{
 "version": "1.8.0",
 "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
 "title": "CampaignClear — A2P 10DLC Brand & Campaign Approval Completeness Pack Engine",
 "vertical": "Regulatory compliance",
 "seed": {
  "s": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "t": "CampaignClear — A2P 10DLC Brand & Campaign Approval Completeness Pack Engine",
  "v": "Regulatory compliance",
  "r": "Medium-high",
  "m": "M"
 },
 "product": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "project_name": "CampaignClear",
  "project_type": "regulator-fluent compliance documentation workflow application",
  "vertical": "Regulatory compliance",
  "audience": "regional multifamily/mixed-use property managers and mid-size owners with 3-40 SMS-sending locations",
  "geography": "US, Twilio-anchored senders (beachhead) first; Telnyx/Bandwidth-anchored senders (secondary); TCR rule library expandable",
  "scale_expectation": "8-20 buildings under Portfolio Desk in year one; per-building pack volume with inspection-cycle seasonality; high artifact fidelity",
  "core_workflows": [
   "TCR profile intake & evidence normalization",
   "Gap matrix scoring against TCR Brand & Campaign vetting checklist / TCR checklist",
   "Analyst release & customer's outside counsel escalation",
   "Vendor resubmit kit & Evidence Index delivery"
  ],
  "discovery": {
   "one_line_purpose": "On CampaignClear, SMS operations coordinators stop guessing whether an SMS-campaign's Brand & Campaign TCR registration will survive an carrier vetting review and start proving it. Vendor logs and signup-page photos are extracted at intake, the gap matrix runs against the adopted TCR Brand & Campaign vetting checklist checklist, and every Completeness Pack releases with a dated Evidence Index a registration analyst has signed.",
   "primary_users": [
    "SMS operations coordinators, PM directors, and risk/facilities VPs at regional multifamily and mixed-use ownership groups",
    "Registration analyst, with customer's own outside counsel informing any contested-question release",
    "carrier vetting reviewer, insurer, or lender diligence team (read-only)"
   ],
   "jobs_to_be_done": [
    "Produce the TCR Brand & Campaign vetting checklist owner-side TCR profile record for every Brand+Campaign registration without hiring a full-time SMS-campaign compliance coordinator",
    "Catch hard gaps - missing TCR profile, no on-site accessibility instructions, short retention - before an carrier vetting reviewer does",
    "Hand an inspector, insurer, or acquiring owner a dated Evidence Index on demand when a vendor changes or a portfolio trades"
   ],
   "value_prop": "CampaignClear turns a scattered, multi-vendor SMS-campaign paperwork trail into a released, analyst-signed TCR checklist Completeness Pack - reconstructable on demand, gap-matrix cited, with the owner always the responsible party of record.",
   "competitors": [
    "Full-service TCPA/telecom attorneys who price TCR profile audits as bespoke, project-length engagements",
    "OEM/service vendors (Twilio, Telnyx, Bandwidth, Vonage) who write the TCR profile but have no incentive to prove its completeness independently",
    "SaaS compliance trackers the facilities team is expected to operate themselves"
   ],
   "differentiation": "Done-for-you Completeness Packs, not a dashboard: deterministic hard-gap rules (no TCR profile, no on-site accessibility instructions, under 5-year retention, missing use-case samples), analyst release on every pack, customer's outside counsel (referral only) escalation only for no-registration-on-file or contested code interpretation, and an explicit gap matrix instead of invented log lines.",
   "positioning_statement": "For SMS operations coordinators and property management leaders at regional multifamily and mixed-use ownership groups with 3-40 SMS-campaign buildings, CampaignClear is the done-for-you documentation service that turns scattered vendor TCR profile paperwork into a released, TCR-checklist-cited Completeness Pack - unlike full-service TCPA/telecom attorneys who price bespoke engagements, or SaaS trackers that leave the completeness work on your staff."
  },
  "assumptions": [
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-a1",
    "statement": "Regional PM buyers will pay a flat per-building fee for an analyst-released Completeness Pack rather than treat a free vendor-supplied TCR profile PDF as good enough.",
    "confidence": "medium",
    "impact_if_wrong": "severe",
    "revisit_trigger": "First 5 design-partner sales calls in Twilio-anchored senders - reject if willingness-to-pay signal is absent."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-a2",
    "statement": "A single-building TCR profile Completeness Pack can be reconstructed from owner-supplied evidence (TCR profile, logs, callbacks, inspections, photos) within the 7-business-day standard cycle.",
    "confidence": "low",
    "impact_if_wrong": "high",
    "revisit_trigger": "First real customer onboarding cycle."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-a3",
    "statement": "CSPs and outside-counsel partners will tolerate an AI-assisted extraction and gap-scoring layer when the release is explicit, analyst-signed, and paused for outside-counsel referral on contested cases.",
    "confidence": "medium",
    "impact_if_wrong": "high",
    "revisit_trigger": "First carrier vetting review or outside-counsel referral interaction referencing a released pack."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-a4",
    "statement": "Logical per-tenant data isolation with row-level auth is acceptable for the first cohort of buildings; single-tenant hosting is not required.",
    "confidence": "medium",
    "impact_if_wrong": "high",
    "revisit_trigger": "Any prospect (insurer or lender diligence team) with a hard single-tenant clause."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-a5",
    "statement": "Manifest-backed blueprint reflects a real Twilio/Telnyx/Bandwidth SMS-campaign-TCR profile workflow, not a synthetic scenario.",
    "confidence": "medium",
    "impact_if_wrong": "medium",
    "revisit_trigger": "First customer walkthrough of the intended workflow."
   }
  ],
  "unknowns": [
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-u1",
    "question": "How will CampaignClear confirm the customer has obtained their own outside counsel's guidance before an escalated (red) pack releases?",
    "blocks": "Any commercial claim; TCR-facing delivery on no-registration-on-file cases.",
    "resolution_path": "Customer's own outside counsel contact on file before any contested-question engagement (never CampaignClear's engagement)."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-u2",
    "question": "Which CSP rulesets and jurisdictions are in scope for launch beyond Twilio and Telnyx/Bandwidth?",
    "blocks": "Rule-library coverage; checklist card accuracy; canonical/hreflang.",
    "resolution_path": "Owner confirms in-scope TCR list in the owner-action pack."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-u3",
    "question": "What is the actual willingness-to-pay above the $1,450-$2,850 pack band across portfolio sizes?",
    "blocks": "Pricing hypothesis; Portfolio Desk tier economics.",
    "resolution_path": "5 design-partner discovery calls with explicit pricing conversation."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-u4",
    "question": "Which existing systems (vendor portals, PM software, insurer portals) must intake integrate with day one?",
    "blocks": "Architecture module boundaries; data-in/out contracts.",
    "resolution_path": "Design-partner tech-inventory questionnaire."
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-u5",
    "question": "Is there a data-residency or litigation-discovery constraint on the evidence evidence archive?",
    "blocks": "Deployment topology; evidence archive retention policy.",
    "resolution_path": "Vendor-diligence questionnaire from first prospect; MSA legal review of evidence archive subpoena exposure."
   }
  ],
  "expert_panel": [
   {
    "role": "Product Strategy",
    "key_concern": "Is the ICP narrow enough to earn a first design-partner cohort without diluting into full SMS-campaign consulting?",
    "recommendation": "Constrain launch to Twilio-anchored senders multifamily/mixed-use PMs with 3-40 SMS-campaign buildings; broaden to Telnyx/Bandwidth only after 5 signed design partners.",
    "dissent": "May under-price the national installed-base opportunity and slow the fundraising narrative."
   },
   {
    "role": "Software Architecture",
    "key_concern": "Are we defaulting to microservices without justification for a document-extraction workload?",
    "recommendation": "Single deployable modular monolith with a documented seam for the OCR/extraction module, the highest-volume path.",
    "dissent": "May look unsophisticated to enterprise reviewers expecting a service-mesh diagram."
   },
   {
    "role": "Frontend / UX",
    "key_concern": "Is the gap matrix visible and trustable in every workflow screen?",
    "recommendation": "Every artifact view renders checklist clause to evidence pointer to release signature in one glance, styled as a signal registry ledger.",
    "dissent": "Adds vertical density that non-domain reviewers may call cluttered."
   },
   {
    "role": "Backend / Data",
    "key_concern": "Is the Evidence Index append-only and reconstructable given the litigation-discovery exposure of maintenance records?",
    "recommendation": "Event-sourced audit log for all pack state transitions; hash-stamped evidence snapshots; versioned rule tables per CSP ruleset.",
    "dissent": "Higher write-path complexity than plain CRUD; discipline required as CSP rulesets change."
   },
   {
    "role": "AI / ML",
    "key_concern": "Are extraction outputs grounded, cited, and gated against fabricated log lines?",
    "recommendation": "Retrieval-first OCR/extraction with source-span citations, structured output validation, and human release gate before delivery.",
    "dissent": "Slower than open-ended chat; may frustrate prospects expecting instant AI certification."
   },
   {
    "role": "Security",
    "key_concern": "Is the STRIDE surface documented for a evidence archive holding subpoena-exposed maintenance records?",
    "recommendation": "Threat model per module, per-tenant row-level auth, secrets in managed KMS, dependency scanning in CI.",
    "dissent": "Overhead in early prototype; some controls can wait until first paying portfolio customer."
   },
   {
    "role": "Privacy / Compliance",
    "key_concern": "Is the compliance target realistic given the evidence archive's litigation-discovery risk?",
    "recommendation": "SOC 2 Type I in year one with mapped controls for Type II; client-owned evidence archive export option to limit discovery exposure.",
    "dissent": "May lock out enterprise buyers requiring ISO/HITRUST on day one."
   },
   {
    "role": "DevOps / Reliability",
    "key_concern": "Is the ops model boring enough to run without a dedicated SRE during inspection-cycle demand spikes?",
    "recommendation": "Single production region + managed database + edge delivery; SLO published as availability + p95 latency only.",
    "dissent": "Single region concentrates risk during a regional outage at peak inspection season."
   },
   {
    "role": "Data / Analytics",
    "key_concern": "Are the leading indicators (cycle time, escalation rate, cure rate) wired before launch?",
    "recommendation": "Instrument intake-to-release cycle time, escalation/decline rate, and rejection cure rate; ship dashboards before first design partner.",
    "dissent": "Analytics scope-creep can steal weeks from core extraction and rules work."
   },
   {
    "role": "Accessibility",
    "key_concern": "Does the analyst release workflow meet WCAG 2.2 AA for every screen a reviewer uses?",
    "recommendation": "Enforce keyboard-only walkthrough for the gap-matrix and release screens; add axe-core to CI on reviewer surfaces.",
    "dissent": "Density-heavy ledger UI is hard to ship AA-clean quickly."
   },
   {
    "role": "SEO / Content",
    "key_concern": "Is the microsite claim honest and gated on evidence, avoiding any implied inspection guarantee?",
    "recommendation": "Regulator-fluent topical-authority content only (Twilio rejection code 30908 (privacy policy), Telnyx/Bandwidth TCR profile custody); no fake reviews, no LocalBusiness identity schema until owner facts close.",
    "dissent": "Slower content velocity than a generic SaaS blog."
   },
   {
    "role": "Executive Sponsor",
    "key_concern": "Is there a written kill criterion given outside-counsel-referral channel-conflict risk?",
    "recommendation": "Kill/pivot decision at 90 days if no design-partner LOI, or if escalation/decline rate exceeds 15% of packs.",
    "dissent": "Founders often resist naming kill criteria in writing."
   }
  ],
  "strategy": {
   "business_model": "Per-building outcome pricing with a recurring Portfolio Desk subscription tier",
   "revenue_streams": [
    "TCR profile Completeness Pack (flat per-building fee)",
    "Pre-Inspection Rush add-on",
    "Rejection Cure & Resubmit Desk add-on",
    "Portfolio Desk monthly subscription (5-40 buildings)"
   ],
   "moat": [
    "CSP ruleset rule library accumulated per jurisdiction",
    "Evidence Index history per building/Brand+Campaign registration",
    "Licensed outside counsel escalation relationships"
   ],
   "gtm": [
    "Founder-led design partner cohort (Twilio-anchored senders, 5-10 buildings)",
    "Free TCR profile Gap Scan lead magnet",
    "TCR/industry roundtable presence and SMS-campaign-vendor referral partnerships"
   ],
   "pricing_hypothesis": "Design-partner packs priced at the low end of the $1,450-$2,850 band; commercial tier validated against outside-counsel hourly cost and coordinator-hour opportunity cost before Portfolio Desk scale-up.",
   "kill_criteria": [
    "No signed design-partner LOI in 4 weeks",
    "Scan-to-paid conversion below 25% after 8 pilots or rework above 25%",
    "Escalation/decline rate exceeds 15% of packs sustained over a quarter",
    "outside-counsel-referral channel issues a written competitive objection"
   ]
  },
  "security": {
   "stride": [
    {
     "threat": "Spoofing",
     "scenario": "Attacker attempts to impersonate a registration analyst to release a fabricated Completeness Pack.",
     "mitigation": "SSO with MFA; release signatures bound to a cryptographic session claim, not a form field."
    },
    {
     "threat": "Tampering",
     "scenario": "Historical gap-matrix entries edited after the fact to hide an unresolved hard gap.",
     "mitigation": "Append-only audit log; hash-chained evidence-index snapshots; diff view on every analyst release surface."
    },
    {
     "threat": "Repudiation",
     "scenario": "Analyst denies releasing a delivered Completeness Pack.",
     "mitigation": "Signed attestations with server-side timestamp + releaser identity; export bundle includes signature manifest."
    },
    {
     "threat": "Information Disclosure",
     "scenario": "Cross-tenant leak of Regulated-record, PII, or Internal-audit data through shared retrieval indices or logs.",
     "mitigation": "Tenant-scoped row-level auth; PII scrubbing in logs; TCR retrieval indices partitioned per tenant."
    },
    {
     "threat": "Denial of Service",
     "scenario": "Runaway OCR/extraction job or export exhausts shared workers during an inspection-season demand spike.",
     "mitigation": "Per-tenant concurrency + budget caps; circuit breaker on model calls; degrade-gracefully queue."
    },
    {
     "threat": "Elevation of Privilege",
     "scenario": "Standard user acquires analyst-release capability via a workflow shortcut.",
     "mitigation": "Roles stored in a separate table; capability checks server-side; no client-only role checks."
    }
   ],
   "privacy_posture": "Data-minimization by default; per-tenant isolation; DPA templates on file; client-owned evidence archive export option to limit litigation-discovery exposure.",
   "compliance_targets": [
    "Twilio rejection code 30909 (message flow) 5-year record retention",
    "SOC 2 Type II",
    "ISO 27001 (year two)"
   ],
   "data_classifications": [
    "Regulated-record",
    "PII",
    "Internal-audit"
   ]
  },
  "devops": {
   "ci_cd": "PR -> typecheck + unit + snapshot tests -> preview deploy -> main auto-deploys to a single production region; TCR rule-table migrations gated on review.",
   "environments": [
    "local",
    "preview (per-PR)",
    "staging (shared)",
    "production (single region + multi-AZ)"
   ],
   "observability": [
    "Structured logs with tenant + request IDs",
    "RED metrics per workflow",
    "Error tracking with source maps",
    "Model-call spans with cost + latency",
    "Weekly SLO review"
   ],
   "testing_pyramid": [
    "Unit tests on gap-matrix scoring and hard-gap rule modules",
    "Component tests on analyst release surfaces",
    "Contract tests on TCR rule-library integrations",
    "End-to-end smoke test on the intake -> release -> delivery path"
   ],
   "accessibility_tests": [
    "axe-core in CI on analyst release surfaces",
    "Keyboard-only walkthrough per workflow",
    "Prefers-reduced-motion honored"
   ],
   "performance_budget": "p95 workflow latency published per module; gap-matrix generation cold-path under 30s or shown as background job."
  },
  "accessibility_i18n_ethics": {
   "wcag_target": "AA",
   "locales": [
    "en-US"
   ],
   "rtl_support": false,
   "ethical_risks": [
    "Pack released without analyst review",
    "CSP ruleset mismatch producing a false hard gap or a missed one",
    "TCR-facing errors attributed to AI",
    "Mis-selling the pack as an engineering or outside counsel service"
   ],
   "ethical_guardrails": [
    "Human analyst release required before delivery; counsel-referral escalation for contested interpretation",
    "Per-TCR-edition rule-card isolation with dated citations",
    "Standing disclaimer on every pack: documentation-readiness support only, owner remains responsible party"
   ]
  },
  "governance": {
   "ownership": [
    {
     "area": "Product + roadmap",
     "owner": "Executive Sponsor"
    },
    {
     "area": "Architecture + platform",
     "owner": "Engineering Lead"
    },
    {
     "area": "Gap matrix + release workflow",
     "owner": "Named registration analyst"
    },
    {
     "area": "Compliance + privacy",
     "owner": "Compliance Lead"
    },
    {
     "area": "Design system",
     "owner": "Design Lead"
    },
    {
     "area": "SEO + content",
     "owner": "Content Lead"
    }
   ],
   "docs_required": [
    "ADR log (checked in)",
    "Owner-action ledger",
    "Gap matrix evidence register",
    "STRIDE threat model",
    "Runbook: incident, restore, breach notification",
    "Analyst release playbook + counsel-referral policy"
   ],
   "naming_conventions": [
    "kebab-case slugs for blueprints and routes",
    "camelCase for TypeScript identifiers",
    "SCREAMING_SNAKE_CASE for environment variables",
    "Verb-first action names (e.g., generate-completeness-pack)"
   ],
   "change_control": "ADR-per-major-decision; TCR rule-table migrations require review; production deploys gated on green CI + owner-action ledger check."
  },
  "risk_register": [
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-r1",
    "risk": "TCR-facing claim in a released pack proves incorrect (wrong edition, misapplied clause)",
    "likelihood": "medium",
    "impact": "severe",
    "mitigation": "Every hard gap cites a dated checklist clause + evidence pointer; analyst release required",
    "contingency": "Retraction workflow; customer-notification template; audit-log export within 24 hours",
    "owner": "legal"
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-r2",
    "risk": "AI hallucination / fabricated log line in a delivered pack",
    "likelihood": "medium",
    "impact": "high",
    "mitigation": "Retrieval-first extraction + structured output validation + anti-fabrication QA sampling + analyst release gate",
    "contingency": "Analyst-triggered rollback + regeneration; incident postmortem published to customer",
    "owner": "engineering"
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-r3",
    "risk": "Cross-tenant data leak of evidence-indexed maintenance records",
    "likelihood": "low",
    "impact": "severe",
    "mitigation": "Row-level auth + per-tenant retrieval indices + log-scrubbing",
    "contingency": "Breach-notification runbook; forced credential rotation; scoped tenant kill switch",
    "owner": "engineering"
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-r4",
    "risk": "Design partner churns before contract, or outside counsel perceives a conflicted referral",
    "likelihood": "medium",
    "impact": "high",
    "mitigation": "Weekly working-session cadence; documented value moments; no revenue-share on counsel referrals — CampaignClear never brokers or pays counsel",
    "contingency": "Structured exit interview; write learnings into ICP + pricing hypothesis",
    "owner": "owner"
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-r5",
    "risk": "Analyst shortage during inspection-season demand spike (early demand trap)",
    "likelihood": "high",
    "impact": "high",
    "mitigation": "Hard pilot cap at 8 buildings; build-before-scale gates; SOC 2 Type I year one",
    "contingency": "Pause new logo intake; contract framework carve-out with legal review",
    "owner": "ops"
   },
   {
    "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-r6",
    "risk": "Single-region outage takes production down during a rush-pack cycle",
    "likelihood": "low",
    "impact": "high",
    "mitigation": "Multi-AZ managed database; nightly cross-region backup",
    "contingency": "Documented restore-to-DR runbook; RTO 8h / RPO 1h during pilot",
    "owner": "engineering"
   }
  ],
  "roadmap": [
   {
    "phase": "Phase 0 - Discovery + design-partner LOI",
    "weeks": "Weeks 1-4",
    "outcomes": [
     "3-5 Twilio-anchored senders design-partner LOIs",
     "Gap Scan evidence pack from each partner",
     "Written ICP + pricing hypothesis"
    ],
    "exit_criteria": [
     "≥3 LOIs signed",
     "Owner-action ledger populated per partner",
     "Licensed outside counsel identity confirmed"
    ],
    "kill_criteria": [
     "<2 LOIs after 4 weeks",
     "No willingness-to-pay signal above cost baseline"
    ]
   },
   {
    "phase": "Phase 1 - Thin vertical slice",
    "weeks": "Weeks 5-10",
    "outcomes": [
     "Intake -> gap matrix -> analyst release -> delivery working end-to-end for one building",
     "Evidence Index audit trail wired",
     "Instrumentation live"
    ],
    "exit_criteria": [
     "1 real Completeness Pack delivered + analyst-released",
     "p95 workflow latency published"
    ],
    "kill_criteria": [
     "Analyst release cycle >7 business days",
     "Evidence Index cannot be reconstructed on demand"
    ]
   },
   {
    "phase": "Phase 2 - Design-partner cohort",
    "weeks": "Weeks 11-20",
    "outcomes": [
     "3-5 buildings in weekly production use",
     "First paid Completeness Pack conversion",
     "SOC 2 Type I scoping"
    ],
    "exit_criteria": [
     "≥1 paid contract",
     "Scan-to-paid conversion signal captured",
     "Postmortem cadence in place"
    ],
    "kill_criteria": [
     "No paid conversion by week 20",
     "Escalation/decline rate exceeds 15% without contract offset"
    ]
   },
   {
    "phase": "Phase 3 - Commercial launch",
    "weeks": "Weeks 21-36",
    "outcomes": [
     "Public commercial launch of the microsite as 'ready'",
     "SOC 2 Type I completed",
     "Owner-action ledger closed for launched blueprint"
    ],
    "exit_criteria": [
     "Zero blocking owner actions for launched blueprint",
     "Publicly indexable microsite with WebPage+FAQPage schema only"
    ],
    "kill_criteria": [
     "Public launch not defensible against a plausible TCR or outside-counsel-referral inquiry"
    ]
   }
  ],
  "metrics": {
   "north_star": "Released Completeness Packs per week, per building, with zero re-issues for defects of our making",
   "leading": [
    "Design-partner LOIs signed",
    "Intake -> pack cycle time",
    "Analyst release cycle time",
    "Escalation/decline rate",
    "Hard-gap cure rate within 30 days"
   ],
   "lagging": [
    "Paid packs signed",
    "Portfolio Desk net revenue retention (post first cohort)",
    "TCR or counsel-referral objection count (target: 0)",
    "Retraction count on delivered packs (target: 0)"
   ],
   "guardrails": [
    "Model spend per tenant per week",
    "PII in logs (target: 0)",
    "Cross-tenant access attempts (target: 0)",
    "p95 workflow latency ceiling"
   ]
  },
  "executive_review": {
   "consensus": "Ship a thin, gap-matrix-linked, analyst-released vertical slice for CampaignClear. Prefer a boring, single-region modular monolith. Do not launch commercially until owner-action facts close and at least one analyst-released Completeness Pack is delivered.",
   "dissent": "Executive Sponsor and Privacy/Compliance disagree on launch tempo - Privacy recommends waiting for SOC 2 Type II mapping before any public commercial claim.",
   "go_no_go": "conditional-go",
   "top_3_risks": [
    "TCR-facing claim in a released pack proves incorrect",
    "AI hallucination / fabricated log line in a delivered pack",
    "Cross-tenant data leak of evidence-indexed maintenance records"
   ],
   "first_10_steps": [
    "Confirm the named customer's outside counsel (referral only) + engagement letter on file",
    "Populate owner-action ledger with entity, jurisdiction, contact inbox, privacy inbox",
    "Open 5 design-partner discovery calls in Twilio-anchored senders with explicit pricing conversation",
    "Write ICP + kill/pivot criteria in the plan file",
    "Stand up the intake -> gap matrix -> analyst release -> delivery loop",
    "Wire append-only audit log + hash-chained evidence-index snapshots",
    "Add row-level auth + tenant-scoped TCR retrieval indices",
    "Instrument intake-to-release cycle time, escalation rate, and cure-rate events",
    "Publish the microsite with WebPage+FAQPage schema only and noindex until owner-facts close",
    "Schedule the 90-day kill/pivot review with executive sponsor"
   ]
  }
 },
 "project_site": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "app_name": "CampaignClear Desk",
  "archetype": "filing-dossier",
  "archetype_label": "signal registry desk",
  "reader_role": "SMS Operations Coordinator",
  "one_sentence_app": "CampaignClear Desk is a signal registry desk for office managers and agency media buyers who need every Brand and Campaign tied to a rejection-code-complete record before a carrier vetting review or a new-location launch asks.",
  "homepage_sequence": [
   "scene",
   "workflow",
   "instrument",
   "offer",
   "proof",
   "qualification",
   "objections"
  ],
  "hero": {
   "frame_label": "Registration / Compliance · signal registry desk",
   "eyebrow": "SMS Operations Coordinator / rejected Campaign or new-location launch trigger",
   "interface_title": "CampaignClear release desk",
   "primary_panel_title": "Smith Family Dental · Brand + Campaign · gap scorecard: 2 hard gaps open",
   "primary_panel_body": "Open pack run: extract the website and sample messages, score against the Twilio/TCR rejection-code checklist, then stage the Approval Completeness Pack for analyst release.",
   "side_panel_title": "Before this ships",
   "side_panel_items": [
    "Privacy-policy SMS clause confirmed",
    "EIN legal-name match checked",
    "Evidence Index row staged"
   ],
   "status_metric": "REVIEW",
   "status_label": "release gate active"
  },
  "language": {
   "problem_heading": "The SMS Operations Coordinator moment",
   "mechanism_heading": "Inside the CampaignClear Desk",
   "proof_heading": "Why this survives a carrier vetting review",
   "offer_heading": "What leaves the room",
   "objection_heading": "The hard questions",
   "qualification_heading": "Who should not use this",
   "cta_close": "Open a pack run from your most recent rejection notice and website content — released by a real registration analyst, paused for outside-counsel referral when a genuine legal question is open."
  },
  "modules": [
   {
    "name": "Brand intake",
    "job": "Turns an uploaded rejection notice, EIN, and website URLs into a named pack run with a Brand+Campaign match, extracted fields, and a missing-evidence list.",
    "artifact": "triage record"
   },
   {
    "name": "Gap scorecard",
    "job": "Holds the line-by-line comparison of every required Twilio/TCR checklist item against the evidence on file, flagging hard gaps with the code and evidence pointer behind each.",
    "artifact": "gap scorecard worksheet"
   },
   {
    "name": "Completeness Pack",
    "job": "Packages the gap scorecard, redlined privacy clause, message flow, sample messages, and dated Evidence Index into the record a CSP can review without a meeting.",
    "artifact": "release package"
   }
  ],
  "checkpoints": [
   {
    "label": "rejection-code checklist item",
    "pass": "extracted with source citation",
    "fail": "chased or shipped as explicit gap"
   },
   {
    "label": "hard-gap rule",
    "pass": "deterministic gate, evidence-pointer cited",
    "fail": "blocked before release"
   },
   {
    "label": "Completeness Pack",
    "pass": "registration analyst releases",
    "fail": "stays draft or declines"
   }
  ],
  "signature_scene": "You're the office manager at Smith Family Dental. A rejection notice landed last week citing code 30909, and the agency that submitted the original Campaign isn't returning calls. Someone needs to know today whether that's a five-minute privacy-clause fix or a real gap, and the only paper trail is a rejection email and a website nobody has re-read since launch. This page is built like the signal registry desk that person needed before the next text was due to go out."
 },
 "ddd": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "project_name": "CampaignClear",
  "business_understanding": {
   "summary": "CampaignClear — On CampaignClear, multifamily and commercial owners stop guessing whether their SMS Campaign Brand & Campaign TCR registration (TCR profile) will survive an carrier vetting review. Vendor TCR profiles, service logs, callbacks, and inspection reports are extracted at intake, checked against a jurisdiction-specific TCR Brand & Campaign vetting checklist checklist in deterministic code, and every Completeness Pack releases with a dated, cited Evidence Index.",
   "customer_profile": "regional multifamily / mixed-use property managers and mid-size owners with 3-40 SMS-sending assets in high-enforcement CSPs (beachhead: Twilio-anchored senders; secondary: Telnyx/Bandwidth-anchored senders)",
   "customer_pain": "Most owners have never reviewed their own TCR profile. A missing, generic, or inaccessible TCR profile is treated by the TCR as an inspection-failure condition independent of equipment condition; the TCR profile can 'walk' with an outgoing vendor; five-year maintenance/callback/use-case-sample records are scattered across 2-4 vendors; nobody has a released, checklist-cited proof of completeness before an inspection, insurer request, or vendor change.",
   "paid_outcome": "A specialist-released A2P 10DLC Approval Completeness Pack per building (or per-Brand+Campaign registration add-on): gap matrix mapped to TCR Brand & Campaign vetting checklist / TCR checklist, evidence inventory, punch list, vendor resubmit kit, accessibility-instruction template, and a dated Evidence Index — plus an optional Managed Rejection Cure & Resubmit Desk and a recurring Portfolio Desk with quarterly re-scans.",
   "value_creation": "AI compresses OCR, TCR-checklist matching, gap scoring, and chase-letter drafting; deterministic code owns every hard-fail gate (no TCR profile, no on-site accessibility instructions, retention under five years, missing use-case samples); a registration analyst releases the pack for green/yellow packs and a customer's outside counsel (referral only) is engaged only for no registration on file or contested code interpretation; the platform binds them with an append-only audit trail and a dated Evidence Index.",
   "why_ai_native": "The extract-score-release-chase loop is only economical with a bounded AI layer feeding deterministic rules. A pure-manual audit service cannot hit $1,450-$2,850 pack pricing at the cycle times owners need before an inspection; a pure-automated SaaS tracker cannot chase vendors, hold the release gate, or absorb the judgment calls (missing TCR profile, contested code citation) that keep the pack defensible.",
   "operational_risks": [
    "Registration analyst bottleneck during high-enforcement season (Twilio 2026 rule awareness spike)",
    "CSP ruleset mismatch causing a false hard-fail",
    "OEM/vendor refusal to share TCR profile or service logs",
    "Fabricated or hallucinated log dates in a released pack",
    "DeviceClear brand confusion undermining positioning"
   ],
   "assumptions": [
    "The target audience will pay for a released, checklist-cited documentation-completeness pack over a free vendor-supplied PDF.",
    "A Completeness Pack can be reconstructed from an owner-supplied evidence set within the standard 7-business-day cycle.",
    "The vertical tolerates AI-assisted extraction and drafting when compliance-analyst review is explicit and audit-traceable.",
    "Logical per-tenant isolation with row-level auth is acceptable for the first cohort — single-tenant infrastructure is not required.",
    "Twilio-anchored senders and Telnyx/Bandwidth enforcement signals generalize to other high-enforcement CSPs as the rule library expands."
   ],
   "validation_questions": [
    "Which customer's outside counsel (referral only) will sign red (missing-TCR profile or contested-citation) packs?",
    "Which CSP rulesets are in scope for launch beyond Twilio and Telnyx/Bandwidth?",
    "What is the actual willingness-to-pay once a Gap Scan shows a generic or incomplete TCR profile?",
    "Which vendor invoice / CMMS systems must intake integrate with on day one?",
    "Is there a data-residency or client-owned-evidence archive constraint given litigation-discovery risk?"
   ]
  },
  "domain_discovery": {
   "actors": [
    {
     "actor": "Customer operator",
     "role": "SMS operations coordinator / agency media buyer or property manager who herds Twilio/Telnyx/Bandwidth/Vonage vendors",
     "goals": [
      "Prove TCR profile + five-year documentation readiness before the next inspection",
      "Keep the TCR profile and records with the building when a vendor changes"
     ],
     "decisions": [
      "Submit Brand+Campaign intake",
      "Accept or request revisions on the draft gap matrix",
      "Approve outbound delivery of the Completeness Pack"
     ],
     "pain_points": [
      "Records scattered across 2-4 vendors and formats",
      "No independent proof the TCR profile is equipment-specific",
      "Discovering a hard gap only after a failed inspection"
     ]
    },
    {
     "actor": "Registration analyst",
     "role": "Releases green/yellow Completeness Packs; the everyday human chokepoint",
     "goals": [
      "Release only packs whose claims are evidence-cited",
      "Keep cycle time inside the 7-business-day (5 for rush) standard"
     ],
     "decisions": [
      "Release, request revision, or escalate to a decline or an outside-counsel referral",
      "Confirm resubmission cure evidence closes a hard gap"
     ],
     "pain_points": [
      "Incomplete signup-page photo evidence",
      "Ambiguous AI extraction on non-standard vendor invoice formats",
      "Analyst shortage during high-enforcement season"
     ]
    },
    {
     "actor": "Licensed outside counsel",
     "role": "Authors or certifies a new technical TCR profile when one is missing; interprets contested code citations; advises on alterations/modernization; engaged only on escalation (red packs)",
     "goals": [
      "Release only technically defensible red packs",
      "Avoid being pulled into full VT program consulting scope"
     ],
     "decisions": [
      "Author/certify a missing TCR profile or decline",
      "Interpret a contested TCR code citation"
     ],
     "pain_points": [
      "Perceiving TCR profileEvidence archive as a competitive threat rather than a referral funnel",
      "Scope creep from documentation review into full consulting"
     ]
    },
    {
     "actor": "TCR / Regulator",
     "role": "the Twilio CSP vetting desk, the Telnyx/Bandwidth CSP onboarding track, and other adopting jurisdictions; inspects on demand and treats a missing/incomplete TCR profile as an inspection-failure condition",
     "goals": [
      "Confirm the equipment-specific TCR profile and five-year records exist and are accessible on-site"
     ],
     "decisions": [
      "Accept, cite, or red-tag a Brand+Campaign registration based on TCR profile completeness"
     ],
     "pain_points": [
      "Generic, non-equipment-specific TCR profiles presented as compliant",
      "TCR profiles that walked with an outgoing vendor"
     ]
    },
    {
     "actor": "AI extraction/orchestration layer",
     "role": "OCRs and classifies intake documents, drafts the gap matrix and CSP resubmission memos, scores confidence, escalates on ambiguity; never invents dates, procedures, or citations",
     "goals": [
      "Produce a fully cited gap-matrix draft",
      "Escalate rather than guess on ambiguous equipment or CSP ruleset matches"
     ],
     "decisions": [
      "Draft vs escalate",
      "Which CSP ruleset and checklist cards to cite"
     ],
     "pain_points": [
      "Heterogeneous vendor invoice formats",
      "Sparse signup-page photo evidence"
     ]
    },
    {
     "actor": "Platform admin",
     "role": "Runs the tenant, manages users/integrations (internal, not customer-facing)",
     "goals": [
      "Keep the system safe, observable, and edition-current"
     ],
     "decisions": [
      "Provision users",
      "Rotate secrets and manage feature flags"
     ],
     "pain_points": [
      "Change management across tenants and CSP rulesets"
     ]
    }
   ],
   "glossary": [
    {
     "term": "TCR profile",
     "definition": "The equipment-specific written Brand & Campaign TCR registration required under TCR Brand & Campaign vetting checklist.",
     "used_by": "Customer operator, Registration analyst, Licensed outside counsel",
     "context": "Completeness Pack Fulfillment",
     "example": "\"Does the TCR profile on file name this Brand+Campaign registration's specific equipment, or is it generic boilerplate?\"",
     "notes": "Never abbreviate to a different term; always 'TCR profile.'"
    },
    {
     "term": "Completeness Pack",
     "definition": "The released deliverable for one building/Brand+Campaign registration: gap matrix, evidence inventory, punch list, vendor resubmit kit, accessibility-instruction template, and dated Evidence Index.",
     "used_by": "Customer operator, Registration analyst, Licensed outside counsel",
     "context": "Completeness Pack Fulfillment",
     "example": "\"Ship the Completeness Pack once the analyst releases it.\"",
     "notes": "Immutable once released; corrections go through PackRetraction."
    },
    {
     "term": "Gap matrix",
     "definition": "The line-by-line comparison of required TCR Brand & Campaign vetting checklist / TCR checklist items vs. the evidence that actually exists.",
     "used_by": "AI extraction/orchestration layer, Registration analyst, Licensed outside counsel",
     "context": "Completeness Pack Fulfillment",
     "example": "\"The gap matrix shows callback logs missing for two of the last five years.\"",
     "notes": "Every line cites evidence or is marked an explicit gap; never invented."
    },
    {
     "term": "Hard gap",
     "definition": "A checklist item an TCR treats as an inspection-failure condition: no TCR profile; no on-site accessibility instructions; under five-year retention; missing use-case sample where required.",
     "used_by": "Registration analyst, Licensed outside counsel, Customer operator",
     "context": "Completeness Pack Fulfillment",
     "example": "\"Flag this as a hard gap — the SMS signup page has no accessible TCR profile copy.\"",
     "notes": "Also called hard-fail; distinguish from a soft/administrative gap."
    },
    {
     "term": "Gap Scan",
     "definition": "The free, scored, preview-only lead magnet for one building / up to two SMS-campaigns; not a released pack, not a certificate.",
     "used_by": "Customer operator, AI extraction/orchestration layer",
     "context": "Sales & Intake",
     "example": "\"Run the free Gap Scan before committing to a paid Completeness Pack.\"",
     "notes": "Never call it a certificate or a release."
    },
    {
     "term": "Evidence Index",
     "definition": "The dated, versioned index of every evidence item behind a Completeness Pack.",
     "used_by": "Registration analyst, Customer operator",
     "context": "Completeness Pack Fulfillment",
     "example": "\"The Evidence Index lists every invoice, log, and photo cited in this pack.\"",
     "notes": "Append-only; a retraction adds an entry, it never deletes one."
    },
    {
     "term": "Chase kit / CSP resubmission memo",
     "definition": "The drafted demand-letter templates used to recover missing vendor records.",
     "used_by": "AI extraction/orchestration layer, Registration analyst",
     "context": "Vendor Resubmit Desk",
     "example": "\"Send the CSP resubmission memo for the missing 2023 callback log.\"",
     "notes": "Distinct from an owner action; a resubmission memo targets the vendor, not the owner."
    },
    {
     "term": "Release",
     "definition": "The registration analyst's (or, on escalation, the outside counsel's) signed attestation that a pack is complete and its citations are sourced.",
     "used_by": "Registration analyst, Licensed outside counsel",
     "context": "Release & Quality Assurance",
     "example": "\"Analyst release bound to session + timestamp.\"",
     "notes": "Never 'approval,' never 'certification,' never an ambiguous 'signoff' — always paired with who: 'analyst release' — there is no separate 'counsel-cleared analyst release' tier in this business."
    },
    {
     "term": "Escalation",
     "definition": "Routing a pack from AI drafting or analyst review to the outside counsel; used for 'no TCR profile exists' and contested-interpretation cases.",
     "used_by": "AI extraction/orchestration layer, Registration analyst, Licensed outside counsel",
     "context": "AI Workbench & Extraction",
     "example": "\"Escalate — no TCR profile was ever authored for this Brand+Campaign registration.\"",
     "notes": "Escalation is a hand-off, never a rejection."
    },
    {
     "term": "TCR",
     "definition": "The Campaign Registry / Campaign Service Provider (the Twilio CSP vetting desk, the Telnyx/Bandwidth CSP onboarding track, etc.).",
     "used_by": "All actors",
     "context": "TCR Rule Library & Retrieval",
     "example": "\"This Brand+Campaign registration's TCR adopted the 2025 edition with the networked-control cybersecurity module.\"",
     "notes": "Always cite the adopted edition; edition mismatch is a top risk."
    },
    {
     "term": "Brand+Campaign registration",
     "definition": "One Brand/Campaign unit; a building can have several.",
     "used_by": "All actors",
     "context": "Completeness Pack Fulfillment",
     "example": "\"This building has four Brand+Campaign registrations; two are past the base pack tier.\"",
     "notes": "A pack is priced per building (1-4 Brand+Campaign registrations included)."
    },
    {
     "term": "On-site accessibility instructions",
     "definition": "The requirement that the TCR profile (paper or electronic) is viewable at the SMS signup page / on site, not just at the vendor's office.",
     "used_by": "Customer operator, Registration analyst, TCR / Regulator",
     "context": "Completeness Pack Fulfillment",
     "example": "\"Photo-verify the login instructions posted at the SMS signup page controller.\"",
     "notes": "A missing accessibility instruction is itself a hard gap."
    },
    {
     "term": "Portfolio Desk",
     "definition": "The recurring multi-building subscription (5-40 buildings) with quarterly re-scans.",
     "used_by": "Customer operator, Registration analyst",
     "context": "Portfolio & Recurring Programs",
     "example": "\"Enroll the 18-building portfolio in the Portfolio Desk for quarterly re-scans.\"",
     "notes": "Distinct from a one-time Completeness Pack purchase."
    },
    {
     "term": "Resubmit Desk",
     "definition": "The paid add-on that manages vendor cure-evidence follow-up until hard gaps close.",
     "used_by": "Registration analyst, Customer operator",
     "context": "Vendor Resubmit Desk",
     "example": "\"Purchase the Resubmit Desk to keep chasing the vendor until the callback logs surface.\"",
     "notes": "Priced per open hard-gap cycle."
    },
    {
     "term": "Owner action",
     "definition": "A fact only the building owner can supply, e.g. confirming which vendor currently holds TCR profile custody, or attesting that no TCR profile exists.",
     "used_by": "Customer operator, Compliance & Licensing Governance",
     "context": "Compliance & Licensing Governance",
     "example": "\"Owner action open: confirm which vendor currently has custody of the TCR profile.\"",
     "notes": "Caps the release at yellow while open."
    }
   ],
   "decisions": [
    {
     "decision": "Accept Brand+Campaign intake",
     "who": "Sales & Intake context (rule + operator override)",
     "inputs": [
      "Customer identity",
      "Building + Brand+Campaign registration count",
      "Scope statement (ICP fit)"
     ],
     "rule": "Reject if the building is out of ICP (no SMS-campaigns, or a Class-A tower already retaining a full-service marketing-compliance consultancy) or the scope statement is missing",
     "output": "Brand+Campaign intake accepted event",
     "risk": "Accepting an out-of-scope engagement degrades analyst trust and margin"
    },
    {
     "decision": "Draft vs escalate",
     "who": "AI extraction/orchestration layer",
     "inputs": [
      "Evidence coverage",
      "Confidence score",
      "Equipment / CSP ruleset match certainty"
     ],
     "rule": "Escalate below confidence threshold, on an ambiguous equipment match, or when no TCR profile is found",
     "output": "Draft-ready gap matrix OR escalation event",
     "risk": "A silent low-confidence draft erodes analyst trust"
    },
    {
     "decision": "Release the Completeness Pack",
     "who": "Registration analyst (green/yellow) or Licensed outside counsel (red)",
     "inputs": [
      "Draft gap matrix",
      "Full evidence citations",
      "Hard-gate evaluation results"
     ],
     "rule": "Release only if every gap-matrix line cites a source or an explicit gap, AND every hard gap is either cleared or logged as an open owner action",
     "output": "Pack released event",
     "risk": "Over-broad release erodes the audit trail and inspection defensibility"
    },
    {
     "decision": "Flip release readiness on the microsite / marketing claims",
     "who": "Compliance & Licensing Governance",
     "inputs": [
      "Owner-action ledger status",
      "Evidence closure",
      "Legal review flag"
     ],
     "rule": "Blocked if any owner action is open OR an unresolved release-blocker evidence gap exists",
     "output": "Release-decision event OR blocked-release event",
     "risk": "A premature public claim of inspection-readiness is unretractable in perception"
    },
    {
     "decision": "Retract a delivered Completeness Pack",
     "who": "Legal + Licensed outside counsel",
     "inputs": [
      "Newly discovered fact (e.g. fabricated vendor evidence)",
      "Impact assessment"
     ],
     "rule": "Retract if any released claim is materially wrong OR unsupported by evidence",
     "output": "Retraction event + customer notification",
     "risk": "Delayed retraction compounds litigation-discovery exposure on the evidence archive"
    }
   ],
   "events": [
    {
     "event": "Brand+Campaign registrationIntakeAccepted",
     "meaning": "A building/Brand+Campaign registration batch is now committed to fulfillment",
     "trigger": "Operator or auto-rule accepts the intake",
     "downstream": [
      "Normalization + TCR retrieval scheduled",
      "AI extraction scheduled"
     ]
    },
    {
     "event": "evidenceIngested",
     "meaning": "Enough TCR profile/log/callback/inspection/photo evidence exists to extract",
     "trigger": "Normalization passes the coverage rule",
     "downstream": [
      "Extraction authorized"
     ]
    },
    {
     "event": "gapMatrixDrafted",
     "meaning": "AI extraction produced a cited gap-matrix draft for analyst review",
     "trigger": "Extraction Agent finishes its run",
     "downstream": [
      "Hard-gate evaluation"
     ]
    },
    {
     "event": "hardGatesEvaluated",
     "meaning": "Deterministic rules ran the hard-fail checks against the draft gap matrix",
     "trigger": "Rule engine completes evaluation",
     "downstream": [
      "Analyst queue or decline/counsel-referral escalation"
     ]
    },
    {
     "event": "escalationRaised",
     "meaning": "AI or the analyst could not complete safely",
     "trigger": "Confidence below threshold, no TCR profile found, or contested code interpretation",
     "downstream": [
      "Counsel-referral queue"
     ]
    },
    {
     "event": "packReleased",
     "meaning": "Registration analyst or outside counsel took accountability for the pack",
     "trigger": "Release signature captured",
     "downstream": [
      "Delivery authorized",
      "Audit-log snapshot"
     ]
    },
    {
     "event": "packDelivered",
     "meaning": "Completeness Pack + resubmit kit + Evidence Index handed to the customer",
     "trigger": "Delivery adapter confirms transmit",
     "downstream": [
      "Billing event",
      "Customer notification"
     ]
    },
    {
     "event": "ownerActionResolved",
     "meaning": "A blocking owner-supplied fact is now on file",
     "trigger": "Owner/operator updates the ledger",
     "downstream": [
      "Release-decision recomputation"
     ]
    },
    {
     "event": "hardGapCured",
     "meaning": "Vendor-sourced cure evidence closed a previously flagged hard gap",
     "trigger": "Analyst confirms resubmission cure evidence",
     "downstream": [
      "Gap matrix re-scored"
     ]
    },
    {
     "event": "packRetracted",
     "meaning": "A delivered Completeness Pack is formally withdrawn or corrected",
     "trigger": "Legal jointly files, informed by any outside-counsel guidance on record",
     "downstream": [
      "Customer notification",
      "Audit-log append"
     ]
    }
   ]
  },
  "subdomains": [
   {
    "name": "Completeness Pack Fulfillment (evidence-linked extraction + release)",
    "type": "core",
    "description": "The end-to-end path from Brand+Campaign intake to analyst-released Completeness Pack (paused for outside-counsel referral where a contested legal question exists), with every gap-matrix line cited.",
    "reason": "This is what customers pay for and what an carrier vetting review tests against.",
    "business_value": "Direct revenue and inspection defensibility.",
    "recommendation": "build",
    "ai_involvement": "high",
    "human_involvement": "high",
    "risks": [
     "Hallucinated or invented log lines",
     "Analyst bottleneck during high-enforcement season",
     "Un-reconstructable Evidence Index"
    ],
    "validation_questions": [
     "Can the analyst release in <=5 business days on a rush pack?",
     "Can we reconstruct any past pack's Evidence Index on demand?"
