork, three details,” “Same year, different worlds,” “A disputed identity,” and “How an object changed hands.” Add exploration by subject, place, century, and color; add mood only as clearly labeled interpretation. Hide empty maps and timelines. | A minimum viable editorial cadence is sustainable; every factual claim resolves to a source; guided filters return useful results; empty analytical surfaces do not appear publicly. | Story-schema and citation tests, filter-quality samples, editorial review log, structured-data/share-card validation, and completion-rate measurement. |</p>\n<p>| PD5 | Make trustworthy reuse and participation useful. | Add public-domain image download with source, rights, attribution, and metadata. Add “What changed?” with plain-language record version comparisons. Allow local-first saved collections, then optional account sync and read-only sharing after demand is observed. | Downloads package correct rights context; record changes identify source, time, and change origin; a visitor can save and share a coherent collection without being forced to sign in first. | Rights/download fixtures, version-diff tests, local-storage and account-migration tests, privacy review, and collection share E2E. |</p>\n<p>| PD6 | Prove retention before expanding. | Evaluate artwork continuation, Surprise Me use, story completion, connection opens, downloads, collections created/shared, and 7-day return visits. Improve the strongest loop; retire or revise weak entry points. | Two consecutive measurement windows show a credible repeat-use signal and no regression in accessibility, performance, rights, or citation quality. Any further personalization or recommendation work has a measured hypothesis. | Analytics review, usability replay, public performance/a11y matrix, editorial quality audit, and a written continue/change/stop decision. |</p>\n<p>Recommended first release: <strong>PD0 + PD1 + PD2 + three PD3 journeys</strong>. It must</p>\n<p>demonstrate one complete public loop:</p>\n<blockquote>Interesting entry point → beautiful artwork → understandable source-backed</blockquote>\n<blockquote>story → unexpected cross-museum connection → another discovery → save or share.</blockquote>\n<p>Public discovery stop conditions: pause expansion if featured-record quality</p>\n<p>cannot be guaranteed, if connection evidence cannot support the displayed claim,</p>\n<p>if rights context is separated from a download, if public pages regress the</p>\n<p>agreed accessibility or performance budgets, or if measured use shows no</p>\n<p>improvement after two iterations.</p>\n<p>PD1 implementation checkpoint (August 6): the primary public navigation is now</p>\n<p>Home, Explore, Stories, Connections, My Collection, About, and one quiet “For</p>\n<p>museums and researchers” entry. Anonymous Explore and artwork journeys no longer</p>\n<p>render organization status or professional workspace chrome, and public Explore</p>\n<p>suppresses import prompts, roadmap language, and provider implementation notes.</p>\n<p>The homepage now leads with cross-museum discovery in plain language; dedicated</p>\n<p>Stories, Connections, My Collection, and professional-workspace landing pages</p>\n<p>make every navigation destination intentional. Automated navigation, homepage,</p>\n<p>workspace-boundary, and Explore acceptance tests are green. The local production</p>\n<p>build passes, the 18-route accessibility matrix reports zero severe violations,</p>\n<p>and a 375 px browser review finds no horizontal overflow. A fresh deployed visual</p>\n<p>review and non-specialist comprehension sessions remain PD1 evidence tasks rather</p>\n<p>than reasons to reopen its implementation scope.</p>\n<p>PD2 implementation checkpoint (August 6): `/surprise` selects from the same</p>\n<p>image-backed, publication-eligible local artwork pool as the homepage and sends</p>\n<p>visitors directly into a public artwork journey. `/today` resolves to a stable</p>\n<p>UTC-dated `/today/YYYY-MM-DD` page whose selection is deterministic for that date.