    ]
   },
   {
    "name": "AI Workbench & Extraction (bounded agents + retrieval)",
    "type": "core",
    "description": "The bounded AI layer that OCRs, classifies, drafts the gap matrix, cites evidence, and escalates — never authors a technical TCR profile or a final release unassisted.",
    "reason": "The AI-native competitive edge lives here; misuse here creates every high-severity risk.",
    "business_value": "Cycle-time and margin advantage over full-service consulting.",
    "recommendation": "build",
    "ai_involvement": "high",
    "human_involvement": "medium",
    "risks": [
     "Prompt injection via vendor invoice content",
     "Grounding drift on non-standard vendor formats",
     "Silent low-confidence output"
    ],
    "validation_questions": [
     "What is the acceptance rate of AI-drafted gap matrices by analysts?",
     "What percent of runs escalate correctly on missing-TCR profile or contested-citation cases?"
    ]
   },
   {
    "name": "Release & Quality Assurance (analyst release + counsel-referral pause + retraction)",
    "type": "core",
    "description": "Registration analyst and customer's outside counsel (referral only) release workflow, signature capture, retraction workflow, and audit-log snapshots.",
    "reason": "Release is the trust primitive of the whole business.",
    "business_value": "Defensibility; premium pricing over free vendor PDFs.",
    "recommendation": "build",
    "ai_involvement": "medium",
    "human_involvement": "high",
    "risks": [
     "Release-signature spoofing",
     "Repudiation of a release",
     "Delayed retraction"
    ],
    "validation_questions": [
     "Is every release cryptographically bound to an authenticated session?",
     "Can we replay any past release on demand?"
    ]
   },
   {
    "name": "TCR Rule Library & Retrieval",
    "type": "supporting",
    "description": "Per-jurisdiction CSP ruleset library (Twilio, Telnyx/Bandwidth/VA, expandable) and TCR Brand & Campaign vetting checklist checklist cards feeding the extraction layer.",
    "reason": "Poor or stale TCR retrieval directly causes false hard-fails.",
    "business_value": "Drives extraction and release quality.",
    "recommendation": "build",
    "ai_involvement": "high",
    "human_involvement": "medium",
    "risks": [
     "Stale CSP ruleset after a rule update",
     "Cross-tenant retrieval leakage"
    ],
    "validation_questions": [
     "Is every checklist card dated to its adopted edition?"
    ]
   },
   {
    "name": "Compliance & Licensing Governance",
    "type": "supporting",
    "description": "Owner-action ledger, release-decision policy, licensing-boundary enforcement (AI may extract/classify/gap-score/draft resubmission memos; only the customer's own outside counsel may opine on contested code; the company never inspects, certifies, or practices engineering).",
    "reason": "Cross-cuts every context; owns 'can we publicly claim this is inspection-ready.'",
    "business_value": "Prevents category-level and licensing-boundary failure.",
    "recommendation": "build",
    "ai_involvement": "low",
    "human_involvement": "high",
    "risks": [
     "Premature public claim of inspection-readiness",
     "Mis-selling as engineering / outside counsel services"
    ],
    "validation_questions": [
     "Are all owner actions closed before a public release claim?"
    ]
   },
   {
    "name": "Sales & Intake",
    "type": "supporting",
    "description": "Free Gap Scan lead capture through accepted engagement + scope statement.",
    "reason": "Feeds Fulfillment; not the differentiator, but if broken, nothing else runs.",
    "business_value": "Feeds pipeline via the Gap Scan lead magnet.",
    "recommendation": "build",
    "ai_involvement": "medium",
    "human_involvement": "high",
    "risks": [
     "Accepting an out-of-ICP engagement"
    ],
    "validation_questions": [
     "Do we reject buildings with no SMS-campaigns or Class-A towers already fully staffed?"
    ]
   },
   {
    "name": "Client Onboarding & Tenant Profile",
    "type": "supporting",
    "description": "Tenant provisioning, compliance-analyst-of-record registration, existing TCR profile/evidence-pack import, engagement letter.",
    "reason": "One-time high-touch step per customer.",
    "business_value": "Reduces time-to-first-pack.",
    "recommendation": "build",
    "ai_involvement": "low",
    "human_involvement": "high",
    "risks": [
     "No analyst of record registered before intake opens"
    ],
    "validation_questions": [
     "Is a registration analyst named per tenant before go-live?"
    ]
   },
   {
    "name": "Client Delivery & Success",
    "type": "supporting",
    "description": "Delivery adapter, customer portal, revision loop, Portfolio Desk renewal signal.",
    "reason": "Customer-visible surface; drives retention and Portfolio Desk upsell.",
    "business_value": "Retention.",
    "recommendation": "build",
    "ai_involvement": "low",
    "human_involvement": "medium",
    "risks": [
     "Silent delivery failure on a pack needed before an inspection date"
    ],
    "validation_questions": [
     "Do we alert the customer within 1h of any delivery failure?"
    ]
   },
   {
    "name": "Vendor Resubmit Desk",
    "type": "supporting",
    "description": "Managed vendor cure-evidence follow-up: drafts and tracks resubmission memos until a flagged hard gap closes.",
    "reason": "Monetizes the highest-friction part of the workflow (getting records out of OEM/vendor hands) without becoming unpaid consulting.",
    "business_value": "Add-on revenue ($650-$1,200 per open hard-gap cycle) and rejection cure-rate KPI.",
    "recommendation": "build",
    "ai_involvement": "medium",
    "human_involvement": "medium",
    "risks": [
     "OEM/vendor refusal to share TCR profile/logs",
     "Resubmit Desk scope-creeping into unpaid custom consulting"
    ],
    "validation_questions": [
     "Is the rejection cure rate >=70% within 30 days when the Resubmit Desk is purchased?"
    ]
   },
   {
    "name": "Portfolio & Recurring Programs",
    "type": "supporting",
    "description": "Portfolio Desk subscription covering 5-40 buildings with quarterly re-scans and a rolling scorecard.",
    "reason": "Converts one-time packs into recurring revenue for multi-building owners.",
    "business_value": "Recurring revenue ($899-$2,499/mo).",
    "recommendation": "build",
    "ai_involvement": "low",
    "human_involvement": "medium",
    "risks": [
     "Portfolio Desk scope-creeping into unpaid custom consulting"
    ],
    "validation_questions": [
     "Is the quarterly re-scan cadence actually met per enrolled building?"
    ]
   },
   {
    "name": "Billing & Revenue",
    "type": "generic",
    "description": "Per-pack, Rush, Resubmit Desk, and Portfolio Desk subscription invoicing, dunning, revenue reporting.",
    "reason": "Solved category; do not build.",
    "business_value": "Cash collection.",
    "recommendation": "buy",
    "ai_involvement": "low",
    "human_involvement": "low",
    "risks": [
     "Tax jurisdictional errors"
    ],
    "validation_questions": [
     "Is Stripe Tax sufficient for Twilio + Virginia launch jurisdictions?"
    ]
   },
   {
    "name": "Identity & Access",
    "type": "generic",
    "description": "SSO, MFA, RBAC, session management.",
    "reason": "Solved category.",
    "business_value": "Table stakes.",
    "recommendation": "integrate",
    "ai_involvement": "low",
    "human_involvement": "low",
    "risks": [
     "Role escalation"
    ],
    "validation_questions": [
     "Are roles stored in a dedicated table?"
    ]
   },
   {
    "name": "Analytics & Reporting",
    "type": "supporting",
    "description": "Scan-to-paid, cycle time, rejection cure rate, escalation rate, gross margin, and portfolio-scorecard reporting.",
    "reason": "Drives every operational decision against the brief's KPI targets.",
    "business_value": "Feedback loop.",
    "recommendation": "build",
    "ai_involvement": "low",
    "human_involvement": "low",
    "risks": [
     "Vanity metrics"
    ],
    "validation_questions": [
     "Is scan-to-paid >=25% wired as the north-star?"
    ]
   },
   {
    "name": "External Integrations (Anti-Corruption Layer)",
    "type": "supporting",
    "description": "Adapters to vendor invoice inboxes, SMS-campaign-vendor work-order / CMMS platforms, customer document portals, and other tools with translation to internal domain terms.",
    "reason": "External schemas must never leak into the core.",
    "business_value": "Enables integration without corrupting the model.",
    "recommendation": "build",
    "ai_involvement": "low",
    "human_involvement": "medium",
    "risks": [
     "Silent schema drift"
    ],
    "validation_questions": [
     "Do all external calls pass through an ACL translator?"
    ]
   }
  ],
  "core_domain_analysis": {
   "primary_core": "Completeness Pack Fulfillment (evidence-linked extraction + release)",
   "secondary_cores": [
    "AI Workbench & Extraction (bounded agents + retrieval)",
    "Release & Quality Assurance (analyst release + counsel-referral pause + retraction)"
   ],
   "supporting_may_become_core": [
    "TCR Rule Library & Retrieval (as multi-TCR coverage accumulates)",
    "Vendor Resubmit Desk (as rejection cure-rate becomes a differentiator)"
   ],
   "generic_do_not_distract": [
    "Billing & Revenue",
    "Identity & Access"
   ],
   "rationale": "The paid outcome (analyst-released, evidence-linked Completeness Pack) lives in Fulfillment, but its defensibility depends on AI Workbench & Extraction and Release & Quality Assurance behaving correctly. Treat all three as core; do not dilute engineering time on generic subdomains."
  },
  "bounded_contexts": [
   {
    "name": "Completeness Pack Fulfillment",
    "purpose": "Turn accepted Brand+Campaign intakes into analyst-released Completeness Packs, pausing for outside-counsel referral where a contested legal question exists.",
    "subdomain": "Completeness Pack Fulfillment (core)",
    "type": "core",
    "owned_language": [
     "Brand+Campaign registration",
     "Gap matrix",
     "Hard gap",
     "Completeness Pack",
     "Evidence Index",
     "Escalation"
    ],
    "owns": [
     "Brand+Campaign intake lifecycle",
     "Gap-matrix state",
     "Evidence links",
     "Delivery packet composition"
    ],
    "does_not_own": [
     "Analyst identity",
     "Billing",
     "Public release-claim decision"
    ],
    "primary_actors": [
     "Customer operator",
     "AI extraction/orchestration layer",
     "Registration analyst"
    ],
    "entities": [
     "BrandCampaignIntake",
     "GapMatrix",
     "Completeness Pack",
     "Delivery"
    ],
    "value_objects": [
     "Confidence score",
     "Evidence citation",
     "Delivery address"
    ],
    "aggregates": [
     "BrandCampaignIntakeAggregate",
     "GapMatrixAggregate",
     "CompletenessPackAggregate"
    ],
    "domain_services": [
     "Gap-matrix composer",
     "Delivery adapter"
    ],
    "application_services": [
     "OpenBrandCampaignIntake",
     "IngestEvidence",
     "StartExtractionRun",
     "EvaluateHardGates",
     "DeliverCompletenessPack"
    ],
    "commands": [
     "OpenBrandCampaignIntake",
     "IngestEvidence",
     "StartExtractionRun",
     "EvaluateHardGates",
     "DeliverCompletenessPack"
    ],
    "domain_events": [
     "BrandCampaignIntakeAccepted",
     "EvidenceIngested",
     "GapMatrixDrafted",
     "HardGatesEvaluated",
     "PackDelivered"
    ],
    "policies": [
     "Auto-request release when hard-gate evaluation is complete",
     "Auto-block delivery until release is received"
    ],
    "specifications": [
     "EvidenceCoverageSpec",
     "DeliverabilitySpec"
    ],
    "invariants": [
     "A Completeness Pack cannot be delivered without a valid analyst Release",
     "Every gap-matrix line cites at least one evidence item or is marked an explicit gap"
    ],
    "ai_agents": [
     "Extraction Agent"
    ],
    "human_roles": [
     "Customer operator",
     "Registration analyst"
    ],
    "data_owned": [
     "BrandCampaignIntake",
     "GapMatrix",
     "Completeness Pack",
     "Delivery"
    ],
    "inputs": [
     "Intake payload",
     "Ingested evidence",
     "TCR retrieval hits"
    ],
    "outputs": [
     "Released Completeness Pack",
     "Delivery confirmation"
    ],
    "external_integrations": [
     "Vendor invoice inboxes",
     "SMS Campaign-vendor work-order / CMMS platforms"
    ],
    "risks": [
     "An un-cited gap-matrix line slips into delivery",
     "Delivery adapter fails silently"
    ],
    "interfaces": [
     "-> Release & Quality Assurance (request release)",
     "-> Client Delivery & Success (PackDelivered)",
     "<- AI Workbench & Extraction (GapMatrixDrafted)"
    ]
   },
   {
    "name": "AI Workbench & Extraction",
    "purpose": "Run bounded AI agents that OCR, classify, draft, cite, and escalate.",
    "subdomain": "AI Workbench & Extraction (core)",
    "type": "core",
    "owned_language": [
     "Prompt version",
     "Confidence score",
     "Escalation",
     "Retrieval hit"
    ],
    "owns": [
     "Prompt registry",
     "Extraction run log",
     "Confidence thresholds"
    ],
    "does_not_own": [
     "Evidence sourcing",
     "Analyst release",
     "Business release decisions"
    ],
    "primary_actors": [
     "AI extraction/orchestration layer",
     "Ops (prompt owner)"
    ],
    "entities": [
     "ExtractionRun",
     "PromptVersion",
     "RetrievalHit"
    ],
    "value_objects": [
     "Confidence score",
     "Token budget",
     "Model cost"
    ],
    "aggregates": [
     "ExtractionRunAggregate"
    ],
    "domain_services": [
     "Retrieval router",
     "Output validator",
     "Escalation router"
    ],
    "application_services": [
     "StartAgentRun",
     "ValidateOutput",
     "PublishPromptVersion"
    ],
    "commands": [
     "StartExtractionRun",
     "PublishPromptVersion",
     "SetConfidenceThreshold"
    ],
    "domain_events": [
     "GapMatrixDrafted",
     "EscalationRaised",
     "PromptVersionPublished"
    ],
    "policies": [
     "Escalate on confidence < threshold, no TCR profile found, or contested code interpretation",
     "Never call the model with cross-tenant retrieval context",
     "Reject output failing the structured-output validator"
    ],
    "specifications": [
     "GroundedOutputSpec",
     "TokenBudgetSpec"
    ],
    "invariants": [
     "No extraction output leaves this context without passing OutputValidator",
     "Prompt versions are immutable once published"
    ],
    "ai_agents": [
     "Extraction Agent",
     "Routing & Classification Agent",
     "Eval Agent"
    ],
    "human_roles": [
     "Ops (prompt owner)"
    ],
    "data_owned": [
     "Prompt registry",
     "Extraction run logs",
     "Confidence thresholds"
    ],
    "inputs": [
     "Intake context",
     "TCR retrieval hits",
     "Prompt version"
    ],
    "outputs": [
     "Gap-matrix draft payload",
     "Escalation event",
     "Run trace"
    ],
    "external_integrations": [
     "OpenAI / Anthropic API",
     "TCR Rule Library retrieval index"
    ],
    "risks": [
     "Prompt injection via vendor invoice content",
     "Retrieval leakage across tenants",
     "Silent hallucination of log lines or dates"
    ],
    "interfaces": [
     "-> Completeness Pack Fulfillment (GapMatrixDrafted)",
     "-> Release & Quality Assurance (EscalationRaised)",
     "<- TCR Rule Library & Retrieval (RetrievalHit)"
    ]
   },
   {
    "name": "Release & Quality Assurance",
    "purpose": "Registration analyst release workflow, with a counsel-referral pause, signature capture, retraction workflow, audit-log snapshots.",
    "subdomain": "Release & Quality Assurance (core)",
    "type": "core",
    "owned_language": [
     "Release",
     "Retraction",
     "Analyst session"
    ],
    "owns": [
     "Release log",
     "Analyst queue / counsel-referral queue",
     "Retraction workflow"
    ],
    "does_not_own": [
     "Completeness Pack content",
     "Public release-claim decision"
    ],
    "primary_actors": [
     "Registration analyst",
     "Licensed outside counsel",
     "Legal reviewer"
    ],
    "entities": [
     "Release",
     "PackRetraction",
     "AnalystSession"
    ],
    "value_objects": [
     "Release manifest",
     "Retraction reason"
    ],
    "aggregates": [
     "ReleaseAggregate",
     "PackRetractionAggregate"
    ],
    "domain_services": [
     "Release service",
     "Retraction service"
    ],
    "application_services": [
     "ReleasePack",
     "RejectPack",
     "RetractPack"
    ],
    "commands": [
     "ReleasePack",
     "RetractPack"
    ],
    "domain_events": [
     "PackReleased",
     "PackReleaseRejected",
     "PackRetracted"
    ],
    "policies": [
     "Only only the tenant's registered registration analyst may release, and only after any required outside-counsel guidance is on file for red packs",
     "Retraction requires legal sign-off, informed by any outside-counsel guidance on record"
    ],
    "specifications": [
     "ReleaserAuthoritySpec",
     "RetractionPreconditionsSpec"
    ],
    "invariants": [
     "A Release is bound to a live authenticated session, not a form field",
     "Released Completeness Packs are immutable; corrections go through PackRetraction"
    ],
    "ai_agents": [],
    "human_roles": [
     "Registration analyst",
     "Licensed outside counsel",
     "Legal reviewer"
    ],
    "data_owned": [
     "Releases",
     "Retractions",
     "Analyst sessions"
    ],
    "inputs": [
     "Gap matrix drafted",
     "Escalation payload"
    ],
    "outputs": [
     "Release event",
     "Retraction event"
    ],
    "external_integrations": [
     "IdP (Okta / Google)"
    ],
    "risks": [
     "Release-signature spoofing",
     "Repudiation of a release"
    ],
    "interfaces": [
     "-> Completeness Pack Fulfillment (PackReleased)",
     "-> Compliance & Licensing Governance (PackRetracted)"
    ]
   },
   {
    "name": "TCR Rule Library & Retrieval",
    "purpose": "Own per-jurisdiction CSP ruleset library, TCR Brand & Campaign vetting checklist checklist cards, and retrieval indices feeding extraction.",
    "subdomain": "TCR Rule Library & Retrieval (supporting)",
    "type": "supporting",
    "owned_language": [
     "TCR",
     "CSP ruleset",
     "Checklist card"
    ],
    "owns": [
     "TCR rule sets",
     "Checklist cards",
     "Retrieval indices"
    ],
    "does_not_own": [
     "Prompt versions",
     "Model calls"
    ],
    "primary_actors": [
     "Ops (prompt owner)"
    ],
    "entities": [
     "TCRRuleSet",
     "ChecklistCard",
     "IndexShard"
    ],
    "value_objects": [
     "Edition citation",
     "SourceCitation"
    ],
    "aggregates": [
     "TCRRuleSetAggregate"
    ],
    "domain_services": [
     "Ingestion pipeline",
     "Reindex service"
    ],
    "application_services": [
     "IngestRuleUpdate",
     "Reindex",
     "PurgeStaleEdition"
    ],
    "commands": [
     "IngestRuleUpdate",
     "Reindex",
     "PurgeStaleEdition"
    ],
    "domain_events": [
     "RuleUpdateIngested",
     "IndexRebuilt"
    ],
    "policies": [
     "Retrieval indices partitioned per tenant and per CSP ruleset",
     "Purge cascades to indices within SLA"
    ],
    "specifications": [
     "TenantIsolationSpec",
     "CSPScopeSpec"
    ],
    "invariants": [
     "TCR retrieval is scoped to the checklist edition adopted by the Brand+Campaign registration's jurisdiction"
    ],
    "ai_agents": [],
    "human_roles": [
     "Ops (prompt owner)"
    ],
    "data_owned": [
     "TCR rule sets",
     "Indices"
    ],
    "inputs": [
     "TCR published rule/edition updates",
     "Uploaded checklist source docs"
    ],
    "outputs": [
     "Retrieval hits with citations"
    ],
    "external_integrations": [
     "Blob storage",
     "Search API"
    ],
    "risks": [
     "Cross-tenant retrieval leak",
     "Stale CSP ruleset"
    ],
    "interfaces": [
     "-> AI Workbench & Extraction"
    ]
   },
   {
    "name": "Compliance & Licensing Governance",
    "purpose": "Own the release-readiness decision, owner-action ledger, and licensing-boundary enforcement.",
    "subdomain": "Compliance & Licensing Governance (supporting)",
    "type": "supporting",
    "owned_language": [
     "Owner action",
     "Release decision",
     "Licensing boundary"
    ],
    "owns": [
     "Owner-action ledger",
     "Release-decision policy",
     "Licensing-boundary attestations"
    ],
    "does_not_own": [
     "Completeness Pack content",
     "Analyst identity"
    ],
    "primary_actors": [
     "Business owner / founder",
     "Legal reviewer",
     "Registration analyst"
    ],
    "entities": [
     "OwnerAction",
     "ReleaseDecision",
     "DSARRequest"
    ],
    "value_objects": [
     "Blocker reason",
     "Jurisdiction"
    ],
    "aggregates": [
     "OwnerActionLedgerAggregate"
    ],
    "domain_services": [
     "Release-decision engine",
     "DSAR fulfillment service"
    ],
    "application_services": [
     "ResolveOwnerAction",
     "RecomputeReleaseDecision",
     "ProcessDSAR"
    ],
    "commands": [
     "ResolveOwnerAction",
     "RaiseOwnerAction",
     "ProcessDSAR"
    ],
    "domain_events": [
     "OwnerActionResolved",
     "ReleaseDecisionChanged",
     "DSARFulfilled"
    ],
    "policies": [
     "Block a public release-readiness claim while any owner action is open",
     "DSAR SLA 30 days",
     "AI may extract/classify/gap-score/draft resubmission memos; only a customer's outside counsel (referral only) may author or certify a TCR profile or interpret contested code; the company never inspects, certifies, or practices engineering"
    ],
    "specifications": [
     "ReleaseReadinessSpec",
     "DSARSpec"
    ],
    "invariants": [
     "Release cannot flip to 'ready' with open blocking owner actions"
    ],
    "ai_agents": [],
    "human_roles": [
     "Business owner / founder",
     "Legal reviewer"
    ],
    "data_owned": [
     "Owner-action ledger",
     "Release decisions",
     "DSAR queue"
    ],
    "inputs": [
     "Owner/operator input",
     "Legal review outcome"
    ],
    "outputs": [
     "Release-decision event",
     "DSAR confirmation"
    ],
    "external_integrations": [
     "Email inbox"
    ],
    "risks": [
     "Public release-readiness claim while a blocker is open",
     "Mis-selling as engineering / outside counsel services"
    ],
    "interfaces": [
     "<- Completeness Pack Fulfillment",
     "<- Release & Quality Assurance (PackRetracted)"
    ]
   },
   {
    "name": "Sales & Intake",
    "purpose": "Lead (Gap Scan) -> qualified engagement -> accepted Brand+Campaign intake.",
    "subdomain": "Sales & Intake (supporting)",
    "type": "supporting",
    "owned_language": [
     "Lead",
     "Engagement",
     "Gap Scan"
    ],
    "owns": [
     "Lead pipeline",
     "Engagement letter",
     "Gap Scan requests"
    ],
    "does_not_own": [
     "Fulfillment",
     "Billing"
    ],
    "primary_actors": [
     "Business owner / founder",
     "Customer operator"
    ],
    "entities": [
     "Lead",
     "Engagement"
    ],
    "value_objects": [
     "Scope statement",
     "Pricing offer"
    ],
    "aggregates": [
     "EngagementAggregate"
    ],
    "domain_services": [
     "Scope-fit evaluator"
    ],
    "application_services": [
     "QualifyLead",
     "AcceptEngagement"
    ],
    "commands": [
     "QualifyLead",
     "AcceptEngagement"
    ],
    "domain_events": [
     "EngagementAccepted"
    ],
    "policies": [
     "Reject out-of-ICP engagement (no SMS-campaigns, or fully staffed Class-A tower)",
     "Engagement letter required before intake"
    ],
    "specifications": [
     "ScopeFitSpec"
    ],
    "invariants": [
     "Cannot open a Brand+Campaign intake without an accepted engagement"
    ],
    "ai_agents": [],
    "human_roles": [
     "Business owner / founder"
    ],
    "data_owned": [
     "Leads",
     "Engagements"
    ],
    "inputs": [
     "Gap Scan upload",
     "Discovery notes"
    ],
    "outputs": [
     "Accepted engagement event"
    ],
    "external_integrations": [
     "CRM",
     "Email inbox"
    ],
    "risks": [
     "Accepting an out-of-scope engagement"
    ],
    "interfaces": [
     "-> Client Onboarding & Tenant Profile",
     "-> Completeness Pack Fulfillment (intake enablement)"
    ]
   },
   {
    "name": "Client Onboarding & Tenant Profile",
    "purpose": "Provision the tenant, capture the compliance-analyst-of-record, import any existing TCR profile/evidence pack.",
    "subdomain": "Client Onboarding & Tenant Profile (supporting)",
    "type": "supporting",
    "owned_language": [
     "Tenant",
     "Analyst of record",
     "Evidence pack import"
    ],
    "owns": [
     "Tenant provisioning",
     "Analyst-of-record record",
     "Evidence pack import"
    ],
    "does_not_own": [
     "Release capture",
     "Delivery"
    ],
    "primary_actors": [
     "Onboarding lead",
     "Customer admin"
    ],
    "entities": [
     "Tenant",
     "AnalystOfRecord",
     "EvidencePackImport"
    ],
    "value_objects": [
     "Contact matrix",
     "TCR set"
    ],
    "aggregates": [
     "TenantAggregate"
    ],
    "domain_services": [
     "Tenant provisioner"
    ],
    "application_services": [
     "ProvisionTenant",
     "RegisterAnalystOfRecord",
     "ImportEvidencePack"
    ],
    "commands": [
     "ProvisionTenant",
     "RegisterAnalystOfRecord",
     "ImportEvidencePack"
    ],
    "domain_events": [
     "TenantProvisioned",
     "AnalystOfRecordRegistered"
    ],
    "policies": [
     "No intake opens until a registration analyst of record is registered per tenant"
    ],
    "specifications": [
     "AnalystCredentialSpec"
    ],
    "invariants": [
     "Every tenant has at least one named registration analyst of record on file"
    ],
    "ai_agents": [],
    "human_roles": [
     "Onboarding lead"
    ],
    "data_owned": [
     "Tenants",
     "Analyst-of-record records",
     "Evidence pack imports"
    ],
    "inputs": [
     "Engagement",
     "Customer-supplied evidence pack"
    ],
    "outputs": [
     "Provisioned tenant"
    ],
    "external_integrations": [
     "IdP",
     "Google Drive / S3"
    ],
    "risks": [
     "No analyst of record before go-live"
    ],
    "interfaces": [
     "-> Completeness Pack Fulfillment"
    ]
   },
   {
    "name": "Client Delivery & Success",
    "purpose": "Deliver released packs, own the customer surface, drive Portfolio Desk renewal.",
    "subdomain": "Client Delivery & Success (supporting)",
    "type": "supporting",
    "owned_language": [
     "Delivery",
     "Revision request",
     "Renewal signal"
    ],
    "owns": [
     "Customer portal",
     "Delivery log",
     "Revision workflow"
    ],
    "does_not_own": [
     "Released content",
     "Billing"
    ],
    "primary_actors": [
     "Customer operator",
     "Success lead"
    ],
    "entities": [
     "DeliveryReceipt",
     "RevisionRequest"
    ],
    "value_objects": [
     "Delivery method",
     "NPS signal"
    ],
    "aggregates": [
     "DeliveryAggregate"
    ],
    "domain_services": [
     "Delivery adapter"
    ],
    "application_services": [
     "ConfirmDelivery",
     "RecordRevisionRequest"
    ],
    "commands": [
     "ConfirmDelivery",
     "RecordRevisionRequest"
    ],
    "domain_events": [
     "DeliveryConfirmed",
     "RevisionRequested"
    ],
    "policies": [
     "Alert customer within 1h of any delivery failure"
    ],
    "specifications": [
     "DeliveryAcknowledgmentSpec"
    ],
    "invariants": [
     "Every DeliveryConfirmed has a linked Release"
    ],
    "ai_agents": [
     "Success Copilot (assist only)"
    ],
    "human_roles": [
     "Success lead"
    ],
    "data_owned": [
     "Deliveries",
     "Revision requests"
    ],
    "inputs": [
     "Released Completeness Pack",
     "Customer feedback"
    ],
    "outputs": [
     "Delivery confirmation",
     "Revision request"
    ],
    "external_integrations": [
     "Email",
     "Customer portal"
    ],
    "risks": [
     "Silent delivery failure ahead of an inspection date"
    ],
    "interfaces": [
     "<- Completeness Pack Fulfillment",
     "-> Portfolio & Recurring Programs",
     "-> Billing & Revenue"
    ]
   },
   {
    "name": "Vendor Resubmit Desk",
    "purpose": "Manage the paid vendor cure-evidence follow-up until flagged hard gaps close.",
    "subdomain": "Vendor Resubmit Desk (supporting)",
    "type": "supporting",
    "owned_language": [
     "Chase kit",
     "Vendor resubmission memo",
     "Resubmit Desk"
    ],
    "owns": [
     "Vendor chase cases",
     "Chase letter templates",
     "Cure-evidence log"
    ],
    "does_not_own": [
     "Gap-matrix release",
     "Billing"
    ],
    "primary_actors": [
     "Registration analyst",
     "AI extraction/orchestration layer"
    ],
    "entities": [
     "VendorChaseCase",
     "ChaseLetter"
    ],
    "value_objects": [
     "Chase cadence",
     "Cure-evidence citation"
    ],
    "aggregates": [
     "VendorChaseCaseAggregate"
    ],
    "domain_services": [
     "Chase-letter drafter",
     "Cure-evidence validator"
    ],
    "application_services": [
     "DispatchChaseLetter",
     "ConfirmVendorCure"
    ],
    "commands": [
     "DispatchChaseLetter",
     "ConfirmVendorCure"
    ],
    "domain_events": [
     "ChaseLetterDispatched",
     "RejectionCured"
    ],
    "policies": [
     "Open a vendor chase case only for a vendor-attributable hard gap on a paid Resubmit Desk cycle",
     "A hard gap cannot be marked cured without vendor-sourced cure evidence"
    ],
    "specifications": [
     "CureEvidenceSpec"
    ],
    "invariants": [
     "A hard gap cannot be marked cured without vendor-sourced cure evidence citing the original clause"
    ],
    "ai_agents": [
     "Extraction Agent"
    ],
    "human_roles": [
     "Registration analyst"
    ],
    "data_owned": [
     "Vendor chase cases",
     "Chase letters"
    ],
    "inputs": [
     "Flagged hard gap",
     "Vendor response"
    ],
    "outputs": [
     "Chase letter",
     "Cure confirmation"
    ],
    "external_integrations": [
     "Email",
     "SMS Campaign-vendor work-order / CMMS platforms"
    ],
    "risks": [
     "OEM/vendor refusal to share TCR profile/logs",
     "Resubmit Desk scope-creeping into unpaid custom consulting"
    ],
    "interfaces": [
     "<- Completeness Pack Fulfillment (HardGatesEvaluated)",
     "-> Completeness Pack Fulfillment (gap matrix re-score)"
    ]
   },
   {
    "name": "Portfolio & Recurring Programs",
    "purpose": "Own the Portfolio Desk subscription: 5-40 buildings, quarterly re-scans, rolling scorecard.",
    "subdomain": "Portfolio & Recurring Programs (supporting)",
    "type": "supporting",
    "owned_language": [
     "Portfolio Desk",
     "Quarterly re-scan"
    ],
    "owns": [
     "Portfolio enrollment",
     "Re-scan schedule",
     "Portfolio scorecard"
    ],
    "does_not_own": [
     "Individual pack release",
     "Billing"
    ],
    "primary_actors": [
     "Success lead",
     "Customer operator"
    ],
    "entities": [
     "Portfolio",
     "ReScanSchedule"
    ],
    "value_objects": [
     "Cadence",
     "Scorecard snapshot"
    ],
    "aggregates": [
     "PortfolioAggregate"
    ],
    "domain_services": [
     "Re-scan scheduler"
    ],
    "application_services": [
     "EnrollPortfolio",
     "ScheduleQuarterlyReScan"
    ],
    "commands": [
     "EnrollPortfolio",
     "ScheduleQuarterlyReScan"
    ],
    "domain_events": [
     "PortfolioEnrolled",
     "ReScanScheduled"
    ],
    "policies": [
     "Quarterly re-scan is mandatory for every enrolled building",
     "Enrollment capped at 40 buildings per Portfolio Desk subscription"
    ],
    "specifications": [
     "ReScanCadenceSpec"
    ],
    "invariants": [
     "Every enrolled building has a non-lapsed quarterly re-scan schedule"
    ],
    "ai_agents": [],
    "human_roles": [
     "Success lead"
    ],
    "data_owned": [
     "Portfolios",
     "Re-scan schedules"
    ],
    "inputs": [
     "Enrollment request",
     "Prior Completeness Packs"
    ],
    "outputs": [
     "Portfolio scorecard",
     "New Brand+Campaign intake batch"
    ],
    "external_integrations": [
     "Customer portal"
    ],
    "risks": [
     "Portfolio Desk scope-creeping into unpaid custom consulting"
    ],
    "interfaces": [
     "-> Completeness Pack Fulfillment (new intake batch)",
     "<- Client Delivery & Success"
    ]
   },
   {
    "name": "Billing & Revenue",
    "purpose": "Invoicing, subscription management, dunning, revenue reporting across all pricing tiers.",
    "subdomain": "Billing & Revenue (generic)",
    "type": "generic",
    "owned_language": [
     "Invoice",
     "Subscription",
     "Usage record"
    ],
    "owns": [
     "Invoices",
     "Subscriptions",
     "Usage records"
    ],
    "does_not_own": [
     "Fulfillment",
     "Release"
    ],
    "primary_actors": [
     "Finance",
     "Customer admin"
    ],
    "entities": [
     "Subscription",
     "Invoice",
     "UsageRecord"
    ],
    "value_objects": [
     "Line item",
     "Tax jurisdiction"
    ],
    "aggregates": [
     "SubscriptionAggregate"
    ],
    "domain_services": [
     "Billing adapter"
    ],
    "application_services": [
     "ChargeSubscription",
     "RecordUsage"
    ],
    "commands": [
     "ChargeSubscription",
     "RecordUsage"
    ],
    "domain_events": [
     "InvoicePaid",
     "SubscriptionCanceled"
    ],
    "policies": [
     "Meter delivered Completeness Packs for per-pack pricing"
    ],
    "specifications": [
     "ChargeabilitySpec"
    ],
    "invariants": [
     "No charge without a delivered Completeness Pack when priced per pack"
    ],
    "ai_agents": [],
    "human_roles": [
     "Finance"
    ],
    "data_owned": [
     "Subscriptions",
     "Invoices"
    ],
    "inputs": [
     "Delivery events"
    ],
    "outputs": [
     "Invoice records"
    ],
    "external_integrations": [
     "Stripe"
    ],
    "risks": [
     "Tax jurisdictional errors"
    ],
    "interfaces": [
     "<- Client Delivery & Success"
    ]
   },
   {
    "name": "Identity & Access",
    "purpose": "SSO, MFA, RBAC, session management.",
    "subdomain": "Identity & Access (generic)",
    "type": "generic",
    "owned_language": [
     "User",
     "Role",
     "Session"
    ],
    "owns": [
     "Users",
     "Roles table",
     "Sessions"
    ],
    "does_not_own": [
     "Business capability decisions"
    ],
    "primary_actors": [
     "Platform admin",
     "User"
    ],
    "entities": [
     "User",
     "RoleAssignment",
     "Session"
    ],
    "value_objects": [
     "Role",
     "Claim"
    ],
    "aggregates": [
     "UserAggregate"
    ],
    "domain_services": [
     "Auth service"
    ],
    "application_services": [
     "SignIn",
     "AssignRole"
    ],
    "commands": [
     "SignIn",
     "AssignRole"
    ],
    "domain_events": [
     "UserSignedIn",
     "RoleAssigned"
    ],
    "policies": [
     "Roles in a dedicated table, checked server-side"
    ],
    "specifications": [
     "RoleAuthoritySpec"
    ],
    "invariants": [
     "No role check runs client-only"
    ],
    "ai_agents": [],
    "human_roles": [
     "Platform admin"
    ],
    "data_owned": [
     "Users",
     "Roles",
     "Sessions"
    ],
    "inputs": [
     "Auth events"
    ],
    "outputs": [
     "Sessions"
    ],
    "external_integrations": [
     "IdP (Google / Okta)"
    ],
    "risks": [
     "Role escalation"
    ],
    "interfaces": [
     "-> every other context"
    ]
   },
   {
    "name": "Analytics & Reporting",
    "purpose": "Operational + business metrics, outcome reports against the brief's KPI targets.",
    "subdomain": "Analytics & Reporting (supporting)",
    "type": "supporting",
    "owned_language": [
     "Metric",
     "Dashboard",
     "Outcome report"
    ],
    "owns": [
     "Metric definitions",
     "Dashboards"
    ],
    "does_not_own": [
     "Raw write models"
    ],
    "primary_actors": [
     "Ops lead",
     "Business owner / founder"
    ],
    "entities": [
     "MetricDefinition",
     "Dashboard"
    ],
    "value_objects": [
     "Window",
     "Target"
    ],
    "aggregates": [
     "MetricDefinitionAggregate"
    ],
    "domain_services": [
     "Rollup service"
    ],
    "application_services": [
     "PublishMetric",
     "PublishDashboard"
    ],
    "commands": [
     "PublishMetric",
     "PublishDashboard"
    ],
    "domain_events": [
     "DashboardPublished"
    ],
    "policies": [
     "North-star (scan-to-paid) must be wired before Phase 2 launch"
    ],
    "specifications": [
     "MetricDefinedSpec"
    ],
    "invariants": [
     "Metrics have a definition, a target, and an owner"
    ],
    "ai_agents": [],
    "human_roles": [
     "Ops lead"
    ],
    "data_owned": [
     "Metric definitions",
     "Read-model rollups"
    ],
    "inputs": [
     "Domain events (as read-only consumer)"
    ],
    "outputs": [
     "Dashboards",
     "Outcome reports"
    ],
    "external_integrations": [
     "BI tool"
    ],
    "risks": [
     "Vanity metrics dominating"
    ],
    "interfaces": [
     "<- every context (read-only)"
    ]
   }
  ],
  "context_map": [
   {
    "upstream": "Sales & Intake",
    "downstream": "Completeness Pack Fulfillment",
    "pattern": "customer-supplier",
    "business_reason": "Fulfillment cannot start without an accepted engagement.",
    "data_exchanged": [
     "Engagement",
     "Scope statement"
    ],
    "events_exchanged": [
     "EngagementAccepted"
    ],
    "contract_type": "Published language (Engagement record)",
    "failure_risks": [
     "Silent scope mismatch"
    ],
    "acl_notes": "Fulfillment consumes only fields it needs; no direct DB coupling.",
    "ownership_boundary": "Sales owns engagement lifecycle."
   },
   {
    "upstream": "Completeness Pack Fulfillment",
    "downstream": "Release & Quality Assurance",
    "pattern": "customer-supplier",
    "business_reason": "Release is a hard gate on delivery.",
    "data_exchanged": [
     "GapMatrix",
     "Evidence trail"
    ],
    "events_exchanged": [
     "GapMatrixDrafted",
     "PackReleased"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Analyst bottleneck"
    ],
    "acl_notes": "QA never mutates gap-matrix content; only appends a release.",
    "ownership_boundary": "QA owns the release log."
   },
   {
    "upstream": "AI Workbench & Extraction",
    "downstream": "Completeness Pack Fulfillment",
    "pattern": "customer-supplier",
    "business_reason": "The gap-matrix draft is produced by AI; Fulfillment consumes it.",
    "data_exchanged": [
     "Gap-matrix draft payload",
     "Confidence score"
    ],
    "events_exchanged": [
     "GapMatrixDrafted",
     "EscalationRaised"
    ],
    "contract_type": "Published language (validated schema)",
    "failure_risks": [
     "A draft failing OutputValidator reaches Fulfillment"
    ],
    "acl_notes": "OutputValidator sits inside AI Workbench & Extraction.",
    "ownership_boundary": "AI owns the run log; Fulfillment owns gap-matrix state."
   },
   {
    "upstream": "TCR Rule Library & Retrieval",
    "downstream": "AI Workbench & Extraction",
    "pattern": "open-host-service",
    "business_reason": "TCR retrieval is a stable interface used by all agents.",
    "data_exchanged": [
     "Retrieval hits",
     "Edition citations"
    ],
    "events_exchanged": [
     "RuleUpdateIngested",
     "IndexRebuilt"
    ],
    "contract_type": "Open-host published API",
    "failure_risks": [
     "Cross-tenant leak",
     "Stale CSP ruleset"
    ],
    "acl_notes": "Every call carries tenant + TCR-edition claim.",
    "ownership_boundary": "TCR Rule Library owns indices."
   },
   {
    "upstream": "Client Onboarding & Tenant Profile",
    "downstream": "Completeness Pack Fulfillment",
    "pattern": "customer-supplier",
    "business_reason": "No intake without a provisioned tenant + analyst of record.",
    "data_exchanged": [
     "Tenant profile",
     "Analyst-of-record identity"
    ],
    "events_exchanged": [
     "TenantProvisioned",
     "AnalystOfRecordRegistered"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "No analyst of record on file"
    ],
    "acl_notes": "Fulfillment reads a projection; does not query Onboarding tables.",
    "ownership_boundary": "Onboarding owns tenant + analyst-of-record records."
   },
   {
    "upstream": "Completeness Pack Fulfillment",
    "downstream": "Client Delivery & Success",
    "pattern": "customer-supplier",
    "business_reason": "Delivery is downstream of release.",
    "data_exchanged": [
     "Released Completeness Pack"
    ],
    "events_exchanged": [
     "PackDelivered",
     "DeliveryConfirmed"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Silent delivery failure"
    ],
    "acl_notes": "Delivery adapter is inside Fulfillment; Delivery context tracks the receipt.",
    "ownership_boundary": "Delivery context owns receipts."
   },
   {
    "upstream": "Release & Quality Assurance",
    "downstream": "Compliance & Licensing Governance",
    "pattern": "customer-supplier",
    "business_reason": "Retractions feed compliance and licensing-boundary workflows.",
    "data_exchanged": [
     "Retraction record"
    ],
    "events_exchanged": [
     "PackRetracted"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Retraction not surfaced"
    ],
    "acl_notes": "Compliance subscribes to the event stream.",
    "ownership_boundary": "QA owns the retraction record; Compliance owns the downstream runbook."
   },
   {
    "upstream": "Compliance & Licensing Governance",
    "downstream": "Completeness Pack Fulfillment",
    "pattern": "conformist",
    "business_reason": "Fulfillment must respect release-readiness decisions.",
    "data_exchanged": [
     "Release decision"
    ],
    "events_exchanged": [
     "ReleaseDecisionChanged"
    ],
    "contract_type": "Read-only projection consumed by Fulfillment",
    "failure_risks": [
     "Fulfillment ignoring a blocked release-readiness claim"
    ],
    "acl_notes": "Fulfillment conforms to Compliance's release model.",
    "ownership_boundary": "Compliance owns the release model."
   },
   {
    "upstream": "Completeness Pack Fulfillment",
    "downstream": "Vendor Resubmit Desk",
    "pattern": "customer-supplier",
    "business_reason": "A flagged, vendor-attributable hard gap opens a chase case.",
    "data_exchanged": [
     "Hard-gap flag",
     "Vendor contact"
    ],
    "events_exchanged": [
     "HardGatesEvaluated"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Chase case opened on a non-vendor-attributable gap"
    ],
    "acl_notes": "Resubmit Desk reads a projection of the gap matrix; does not mutate it.",
    "ownership_boundary": "Vendor Resubmit Desk owns chase cases."
   },
   {
    "upstream": "Vendor Resubmit Desk",
    "downstream": "Completeness Pack Fulfillment",
    "pattern": "customer-supplier",
    "business_reason": "Cure evidence must flow back into a gap-matrix re-score.",
    "data_exchanged": [
     "Cure evidence"
    ],
    "events_exchanged": [
     "RejectionCured"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Cure evidence not reflected in the re-score"
    ],
    "acl_notes": "Fulfillment re-runs hard-gate evaluation on RejectionCured.",
    "ownership_boundary": "Resubmit Desk owns cure evidence; Fulfillment owns the re-score."
   },
   {
    "upstream": "Client Delivery & Success",
    "downstream": "Portfolio & Recurring Programs",
    "pattern": "customer-supplier",
    "business_reason": "Renewal signal from delivered packs feeds Portfolio Desk enrollment.",
    "data_exchanged": [
     "Renewal signal"
    ],
    "events_exchanged": [
     "DeliveryConfirmed"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Missed upsell signal"
    ],
    "acl_notes": "Portfolio & Recurring Programs subscribes to delivery events.",
    "ownership_boundary": "Portfolio owns enrollment + re-scan schedule."
   },
   {
    "upstream": "Client Delivery & Success",
    "downstream": "Billing & Revenue",
    "pattern": "customer-supplier",
    "business_reason": "Delivery is the meter for per-pack pricing.",
    "data_exchanged": [
     "Delivery receipt"
    ],
    "events_exchanged": [
     "DeliveryConfirmed"
    ],
    "contract_type": "Published language",
    "failure_risks": [
     "Missed usage record"
    ],
    "acl_notes": "Billing subscribes to delivery events.",
    "ownership_boundary": "Billing owns invoicing."
   },
   {
    "upstream": "Identity & Access",
    "downstream": "every other context",
    "pattern": "shared-kernel",
    "business_reason": "Auth primitives are shared.",
    "data_exchanged": [
     "Session claim",
     "Role"
    ],
    "events_exchanged": [],
    "contract_type": "Shared kernel (tiny, versioned)",
    "failure_risks": [
     "Kernel bloat"
    ],
    "acl_notes": "Kernel kept intentionally small.",
    "ownership_boundary": "Identity owns the primitives."
   },
   {
    "upstream": "every context",
    "downstream": "Analytics & Reporting",
    "pattern": "conformist",
    "business_reason": "Analytics conforms to whatever events contexts publish.",
    "data_exchanged": [
     "Domain events (read-only)"
    ],
    "events_exchanged": [
     "all"
    ],
    "contract_type": "Read-only event subscription",
    "failure_risks": [
     "Event schema drift"
    ],
    "acl_notes": "Analytics stores its own read model.",
    "ownership_boundary": "Analytics owns rollups."
   }
  ],
  "external_integrations": [
   {
    "system": "Vendor invoice inboxes",
    "risk": "Schema drift; silent field rename; rate limits",
    "internal_model": "evidence citation record or chase notification",
    "acl_strategy": "Adapter in External Integrations context translates external schema -> internal domain term; upstream schema never leaks past the adapter.",
    "owner_context": "External Integrations",
    "data_in": [
     "External record"
    ],
    "data_out": [
     "Ack or receipt"
    ],
    "trigger": "api",
    "failure_strategy": "Exponential backoff with jitter; circuit breaker on repeated failure; dead-letter with owner-visible alert.",
    "audit_need": "Every call logged with tenant, request id, cost, and payload hash (no PII in logs)."
   },
   {
    "system": "SMS Campaign-vendor work-order / CMMS platforms",
    "risk": "Schema drift; silent field rename; rate limits",
    "internal_model": "evidence citation record or notification",
    "acl_strategy": "Adapter in External Integrations context translates external schema -> internal domain term; upstream schema never leaks past the adapter.",
    "owner_context": "External Integrations",
    "data_in": [
     "External record"
    ],
    "data_out": [
     "Ack or receipt"
    ],
    "trigger": "api",
    "failure_strategy": "Exponential backoff with jitter; circuit breaker on repeated failure; dead-letter with owner-visible alert.",
    "audit_need": "Every call logged with tenant, request id, cost, and payload hash (no PII in logs)."
   },
   {
    "system": "Customer document portals",
    "risk": "Schema drift; silent field rename; rate limits",
    "internal_model": "evidence citation record or notification",
    "acl_strategy": "Adapter in External Integrations context translates external schema -> internal domain term; upstream schema never leaks past the adapter.",
    "owner_context": "External Integrations",
    "data_in": [
     "External record"
    ],
    "data_out": [
     "Ack or receipt"
    ],
    "trigger": "api",
    "failure_strategy": "Exponential backoff with jitter; circuit breaker on repeated failure; dead-letter with owner-visible alert.",
    "audit_need": "Every call logged with tenant, request id, cost, and payload hash (no PII in logs)."
   },
   {
    "system": "OpenAI / Anthropic API",
    "risk": "Prompt-injection surface; token cost blowout; provider outage",
    "internal_model": "Gap-matrix draft payload with confidence score + validated schema",
    "acl_strategy": "OutputValidator + prompt-injection scrubber + per-tenant retrieval scope inside AI Workbench & Extraction.",
    "owner_context": "AI Workbench & Extraction",
    "data_in": [
     "Prompt + retrieval context"
    ],
    "data_out": [
     "Draft + confidence"
    ],
    "trigger": "api",
    "failure_strategy": "Exponential backoff with jitter; circuit breaker on repeated failure; dead-letter with owner-visible alert.",
    "audit_need": "Every call logged with tenant, request id, cost, and payload hash (no PII in logs)."
   }
  ],
  "event_storm": [
   {
    "seq": 1,
    "command": "QualifyLead",
    "event": "LeadQualified",
    "actor": "Business owner / founder",
    "context": "Sales & Intake",
    "aggregate": "EngagementAggregate",
    "policy": "Reject out-of-ICP",
    "downstream": "Engagement offer",
    "risk": "Out-of-scope acceptance"
   },
   {
    "seq": 2,
    "command": "AcceptEngagement",
    "event": "EngagementAccepted",
    "actor": "Customer operator",
    "context": "Sales & Intake",
    "aggregate": "EngagementAggregate",
    "policy": "Engagement letter required",
    "downstream": "Onboarding starts",
    "risk": "Missing engagement letter"
   },
   {
    "seq": 3,
    "command": "ProvisionTenant",
    "event": "TenantProvisioned",
    "actor": "Onboarding lead",
    "context": "Client Onboarding & Tenant Profile",
    "aggregate": "TenantAggregate",
    "policy": "Named analyst of record required",
    "downstream": "Analyst-of-record registration",
    "risk": "No analyst of record on file"
   },
   {
    "seq": 4,
    "command": "OpenBrandCampaignIntake",
    "event": "BrandCampaignIntakeAccepted",
    "actor": "Customer operator",
    "context": "Completeness Pack Fulfillment",
    "aggregate": "BrandCampaignIntakeAggregate",
    "policy": "Scope-fit spec",
    "downstream": "Evidence upload window opens",
    "risk": "Scope drift beyond ICP"
   },
   {
    "seq": 5,
    "command": "IngestEvidence",
    "event": "EvidenceIngested",
    "actor": "Customer operator + Normalization service",
    "context": "Completeness Pack Fulfillment",
    "aggregate": "BrandCampaignIntakeAggregate",
    "policy": "Evidence coverage spec",
    "downstream": "Extraction authorized",
    "risk": "Insufficient signup-page photo evidence"
   },
   {
    "seq": 6,
    "command": "StartExtractionRun",
    "event": "GapMatrixDrafted",
    "actor": "AI extraction/orchestration layer",
    "context": "AI Workbench & Extraction",
    "aggregate": "ExtractionRunAggregate",
    "policy": "Confidence threshold",
    "downstream": "Hard-gate evaluation",
    "risk": "Prompt injection via vendor invoice content"
   },
   {
    "seq": 7,
    "command": "EvaluateHardGates",
    "event": "HardGatesEvaluated",
    "actor": "Deterministic rule engine",
    "context": "Completeness Pack Fulfillment",
    "aggregate": "GapMatrixAggregate",
    "policy": "Hard-fail checklist spec",
    "downstream": "Analyst queue or decline/counsel-referral escalation",
    "risk": "CSP ruleset mismatch causing a false hard-fail"
   },
   {
    "seq": 8,
    "command": "ReleasePack",
    "event": "PackReleased",
    "actor": "Registration analyst / Licensed outside counsel (outside counsel) on escalation",
    "context": "Release & Quality Assurance",
    "aggregate": "ReleaseAggregate",
    "policy": "Releaser authority spec",
    "downstream": "Delivery authorized",
    "risk": "Missing-TCR-profile-authorship escalation skipped"
   },
   {
    "seq": 9,
    "command": "DeliverCompletenessPack",
    "event": "PackDelivered",
    "actor": "Delivery adapter",
    "context": "Completeness Pack Fulfillment",
    "aggregate": "CompletenessPackAggregate",
    "policy": "Deliverability spec",
    "downstream": "Billing meter, customer notified",
    "risk": "Silent delivery failure"
   },
   {
    "seq": 10,
    "command": "ConfirmDelivery",
    "event": "DeliveryConfirmed",
    "actor": "Client Delivery & Success",
    "context": "Client Delivery & Success",
    "aggregate": "DeliveryAggregate",
    "policy": "Ack within SLA",
    "downstream": "Success cadence",
    "risk": "Missed ack"
   },
   {
    "seq": 11,
    "command": "DispatchChaseLetter",
    "event": "ChaseLetterDispatched",
    "actor": "AI extraction/orchestration layer + Registration analyst",
    "context": "Vendor Resubmit Desk",
    "aggregate": "VendorChaseCaseAggregate",
    "policy": "Chase-cadence spec",
    "downstream": "Vendor cure evidence tracked",
    "risk": "OEM vendor refuses to share TCR profile/logs"
   },
   {
    "seq": 12,
    "command": "ConfirmVendorCure",
    "event": "RejectionCured",
    "actor": "Registration analyst",
    "context": "Vendor Resubmit Desk",
    "aggregate": "VendorChaseCaseAggregate",
    "policy": "Cure-evidence coverage spec",
    "downstream": "Gap matrix re-score",
    "risk": "Fabricated cure evidence accepted"
   },
   {
    "seq": 13,
    "command": "ResolveOwnerAction",
    "event": "OwnerActionResolved",
    "actor": "Customer operator (attesting for the building owner)",
    "context": "Compliance & Licensing Governance",
    "aggregate": "OwnerActionLedgerAggregate",
    "policy": "Release readiness spec",
    "downstream": "Release-decision recompute",
    "risk": "Public claim while blocker open"
   },
   {
    "seq": 14,
    "command": "ScheduleQuarterlyReScan",
    "event": "ReScanScheduled",
    "actor": "Success lead",
    "context": "Portfolio & Recurring Programs",
    "aggregate": "PortfolioAggregate",
    "policy": "Re-scan cadence spec",
    "downstream": "New Brand+Campaign intake batch opened",
    "risk": "Portfolio Desk scope-creeping into unpaid custom consulting"
   },
   {
    "seq": 15,
    "command": "RetractPack",
    "event": "PackRetracted",
    "actor": "Legal reviewer + Licensed outside counsel",
    "context": "Release & Quality Assurance",
    "aggregate": "PackRetractionAggregate",
    "policy": "Retraction preconditions",
    "downstream": "Customer notification, audit log",
    "risk": "Litigation discovery subpoena of the evidence archive"
   }
  ],
  "critical_path": [
   "BrandCampaignIntakeAccepted -> EvidenceIngested -> GapMatrixDrafted -> HardGatesEvaluated -> PackReleased -> PackDelivered -> DeliveryConfirmed"
  ],
  "exception_flows": [
   "GapMatrixDrafted with a missing TCR profile or contested code interpretation -> EscalationRaised -> Licensed outside counsel authors or interprets -> PackReleased (red)",
   "DeliverCompletenessPack blocked by an open owner action -> DeliveryBlocked -> owner/operator resolves -> retry",
   "DeliveryFailed at the adapter -> customer alert within 1h -> Success ticket -> retry with backoff",
   "HardGatesEvaluated flags a vendor-attributable gap with no vendor response -> Vendor Resubmit Desk opened -> ChaseLetterDispatched -> RejectionCured or re-escalated to owner demand"
  ],
  "escalation_flows": [
   "AI extraction/orchestration layer escalates to Registration analyst",
   "Registration analyst escalates no-registration-on-file or contested code interpretation to Licensed outside counsel",
   "Success lead escalates silent delivery failure to Business owner / founder",
   "Business owner escalates an TCR or insurer inquiry to external counsel"
  ],
  "retry_flows": [
   "External API failure -> exponential backoff with jitter, then dead-letter with owner-visible alert",
   "Model timeout -> retry once, then EscalationRaised",
   "Delivery adapter failure -> retry with backoff, then customer alert"
  ],
  "manual_override_flows": [
   "Registration analyst may override an AI-classified hard gap and re-route to a decline or an outside-counsel referral",
   "Business owner may force-block a delivery via the Compliance & Licensing Governance ledger",
   "Ops may pull a prompt version at any time (feature flag)"
  ],
  "commands": [
   {
    "name": "OpenBrandCampaignIntake",
    "issued_by": "Customer operator",
    "preconditions": [
     "Engagement accepted",
     "Tenant provisioned"
    ],
    "aggregate": "BrandCampaignIntakeAggregate",
    "success_event": "BrandCampaignIntakeAccepted",
    "failure_event": "IntakeRejected",
    "authorization": "Tenant member with Operator role",
    "validation": "Building + Brand+Campaign registration count present; no duplicate open intake for the same building",
    "audit": "Command + payload hash logged with tenant + user"
   },
   {
    "name": "IngestEvidence",
    "issued_by": "Customer operator / Normalization service",
    "preconditions": [
     "Intake open",
     "File type allowed"
    ],
    "aggregate": "BrandCampaignIntakeAggregate",
    "success_event": "EvidenceIngested",
    "failure_event": "EvidenceRejected",
    "authorization": "Same tenant",
    "validation": "Virus scan clean; vendor name canonicalized; unit ID matched",
    "audit": "Every attachment hashed and logged"
   },
   {
    "name": "StartExtractionRun",
    "issued_by": "AI extraction/orchestration layer",
    "preconditions": [
     "Evidence coverage complete",
     "Prompt version active"
    ],
    "aggregate": "ExtractionRunAggregate",
    "success_event": "GapMatrixDrafted",
    "failure_event": "EscalationRaised",
    "authorization": "Service role",
    "validation": "OutputValidator schema passes; citation-per-line check",
    "audit": "Prompt version + retrieval hits + cost captured"
   },
   {
    "name": "EvaluateHardGates",
    "issued_by": "Deterministic rule engine",
    "preconditions": [
     "GapMatrixDrafted"
    ],
    "aggregate": "GapMatrixAggregate",
    "success_event": "HardGatesEvaluated",
    "failure_event": "HardGateEvaluationError",
    "authorization": "Service role",
    "validation": "Every hard-fail checklist item (TCR profile present, accessibility instructions, 5-year retention, use-case sample) evaluated with a citation",
    "audit": "Rule version + evaluation result logged"
   },
   {
    "name": "ReleasePack",
    "issued_by": "Registration analyst / Licensed outside counsel (outside counsel) on escalation",
    "preconditions": [
     "GapMatrixDrafted",
     "HardGatesEvaluated",
     "No unresolved escalation"
    ],
    "aggregate": "ReleaseAggregate",
    "success_event": "PackReleased",
    "failure_event": "PackReleaseRejected",
    "authorization": "Analyst role bound to tenant; red packs additionally require outside-counsel guidance on file",
    "validation": "Every hard gap either cleared or logged as an open owner action; every gap-matrix line cites evidence",
    "audit": "Release attestation + timestamp + releaser identity"
   },
   {
    "name": "DeliverCompletenessPack",
    "issued_by": "Delivery adapter",
    "preconditions": [
     "PackReleased",
     "Compliance release-readiness allows delivery"
    ],
    "aggregate": "CompletenessPackAggregate",
    "success_event": "PackDelivered",
    "failure_event": "DeliveryFailed",
    "authorization": "Service role",
    "validation": "Delivery method valid; Evidence Index attached",
    "audit": "Delivery receipt archived"
   },
   {
    "name": "ResolveOwnerAction",
    "issued_by": "Customer operator (attesting for the building owner)",
    "preconditions": [
     "Owner action open"
    ],
    "aggregate": "OwnerActionLedgerAggregate",
    "success_event": "OwnerActionResolved",
    "failure_event": "OwnerActionRejected",
    "authorization": "Owner/operator role",
    "validation": "Supplied fact matches the action schema (e.g. CSP account custody attestation, no-TCR-profile-exists attestation)",
    "audit": "Actor + before/after captured"
   },
   {
    "name": "DispatchChaseLetter",
    "issued_by": "Registration analyst / AI extraction/orchestration layer (draft)",
    "preconditions": [
     "Hard gap open and vendor-attributable",
     "Vendor contact on file"
    ],
    "aggregate": "VendorChaseCaseAggregate",
    "success_event": "ChaseLetterDispatched",
    "failure_event": "ChaseLetterFailed",
    "authorization": "Analyst role",
    "validation": "Chase letter template populated; no invented procedure text",
    "audit": "Chase letter + send receipt archived"
   },
   {
    "name": "ConfirmVendorCure",
    "issued_by": "Registration analyst",
    "preconditions": [
     "ChaseLetterDispatched",
     "Vendor evidence received"
    ],
    "aggregate": "VendorChaseCaseAggregate",
    "success_event": "RejectionCured",
    "failure_event": "VendorCureRejected",
    "authorization": "Analyst role",
    "validation": "Cure evidence cites a source and matches the original hard-gap clause",
    "audit": "Cure evidence hash + reviewer id logged"
   },
   {
    "name": "RetractPack",
    "issued_by": "Legal reviewer + Licensed outside counsel",
    "preconditions": [
     "Pack previously delivered",
     "Material finding documented"
    ],
    "aggregate": "PackRetractionAggregate",
    "success_event": "PackRetracted",
    "failure_event": "RetractionRejected",
    "authorization": "Legal sign-off, informed by any outside-counsel guidance on record",
    "validation": "Retraction preconditions spec",
    "audit": "Full retraction packet archived"
   }
  ],
  "policies": [
   {
    "name": "Auto-request release on hard-gate evaluation complete",
    "trigger": "HardGatesEvaluated",
    "condition": "Gap-matrix coverage spec passes",
    "action": "Enqueue ReleasePack",
    "context": "Completeness Pack Fulfillment",
    "ai_involvement": "none",
    "human_approval": false
   },
   {
    "name": "Escalate on low confidence or missing TCR profile",
    "trigger": "GapMatrixDrafted",
    "condition": "Confidence < threshold OR no TCR profile found OR contested code interpretation",
    "action": "Emit EscalationRaised, route to decline or counsel-referral queue",
    "context": "AI Workbench & Extraction",
    "ai_involvement": "author",
    "human_approval": false
   },
   {
    "name": "Block delivery on open compliance blocker",
    "trigger": "DeliverCompletenessPack command",
    "condition": "Owner-action ledger has an open blocking item",
    "action": "Reject delivery, emit DeliveryBlocked",
    "context": "Completeness Pack Fulfillment <-> Compliance & Licensing Governance",
    "ai_involvement": "none",
    "human_approval": true
   },
   {
    "name": "Retract on material finding",
    "trigger": "MaterialFindingReported",
    "condition": "Signed claim materially wrong or fabricated evidence discovered",
    "action": "Open PackRetraction workflow with legal sign-off, informed by any outside-counsel guidance on record",
    "context": "Release & Quality Assurance",
    "ai_involvement": "assist",
    "human_approval": true
   },
   {
    "name": "Alert on delivery failure",
    "trigger": "DeliveryFailed",
    "condition": "Any",
    "action": "Notify customer within 1h + open Success ticket",
    "context": "Client Delivery & Success",
    "ai_involvement": "none",
    "human_approval": false
   },
   {
    "name": "Open vendor chase case on vendor-attributable hard gap",
    "trigger": "HardGatesEvaluated",
    "condition": "Hard gap = missing 5-year record or missing use-case sample attributable to a vendor, and Resubmit Desk purchased",
    "action": "Offer / open Vendor Resubmit Desk case",
    "context": "Vendor Resubmit Desk",
    "ai_involvement": "assist",
    "human_approval": true
   }
  ],
  "aggregates": [
   {
    "name": "EngagementAggregate",
    "root": "Engagement",
    "context": "Sales & Intake",
    "purpose": "Guard lead qualification and accepted-engagement state.",
    "entities": [
     "Lead",
     "Engagement"
    ],
    "value_objects": [
     "ScopeStatement",
     "PricingOffer"
    ],
    "invariants": [
     "Cannot open a Brand+Campaign intake without an accepted engagement"
    ],
    "commands": [
     "QualifyLead",
     "AcceptEngagement"
    ],
    "events": [
     "EngagementAccepted"
    ],
    "repository": "EngagementRepository",
    "transaction_boundary": "One engagement per transaction"
   },
   {
    "name": "TenantAggregate",
    "root": "Tenant",
    "context": "Client Onboarding & Tenant Profile",
    "purpose": "Own tenant provisioning and analyst-of-record registration.",
    "entities": [
     "Tenant",
     "AnalystOfRecord"
    ],
    "value_objects": [
     "ContactMatrix",
     "TCRSet"
    ],
    "invariants": [
     "Every tenant has at least one named analyst of record with a valid credential"
    ],
    "commands": [
     "ProvisionTenant",
     "RegisterAnalystOfRecord"
    ],
    "events": [
     "TenantProvisioned",
     "AnalystOfRecordRegistered"
    ],
    "repository": "TenantRepository",
    "transaction_boundary": "One tenant per transaction"
   },
   {
    "name": "BrandCampaignIntakeAggregate",
    "root": "BrandCampaignIntake",
    "context": "Completeness Pack Fulfillment",
    "purpose": "Guard intake + evidence-ingestion state transitions for one building/Brand+Campaign registration batch.",
    "entities": [
     "BrandCampaignIntake",
     "EvidenceLink"
    ],
    "value_objects": [
     "ConfidenceScore",
     "EvidenceCitation"
    ],
    "invariants": [
     "An intake in state 'delivered' is immutable"
    ],
    "commands": [
     "OpenBrandCampaignIntake",
     "IngestEvidence"
    ],
    "events": [
     "BrandCampaignIntakeAccepted",
     "EvidenceIngested"
    ],
    "repository": "BrandCampaignIntakeRepository",
    "transaction_boundary": "One Brand+Campaign intake per transaction"
   },
   {
    "name": "GapMatrixAggregate",
    "root": "GapMatrix",
    "context": "Completeness Pack Fulfillment",
    "purpose": "Own the line-by-line checklist-vs-evidence comparison and the hard-gate evaluation.",
    "entities": [
     "GapMatrix",
     "GapMatrixLine",
     "HardGapFlag"
    ],
    "value_objects": [
     "ChecklistClauseCitation",
     "EvidenceCitation"
    ],
    "invariants": [
     "Every gap-matrix line cites at least one evidence item or is marked an explicit gap"
    ],
    "commands": [
     "EvaluateHardGates"
    ],
    "events": [
     "HardGatesEvaluated"
    ],
    "repository": "GapMatrixRepository",
    "transaction_boundary": "One gap matrix per transaction"
   },
   {
    "name": "CompletenessPackAggregate",
    "root": "Completeness Pack",
    "context": "Completeness Pack Fulfillment",
    "purpose": "Own the Completeness Pack lifecycle from released to delivered.",
    "entities": [
     "Completeness Pack",
     "Delivery"
    ],
    "value_objects": [
     "DeliveryAddress",
     "Evidence archiveIndexEntry"
    ],
    "invariants": [
     "A Completeness Pack cannot be delivered without a valid Release"
    ],
    "commands": [
     "DeliverCompletenessPack"
    ],
    "events": [
     "PackDelivered"
    ],
    "repository": "CompletenessPackRepository",
    "transaction_boundary": "One Completeness Pack per transaction"
   },
   {
    "name": "ExtractionRunAggregate",
    "root": "ExtractionRun",
    "context": "AI Workbench & Extraction",
    "purpose": "Track a single bounded AI extraction run with prompt version, cost, and output validation.",
    "entities": [
     "ExtractionRun",
     "RetrievalHit"
    ],
    "value_objects": [
     "ConfidenceScore",
     "TokenBudget",
     "ModelCost"
    ],
    "invariants": [
     "No output emitted without OutputValidator pass",
     "Retrieval scoped to a single tenant partition"
    ],
    "commands": [
     "StartExtractionRun"
    ],
    "events": [
     "GapMatrixDrafted",
     "EscalationRaised"
    ],
    "repository": "ExtractionRunRepository",
    "transaction_boundary": "One run per transaction"
   },
   {
    "name": "TCRRuleSetAggregate",
    "root": "TCRRuleSet",
    "context": "TCR Rule Library & Retrieval",
    "purpose": "Own the per-jurisdiction CSP ruleset library and TCR Brand & Campaign vetting checklist checklist cards.",
    "entities": [
     "TCRRuleSet",
     "ChecklistCard"
    ],
    "value_objects": [
     "EditionCitation"
    ],
    "invariants": [
     "A checklist card is never served for an edition other than the one adopted by the Brand+Campaign registration's TCR"
    ],
    "commands": [
     "IngestRuleUpdate",
     "Reindex"
    ],
    "events": [
     "RuleUpdateIngested",
     "IndexRebuilt"
    ],
    "repository": "TCRRuleSetRepository",
    "transaction_boundary": "One rule-set update per transaction"
   },
   {
    "name": "ReleaseAggregate",
    "root": "Release",
    "context": "Release & Quality Assurance",
    "purpose": "Bind releaser identity + timestamp + pack hash immutably.",
    "entities": [
     "Release"
    ],
    "value_objects": [
     "ReleaseManifest"
    ],
    "invariants": [
     "A Release is bound to a live authenticated session, not a form field",
     "Released packs are immutable"
    ],
    "commands": [
     "ReleasePack"
    ],
    "events": [
     "PackReleased"
    ],
    "repository": "ReleaseRepository",
    "transaction_boundary": "One release per transaction"
   },
   {
    "name": "PackRetractionAggregate",
    "root": "PackRetraction",
    "context": "Release & Quality Assurance",
    "purpose": "Handle formal correction/withdrawal of a released Completeness Pack.",
    "entities": [
     "PackRetraction"
    ],
    "value_objects": [
     "RetractionReason",
     "ImpactStatement"
    ],
    "invariants": [
     "A retraction requires legal sign-off, informed by any outside-counsel guidance on record"
    ],
    "commands": [
     "RetractPack"
    ],
    "events": [
     "PackRetracted"
    ],
    "repository": "PackRetractionRepository",
    "transaction_boundary": "One retraction per transaction"
   },
   {
    "name": "OwnerActionLedgerAggregate",
    "root": "OwnerActionLedger",
    "context": "Compliance & Licensing Governance",
    "purpose": "Own the set of owner-supplied facts blocking a release-readiness claim.",
    "entities": [
     "OwnerAction"
    ],
    "value_objects": [
     "BlockerReason",
     "Jurisdiction"
    ],
    "invariants": [
     "Release cannot flip to 'ready' with open blocking owner actions"
    ],
    "commands": [
     "RaiseOwnerAction",
     "ResolveOwnerAction"
    ],
    "events": [
     "OwnerActionResolved",
     "ReleaseDecisionChanged"
    ],
    "repository": "OwnerActionRepository",
    "transaction_boundary": "One ledger per tenant"
   },
   {
    "name": "VendorChaseCaseAggregate",
    "root": "VendorChaseCase",
    "context": "Vendor Resubmit Desk",
    "purpose": "Own an open rejection cure cycle: resubmission memos, vendor responses, and cure-evidence confirmation.",
    "entities": [
     "VendorChaseCase",
     "ChaseLetter"
    ],
    "value_objects": [
     "ChaseCadence",
     "CureEvidenceCitation"
    ],
    "invariants": [
     "A hard gap cannot be marked cured without vendor-sourced cure evidence citing the original clause"
    ],
    "commands": [
     "DispatchChaseLetter",
     "ConfirmVendorCure"
    ],
    "events": [
     "ChaseLetterDispatched",
     "RejectionCured"
    ],
    "repository": "VendorChaseCaseRepository",
    "transaction_boundary": "One chase case per transaction"
   },
   {
    "name": "PortfolioAggregate",
    "root": "Portfolio",
    "context": "Portfolio & Recurring Programs",
    "purpose": "Own Portfolio Desk enrollment, quarterly re-scan scheduling, and the rolling scorecard.",
    "entities": [
     "Portfolio",
     "ReScanSchedule"
    ],
    "value_objects": [
     "Cadence",
     "ScorecardSnapshot"
    ],
    "invariants": [
     "Every enrolled building has a non-lapsed quarterly re-scan schedule"
    ],
    "commands": [
     "EnrollPortfolio",
     "ScheduleQuarterlyReScan"
    ],
    "events": [
     "PortfolioEnrolled",
     "ReScanScheduled"
    ],
    "repository": "PortfolioRepository",
    "transaction_boundary": "One portfolio per transaction"
   },
   {
    "name": "DeliveryAggregate",
    "root": "Delivery",
    "context": "Client Delivery & Success",
    "purpose": "Own delivery receipts and revision requests.",
    "entities": [
     "Delivery",
     "RevisionRequest"
    ],
    "value_objects": [
     "DeliveryMethod"
    ],
    "invariants": [
     "Every DeliveryConfirmed has a linked Release"
    ],
    "commands": [
     "ConfirmDelivery",
     "RecordRevisionRequest"
    ],
    "events": [
     "DeliveryConfirmed",
     "RevisionRequested"
    ],
    "repository": "DeliveryRepository",
    "transaction_boundary": "One delivery per transaction"
   }
  ],
  "invariants": [
   {
    "invariant": "A Completeness Pack cannot be delivered without a valid analyst Release.",
    "context": "Completeness Pack Fulfillment <-> Release & Quality Assurance",
    "aggregate": "CompletenessPackAggregate",
    "why": "Inspection defensibility; brand-risk",
    "enforcement": "Aggregate command handler rejects delivery without a release reference"
   },
   {
    "invariant": "Every gap-matrix line cites at least one evidence item or is marked an explicit gap.",
    "context": "Completeness Pack Fulfillment",
    "aggregate": "GapMatrixAggregate",
    "why": "Anti-fabrication; audit reconstructability",
    "enforcement": "EvidenceCoverageSpec on hard-gate evaluation"
   },
   {
    "invariant": "A Release is bound to a live authenticated session, not a form field.",
    "context": "Release & Quality Assurance",
    "aggregate": "ReleaseAggregate",
    "why": "Anti-spoofing, anti-repudiation",
    "enforcement": "Release service validates session claim server-side"
   },
   {
    "invariant": "Released Completeness Packs are immutable; corrections go through PackRetraction.",
    "context": "Release & Quality Assurance",
    "aggregate": "ReleaseAggregate + PackRetractionAggregate",
    "why": "Preserves the audit chain",
    "enforcement": "Repository denies mutation after release"
   },
   {
    "invariant": "No extraction output leaves AI Workbench & Extraction without an OutputValidator pass.",
    "context": "AI Workbench & Extraction",
    "aggregate": "ExtractionRunAggregate",
    "why": "Grounding + hallucination control (no invented log lines or dates)",
    "enforcement": "ExtractionRun terminates as EscalationRaised on validator failure"
   },
   {
    "invariant": "TCR retrieval is scoped to the checklist edition adopted by the Brand+Campaign registration's jurisdiction.",
    "context": "TCR Rule Library & Retrieval <-> AI Workbench & Extraction",
    "aggregate": "TCRRuleSetAggregate",
    "why": "Prevent CSP ruleset mismatch / false hard-fail",
    "enforcement": "CSPScopeSpec at the retrieval router"
   },
   {
    "invariant": "Release cannot flip to 'ready' with open blocking owner actions.",
    "context": "Compliance & Licensing Governance",
    "aggregate": "OwnerActionLedgerAggregate",
    "why": "Prevent a premature public claim of inspection-readiness",
    "enforcement": "ReleaseReadinessSpec on ResolveOwnerAction"
   },
   {
    "invariant": "Every tenant has at least one named registration analyst of record on file before intake opens.",
    "context": "Client Onboarding & Tenant Profile",
    "aggregate": "TenantAggregate",
    "why": "No unattributed releases",
    "enforcement": "AnalystCredentialSpec on tenant provisioning"
   },
   {
    "invariant": "A hard gap cannot be marked cured without vendor-sourced cure evidence citing the original clause.",
    "context": "Vendor Resubmit Desk",
    "aggregate": "VendorChaseCaseAggregate",
    "why": "Anti-fabrication on cure claims",
    "enforcement": "CureEvidenceSpec on ConfirmVendorCure"
   },
   {
    "invariant": "Roles are stored in a dedicated table and checked server-side.",
    "context": "Identity & Access",
    "aggregate": "UserAggregate",
    "why": "Prevent privilege escalation",
    "enforcement": "RoleAuthoritySpec + RLS on protected tables"
   }
  ],
  "ai_agents": [
   {
    "name": "Extraction Agent",
    "context": "AI Workbench & Extraction",
    "responsibility": "OCR heterogeneous vendor TCR profiles, service logs, callback records, inspection reports, and signup-page photos; extract equipment-specific fields; build the five-year coverage timeline; draft the cited gap matrix.",
    "inputs": [
     "Ingested evidence (tenant-scoped)",
     "TCR rule-set retrieval hits",
     "Prompt version"
    ],
    "outputs": [
     "Structured gap-matrix draft",
     "Confidence score",
     "Citations"
    ],
    "tools": [
     "Retrieval API",
     "Structured-output validator",
     "Cost meter"
    ],
    "forbidden_actions": [
     "Call external tools not in its allowlist",
     "Access another tenant's retrieval index",
     "Emit output that skips the OutputValidator",
     "Author a technical TCR profile or interpret a contested code citation",
     "Invent log lines, dates, or procedures not present in source evidence"
    ],
    "memory_scope": "Per-run only; no cross-run memory; prompt-injection scrubber on all customer and vendor inputs.",
    "retrieval_sources": [
     "Tenant-scoped evidence index",
     "CSP ruleset checklist library (read-only cache)"
    ],
    "validations": [
     "Structured-output schema",
     "Citation-coverage rule",
     "PII-scrub rule on prompt inputs"
    ],
    "confidence_scoring": "Model-reported logprobs + citation-coverage combined into a bounded [0..1] score.",
    "escalation_triggers": [
     "Score < threshold",
     "No TCR profile found for a Brand+Campaign registration",
     "Contested code-edition interpretation",
     "Missing citation on any claim"
    ],
    "human_approval": true,
    "failure_modes": [
     "Prompt injection via vendor invoice/log content",
     "Hallucinated citation",
     "Retrieval-tenant leak"
    ],
    "audit_logs": [
     "Prompt version",
     "Retrieval hits (ids only)",
     "Cost + latency",
     "Validator verdict"
    ],
    "metrics": [
     "Draft acceptance rate",
     "Escalation rate",
     "Cost per pack",
     "p95 latency"
    ],
    "versioning": "Prompt versions immutable once published; published via the prompt registry; rollout via feature flag."
   },
   {
    "name": "Routing & Classification Agent",
    "context": "AI Workbench & Extraction",
    "responsibility": "Match each Brand+Campaign registration to the correct TCR checklist edition and equipment category, and route the intake to the registration analyst queue or, on ambiguity, the decline/counsel-referral queue.",
    "inputs": [
     "Intake payload",
     "Building jurisdiction"
    ],
    "outputs": [
     "Route decision + confidence"
    ],
    "tools": [
     "TCR rule-set registry"
    ],
    "forbidden_actions": [
     "Make final release decisions",
     "Bypass analyst-queue routing",
     "Guarantee an inspection outcome"
    ],
    "memory_scope": "Per-run only",
    "retrieval_sources": [
     "CSP ruleset reference table"
    ],
    "validations": [
     "Structured-output schema",
     "Known-route allowlist"
    ],
    "confidence_scoring": "Model logprobs.",
    "escalation_triggers": [
     "Score < threshold",
     "Unrecognized TCR or edition"
    ],
    "human_approval": false,
    "failure_modes": [
     "Wrong route -> wrong reviewer",
     "Wrong CSP ruleset applied"
    ],
    "audit_logs": [
     "Route decision + rationale"
    ],
    "metrics": [
     "Routing accuracy vs analyst corrections"
    ],
    "versioning": "Same as Extraction Agent"
   },
   {
    "name": "Eval Agent",
    "context": "AI Workbench & Extraction",
    "responsibility": "Run offline evals on prompt versions against a golden dataset of past analyst-released Completeness Packs before rollout.",
    "inputs": [
     "Golden dataset",
     "Prompt candidate"
    ],
    "outputs": [
     "Pass/fail per case + drift report"
    ],
    "tools": [
     "Golden dataset"
    ],
    "forbidden_actions": [
     "Touch production tenant data"
    ],
    "memory_scope": "Per-eval only",
    "retrieval_sources": [
     "Golden dataset only"
    ],
    "validations": [
     "Regression thresholds"
    ],
    "confidence_scoring": "Aggregate over dataset",
    "escalation_triggers": [
     "Regression > threshold"
    ],
    "human_approval": true,
    "failure_modes": [
     "Overfit to golden dataset"
    ],
    "audit_logs": [
     "Full eval report archived"
    ],
    "metrics": [
     "Pass rate",
     "Regression rate"
    ],
    "versioning": "Every prompt release requires a passing eval"
   }
  ],
  "prompt_chain_map": [
   "Intake -> Routing & Classification Agent (CSP ruleset + equipment category) -> Extraction Agent (cite + draft gap matrix) -> OutputValidator -> Registration analyst (release or escalate)",
   "Retraction analysis -> Eval Agent (assist only) -> Legal reviewer sign-off, informed by any outside-counsel guidance on record"
  ],
  "rag_map": [
   "Per-tenant evidence index -> retrieval router -> tenant-scoped hits -> Extraction Agent",
   "CSP ruleset checklist library (Twilio, Telnyx/Bandwidth/VA, expandable, read-only cache) -> shared retrieval -> Extraction Agent (cited)"
  ],
  "ai_evaluation": [
   "Golden dataset of past analyst-released Completeness Packs per TCR",
   "Regression thresholds on release-acceptance rate + citation coverage",
   "Every prompt release requires a passing Eval Agent run"
  ],
  "hallucination_controls": [
   "Retrieval-first (no free-form generation of log lines, dates, or procedures without citation)",
   "Structured-output validator enforces citation-per-claim",
   "Confidence-scored escalation to registration analyst",
   "Analyst release gate on every outbound Completeness Pack"
  ],
  "human_in_the_loop_plan": [
   "Registration analyst release on every green/yellow Completeness Pack",
   "Licensed outside counsel release on every red (missing-TCR profile or contested-code) Completeness Pack",
   "Legal sign-off on retractions, informed by any outside-counsel guidance on record",
   "Business owner approval on public release-readiness claims for the microsite",
   "Ops sign-off on prompt-version rollout"
  ],
  "ai_audit_plan": [
   "Every ExtractionRun logged with prompt version, retrieval hit ids, cost, latency, validator verdict",
   "13-month rolling retention on run logs",
   "PII scrubbed from log payloads"
  ],
  "prompt_versioning": "Prompt versions immutable once published; rolled out via feature flag; every rollout paired with an Eval Agent run.",
  "human_roles": [
   {
    "role": "Registration analyst",
    "responsibilities": [
     "Release green/yellow Completeness Packs",
     "Escalate missing-TCR profile or contested-interpretation packs to the outside counsel",
     "Draft/edit CSP resubmission memos"
    ],
    "contexts": [
     "Release & Quality Assurance",
     "Completeness Pack Fulfillment"
    ],
    "decisions_owned": [
     "Release (green/yellow)",
     "Escalation"
    ],
    "ai_support": [
     "Cited gap-matrix drafts",
     "Confidence-ranked hard gaps"
    ],
    "approval_authority": "Green/yellow pack release",
    "escalation_authority": "Escalate to Licensed outside counsel",
    "quality_metrics": [
     "Cycle time to release",
     "Release-to-retraction ratio"
    ],
    "workload_risks": [
     "Analyst shortage / early demand trap"
    ]
   },
   {
    "role": "Licensed outside counsel",
    "responsibilities": [
     "Author or certify a new technical TCR profile when none exists",
     "Interpret contested code citations",
     "Release red packs",
     "Advise on alteration/modernization escalations"
    ],
    "contexts": [
     "Release & Quality Assurance"
    ],
    "decisions_owned": [
     "Red-pack release",
     "Technical Brand+Campaign registration setup"
    ],
    "ai_support": [
     "Escalation summary",
     "Prior-similar-case surfacing"
    ],
    "approval_authority": "Red-pack release",
    "escalation_authority": "Escalate to Legal reviewer / Business owner",
    "quality_metrics": [
     "Escalation-to-release cycle time"
    ],
    "workload_risks": [
     "Outside-counsel referral volume",
     "SMS Campaign-outside counsel partners perceiving TCR profileEvidence archive as a competitor"
    ]
   },
   {
    "role": "Business owner / founder",
    "responsibilities": [
     "Resolve escalated owner actions",
     "Decide public release-readiness for the microsite",
     "Own commercial claims"
    ],
    "contexts": [
     "Compliance & Licensing Governance",
     "Sales & Intake"
    ],
    "decisions_owned": [
     "Release readiness",
     "Owner-action ledger policy"
    ],
    "ai_support": [
     "Blocker summary"
    ],
    "approval_authority": "Release readiness (public claims)",
    "escalation_authority": "Escalate to Legal reviewer",
    "quality_metrics": [
     "Blocker close time"
    ],
    "workload_risks": [
     "Single-owner queue"
    ]
   },
   {
    "role": "Legal reviewer",
    "responsibilities": [
     "Retraction co-sign",
     "DSAR + TCR/regulator response",
     "Litigation-discovery evidence archive requests"
    ],
    "contexts": [
     "Release & Quality Assurance",
     "Compliance & Licensing Governance"
    ],
    "decisions_owned": [
     "Retraction approval",
     "Regulator/subpoena response"
    ],
    "ai_support": [
     "Precedent surfacing (assist only)"
    ],
    "approval_authority": "Retraction, regulator response",
    "escalation_authority": "External counsel",
    "quality_metrics": [
     "Retraction latency"
    ],
    "workload_risks": [
     "Retainer capacity"
    ]
   },
   {
    "role": "Success lead",
    "responsibilities": [
     "Delivery health, revision loop, Portfolio Desk renewal signal"
    ],
    "contexts": [
     "Client Delivery & Success"
    ],
    "decisions_owned": [
     "Escalate silent failures"
    ],
    "ai_support": [
     "Delivery health digest"
    ],
    "approval_authority": "Customer-visible remediation",
    "escalation_authority": "Business owner / founder",
    "quality_metrics": [
     "Time-to-alert on delivery failure"
    ],
    "workload_risks": [
     "Alert fatigue"
    ]
   },
   {
    "role": "Onboarding lead",
    "responsibilities": [
     "Provision tenants, register the registration analyst of record, import existing TCR profile/evidence pack"
    ],
    "contexts": [
     "Client Onboarding & Tenant Profile"
    ],
    "decisions_owned": [
     "Tenant readiness"
    ],
    "ai_support": [
     "Checklist coverage"
    ],
    "approval_authority": "Go-live per tenant",
    "escalation_authority": "Business owner / founder",
    "quality_metrics": [
     "Time-to-first-pack"
    ],
    "workload_risks": [
     "Sequential onboarding queue"
    ]
   },
   {
    "role": "Ops (prompt owner)",
    "responsibilities": [
     "Prompt version registry + eval sign-off",
     "TCR rule-library maintenance"
    ],
    "contexts": [
     "AI Workbench & Extraction",
     "TCR Rule Library & Retrieval"
    ],
    "decisions_owned": [
     "Prompt rollout",
     "Rule-library edition updates"
    ],
    "ai_support": [
     "Eval Agent"
    ],
    "approval_authority": "Prompt rollout",
    "escalation_authority": "Engineering",
    "quality_metrics": [
     "Regression rate at rollout"
    ],
    "workload_risks": [
     "Version drift",
     "CSP ruleset tracking lag"
    ]
   }
  ],
  "human_review_checkpoints": [
   "AI gap-matrix draft -> registration analyst approval",
   "Missing-TCR profile or contested-code pack -> counsel-cleared analyst release",
   "Public release-readiness claim -> business owner acceptance",
   "Retraction -> legal sign-off, informed by outside-counsel guidance where on record",
   "Prompt rollout -> ops + eval agent"
  ],
  "escalation_matrix": [
   "AI extraction/orchestration layer -> Registration analyst -> Licensed outside counsel -> Business owner -> External counsel",
   "Success lead -> Business owner -> External counsel (TCR/insurer inquiries)"
  ],
  "manual_override_rules": [
   "Any manual override captured as an explicit override event with actor + reason",
   "No override may bypass the analyst/counsel-cleared analyst release invariant"
  ],
  "separation_of_duties": [
   "Extraction Agent cannot release a pack; Registration analyst cannot author a technical TCR profile without outside counsel escalation; Legal reviewer cannot silently retract a pack"
  ],
  "quality_control_workflow": [
   "Weekly analyst calibration meeting",
   "Monthly eval-agent regression report",
   "Quarterly retraction-rate review with business owner + legal"
  ],
  "data_objects": [
   {
    "name": "BrandCampaignIntake",
    "meaning": "Unit of intake work per building/Brand+Campaign registration batch brought in by the customer",
    "owner_context": "Completeness Pack Fulfillment",
    "writers": [
     "Completeness Pack Fulfillment"
    ],
    "readers": [
     "Release & Quality Assurance",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Completeness Pack Fulfillment DB",
    "retention": "5 years + 6 months (mirrors Twilio rejection code 30909 (message flow) retention + buffer)",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "GapMatrix",
    "meaning": "Line-by-line cited comparison of required checklist items vs. evidence found",
    "owner_context": "Completeness Pack Fulfillment",
    "writers": [
     "Completeness Pack Fulfillment"
    ],
    "readers": [
     "Release & Quality Assurance",
     "Vendor Resubmit Desk",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Completeness Pack Fulfillment DB + TCR Rule Library pointers",
    "retention": "5 years + 6 months",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "Completeness Pack",
    "meaning": "Analyst-released deliverable",
    "owner_context": "Completeness Pack Fulfillment",
    "writers": [
     "Completeness Pack Fulfillment"
    ],
    "readers": [
     "Release & Quality Assurance",
     "Client Delivery & Success",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Completeness Pack Fulfillment DB (immutable after release)",
    "retention": "5 years + 6 months (mirrors the code 30909 5-year duty + buffer)",
    "privacy": "regulated",
    "audit": true
   },
   {
    "name": "Release",
    "meaning": "Analyst or counsel-cleared analyst release attestation",
    "owner_context": "Release & Quality Assurance",
    "writers": [
     "Release & Quality Assurance"
    ],
    "readers": [
     "Completeness Pack Fulfillment",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Release & Quality Assurance DB (append-only)",
    "retention": "5 years + 6 months",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "OwnerActionLedger",
    "meaning": "Blocker facts per tenant (e.g. CSP account custody attestation, no-TCR-profile-exists attestation)",
    "owner_context": "Compliance & Licensing Governance",
    "writers": [
     "Compliance & Licensing Governance"
    ],
    "readers": [
     "Completeness Pack Fulfillment (release decision)",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Compliance & Licensing Governance DB",
    "retention": "5 years + 6 months",
    "privacy": "internal",
    "audit": true
   },
   {
    "name": "ExtractionRun",
    "meaning": "Trace of one AI Workbench extraction run",
    "owner_context": "AI Workbench & Extraction",
    "writers": [
     "AI Workbench & Extraction"
    ],
    "readers": [
     "Analytics & Reporting",
     "Release & Quality Assurance (on escalation)"
    ],
    "source_of_truth": "AI Workbench & Extraction DB",
    "retention": "13 months (rolling)",
    "privacy": "internal",
    "audit": true
   },
   {
    "name": "Tenant",
    "meaning": "Customer organization + registered registration analyst of record",
    "owner_context": "Client Onboarding & Tenant Profile",
    "writers": [
     "Client Onboarding & Tenant Profile"
    ],
    "readers": [
     "all contexts"
    ],
    "source_of_truth": "Onboarding DB",
    "retention": "Life of contract + 3.5 years",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "VendorChaseCase",
    "meaning": "Open rejection cure cycle with CSP resubmission memos + cure evidence",
    "owner_context": "Vendor Resubmit Desk",
    "writers": [
     "Vendor Resubmit Desk"
    ],
    "readers": [
     "Completeness Pack Fulfillment",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Vendor Resubmit Desk DB",
    "retention": "5 years + 6 months",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "Portfolio",
    "meaning": "Portfolio Desk enrollment, re-scan schedule, and rolling scorecard",
    "owner_context": "Portfolio & Recurring Programs",
    "writers": [
     "Portfolio & Recurring Programs"
    ],
    "readers": [
     "Client Delivery & Success",
     "Analytics & Reporting"
    ],
    "source_of_truth": "Portfolio & Recurring Programs DB",
    "retention": "Life of subscription + 2 years",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "Subscription + Invoice",
    "meaning": "Commercial relationship + charges (per-pack, Rush, Resubmit Desk, Portfolio Desk)",
    "owner_context": "Billing & Revenue",
    "writers": [
     "Billing"
    ],
    "readers": [
     "Analytics & Reporting"
    ],
    "source_of_truth": "Billing provider (Stripe)",
    "retention": "As required by tax law",
    "privacy": "confidential",
    "audit": true
   },
   {
    "name": "User + Role",
    "meaning": "Identity + authorization",
    "owner_context": "Identity & Access",
    "writers": [
     "Identity & Access"
    ],
    "readers": [
     "all contexts"
    ],
    "source_of_truth": "Identity DB",
    "retention": "Life of account + 2 years",
    "privacy": "confidential",
    "audit": true
   }
  ],
  "read_models": [
   "Operator dashboard read model (per tenant): open intakes, in-extraction, in-release, delivered this quarter",
   "Analyst queue read model: gap matrices awaiting release with confidence + escalation reason",
   "Compliance ledger read model: open owner actions + release-decision",
   "Portfolio scorecard read model: TCR profile completeness status across 5-40 buildings",
   "Analytics rollup read model: metric definitions rolled up daily"
  ],
  "reporting_models": [
   "Outcome report per customer: packs delivered, cycle time, escalation rate, rejection cure rate",
   "Ops report: AI cost per pack, escalation rate, analyst load"
  ],
  "data_duplication_notes": [
   "Registration analyst of record is stored in Onboarding, referenced by Release & Quality Assurance -- QA does not own it",
   "OwnerActionLedger duplicates minimal facts into read models for Fulfillment consumption"
  ],
  "data_retention": [
   "Completeness Packs + gap matrices + releases: 5 years + 6 months (mirrors the Twilio rejection code 30909 (message flow) 5-year duty + buffer)",
   "ExtractionRun logs: 13 months rolling",
   "Users + sessions: life of account + 2 years"
  ],
  "data_quality_risks": [
   "Silent schema drift from vendor invoice / CMMS systems",
   "Stale CSP ruleset index after a rule-library update",
   "Missing retraction cross-links after legacy import"
  ],
  "use_cases": [
   {
    "name": "Deliver an analyst-released Completeness Pack (paused for outside-counsel referral where a contested legal question exists)",
    "actor": "Customer operator + Registration analyst",
    "context": "Completeness Pack Fulfillment + Release & Quality Assurance + AI Workbench & Extraction",
    "goal": "Produce and deliver a released A2P 10DLC Approval Completeness Pack for one building/Brand+Campaign registration",
    "preconditions": [
     "Tenant provisioned",
     "Registration analyst of record registered",
     "Engagement accepted"
    ],
    "main_flow": [
     "Operator opens a Brand+Campaign intake",
     "Evidence ingested (TCR profile, logs, callbacks, inspections, signup-page photos)",
     "Extraction Agent drafts the gap matrix with citations",
     "Deterministic rules evaluate the hard gates",
     "Registration analyst releases the pack, or declines it, or pauses it for outside-counsel referral",
     "Delivery adapter delivers the pack + resubmit kit + Evidence Index",
     "Success lead confirms delivery"
    ],
    "alternative_flows": [
     "Confidence below threshold or no TCR profile found -> EscalationRaised -> decline, or pause for outside-counsel referral, then analyst releases",
     "Blocking owner action open -> DeliveryBlocked -> surfaced to customer operator",
     "Delivery failure -> alert customer within 1h"
    ],
    "business_rules": [
     "Every gap-matrix line cites evidence or is an explicit gap",
     "Only the tenant's registered analyst may release — including red packs, which release only after outside counsel has cleared the contested question"
    ],
    "ai_role": "Extract + draft the gap matrix + score confidence",
    "human_role": "Release; escalate; retract",
    "commands": [
     "OpenBrandCampaignIntake",
     "IngestEvidence",
     "StartExtractionRun",
     "EvaluateHardGates",
     "ReleasePack",
     "DeliverCompletenessPack"
    ],
    "events": [
     "BrandCampaignIntakeAccepted",
     "EvidenceIngested",
     "GapMatrixDrafted",
     "HardGatesEvaluated",
     "PackReleased",
     "PackDelivered"
    ],
    "aggregates": [
     "BrandCampaignIntakeAggregate",
     "GapMatrixAggregate",
     "ExtractionRunAggregate",
     "ReleaseAggregate",
     "CompletenessPackAggregate"
    ],
    "success": "Completeness Pack delivered + release attached + audit trail complete",
    "failure_handling": "EscalationRaised -> decline/counsel-referral queue; DeliveryFailed -> customer alert + Success ticket",
    "audit": "Full command -> event chain with actor + timestamp per step"
   },
   {
    "name": "Run a vendor cure chase cycle and close a hard gap",
    "actor": "Registration analyst",
    "context": "Vendor Resubmit Desk + Completeness Pack Fulfillment",
    "goal": "Recover missing vendor records and clear a flagged hard gap",
    "preconditions": [
     "HardGatesEvaluated flagged a vendor-attributable gap",
     "Resubmit Desk purchased"
    ],
    "main_flow": [
     "Analyst dispatches a resubmission memo",
     "Vendor responds with cure evidence",
     "Analyst confirms cure evidence against the original clause",
     "Gap matrix re-scored"
    ],
    "alternative_flows": [
     "Vendor refuses to respond -> repeat chase cadence / escalate to owner demand",
     "Cure evidence incomplete -> gap stays open"
    ],
    "business_rules": [
     "Cure evidence must cite the original hard-gap clause",
     "No cure marked closed without a sourced document"
    ],
    "ai_role": "Draft resubmission memos; flag stale cases",
    "human_role": "Confirm cure evidence; close or re-escalate",
    "commands": [
     "DispatchChaseLetter",
     "ConfirmVendorCure"
    ],
    "events": [
     "ChaseLetterDispatched",
     "RejectionCured"
    ],
    "aggregates": [
     "VendorChaseCaseAggregate",
     "GapMatrixAggregate"
    ],
    "success": "Hard gap cured within 30 days and reflected in an updated gap matrix",
    "failure_handling": "VendorCureRejected -> chase case remains open, escalate to owner",
    "audit": "Chase letter + cure evidence archived, immutable"
   },
   {
    "name": "Resolve an owner action and flip release decision",
    "actor": "Customer operator (attesting for the building owner)",
    "context": "Compliance & Licensing Governance",
    "goal": "Close a blocking owner-supplied fact and recompute release readiness",
    "preconditions": [
     "Owner action open"
    ],
    "main_flow": [
     "Owner/operator supplies fact (e.g. vendor TCR profile custody attestation)",
     "Ledger updated",
     "Release decision recomputed",
     "Downstream contexts notified"
    ],
    "alternative_flows": [
     "Fact rejected -> OwnerActionRejected",
     "Legal review required -> route to legal reviewer"
    ],
    "business_rules": [
     "Release cannot flip to ready with any blocking action open"
    ],
    "ai_role": "Blocker digest",
    "human_role": "Supply fact + accept release",
    "commands": [
     "ResolveOwnerAction"
    ],
    "events": [
     "OwnerActionResolved"
    ],
    "aggregates": [
     "OwnerActionLedgerAggregate"
    ],
    "success": "Release decision flips or stays with a clear reason",
    "failure_handling": "OwnerActionRejected + retry loop",
    "audit": "Actor + before/after + timestamp"
   },
   {
    "name": "Retract a delivered Completeness Pack",
    "actor": "Legal reviewer + Licensed outside counsel",
    "context": "Release & Quality Assurance + Compliance & Licensing Governance",
    "goal": "Formally withdraw or correct a delivered pack after a material finding",
    "preconditions": [
     "Pack previously delivered",
     "Material finding documented"
    ],
    "main_flow": [
     "Finding documented",
     "Legal reviewer signs off on the retraction, informed by any outside-counsel guidance on record",
     "Customer notified",
     "Audit-log append"
    ],
    "alternative_flows": [
     "Outside counsel's guidance is disputed internally -> escalate to business owner",
     "TCR/insurer inquiry incoming -> run in parallel with legal-response workflow"
    ],
    "business_rules": [
     "Retraction requires legal sign-off, informed by any outside-counsel guidance on record"
    ],
    "ai_role": "Surface prior similar cases (assist only)",
    "human_role": "Co-sign + notify",
    "commands": [
     "RetractPack"
    ],
    "events": [
     "PackRetracted"
    ],
    "aggregates": [
     "PackRetractionAggregate",
     "OwnerActionLedgerAggregate"
    ],
    "success": "Retraction filed + customer notified + audit trail updated",
    "failure_handling": "RetractionRejected path escalates to business owner",
    "audit": "Full retraction packet archived, immutable"
   }
  ],
  "architecture": {
   "style": "modular-monolith-event-driven",
   "why": "Single team + single regulated vertical (SMS-campaign TCR profile documentation completeness) per blueprint + strong consistency requirements around release / delivery / release-decision favor a monolith. Event-driven internals give an audit-friendly append-only log without the operational cost of microservices.",
   "rejected_alternatives": [
    "Microservices -- no independent scaling or team boundary justifies distributed cost yet.",
    "Serverless-workflow-only -- analyst release and audit invariants are easier to keep correct in a monolith.",
    "No-code / low-code -- cannot enforce OutputValidator, prompt versioning, or per-tenant retrieval isolation with fidelity."