</p>\n<p>The homepage exposes both entry points. Anonymous artwork pages now lead with</p>\n<p>“Why this is interesting,” keep facts and source detail in an expandable section,</p>\n<p>offer previous, next, Surprise Me, and related-artwork paths, and withhold</p>\n<p>researcher annotations and operational relationship tools. Signed-in researchers</p>\n<p>retain the complete professional view. Selection and surface acceptance tests are</p>\n<p>green. The production build passes, the 18-route accessibility matrix reports</p>\n<p>zero severe violations, Surprise Me resolves into an eligible local artwork, and</p>\n<p>homepage, daily, and artwork routes show no horizontal overflow at 375 px. A</p>\n<p>deployed review remains necessary before promoting this local checkpoint to</p>\n<p>production proof.</p>\n<p>August 7 deployed checkpoint: PD1/PD2 is live on the production alias. The full</p>\n<p>serial test suite, lint, diagnostic typecheck, local and Vercel builds,</p>\n<p>production 18-route axe audit, 66-check crawler preview, 20/20 deployment</p>\n<p>preflight, public Explore smoke, repeated public-trust screenshot baseline, and</p>\n<p>zero-advisory dependency audit pass. Ten retained Lighthouse captures report</p>\n<p>100 accessibility and 0 CLS; the desktop routes pass the LCP budget, while the</p>\n<p>stricter Lighthouse mobile profile reports 3.7-5.9 second LCP and keeps P1.5</p>\n<p>open for remediation and an agreed-profile recapture. The refreshed adoption</p>\n<p>matrix passes 12/12 operator-run endpoint probes for all three named consumer</p>\n<p>IDs and remains blocked on genuine `Delete`. Those probes do not substitute for</p>\n<p>fresh reads made by the external consumers themselves: the retained declared</p>\n<p>consumer reads are outside the 30-day adoption window, so Era C correctly</p>\n<p>reports `0/3`. Production preflight is 20/20 with zero deployment-environment</p>\n<p>failures; the remaining launch-review blockers are time-bound SLO samples and</p>\n<p>real-world adoption/KPI evidence.</p>\n<p>The concrete production preflight is zero-failure on deployment</p>\n<p>`dpl_2WH2w1hrM4zftM84kn3ouU3xu4N4`. The broader `review:goals:local` roll-up now</p>\n<p>also reports zero deployment-environment blockers: aggregate launch-review and</p>\n<p>Era C wrappers inherit real-world-evidence scope, while concrete preflight,</p>\n<p>auth, smoke, IIIF, and k6 failures remain deployment-scoped when present. The</p>\n<p>remaining 21 strict blockers are explicitly time-bound or human/external</p>\n<p>evidence rather than deployment configuration failures.</p>\n<p>August 7 PD0/PD3 checkpoint: the five public outcome events now have a typed,</p>\n<p>consent-gated contract that excludes direct identifiers and professional</p>\n<p>routes. First artwork completion, artwork continuation, 24-hour return,</p>\n<p>rights-qualified download selection, and successful share are instrumented.</p>\n<p>A dated baseline artifact and five-session non-specialist</p>\n<p>protocol are present, while production observation and the five human sessions</p>\n<p>remain open. PD3 has exactly one curated journey—Flowers across two centuries—</p>\n<p>spanning Getty and Met records with citations, a high-confidence metadata</p>\n<p>label, an explicit no-influence boundary, contract tests, and an editorial</p>\n<p>decision packet awaiting attributable human sign-off. Do not expand to three until this first</p>\n<p>journey is deployed and the measurement/editorial evidence is reviewed.