   ],
   "backend_modules": [
    "Completeness Pack Fulfillment",
    "AI Workbench & Extraction",
    "Release & Quality Assurance",
    "Compliance & Licensing Governance",
    "TCR Rule Library & Retrieval",
    "Sales & Intake",
    "Client Onboarding & Tenant Profile",
    "Client Delivery & Success",
    "Vendor Resubmit Desk",
    "Portfolio & Recurring Programs",
    "Analytics & Reporting"
   ],
   "frontend_modules": [
    "Operator dashboard",
    "Analyst console",
    "Counsel-referral tracking console",
    "Client portal",
    "Business owner console",
    "Ops (prompt registry) console"
   ],
   "api_boundaries": [
    "/intake/*",
    "/packs/*",
    "/analyst/*",
    "/compliance/*",
    "/knowledge/*",
    "/chase/*",
    "/portfolio/*",
    "/admin/*"
   ],
   "database_strategy": "One managed Postgres; schema-per-context; cross-context reads via published projections; RLS on protected tables.",
   "event_bus": "In-process event dispatcher backed by an outbox table (transactional publish); upgrade path to a real broker if throughput demands.",
   "queue": "Background job queue (managed) for extraction runs, delivery adapters, and reindex jobs.",
   "workflow_engine": "None initially -- orchestrate via domain events + policies; add a workflow engine if orchestrations exceed 5 sequential steps.",
   "ai_orchestration": "AI Workbench & Extraction context owns bounded agents; OutputValidator + prompt registry + tenant-scoped retrieval; retries with backoff.",
   "rag_layer": "Per-tenant partitioned evidence indices plus a shared CSP ruleset checklist index in a managed vector DB; ingestion pipeline in the TCR Rule Library & Retrieval context.",
   "file_storage": "Managed blob storage with per-tenant prefixes + signed URLs; TCR profiles, logs, and photos hashed on write.",
   "authn_authz": "IdP (Google / Okta) for authn; RBAC via a dedicated roles table with server-side checks + RLS.",
   "admin_dashboard": "Ops-facing admin for tenants, users, feature flags, prompt versions, and the CSP ruleset library.",
   "client_portal": "Customer-facing portal: submit intake, see gap-matrix status, receive packs and resubmit kits.",
   "operator_dashboard": "Internal: intake queue, analyst queue, escalation queue, delivery health, chase-case queue.",
   "observability": "Structured logs with tenant + request ids; RED metrics per workflow; error tracking with source maps; model-call spans with cost + latency; SLO review weekly.",
   "audit_logging": "Append-only audit log for all state transitions; hash-chained snapshots on released packs.",
   "deployment": "Single production region + multi-AZ managed DB; per-PR preview deploys; migrations gated on review."
  },
  "module_structure": {
   "tree": "/src\n  /contexts\n    /sales-intake\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /client-onboarding\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /completeness-pack-fulfillment\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /ai-workbench-extraction\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /release-quality-assurance\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /tcr-rule-library\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /compliance-licensing-governance\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /vendor-chase-desk\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /portfolio-recurring-programs\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /client-delivery\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n    /analytics\n      /domain\n      /application\n      /infrastructure\n      /interfaces\n  /shared\n    /kernel        # tiny -- Ids, Money, Tenant, Actor\n    /events        # published-language event contracts\n    /auth          # session + role primitives\n    /observability # logging, metrics, tracing\n    /config",
   "modules": [
    {
     "name": "completeness-pack-fulfillment",
     "purpose": "BrandCampaignIntake -> GapMatrix -> Completeness Pack lifecycle",
     "owned_domain": [
      "BrandCampaignIntake",
      "GapMatrix",
      "Completeness Pack",
      "Delivery"
     ],
     "application_services": [
      "OpenBrandCampaignIntake",
      "IngestEvidence",
      "EvaluateHardGates",
      "DeliverCompletenessPack"
     ],
     "infra_adapters": [
      "Delivery adapter",
      "Outbox publisher"
     ],
     "public_interfaces": [
      "/intake/*",
      "/packs/*"
     ],
     "forbidden_deps": [
      "billing infra",
      "identity provider internals"
     ]
    },
    {
     "name": "ai-workbench-extraction",
     "purpose": "Bounded AI extraction + classification agents",
     "owned_domain": [
      "ExtractionRun",
      "PromptVersion"
     ],
     "application_services": [
      "StartExtractionRun",
      "PublishPromptVersion"
     ],
     "infra_adapters": [
      "OpenAI/Anthropic client",
      "Retrieval router"
     ],
     "public_interfaces": [
      "internal"
     ],
     "forbidden_deps": [
      "cross-tenant retrieval",
      "direct delivery"
     ]
    },
    {
     "name": "release-quality-assurance",
     "purpose": "Release + retraction",
     "owned_domain": [
      "Release",
      "PackRetraction"
     ],
     "application_services": [
      "ReleasePack",
      "RetractPack"
     ],
     "infra_adapters": [
      "Release service"
     ],
     "public_interfaces": [
      "/analyst/*"
     ],
     "forbidden_deps": [
      "gap-matrix content mutation"
     ]
    },
    {
     "name": "compliance-licensing-governance",
     "purpose": "Owner-action ledger + release decision + licensing-boundary enforcement",
     "owned_domain": [
      "OwnerActionLedger",
      "ReleaseDecision",
      "DSARRequest"
     ],
     "application_services": [
      "ResolveOwnerAction",
      "ProcessDSAR"
     ],
     "infra_adapters": [
      "Email adapter"
     ],
     "public_interfaces": [
      "/compliance/*"
     ],
     "forbidden_deps": [
      "gap-matrix content"
     ]
    }
   ],
   "dependency_rules": [
    "Domain layer must not depend on infrastructure.",
    "Application layer may depend on domain.",
    "Infrastructure implements ports defined by application/domain.",
    "Interfaces call application services.",
    "Shared kernel must remain small (Ids, Money, Tenant, Actor).",
    "Contexts communicate through published events or explicit application APIs -- never via direct database access to another context."
   ]
  },
  "security_governance": {
   "controls": [
    {
     "risk": "Prompt injection via vendor invoice/log content",
     "context": "AI Workbench & Extraction",
     "impact": "high",
     "control": "Input scrubber + OutputValidator + tenant-scoped retrieval",
     "audit": "ExtractionRun trace"
    },
    {
     "risk": "Cross-tenant retrieval leak",
     "context": "TCR Rule Library & Retrieval",
     "impact": "severe",
     "control": "Per-tenant index partitions + TenantIsolationSpec enforced at router",
     "audit": "Retrieval call log"
    },
    {
     "risk": "Release-signature spoofing",
     "context": "Release & Quality Assurance",
     "impact": "severe",
     "control": "Release bound to authenticated session; server-side validation",
     "audit": "Release manifest"
    },
    {
     "risk": "Premature public claim of inspection-readiness",
     "context": "Compliance & Licensing Governance",
     "impact": "high",
     "control": "ReleaseReadinessSpec on OwnerActionLedger",
     "audit": "Release-decision log"
    },
    {
     "risk": "Privilege escalation",
     "context": "Identity & Access",
     "impact": "high",
     "control": "Roles in dedicated table + server-side checks + RLS",
     "audit": "Role assignment log"
    },
    {
     "risk": "Silent delivery failure ahead of an inspection date",
     "context": "Client Delivery & Success",
     "impact": "medium",
     "control": "Adapter receipt required; alert customer within 1h on failure",
     "audit": "Delivery receipt archive"
    }
   ],
   "ai_governance": [
    "Every prompt version has a named owner + eval run + rollout flag",
    "AI outputs marked as drafts until analyst release",
    "Model + prompt inventory maintained in the Ops console"
   ],
   "prompt_injection_defense": [
    "Strip / neutralize instruction-like patterns in vendor and customer inputs before prompt assembly",
    "Never concatenate raw vendor/customer input into a system prompt",
    "OutputValidator rejects outputs that reference forbidden actions"
   ],
   "sensitive_data_handling": [
    "PII scrubbed from logs",
    "Regulated data classes never sent to external model providers unless a DPA covers it",
    "Per-tenant blob storage prefixes + signed URLs"
   ],
   "access_control_matrix": [
    {
     "role": "Customer operator",
     "context": "Completeness Pack Fulfillment",
     "capabilities": [
      "OpenBrandCampaignIntake",
      "IngestEvidence",
      "View own packs"
     ]
    },
    {
     "role": "Registration analyst",
     "context": "Release & Quality Assurance",
     "capabilities": [
      "ReleasePack (green/yellow)",
      "Decline, or pause for outside-counsel referral"
     ]
    },
    {
     "role": "Licensed outside counsel",
     "context": "Release & Quality Assurance",
     "capabilities": [
      "ReleasePack (red)",
      "Author/certify TCR profile",
      "Co-sign retraction"
     ]
    },
    {
     "role": "Business owner / founder",
     "context": "Compliance & Licensing Governance",
     "capabilities": [
      "ResolveOwnerAction",
      "Set release-readiness decision"
     ]
    },
    {
     "role": "Legal reviewer",
     "context": "Release & Quality Assurance + Compliance",
     "capabilities": [
      "Co-sign retraction",
      "Handle DSAR"
     ]
    },
    {
     "role": "Ops",
     "context": "AI Workbench & Extraction",
     "capabilities": [
      "PublishPromptVersion",
      "Set confidence threshold"
     ]
    },
    {
     "role": "Platform admin",
     "context": "Identity & Access",
     "capabilities": [
      "Provision users",
      "Assign roles"
     ]
    }
   ],
   "audit_log_requirements": [
    "Append-only",
    "Actor + tenant + timestamp + command + before/after hash",
    "PII scrubbed",
    "Exportable per tenant on request (DSAR support)"
   ]
  },
  "observability": {
   "metrics": [
    {
     "metric": "Released Completeness Packs / week / tenant",
     "type": "business",
     "context": "Completeness Pack Fulfillment",
     "why": "North star: repeatable value delivery",
     "target": ">= contracted cadence",
     "alert_threshold": "< 80% of contracted cadence"
    },
    {
     "metric": "Scan-to-paid conversion",
     "type": "business",
     "context": "Sales & Intake",
     "why": "Validates the Gap Scan lead magnet",
     "target": ">= 25%",
     "alert_threshold": "< 15% monthly"
    },
    {
     "metric": "AI gap-matrix draft acceptance rate",
     "type": "ai-quality",
     "context": "AI Workbench & Extraction",
     "why": "Signals grounding + prompt fit",
     "target": ">= 70% by Phase 2",
     "alert_threshold": "< 50% weekly"
    },
    {
     "metric": "Escalation/decline rate",
     "type": "ai-quality",
     "context": "AI Workbench & Extraction",
     "why": "Guardrails firing correctly, not over- or under-escalating",
     "target": "<= 15% of packs",
     "alert_threshold": "> 30% weekly"
    },
    {
     "metric": "Cycle time to release (p50 + p95)",
     "type": "operational",
     "context": "Release & Quality Assurance",
     "why": "Analyst throughput vs the 7-business-day / 5-day rush standard",
     "target": "p95 <= 7 business days standard, <= 5 rush",
     "alert_threshold": "> 7 business days"
    },
    {
     "metric": "Hard-gap cure rate within 30 days",
     "type": "business",
     "context": "Vendor Resubmit Desk",
     "why": "Resubmit Desk value delivered",
     "target": ">= 70% when Resubmit Desk purchased",
     "alert_threshold": "< 50% monthly"
    },
    {
     "metric": "Delivery failure rate",
     "type": "reliability",
     "context": "Client Delivery & Success",
     "why": "Customer-facing reliability ahead of inspection dates",
     "target": "< 0.5%",
     "alert_threshold": "> 1% daily"
    },
    {
     "metric": "Owner-action open count",
     "type": "business",
     "context": "Compliance & Licensing Governance",
     "why": "Release-readiness for public claims",
     "target": "0 for launched blueprints",
     "alert_threshold": "any blocker aging > 30 days"
    },
    {
     "metric": "Model cost per pack",
     "type": "financial",
     "context": "AI Workbench & Extraction",
     "why": "Margin control against the >=55% gross-margin target",
     "target": "<= target per pricing tier",
     "alert_threshold": "> 1.5x target"
    },
    {
     "metric": "Cross-tenant retrieval violation attempts",
     "type": "risk",
     "context": "TCR Rule Library & Retrieval",
     "why": "Security invariant",
     "target": "0",
     "alert_threshold": "any > 0"
    }
   ],
   "dashboards": [
    "Operator dashboard",
    "Analyst queue",
    "Delivery health",
    "AI cost + escalation",
    "Compliance blockers"
   ],
   "audit_reports": [
    "Per-tenant audit-log export",
    "Release manifest export"
   ],
   "quality_review_reports": [
    "Analyst calibration report",
    "Escalation-outcome report"
   ],
   "ai_evaluation_reports": [
    "Eval Agent regression report",
    "Prompt-rollout diff"
   ],
   "client_outcome_reports": [
    "Packs delivered",
    "Cycle time",
    "Hard-gap cure rate"
   ]
  },
  "testing_strategy": {
   "tests": [
    {
     "type": "Domain unit",
     "validates": "Aggregate invariants",
     "context": "all core contexts",
     "example": "CompletenessPackAggregate rejects delivery without a release"
    },
    {
     "type": "Aggregate invariant",
     "validates": "Consistency boundaries",
     "context": "Completeness Pack Fulfillment / Release & QA",
     "example": "Released pack is immutable"
    },
    {
     "type": "Policy",
     "validates": "Reactive rules",
     "context": "AI Workbench & Extraction",
     "example": "Escalates below confidence threshold or on no-TCR-profile-found"
    },
    {
     "type": "Specification",
     "validates": "Reusable rules",
     "context": "Compliance & Licensing Governance",
     "example": "ReleaseReadinessSpec blocks 'ready' with open owner actions"
    },
    {
     "type": "Application use-case",
     "validates": "End-to-end command flow",
     "context": "Fulfillment + QA",
     "example": "Deliver a released Completeness Pack happy path"
    },
    {
     "type": "Integration",
     "validates": "Adapter behavior",
     "context": "External Integrations",
     "example": "Vendor invoice inbox adapter translates correctly"
    },
    {
     "type": "Contract",
     "validates": "Published-language event schemas",
     "context": "cross-context",
     "example": "GapMatrixDrafted payload matches consumer expectations"
    },
    {
     "type": "AI prompt eval",
     "validates": "Prompt quality vs golden dataset",
     "context": "AI Workbench & Extraction",
     "example": "Extraction Agent accepts >= 40% in shadow mode"
    },
    {
     "type": "RAG retrieval",
     "validates": "Tenant isolation + TCR-edition coverage",
     "context": "TCR Rule Library & Retrieval",
     "example": "Cross-tenant lookup returns zero rows"
    },
    {
     "type": "Golden dataset",
     "validates": "AI regression",
     "context": "AI Workbench & Extraction",
     "example": "No regression on past released packs"
    },
    {
     "type": "Human review simulation",
     "validates": "Escalation UX",
     "context": "Release & Quality Assurance",
     "example": "Analyst can complete a release in <= 5 clicks"
    },
    {
     "type": "End-to-end",
     "validates": "Critical path",
     "context": "all",
     "example": "Intake -> release -> delivery in staging"
    },
    {
     "type": "Security",
     "validates": "Auth + RLS + injection defense",
     "context": "Identity + AI Workbench & Extraction",
     "example": "Prompt-injection payload is neutralized"
    },
    {
     "type": "Regression",
     "validates": "No drift on prior fixes",
     "context": "all",
     "example": "Prior retraction bug does not reappear"
    }
   ],
   "critical_domain_rules": [
    "No delivery without a release",
    "No AI extraction output without an OutputValidator pass",
    "No TCR retrieval outside the correct edition or tenant partition",
    "No public release-readiness claim with open blockers"
   ],
   "ai_eval_dataset": [
    "50 past analyst-released Completeness Packs per TCR (redacted)",
    "20 rejected drafts (ground truth for escalation)",
    "10 injection-payload cases"
   ],
   "regression_plan": "Every PR runs domain + policy + spec unit tests. Every prompt release runs the Eval Agent with a regression gate. Weekly critical-path smoke test in staging.",
   "contract_testing_plan": "Published-language event schemas versioned in /shared/events; consumer tests run in CI against schema-version compatibility.",
   "manual_qa_checklist": [
    "Release flow: signature captured + timestamp + hash",
    "Retraction flow: co-sign captured + customer notified",
    "Delivery flow: receipt archived",
    "DSAR flow: export completes end-to-end"
   ]
  },
  "mvp_roadmap": [
   {
    "phase": "Phase 0 -- Manual workflow with instrumented capture",
    "goal": "Deliver one Completeness Pack end-to-end manually, capture every step as a domain event.",
    "features": [
     "Manual intake form",
     "Evidence upload",
     "Human-drafted gap matrix",
     "Analyst release via signed form"
    ],
    "contexts": [
     "Sales & Intake",
     "Completeness Pack Fulfillment",
     "Release & Quality Assurance"
    ],
    "ai_needs": [
     "[PLACEHOLDER] owner to complete"
    ],
    "human_workflows": [
     "Analyst release"
    ],
    "data_needs": [
     "BrandCampaignIntake",
     "GapMatrix",
     "Completeness Pack"
    ],
    "integrations": [
     "Email"
    ],
    "risks": [
     "Un-audited manual step"
    ],
    "exit_criteria": [
     "1 real Completeness Pack delivered + analyst-released"
    ]
   },
   {
    "phase": "Phase 1 -- AI-assisted extraction for internal use only",
    "goal": "Introduce the Extraction Agent with an analyst gate; no customer-facing AI language.",
    "features": [
     "Extraction Agent (internal)",
     "OutputValidator",
     "Escalation route"
    ],
    "contexts": [
     "AI Workbench & Extraction",
     "Completeness Pack Fulfillment"
    ],
    "ai_needs": [
     "Extraction Agent, Routing & Classification Agent"
    ],
    "human_workflows": [
     "Escalation review"
    ],
    "data_needs": [
     "ExtractionRun",
     "PromptVersion"
    ],
    "integrations": [
     "OpenAI / Anthropic"
    ],
    "risks": [
     "Prompt injection",
     "Grounding drift"
    ],
    "exit_criteria": [
     "AI draft acceptance rate >= 40% in shadow mode"
    ]
   },
   {
    "phase": "Phase 2 -- Operator dashboard + owner-action ledger",
    "goal": "Make the workflow legible and governable for the business owner.",
    "features": [
     "Operator dashboard",
     "Owner-action ledger",
     "Release-decision engine"
    ],
    "contexts": [
     "Compliance & Licensing Governance"
    ],
    "ai_needs": [],
    "human_workflows": [
     "Owner action resolution"
    ],
    "data_needs": [
     "OwnerActionLedger"
    ],
    "integrations": [
     "IdP"
    ],
    "risks": [
     "Ungoverned public claims"
    ],
    "exit_criteria": [
     "Release decisions computed from the ledger"
    ]
   },
   {
    "phase": "Phase 3 -- Client delivery portal + Vendor Resubmit Desk",
    "goal": "Give customers a portal to see gap-matrix status and receive packs and resubmit kits.",
    "features": [
     "Client portal",
     "Delivery adapter",
     "Vendor Resubmit Desk case tracking"
    ],
    "contexts": [
     "Client Delivery & Success",
     "Vendor Resubmit Desk"
    ],
    "ai_needs": [
     "Chase-letter drafting"
    ],
    "human_workflows": [
     "Success cadence",
     "Chase-case management"
    ],
    "data_needs": [
     "Delivery",
     "VendorChaseCase"
    ],
    "integrations": [
     "Email"
    ],
    "risks": [
     "Silent delivery failure"
    ],
    "exit_criteria": [
     "Delivery-failure alert within 1h"
    ]
   },
   {
    "phase": "Phase 4 -- Automated QA, Portfolio Desk, and reporting",
    "goal": "Wire metrics, the retraction runbook, the eval agent, and Portfolio Desk enrollment.",
    "features": [
     "Eval Agent",
     "Retraction workflow",
     "Portfolio Desk enrollment + quarterly re-scan",
     "Dashboards"
    ],
    "contexts": [
     "Analytics & Reporting",
     "Release & Quality Assurance",
     "Portfolio & Recurring Programs"
    ],
    "ai_needs": [
     "Eval Agent"
    ],
    "human_workflows": [
     "Retraction co-sign"
    ],
    "data_needs": [
     "PackRetraction",
     "Portfolio"
    ],
    "integrations": [],
    "risks": [
     "Vanity metrics"
    ],
    "exit_criteria": [
     "North-star + guardrail metrics live"
    ]
   },
   {
    "phase": "Phase 5 -- Scale + optimization",
    "goal": "Reduce cost per pack, increase analyst throughput, expand TCR coverage.",
    "features": [
     "Prompt versioning UI",
     "Cost budgeting",
     "Multi-analyst queue",
     "Third CSP ruleset onboarded"
    ],
    "contexts": [
     "AI Workbench & Extraction",
     "Release & Quality Assurance",
     "TCR Rule Library & Retrieval"
    ],
    "ai_needs": [
     "Cost meter"
    ],
    "human_workflows": [
     "Multi-analyst routing"
    ],
    "data_needs": [],
    "integrations": [],
    "risks": [
     "Regression on rollout"
    ],
    "exit_criteria": [
     "Model cost per pack <= target"
    ]
   }
  ],
  "scaling_roadmap": [
   {
    "stage": "<= 5 tenants",
    "trigger": "Design-partner / pilot cohort (8-building cap)",
    "architecture_change": "Single-region modular monolith + managed DB",
    "operational_change": "Founder-led ops; weekly working session",
    "risk": "Single-analyst queue"
   },
   {
    "stage": "5-25 tenants",
    "trigger": "First paid conversions past the pilot cap",
    "architecture_change": "Extract the heaviest module (AI Workbench & Extraction) behind an internal queue; keep the monolith",
    "operational_change": "Named on-call rotation; SOC 2 Type I scoping",
    "risk": "Analyst bottleneck"
   },
   {
    "stage": "25-100 tenants",
    "trigger": "Multi-analyst demand and a third CSP ruleset",
    "architecture_change": "Split AI Workbench & Extraction into its own service if throughput/isolation demands it; per-tenant retrieval sharding",
    "operational_change": "Dedicated success + prompt-ops roles",
    "risk": "Prompt version drift"
   },
   {
    "stage": "100+ tenants",
    "trigger": "Enterprise portfolios and additional high-enforcement CSPs",
    "architecture_change": "Regional deployments; per-region data residency; segregated compliance environments",
    "operational_change": "Dedicated SRE + compliance team; SOC 2 Type II + framework additions",
    "risk": "Compliance framework demand exceeds team capacity"
   }
  ],
  "risk_register": [
   {
    "risk": "CSP ruleset mismatch causes a false hard-fail",
    "likelihood": "medium",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Maintain edition-dated checklist cards; cite the edition on every pack; dual-check Twilio and Virginia first",
    "owner": "engineering",
    "context": "TCR Rule Library & Retrieval"
   },
   {
    "risk": "Client expects a guaranteed inspection pass",
    "likelihood": "high",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Contract language: documentation-readiness support only; owner remains responsible party; no pass guarantee",
    "owner": "legal",
    "context": "Compliance & Licensing Governance"
   },
   {
    "risk": "Licensed outside counsel partners perceive TCR profileEvidence archive as a competitor",
    "likelihood": "medium",
    "impact": "medium",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Refer technical Brand+Campaign registration setup out; revenue-share on escalations; position as a referral funnel",
    "owner": "owner",
    "context": "Release & Quality Assurance"
   },
   {
    "risk": "OEM/vendor refuses to share TCR profile or service logs",
    "likelihood": "high",
    "impact": "medium",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Owner-property framing; contract clause templates; photo of the on-site binder; escalate to owner demand",
    "owner": "ops",
    "context": "Vendor Resubmit Desk"
   },
   {
    "risk": "Fabricated or AI-hallucinated log dates in a released pack",
    "likelihood": "low",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Evidence citations mandatory; QA red-team; no free-text dates without a source span",
    "owner": "engineering",
    "context": "AI Workbench & Extraction"
   },
   {
    "risk": "DeviceClear brand confusion",
    "likelihood": "medium",
    "impact": "medium",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Explicit 'not a filing service' positioning; separate slug/brand",
    "owner": "owner",
    "context": "Sales & Intake"
   },
   {
    "risk": "Cybersecurity module scope creep (A17.1-2025 networked-control content)",
    "likelihood": "medium",
    "impact": "medium",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Optional TCR-conditional checklist module only; do not block the MVP",
    "owner": "engineering",
    "context": "TCR Rule Library & Retrieval"
   },
   {
    "risk": "Low willingness-to-pay vs. a 'good enough' free vendor PDF",
    "likelihood": "medium",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Gap Scan shows the generic/incomplete TCR profile; price against coordinator hours + inspection risk",
    "owner": "owner",
    "context": "Sales & Intake"
   },
   {
    "risk": "Litigation-discovery subpoena of the evidence archive",
    "likelihood": "low",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Retention policy; client-owned evidence archive option; legal review of the MSA",
    "owner": "legal",
    "context": "Compliance & Licensing Governance"
   },
   {
    "risk": "Analyst shortage / early demand trap",
    "likelihood": "medium",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Hard pilot cap of 8 buildings; build-before-scale gates",
    "owner": "ops",
    "context": "Release & Quality Assurance"
   },
   {
    "risk": "Mis-selling as engineering / outside counsel services",
    "likelihood": "medium",
    "impact": "high",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Licensing-boundary training; website disclaimers; escalation SOP",
    "owner": "legal",
    "context": "Compliance & Licensing Governance"
   },
   {
    "risk": "Portfolio Desk scope-creeps into unpaid custom consulting",
    "likelihood": "medium",
    "impact": "medium",
    "signal": "See ProductBlueprintDNA / risk register for tuned early-warning signals",
    "mitigation": "Scope menu; change-order for authorship; weekly cap",
    "owner": "ops",
    "context": "Portfolio & Recurring Programs"
   }
  ],
  "adrs": [
   {
    "id": "ADR-001",
    "decision": "Architecture style",
    "status": "accepted",
    "context": "Single team, single regulated vertical (SMS-campaign TCR profile documentation) per blueprint, evidence-linked workflow.",
    "options": [
     "Modular monolith",
     "Microservices",
     "Serverless workflow",
     "No-code first"
    ],
    "chosen": "Modular monolith with event-driven internals",
    "business_reason": "Ship a defensible vertical slice with one team; avoid distributed-systems cost until scale forces it.",
    "technical_reason": "Deterministic transactions across aggregates; simpler ops; one deployable.",
    "tradeoffs": [
     "May feel unsophisticated to enterprise reviewers",
     "Refactor cost if we later split"
    ],
    "risks": [
     "Module boundaries erode without discipline"
    ],
    "revisit_trigger": "Any single module needs independent scaling or a team boundary."
   },
   {
    "id": "ADR-002",
    "decision": "Bounded context boundaries",
    "status": "accepted",
    "context": "Domain analysis above; distinct language groups for Fulfillment, AI Workbench, Release & QA, Compliance & Licensing.",
    "options": [
     "Contexts as above",
     "One big 'app' context",
     "Contexts split by UI page"
    ],
    "chosen": "Contexts as above (domain-derived)",
    "business_reason": "Protects the release invariant + owner-action ledger + evidence spine as first-class boundaries.",
    "technical_reason": "Aggregates align to consistency boundaries; ACLs contain external mess.",
    "tradeoffs": [
     "More code organization discipline"
    ],
    "risks": [
     "Team tries to bypass the ACL for speed"
    ],
    "revisit_trigger": "New subdomain emerges (e.g. a self-serve marketplace)."
   },
   {
    "id": "ADR-003",
    "decision": "Database ownership",
    "status": "accepted",
    "context": "Modular monolith with a shared Postgres; per-context schemas.",
    "options": [
     "One shared schema",
     "Schema per context",
     "DB per context"
    ],
    "chosen": "Schema per context in a shared Postgres, cross-context reads only via published projections.",
    "business_reason": "Keeps operational cost low; enforces boundaries without paying the multi-DB tax.",
    "technical_reason": "RLS + schema separation gives ownership clarity.",
    "tradeoffs": [
     "Discipline required to avoid cross-schema joins"
    ],
    "risks": [
     "Bypass joins for speed"
    ],
    "revisit_trigger": "A context needs independent scaling or residency."
   },
   {
    "id": "ADR-004",
    "decision": "AI orchestration strategy",
    "status": "accepted",
    "context": "Retrieval-first with structured-output validation + human release gate.",
    "options": [
     "Open-ended chat",
     "Retrieval-first + validated",
     "Autonomous multi-agent"
    ],
    "chosen": "Retrieval-first + structured validation + analyst/counsel-cleared analyst release gate",
    "business_reason": "Grounding and inspection defensibility are the paid outcome.",
    "technical_reason": "OutputValidator gives a hard boundary before drafts leave AI Workbench & Extraction.",
    "tradeoffs": [
     "Slower than agentic chat"
    ],
    "risks": [
     "Prompt version regression"
    ],
    "revisit_trigger": "The Eval Agent shows a step-function accuracy gain from a new pattern."
   },
   {
    "id": "ADR-005",
    "decision": "Human review strategy",
    "status": "accepted",
    "context": "Regulated vertical; brand + liability-adjacent risk on wrong outputs.",
    "options": [
     "No human review (fully automated)",
     "Sampling review",
     "Every-pack review"
    ],
    "chosen": "Every-pack review by a named registration analyst (or outside counsel on red packs)",
    "business_reason": "Release is the trust primitive.",
    "technical_reason": "Release bound to session; append-only log.",
    "tradeoffs": [
     "Analyst throughput becomes the bottleneck"
    ],
    "risks": [
     "Analyst burnout during high-enforcement season"
    ],
    "revisit_trigger": "Sustained low retraction rate + TCR acceptance."
   },
   {
    "id": "ADR-006",
    "decision": "Integration strategy",
    "status": "accepted",
    "context": "External systems: vendor invoice inboxes, SMS-campaign-vendor work-order/CMMS platforms, customer document portals, ...",
    "options": [
     "Direct API coupling",
     "Anti-corruption layer per system",
     "Middleware bus (Zapier/n8n)"
    ],
    "chosen": "Anti-corruption layer per system, owned by the External Integrations context",
    "business_reason": "External schemas must never leak into the core.",
    "technical_reason": "Adapters translate + validate; upstream breakage is contained.",
    "tradeoffs": [
     "More code than direct coupling"
    ],
    "risks": [
     "Adapter lag on upstream change"
    ],
    "revisit_trigger": "External system stability changes materially."
   },
   {
    "id": "ADR-007",
    "decision": "Modular monolith vs microservices",
    "status": "accepted",
    "context": "Same as ADR-001.",
    "options": [
     "Monolith",
     "Microservices"
    ],
    "chosen": "Monolith",
    "business_reason": "Team size and scale do not justify microservices cost.",
    "technical_reason": "Distributed transactions across release/delivery would be a nightmare early.",
    "tradeoffs": [
     "Refactor cost later"
    ],
    "risks": [
     "Cultural expectation drift"
    ],
    "revisit_trigger": "See ADR-001."
   },
   {
    "id": "ADR-008",
    "decision": "Build vs buy for generic subdomains",
    "status": "accepted",
    "context": "Billing, Identity, IdP, email.",
    "options": [
     "Build all",
     "Buy generics"
    ],
    "chosen": "Buy generics (Stripe, IdP, transactional email)",
    "business_reason": "Do not spend core-domain hours on solved categories.",
    "technical_reason": "Standard SDKs + well-documented failure modes.",
    "tradeoffs": [
     "Vendor risk"
    ],
    "risks": [
     "Vendor lock-in"
    ],
    "revisit_trigger": "Cost or reliability materially degrades."
   }
  ],
  "self_audit": {
   "scores": [
    {
     "category": "Domain accuracy",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Ubiquitous language quality",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Subdomain classification quality",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Bounded context clarity",
     "score": 9,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Core domain focus",
     "score": 9,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Context map quality",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Aggregate design quality",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Invariant quality",
     "score": 9,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "AI-agent responsibility design",
     "score": 9,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Human review safety",
     "score": 9,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Data ownership clarity",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Integration protection",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Implementation feasibility",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Scalability",
     "score": 7,
     "weakness": "Single-region; single-analyst bottleneck; monolith split not yet planned.",
     "improvement": "Add a per-tenant extraction queue + multi-analyst routing at Phase 2."
    },
    {
     "category": "Security and compliance",
     "score": 7,
     "weakness": "High-trust, liability-adjacent vertical needs Type II mapping and per-TCR controls earlier.",
     "improvement": "Map controls at Phase 1; commit to Type II by Phase 3."
    },
    {
     "category": "Testing strategy",
     "score": 8,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    },
    {
     "category": "Operational realism",
     "score": 7,
     "weakness": "Founder-led ops assumed through Phase 2; brittle to key-person absence.",
     "improvement": "Document runbooks; cross-train a success + prompt-ops role by Phase 2."
    },
    {
     "category": "MVP practicality",
     "score": 9,
     "weakness": "None material at this stage.",
     "improvement": "Maintain the current standard; re-audit after the first pilot buildings land real data."
    }
   ],
   "weakest_parts": [
    "Scalability plan assumes a single registration analyst per tenant through Phase 2",
    "Operational realism depends on founder-led ops",
    "Compliance framework depth for Type II"
   ],
   "biggest_assumptions": [
    "The target audience will pay for a released, checklist-cited documentation-completeness pack over a free vendor-supplied PDF.",
    "A Completeness Pack can be reconstructed from an owner-supplied evidence set within the standard 7-business-day cycle.",
    "The vertical tolerates AI-assisted extraction and drafting when compliance-analyst review is explicit and audit-traceable."
   ],
   "highest_risk_decisions": [
    "Modular monolith (ADR-001)",
    "Every-pack analyst/counsel-cleared analyst release (ADR-005)",
    "Anti-corruption layer per external system (ADR-006)"
   ],
   "needs_domain_expert": [
    "Licensed outside counsel to validate release-gate ergonomics on red packs",
    "TCR-program subject-matter expert on Twilio and Telnyx/Bandwidth edition nuances"
   ],
   "needs_legal": [
    "Retraction workflow language",
    "DSAR SLA + TCR/regulator-response runbook",
    "Public release-readiness claim policy for the microsite"
   ],
   "needs_prototype": [
    "Extraction Agent accuracy on a 20-case golden dataset",
    "Analyst release UX end-to-end in <= 5 minutes per pack",
    "Per-tenant retrieval isolation test on the TCR Rule Library"
   ],
   "validate_before_prod": [
    "Named registration analyst of record + engagement letter on file",
    "Owner-action ledger populated per launch tenant",
    "OutputValidator false-negative rate acceptable",
    "Delivery failure alert path tested"
   ]
  },
  "final_recommendations": [
   "Ship a modular-monolith, evidence-linked, release-gated vertical slice for CampaignClear. Preserve the invariant that no Completeness Pack leaves the system without a signed human release -- registration analyst on green/yellow, customer's outside counsel (referral only) on red. Do not launch commercially until owner-action facts close and at least one human-released Completeness Pack is delivered.",
   "Do NOT default to microservices. Extract a module only when a specific pressure demands it.",
   "Do NOT allow AI extraction outputs to leave AI Workbench & Extraction without an OutputValidator pass and citation coverage.",
   "Do NOT ship any release-readiness claim on the CampaignClear microsite while owner actions are open.",
   "Do NOT store roles on user/profile tables; use a dedicated roles table with server-side checks + RLS.",
   "DO wire the north-star (scan-to-paid) + guardrail metrics before Phase 2 launch.",
   "DO capture every state transition as an append-only domain event; the Evidence Index is the product."