</p>\n<p>August 8 cultural-intelligence checkpoint: the first journey now produces three</p>\n<p>synchronized representations from one typed contract: a public visual story, a</p>\n<p>research dossier exposing fact/inference labels, method, uncertainties, rejected</p>\n<p>hypotheses, novelty status, and rights boundary, plus an evaluation-only JSON</p>\n<p>record with the same claim/citation graph and human-review state. Consent-gated</p>\n<p>story-completion and reuse-interest signals are instrumented outside the five PD0</p>\n<p>outcomes. Institutional usefulness, agent/editorial minutes, independent novelty</p>\n<p>verification, five usability sessions, and attributable editorial approval remain</p>\n<p>external evidence gates; the one-journey expansion stop is unchanged.</p>\n<p>The expansion gate is now executable through `pnpm connections:evidence`: its</p>\n<p>privacy-safe artifact requires observed completion plus sharing/reuse, qualified</p>\n<p>editorial sign-off, institutional usefulness, agent/editorial labor and cost,</p>\n<p>independent novelty review, a real price response, and the valid synchronized</p>\n<p>machine record. It reports tested gross value before labor separately from labor</p>\n<p>minutes and cannot call that result profit. No real evidence has been imported,</p>\n<p>so expansion remains unauthorized.</p>\n<p>Internal hidden-pattern work can now proceed without violating that public gate:</p>\n<p>`pnpm connections:patterns` emits a review-only collection-intelligence report</p>\n<p>from normalized records plus explicit source rows. Deterministic candidates cover</p>\n<p>equivalent-record conflicts, possible entity reconciliation, shared materials,</p>\n<p>owner/custodian or set references, structured-provenance coverage gaps, and</p>\n<p>geographic contrasts. Every lead carries citations, confidence, and a refusal</p>\n<p>boundary; uncited records are rejected and unsupported demographic or market</p>\n<p>conclusions are listed as refused analyses. No second public journey was added.</p>\n<p>The review-only report now also consumes explicit Linked Art event evidence:</p>\n<p>matching exhibition identifiers, `used_specific_object` groupings, structured</p>\n<p>acquisition/transfer parts, dated event places, and shared activity actors. Its</p>\n<p>event graph preserves source-record IDs on every edge. Geographic sequences are</p>\n<p>movement candidates rather than transport claims; ownership histories do not</p>\n<p>assert completeness, authenticity, custody, or legal title.</p>\n<p>Additional explicit-evidence candidates now cover alternative maker assignments,</p>\n<p>reversed event timespans, repeated technique identifiers, separate `represents`</p>\n<p>and `about` iconographic concepts, and unidentified depicted people. Boundaries</p>\n<p>prevent authorship resolution, invented corrected dates, workshop/influence</p>\n<p>claims, collapsed depiction semantics, or demographic/underrepresentation</p>\n<p>inference from these candidates.</p>\n<p>The machine layer now also exposes `/api/cultural-intelligence` as a lifecycle-</p>\n<p>aware collection feed. Each item preserves revision, production provenance,</p>\n<p>review history, corrections, and separate editorial/licensing decisions. The</p>\n<p>feed currently reports one evaluation item and zero licensable items; approval</p>\n<p>metadata must be complete and all corrections resolved before eligibility can</p>\n<p>change. Underlying source-record and media rights remain explicitly separate.</p>\n<p>Five derivative formats now compile from the same versioned claim graph:</p>\n<p>newsletter, daily feed, narrated visual essay, classroom package, and licensed</p>\n<p>article. Evidence sections preserve claim/citation IDs and all formats repeat the</p>\n<p>rights boundary. The derivative endpoint returns only an HTTP 409 release</p>\n<p>manifest—not internal copy—while the first record lacks editorial and licensing</p>\n<p>approval. Format availability is therefore implemented but audience demand,</p>\n<p>quality, labor, accessibility, and price remain unproven external evidence.