  ],
  "extensions": {
   "service_business_reality_check": {
    "is_service_business": true,
    "paid_outcome_clear": true,
    "workflow_present": true,
    "ai_native_fit_score": 8,
    "red_flags": [
     "[PLACEHOLDER] owner to complete"
    ]
   },
   "ai_native_fit": {
    "score": 8,
    "why": "Evidence-linked extraction + confidence-scored escalation is only economical with bounded AI orchestration. Pure-manual audit consulting is uneconomic at pack pricing; a pure-automated SaaS tracker is undefensible without a human release gate.",
    "disqualifiers": [
     "Liability-adjacent vertical: cannot ship without a named registration analyst / licensed counsel-cleared analyst release"
    ]
   },
   "domain_evidence_register": [
    {
     "claim": "CampaignClear's paid outcome is an analyst-released Completeness Pack",
     "evidence_type": "primary",
     "source": "Business Understanding + subdomain 'Completeness Pack Fulfillment'",
     "strength": "strong",
     "gaps": "Confirm with 3 design-partner interviews in Twilio-anchored senders"
    },
    {
     "claim": "Analyst or counsel-cleared analyst release is commercially required for inspection defensibility",
     "evidence_type": "primary",
     "source": "TCR Brand & Campaign vetting checklist / TCR enforcement archetype (Twilio, Telnyx/Bandwidth)",
     "strength": "strong",
     "gaps": "Vertical-specific attestation-standard citation"
    },
    {
     "claim": "AI extraction materially reduces cycle time vs. pure-manual document review",
     "evidence_type": "assumed",
     "source": "Category benchmark (DFY registration-help pricing norms)",
     "strength": "medium",
     "gaps": "Measure on internal golden dataset"
    },
    {
     "claim": "Customer will supply structured intake (TCR profile, logs, callbacks, photos) within SLA",
     "evidence_type": "assumed",
     "source": "Prospect conversations (unverified)",
     "strength": "weak",
     "gaps": "Run 5 intake dry-runs with pilot buildings"
    },
    {
     "claim": "Per-tenant TCR retrieval isolation prevents cross-tenant leakage",
     "evidence_type": "primary",
     "source": "Architecture (TCR Rule Library & Retrieval context)",
     "strength": "strong",
     "gaps": "Add automated cross-tenant lookup test"
    },
    {
     "claim": "Owner-action ledger blocks a premature release-readiness claim",
     "evidence_type": "primary",
     "source": "Compliance & Licensing Governance context invariants",
     "strength": "strong",
     "gaps": "None"
    },
    {
     "claim": "Model + prompt versioning enables reproducible gap-matrix outputs",
     "evidence_type": "primary",
     "source": "AI Workbench & Extraction context",
     "strength": "strong",
     "gaps": "Eval Agent regression thresholds not yet baselined"
    },
    {
     "claim": "Cycle-time reduction supports the $1,450-$2,850 pack pricing tier",
     "evidence_type": "assumed",
     "source": "Pricing hypothesis anchored to DFY registration-help pricing norms",
     "strength": "medium",
     "gaps": "Test with 3 pricing conversations"
    }
   ],
   "assumption_register": [
    {
     "assumption": "The target audience will pay for a released, checklist-cited documentation-completeness pack over a free vendor-supplied PDF.",
     "impact_if_wrong": "high",
     "how_to_validate": "Pilot-building interview + measurement",
     "blocking": true
    },
    {
     "assumption": "A Completeness Pack can be reconstructed from an owner-supplied evidence set within the standard 7-business-day cycle.",
     "impact_if_wrong": "high",
     "how_to_validate": "Pilot-building interview + measurement",
     "blocking": true
    },
    {
     "assumption": "The vertical tolerates AI-assisted extraction and drafting when compliance-analyst review is explicit and audit-traceable.",
     "impact_if_wrong": "high",
     "how_to_validate": "Pilot-building interview + measurement",
     "blocking": false
    },
    {
     "assumption": "Logical per-tenant isolation with row-level auth is acceptable for the first cohort -- single-tenant infrastructure is not required.",
     "impact_if_wrong": "medium",
     "how_to_validate": "Instrument metric + review after Phase 1",
     "blocking": false
    },
    {
     "assumption": "Twilio-anchored senders and Telnyx/Bandwidth enforcement signals generalize to other high-enforcement CSPs as the rule library expands.",
     "impact_if_wrong": "medium",
     "how_to_validate": "Instrument metric + review after Phase 1",
     "blocking": false
    },
    {
     "assumption": "A customer's outside counsel (referral only) can be sourced and retained for this vertical.",
     "impact_if_wrong": "severe",
     "how_to_validate": "Recruit + sign engagement letter before commercial launch",
     "blocking": true
    },
    {
     "assumption": "External systems (vendor invoice inboxes, CMMS platforms) expose stable APIs with predictable failure modes.",
     "impact_if_wrong": "medium",
     "how_to_validate": "Adapter contract tests + failure-injection",
     "blocking": false
    }
   ],
   "language_conflict_map": [
    {
     "term": "Engagement",
     "meaning_a": "A signed billing contract",
     "context_a": "Billing & Revenue",
     "meaning_b": "An accepted unit of intake work",
     "context_b": "Sales & Intake",
     "resolution": "Billing owns 'Subscription'; Sales & Intake owns 'Engagement' as the accepted-intake noun."
    },
    {
     "term": "Release",
     "meaning_a": "Analyst signs a Completeness Pack",
     "context_a": "Release & Quality Assurance",
     "meaning_b": "Business owner decides a public claim is release-ready",
     "context_b": "Compliance & Licensing Governance",
     "resolution": "QA uses 'analyst release' / 'counsel-cleared analyst release'; Compliance uses 'release-readiness decision' -- never conflate the two."
    },
    {
     "term": "Confidence",
     "meaning_a": "Model-assigned probability",
     "context_a": "AI Workbench & Extraction",
     "meaning_b": "Human analyst confidence in a gap-matrix line",
     "context_b": "Release & Quality Assurance",
     "resolution": "Never conflate; always qualify (model_confidence vs analyst_confidence)."
    }
   ],
   "build_buy_integrate": [
    {
     "subdomain": "Completeness Pack Fulfillment (evidence-linked extraction + release)",
     "decision": "build",
     "reason": "This is what customers pay for and what an carrier vetting review tests against."
    },
    {
     "subdomain": "AI Workbench & Extraction (bounded agents + retrieval)",
     "decision": "build",
     "reason": "The AI-native competitive edge lives here; misuse here creates every high-severity risk."
    },
    {
     "subdomain": "Release & Quality Assurance (analyst release + counsel-referral pause + retraction)",
     "decision": "build",
     "reason": "Release is the trust primitive of the whole business."
    },
    {
     "subdomain": "TCR Rule Library & Retrieval",
     "decision": "build",
     "reason": "Poor or stale TCR retrieval directly causes false hard-fails."
    },
    {
     "subdomain": "Compliance & Licensing Governance",
     "decision": "build",
     "reason": "Cross-cuts every context; owns the licensing-boundary and release-claim decision."
    },
    {
     "subdomain": "Sales & Intake",
     "decision": "build",
     "reason": "Feeds Fulfillment; not the differentiator, but if broken, nothing else runs."
    },
    {
     "subdomain": "Client Onboarding & Tenant Profile",
     "decision": "build",
     "reason": "One-time high-touch step per customer."
    },
    {
     "subdomain": "Client Delivery & Success",
     "decision": "build",
     "reason": "Customer-visible surface; drives retention."
    },
    {
     "subdomain": "Vendor Resubmit Desk",
     "decision": "build",
     "reason": "Monetizes the highest-friction part of the workflow without becoming unpaid consulting."
    },
    {
     "subdomain": "Portfolio & Recurring Programs",
     "decision": "build",
     "reason": "Converts one-time packs into recurring revenue for multi-building owners."
    },
    {
     "subdomain": "Billing & Revenue",
     "decision": "buy",
     "reason": "Solved category; do not build."
    },
    {
     "subdomain": "Identity & Access",
     "decision": "integrate",
     "reason": "Solved category."
    },
    {
     "subdomain": "Analytics & Reporting",
     "decision": "build",
     "reason": "Drives every operational decision against the brief's KPI targets."
    },
    {
     "subdomain": "External Integrations (Anti-Corruption Layer)",
     "decision": "build",
     "reason": "External schemas must never leak into the core."
    }
   ],
   "core_protection_strategy": [
    "Core contexts (Completeness Pack Fulfillment, AI Workbench & Extraction, Release & Quality Assurance) staffed before any generic subdomain work.",
    "Any change to a core aggregate requires a paired ADR + invariant test.",
    "Generic subdomains (Billing, Identity) are bought or integrated; never built in-house without a killer reason.",
    "Prompt-version rollout to core agents gated on an Eval Agent regression run.",
    "No feature flag may bypass the analyst/counsel-cleared analyst release invariant."
   ],
   "boundary_stress_tests": [
    {
     "scenario": "Customer requests changes to a delivered Completeness Pack",
     "contexts_touched": [
      "Client Delivery & Success",
      "Completeness Pack Fulfillment",
      "Release & Quality Assurance"
     ],
     "breaks_if": "A revision creates a new gap matrix without re-triggering release",
     "verdict": "holds"
    },
    {
     "scenario": "Registration analyst of record changes mid-engagement",
     "contexts_touched": [
      "Client Onboarding & Tenant Profile",
      "Release & Quality Assurance"
     ],
     "breaks_if": "QA cached the analyst identity locally",
     "verdict": "adjust"
    },
    {
     "scenario": "the Twilio CSP vetting desk or Telnyx/Bandwidth finalizes a rule change touching TCR checklist scope",
     "contexts_touched": [
      "Compliance & Licensing Governance",
      "TCR Rule Library & Retrieval"
     ],
     "breaks_if": "The retrieval index is not reindexed within SLA",
     "verdict": "holds"
    },
    {
     "scenario": "Owner/operator marks an owner action resolved that is actually not",
     "contexts_touched": [
      "Compliance & Licensing Governance"
     ],
     "breaks_if": "No re-verification step before the release decision flips",
     "verdict": "adjust"
    },
    {
     "scenario": "AI produces a high-confidence gap-matrix line with a wrong citation",
     "contexts_touched": [
      "AI Workbench & Extraction",
      "Release & Quality Assurance"
     ],
     "breaks_if": "OutputValidator does not check citation-to-claim linkage",
     "verdict": "holds"
    }
   ],
   "unresolved_ownership": [
    {
     "concept": "Registration analyst engagement letter",
     "candidates": [
      "Client Onboarding & Tenant Profile",
      "Release & Quality Assurance"
     ],
     "recommendation": "Own in Client Onboarding & Tenant Profile; QA references by id."
    },
    {
     "concept": "Public release-readiness claim / marketing site content",
     "candidates": [
      "Compliance & Licensing Governance",
      "Client Delivery & Success"
     ],
     "recommendation": "Compliance owns the release-decision; Delivery renders it."
    },
    {
     "concept": "Model + prompt cost attribution",
     "candidates": [
      "AI Workbench & Extraction",
      "Billing & Revenue"
     ],
     "recommendation": "AI Workbench & Extraction owns the raw run cost; Billing consumes rolled-up projections."
    }
   ],
   "published_language_contracts": [
    {
     "producer": "Sales & Intake",
     "consumer": "Completeness Pack Fulfillment",
     "contract": "EngagementAccepted",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "Completeness Pack Fulfillment",
     "consumer": "Release & Quality Assurance",
     "contract": "GapMatrixDrafted, HardGatesEvaluated",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "AI Workbench & Extraction",
     "consumer": "Completeness Pack Fulfillment",
     "contract": "GapMatrixDrafted, EscalationRaised",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "TCR Rule Library & Retrieval",
     "consumer": "AI Workbench & Extraction",
     "contract": "RuleUpdateIngested, IndexRebuilt",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "Client Onboarding & Tenant Profile",
     "consumer": "Completeness Pack Fulfillment",
     "contract": "TenantProvisioned, AnalystOfRecordRegistered",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "Completeness Pack Fulfillment",
     "consumer": "Client Delivery & Success",
     "contract": "PackDelivered, DeliveryConfirmed",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "Release & Quality Assurance",
     "consumer": "Compliance & Licensing Governance",
     "contract": "PackRetracted",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    },
    {
     "producer": "Vendor Resubmit Desk",
     "consumer": "Completeness Pack Fulfillment",
     "contract": "RejectionCured",
     "versioning": "SemVer on event schema; consumer contract tests in CI."
    }
   ],
   "shared_kernel_warnings": [
    "Shared kernel must remain small: Ids, Money, Tenant, Actor. Adding a domain concept here couples every context.",
    "Never share aggregates across contexts via the shared kernel -- publish an event or expose an application service.",
    "Any addition to /shared requires 2-context approval to prevent silent coupling."
   ],
   "aggregate_stress_tests": [
    {
     "aggregate": "BrandCampaignIntakeAggregate",
     "scenario": "Concurrent command on BrandCampaignIntakeAggregate",
     "invariant_at_risk": "An intake in state 'delivered' is immutable",
     "verdict": "holds"
    },
    {
     "aggregate": "GapMatrixAggregate",
     "scenario": "Concurrent command on GapMatrixAggregate",
     "invariant_at_risk": "Every gap-matrix line cites evidence or is marked an explicit gap",
     "verdict": "holds"
    },
    {
     "aggregate": "CompletenessPackAggregate",
     "scenario": "Concurrent command on CompletenessPackAggregate",
     "invariant_at_risk": "A Completeness Pack cannot be delivered without a valid Release",
     "verdict": "holds"
    },
    {
     "aggregate": "ReleaseAggregate",
     "scenario": "Concurrent command on ReleaseAggregate",
     "invariant_at_risk": "A Release is bound to a live authenticated session, not a form field",
     "verdict": "holds"
    },
    {
     "aggregate": "VendorChaseCaseAggregate",
     "scenario": "Concurrent command on VendorChaseCaseAggregate",
     "invariant_at_risk": "A hard gap cannot be marked cured without vendor-sourced cure evidence",
     "verdict": "holds"
    }
   ],
   "agent_stress_tests": [
    {
     "agent": "Extraction Agent",
     "scenario": "Malformed / adversarial input to the Extraction Agent",
     "failure_mode": "Prompt injection via vendor invoice content",
     "guardrail": "Structured-output schema",
     "verdict": "holds"
    },
    {
     "agent": "Routing & Classification Agent",
     "scenario": "Malformed / adversarial input to the Routing & Classification Agent",
     "failure_mode": "Wrong route -> wrong reviewer or wrong CSP ruleset",
     "guardrail": "Structured-output schema",
     "verdict": "holds"
    },
    {
     "agent": "Eval Agent",
     "scenario": "Malformed / adversarial input to the Eval Agent",
     "failure_mode": "Overfit to the golden dataset",
     "guardrail": "Regression thresholds",
     "verdict": "holds"
    }
   ],
   "regulated_domain_handling": [
    {
     "regime": "TCR Brand & Campaign vetting checklist (TCR profile requirement) and code 30909 (5-year record retention) as adopted by the TCR; Twilio rejection code 30908 (privacy policy); Telnyx/Bandwidth / Virginia SMS-campaign program policy",
     "applies_because": "The TCR treats a missing/incomplete TCR profile or under-5-year records as an inspection-failure condition; owner remains the legally accountable party even though a vendor typically writes/executes the TCR profile.",
     "controls": [
      "Edition-dated checklist card cited per hard-gap claim",
      "Registration analyst release on green/yellow; customer's outside counsel (referral only) release on red packs"
     ],
     "evidence_required": [
      "Checklist-clause-to-evidence map",
      "Release records + Evidence Index rows"
     ]
    }
   ],
   "unit_economics": {
    "price_model": "Per-building Completeness Pack tiers (base 1-4 Brand+Campaign registrations + per-Brand+Campaign registration overage) + Rush add-on + Resubmit Desk per-cycle add-on + Portfolio Desk monthly retainer",
    "unit_of_value": "Released a2p-10dlc-brand-campaign-approval-completeness-pack-engine Completeness Pack",
    "gross_margin_pct": 61,
    "cost_drivers": [
     "Analyst minutes per pack",
     "AI model + retrieval cost",
     "Outside-counsel-referral admin time (near-zero — no retainer paid)",
     "Support + success"
    ],
    "breakeven_note": "Breakeven depends on analyst throughput and extraction acceptance rate; target analyst minutes per green pack <=40 by day 90 and >=55% automation share by month 6, per the brief's unit-economics table."
   },
   "margin_leakage_map": [
    {
     "leakage": "Analyst over-editing AI-drafted gap matrices",
     "cause": "Low AI acceptance rate on non-standard vendor formats",
     "impact": "high",
     "mitigation": "Eval Agent regression + prompt-owner accountability"
    },
    {
     "leakage": "External API retries without backoff",
     "cause": "Poor adapter design",
     "impact": "medium",
     "mitigation": "Exponential backoff + circuit breaker"
    },
    {
     "leakage": "Cross-tenant retrieval scan cost",
     "cause": "Missing TCR-index partitioning",
     "impact": "high",
     "mitigation": "Per-tenant index partitions"
    },
    {
     "leakage": "Vendor Resubmit Desk cases running past the paid cycle",
     "cause": "No cadence cap on chase attempts",
     "impact": "medium",
     "mitigation": "Chase-cadence spec + weekly cap"
    }
   ],
   "slop_findings": [
    {
     "pattern": "generic 'dashboard'-only value prop",
     "status": "clean",
     "note": "Value prop is a released, cited Completeness Pack, not a dashboard."
    },
    {
     "pattern": "AI-as-magic",
     "status": "clean",
     "note": "AI is bounded to extraction + drafting + validation; humans own release."
    },
    {
     "pattern": "blockchain",
     "status": "clean",
     "note": "No blockchain-as-hype in derivation."
    },
    {
     "pattern": "agent-first (agents replace humans)",
     "status": "clean",
     "note": "Every agent has forbidden actions + human escalation."
    },
    {
     "pattern": "microservices by default",
     "status": "clean",
     "note": "ADR-001 chose a modular monolith."
    },
    {
     "pattern": "everything-is-core",
     "status": "clean",
     "note": "Generic subdomains explicitly marked buy/integrate."
    }
   ],
   "drift_checks": [
    {
     "stage": "Business Truth Discovery",
     "status": "pass",
     "findings": [
      "[PLACEHOLDER] owner to complete"
     ]
    },
    {
     "stage": "Ubiquitous Language",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Strategic Subdomains",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Bounded Contexts",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Context Mapping",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Event Storming",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Commands/Events/Policies",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Tactical Model",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "AI-Native Ops",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Human-in-the-Loop",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Evidence + Compliance",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Data Ownership",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Integration",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Application Use Cases",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Outcome Economics",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Technical Architecture",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Security + Governance",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Testing",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "MVP Roadmap",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Scaling",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Risk",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "ADRs",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Foundry Package",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Contradiction Scan",
     "status": "pass",
     "findings": []
    },
    {
     "stage": "Self-Audit",
     "status": "pass",
     "findings": []
    }
   ],
   "gates": [
    {
     "id": "domain",
     "title": "Domain Clarity",
     "passed": true,
     "checks": [
      {
       "name": "Paid outcome present",
       "ok": true,
       "evidence": "business_understanding.paid_outcome"
      },
      {
       "name": ">=3 actors identified",
       "ok": true,
       "evidence": "6 actors"
      }
     ]
    },
    {
     "id": "core",
     "title": "Core Domain",
     "passed": true,
     "checks": [
      {
       "name": "At least one core subdomain",
       "ok": true,
       "evidence": "Completeness Pack Fulfillment, AI Workbench & Extraction, Release & Quality Assurance"
      }
     ]
    },
    {
     "id": "boundary",
     "title": "Boundary",
     "passed": true,
     "checks": [
      {
       "name": ">=4 bounded contexts",
       "ok": true,
       "evidence": "13 contexts"
      },
      {
       "name": "Every context has owned language",
       "ok": true,
       "evidence": "all populated"
      }
     ]
    },
    {
     "id": "invariant",
     "title": "Invariant",
     "passed": true,
     "checks": [
      {
       "name": ">=4 business invariants",
       "ok": true,
       "evidence": "9 invariants"
      }
     ]
    },
    {
     "id": "ai-safety",
     "title": "AI Safety",
     "passed": true,
     "checks": [
      {
       "name": "Every agent has forbidden actions",
       "ok": true,
       "evidence": "yes"
      },
      {
       "name": "Every agent has escalation triggers",
       "ok": true,
       "evidence": "yes"
      }
     ]
    },
    {
     "id": "buildability",
     "title": "Buildability",
     "passed": true,
     "checks": [
      {
       "name": "MVP roadmap >=2 phases",
       "ok": true,
       "evidence": "6 phases"
      }
     ]
    },
    {
     "id": "anti-slop",
     "title": "Anti-Slop",
     "passed": true,
     "checks": [
      {
       "name": "No slop patterns",
       "ok": true,
       "evidence": "slop_findings all clean"
      },
      {
       "name": "No failing contradictions",
       "ok": true,
       "evidence": "10 findings, none severity=error"
      }
     ]
    }
   ],
   "contradiction_scan": [
    {
     "id": "INV-AGG-ReleaseAggregate+PackRetractionAggregate",
     "severity": "warn",
     "message": "Invariant references aggregate 'ReleaseAggregate + PackRetractionAggregate' not defined as a single aggregate",
     "refs": [
      "ReleaseAggregate + PackRetractionAggregate"
     ]
    },
    {
     "id": "CMD-EVT-OpenBrandCampaignIntake-IntakeRejected",
     "severity": "info",
     "message": "Command OpenBrandCampaignIntake references event 'IntakeRejected' not present in domain_events",
     "refs": [
      "OpenBrandCampaignIntake",
      "IntakeRejected"
     ]
    },
    {
     "id": "CMD-EVT-IngestEvidence-EvidenceRejected",
     "severity": "info",
     "message": "Command IngestEvidence references event 'EvidenceRejected' not present in domain_events",
     "refs": [
      "IngestEvidence",
      "EvidenceRejected"
     ]
    },
    {
     "id": "CMD-EVT-EvaluateHardGates-HardGateEvaluationError",
     "severity": "info",
     "message": "Command EvaluateHardGates references event 'HardGateEvaluationError' not present in domain_events",
     "refs": [
      "EvaluateHardGates",
      "HardGateEvaluationError"
     ]
    },
    {
     "id": "CMD-EVT-ReleasePack-PackReleaseRejected",
     "severity": "info",
     "message": "Command ReleasePack references event 'PackReleaseRejected' not present in domain_events",
     "refs": [
      "ReleasePack",
      "PackReleaseRejected"
     ]
    },
    {
     "id": "CMD-EVT-DeliverCompletenessPack-DeliveryFailed",
     "severity": "info",
     "message": "Command DeliverCompletenessPack references event 'DeliveryFailed' not present in domain_events",
     "refs": [
      "DeliverCompletenessPack",
      "DeliveryFailed"
     ]
    },
    {
     "id": "CMD-EVT-ResolveOwnerAction-OwnerActionRejected",
     "severity": "info",
     "message": "Command ResolveOwnerAction references event 'OwnerActionRejected' not present in domain_events",
     "refs": [
      "ResolveOwnerAction",
      "OwnerActionRejected"
     ]
    },
    {
     "id": "CMD-EVT-DispatchChaseLetter-ChaseLetterFailed",
     "severity": "info",
     "message": "Command DispatchChaseLetter references event 'ChaseLetterFailed' not present in domain_events",
     "refs": [
      "DispatchChaseLetter",
      "ChaseLetterFailed"
     ]
    },
    {
     "id": "CMD-EVT-ConfirmVendorCure-VendorCureRejected",
     "severity": "info",
     "message": "Command ConfirmVendorCure references event 'VendorCureRejected' not present in domain_events",
     "refs": [
      "ConfirmVendorCure",
      "VendorCureRejected"
     ]
    },
    {
     "id": "CMD-EVT-RetractPack-RetractionRejected",
     "severity": "info",
     "message": "Command RetractPack references event 'RetractionRejected' not present in domain_events",
     "refs": [
      "RetractPack",
      "RetractionRejected"
     ]
    }
   ],
   "rubric": {
    "categories": [
     {
      "category": "Domain accuracy",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Ubiquitous language quality",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Subdomain classification quality",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Bounded context clarity",
      "score": 9,
      "min": 7,
      "passed": true
     },
     {
      "category": "Core domain focus",
      "score": 9,
      "min": 7,
      "passed": true
     },
     {
      "category": "Context map quality",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Aggregate design quality",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Invariant quality",
      "score": 9,
      "min": 7,
      "passed": true
     },
     {
      "category": "AI-agent responsibility design",
      "score": 9,
      "min": 7,
      "passed": true
     },
     {
      "category": "Human review safety",
      "score": 9,
      "min": 7,
      "passed": true
     },
     {
      "category": "Data ownership clarity",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Integration protection",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Implementation feasibility",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Scalability",
      "score": 7,
      "min": 7,
      "passed": true
     },
     {
      "category": "Security and compliance",
      "score": 7,
      "min": 7,
      "passed": true
     },
     {
      "category": "Testing strategy",
      "score": 8,
      "min": 7,
      "passed": true
     },
     {
      "category": "Operational realism",
      "score": 7,
      "min": 7,
      "passed": true
     },
     {
      "category": "MVP practicality",
      "score": 9,
      "min": 7,
      "passed": true
     }
    ],
    "pass": true,
    "average": 8.17
   },
   "foundry_package": {
    "version": "1.0.0",
    "checksum": "a2pv0001",
    "counts": {
     "subdomains": 14,
     "bounded_contexts": 13,
     "aggregates": 13,
     "events": 10,
     "commands": 10,
     "policies": 6,
     "ai_agents": 3,
     "invariants": 10,
     "integrations": 4,
     "adrs": 8
    },
    "subset": {
     "subdomains": [
      "Completeness Pack Fulfillment (evidence-linked extraction + release)",
      "AI Workbench & Extraction (bounded agents + retrieval)",
      "Release & Quality Assurance (analyst release + counsel-referral pause + retraction)",
      "TCR Rule Library & Retrieval",
      "Compliance & Licensing Governance",
      "Sales & Intake",
      "Client Onboarding & Tenant Profile",
      "Client Delivery & Success",
      "Vendor Resubmit Desk",
      "Portfolio & Recurring Programs",
      "Billing & Revenue",
      "Identity & Access",
      "Analytics & Reporting",
      "External Integrations (Anti-Corruption Layer)"
     ],
     "bounded_contexts": [
      "Completeness Pack Fulfillment",
      "AI Workbench & Extraction",
      "Release & Quality Assurance",
      "TCR Rule Library & Retrieval",
      "Compliance & Licensing Governance",
      "Sales & Intake",
      "Client Onboarding & Tenant Profile",
      "Client Delivery & Success",
      "Vendor Resubmit Desk",
      "Portfolio & Recurring Programs",
      "Billing & Revenue",
      "Identity & Access",
      "Analytics & Reporting"
     ],
     "aggregates": [
      "EngagementAggregate",
      "TenantAggregate",
      "BrandCampaignIntakeAggregate",
      "GapMatrixAggregate",
      "CompletenessPackAggregate",
      "ExtractionRunAggregate",
      "TCRRuleSetAggregate",
      "ReleaseAggregate",
      "PackRetractionAggregate",
      "OwnerActionLedgerAggregate",
      "VendorChaseCaseAggregate",
      "PortfolioAggregate",
      "DeliveryAggregate"
     ],
     "events": [
      "Brand+Campaign registrationIntakeAccepted",
      "evidenceIngested",
      "gapMatrixDrafted",
      "hardGatesEvaluated",
      "escalationRaised",
      "packReleased",
      "packDelivered",
      "ownerActionResolved",
      "hardGapCured",
      "packRetracted"
     ],
     "commands": [
      "OpenBrandCampaignIntake",
      "IngestEvidence",
      "StartExtractionRun",
      "EvaluateHardGates",
      "ReleasePack",
      "DeliverCompletenessPack",
      "ResolveOwnerAction",
      "DispatchChaseLetter",
      "ConfirmVendorCure",
      "RetractPack"
     ],
     "policies": [
      "Auto-request release on hard-gate evaluation complete",
      "Escalate on low confidence or missing TCR profile",
      "Block delivery on open compliance blocker",
      "Retract on material finding",
      "Alert on delivery failure",
      "Open vendor chase case on vendor-attributable hard gap"
     ],
     "ai_agents": [
      "Extraction Agent",
      "Routing & Classification Agent",
      "Eval Agent"
     ],
     "invariants": [
      "A Completeness Pack cannot be delivered without a valid analyst Release.",
      "Every gap-matrix line cites at least one evidence item or is marked an explicit gap.",
      "A Release is bound to a live authenticated session, not a form field.",
      "Released Completeness Packs are immutable; corrections go through PackRetraction.",
      "No extraction output leaves AI Workbench & Extraction without an OutputValidator pass.",
      "TCR retrieval is scoped to the checklist edition adopted by the Brand+Campaign registration's jurisdiction.",
      "Release cannot flip to 'ready' with open blocking owner actions.",
      "Every tenant has at least one named registration analyst of record on file before intake opens.",
      "A hard gap cannot be marked cured without vendor-sourced cure evidence citing the original clause.",
      "Roles are stored in a dedicated table and checked server-side."
     ],
     "integrations": [
      "Vendor invoice inboxes",
      "SMS Campaign-vendor work-order / CMMS platforms",
      "Customer document portals",
      "OpenAI / Anthropic API"
     ],
     "adrs": [
      "ADR-001",
      "ADR-002",
      "ADR-003",
      "ADR-004",
      "ADR-005",
      "ADR-006",
      "ADR-007",
      "ADR-008"
     ]
    }
   }
  }
 },
 "ddd_coverage": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "total": 20,
  "passed": 20,
  "pct": 100,
  "checks": [
   {
    "key": "actors",
    "label": "Actors",
    "count": 6,
    "min": 3,
    "ok": true,
    "gate": "domain",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "glossary",
    "label": "Glossary",
    "count": 15,
    "min": 6,
    "ok": true,
    "gate": "domain",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "decisions",
    "label": "Business decisions",
    "count": 5,
    "min": 4,
    "ok": true,
    "gate": "domain",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "events",
    "label": "Domain events",
    "count": 10,
    "min": 6,
    "ok": true,
    "gate": "domain",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "subdomains",
    "label": "Subdomains",
    "count": 14,
    "min": 8,
    "ok": true,
    "gate": "core",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "bcs",
    "label": "Bounded contexts",
    "count": 13,
    "min": 4,
    "ok": true,
    "gate": "boundary",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "ctx_map",
    "label": "Context map",
    "count": 14,
    "min": 3,
    "ok": true,
    "gate": "boundary",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "event_storm",
    "label": "Event storm rows",
    "count": 15,
    "min": 6,
    "ok": true,
    "gate": "boundary",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "aggregates",
    "label": "Aggregates",
    "count": 13,
    "min": 3,
    "ok": true,
    "gate": "invariant",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "invariants",
    "label": "Invariants",
    "count": 10,
    "min": 4,
    "ok": true,
    "gate": "invariant",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "ai_agents",
    "label": "AI agents",
    "count": 3,
    "min": 2,
    "ok": true,
    "gate": "ai-safety",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "use_cases",
    "label": "Use cases",
    "count": 4,
    "min": 3,
    "ok": true,
    "gate": "buildability",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "evidence_reg",
    "label": "Evidence register",
    "count": 8,
    "min": 5,
    "ok": true,
    "gate": "domain",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "assumptions",
    "label": "Assumption register",
    "count": 7,
    "min": 4,
    "ok": true,
    "gate": "domain",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "stress_boundary",
    "label": "Boundary stress tests",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "boundary",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "stress_agg",
    "label": "Aggregate stress tests",
    "count": 5,
    "min": 3,
    "ok": true,
    "gate": "invariant",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "stress_agent",
    "label": "Agent stress tests",
    "count": 3,
    "min": 2,
    "ok": true,
    "gate": "ai-safety",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "gates_pass",
    "label": "Hard gates passing",
    "count": 7,
    "min": 7,
    "ok": true,
    "gate": null,
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "rubric",
    "label": "Extended rubric pass",
    "count": 1,
    "min": 1,
    "ok": true,
    "gate": "buildability",
    "unblock": "Not needed -- check passes at current counts."
   },
   {
    "key": "foundry",
    "label": "Foundry package",
    "count": 13,
    "min": 4,
    "ok": true,
    "gate": "buildability",
    "unblock": "Not needed -- check passes at current counts."
   }
  ],
  "failingGates": [
   "[PLACEHOLDER] owner to complete"
  ]
 },
 "architecture": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "archetypes": [
   "regulated system",
   "CRUD/workflow application",
   "internal operations platform"
  ],
  "archetype_impact": "TCR jurisdiction is a global query parameter — every read/write is scoped by building, CSP ruleset, and Brand+Campaign registration, not just tenant.",
  "personality": [
   "workflow-heavy",
   "cost-sensitive",
   "highly regulated",
   "highly secure"
  ],
  "forces_ranked": [
   {
    "force": "compliance",
    "why": "Regulated verticals gate release; the architecture must prove, not assert, compliance."
   },
   {
    "force": "auditability",
    "why": "Every release decision, every evidence toggle, must be defensible in review."
   },
   {
    "force": "reliability",
    "why": "A broken blueprint is a broken release gate — availability is a product feature."
   },
   {
    "force": "data integrity",
    "why": "Evidence is the product; a corrupted citation is a shipped defect."
   },
   {
    "force": "maintainability",
    "why": "One team maintains dozens of blueprints; the shape must be identical across them."
   }
  ],
  "tradeoffs": [
   "Prioritizing auditability slows raw throughput — accepted; the product IS the audit trail.",
   "Choosing a modular monolith trades independent scaling for a single deploy story — accepted while the team is small.",
   "Using managed Cloud primitives trades some portability for zero ops — accepted; data is portable, runtime is not the moat."
  ],
  "quality_scenarios": [
   {
    "attribute": "Performance (interactive p95)",
    "target": "600 ms on Blueprint detail routes",
    "assumption": "Measured from Cloud edge, warm cache."
   },
   {
    "attribute": "Availability",
    "target": "99.5% (with March-reporting-window freeze protection)",
    "assumption": "Rolling 30-day window; excludes announced maintenance."
   },
   {
    "attribute": "RTO",
    "target": "24h"
   },
   {
    "attribute": "RPO",
    "target": "24h (daily backups)"
   },
   {
    "attribute": "Latency (edge function warm)",
    "target": "≤ 800ms p95 excluding upstream AI calls"
   },
   {
    "attribute": "Data durability",
    "target": "11 nines via managed Postgres + storage replication"
   },
   {
    "attribute": "Security",
    "target": "OWASP ASVS L1 baseline"
   },
   {
    "attribute": "Auditability",
    "target": "100% of release decisions + evidence toggles logged with actor + timestamp"
   },
   {
    "attribute": "Maintainability",
    "target": "New blueprint reaches validation-microsite state in ≤ 1 working session"
   },
   {
    "attribute": "Deployment frequency",
    "target": "≥ 5 deploys/week without incident"
   },
   {
    "attribute": "Observability",
    "target": "Every edge function emits correlationId; retries + phases visible in diagnostics drawer"
   },
   {
    "attribute": "Cost envelope",
    "target": "Idle per-blueprint cost ≈ $0; active < $5/month at MVP traffic"
   },
   {
    "attribute": "Scalability",
    "target": "Horizontal by blueprint count; single blueprint sized for < 10 req/s sustained"
   }
  ],
  "options": [
   {
    "style": "simple monolith",
    "fits_when": "Single team, low traffic, no independent scaling concerns.",
    "fits_here": "Matches the per-blueprint scope — one microsite, one schema, one code path.",
    "wrong_here": "Would couple every blueprint into a single deploy — not acceptable at network scale.",
    "complexity": "low",
    "cost": "low",
    "ops_burden": "low",
    "security_impact": "Small surface, single audit boundary.",
    "scaling_path": "Vertical scale only; hits ceiling on team velocity, not compute.",
    "team_fit": "Ideal for one dev; fine at MVP.",
    "recommended": false
   },
   {
    "style": "modular monolith",
    "fits_when": "Multiple bounded contexts but shared deploy lifecycle acceptable.",
    "fits_here": "Each blueprint is a module inside the network shell; shared shell, isolated data.",
    "wrong_here": "Wrong only if a blueprint needs independent SLOs — none currently do.",
    "complexity": "moderate",
    "cost": "low",
    "ops_burden": "low",
    "security_impact": "Single trust boundary; row-level isolation carries the tenancy load.",
    "scaling_path": "Modules become services only when SLOs or teams diverge.",
    "team_fit": "Best fit for a small team maintaining many blueprints.",
    "recommended": true
   },
   {
    "style": "serverless",
    "fits_when": "Bursty, per-request workloads with idle-to-zero cost targets.",
    "fits_here": "Edge functions already handle sync, docs, legal, seed articles, integrity — pay-per-invoke.",
    "wrong_here": "Wrong for long-running orchestrations; IDLE_TIMEOUT already bit us on legal docs.",
    "complexity": "moderate",
    "cost": "low",
    "ops_burden": "moderate",
    "security_impact": "Function-scoped IAM; secrets via managed evidence archive.",
    "scaling_path": "Auto; watch cold-start p95 and per-invocation cost.",
    "team_fit": "Good — team already ships functions weekly.",
    "recommended": false
   },
   {
    "style": "microservices",
    "fits_when": "Multiple teams, divergent SLOs, independent release cadence required.",
    "fits_here": "Nothing here justifies it; single team, single deploy cadence, shared data plane.",
    "wrong_here": "Adds network, discovery, deploy topology, and observability cost with zero product benefit.",
    "complexity": "very high",
    "cost": "high",
    "ops_burden": "high",
    "security_impact": "Bigger attack surface, more inter-service auth to get right.",
    "scaling_path": "Best-in-class if the org can afford it.",
    "team_fit": "Wrong for this team.",
    "recommended": false
   },
   {
    "style": "event-driven",
    "fits_when": "Async fan-out, decoupled producers/consumers, replayable history required.",
    "fits_here": "Only the sync + integrity pipeline is fan-out; keep it as background jobs, not a broker.",
    "wrong_here": "Broker + schema registry + DLQ topology is overkill for current volumes.",
    "complexity": "high",
    "cost": "moderate",
    "ops_burden": "high",
    "security_impact": "Extra ACLs; message-level auth needed.",
    "scaling_path": "Excellent for future audit-log fan-out, revisit at 10x volume.",
    "team_fit": "Team can operate a small in-process queue; not a full broker yet.",
    "recommended": false
   },
   {
    "style": "workflow/orchestration",
    "fits_when": "Long, multi-step, resumable pipelines with human-in-the-loop steps.",
    "fits_here": "Blueprint pipeline (sources → articles → integrity → smoke test) already smells like this.",
    "wrong_here": "Full engine (Temporal/Airflow) is heavy; a typed in-app queue with retries covers today's needs.",
    "complexity": "high",
    "cost": "moderate",
    "ops_burden": "moderate",
    "security_impact": "Central choke point — must be hardened.",
    "scaling_path": "Adopt engine once we cross ~10 concurrent long-running jobs per blueprint.",
    "team_fit": "Would require operator ramp-up.",
    "recommended": false
   }
  ],
  "chosen_style": "modular monolith",
  "chosen_rationale": "Modular monolith with edge functions for bursty AI/generation — one audit boundary, low ops burden, easy per-team ownership.",
  "rejected": [
   {
    "style": "microservices",
    "why_rejected": "Adds network, discovery, deploy topology, and observability cost with zero product benefit."
   },
   {
    "style": "event-driven",
    "why_rejected": "Broker + schema registry + DLQ topology is overkill for current volumes."
   }
  ],
  "target": {
   "overview": "React shell → Lovable Cloud (Postgres + Auth + Storage + Edge Functions). Every blueprint is a module inside the shell; per-vertical differences live in derived DNA, not in separate deploys. Compliance posture: Domain-specific (owner-side TCR profile and Brand+Campaign registration maintenance records, analyst/counsel-cleared analyst release signers, 5-year retention schedules).",
   "frontend": "Vite + React + TypeScript + Tailwind + shadcn primitives; per-blueprint themed via Design DNA; job queue for background pipelines; URL-persisted filter state on audit + diagnostics.",
   "backend": "Deno-based edge functions per capability. Long generations split into per-item endpoints to stay under IDLE_TIMEOUT.",
   "data": "Managed Postgres with RLS + JSONB for shape drift. Object storage for source files + generated artifacts.",
   "api": "REST-ish RPC over edge functions with typed payloads; correlationId on every call for retry/diagnostics.",
   "authn_authz": "Managed OAuth (Google default). Roles in a dedicated user_roles table + has_role() SECURITY DEFINER function referenced by RLS policies.",
   "integrations": "GitHub (public read for sync + sources), Lovable AI Gateway (all LLM calls), Cloud Storage (artifacts). No third-party CRM/email yet.",
   "background_jobs": "blueprintJobQueue in-app: per-slug concurrency limit, exponential backoff + jitter, cancel + invalidate, retention of last error diagnostics.",
   "object_storage": "Cloud Storage buckets scoped per blueprint slug; signed URLs for artifact download.",
   "notifications": "In-app toasts + audit trail entries. Email/webhook deferred until owners request it.",
   "search": "Postgres FTS on blueprint titles + evidence claims; client-side filter for audit trail. Dedicated index deferred.",
   "analytics": "Lightweight event log in Postgres; dashboard-grade analytics deferred until we have a paying tenant.",
   "ai": "not applicable",
   "observability": "correlationId per request, per-phase timings, retry timeline in diagnostics drawer, per-blueprint pipeline status panel, JSON report export.",
   "deployment": "Preview + Production environments; edge functions deploy with the app; Postgres migrations shipped via managed migration tool.",
   "security": "RLS on every public table; roles in user_roles; secrets in managed evidence archive; OWASP ASVS L1 baseline.",
   "dr": "Daily backups; restore drill twice/year."
  },
  "modules": [
   {
    "name": "Blueprint Core",
    "responsibility": "Owns the SeedBusiness catalog, release decisions, evidence register, owner actions.",
    "owned_data": [
     "seed business rows",
     "release_decision",
     "evidence items",
     "owner-action state"
    ],
    "entities": [
     "SeedBusiness",
     "EvidenceItem",
     "OwnerAction",
     "ReleaseDecision"
    ],
    "interfaces": [
     "React store (StoreProvider)",
     "public read via microsite route"
    ],
    "depends_on": [
     "Content Pipeline (for source files + articles)",
     "Cloud auth"
    ],
    "events_produced": [
     "release.decision.changed",
     "evidence.status.changed",
     "owner.action.resolved"
    ],
    "events_consumed": [
     "sync.blueprint.applied",
     "integrity.check.completed"
    ],
    "failure_risks": [
     "Duplicate slug in seed → React key crash (mitigated by dedupe in mergedSeed)",
     "Evidence drift after sync"
    ],
    "scaling": "Bounded by SEED size; irrelevant even at 10x.",
    "future_split_trigger": "Split out Blueprint Core into an independent deployment when its throughput or a distinct scaling profile justifies it; not warranted pre-revenue."
   },
   {
    "name": "Content Pipeline",
    "responsibility": "Fetches GitHub sources, generates docs/seed articles, runs citation integrity, per slug with concurrency + backoff.",
    "owned_data": [
     "blueprint_sources",
     "blueprint_seed_articles",
     "job status per slug",
     "integrity results"
    ],
    "entities": [
     "SourceFile",
     "SeedArticle",
     "IntegrityReport",
     "JobState"
    ],
    "interfaces": [
     "blueprintJobQueue API",
     "edge functions: fetch-blueprint-sources, generate-seed-articles, generate-blueprint-docs"
    ],
    "depends_on": [
     "Cloud edge functions",
     "AI Gateway",
     "GitHub public read"
    ],
    "events_produced": [
     "sources.fetched",
     "articles.generated",
     "integrity.completed",
     "cache.invalidated"
    ],
    "events_consumed": [
     "blueprint.cache.invalidate"
    ],
    "failure_risks": [
     "Edge IDLE_TIMEOUT on long generations (mitigated: per-doc endpoints + retries)",
     "Upstream AI 5xx storms"
    ],
    "scaling": "Concurrency + backoff configurable in UI; scales with edge function limits.",
    "future_split_trigger": "If cross-blueprint queueing coordination is needed, promote to a shared job service."
   },
   {
    "name": "Runtime & Capabilities",
    "responsibility": "Per-blueprint runtime modules — verification, SEO, legal docs, chatbot — with retry + diagnostic history.",
    "owned_data": [
     "capability status per slug",
     "runtime module errors",
     "chatbot threads + FAQ"
    ],
    "entities": [
     "CapabilityStatus",
     "RuntimeError",
     "ChatMessage"
    ],
    "interfaces": [
     "React Runtime tab",
     "edge functions: verify-blueprint, generate-seo-posts, generate-legal-docs/*, blueprint-chat"
    ],
    "depends_on": [
     "Content Pipeline (grounding)",
     "AI Gateway"
    ],
    "events_produced": [
     "capability.status.changed",
     "runtime.error.recorded"
    ],
    "events_consumed": [
     "cache.invalidated"
    ],
    "failure_risks": [
     "AI provider outage",
     "Prompt drift causing ungrounded output"
    ],
    "scaling": "Per-slug; independent of network size.",
    "future_split_trigger": "Split out Runtime & Capabilities into an independent deployment when its throughput or a distinct scaling profile justifies it; not warranted pre-revenue."