</p>\n<p>Value-based pricing now has an executable evidence ladder through</p>\n<p>`pnpm connections:pricing`: hypothesis, tested-no-signal, market signal, one</p>\n<p>invoice-validated delivery, and repeatable price evidence. Repeatability requires</p>\n<p>three scoped offers and two paid, accepted, value-confirmed, positive-contribution</p>\n<p>deliveries across buyer segments. Labor is fully costed at an attributable rate;</p>\n<p>interest is never revenue. No real offer artifact exists yet, so pricing remains</p>\n<p>unvalidated.</p>\n<p>The `pd0:evidence` intake command now validates a real GA4 export and moderated</p>\n<p>session records, rejects direct identifiers or invented counts, and derives</p>\n<p>completion only from five sessions plus attributable product-owner approval.</p>\n<p>Its package namespace, script, artifact directory, and product-governance owner</p>\n<p>are registered in the executable evidence-ownership and operations-risk controls.</p>\n<p>Responsive browser review found the initial action block below the full image on</p>\n<p>mobile; it now precedes the image and remains overflow-free at 390 px and 1440 px.</p>\n<p>The Vercel ignore contract excludes local provider source mirrors, the `.tools`</p>\n<p>binary cache, and the upstream `linked.art` checkout except its required schema</p>\n<p>subtree. However, deployment `dpl_GiNFmNpo2UZs4uGEm4Y3B54Bya3b` still archived</p>\n<p>79,077 files (669.1 MB), so CLI archive filtering remains an open packaging</p>\n<p>optimization; the deploy itself completed and passed its runtime build.</p>\n<h3 id=\"p2-productize-only-after-the-pilot-loop-works-later-6-12-weeks\">P2 - Productize Only After The Pilot Loop Works (Later, 6-12 Weeks)</h3>\n<p>| ID | Outcome | Trigger | Exit criteria |</p>\n<p>|---|---|---|---|</p>\n<p>| P2.1 | Guided organization onboarding and first-value dashboard. | One invoice-backed pilot completes activation and its friction is documented. | A new managed org can be provisioned with a sample or customer dataset in under 15 minutes; progress and first value are visible without engineering inspection. |</p>\n<p>| P2.2 | Repeatable subscriptions and usage visibility. | Pricing, support load, and gross margin are validated on at least one pilot. | Checkout or invoice-backed subscription sync, webhook/audit evidence, quotas, usage, billing state, cancellation reason, and customer portal are supportable. |</p>\n<p>| P2.3 | Institution procurement package. | A buyer starts security/legal review. | Deployment-specific subprocessors, DPA/legal artifacts, access review, incident drill, retention controls, backup/restore proof, status reporting, and SLA/SLO packet are buyer-reviewable. |</p>\n<p>| P2.4 | Production agent bridge decision. | A named operator accepts the review workload and risk boundary. | AG2 bridge has explicit sign-off, eval evidence, rollback, auditability, and human-publication approval. A2A/AG-UI remain deferred. |</p>\n<p>---</p>\n<h2 id=\"readiness-scorecards\">Readiness Scorecards</h2>\n<h3 id=\"launch-readiness\">Launch Readiness</h3>\n<p>| Lane | Score | Decision | Next evidence |</p>\n<p>|---|---:|---|---|</p>\n<p>| Internal development and portfolio demo | 9.0/10 | Safe to use and present with the strict-readiness caveat. | Reproduce the canonical local gate and resolve the public evidence inconsistencies. |</p>\n<p>| Controlled public beta | 8.4/10 | Technically credible on Vercel + Neon, but the formal beta gate remains evidence-red. | Clear P0, then maintain narrow acceptance criteria while the 30-day window accumulates. |</p>\n<p>| General public production | 6.5/10 | Do not claim complete readiness. | Passing long-window SLO/uptime, production KPI, and coherent launch evidence. |</p>\n<p>| Institution-grade / strict 10/10 | 5.5-6.0/10 | Blocked by external and time-based proof. | `pnpm review:goals:check` passes