   },
   {
    "name": "Sync & Rollback",
    "responsibility": "Daily GitHub sync of blueprint definitions with dry-run, partial-apply, and server-backed rollback of last snapshot.",
    "owned_data": [
     "sync_runs",
     "sync_snapshots per slug",
     "audit_trail"
    ],
    "entities": [
     "SyncRun",
     "SyncDiff",
     "SyncSnapshot",
     "AuditEntry"
    ],
    "interfaces": [
     "/github-sync page",
     "edge functions: github-sync-blueprints, rollback-blueprint-sync"
    ],
    "depends_on": [
     "Blueprint Core",
     "Cloud storage for snapshots"
    ],
    "events_produced": [
     "sync.run.completed",
     "sync.blueprint.applied",
     "sync.blueprint.rolled_back"
    ],
    "events_consumed": [],
    "failure_risks": [
     "Partial apply leaving mixed state (mitigated by per-blueprint snapshots)",
     "Audit trail size growth"
    ],
    "scaling": "Paginate audit trail; snapshot retention window is finite.",
    "future_split_trigger": "Split out Sync & Rollback into an independent deployment when its throughput or a distinct scaling profile justifies it; not warranted pre-revenue."
   },
   {
    "name": "Design & Architecture DNA",
    "responsibility": "Deterministic per-blueprint design + architecture briefs used to gate release readiness.",
    "owned_data": [
     "derived only — no persistence"
    ],
    "entities": [
     "DesignDNA",
     "ArchitectureDNA"
    ],
    "interfaces": [
     "React panels in Business Detail"
    ],
    "depends_on": [
     "Blueprint Core"
    ],
    "events_produced": [],
    "events_consumed": [],
    "failure_risks": [
     "Vertical → profile drift if new verticals are not mapped"
    ],
    "scaling": "Pure functions; free.",
    "future_split_trigger": "Split out Design & Architecture DNA into an independent deployment when its throughput or a distinct scaling profile justifies it; not warranted pre-revenue."
   }
  ],
  "data_architecture": {
   "primary_db": "Managed Postgres (Cloud)",
   "secondary": [
    "Object storage for artifacts + snapshots",
    "Client localStorage for UI state (filters, drawer state) — never for auth"
   ],
   "cache": "React Query + module-level memoization; no dedicated cache service.",
   "search": "Postgres FTS on titles + evidence; consider pg_trgm on slugs.",
   "vector": "not applicable",
   "object_storage": "Per-slug prefixes; lifecycle rules to prune stale sync snapshots.",
   "schema_strategy": "Normalized core + JSONB for evolving shapes (evidence details, capability status).",
   "migrations": "Forward-only migrations reviewed in PR; every CREATE TABLE ships GRANTs + RLS enable + policies in the same migration.",
   "backups": "Managed daily backups with 30-day retention.",
   "retention": "Audit trail retained ≥ 1y; sync snapshots retained 90d; error diagnostics retained 30d.",
   "audit_logs": "audit_trail table + append-only pattern; export CSV from UI.",
   "soft_delete": "Soft-delete evidence via status transition; hard-delete only via owner-initiated purge.",
   "privacy": "Only owner-supplied facts persist; service records, attestations, regulator correspondence handled per vertical policy.",
   "encryption": "TLS 1.2+ in transit; AES-256 at rest via managed storage.",
   "multi_tenancy": "Row-level tenancy keyed on auth.uid() + blueprint slug; RLS policies enforce isolation."
  },
  "api": {
   "style": "REST-ish RPC over edge functions with JSON payloads; typed client wrappers.",
   "public_vs_internal": "Public microsite reads via Postgres RLS-protected queries; internal capability calls via authenticated edge functions.",
   "versioning": "Version via function name suffix (v1, v2) when breaking; additive changes preferred.",
   "rate_limiting": "Per-user + per-slug in edge functions; UI-level concurrency caps for AI calls.",
   "idempotency": "Sync + rollback carry an idempotency key; retries safe.",
   "pagination": "Cursor pagination on audit trail; offset paging tolerated on small lists.",
   "error_format": "{ code, message, correlationId, retryable, details? } — normalized in client.",
   "webhook_security": "HMAC-signed webhooks (deferred until we accept inbound webhooks).",
   "retries": "Exponential backoff + jitter, capped attempts, respect idempotency keys.",
   "contract_testing": "Zod schemas shared between client + edge; smoke test runner exercises each endpoint.",
   "backward_compat": "Additive fields only; deprecations announced in audit trail before removal.",
   "contract_testing_plan": "Intake, source-result, and delivery payload schemas are contract-tested per consumer; the JSON contract between AI layers is schema-pinned and versioned."
  },
  "security": {
   "authn": "Managed OAuth (Google default). Session in httpOnly cookie / managed client storage.",
   "authz": "user_roles table + has_role() SECURITY DEFINER, referenced from RLS policies. Never store roles on profiles.",
   "tenant_isolation": "RLS on every public table; every query filters by auth.uid() or by an explicit owner grant.",
   "secrets": "Managed evidence archive; never in client bundle; edge functions read via runtime env.",
   "encryption": "TLS in transit; AES-256 at rest; column-level encryption only when regulation requires.",
   "session": "Short-lived access tokens + refresh rotation; SSR cookie parity for edge routes.",
   "input_validation": "Zod schemas at the edge boundary; reject on unknown fields.",
   "api_protection": "Rate limits + WAF rules on public endpoints; correlationId logging for abuse forensics.",
   "audit_log": "Every release decision, evidence toggle, sync, and rollback records actor + timestamp + before/after.",
   "admin_access": "Admin actions gated behind role check + two-key confirmation on destructive operations.",
   "supply_chain": "Lockfile pinning + weekly dependency scan; SBOM produced on release.",
   "threat_model": [
    "Prompt injection via ingested source files → sanitize + refuse instructions from ingested content.",
    "Cross-tenant read via missing RLS on new table → migration checklist blocks merge.",
    "Rollback abuse to overwrite recent legitimate edits → rollback preview + confirm-typed pattern.",
    "AI cost DOS by repeated regeneration → per-slug rate limits + concurrency cap."
   ],
   "abuse_cases": [
    "Malicious owner uploads privileged content into a public microsite field.",
    "Sync run tampered with to inject a slug that overlaps a real blueprint.",
    "Attacker triggers regeneration loop to drive AI cost."
   ],
   "zero_trust": "Every service call authenticates; no implicit trust between edge functions.",
   "asvs_notes": "OWASP ASVS L1 baseline."
  },
  "reliability": {
   "failure_modes": [
    "Edge function IDLE_TIMEOUT on long AI generations.",
    "Upstream AI provider 5xx / rate limit.",
    "GitHub API rate limit during sync.",
    "Postgres connection saturation during sync fan-out."
   ],
   "graceful_degradation": "Runtime tab modules degrade independently; microsite serves cached last-known-good content when generation fails.",
   "retry_policy": "Exponential backoff + jitter, max 5 attempts, respect Retry-After.",
   "timeouts": "Edge function ≤ 120s wall clock (safety margin under 150s limit); client fetch ≤ 60s per call.",
   "circuit_breaker": "Client-side per-endpoint breaker: after 3 consecutive IDLE_TIMEOUTs, pause 5m and surface to UI.",
   "queueing": "In-app blueprintJobQueue with concurrency limits per slug.",
   "idempotency": "Sync + rollback idempotent via key; generation endpoints idempotent per (slug, doc_key).",
   "dlq": "Failed jobs recorded in error diagnostics; user re-triggers manually (no auto-DLQ needed at current volume).",
   "transactions": "Multi-row writes wrapped in single transaction; audit entry written in the same transaction as the mutation.",
   "dr": "Daily backup + semi-annual restore drill.",
   "incident_response": "correlationId in every log line; on-call runbook per capability module; smoke test replays post-incident.",
   "slos": [
    {
     "name": "Interactive p95",
     "target": "600 ms on blueprint detail"
    },
    {
     "name": "Availability",
     "target": "99.5% (with March-reporting-window freeze protection)"
    },
    {
     "name": "Sync success rate",
     "target": "≥ 99% per daily run over rolling 7 days"
    },
    {
     "name": "Generation success rate",
     "target": "≥ 95% per doc across last 7d (excludes provider outages)"
    }
   ]
  },
  "scaling": {
   "mvp_can_stay_simple": [
    "Single Postgres, single region.",
    "No dedicated search or vector index.",
    "In-app job queue; no message broker."
   ],
   "modular_now": [
    "Content Pipeline is already isolated behind blueprintJobQueue — future extraction is a 1-day job.",
    "Runtime capabilities are one function per module — swap in isolation."
   ],
   "deferrable": [
    "Workflow engine (Temporal/Airflow).",
    "Vector DB / RAG.",
    "Multi-region replication.",
    "Feature flag service (env-based toggle covers MVP)."
   ],
   "breaks_first": "Edge function IDLE_TIMEOUT under multi-doc generation — already addressed by per-doc endpoints; watch for regression.",
   "db_path": "Vertical scale → read replica → partition by tenant if a single tenant dominates load.",
   "jobs_path": "In-app queue → dedicated worker → workflow engine, gated by concurrency + resumability need.",
   "cache_path": "React Query only → HTTP cache headers → CDN edge cache for microsite content.",
   "search_path": "Postgres FTS → pg_trgm → dedicated search only when p95 breaches SLO.",
   "files_path": "Managed object storage → CDN → per-region cache if traffic warrants.",
   "api_path": "Vertical edge function scale → per-capability autoscaling → extract hot module to its own service.",
   "multi_region": "Not planned; introduce only on customer contract with residency requirement.",
   "cost_control": "Per-blueprint AI budget, concurrency cap, smoke-test cache; monthly cost review with per-blueprint attribution."
  },
  "ai": {
   "provider": "Frontier LLM via API with provider-agnostic prompt contracts; a second vendor is configured for failover so a released deliverable never depends on a single model.",
   "prompt_mgmt": "Extraction, drafting, and matrix prompts are held in versioned files with eval-gated deploys and one-step rollback; prompt changes require diff review.",
   "rag": "A versioned, jurisdiction-scoped rule pack for Regulatory compliance is retrieved with source-scoped filters; drafting is grounded and citation-anchored to the source text, never free-form generation.",
   "vector": "Not warranted pre-revenue — the rule pack is small and structured, so section/keyword lookups suffice until a larger corpus justifies similarity search.",
   "embeddings": "Deferred with the vector store; rule-pack keys are structured (element, source, subsection), not semantic.",
   "eval": "A gold set of specialist-released packs measures element-extraction F1 and completeness-gate agreement per model release; accuracy vs specialist labels is reviewed on a fixed cadence.",
   "hitl": "Specialist release is never automated; a domain expert signs off on the exception queue, with sampling QA on a fraction of outputs and expert red-team on the first releases.",
   "guardrails": "Field-locked templates, source-tie reconciliation, and completeness rules mean a draft missing a required field emits a MISSING_ELEMENT exception rather than inventing content.",
   "prompt_injection": "Source documents are treated as data, never instructions; the red-team suite includes injected-instruction files disguised as legitimate inputs.",
   "leakage": "Client and subject identifiers are scoped per case; retrieval is scoped per client; provider training-use is disabled; there is no cross-client corpus.",
   "fallback": "A manual specialist workbench runbook plus the second LLM vendor keep production moving if the primary model is unavailable.",
   "latency_cost": "Inference cost per deliverable is bounded at launch and trends down with volume; the standard SLA leaves generous headroom over model latency.",
   "memory": "Agents are stateless per case; durable knowledge lives in the versioned rule pack and SOP library, not in model memory.",
   "tool_permissions": "The prompt runner has no tool access beyond returning JSON; search ordering, document assembly, and delivery are deterministic code.",
   "auditability": "Every prompt+output pair is logged to the per-case audit trail with version tags alongside the specialist release record.",
   "citation": "Every drafted element carries the source provision it satisfies, and every matrix entry carries the search or record it came from."
  },
  "devops": {
   "environments": [
    "Preview (per branch)",
    "Production"
   ],
   "cicd": "Lovable build pipeline; deploys on merge; edge functions ship atomically with the app.",
   "iac": "Cloud managed; migrations + config in-repo.",
   "secrets": "Managed evidence archive; separate values per environment.",
   "preview_envs": "Automatic per branch; seeded with anonymized fixtures.",
   "migrations": "Forward-only; migrations reviewed for GRANT + RLS + policies; every table gated by the migration checklist.",
   "rollback": "App: redeploy previous build. Data: server-backed rollback per blueprint via rollback-blueprint-sync.",
   "release_style": "Continuous deploy with feature flags; canary only when a change touches shared shell.",
   "feature_flags": "Env-based booleans at MVP; consider a flag service when we have > 20 flags in flight.",
   "monitoring": "Cloud platform metrics + per-function logs + client error reporting.",
   "alerting": "SLO burn-rate alerts + IDLE_TIMEOUT rate alert + AI cost anomaly alert.",
   "logs": "Structured JSON with correlationId; retained per platform defaults.",
   "error_tracking": "Client-side error capture wired to console + in-app diagnostics drawer.",
   "uptime": "Synthetic checks on microsite + shell login every 5 minutes.",
   "cost_monitoring": "Per-blueprint cost view; alert on 3x baseline over 24h."
  },
  "testing": {
   "unit": "Vitest for pure derivations (DNA, business helpers).",
   "integration": "Edge function contract tests with recorded fixtures.",
   "contract": "Zod schemas shared client + edge; smoke test runner as continuous contract check.",
   "e2e": "Playwright against localhost preview for critical flows (sign in, evidence toggle, sync apply).",
   "security": "Weekly dependency scan; RLS policy audit script; abuse-case checklist per release.",
   "a11y": "Axe checks + keyboard-only smoke on shell components; WCAG 2.2 AA target.",
   "load": "k6 scenarios against edge functions before enabling a new capability network-wide.",
   "chaos": "Manual fault injection on AI provider (simulate 500s) during release rehearsal.",
   "migration": "Every migration runs in preview + dry-run on prod snapshot before apply.",
   "backup_restore": "Semi-annual restore drill.",
   "ai_eval": "not applicable",
   "test_data": "Deterministic fixtures per vertical; no real PHI/PII ever in fixtures."
  },
  "observability": {
   "logs": "Structured JSON with correlationId, phase, attempt, doc_key, slug.",
   "metrics": "Per-endpoint latency, error rate, retry count, AI token spend.",
   "traces": "Cross-function trace via correlationId propagation.",
   "audit_events": "Release decision, evidence toggle, sync, rollback, cache invalidation.",
   "business_events": "Blueprint promoted to ready, first microsite view, first customer-visible export.",
   "error_tracking": "In-app diagnostics drawer + persistent per-slug error history.",
   "security_monitoring": "Failed auth + rate-limit breach + admin action logs.",
   "cost_monitoring": "Per-blueprint + per-capability cost attribution.",
   "dashboards": [
    "SLO burn",
    "AI cost per blueprint",
    "Sync success rate",
    "Generation success rate"
   ],
   "alert_thresholds": [
    "IDLE_TIMEOUT rate > 3/day for one blueprint.",
    "Sync run failure > 1 in rolling 7 days.",
    "AI cost > 3x rolling 7-day baseline over 24h.",
    "p95 breach on Blueprint detail > 800ms for 15 min."
   ],
   "triage": "correlationId → diagnostics drawer → retry timeline → JSON report export → runbook link."
  },
  "cost": {
   "drivers": [
    {
     "name": "AI generation",
     "note": "Dominant driver; capped by concurrency + per-slug budget."
    },
    {
     "name": "Edge function invocations",
     "note": "Bursty at sync + generation; idle-to-zero otherwise."
    },
    {
     "name": "Managed Postgres",
     "note": "Small; scales with audit trail retention."
    },
    {
     "name": "Object storage",
     "note": "Snapshots + artifacts; lifecycle rules prevent growth."
    },
    {
     "name": "Bandwidth",
     "note": "Low; static microsite content."
    }
   ],
   "likely_traps": [
    "Regeneration loops on failure (mitigated by circuit breaker).",
    "Audit trail unbounded growth (mitigated by retention policy).",
    "Storing large HTML snapshots per sync (mitigated by delta snapshots)."
   ],
   "controls": [
    "Per-blueprint AI budget with hard cap.",
    "Smoke-test result caching in localStorage.",
    "Concurrency cap in blueprintJobQueue.",
    "Retention policy on audit + diagnostics."
   ]
  },
  "multi_tenancy": {
   "model": "Row-level tenancy: one shared Postgres, tenant scope by auth.uid() + blueprint slug.",
   "isolation": "RLS policies on every public table; policies reference has_role() where role checks are needed.",
   "tenant_aware_authz": "Every query filters by auth.uid(); admin overrides go through explicit role check + audit entry.",
   "tenant_config": "Per-slug config stored as JSONB on the blueprint row; no per-tenant deploy.",
   "branding": "Per-blueprint Design DNA drives theme; no runtime branding upload at MVP.",
   "tenant_export": "Owner can export evidence + audit trail as JSON/CSV from the UI.",
   "tenant_deletion": "Owner-initiated purge cascades across blueprint rows + storage prefix; soft-delete window of 30 days.",
   "tenant_audit": "Per-slug audit trail table view with actor + timestamp on every mutation.",
   "noisy_neighbor": "Per-slug concurrency cap in blueprintJobQueue; per-slug AI budget.",
   "tenant_rate_limits": "Edge functions apply per-slug + per-user rate limits.",
   "billing": "Not billed at MVP; per-blueprint cost attribution feeds the future billing model.",
   "why_this_fits": "Team size and blueprint scale don't justify schema/db-per-tenant; RLS covers the isolation requirement with negligible ops burden."
  },
  "privacy_compliance": {
   "data_classification": "Owner-supplied facts and evidence citations are the sensitive classes; service records, attestations, regulator correspondence per vertical.",
   "minimization": "Only owner-supplied facts persist; no third-party enrichment; no PII scraping.",
   "consent": "Consent captured at intake for owner-supplied contact info; microsite visitors get standard cookie/consent banner where required.",
   "access_logs": "Every admin + edge function invocation logged with correlationId + actor.",
   "audit_trails": "Immutable append-only audit_trail table; export from UI.",
   "retention": "Audit ≥ 1y; sync snapshots 90d; error diagnostics 30d; artifacts per lifecycle rule.",
   "legal_hold": "Deferred until a matter requires it.",
   "right_to_delete": "Owner-initiated purge honored within 30 days; downstream copies pruned by lifecycle rules.",
   "right_to_export": "JSON + CSV export for evidence, audit trail, and generated artifacts.",
   "sensitive_handling": "No PHI/PII in prompts; owner-supplied facts only; secrets in managed evidence archive.",
   "boundaries": "Domain-specific (owner-side TCR profile and Brand+Campaign registration maintenance records, analyst/counsel-cleared analyst release signers, 5-year retention schedules)",
   "residency": "Single region at MVP; residency contract triggers per-tenant residency planning.",
   "vendor_risk": "Lovable Cloud + AI Gateway are the only critical vendors; both reviewed for security posture.",
   "breach_response": "correlationId + audit trail enables scope determination; disclosure per compliance policy within statutory window.",
   "admin_controls": "Admin actions gated by role check + two-key confirm for destructive operations; every admin session logged.",
   "evidence_collection": "Access reviews, change management, restore drills produce artifacts filed into the evidence pipeline."
  },
  "frontend": {
   "framework": "React 18 + Vite + TypeScript.",
   "rendering": "SPA with per-route code-split; microsite routes prerender-friendly.",
   "routing": "react-router-dom v6 with URL-persisted filter/drawer state.",
   "state": "React context + useSyncExternalStore for the job queue; localStorage only for UI state, never for auth.",
   "server_state": "@tanstack/react-query for cache + retries.",
   "forms": "Controlled components + Zod validation on submit; RHF only where forms grow.",
   "error_handling": "Error boundary at shell + per-panel skeletons + retry affordances.",
   "components": "shadcn primitives + per-blueprint themed panels; deterministic Design DNA drives look.",
   "design_system": "Tailwind semantic tokens (index.css); no hardcoded color utilities in components.",
   "auth_ui": "Managed OAuth callback via Cloud client; session hydration before protected routes render.",
   "authz_aware_ui": "UI hides actions the current role cannot perform; server-side check is authoritative.",
   "a11y": "WCAG 2.2 AA target; visible focus rings; keyboard shortcuts in diagnostics drawer.",
   "i18n": "Copy budgets assume +35% expansion for DE/FR; Intl APIs for dates/currencies.",
   "performance": "Route-level code split; lazy-load Runtime tab; memoize DNA derivations.",
   "bundling": "Vite defaults; per-route lazy imports for heavy panels.",
   "testing": "Vitest for unit; Playwright for critical flows.",
   "offline": "Not required; last-known-good served from React Query cache.",
   "realtime": "Not required at MVP; audit trail is polled on interaction."
  },
  "backend": {
   "framework": "Deno-based edge functions on Lovable Cloud, one function per capability.",
   "layering": "Handler → validator (Zod) → service → repository → Postgres.",
   "domain": "Blueprint, Evidence, OwnerAction, SyncRun, RuntimeCapability, ChatMessage.",
   "services": "Pure functions kept out of edge boundary; shared logic imported from a common module.",
   "repositories": "Thin Postgres wrappers; RLS enforces tenant scope.",
   "validation": "Zod at the edge boundary; reject unknown fields.",
   "authorization": "has_role() SECURITY DEFINER in Postgres; edge function also asserts role for defense in depth.",
   "jobs": "In-app blueprintJobQueue on the client for user-triggered pipelines; server-side cron only for daily sync.",
   "events": "Domain events emitted to audit_trail; no external broker.",
   "files": "Signed URLs from Cloud Storage; virus scan on upload (deferred until user uploads exist).",
   "email_sms": "Deferred; owner-configured inbox required before enabling outbound mail.",
   "scheduled": "Daily GitHub sync via scheduled function; retention prune weekly.",
   "errors": "Normalized error envelope { code, message, correlationId, retryable, details? }.",
   "logging": "Structured JSON logs with correlationId, phase, attempt, slug.",
   "config": "Env-based; secrets from managed evidence archive.",
   "di": "Not required at current size; explicit imports.",
   "testing": "Contract tests per function with recorded fixtures + smoke-test runner."
  },
  "diagrams": {
   "context_mermaid": "flowchart LR\n  Owner([Blueprint Owner]) --> Shell[Network Shell]\n  Reviewer([Reviewer]) --> Shell\n  Public([Public Visitor]) --> Micro[Public Microsite a2p-10dlc-brand-campaign-approval-completeness-pack-engine]\n  Shell --> Cloud[(Lovable Cloud: DB + Auth + Storage + Edge)]\n  Cloud --> AI[[AI Gateway]]\n  Cloud --> GH[[GitHub API]]\n  Micro --> Cloud",
   "container_mermaid": "flowchart TB\n  subgraph Client\n    UI[React Shell + Blueprint Detail]\n    Queue[blueprintJobQueue]\n  end\n  subgraph Cloud[Lovable Cloud]\n    DB[(Postgres + RLS)]\n    Store[(Object Storage)]\n    subgraph Edge[Edge Functions]\n      Sync[github-sync-blueprints]\n      Roll[rollback-blueprint-sync]\n      Src[fetch-blueprint-sources]\n      Seed[generate-seed-articles]\n      Docs[generate-blueprint-docs]\n      Legal[generate-legal-docs/*]\n      Verify[verify-blueprint]\n      SEO[generate-seo-posts]\n      Chat[blueprint-chat]\n    end\n  end\n  UI --> DB\n  Queue --> Src\n  Queue --> Seed\n  UI --> Docs\n  UI --> Legal\n  UI --> Verify\n  UI --> SEO\n  UI --> Chat\n  UI --> Sync\n  UI --> Roll\n  Seed --> AI[[AI Gateway]]\n  Docs --> AI\n  Legal --> AI\n  Chat --> AI\n  Src --> GH[[GitHub]]",
   "data_flow_mermaid": "flowchart LR\n  A[Owner edits Evidence] --> B[Store: evidence.custom]\n  B --> C{Release Gate}\n  C -- ready --> D[Business marked Ready]\n  C -- blocker --> E[Owner Actions queue]\n  F[GitHub Sync] --> G[Diff + Snapshot]\n  G --> H[(Postgres)]\n  H --> I[Audit trail]\n  H --> J[React store]",
   "auth_flow_mermaid": "sequenceDiagram\n  participant U as User\n  participant UI as Network Shell\n  participant Auth as Cloud Auth\n  participant API as Edge Function\n  participant DB as Postgres+RLS\n  U->>UI: sign in\n  UI->>Auth: OAuth (Google)\n  Auth-->>UI: session (JWT)\n  UI->>API: call with JWT\n  API->>DB: query as auth.uid()\n  DB-->>API: rows filtered by RLS\n  API-->>UI: response",
   "authz_flow_mermaid": "flowchart LR\n  Req[Request w/ JWT] --> Fn[Edge Function]\n  Fn --> Role[has_role user_id, role]\n  Role --> DB[(user_roles + RLS policies)]\n  DB -- allow --> Ok[Return rows]\n  DB -- deny --> Err[403 + audit entry]",
   "deployment_mermaid": "flowchart LR\n  Dev[Developer] --> Repo[Git]\n  Repo --> CI[Lovable Build]\n  CI --> Preview[Preview Env]\n  CI --> Prod[Production]\n  Prod --> Cloud[(Lovable Cloud)]\n  Prod --> CDN[[Edge CDN]]",
   "background_job_mermaid": "flowchart LR\n  UI[Blueprint Detail] --> Enq[blueprintJobQueue.enqueue]\n  Enq --> Slot{Concurrency slot?}\n  Slot -- yes --> Run[Run job]\n  Slot -- no --> Queued[queued]\n  Run -->|success| Done[Persist result + emit event]\n  Run -->|error| Back[Exponential backoff + jitter]\n  Back -->|attempts left| Run\n  Back -->|exhausted| Fail[Record diagnostic + expose retry button]",
   "event_flow_mermaid": "flowchart LR\n  Sync[sync.blueprint.applied] --> Core[Blueprint Core]\n  Integ[integrity.completed] --> UI\n  CacheInv[cache.invalidated] --> Pipe[Content Pipeline]\n  Pipe --> Sources[sources.fetched]\n  Sources --> Articles[articles.generated]\n  Articles --> Integ",
   "failure_flow_mermaid": "flowchart LR\n  Call[Edge Function call] --> Timeout{Timeout / 5xx?}\n  Timeout -- no --> Ok[Success]\n  Timeout -- yes --> Retry[Backoff + retry]\n  Retry --> Cap{Attempts cap?}\n  Cap -- no --> Call\n  Cap -- yes --> Breaker[Open circuit]\n  Breaker --> Cache[Serve last-known-good]\n  Breaker --> Owner[Surface diagnostic + owner action]",
   "multi_tenant_flow_mermaid": "flowchart LR\n  Owner1([Owner A]) --> UI\n  Owner2([Owner B]) --> UI\n  UI --> API[Edge Function w/ JWT]\n  API --> Policy{RLS: auth.uid + slug scope}\n  Policy -- match --> Rows[Owner-scoped rows]\n  Policy -- no match --> Deny[403]",
   "ai_flow_mermaid": "graph LR; SRC[Source documents as DATA]-->EX[Extract + normalize]-->SR[Order source searches]-->MTX[Build matrix]-->DR[Draft locked-field elements]-->GT[Deterministic completeness gates]-->SP[Specialist release]-->DL[Deliver]; GT-.exception.->SP; SP-.high-risk.->EXP[Expert review]"
  },
  "adrs": [
   {
    "id": "ADR-001",
    "decision": "Adopt modular monolith as the network-wide architecture style",
    "context": "Small team maintaining many blueprints with shared shell, evidence discipline, and per-vertical trust variation.",
    "options": [
     "simple monolith",
     "modular monolith",
     "microservices",
     "serverless-only",
     "hybrid"
    ],
    "chosen": "modular monolith",
    "why": "Preserves a single audit boundary and deploy cadence while allowing edge functions for burst workloads.",
    "consequences": [
     "Shared deploy lifecycle across blueprints",
     "Row-level tenant isolation carries the security load"
    ],
    "risks": [
     "A rogue blueprint can regress network shell performance"
    ],
    "reversal": "Extract a module to its own deploy only when its SLO diverges from the network shell.",
    "revisit_when": "A blueprint acquires a divergent SLO, a second team joins, or the shell deploy time exceeds 10 minutes."
   },
   {
    "id": "ADR-002",
    "decision": "Managed Postgres as the sole primary datastore",
    "context": "All entities are relational (blueprints, evidence, sync runs, articles, audit).",
    "options": [
     "Postgres",
     "Postgres + DocumentDB",
     "Postgres + vector DB",
     "Firestore"
    ],
    "chosen": "Postgres (Cloud managed) with JSONB for semi-structured fields",
    "why": "Relational integrity + row-level security satisfies audit, tenancy, and reporting; JSONB absorbs shape drift.",
    "consequences": [
     "RLS policies are the primary tenancy control",
     "Full-text search via Postgres FTS until it stops scaling"
    ],
    "risks": [
     "Complex joins under growth"
    ],
    "reversal": "Introduce a read-replica or a dedicated search index only when p95 breaches SLO.",
    "revisit_when": "FTS p95 > SLO for 2 consecutive weeks, or a genuine RAG surface appears."
   },
   {
    "id": "ADR-003",
    "decision": "Per-document edge functions for long-running AI generation",
    "context": "IDLE_TIMEOUT (150s) on monolithic legal-docs generator forced this split.",
    "options": [
     "Single long function",
     "Chunked per-doc functions",
     "Background job with polling"
    ],
    "chosen": "Per-document endpoints with client-side fan-out + retries",
    "why": "Keeps each invocation under the timeout, isolates failures, enables partial success reporting.",
    "consequences": [
     "More endpoints to maintain",
     "Client must own orchestration"
    ],
    "risks": [
     "Client back-pressure if fan-out is too wide"
    ],
    "reversal": "Move to a real workflow engine when we cross ~10 concurrent long jobs per blueprint.",
    "revisit_when": "Concurrent long-running jobs > 10 per blueprint, or client-side orchestration becomes buggy."
   },
   {
    "id": "ADR-004",
    "decision": "Evidence-first release gate",
    "context": "Vertical compliance posture: Domain-specific (owner-side TCR profile and Brand+Campaign registration maintenance records, analyst/counsel-cleared analyst release signers, 5-year retention schedules).",
    "options": [
     "Owner-declared ready",
     "Auto-ready via checklist",
     "Evidence-gated ready"
    ],
    "chosen": "Evidence-gated ready — release requires resolved owner actions + verified evidence",
    "why": "Regulated verticals cannot ship on self-declaration; evidence provides defensibility.",
    "consequences": [
     "Slower path to ready",
     "Higher confidence at ready"
    ],
    "risks": [
     "Owners abandon incomplete blueprints"
    ],
    "reversal": "Introduce a 'ready-with-caveats' state only if the network stalls on this gate.",
    "revisit_when": "> 30% of blueprints stuck in owner-action state for > 30 days."
   },
   {
    "id": "ADR-005",
    "decision": "Defer AI adoption until a specific evidence-generation need arises",
    "context": "AI is powerful but adds cost, latency, and auditability burden.",
    "options": [
     "No AI",
     "Grounded AI only",
     "Agentic AI"
    ],
    "chosen": "No AI in this vertical",
    "why": "Vertical does not currently justify AI-shaped complexity.",
    "consequences": [
     "No prompt catalog to maintain"
    ],
    "risks": [],
    "reversal": "Introduce AI only for a scoped generation task.",
    "revisit_when": "A specific generation task appears with clear source grounding."
   },
   {
    "id": "ADR-006",
    "decision": "Managed OAuth (Google) with roles in a dedicated user_roles table",
    "context": "Storing roles on the profile row invites privilege-escalation bugs; RLS policies must reference a stable role source.",
    "options": [
     "Roles on profiles",
     "user_roles + has_role() SECURITY DEFINER",
     "External IdP with JIT claims"
    ],
    "chosen": "user_roles table + has_role() SECURITY DEFINER, referenced by RLS",
    "why": "Prevents recursive RLS, isolates authz decisions, satisfies audit review.",
    "consequences": [
     "One extra join in policies",
     "Explicit role grants required"
    ],
    "risks": [
     "Role drift if grants are not audited"
    ],
    "reversal": "Swap SECURITY DEFINER function for an IdP claim without changing policies.",
    "revisit_when": "Enterprise SSO / SAML contract signed, or role count exceeds ~10."
   },
   {
    "id": "ADR-007",
    "decision": "Single-tenant per blueprint slug with row-level isolation",
    "context": "Blueprints share infra but must never cross-read evidence, sync history, or generated artifacts.",
    "options": [
     "Shared DB + RLS",
     "Schema-per-tenant",
     "DB-per-tenant"
    ],
    "chosen": "Shared DB + RLS keyed on auth.uid() and blueprint slug",
    "why": "Simplest operable model at current scale; migration cost stays near zero.",
    "consequences": [
     "RLS is load-bearing security"
    ],
    "risks": [
     "A missing policy = a leak"
    ],
    "reversal": "Extract a specific tenant to its own schema when contract requires it.",
    "revisit_when": "First enterprise customer with a residency or dedicated-DB clause."
   }
  ],
  "roadmap": [
   {
    "phase": "MVP",
    "build": [
     "Network shell + Blueprint Core module",
     "Content Pipeline with concurrency + backoff",
     "Design + Architecture DNA per blueprint",
     "Sync + rollback + audit trail"
    ],
    "avoid": [
     "Any per-blueprint deploy pipeline",
     "Message brokers",
     "Vector DBs",
     "Multi-region"
    ],
    "defer": [
     "A workflow engine",
     "Full-text search infra",
     "Dedicated CDN rules"
    ],
    "monitor": [
     "Edge function IDLE_TIMEOUT rate",
     "AI cost per generation",
     "Duplicate-slug regressions"
    ],
    "triggers_to_change": [
     "p95 breach on Blueprint detail > 800ms",
     "≥ 3 IDLE_TIMEOUTs/day sustained"
    ],
    "acceptable_debt": [
     "Client-owned job orchestration",
     "localStorage-backed UI state"
    ],
    "dangerous_debt": [
     "Missing RLS on any public table",
     "Ungrounded AI in customer-visible surfaces"
    ]
   },
   {
    "phase": "Stabilization",
    "build": [
     "Automated smoke test per blueprint on cache invalidation",
     "Per-slug retention + audit trail export",
     "Contract tests for every edge function"
    ],
    "avoid": [
     "Premature module extraction"
    ],
    "defer": [
     "Multi-tenant admin console"
    ],
    "monitor": [
     "SLO burn rate",
     "Cost per blueprint per week"
    ],
    "triggers_to_change": [
     "A single blueprint accounts for > 30% of AI spend"
    ],
    "acceptable_debt": [
     "Manual runbook execution for rare failures"
    ],
    "dangerous_debt": [
     "Untested rollback path",
     "Backups without a restore drill"
    ]
   },
   {
    "phase": "Growth",
    "build": [
     "Optional workflow engine adapter behind the current queue interface",
     "Read replica for Postgres if analytics queries interfere",
     "Feature flags per capability module"
    ],
    "avoid": [
     "Splitting Blueprint Core into services without SLO justification"
    ],
    "defer": [
     "Real-time collaboration"
    ],
    "monitor": [
     "Fan-out concurrency vs edge function limits"
    ],
    "triggers_to_change": [
     "> 10 concurrent long jobs per blueprint",
     "New team joins with independent release cadence"
    ],
    "acceptable_debt": [
     "Env-based feature flags"
    ],
    "dangerous_debt": [
     "Skipping migration reviews",
     "Unaudited role grants"
    ]
   },
   {
    "phase": "Scale",
    "build": [
     "Extract Content Pipeline to a dedicated service if it dominates deploys",
     "Search index (Postgres FTS → dedicated) once FTS p95 breaches SLO"
    ],
    "avoid": [
     "Microservices per blueprint"
    ],
    "defer": [
     "Multi-region until a customer contract requires it"
    ],
    "monitor": [
     "DB CPU + IO under peak",
     "Search p95"
    ],
    "triggers_to_change": [
     "Regional compliance contract signed"
    ],
    "acceptable_debt": [
     "Single-region deployment"
    ],
    "dangerous_debt": [
     "Unbounded audit trail growth",
     "Missing DR drill evidence"
    ]
   },
   {
    "phase": "Enterprise/Compliance",
    "build": [
     "Formal SOC 2 evidence pipeline (access reviews, change management)",
     "Tenant-scoped encryption keys where regulation requires",
     "DR drill quarterly with restore proof"
    ],
    "avoid": [
     "Custom compliance frameworks; ride managed platform attestations"
    ],
    "defer": [
     "FedRAMP unless a customer commits"
    ],
    "monitor": [
     "Access review completion",
     "Restore-test success rate"
    ],
    "triggers_to_change": [
     "Signed contract with SOC 2 clause",
     "PHI/PII scope change"
    ],
    "acceptable_debt": [
     "Manual quarterly access review with checklist"
    ],
    "dangerous_debt": [
     "Ad-hoc admin access without approval trail"
    ]
   }
  ],
  "anti_overengineering": {
   "flagged": [
    {
     "item": "Introducing Kubernetes",
     "why": "Team size + workload shape don't justify it.",
     "simpler": "Managed Cloud primitives."
    },
    {
     "item": "Adopting microservices",
     "why": "Single deploy cadence + shared audit boundary.",
     "simpler": "Modular monolith with edge functions."
    },
    {
     "item": "Adopting a vector DB",
     "why": "Sources are small + structured; deterministic retrieval works.",
     "simpler": "Direct source fetch + Postgres FTS."
    },
    {
     "item": "Adopting event sourcing",
     "why": "Audit trail table already provides the needed reconstructibility.",
     "simpler": "Append-only audit_trail + snapshots."
    },
    {
     "item": "Multi-region from day one",
     "why": "No customer contract requires it.",
     "simpler": "Single region + documented DR plan."
    },
    {
     "item": "Custom workflow engine",
     "why": "In-app queue covers current concurrency needs.",
     "simpler": "blueprintJobQueue with backoff."
    },
    {
     "item": "Premature message queue",
     "why": "In-app queue + audit trail cover the fan-out cases.",
     "simpler": "Keep blueprintJobQueue; revisit at 10x volume."
    },
    {
     "item": "Custom auth",
     "why": "Managed OAuth + user_roles cover the model.",
     "simpler": "Cloud Auth + user_roles table."
    },
    {
     "item": "Premature caching layer",
     "why": "React Query covers the read-heavy paths.",
     "simpler": "React Query + HTTP cache headers."
    },
    {
     "item": "Data warehouse",
     "why": "No analytics contract; Postgres analytics queries suffice.",
     "simpler": "Read replica if the primary is hurt."
    }
   ]
  },
  "risks": [
   {
    "risk": "Edge function IDLE_TIMEOUT on long generations",
    "likelihood": "moderate",
    "impact": "high",
    "mitigation": "Per-document endpoints + client-side retries with exponential backoff.",
    "detection": "Smoke test runner + diagnostics drawer flags IDLE_TIMEOUT.",
    "owner": "engineering",
    "escalation": "Sustained > 3/day for one blueprint → open incident.",
    "fallback": "Fall back to last-known-good cached artifact; pause auto-generation for the affected blueprint.",
    "category": "technical"
   },
   {
    "risk": "Duplicate slugs in SEED causing UI regressions",
    "likelihood": "moderate",
    "impact": "moderate",
    "mitigation": "mergedSeed dedupes by slug; add lint on SEED at build time.",
    "detection": "React duplicate-key warning; per-slug uniqueness assertion in tests.",
    "owner": "engineering",
    "escalation": "Ship-block if reproduced on main.",
    "fallback": "Runtime dedupe in mergedSeed keeps first occurrence.",
    "category": "technical"
   },
   {
    "risk": "Ungrounded AI output shipped to microsite",
    "likelihood": "low",
    "impact": "high",
    "mitigation": "Citation-first prompts; integrity check gates Seed Articles view.",
    "detection": "Integrity report failing count > 0 blocks display.",
    "owner": "engineering",
    "escalation": "Any customer-visible ungrounded claim → rollback the blueprint.",
    "fallback": "Auto-hide the article + surface owner action to regenerate with stricter prompt.",
    "category": "product"
   },
   {
    "risk": "Cross-tenant data leak via missing RLS on new table",
    "likelihood": "low",
    "impact": "critical",
    "mitigation": "Every CREATE TABLE ships with GRANT + ENABLE RLS + policies in the same migration.",
    "detection": "Security scanner + migration checklist.",
    "owner": "engineering",
    "escalation": "Immediate lockdown + audit.",
    "fallback": "Revoke Data API grants on affected table; restore from PITR if data was modified.",
    "category": "security"
   },
   {
    "risk": "AI cost runaway on a single blueprint",
    "likelihood": "moderate",
    "impact": "moderate",
    "mitigation": "Per-slug rate limits + smoke-test cache + concurrency cap in UI.",
    "detection": "Cost monitoring dashboard; per-blueprint spend alert at 3x baseline.",
    "owner": "SRE",
    "escalation": "Auto-pause generation; require manual re-enable.",
    "fallback": "Disable AI for the offending blueprint via feature flag; serve last-known-good.",
    "category": "cost"
   },
   {
    "risk": "AI provider outage or model deprecation",
    "likelihood": "moderate",
    "impact": "moderate",
    "mitigation": "Per-capability fallback model + retry with backoff; abstract via Lovable AI Gateway.",
    "detection": "Elevated 5xx or empty completions; smoke test failing across blueprints.",
    "owner": "engineering",
    "escalation": "Sustained > 30 min → switch fallback model; notify owners.",
    "fallback": "Serve cached artifacts + disable AI-only capabilities until restored.",
    "category": "vendor"
   },
   {
    "risk": "Compliance evidence gap during audit",
    "likelihood": "low",
    "impact": "high",
    "mitigation": "Evidence-first release gate + audit trail export from UI.",
    "detection": "Missing audit entries surfaced in periodic reconciliation report.",
    "owner": "legal",
    "escalation": "Regulator-visible gap → incident + disclosure per policy.",
    "fallback": "Freeze affected blueprint's release state; produce backfill evidence pack.",
    "category": "compliance"
   },
   {
    "risk": "Solo/small-team key-person dependency",
    "likelihood": "moderate",
    "impact": "high",
    "mitigation": "Deterministic DNA modules keep decisions in code, not in one head; runbooks per capability.",
    "detection": "Bus-factor review each quarter.",
    "owner": "owner",
    "escalation": "> 1 critical path with no backup → hire or contract.",
    "fallback": "Freeze non-critical changes; document current state before further work.",
    "category": "team"
   },
   {
    "risk": "Audit trail gaps on release decisions",
    "likelihood": "low",
    "impact": "critical",
    "mitigation": "Every mutation writes audit entry in the same transaction.",
    "detection": "Audit trail row count vs mutation count reconciliation.",
    "owner": "engineering",
    "escalation": "Regulator-visible gap → incident + disclosure.",
    "fallback": "Reconstruct from Postgres WAL + application logs; disclose per compliance policy.",
    "category": "compliance"
   }
  ],
  "rules": [
   "Keep business logic out of UI components — derivations live in lib/*, panels only render.",
   "Do not introduce a new service without a clear owner and a scaling reason.",
   "All external integrations must have retries, timeouts, and failure handling.",
   "All sensitive actions must be auditable in the same transaction that performs them.",
   "All background jobs must be idempotent.",
   "All APIs must return the normalized error envelope.",
   "All tenant-scoped queries must enforce tenant isolation via RLS — never trust the client.",
   "All expensive AI calls must be logged, capped, and observable.",
   "All schema changes must be reversible or safely migratable — no destructive drops without a rollout plan.",
   "All critical workflows must have observability: correlationId, phase timings, retry timeline.",
   "Every public table ships with GRANT + ENABLE RLS + policies in the same migration.",
   "Every AI span carries a citation; no citation, no ship.",
   "Every destructive action requires typed confirmation."
  ],
  "audit": {
   "product_fit": "Architecture matches an evidence-first, regulated-adjacent workflow product per blueprint.",
   "simplicity": "One shell, one DB, edge functions for bursts — near the simplicity floor for the product's ambitions.",
   "security": "RLS + role table + audit trail; meets ASVS L1 baseline.",
   "reliability": "SLOs defined; per-module degradation; retries + diagnostics in place.",
   "scalability": "Horizontal by blueprint count is the growth axis; per-blueprint scaling is comfortably in headroom.",
   "maintainability": "Deterministic derivations (Design DNA, Architecture DNA) keep per-vertical drift out of components.",
   "performance": "p95 target 600ms is realistic on Cloud edge with warm cache.",
   "cost": "Idle-to-zero for cold blueprints; per-blueprint attribution keeps AI spend controllable.",
   "compliance": "Domain-specific (owner-side TCR profile and Brand+Campaign registration maintenance records, analyst/counsel-cleared analyst release signers, 5-year retention schedules)",
   "dx": "Single stack (React + Vite + Tailwind + Cloud); new blueprint reaches microsite state in one session.",
   "ops_burden": "Managed platform absorbs infra ops; SRE work is limited to SLO watch + runbooks.",
   "extensibility": "New capability = new edge function + new Runtime tab entry; no shell changes required.",
   "team_suitability": "Fits a small team; every added component must retire an older one.",
   "time_to_market": "New blueprint reachable to validation-microsite state within one working session.",
   "recommendation": {
    "style": "modular monolith",
    "stack": "React + Vite + TypeScript + Tailwind + shadcn on the client; Deno edge functions + managed Postgres (RLS) + object storage on the server; Lovable AI Gateway (unused in this vertical).",
    "hosting": "Lovable Cloud managed hosting; preview + production environments; edge functions co-deploy with the app.",
    "database": "Managed Postgres with RLS + JSONB; PITR enabled for critical-tier tenants.",
    "auth": "Managed OAuth (Google default) + user_roles table + has_role() SECURITY DEFINER referenced from RLS policies.",
    "integrations": "GitHub (public read) for sync + sources; Lovable AI Gateway for LLM calls; Cloud Storage for artifacts. No third-party CRM/email/SMS at MVP.",
    "ai_approach": "No AI at MVP for this vertical; revisit only when a scoped generation task with clear sources appears.",
    "build_first": [
     "Blueprint Core (evidence + release gate) — vertical-agnostic.",
     "Content Pipeline (sources → articles → integrity) — required for any evidence claim.",
     "Sync + rollback — required to safely onboard the network."
    ],
    "avoid": [
     "Any per-blueprint deploy pipeline.",
     "Autonomous AI agents that mutate data without owner confirmation.",
     "Bespoke workflow engines before the in-app queue is exhausted."