with no production-proof blockers. |</p>\n<h3 id=\"saas-readiness\">SaaS Readiness</h3>\n<p>| Lane | Score | Decision | Next evidence |</p>\n<p>|---|---:|---|---|</p>\n<p>| Technical SaaS foundation | 7.0/10 | Strong enough for concierge pilots. | Prove onboarding, support load, usage, and tenant operations with one buyer. |</p>\n<p>| Paid pilot readiness | 8.2/10 | The offer and operator path are ready; revenue proof is not. | Reply or qualified follow-up, signed scope, invoice-backed entitlement, real activation. |</p>\n<p>| Self-serve SaaS readiness | 3.0/10 | Deferred. | Start only after the pilot validates pricing and activation friction. |</p>\n<p>| Profitable SaaS business | 4/10 | Credible wedge, but repeatable revenue is not proven yet. | Retention, support minutes, infrastructure cost, conversion, and gross-margin evidence. |</p>\n<p>The primary wedge remains the <strong>Managed Linked Art Launch Pilot</strong> for small and</p>\n<p>mid-size museums, archives, galleries, digital-humanities labs, and artist estates</p>\n<p>that need standards-compliant collection publication without a semantic-web team.</p>\n<p>Manual invoicing is correct for the first 1-3 pilots. Creator-side provenance and</p>\n<p>self-serve billing stay deferred until the B2B pilot loop produces evidence.</p>\n<p>---</p>\n<h2 id=\"evidence-workstreams\">Evidence Workstreams</h2>\n<p>| Workstream | Current state | Completion condition |</p>\n<p>|---|---|---|</p>\n<p>| Local quality | Review-goals local status passes and direct ESLint passes; full canonical reproducibility was not demonstrated in the July 12 audit. | P0.2 is green from a clean generated state. |</p>\n<p>| Deployment | Preflight `20/20`, both Render probes, all public smokes, and deployed k6 pass; launch review is `7/8`. The strict handoff has zero deployment-environment blockers because its remaining launch and Era C wrappers depend only on real-world evidence. | Preserve the green concrete deployment matrix while the real-world evidence windows mature. |</p>\n<p>| Long-window SLO and uptime | The latest strict handoff reports `11` retained deployed SLO samples across `10/30` distinct UTC days, with `11` passing samples and no failed or incomplete rows in the active report window; the Era C artifact still reports only `15/30` samples toward its exit gate. | Continue distinct-day collection until the complete 30-day threshold is genuinely met. |</p>\n<p>| ActivityStreams | Operator endpoint probes pass for three named IDs, but the retained real external consumer evidence is stale and therefore counts as `0/3`; genuine `Delete` evidence is pending. | Collect three fresh real external consumers covering `Create`, `Update`, and `Delete`, with verified callbacks. |</p>\n<p>| Production KPI | Local enrichment is promising; production reconciliation distribution and reviewed precision are incomplete. | P1.2 passes the SOTA KPI acceptance rows from named production sources. |</p>\n<p>| Managed pilot | The offer, runbook, entitlement, activation, support, and evidence tooling exist. The latest no-pricing buyer pack is specific to the recorded Te Papa outreach and has a real account, organization, and owner, but no paid-pilot tenant or invoice-backed entitlement exists. | Obtain a real buyer reply plus signed scope or invoice reference, provision the tenant, then use P1.3 tooling to record activation, retention, support load, and margin evidence. |</p>\n<p>The buyer-review surface now includes a standalone ten-record demonstration at</p>\n<p>`/museum-linked-art-pilot-demonstration.html`. It uses traceable public API records</p>\n<p>to show source preservation, event-centric Linked Art JSON-LD, rights review</p>\n<p>boundaries, validation findings, and museum questions. It proves a review pattern,</p>\n<p>not a completed customer engagement or permission to reuse source images.</p>\n<p>A one-page buyer brief at `/managed-linked-art-pilot-brief.html` now packages the</p>\n<p>problem, five-day process, required inputs, deliverables, privacy and security</p>\n<p>boundaries, and post-pilot decision into a printable pre-call handout. It links to</p>\n<p>the ten-record demonstration and preserves the same evaluation-only claim boundary.</p>\n<p>The first-call workflow now has a timed guide at</p>\n<p>`/museum-pilot-discovery-call-guide.html`: a one-minute permission-based opening,</p>\n<p>five fit questions, a boundary recap, three explicit decision paths, and a</p>\n<p>follow-up record. The call qualifies a bounded pilot before any product tour and</p>\n<p>links directly to the buyer brief and demonstration when supporting proof is useful.</p>\n<p>The post-call handoff now has a public-data request at</p>\n<p>`/museum-pilot-data-request-template.html`. It supplies a copy-ready museum message,</p>\n<p>accepts CSV, JSON, XML, LIDO, or a public API, distinguishes minimum from optional</p>\n<p>fields, excludes credentials and restricted material, and records the reviewer,</p>\n<p>publication boundary, transfer method, receipt evidence, and agreed deletion date.</p>\n<p>The conversion and delivery packet now adds a counsel-review sample agreement,</p>\n<p>four-level introductory pricing, and a reusable results report. The public pilot</p>\n<p>offer uses the same `$0` evaluation, `$3,500` fixed paid pilot, implementation from</p>\n<p>`$12,000`, and ongoing service from `$1,250` monthly hypothesis, so buyer surfaces</p>\n<p>no longer conflict. These remain unvalidated prices until invoice-backed delivery,</p>\n<p>acceptance, retention, and gross-margin evidence exists.</p>\n<p>The refined demonstration presents one primary path on desktop and mobile:</p>\n<p>collection record, Linked Art mapping, validation, then reviewable result. Source</p>\n<p>evidence is collapsed beneath the interaction, and the final state names open</p>\n<p>museum decisions and the human publication gate.</p>\n<p>The current outreach ledger records the eight user-confirmed August 5 submissions,</p>\n<p>their real recipient or form channel, zero assumed replies, and August 12 follow-up</p>\n<p>dates. `docs/sales/museum-outreach-pipeline.md` contains eight unsent follow-up</p>\n<p>drafts plus a second official-source-researched group of eight prospects that must</p>\n<p>remain `research_only` until first-round feedback is reviewed and sending is</p>\n<p>authorized. `docs/ops/paid-pilot-commercial-evidence-process.md` closes the</p>\n<p>invoice-to-margin capture design without treating placeholders as proof.</p>\n<h3 id=\"standing-evidence-controls\">Standing Evidence Controls</h3>\n<p>  `generatedAt` separate from source `sourceUpdatedAt` and `sourceUpdatedDoc`</p>\n<p>  checksum metadata.</p>\n<p>  `wikidataexplorer-metamuseum-prod` and the other real consumers distinct,</p>\n<p>  retain durable callback evidence, and preserve the zero rejected subscriptions</p>\n<p>  state without allowing placeholders to satisfy strict proof.</p>\n<p>  `pnpm longterm:evidence:public` output remain strict gates; a frontend Core Web</p>\n<p>  Vitals baseline is added in P1.5 rather than inferred from API SLO evidence.</p>\n<p>  remain separate scopes. No aggregate badge may silently promote one scope into</p>\n<p>  another.</p>\n<ul><li><strong>Public docs metadata freshness:</strong> `/api/docs/manifest` must keep response</li><li><strong>ActivityStreams onboarding ledger:</strong> partner rows must keep</li><li><strong>Performance evidence:</strong> the cold-record budget, 30-day SLO depth, and</li><li><strong>Claim boundary:</strong> local success, deployment success, and real-world success</li></ul>\n<p>---</p>\n<h2 id=\"product-and-engineering-guardrails\">Product And Engineering Guardrails</h2>\n<ol><li>Linked Art JSON-LD remains canonical; UI DTOs are projections at boundaries.