    ],
    "revisit_later": [
     "Workflow engine adoption when > 10 concurrent long jobs per blueprint.",
     "Search index dedicated infra when Postgres FTS p95 breaches SLO.",
     "Multi-region on the first residency-bound contract."
    ],
    "biggest_risks": [
     "Missing RLS on a new public table (critical).",
     "Ungrounded AI output reaching a customer-visible surface.",
     "AI cost runaway on a single blueprint.",
     "Solo/small-team key-person dependency."
    ],
    "first_10_steps": [
     "Confirm managed OAuth + user_roles table + has_role() function are in place.",
     "Enable RLS + policies on every existing public table; add the migration checklist to CI.",
     "Wire correlationId end-to-end across every edge function call.",
     "Ship the smoke test runner as a required post-deploy gate.",
     "Enable PITR + schedule the first restore drill on the calendar.",
     "Add per-slug AI budget caps and cost dashboards.",
     "Enforce evidence-first release gate for every blueprint.",
     "Set SLO burn-rate alerts on the top 3 SLIs.",
     "Document the per-capability runbook (retry, cancel, invalidate).",
     "Publish this Architecture DNA per blueprint as part of the release evidence pack."
    ],
    "top_10_rules": [
     "Every public table ships with GRANT + RLS + policies in the same migration.",
     "Every mutation writes an audit entry in the same transaction.",
     "Every AI span carries a citation; no citation, no ship.",
     "Every long AI call is per-item, never monolithic.",
     "Every edge function call carries a correlationId end-to-end.",
     "Every retry uses exponential backoff + jitter with a hard attempt cap.",
     "Every destructive action requires typed confirmation.",
     "No microservice extraction without a divergent SLO.",
     "No new dependency without a supply-chain scan.",
     "Signature element (Pack-binder tabs with regime chip) and accent (register-slate) are network invariants — respect them."
    ]
   }
  }
 },
 "design": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "archetypes": [
   "compliance/regulatory tool",
   "workflow tool",
   "operations system"
  ],
  "user_mindset": {
   "goals": "Prove, in minutes, that a Brand and Campaign's registration evidence is complete — often while a carrier rejection clock or a new-location launch is already on the calendar.",
   "session_length": "Bursty around rejection events and new-location launches; otherwise a quarterly portfolio drift check.",
   "confidence": "Expert users (office managers, agency media buyers); will not accept an opaque AI verdict without a cited rejection code.",
   "interface_needs": "Print-parity pack layouts, code-cited gap rows, release states, a portfolio view for 5-25 locations."
  },
  "posture": [
   "authoritative",
   "trustworthy",
   "operational"
  ],
  "density": "compact",
  "trust_level": {
   "tier": "high",
   "sensitive_domains": [
    "EIN and legal-entity data",
    "CSP account credentials",
    "customer SMS consent records"
   ],
   "implications": [
    "Every destructive action confirmed with typed intent, never a single click.",
    "Errors carry remediation copy + owner, not just a message.",
    "Focus rings visible on every interactive element (WCAG 2.2 AA minimum).",
    "Named releaser (registration analyst) on any outbound pack.",
    "Explicit unsaved-changes gate on navigation away from an open pack."
   ]
  },
  "differentiation": {
   "avoid": [
    "Material Design defaults",
    "shadcn stock look (unstyled cards + slate ring)",
    "Purple/indigo gradient heroes",
    "Stripe/Linear/Notion mimicry",
    "Vertical cliché: generic AI-chatbot stock photography and alarm-red penalty banners"
   ],
   "strategy": "Anchor on the Signal Registry — a status board of Brands and Campaigns moving from rejected to cleared, each with a CSP chip — as the recurring signature element; every page must include it at least once. Reserve the teal signal accent for release-state and rejection-code signals only."
  },
  "territories": [
   {
    "name": "Signal Registry",
    "color_mood": "signal navy + teal indicator",
    "typography": "Fraunces + Inter",
    "density": "status rows",
    "component_feel": "a carrier-signal status board tracking Brands and Campaigns",
    "motion": "row-reveal",
    "fits": "per-Brand+Campaign pack review and release",
    "risks": "could read as too technical without warm neutrals"
   },
   {
    "name": "Portfolio Signal Board",
    "color_mood": "control-panel navy + teal",
    "typography": "Neue Haas Grotesk",
    "density": "grid-driven",
    "component_feel": "a carrier dispatch panel: one signal light per location",
    "motion": "status-pulse on change",
    "fits": "5-25 location Portfolio Desk view",
    "risks": "grid can overwhelm at very large portfolios without grouping"
   },
   {
    "name": "Resubmit Timeline",
    "color_mood": "slate + teal",
    "typography": "Inter",
    "density": "timeline",
    "component_feel": "a rejection-to-resubmit thread with dated follow-ups",
    "motion": "scroll-sync",
    "fits": "Rejection Cure & Resubmit Desk cycle tracking",
    "risks": "timeline fatigue on long-running rejection chains"
   }
  ],
  "chosen_territory": "Signal Registry",
  "chosen_rationale": "The Completeness Pack is the deliverable and the Brand+Campaign pair is the unit of work; a signal/status-board metaphor keeps every screen artifact-shaped — the way a CSP or a customer's own counsel would actually ask to see it — without borrowing another launched business's binder-tab, ledger-row, or dispatch-panel motif.",
  "prioritized_components": [
   {
    "name": "CSP chip",
    "why": "every Brand+Campaign is scoped by which CSP (Twilio, Telnyx, Bandwidth, Vonage) it registers through"
   },
   {
    "name": "Gap row with rejection-code citation",
    "why": "every line in the gap scorecard must show the exact Twilio/TCR code it fails or satisfies"
   },
   {
    "name": "Completeness Pack assembler",
    "why": "the release output is a bundle: gap scorecard + redlined privacy clause + message flow + samples + CSP checklist + Evidence Index"
   }
  ],
  "patterns": [
   {
    "name": "CSP switcher",
    "description": "Global CSP selector (Twilio, Telnyx, Bandwidth, Vonage, expandable); every query and checklist respects it."
   },
   {
    "name": "Pack release stamp",
    "description": "Named registration analyst attestation; red (escalated) packs pause for outside-counsel referral and cannot release until that guidance is on file."
   }
  ],
  "states": [
   "default",
   "hover",
   "active",
   "focus",
   "disabled",
   "loading",
   "skeleton",
   "empty",
   "error",
   "warning",
   "success",
   "offline",
   "permission-denied",
   "partial-data",
   "syncing",
   "unsaved-changes",
   "ai-generating"
  ],
  "localization": [
   "Copy budgets assume +35% expansion for DE/FR translations.",
   "RTL mirror verified for AR/HE (icons flipped, numerals kept LTR).",
   "Dates/times/currencies use Intl APIs, never hardcoded formats.",
   "Touch targets ≥ 44px; keyboard tab order matches visual order.",
   "Density modes: comfortable (default), compact (power users), spacious (accessibility)."
  ],
  "uniqueness_audit": {
   "app_specific_decisions": [
    "Signal Registry motif (status rows, not binder tabs or ledger rows)",
    "Gap-row-cites-rejection-code-or-explicit-gap copy discipline — never invented data"
   ],
   "cliches_avoided": [
    "Generic AI-chatbot stock photography",
    "Green-check compliance theatre",
    "Penalty-scare banners"
   ],
   "scale_notes": "New blueprints inherit the network shell but MUST declare their own signature element, accent role, and anti-reference before they can be marked ready. Enforced by the release gate."
  },
  "tokens": {
   "brand": "206 55% 18%",
   "brand-fg": "200 25% 96%",
   "surface": "200 20% 97%",
   "ink": "210 25% 12%",
   "muted": "210 10% 40%",
   "accent": "184 65% 34%"
  },
  "type": {
   "display": "'Fraunces', ui-serif, serif",
   "body": "'Inter', system-ui, sans-serif",
   "fonts_url": "https://fonts.googleapis.com/css2?family=Fraunces:opsz,wght@9..144,500;9..144,700&family=Inter:wght@400;500;600&display=swap"
  },
  "signature": {
   "motif": "Signal Registry status rows · CSP chip",
   "render": "status-rows"
  }
 },
 "seo": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "archetype": "regulator-fluent authority site",
  "archetype_impact": "Search fit is a regulator-fluent authority site. That means depth over breadth: each page cites the specific TCR Brand & Campaign vetting checklist clause or TCR rule it addresses, and thin variants are refused.",
  "authority_dna": {
   "site_archetype": "regulator-fluent authority site",
   "monetization_model": "B2B lead → validation call → paid Completeness Pack engagement (not ad revenue; not affiliate).",
   "main_search_intents": [
    "informational",
    "commercial"
   ],
   "topical_authority_opportunity": "Own the \"TCR Brand & Campaign vetting checklist SMS-campaign TCR profile\" topic cluster by covering the entire owner-side duty — the written equipment-specific TCR profile, on-site accessibility instructions, 5-year maintenance/callback/use-case-sample record retention (code 30909), gap matrices, vendor TCR profile custody at vendor change, and TCR-specific rules (Twilio rejection code 30908 (privacy policy), the Telnyx/Bandwidth CSP onboarding track) — better than any single-post competitor.",
   "local_seo_opportunity": "Not justified as city pages. Buyers search by TCR/regulator (the Twilio CSP vetting desk, the Telnyx/Bandwidth CSP onboarding track), not by city; that TCR-scoped content belongs in the rule library, not as location doorway pages.",
   "global_national_opportunity": "National (US-first) with two named beachhead CSPs (Twilio-anchored senders; Telnyx/Bandwidth-anchored senders). Expand the TCR rule library market-by-market as new jurisdictions are added — not a global/international play.",
   "easiest_ranking_path": "Long-tail, clause-specific how-to and edge-case queries (\"TCR profile walks with vendor,\" \"gap matrix worked example,\" \"generic TCR profile red flags\") where the SERP is dominated by SMS-campaign-outside counsel marketing pages, OEM vendor boilerplate, or aged SaaS-tracker blogs.",
   "hardest_ranking_path": "Head terms like \"SMS-campaign compliance software\" — dominated by aged SaaS vendor domains (KomplyOS, AuditMate, SMS Campaign App, BRYCER). Defer until authority is established.",
   "trust_credibility_requirements": [
    "Named human authors with role + credentials",
    "Twilio/TCR code and rule citations on every claim",
    "Last-reviewed date + change log on regulatory pages",
    "Direct links to primary TCR/code source (not aggregators)",
    "Licensed outside counsel reviewer attribution on YMYL pages"
   ],
   "ymyl": true,
   "expert_review_needed": true,
   "site_structure": "Authority hub + narrow high-intent service page + linkable evidence assets. Not a directory. Not a marketplace.",
   "seo_moat": "always-current TCR Brand & Campaign vetting checklist + TCR-mapped pages (Twilio rejection code 30908 (privacy policy), the Telnyx/Bandwidth CSP onboarding track) with change-log timestamps tracking the Twilio rule update effective Jan 1, 2026"
  },
  "search_market": {
   "primary_markets": [
    "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile completeness workflow",
    "Twilio rejection code 30908 (privacy policy) Brand+Campaign registration TCR profile compliance"
   ],
   "secondary_markets": [
    "SMS-campaign maintenance-records inspection-readiness",
    "vendor TCR profile custody documentation",
    "SMS-campaign TCR profile gap matrix"
   ],
   "low_competition_subtopics": [
    "TCR profile walks with vendor edge cases",
    "missing use-case-sample record handling",
    "SMS-campaign TCR profile for multifamily portfolios"
   ],
   "high_commercial_intent": [
    "SMS-campaign TCR profile completeness pack service",
    "done-for-you SMS-campaign TCR profile documentation",
    "pre-inspection SMS-campaign TCR profile rush review",
    "SMS-campaign compliance documentation outside counsel"
   ],
   "informational": [
    "what is an SMS-campaign Brand & Campaign TCR registration",
    "TCR Brand & Campaign vetting checklist explained",
    "what happens if an SMS-campaign TCR profile is missing"
   ],
   "local_intent": [
    "[PLACEHOLDER] owner to complete"
   ],
   "transactional": [
    "TCR profile completeness pack pricing",
    "book an SMS-campaign TCR profile gap scan",
    "SMS-campaign TCR profile compliance service demo"
   ],
   "comparison": [
    "completeness pack vs SMS-campaign consulting firm",
    "completeness pack vs SMS-campaign compliance SaaS tracker",
    "CampaignClear vs DeviceClear vs ClosePack Clear"
   ],
   "problem_solution": [
    "how to survive an SMS-campaign inspection with missing records",
    "TCR profile walked away with the old vendor — what to do",
    "red-tag SMS-campaign recovery documentation"
   ],
   "near_me": [
    "[PLACEHOLDER] owner to complete"
   ],
   "long_tail": [
    "Twilio rejection code 30909 (message flow) five-year maintenance record retention explained",
    "Twilio rejection code 30908 (privacy policy) missing TCR profile inspection failure",
    "Telnyx/Bandwidth SMS-campaign TCR profile on-site accessibility requirement"
   ],
   "questions": [
    "what does an SMS-campaign TCR profile need to include?",
    "who owns the SMS-campaign TCR profile when vendors change?",
    "how long must SMS-campaign maintenance records be retained?",
    "how long does a TCR profile Completeness Pack take?"
   ],
   "emerging": [
    "AI-assisted SMS-campaign TCR profile gap scoring",
    "automated vendor chase-letter drafting for SMS-campaign records"
   ],
   "seasonal": [
    "Twilio rejection code 30908 (privacy policy) rule effective January 1, 2026",
    "annual pre-inspection TCR profile re-scan season"
   ],
   "underserved_serps": [
    "TCR profile walks with vendor edge cases",
    "missing use-case-sample record handling"
   ],
   "weak_serps": [
    "SMS-campaign TCR profile records checklist",
    "TCR Brand & Campaign vetting checklist retention requirements"
   ],
   "forum_dominated_serps": [
    "what happens if an SMS-campaign fails inspection for missing TCR profile",
    "SMS-campaign red-tag removal process"
   ],
   "winnable_authoritative_serps": [
    "SMS-campaign TCR profile completeness definitive guide",
    "TCR Brand & Campaign vetting checklist TCR profile evidence requirements"
   ],
   "avoid_initially": [
    "SMS-campaign compliance software",
    "SMS-campaign maintenance tracking platform",
    "best SMS-campaign compliance tools"
   ],
   "easy_wins": [
    "TCR profile walks with vendor edge cases",
    "SMS-campaign TCR profile records checklist",
    "Twilio rejection code 30908 (privacy policy) rule update summary"
   ],
   "moderate": [
    "SMS-campaign TCR profile completeness definitive guide",
    "SMS-campaign maintenance-records inspection-readiness"
   ],
   "long_term_plays": [
    "SMS-campaign compliance software",
    "portfolio TCR profile registers for large owners"
   ],
   "do_not_pursue": [
    "generic \"how to start a compliance business\" content",
    "celebrity or trend-jacking posts",
    "AI-generated listicles"
   ]
  },
  "keyword_clusters": [
   {
    "primary": "TCR Brand & Campaign vetting checklist TCR profile completeness evidence requirements",
    "related": [
     "audit-ready SMS-campaign TCR profile records",
     "TCR profile evidence checklist"
    ],
    "intent": "commercial",
    "user_problem": "An inspection, insurer, or lender diligence request is coming and TCR profile/records are scattered across vendor files",
    "funnel": "BOFU",
    "business_value": "high",
    "ranking_difficulty": "medium",
    "conversion_potential": "high",
    "content_effort": "medium",
    "serp_weakness": "SERP dominated by SMS-campaign-outside counsel marketing pages and generic OEM boilerplate",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "Pillar / evidence guide",
    "reason": "High buyer intent + weak SERP + our unique released-pack proof",
    "priority_score": 17,
    "priority": "P0",
    "bucket": "easy-win"
   },
   {
    "primary": "completeness pack vs SMS-campaign consulting firm vs SaaS tracker",
    "related": [
     "SMS-campaign compliance service alternatives",
     "SMS-campaign TCR profile SaaS comparison"
    ],
    "intent": "commercial",
    "user_problem": "Evaluating a bespoke consulting engagement or a dashboard nobody will operate vs a documentation service",
    "funnel": "BOFU",
    "business_value": "high",
    "ranking_difficulty": "medium",
    "conversion_potential": "high",
    "content_effort": "medium",
    "serp_weakness": "Weak — mostly self-serving SaaS vendor pages and outside counsel firm sites",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "Comparison page (honest, evidence-based)",
    "reason": "Late-funnel intent with weak competition",
    "priority_score": 16,
    "priority": "P0",
    "bucket": "easy-win"
   },
   {
    "primary": "CampaignClear vs DeviceClear vs ClosePack Clear",
    "related": [
     "SMS-campaign TCR profile pack vs TCR certificate filing",
     "SMS-campaign TCR profile vs sprinkler deficiency closure pack"
    ],
    "intent": "commercial",
    "user_problem": "A buyer researching one AINBIS compliance-pack business lands on the wrong one and needs to route to the right outcome",
    "funnel": "MOFU",
    "business_value": "medium",
    "ranking_difficulty": "low",
    "conversion_potential": "medium",
    "content_effort": "low",
    "serp_weakness": "Thin — essentially unclaimed branded/disambiguation query",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "Comparison page (disambiguation)",
    "reason": "Prevents brand confusion and misrouted leads; cheap to rank; explicitly required by risk register",
    "priority_score": 15,
    "priority": "P0",
    "bucket": "easy-win"
   },
   {
    "primary": "SMS-campaign TCR profile records checklist",
    "related": [
     "TCR Brand & Campaign vetting checklist owner checklist",
     "SMS-campaign TCR profile audit checklist"
    ],
    "intent": "informational",
    "user_problem": "Wants a concrete one-page artifact covering the records an carrier vetting reviewer asks for",
    "funnel": "MOFU",
    "business_value": "medium",
    "ranking_difficulty": "low",
    "conversion_potential": "medium",
    "content_effort": "low",
    "serp_weakness": "Weak — thin listicles and vendor PDFs",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "Resource / lead magnet page",
    "reason": "Easy win + strong lead-magnet fit",
    "priority_score": 14,
    "priority": "P0",
    "bucket": "easy-win"
   },
   {
    "primary": "Twilio rejection code 30908 (privacy policy) rule update and Jan 2026 deadlines",
    "related": [
     "Twilio's published error-code index",
     "Twilio's Brand+Campaign registration completeness inspection-failure rule"
    ],
    "intent": "informational",
    "user_problem": "Needs authoritative detail on the Twilio rule update effective January 1, 2026 and what it means for TCR profile completeness",
    "funnel": "TOFU",
    "business_value": "medium",
    "ranking_difficulty": "low",
    "conversion_potential": "medium",
    "content_effort": "low",
    "serp_weakness": "Weak — outdated pages ranking",
    "local_relevance": "medium",
    "global_relevance": "medium",
    "suggested_page_type": "Data table / rule-change page",
    "reason": "Recurring beachhead-TCR traffic + easy freshness moat",
    "priority_score": 14,
    "priority": "P0",
    "bucket": "easy-win"
   },
   {
    "primary": "TCR profile walks with vendor: custody edge cases",
    "related": [
     "vendor change SMS-campaign TCR profile custody",
     "no TCR profile exists escalation",
     "Telnyx/Bandwidth red-tag TCR profile custody guidance"
    ],
    "intent": "informational",
    "user_problem": "Facing a scenario the standard guides do not cover (vendor switch, no TCR profile ever authored, contested code interpretation)",
    "funnel": "MOFU",
    "business_value": "medium",
    "ranking_difficulty": "low",
    "conversion_potential": "medium",
    "content_effort": "medium",
    "serp_weakness": "SERP is thin and forum-heavy",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "How-to cluster page",
    "reason": "Easy win + high assist to product page",
    "priority_score": 13,
    "priority": "P0",
    "bucket": "easy-win"
   },
   {
    "primary": "SMS-campaign compliance software",
    "related": [
     "SMS-campaign compliance platform",
     "best SMS-campaign compliance tracking tools"
    ],
    "intent": "commercial",
    "user_problem": "Ready to buy a tracking tool",
    "funnel": "BOFU",
    "business_value": "high",
    "ranking_difficulty": "high",
    "conversion_potential": "high",
    "content_effort": "high",
    "serp_weakness": "Strong — aged SaaS vendor domains (KomplyOS, AuditMate, SMS Campaign App, BRYCER)",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "Product page (defer)",
    "reason": "Long-term play — do not chase before authority is built",
    "priority_score": 9,
    "priority": "P1",
    "bucket": "medium"
   },
   {
    "primary": "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile definitive guide",
    "related": [
     "what is an SMS-campaign Brand & Campaign TCR registration",
     "who is responsible for the SMS-campaign TCR profile"
    ],
    "intent": "informational",
    "user_problem": "Just inherited SMS-campaign/Brand+Campaign registration compliance responsibility and needs to orient",
    "funnel": "TOFU",
    "business_value": "medium",
    "ranking_difficulty": "medium",
    "conversion_potential": "low",
    "content_effort": "high",
    "serp_weakness": "Moderate — mostly generic OEM and outside counsel vendor content",
    "local_relevance": "low",
    "global_relevance": "high",
    "suggested_page_type": "Pillar page",
    "reason": "Anchors topical authority for the whole cluster",
    "priority_score": 7,
    "priority": "P1",
    "bucket": "medium"
   }
  ],
  "topical_authority_map": {
   "core_topics": [
    "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile — definitive guide",
    "TCR profile evidence & inspection-readiness",
    "TCR rule library (Twilio/TCR TCR checklist, Twilio rejection code 30908 (privacy policy), the Telnyx/Bandwidth CSP onboarding track)"
   ],
   "pillars": [
    {
     "name": "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile — definitive guide",
     "core_intent": "informational",
     "audience": "facilities directors, property managers, and risk/ownership asset managers",
     "conversion_goal": "Owner checklist download → later validation call",
     "supporting_pages": [
      "The equipment-specific TCR profile requirement explained",
      "5-year maintenance-record retention under code 30909",
      "TCR profile custody at vendor change (edge cases)",
      "TCR Brand & Campaign vetting checklist FAQs"
     ],
     "internal_links": [
      "/product",
      "/rules/twilio/rejection-codes/",
      "/resources/checklist"
     ],
     "schema": [
      "Article",
      "BreadcrumbList",
      "FAQPage (where genuine)"
     ],
     "evidence_needed": [
      "Named reviewer",
      "Primary-source citations",
      "Worked example"
     ],
     "local_variants": [
      "[PLACEHOLDER] owner to complete"
     ],
     "national_variants": [
      "US-national (default)"
     ]
    },
    {
     "name": "TCR profile evidence & inspection-readiness",
     "core_intent": "commercial",
     "audience": "facilities directors, property managers, and risk/ownership asset managers",
     "conversion_goal": "Book validation call",
     "supporting_pages": [
      "TCR Brand & Campaign vetting checklist TCR profile completeness evidence requirements",
      "SMS Campaign TCR profile records audit checklist",
      "Common TCR profile evidence gaps (the generic, non-equipment-specific TCR profile)"
     ],
     "internal_links": [
      "/product",
      "/guides/a2p-10dlc-registration/",
      "/resources/evidence-checklist"
     ],
     "schema": [
      "Article",
      "FAQPage",
      "BreadcrumbList",
      "HowTo (only for real workflow)"
     ],
     "evidence_needed": [
      "Worked evidence artifact",
      "TCR citation",
      "Reviewer credential"
     ],
     "local_variants": [],
     "national_variants": [
      "US-national"
     ]
    },
    {
     "name": "TCR rule library",
     "core_intent": "informational",
     "audience": "facilities directors, property managers, and risk/ownership asset managers",
     "conversion_goal": "Assisted conversion via internal linking",
     "supporting_pages": [
      "TCR Brand & Campaign vetting checklist — TCR profile requirement, rules and citations",
      "Twilio rejection code 30909 (message flow) — 5-year record retention, rules and citations",
      "Twilio rejection code 30908 (privacy policy) — Brand+Campaign registration TCR profile definition and inspection-failure rule",
      "Twilio's published error-code index rule update (eff. Jan 1, 2026)",
      "the Telnyx/Bandwidth CSP onboarding track — owner/contractor shared TCR profile responsibility",
      "Telnyx/Bandwidth 5-year maintenance-records acknowledgment form",
      "A17.1-2025 networked-control cybersecurity module (TCR-conditional only)"
     ],
     "internal_links": [
      "/guides/a2p-10dlc-registration/",
      "/product"
     ],
     "schema": [
      "Article",
      "BreadcrumbList"
     ],
     "evidence_needed": [
      "Primary source link",
      "Visited-on date",
      "Reviewer sign-off"
     ],
     "local_variants": [],
     "national_variants": [
      "US-national"
     ]
    }
   ],
   "supporting_page_types": [
    "definition / glossary",
    "how-to workflow",
    "edge-case handling",
    "rule-change explainer",
    "worked example",
    "FAQ",
    "comparison (only when honest)",
    "case study (only with permission)",
    "evidence artifact / template",
    "regulator update log"
   ]
  },
  "site_architecture": {
   "homepage_strategy": "Above-the-fold: one-sentence purpose + primary CTA (validation call). Below: 3 problem-cards linking to pillars, 1 evidence-asset teaser, 1 authority statement with named reviewer.",
   "main_nav": [
    "Product",
    "How it works",
    "Pillars",
    "Resources",
    "About",
    "Contact"
   ],
   "footer_nav": [
    "Editorial policy",
    "Contact",
    "Privacy",
    "Terms",
    "Sitemap",
    "Changelog"
   ],
   "hubs": [
    {
     "name": "Product / service",
     "url": "/product",
     "purpose": "High-intent commercial page"
    },
    {
     "name": "Guides pillar",
     "url": "/guides",
     "purpose": "Topical authority hub"
    },
    {
     "name": "Rule library",
     "url": "/rules",
     "purpose": "Entity/regulation reference"
    },
    {
     "name": "Resources",
     "url": "/resources",
     "purpose": "Linkable assets (templates, checklists)"
    },
    {
     "name": "Changelog",
     "url": "/changelog",
     "purpose": "Freshness + trust signal"
    }
   ],
   "url_patterns": [
    "/product",
    "/guides/[topic]/",
    "/guides/[topic]/[subtopic]/",
    "/rules/[regulator]/[rule]/",
    "/resources/[asset]/",
    "/compare/[a]-vs-[b]/",
    "/glossary/[term]/"
   ],
   "avoid_url_patterns": [
    "/[city]/[service]/ (no local intent for this buyer)",
    "/blog/[year]/[month]/[slug]/ (dated slugs decay CTR)",
    "/tag/[tag]/ (thin archive pages)",
    "Any duplicate /service/ and /solutions/ trees"
   ]
  },
  "global_national": {
   "national_clusters": [
    "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile — definitive guide",
    "TCR profile completeness evidence workflow",
    "Twilio rejection code 30908 (privacy policy) Brand+Campaign registration TCR profile rule",
    "SMS-campaign maintenance-records inspection-readiness"
   ],
   "linkable_assets": [
    "One-page TCR Brand & Campaign vetting checklist owner TCR profile checklist (downloadable, gated by email is OK)",
    "TCR rule-to-record mapping table (Twilio + Telnyx/Bandwidth, HTML + PDF)",
    "Change-log / TCR rule update tracker (incl. Twilio eff. Jan 1, 2026)",
    "Worked gap-matrix examples (redacted, fixture data labeled illustrative)"
   ],
   "original_research_ideas": [
    "Annual multi-portfolio TCR profile completeness readiness benchmark (survey of ~50 property managers)",
    "Evidence completeness index: share of vendor-supplied TCR profiles missing equipment-specific detail (anonymized intake data)",
    "TCR expansion variation index (Twilio vs Telnyx/Bandwidth vs future CSPs)"
   ],
   "international_needed": false,
   "international_notes": "Not needed. US-first. Do not build hreflang variants."
  },
  "local_seo": {
   "justified": false,
   "reason": "Buyers search by TCR/regulator (the Twilio CSP vetting desk, the Telnyx/Bandwidth CSP onboarding track), not by city. City-level local pages would be doorway pages; TCR jurisdiction content belongs in the rule library instead.",
   "gbp_categories_primary": [
    "[PLACEHOLDER] owner to complete"
   ],
   "gbp_categories_secondary": [
    "[PLACEHOLDER] owner to complete"
   ],
   "location_page_rules": [
    "Do not build city-level location pages for this blueprint.",
    "TCR jurisdiction pages (Twilio, Telnyx/Bandwidth) live under /rules/, not as location doorway pages."
   ],
   "citations": [
    "[PLACEHOLDER] owner to complete"
   ],
   "review_strategy": "Reviews are not a Local ranking factor here; use case studies and reviewer credibility instead.",
   "local_schema": [
    "[PLACEHOLDER] owner to complete"
   ]
  },
  "programmatic": {
   "recommended": false,
   "reason": "Programmatic pages almost always become doorway pages in regulated niches. Prefer a small number of deeply-researched pages per TCR.",
   "rules": [
    "Only allowed for genuinely differentiated data (e.g., an TCR-by-TCR rule table where each jurisdiction truly differs)",
    "Every programmatic page must include: unique data field + unique regulatory content + human review before publish",
    "noindex until minimum quality threshold met",
    "Rel=canonical to the pillar when a page falls below threshold"
   ],
   "per_page_requirements": [
    "≥1 unique data point not present on sibling pages",
    "≥1 unique paragraph of human-written analysis",
    "Verified last-reviewed date"
   ],
   "quality_gates": [
    "Editorial review before indexation",
    "Quarterly re-review or noindex",
    "Automated thin-content detector (<300 words unique) blocks publish"
   ]
  },
  "page_templates": [
   {
    "page_type": "Homepage",
    "purpose": "State the offer + route to validation call.",
    "target_intent": "commercial",
    "url_pattern": "/",
    "h1_pattern": "[One-sentence purpose]",
    "title_pattern": "[Brand] — [One-sentence purpose]",
    "meta_description_pattern": "One sentence outcome + CTA verb. ≤ 155 chars.",
    "above_the_fold": [
     "H1",
     "Sub-headline (audience + outcome)",
     "Primary CTA (validation call)",
     "1 trust chip (reviewer / cite)"
    ],
    "outline": [
     "Problem framing",
     "3 pillar cards",
     "Evidence asset teaser",
     "Named reviewer statement",
     "Contact"
    ],
    "internal_links": [
     "/product",
     "/guides",
     "/resources",
     "/about"
    ],
    "conversion_elements": [
     "Calendar CTA",
     "Checklist download secondary"
    ],
    "schema": [
     "Organization",
     "WebSite",
     "SearchAction"
    ],
    "trust_elements": [
     "Reviewer name",
     "Editorial policy link"
    ],
    "media": [
     "Original workflow diagram (SVG)"
    ],
    "faq_opportunities": [
     "Top 3 buyer questions"
    ],
    "cta_strategy": "Above-the-fold soft + end-of-page primary",
    "quality_requirements": [
     "Loads < 2.5s LCP",
     "Named reviewer visible"
    ],
    "anti_thin_rules": [
     "No stock hero",
     "No generic 'we help X do Y' filler"
    ]
   },
   {
    "page_type": "Pillar page",
    "purpose": "Anchor a topic cluster with a definitive explanation.",
    "target_intent": "informational",
    "url_pattern": "/guides/[topic]/",
    "h1_pattern": "[Topic] — Definitive Guide",
    "title_pattern": "[Topic] — Definitive Guide | [Brand]",
    "meta_description_pattern": "Definition + what the reader will learn + reviewer credential.",
    "above_the_fold": [
     "H1",
     "40–60 word definition block",
     "TOC",
     "Last-reviewed date + reviewer"
    ],
    "outline": [
     "Definition",
     "Who this applies to",
     "Workflow",
     "Rules & citations",
     "Edge cases",
     "FAQs",
     "Related pages"
    ],
    "internal_links": [
     "Cluster sub-pages",
     "Rule library",
     "Product"
    ],
    "conversion_elements": [
     "End-of-page checklist download",
     "Sidebar validation call CTA"
    ],
    "schema": [
     "Article",
     "BreadcrumbList",
     "FAQPage (only real FAQs)"
    ],
    "trust_elements": [
     "Named author + reviewer",
     "Primary source cites"
    ],
    "media": [
     "Original diagrams",
     "Rule comparison table"
    ],
    "faq_opportunities": [
     "Real questions from practitioners"
    ],
    "cta_strategy": "Assist conversion via internal link to product; primary CTA end-of-page.",
    "quality_requirements": [
     "≥ 1500 words unique",
     "≥ 3 primary sources cited",
     "Reviewer credential visible"
    ],
    "anti_thin_rules": [
     "No listicles padded with keyword variants",
     "No AI-generated body"
    ]
   },
   {
    "page_type": "How-to cluster page",
    "purpose": "Answer a specific workflow question inside a cluster.",
    "target_intent": "informational",
    "url_pattern": "/guides/[topic]/[subtopic]/",
    "h1_pattern": "[Specific action or question]",
    "title_pattern": "[Specific action] — [Pillar topic] | [Brand]",
    "meta_description_pattern": "Concrete outcome + who it applies to + one caveat.",
    "above_the_fold": [
     "H1",
     "Direct answer paragraph",
     "Numbered steps preview"
    ],
    "outline": [
     "Direct answer",
     "Steps",
     "Edge cases",
     "Common mistakes",
     "Related pages"
    ],
    "internal_links": [
     "Pillar page",
     "Sibling clusters",
     "Product"
    ],
    "conversion_elements": [
     "End-of-page checklist download",
     "Related tool link"
    ],
    "schema": [
     "Article",
     "HowTo (only if real workflow)",
     "BreadcrumbList"
    ],
    "trust_elements": [
     "Named author",
     "Reviewer for YMYL"
    ],
    "media": [
     "Screenshots of the actual workflow"
    ],
    "faq_opportunities": [
     "Follow-up questions"
    ],
    "cta_strategy": "Contextual link to product mid-page; primary CTA end-of-page.",
    "quality_requirements": [
     "Unique steps not duplicated from pillar",
     "Reviewer date visible"
    ],
    "anti_thin_rules": [
     "No spun variants of the pillar"
    ]
   },
   {
    "page_type": "Product / service page",
    "purpose": "Convert commercial intent.",
    "target_intent": "commercial",
    "url_pattern": "/product",
    "h1_pattern": "[Outcome-focused headline]",
    "title_pattern": "[Brand] — [Outcome]",
    "meta_description_pattern": "State the outcome + primary CTA verb.",
    "above_the_fold": [
     "H1",
     "Sub-headline",
     "Primary CTA",
     "Trust chip"
    ],
    "outline": [
     "Problem",
     "How we solve it",
     "Proof / worked example",
     "Objection handling",
     "FAQ",
     "CTA"
    ],
    "internal_links": [
     "Case study",
     "Pillar guide",
     "Evidence checklist"
    ],
    "conversion_elements": [
     "Calendar",
     "Secondary checklist"
    ],
    "schema": [
     "Service or SoftwareApplication (whichever fits)",
     "Organization",
     "FAQPage"
    ],
    "trust_elements": [
     "Named reviewer",
     "Primary-source cites",
     "Contact info"
    ],
    "media": [
     "Screenshot of the actual gap-matrix workflow, not marketing composites"
    ],
    "faq_opportunities": [
     "Buyer objections"
    ],
    "cta_strategy": "Above-the-fold + repeated end-of-page",
    "quality_requirements": [
     "Unique per audience segment (no doorway variants)"
    ],
    "anti_thin_rules": [
     "No thin '/services/X/' spin-offs of the same page"
    ]
   },
   {
    "page_type": "Rule / regulation reference page",
    "purpose": "Serve as the site's citation-grade reference for a specific Twilio rejection code or TCR rule.",
    "target_intent": "informational",
    "url_pattern": "/rules/[regulator]/[rule]/",
    "h1_pattern": "[Regulator] — [Rule] explained",
    "title_pattern": "[Rule] — [Regulator] Requirements | [Brand]",
    "meta_description_pattern": "What the rule requires + last-reviewed date.",
    "above_the_fold": [
     "H1",
     "Definition",
     "Last-reviewed + reviewer"
    ],
    "outline": [
     "What the rule says",
     "Who it applies to",
     "Deadlines",
     "Evidence required",
     "Change log"
    ],
    "internal_links": [
     "Pillar guide",
     "Product"
    ],
    "conversion_elements": [
     "Subscribe to change-log",
     "Sidebar validation call"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "trust_elements": [
     "Primary-source link",
     "Visited-on date",
     "Reviewer credential"
    ],
    "media": [
     "Rule comparison table"
    ],
    "faq_opportunities": [
     "Real practitioner questions"
    ],
    "cta_strategy": "Assist conversion via internal link",
    "quality_requirements": [
     "Primary source link required",
     "Quarterly re-review"
    ],
    "anti_thin_rules": [
     "No auto-generated rule scraping without human review"
    ]
   },
   {
    "page_type": "Comparison page",
    "purpose": "Serve genuine BOFU comparison intent, including disambiguation from sibling AINBIS businesses.",
    "target_intent": "commercial",
    "url_pattern": "/compare/[a]-vs-[b]/",
    "h1_pattern": "[A] vs [B] — Honest Comparison",
    "title_pattern": "[A] vs [B] | [Brand]",
    "meta_description_pattern": "Honest side-by-side + when to pick which.",
    "above_the_fold": [
     "H1",
     "TL;DR verdict",
     "When-to-pick block"
    ],
    "outline": [
     "Criteria",
     "Side-by-side table",
     "Where each wins",
     "Where each loses",
     "Recommendation"
    ],
    "internal_links": [
     "Product",
     "Pillar guide"
    ],
    "conversion_elements": [
     "Calendar CTA",
     "Evidence checklist"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "trust_elements": [
     "Disclose the reviewer's relationship to each option",
     "Never disparage sibling AINBIS businesses — state the different workflow/outcome only"
    ],
    "media": [
     "Feature comparison table"
    ],
    "faq_opportunities": [
     "'Which one do I need?' style"
    ],
    "cta_strategy": "End-of-page primary CTA to the fitting option",
    "quality_requirements": [
     "Honest even when it hurts",
     "Disclose relationship"
    ],
    "anti_thin_rules": [
     "No manufactured 'X vs Y' pages for every pair"
    ]
   },
   {
    "page_type": "FAQ page",
    "purpose": "Aggregate genuine practitioner questions.",
    "target_intent": "informational",
    "url_pattern": "/faq",
    "h1_pattern": "FAQ",
    "title_pattern": "[Topic] FAQ | [Brand]",
    "meta_description_pattern": "Answers to the questions we hear most.",
    "above_the_fold": [
     "H1",
     "Table of contents"
    ],
    "outline": [
     "Grouped questions",
     "Each answer 40–120 words"
    ],
    "internal_links": [
     "Relevant pillars and rule pages"
    ],
    "conversion_elements": [
     "End-of-page CTA"
    ],
    "schema": [
     "FAQPage (only for genuine FAQs visible on-page)"
    ],
    "trust_elements": [
     "Named reviewer"
    ],
    "media": [],
    "faq_opportunities": [
     "Real questions only — never invented"
    ],
    "cta_strategy": "Related-block links, not inline mid-answer",
    "quality_requirements": [
     "No invented questions"
    ],
    "anti_thin_rules": [
     "No 'is X the best' padding"
    ]
   },
   {
    "page_type": "Glossary term page",
    "purpose": "Definition-grade authority for a single ubiquitous-language term.",
    "target_intent": "informational",
    "url_pattern": "/glossary/[term]/",
    "h1_pattern": "[Term]",
    "title_pattern": "[Term] — Definition | [Brand]",
    "meta_description_pattern": "Concise definition + who uses the term.",
    "above_the_fold": [
     "H1",
     "40-word definition"
    ],
    "outline": [
     "Definition",
     "Related terms",
     "Where it applies",
     "Common misuses"
    ],
    "internal_links": [
     "Pillar",
     "Rule pages"
    ],
    "conversion_elements": [
     "Sidebar related-tool link"
    ],
    "schema": [
     "Article",
     "BreadcrumbList",
     "DefinedTerm"
    ],
    "trust_elements": [
     "Cite the primary source of the definition"
    ],
    "media": [],
    "faq_opportunities": [],
    "cta_strategy": "Assist via internal link",
    "quality_requirements": [
     "Never duplicate the pillar's intro"
    ],
    "anti_thin_rules": [
     "No glossary spam"
    ]
   },
   {
    "page_type": "Case study page",
    "purpose": "Concrete outcome-based proof.",
    "target_intent": "commercial",
    "url_pattern": "/case-studies/[slug]/",
    "h1_pattern": "[Outcome achieved for [customer type]]",
    "title_pattern": "Case Study — [Outcome] | [Brand]",
    "meta_description_pattern": "Concrete outcome + timeframe + method.",
    "above_the_fold": [
     "H1",
     "Outcome metric",
     "Approved-for-publication chip"
    ],
    "outline": [
     "Context",
     "Approach",
     "Outcome",
     "Reviewer quote"
    ],
    "internal_links": [
     "Product",
     "Pillar guide"
    ],
    "conversion_elements": [
     "End-of-page CTA"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "trust_elements": [
     "Named customer contact (with permission)"
    ],
    "media": [
     "Redacted artifact screenshots"
    ],
    "faq_opportunities": [],
    "cta_strategy": "End-of-page primary CTA",
    "quality_requirements": [
     "Written approval on file"
    ],
    "anti_thin_rules": [
     "No fabricated case studies"
    ]
   }
  ],
  "on_page_rules": {
   "title_tag": "Pattern: [Primary keyword] — [Angle] | CampaignClear. ≤ 60 chars. Front-load the keyword. No clickbait.",
   "meta_description": "≤ 155 chars. State the specific outcome. Include a verb + a rule citation when applicable. No stuffing.",
   "headings": "One H1. H2s follow the workflow steps or the searcher's questions. H3s for edge cases. No decorative headings.",
   "intro": "First 100 words: define the topic in the searcher's language + name the specific Twilio code/TCR rule + preview what the page delivers.",
   "snippet_targeting": "Add a 40–60 word definition block and a numbered how-to block near the top for featured snippet + AI overview eligibility.",
   "tables_lists": "Use tables for rule comparisons, deadlines, and retention thresholds. Lists for steps. Never use tables for layout.",
   "images": "Original diagrams/screenshots preferred. Descriptive alt text. WebP. Explicit width/height. Never AI slop stock art.",
   "internal_links": "Every page: ≥3 contextual links up to pillar, ≥2 to sibling cluster pages, ≥1 to a commercial page.",
   "external_citations": "Cite the primary source (Twilio/TCR documentation, TCR PDF, eDocket) — not aggregators — with the visited-on date.",
   "author_attribution": "Named author + role + linked bio page. Reviewer for YMYL.",
   "freshness": "Last-reviewed date at top; change log at bottom for regulator pages; quarterly review cadence.",
   "cta_placement": "Above the fold (soft), mid-page (contextual to the section), end-of-page (primary).",
   "mobile": "Single-column, tap targets ≥44px, no interstitials, no autoplay video.",
   "avoid": [
    "Keyword stuffing",
    "AI-generated body copy without human edit",
    "Doorway variants",
    "Unsupported superlatives ('best', 'top-rated') without evidence",
    "Meta descriptions duplicated across pages",
    "Marking up invisible content in schema"
   ]
  },
  "entity_seo": {
   "main_entities": [
    "TCR Brand & Campaign vetting checklist",
    "Brand & Campaign TCR registration (TCR profile)",
    "Twilio rejection code 30908 (privacy policy)",
    "the Telnyx/Bandwidth CSP onboarding track",
    "gap matrix",
    "vendor TCR profile custody",
    "5-year maintenance records",
    "Brand+Campaign registration"
   ],
   "related_entities": [
    "outside counsel (Qualified SMS Campaign Inspector)",
    "on-site accessibility instructions",
    "use-case sample records",
    "hard gap / hard-fail",
    "Evidence Index"
   ],
   "people": [
    "Named practitioners (role-titles)",
    "Licensed outside counsel reviewers",
    "TCR officials referenced (the Twilio CSP vetting desk, the Telnyx/Bandwidth CSP onboarding track)"
   ],
   "orgs": [
    "Twilio Division of Oil and Public Safety (OPS)",
    "the Telnyx/Bandwidth CSP onboarding track",
    "Twilio (CSP)",
    "CSPs (state and county Brand+Campaign registration regulators)"
   ],
   "tools": [
    "TCR rule library",
    "Gap-matrix worksheets",
    "Change-log tracker"
   ],
   "regulations": [
    "TCR Brand & Campaign vetting checklist (TCR profile requirement)",
    "Twilio rejection code 30909 (message flow) (5-year record retention)",
    "Twilio rejection code 30908 (privacy policy) (Brand+Campaign registration TCR profile rule)",
    "Twilio's published error-code index (eff. Jan 1, 2026)",
    "the Telnyx/Bandwidth CSP onboarding track policies",
    "A17.1-2025 networked-control cybersecurity module (TCR-conditional)"
   ],
   "problems": [
    "TCR profile completeness risk",
    "Inspection failure / red-tag risk",
    "TCR profile custody loss at vendor change",
    "Missing 5-year record retention",
    "Evidence gap across vendors"
   ],
   "solutions": [
    "Completeness Pack workflow",
    "Portfolio Desk",
    "TCR-mapped gap matrices",
    "Vendor resubmit kit"
   ],
   "processes": [
    "Intake normalization",
    "TCR checklist matching",
    "Gap scoring",
    "Analyst release",
    "Vendor chase",
    "Re-scan / evidence archive update"
   ],
   "alternatives": [
    "SMS-campaign consulting firms (Argon, KDA, TEC)",
    "OEM/service vendors (Twilio, Telnyx, Bandwidth, Vonage)",
    "SaaS trackers (KomplyOS, AuditMate, SMS Campaign App, BRYCER)"
   ],
   "synonyms": [
    "SMS-campaign maintenance control program records",
    "TCR profile completeness documentation",
    "SMS-campaign compliance binder",
    "audit-ready TCR profile"
   ]
  },
  "schema_strategy": [
   {
    "type": "Organization",
    "where": "Site-wide in head",
    "required_fields": [
     "name",
     "url",
     "logo",
     "sameAs"
    ],
    "caution": "Keep in sync with visible About / contact."
   },
   {
    "type": "WebSite + SearchAction",
    "where": "Homepage",
    "required_fields": [
     "name",
     "url",
     "potentialAction"
    ],
    "caution": "Only if on-site search actually exists."