</li></ol>\n<ol><li>Preserve rights, source attribution, provenance, multi-value arrays, event</li></ol>\n<p>   semantics, carrier/content/surrogate separation, and opaque URI handling.</p>\n<ol><li>Adapters do not import each other; provider parsing stays in adapters;</li></ol>\n<p>   cross-provider mapping stays in `src/utils/artwork-builder.ts`; contracts remain</p>\n<p>   leaf modules.</p>\n<ol><li>AIDD + TDD remains mandatory for behavior changes. Standards-critical work</li></ol>\n<p>   cites reference rounds and fixture anchors before implementation.</p>\n<ol><li>Public publication and agent-generated claims require citations, refusal paths,</li></ol>\n<p>   audit evidence, and human approval.</p>\n<ol><li>Keep Next.js, React, TypeScript, custom CSS, Postgres/JSONB, Solr, GraphDB, and</li></ol>\n<p>   canonical ID decisions locked as documented in CLAUDE.md(../CLAUDE.md).</p>\n<ol><li>No new runtime dependency, provider, service, database, or architecture era is</li></ol>\n<p>   started while P0 is red without explicit approval.</p>\n<h3 id=\"deliberately-deferred\">Deliberately Deferred</h3>\n<p>  economics and activation are real.</p>\n<p>  by measured scale or customer evidence.</p>\n<ul><li>New provider integrations beyond the current 14 production lanes.</li><li>Self-serve signup, checkout, billing portal, and growth automation before pilot</li><li>Synthetic ActivityStreams `Delete` evidence.</li><li>Broad production agent autonomy or public publishing without operator sign-off.</li><li>A microservice, triple-store, vector-store, or framework expansion not justified</li></ul>\n<p>---</p>\n<h2 id=\"cadence-and-ownership\">Cadence And Ownership</h2>\n<p>| Cadence | Required action |</p>\n<p>|---|---|</p>\n<p>| Every behavior change | Red-green-refactor tests, focused smoke/evidence, README + roadmap update, and `pnpm session:closeout`. |</p>\n<p>| Every 72 hours during active shipping | Canonical local gate plus fresh P0 evidence checks. Stop expansion when a required gate is missing. |</p>\n<p>| Weekly | Refresh long-window evidence, inspect failed-sample age-out dates, review pilot pipeline, and update only changed roadmap decisions. |</p>\n<p>| Monthly or before a buyer review | Refresh production preflight, launch evidence/review, procurement packet, access/DR evidence, and the strict handoff. |</p>\n<p>The roadmap records current decisions and measurable outcomes, not every merged</p>\n<p>change. Completed implementation detail belongs in</p>\n<p>progress/era-history.md(progress/era-history.md), specialized docs, generated</p>\n<p>artifacts, and git history.</p>\n<p>---</p>\n<h2 id=\"history-and-references\">History And References</h2>\n<p>  history, including the milestones consumed by `/api/roadmap`.</p>\n<p>  artifact handoff.</p>\n<p>  contract.</p>\n<p>  command ownership and preferred entry points.</p>\n<p>  standards rounds and fixture anchors.</p>\n<p>  architecture and SOTA acceptance criteria.</p>\n<ul><li>progress/era-history.md(progress/era-history.md): full Era A, B, and C slice</li><li>roadmap-to-10.md(roadmap-to-10.md): executable strict-readiness checklist and</li><li>risk-register.md(risk-register.md): open engineering and operating risks.</li><li>ops/review-goals.md(ops/review-goals.md): review-goals policy and command</li><li>ops/evidence-script-ownership.md(ops/evidence-script-ownership.md): evidence</li><li>linked-art/LinkedArtModel1.0-Reference.md(linked-art/LinkedArtModel1.0-Reference.md):</li><li>linked-art/LinkedArtSOTAWebApp.md(linked-art/LinkedArtSOTAWebApp.md): target</li></ul>","updatedAt":"2026-08-06T00:00:00.000Z","checksum":"b2769ae894862f4623e7627dce8cadd5992733cc53ea2ec00f7177195ff6a9ce","checksumPrefix":"b2769ae89486","anchorCount":18,"lineCount":582,"rawUrl":"/api/docs/content?path=roadmap.md","htmlUrl":"/docs?doc=roadmap.md","apiUrl":"/api/docs/content?path=roadmap.md"}