   },
   {
    "type": "BreadcrumbList",
    "where": "All hub / cluster / rule / glossary pages",
    "required_fields": [
     "itemListElement"
    ],
    "caution": "Order must match visible breadcrumbs."
   },
   {
    "type": "Article",
    "where": "Guides, pillars, rule pages",
    "required_fields": [
     "headline",
     "author",
     "datePublished",
     "dateModified"
    ],
    "caution": "Author must exist as a real person."
   },
   {
    "type": "FAQPage",
    "where": "Genuine FAQ pages only",
    "required_fields": [
     "mainEntity[]"
    ],
    "caution": "Only mark up FAQs visible on the page."
   },
   {
    "type": "HowTo",
    "where": "Real step-by-step workflows only",
    "required_fields": [
     "name",
     "step[]"
    ],
    "caution": "Google narrowed HowTo eligibility; use sparingly."
   },
   {
    "type": "Person",
    "where": "Author bio pages",
    "required_fields": [
     "name",
     "jobTitle",
     "sameAs"
    ],
    "caution": "Credentials must be real and verifiable."
   }
  ],
  "internal_linking": {
   "pillar_to_cluster": "Pillar links to every direct cluster page in a curated section (not a mega-menu dump).",
   "cluster_to_pillar": "Every cluster page links back to its pillar in the intro and in-context.",
   "cluster_to_cluster": "Link between sibling clusters only where the user's next question naturally leads there.",
   "service_to_location": "Not applicable.",
   "faq_to_commercial": "Answer the question first, then link to the commercial page in a 'related' block — never inline mid-answer.",
   "breadcrumbs": "Structured breadcrumbs on all guide, rule, and glossary pages.",
   "anchor_text_rules": [
    "Descriptive — match the target page's H1 concept",
    "Vary phrasing across links to the same target",
    "Never exact-match keyword stuffing",
    "Anchor must make sense read aloud"
   ]
  },
  "technical_seo": {
   "crawlability": "Flat depth (≤3 clicks from homepage). No orphan pages. HTML sitemap on /sitemap.",
   "indexability": "Index all real content. noindex utility pages, thank-you pages, and gated-asset landing pages.",
   "sitemaps": "XML sitemap generated at build time. Split by section if > 5k URLs.",
   "robots": "robots.txt allows all; disallow /admin/, /api/. Reference sitemap.",
   "canonicals": "Self-referencing canonical on every page. Filter/sort variants canonical to the base.",
   "pagination": "Prefer 'load more' or a single long page; if paginated, use rel=next/prev semantics via internal linking.",
   "faceted_nav": "Not applicable for this blueprint (no product catalog).",
   "duplicate_control": "One URL per topic. Consolidate before publishing new variants. No www/non-www split.",
   "redirects": "301 for permanent moves; audit chains monthly; never 302 for SEO redirects.",
   "core_web_vitals": "LCP ≤ 2.5s, INP ≤ 200ms, CLS ≤ 0.1. Test with real-user monitoring.",
   "mobile": "Mobile-first design. No tap-target failures. No horizontal scroll.",
   "accessibility": "WCAG AA. Semantic HTML. Landmarks. Focus states. Alt text.",
   "js_seo": "Content in the initial HTML. Client hydration for interactivity only.",
   "rendering": "Static generation preferred; SSR only where personalized. Never client-only for indexable pages.",
   "gsc_setup": "Verify both www and apex; submit sitemap; monitor Coverage and Enhancements weekly.",
   "analytics_setup": "GA4 + server-side event stream. Consent Mode v2. Event schema documented.",
   "rank_tracking": "Semrush or Ahrefs project set to US database; track pillar + top-20 clusters weekly."
  },
  "eeat": {
   "author_bios": "Every content page has a named author with role, credentials, and a linked author page.",
   "expert_reviewers": "Every YMYL page reviewed by a named expert with disclosed credentials.",
   "editorial_policy": "Public /editorial-policy page: sourcing rules, review cadence, correction policy.",
   "fact_checking": "Every Twilio code/TCR rule reference has a link + visited-on date; corrections dated and disclosed.",
   "credentials": [
    "Licensed outside counsel (Qualified SMS Campaign Inspector) reviewer",
    "Relevant professional licensure where public"
   ],
   "citations": "Cite primary sources (Twilio/TCR documentation, TCR PDF, eDocket). No citation of aggregator blogs.",
   "first_hand_proof": [
    "Screenshots of the actual gap-matrix workflow",
    "Redacted worked examples",
    "Signed reviewer statement"
   ],
   "update_cadence": "Regulatory pages reviewed quarterly; commercial pages reviewed twice yearly.",
   "monetization_disclosure": "Public disclosure that leads convert to paid engagements; no undisclosed affiliate content.",
   "ymyl_notes": "This is YMYL. Language stays cautious (\"may\", \"depends on facts\"); documentation-readiness support only — never claims to inspect SMS-campaigns, certify Brand+Campaign registrations safe, or guarantee inspection pass; the owner remains the responsible party and physical maintenance stays with licensed SMS-campaign contractors; disclaimer near every CTA."
  },
  "ai_search": {
   "principles": [
    "Answer the exact question in the first paragraph",
    "Provide a 40–60 word extractable definition near the top",
    "Structured lists and tables for facts",
    "Cite named primary sources",
    "Author + reviewer names on-page"
   ],
   "tactics": [
    "FAQPage schema for genuine FAQs (not stuffed)",
    "HowTo schema for real workflow pages",
    "Consistent entity naming across the site",
    "Concise summaries at the top of long guides"
   ],
   "do_not": [
    "Write pages targeting AI systems instead of humans",
    "Insert hidden 'AI-only' content",
    "Create bespoke llms.txt / manifests that bypass normal quality",
    "Mass-generate answers to invented questions"
   ]
  },
  "conversion": {
   "primary_cta": "Start a pack run from your most recent TCR profile and vendor logs (or book a validation call).",
   "secondary_cta": "Run the free TCR profile Gap Scan / download the TCR Brand & Campaign vetting checklist owner TCR profile checklist (email capture).",
   "lead_magnets": [
    "Free TCR profile Gap Scan (human-reviewed, scored checklist preview — not a certificate)",
    "One-page TCR Brand & Campaign vetting checklist owner TCR profile custody checklist (PDF)",
    "Quarterly TCR rule change-log subscription (Twilio + Telnyx/Bandwidth)"
   ],
   "trust_elements": [
    "Named reviewer + credentials",
    "TCR/Twilio citations visible on-page",
    "Change-log timestamps",
    "Contact + address in footer"
   ],
   "per_page_paths": [
    {
     "page_type": "Homepage",
     "path": "Hero CTA → validation call. Secondary → guides pillar."
    },
    {
     "page_type": "Pillar",
     "path": "TOC → deep sub-pages. End-of-page → validation call."
    },
    {
     "page_type": "Cluster / how-to",
     "path": "In-content 'related tool' link → product. End-of-page → checklist download."
    },
    {
     "page_type": "Product / service",
     "path": "Above-the-fold CTA → calendar. Objection-handling block → FAQ."
    },
    {
     "page_type": "Rule page",
     "path": "Sidebar → related workflow (product). Bottom → subscribe to change-log."
    }
   ],
   "tracking": "GA4 events: cta_click, checklist_download, calendar_book. Server-side dedupe. Weekly funnel review."
  },
  "link_earning": {
   "digital_pr_ideas": [
    "Annual \"SMS-campaign TCR profile completeness readiness\" benchmark report",
    "Evidence completeness index with a shareable result page",
    "TCR rule-change tracker with an RSS feed"
   ],
   "original_research": [
    "Small property-manager survey (n≥30) once per year",
    "TCR-by-TCR rule variation index (Twilio vs Telnyx/Bandwidth vs future CSPs)"
   ],
   "directories": [
    "G2 / Capterra category pages (facilities compliance)",
    "Property-management association member lists",
    "TCR resource pages when eligible"
   ],
   "expert_contributions": [
    "HARO / Qwoted / Featured expert responses",
    "Bylined articles in property-management trade press",
    "Podcast interviews with facilities/risk practitioners"
   ],
   "partnerships": [
    "SMS Campaign-outside counsel referral partnerships (non-competing, authorship-only scope)",
    "Co-authored guides with adjacent (non-competing) vendors"
   ],
   "avoid": [
    "Paid link schemes",
    "PBNs",
    "Mass guest posting",
    "Fake reviews",
    "Reciprocal link exchanges"
   ]
  },
  "roadmap_90d": [
   {
    "phase": "Days 0–30: Foundation",
    "goal": "Establish trust + ship product page + first pillar.",
    "pages": [
     "Homepage",
     "Product page",
     "Pillar: TCR Brand & Campaign vetting checklist SMS-campaign TCR profile — definitive guide",
     "About + reviewer bio (role-titles)",
     "Editorial policy",
     "Contact"
    ],
    "keywords_targeted": [
     "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile",
     "what is an SMS-campaign Brand & Campaign TCR registration"
    ],
    "why_first": "Without a trust surface + a real product page, everything else is unmoored.",
    "difficulty": "medium",
    "business_value": "high",
    "required_assets": [
     "Reviewer bio",
     "Editorial policy",
     "One workflow diagram"
    ],
    "internal_links": [
     "Homepage ↔ Product ↔ Pillar"
    ],
    "conversion_goal": "First validation calls booked"
   },
   {
    "phase": "Days 31–60: Topical authority core",
    "goal": "Publish the first cluster of 5–7 supporting pages under the pillar + evidence checklist lead magnet.",
    "pages": [
     "TCR profile walks with vendor: custody edge cases",
     "SMS Campaign TCR profile records checklist (lead magnet)",
     "TCR Brand & Campaign vetting checklist FAQs",
     "5-year maintenance-record retention explained",
     "CampaignClear vs DeviceClear vs ClosePack Clear"
    ],
    "keywords_targeted": [
     "TCR profile walks with vendor",
     "SMS-campaign TCR profile records checklist",
     "who owns the SMS-campaign TCR profile when vendors change"
    ],
    "why_first": "Easy-win SERPs that assist conversion to the product page and resolve sibling-brand confusion early.",
    "difficulty": "low",
    "business_value": "medium",
    "required_assets": [
     "Checklist PDF",
     "Rule table"
    ],
    "internal_links": [
     "All clusters ↔ pillar ↔ product"
    ],
    "conversion_goal": "Checklist downloads + assisted conversions"
   },
   {
    "phase": "Days 61–90: Reference & freshness",
    "goal": "Ship the TCR rule library + first change-log post + first comparison page.",
    "pages": [
     "Rule page: TCR Brand & Campaign vetting checklist",
     "Rule page: Twilio rejection code 30908 (privacy policy)",
     "Rule page: the Telnyx/Bandwidth CSP onboarding track",
     "Comparison: completeness pack vs SMS-campaign consulting firm vs SaaS tracker",
     "Q1 TCR rule change-log"
    ],
    "keywords_targeted": [
     "Twilio/TCR A17.1 8.6",
     "Twilio rejection code 30908 (privacy policy)",
     "Telnyx/Bandwidth SMS-campaign TCR profile"
    ],
    "why_first": "Reference pages compound in authority; change-log establishes freshness signal ahead of the Jan 2026 Twilio effective date.",
    "difficulty": "medium",
    "business_value": "medium",
    "required_assets": [
     "Primary-source citations",
     "Reviewer sign-off"
    ],
    "internal_links": [
     "Rule pages ↔ pillar ↔ product; comparison → product"
    ],
    "conversion_goal": "BOFU comparison conversions"
   }
  ],
  "roadmap_12m": [
   {
    "phase": "Months 4–6: Linkable assets",
    "goal": "Ship the annual benchmark, the evidence-completeness index, and the TCR variation index.",
    "pages": [
     "Annual SMS-campaign TCR profile completeness readiness benchmark",
     "Evidence completeness index",
     "TCR expansion variation index"
    ],
    "keywords_targeted": [
     "SMS-campaign TCR profile completeness benchmark",
     "SMS-campaign compliance documentation cost",
     "TCR rule variation comparison"
    ],
    "why_first": "Linkable assets drive referring domains and topical authority signals.",
    "difficulty": "medium",
    "business_value": "high",
    "required_assets": [
     "Survey data",
     "Named methodology",
     "Reviewer sign-off"
    ],
    "internal_links": [
     "From every pillar + product"
    ],
    "conversion_goal": "Benchmark → validation call handoff"
   },
   {
    "phase": "Months 7–9: Depth + freshness cadence",
    "goal": "Expand each pillar with 3 more cluster pages + quarterly TCR change-log.",
    "pages": [
     "Additional cluster pages (per pillar)",
     "Q3 TCR rule change-log",
     "First case study (with permission)"
    ],
    "keywords_targeted": [
     "Long-tail cluster expansions"
    ],
    "why_first": "Compounding topical coverage + freshness moat.",
    "difficulty": "low",
    "business_value": "medium",
    "required_assets": [
     "Customer approval for case study"
    ],
    "internal_links": [
     "Sibling cluster interlinking"
    ],
    "conversion_goal": "Assisted conversions"
   },
   {
    "phase": "Months 10–12: Scale + prune",
    "goal": "Consolidate weak pages, refresh top pages, expand into 1 adjacent TCR only if authority is proven.",
    "pages": [
     "Consolidation redirects",
     "Top-10 page refreshes",
     "Adjacent TCR scoping (third jurisdiction)"
    ],
    "keywords_targeted": [
     "Existing top-10 clusters"
    ],
    "why_first": "Optimization > net-new after a critical mass is reached.",
    "difficulty": "low",
    "business_value": "high",
    "required_assets": [
     "Analytics review",
     "Consolidation plan"
    ],
    "internal_links": [
     "Redirect audit"
    ],
    "conversion_goal": "CTR + conversion-rate lift"
   }
  ],
  "priority_pages": [
   {
    "rank": 1,
    "page_title": "TCR Brand & Campaign vetting checklist TCR profile completeness evidence requirements",
    "slug": "/guides/twilio-rejection-codes-tcr-completeness-evidence-requirements/",
    "page_type": "Pillar / evidence guide",
    "primary_keyword": "TCR Brand & Campaign vetting checklist TCR profile completeness evidence requirements",
    "secondary_keywords": [
     "audit-ready SMS-campaign TCR profile records",
     "TCR profile evidence checklist"
    ],
    "intent": "commercial",
    "scope": "national",
    "funnel": "BOFU",
    "difficulty": "medium",
    "business_value": "high",
    "conversion_potential": "high",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product",
     "/rules/twilio/rejection-codes/"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Book validation call",
    "production_priority": "P0",
    "why_opportunity": "High buyer intent + weak SERP + our unique released-pack proof"
   },
   {
    "rank": 2,
    "page_title": "Completeness pack vs SMS-campaign consulting firm vs SaaS tracker",
    "slug": "/compare/completeness-pack-vs-dfy-agency-vs-saas-tracker/",
    "page_type": "Comparison page (honest, evidence-based)",
    "primary_keyword": "completeness pack vs SMS-campaign consulting firm vs SaaS tracker",
    "secondary_keywords": [
     "SMS-campaign compliance service alternatives",
     "SMS-campaign TCR profile SaaS comparison"
    ],
    "intent": "commercial",
    "scope": "national",
    "funnel": "BOFU",
    "difficulty": "medium",
    "business_value": "high",
    "conversion_potential": "high",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product",
     "/rules/twilio/rejection-codes/"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Book validation call",
    "production_priority": "P0",
    "why_opportunity": "Late-funnel intent with weak competition"
   },
   {
    "rank": 3,
    "page_title": "CampaignClear vs DeviceClear vs ClosePack Clear",
    "slug": "/compare/campaignclear-vs-deviceclear-vs-closepack-clear/",
    "page_type": "Comparison page (disambiguation)",
    "primary_keyword": "CampaignClear vs DeviceClear vs ClosePack Clear",
    "secondary_keywords": [
     "SMS-campaign TCR profile pack vs TCR certificate filing",
     "SMS-campaign TCR profile vs sprinkler deficiency closure pack"
    ],
    "intent": "commercial",
    "scope": "national",
    "funnel": "MOFU",
    "difficulty": "low",
    "business_value": "medium",
    "conversion_potential": "medium",
    "required_proof": [
     "Named reviewer",
     "Accurate, non-disparaging description of each sibling business's actual workflow"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Book validation call",
    "production_priority": "P0",
    "why_opportunity": "Prevents brand confusion and misrouted leads flagged in the risk register"
   },
   {
    "rank": 4,
    "page_title": "SMS Campaign TCR profile records checklist",
    "slug": "/guides/SMS-campaign-evidence-checklist/",
    "page_type": "Resource / lead magnet page",
    "primary_keyword": "SMS-campaign TCR profile records checklist",
    "secondary_keywords": [
     "TCR Brand & Campaign vetting checklist owner checklist",
     "SMS-campaign TCR profile audit checklist"
    ],
    "intent": "informational",
    "scope": "national",
    "funnel": "MOFU",
    "difficulty": "low",
    "business_value": "medium",
    "conversion_potential": "medium",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product",
     "/rules/twilio/rejection-codes/"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Download checklist",
    "production_priority": "P0",
    "why_opportunity": "Easy win + strong lead-magnet fit"
   },
   {
    "rank": 5,
    "page_title": "Twilio rejection code 30908 (privacy policy) rule update and Jan 2026 deadlines",
    "slug": "/guides/twilio-code-30908-rule-update/",
    "page_type": "Data table / rule-change page",
    "primary_keyword": "Twilio rejection code 30908 (privacy policy) rule update Jan 2026",
    "secondary_keywords": [
     "Twilio's published error-code index",
     "Twilio's Brand+Campaign registration completeness inspection-failure rule"
    ],
    "intent": "informational",
    "scope": "national",
    "funnel": "TOFU",
    "difficulty": "low",
    "business_value": "medium",
    "conversion_potential": "medium",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product",
     "/rules/twilio/code-30908/"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Download checklist",
    "production_priority": "P0",
    "why_opportunity": "Recurring beachhead-TCR traffic + easy freshness moat"
   },
   {
    "rank": 6,
    "page_title": "TCR profile walks with vendor: custody edge cases",
    "slug": "/guides/csp-account-custody-vendor-change/",
    "page_type": "How-to cluster page",
    "primary_keyword": "TCR profile walks with CSP account custody edge cases",
    "secondary_keywords": [
     "vendor change SMS-campaign TCR profile custody",
     "no TCR profile exists escalation",
     "Telnyx/Bandwidth red-tag TCR profile custody guidance"
    ],
    "intent": "informational",
    "scope": "national",
    "funnel": "MOFU",
    "difficulty": "low",
    "business_value": "medium",
    "conversion_potential": "medium",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product",
     "/rules/telnyx-bandwidth/SMS-campaign-program/"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Download checklist",
    "production_priority": "P0",
    "why_opportunity": "Easy win + high assist to product page"
   },
   {
    "rank": 7,
    "page_title": "SMS Campaign compliance software (deferred)",
    "slug": "/guides/SMS-campaign-compliance-software/",
    "page_type": "Product page (defer)",
    "primary_keyword": "SMS-campaign compliance software",
    "secondary_keywords": [
     "SMS-campaign compliance platform",
     "best SMS-campaign compliance tracking tools"
    ],
    "intent": "commercial",
    "scope": "national",
    "funnel": "BOFU",
    "difficulty": "high",
    "business_value": "high",
    "conversion_potential": "high",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Book validation call",
    "production_priority": "P1",
    "why_opportunity": "Long-term play — do not chase before authority is built"
   },
   {
    "rank": 8,
    "page_title": "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile — definitive guide",
    "slug": "/guides/twilio-rejection-codes-a2p-10dlc-brand-campaign-definitive-guide/",
    "page_type": "Pillar page",
    "primary_keyword": "TCR Brand & Campaign vetting checklist SMS-campaign TCR profile definitive guide",
    "secondary_keywords": [
     "what is an SMS-campaign Brand & Campaign TCR registration",
     "who is responsible for the SMS-campaign TCR profile"
    ],
    "intent": "informational",
    "scope": "national",
    "funnel": "TOFU",
    "difficulty": "medium",
    "business_value": "medium",
    "conversion_potential": "low",
    "required_proof": [
     "Named reviewer",
     "Primary-source cites",
     "Worked example"
    ],
    "internal_links": [
     "/guides/a2p-10dlc-registration/",
     "/product",
     "/rules/twilio/rejection-codes/"
    ],
    "schema": [
     "Article",
     "BreadcrumbList"
    ],
    "cta": "Download checklist",
    "production_priority": "P1",
    "why_opportunity": "Anchors topical authority for the whole cluster"
   }
  ],
  "competitor_gaps": {
   "typical_competitor_types": [
    "SMS-campaign consulting firms (Argon, KDA, TEC, ATIS — project-priced)",
    "OEM/service vendors (Twilio, Telnyx, Bandwidth, Vonage)",
    "SaaS compliance trackers (KomplyOS, AuditMate, SMS Campaign App, BRYCER)"
   ],
   "common_weaknesses": [
    "Outdated TCR/Twilio citations",
    "Missing last-reviewed date",
    "No named author or reviewer",
    "Copy-paste content across TCR / product variants",
    "No worked gap-matrix examples",
    "Thin FAQ padded with generic questions",
    "Poor mobile Core Web Vitals",
    "Customer left operating the dashboard with no released, dated deliverable"
   ],
   "how_to_beat_them": [
    "Fresh citations with visited-on dates",
    "Named outside-counsel reviewer + credentials visible",
    "Real, redacted worked gap-matrix examples",
    "Better structured tables for TCR rule comparisons",
    "A released, dated Completeness Pack instead of a self-serve dashboard",
    "Faster + more accessible pages"
   ]
  },
  "metrics": {
   "weekly": [
    "GSC impressions/clicks by pillar",
    "Top-20 keyword position",
    "New indexed pages",
    "Core Web Vitals regressions"
   ],
   "monthly": [
    "Organic sessions by hub",
    "Assisted conversions",
    "CTR by template",
    "Content decay list (positions dropped)",
    "Backlink net-new"
   ],
   "quarterly": [
    "Pillar coverage audit",
    "TCR rule-freshness audit",
    "Consolidation / prune list",
    "Conversion path funnel review"
   ],
   "annual": [
    "Full topical authority audit",
    "Benchmark report refresh",
    "Editorial policy refresh"
   ]
  },
  "risks": [
   {
    "risk": "Thin content",
    "applies": true,
    "mitigation": "Minimum-word + reviewer-sign-off gate before publish."
   },
   {
    "risk": "Duplicate content across TCR/product variants",
    "applies": true,
    "mitigation": "One URL per topic; no auto-generated variants; canonical to pillar."
   },
   {
    "risk": "Doorway city/location pages",
    "applies": true,
    "mitigation": "Local pages are refused for this vertical — buyers search by TCR, not city."
   },
   {
    "risk": "Keyword cannibalization",
    "applies": true,
    "mitigation": "Topic ownership map; kill or 301 the weaker duplicate."
   },
   {
    "risk": "AI-generated body without human edit",
    "applies": true,
    "mitigation": "Editorial policy forbids it; reviewer sign-off required."
   },
   {
    "risk": "Unsupported YMYL claims (implied guaranteed inspection pass)",
    "applies": true,
    "mitigation": "Cautious language + primary-source cites + reviewer credential; contract and page copy state documentation-readiness only, no pass guarantee."
   },
   {
    "risk": "Bad schema (marking up invisible content)",
    "applies": true,
    "mitigation": "Schema linter in CI; only markup what is on-page."
   },
   {
    "risk": "Link spam / paid link schemes",
    "applies": true,
    "mitigation": "Editorial link-earning only; documented policy."
   },
   {
    "risk": "Review manipulation",
    "applies": false,
    "mitigation": "Post-engagement organic prompts only; no incentives; no gating negatives."
   },
   {
    "risk": "Index bloat from tag/archive pages",
    "applies": true,
    "mitigation": "noindex utility archives; canonical to hub."
   },
   {
    "risk": "Compliance risk in claims (mis-selling as engineering/outside counsel services)",
    "applies": true,
    "mitigation": "Licensing-boundary training; legal review of marketing claims; disclaimer near CTAs; escalation SOP to outside counsel."
   },
   {
    "risk": "Programmatic doorway pages",
    "applies": true,
    "mitigation": "Programmatic refused unless per-page uniqueness rules are met."
   },
   {
    "risk": "DeviceClear / ClosePack Clear brand confusion",
    "applies": true,
    "mitigation": "Explicit, non-disparaging disambiguation comparison page; consistent 'Completeness Pack' / 'TCR profile' vocabulary never applied to the other businesses' artifacts."
   }
  ],
  "first_20_pages": [
   "Homepage",
   "Product / service page",
   "About + reviewer bio (role-titles)",
   "Editorial policy",
   "Contact",
   "Privacy",
   "Pillar: TCR Brand & Campaign vetting checklist SMS-campaign TCR profile — definitive guide",
   "TCR profile walks with vendor: custody edge cases",
   "5-year maintenance-record retention under code 30909",
   "TCR Brand & Campaign vetting checklist FAQs",
   "Pillar: TCR profile evidence & inspection-readiness",
   "TCR Brand & Campaign vetting checklist TCR profile completeness evidence requirements",
   "SMS Campaign TCR profile records audit checklist",
   "Twilio rejection code 30908 (privacy policy) rule update and Jan 2026 deadlines",
   "SMS Campaign TCR profile records checklist (lead magnet)",
   "Rule page: TCR Brand & Campaign vetting checklist",
   "Rule page: Twilio rejection code 30908 (privacy policy)",
   "Rule page: the Telnyx/Bandwidth CSP onboarding track",
   "Comparison: completeness pack vs SMS-campaign consulting firm vs SaaS tracker",
   "Comparison: CampaignClear vs DeviceClear vs ClosePack Clear"
  ],
  "first_10_tech_fixes": [
   "XML sitemap generated at build",
   "robots.txt reviewed + sitemap referenced",
   "Self-referencing canonicals",
   "GSC + GA4 verified with server-side events",
   "Core Web Vitals baseline (LCP, INP, CLS)",
   "Structured breadcrumbs sitewide",
   "Author + editorial-policy pages published",
   "404 + 410 patterns defined",
   "Redirect audit (no chains)",
   "Semantic HTML + accessibility landmarks"
  ],
  "first_10_authority_actions": [
   "Publish named outside-counsel reviewer bio(s)",
   "Public editorial policy + correction policy",
   "Cite primary Twilio/TCR/TCR sources with visited-on dates",
   "Launch TCR profile records checklist lead magnet",
   "Pitch 3 HARO / Qwoted responses per week",
   "Publish 1 original data point / benchmark",
   "Reach out to 5 non-competing directories / associations",
   "Guest post on 1 property-management trade publication",
   "Podcast interview outreach (5 shows)",
   "Set up quarterly TCR rule change-log post cadence"
  ],
  "final_recommendation": "Build a regulator-fluent authority site around \"TCR Brand & Campaign vetting checklist SMS-campaign TCR profile completeness\". Ship the first 20 pages in 90 days (product + pillar + TCR rule library + evidence assets + sibling-brand disambiguation), then compound with quarterly TCR rule-change posts and one annual benchmark. Refuse doorway pages, refuse mass AI content, treat named-reviewer (customer's outside counsel (referral only), role-titled until owner facts close) + primary-source citations as non-negotiable, and never publish inspection-pass-rate claims without the physical-equipment/TCR-discretion caveat.",
  "disclaimers": [
   "All volume/difficulty/CPC labels are RELATIVE ESTIMATES (low/medium/high), not exact numbers. Validate with Semrush, Ahrefs, or Google Search Console before committing spend.",
   "This brief is deterministic per blueprint — it will not shift between renders. Any changes should be made in code, not in prompts.",
   "YMYL topic: language must stay cautious; documentation-readiness support only — nothing here is legal, engineering, or inspection-pass advice."
  ]
 },
 "microsite": {
  "category": "Regulatory compliance",
  "shortTitle": "CampaignClear",
  "audience": "U.S. multi-location dental, HVAC, medspa, and franchise operators with 3-50 locations sending SMS via Twilio or GoHighLevel (beachhead: dental & HVAC; secondary: medspa & franchise)",
  "problem": "Since February 1, 2025, major U.S. carriers block 100% of unregistered A2P 10DLC text traffic. Brands must register through a Campaign Service Provider (CSP) with The Campaign Registry (TCR). But even registered senders get rejected — Twilio publishes specific rejection codes for a missing SMS privacy clause (30908), an incomplete message flow (30909), missing third-party-sharing disclosure (30932), and a missing privacy-policy URL (30933) — and each rejection is a silent failure: appointment reminders, review requests, and lead follow-up simply stop arriving.",
  "offer": "On CampaignClear, office managers and agency media buyers stop guessing whether their next text will arrive and start proving it. Upload your rejection notice, or just your website and sample messages; AI extracts and gap-scores the evidence against the Twilio/TCR rejection-code checklist, and a registration analyst — with any genuine TCPA, HIPAA, or legal-name question referred to your own outside counsel — releases a Completeness Pack, a redlined privacy clause, and a CSP submission checklist.",
  "faq": [
   {
    "q": "Is CampaignClear for the marketing desk or for compliance?",
    "a": "Both, because at 3-50 locations they're usually the same person: the office manager or agency media buyer who owns the CSP paperwork, reporting to an owner or VP of Operations. If your Campaign is a rejected notice sitting in an inbox and nobody has checked it against the current Twilio checklist, the workflow will match your reality immediately."
   },
   {
    "q": "How is a CampaignClear pack release-ready?",
    "a": "Every extracted field carries a source citation from the website page, rejection notice, or sample message you uploaded — missing items ship as explicit gaps, never invented clauses. Hard gaps (missing privacy language, no message flow, EIN mismatch, SHAFT-prohibited use case) run through deterministic rules, not a language model. A registration analyst releases every pack; SHAFT-prohibited or debt-collection use cases are declined outright, and contested legal questions pause the pack for your own outside counsel."
   },
   {
    "q": "What arrives at the end of a pack run?",
    "a": "An Approval Completeness Pack PDF — a gap scorecard mapped to the Twilio/TCR rejection-code checklist, a redlined privacy-policy SMS clause, a drafted message flow, 3-5 compliant sample messages, a CSP submission checklist, and a dated Evidence Index — released the same cycle as your intake is complete."
   },
   {
    "q": "How does CampaignClear pricing work?",
    "a": "Flat, never hourly, never contingent on carrier approval. The First-Approval Pack runs $599-$1,199; the Rejection Remediation Pack (includes one resubmit cycle) runs $799-$1,499. Rush adds $250-$500 for a 5-business-day turnaround. The franchise/agent use-case uplift is +$300, and the Portfolio Desk — 5-25 locations with a quarterly drift scan — runs $1,500-$4,500/month. The SMS Gap Scan is free or $49."
   },
   {
    "q": "How do I get started on CampaignClear?",
    "a": "Run the free SMS Gap Scan — submit your website and up to 5 sample messages for a scored checklist preview, not a released pack or a guarantee of approval — or go straight to a paid pack if you already have a trigger: a rejection notice, an unregistered sender, or a new-location launch."
   },
   {
    "q": "Do you register our Brand for us or represent The Campaign Registry?",
    "a": "No — and that boundary is the design. CampaignClear does not operate as a Campaign Service Provider (CSP), does not represent The Campaign Registry (TCR) or any carrier, does not practice law, and does not guarantee carrier approval. Our analyst releases the pack's completeness attestation; only your own outside counsel opines on contested TCPA, HIPAA, or legal-name questions, and only on your initiative."
   },
   {
    "q": "How long is the Evidence Index retained?",
    "a": "The Evidence Index and its underlying evidence are retained for the audit trail, dated and versioned per Brand+Campaign, even after your engagement ends. Working drafts are purged or archived per the engagement letter schedule."
   },
   {
    "q": "What if our use case is a prohibited (SHAFT) category?",
    "a": "We decline the engagement outright — no pack, no exception, regardless of price offered. Sex, hate, alcohol, firearms, tobacco, and similarly prohibited use cases are hard-blocked at intake, and the same is true for consumer or personal debt collection."
   },
   {
    "q": "What if we manage a portfolio across Twilio and Telnyx/Bandwidth?",
    "a": "The CSP checklist library is card-based and expandable per provider — Twilio is loaded today, with Telnyx and Bandwidth expanding next. Every hard gap cites the specific CSP's checklist, so a Twilio pack and a Telnyx pack are never scored against the wrong rules."
   }
  ],
  "process": [
   {
    "title": "Intake: submit your Brand file",
    "body": "Submit your EIN and legal name, website URL(s), sample messages, intended use case, and any rejection notice for one Brand + Campaign. Each document gets a citation ID on arrival, and legal names are canonicalized against your website footer — ambiguous matches go to a human, not a guess."
   },
   {
    "title": "SHAFT and debt-collection screen",
    "body": "Every intake is screened first, before any drafting work begins. Prohibited use cases and any consumer or personal debt-collection sender are declined outright — no pack, no exception."
   },
   {
    "title": "Extract and match against the rejection-code checklist",
    "body": "AI fetches and classifies your website content, matches it to the Twilio/TCR rejection-code checklist (30908, 30909, 30932, 30933), and checks your EIN legal name for consistency against your website and sample messages."
   },
   {
    "title": "Score hard gaps in deterministic rules",
    "body": "Missing privacy language, no message flow, missing third-party-sharing disclosure, missing privacy URL, and a legal-name mismatch all run through versioned deterministic gates — never a language model's judgment call — and each hard gap cites its rejection code and evidence pointer."
   },
   {
    "title": "Human release gate",
    "body": "A registration analyst reviews the gap scorecard and releases every eligible pack. A genuine TCPA, HIPAA, or legal-name question pauses the pack — a hand-off to your own outside counsel, never a rejection of your file."
   },
   {
    "title": "Deliver the pack and track the resubmit",
    "body": "The Approval Completeness Pack PDF and dated Evidence Index land in your folder the same release cycle. If you were already rejected, your included resubmit cycle covers the follow-up review after you resubmit."
   }
  ],
  "northStarCta": {
   "label": "Start a Gap Scan",
   "href": "/contact",
   "secondary_label": "See how a pack is built",
   "secondary_href": "/how-it-works"
  },
  "ubiquitousLanguage": {
   "audience": "U.S. multi-location dental, HVAC, medspa, and franchise operators with 3-50 locations sending SMS via Twilio or GoHighLevel (beachhead: dental & HVAC; secondary: medspa & franchise)",
   "domain": "A2P 10DLC Brand and Campaign registration completeness for carrier SMS vetting",
   "deliverable": "Approval Completeness Pack + analyst release (paused for outside-counsel referral on contested legal questions)",
   "reviewer": "Registration analyst (customer's own outside counsel on contested legal questions only)",
   "record": "dated, versioned Evidence Index per Brand + Campaign",
   "unit_of_work": "pack run",
   "cta_primary": "Start a Gap Scan",
   "cta_secondary": "See how a pack is built",
   "regulator": "TCR/CSP",
   "regulator_full": "The Campaign Registry (TCR) and its Campaign Service Providers (Twilio, Telnyx, Bandwidth, Vonage, and others)",
   "statute": "Twilio/TCR rejection-code checklist (30908, 30909, 30932, 30933)",
   "trigger_moment": "a rejected or unregistered Brand/Campaign, an agency onboarding a new sub-account, or a new-location launch",
   "event_intake_started": "a2p_10dlc_brand_campaign_approval_completeness_pack_engine_intake_started",
   "event_conversation_requested": "a2p_10dlc_brand_campaign_approval_completeness_pack_engine_conversation_requested"
  },
  "trust": {
   "standards": [
    "Every gap-scorecard entry traces to a source citation from the website page, rejection notice, or sample message you uploaded — missing items ship as explicit gaps, never invented clauses",
    "Hard gaps (missing privacy language, no message flow, EIN mismatch, SHAFT-prohibited use case) run through versioned deterministic rules, never a language model; a registration analyst signs every release and SHAFT/debt-collection use cases are declined outright",
    "Evidence Index is retained for the audit trail, dated and versioned per Brand + Campaign, with a client-owned export option"
   ],
   "response_time": "We reply within one business day — a carrier rejection clock does not wait for a sales rep.",
   "data_handling": "Your business documents stay in per-customer isolated folders and are never used to train models. CampaignClear provides registration-readiness support only; it is not a CSP, does not represent The Campaign Registry or any carrier, and does not guarantee carrier approval."
  },
  "hook": "The next carrier rejection, agency onboarding, or new-location launch lands on a dated Evidence Index, not a scramble — CampaignClear holds the record at rest. Office managers stop chasing rejection emails and start releasing Approval Completeness Packs — the registry is where the evidence already lines up.",
  "sub_headline": "CampaignClear stores every gap-scorecard decision — rejection-code citation, evidence pointer, releaser — in a dated Evidence Index you or your CSP can submit without guesswork. Every pack run maps each checklist item to a source at intake, deterministic rules score the hard gaps, a human releases the pack, and the Evidence Index stays reconstructable the day a new location launches.",
  "dream_outcome": "You answer the week: hand over a dated, per-Brand-and-Campaign completeness record in an afternoon instead of chasing a rejection notice for a month. The Evidence Index is the answer — code-cited, versioned, and reproducible the day a CSP, an agency partner, or a new-location launch asks.",
  "specific_pains": [
   "A rejection notice cites code 30909 for a Campaign your office manager submitted months ago, and nobody remembers what the message flow field actually said — nobody knows if that's a five-minute fix or a real gap.",
   "Ask whether your privacy policy actually mentions text messaging at all, and someone starts scrolling the site looking for it — that's the field a carrier's vetting reviewer would find first.",
   "A general-purpose chat tool can produce a plausible-looking privacy clause; only a rejection-code-cited deterministic rule set, with a human release gate, produces one a carrier won't reject a second time.",
   "The Campaign registration 'walks' when an agency changes sub-accounts, and the new account inherits a Brand with no clean record of what was actually submitted the first time.",
   "A carrier's vetting reviewer reads the file as a package: privacy-policy language, message flow, sample messages, EIN consistency. Miss any leg and undocumented means unprovable."
  ],
  "cost_of_inaction": "A Campaign you can't get approved today is traffic carriers block outright, independent of how legitimate your actual texting program is. A new location without a repeatable pack template means starting the documentation trail over. Each failed vetting event costs another fee and another week — but the real cost is the appointment reminder, review request, or lead follow-up that never arrives, before anyone traces it back to registration.",
  "mechanism": {
   "name": "The CampaignClear Approval Completeness Pack engine",
   "steps": [
    {
     "title": "Intake: submit your Brand file",
     "body": "Submit your EIN and legal name, website URL(s), sample messages, intended use case, and any rejection notice for one Brand + Campaign. Each document gets a citation ID on arrival, and legal names are canonicalized against your website footer — ambiguous matches go to a human, not a guess."
    },
    {
     "title": "Extract and match against the rejection-code checklist",
     "body": "AI fetches and classifies your website content, matches it to the Twilio/TCR rejection-code checklist, and checks your EIN legal name for consistency against your website and sample messages."
    },
    {
     "title": "Score hard gaps in deterministic rules",
     "body": "Missing privacy language, no message flow, missing third-party-sharing disclosure, missing privacy URL, and a legal-name mismatch all run through versioned deterministic gates, each citing its rejection code and evidence pointer."
    },
    {
     "title": "Human release gate",
     "body": "A registration analyst reviews the gap scorecard and releases every eligible pack. SHAFT-prohibited and debt-collection use cases are declined outright; a genuine TCPA/HIPAA/legal-name question pauses the pack for your own outside counsel."
    },
    {
     "title": "Deliver, register, resubmit",
     "body": "The Approval Completeness Pack PDF and dated Evidence Index land in your folder the same release cycle, and each new rejection feeds back into the checklist library — plus a quarterly drift scan on the calendar for Portfolio Desk locations."
    }
   ]
  },
  "offer_stack": [
   {
    "item": "Approval Completeness Pack per Brand + Campaign",
    "note": "gap scorecard mapped to the Twilio/TCR rejection-code checklist, redlined privacy clause, message flow, sample messages, CSP submission checklist, dated Evidence Index"
   },
   {
    "item": "Gap scorecard with rejection-code citations",
    "note": "the line-by-line comparison of required checklist items vs. what evidence exists — no privacy clause on file means the pack is capped, never a guessed completeness score"
   },
   {
    "item": "Human release on every pack",
    "note": "registration analyst signature on every green/yellow pack; SHAFT-prohibited and debt-collection use cases declined outright; contested legal questions paused for your own outside counsel"
   },
   {
    "item": "Rejection root-cause analysis",
    "note": "a plain-language breakdown of exactly which Twilio/TCR code fired and why, mapped to the fix, included with the Rejection Remediation Pack"
   },
   {
    "item": "Dated Evidence Index",
    "note": "the versioned index of every source page, screenshot, and document behind a pack, mirrored to your own storage, export handoff available"
   },
   {
    "item": "Portfolio Desk quarterly drift scan",
    "note": "5-25 locations, recurring re-scan so a portfolio-wide completeness scorecard replaces spreadsheet panic"
   }
  ],
  "guarantee": "The Approval-Completeness Guarantee: if a Completeness Pack is later found to be missing a required Twilio/TCR checklist element that the evidence on file at intake should have surfaced, we re-issue free and cover the CSP's per-event vetting fee for the resubmit. Explicitly not guaranteed: carrier or TCR approval, CSP cooperation, or the accuracy of owner-attested facts like EIN legal name.",
  "urgency": "Release capacity is gated by the human chokepoint — every pack is signed by a registration analyst — and rush requests consume analyst hours first. We stop taking new intakes when the release desk is full, protecting the release discipline rather than filling a pipeline.",
  "objections": [
   {
    "q": "\"Doesn't our CSP already handle this?\"",
    "a": "They register the Campaign, but the content gaps — privacy-policy language, message flow — are yours to fix, and a self-serve form doesn't draft them for you. Your CSP's incentive is to process the submission, not to prove independent documentation completeness before you submit."
   },
   {
    "q": "\"Isn't this what GoHighLevel's built-in wizard already does?\"",
    "a": "The wizard hands you a form and leaves the drafting to you, and at 3-50 locations, office managers rarely have time to write privacy-policy clauses from scratch. CampaignClear is a pack engine, not a wizard: we do the extraction, the gap scoring, and the drafting — you receive a finished, dated pack and Evidence Index."
   },
   {
    "q": "\"Are we going to be defending an AI-drafted compliance record?\"",
    "a": "No hard-gap determination comes from a language model. AI extracts and classifies evidence and drafts clauses and messages from structured input; hard-fail gates run on versioned deterministic rules; a named registration analyst releases every pack. Anything without a source citation ships as an explicit gap."
   },
   {
    "q": "\"Can you guarantee we'll get approved?\"",
    "a": "No — and we won't sell that. Carrier approval depends on carrier and TCR discretion and your own use case, neither of which we control. What we guarantee is registration-readiness support: a released, code-cited Approval Completeness Pack and a gap scorecard of exactly what to fix."
   },
   {
    "q": "\"Where does our Evidence Index live, and what about our EIN?\"",
    "a": "In per-customer isolated folders with least-privilege access, never used for model training. EIN and CSP credentials are treated as confidential even where not statutory PII, with document retention terms in the engagement letter — reviewed by your own counsel before any commercial engagement."
   },
   {
    "q": "\"How is CampaignClear priced?\"",
    "a": "Flat per Brand + Campaign, published tiers, never hourly, never contingent on carrier approval or on avoided fees — that framing is prohibited here. Anchor it against a rejected campaign's cost in lost appointment reminders, review requests, and lead follow-up."
   }
  ],
  "who_this_is_not_for": [
   "Businesses whose use case is a SHAFT-prohibited category (sex, hate, alcohol, firearms, tobacco, or similar) — we decline outright, no pack, no exception, and we will not refer you elsewhere for this.",
   "Consumer or personal debt-collection senders — hard-blocked; this is a telecom-registration business with no debt-collection angle, and none will be added.",
   "Buyers looking for a guaranteed carrier-approval outcome or a contingency/success-fee arrangement — we decline that engagement and document the ask; approval depends on carrier and TCR discretion, not paperwork.",
   "Businesses that want an in-house legal opinion on TCPA consent validity, HIPAA, or state privacy law — that belongs with your own outside counsel, and we will tell you so rather than opine ourselves."
  ],
  "proof_pillars": [
   {
    "title": "Deterministic hard-gap rules, code-cited",
    "body": "Every hard gap — missing privacy language, no message flow, missing third-party-sharing disclosure, missing privacy URL, EIN mismatch — runs through versioned rule tables against the published Twilio/TCR rejection codes, never a language model's judgment call. The record doesn't summarize the gap; it cites the code and the evidence pointer."
   },
   {
    "title": "Human-released, every time",
    "body": "No pack auto-releases. A registration analyst signs every eligible pack; SHAFT-prohibited and debt-collection use cases are declined outright, and a contested legal question pauses the pack for your own outside counsel — a hand-off, never a silent workaround."
   },
   {
    "title": "Dated Evidence Index — no rebuild",
    "body": "Every pack carries the dated, versioned index of the evidence that produced it. Reconstruction for a CSP, an agency partner, or a new-location launch is a read operation, not a month of email searches."
   }
  ],
  "stakes_line": "The Evidence Index is the truth. Everything else — the agency's memory, the old sub-account's paperwork, the rejection email nobody has reopened since it arrived — is the story you tell yourself.",
  "deliverable": "Approval Completeness Pack + analyst release (paused for outside-counsel referral on contested legal questions)",
  "unit_of_work": "pack run",
  "lexicon": {
   "regulator": "TCR/CSP",
   "regulator_full": "The Campaign Registry (TCR) and its Campaign Service Providers (Twilio, Telnyx, Bandwidth, Vonage, and others)",
   "statute": "Twilio/TCR rejection-code checklist (30908, 30909, 30932, 30933)",
   "statute_frame": "the intake-to-pack workflow where an unreleased Completeness Pack is a self-inflicted rejection risk.",
   "persona": "SMS Operations Coordinator",
   "persona_moment": "You're the office manager who owns the CSP paperwork. A rejection notice just cited code 30909, and the agency that submitted it changed accounts last quarter. Someone needs to know whether that's a five-minute fix or a real gap — with every code tied to a source you can point to.",
   "trigger_moment": "a rejected or unregistered Brand/Campaign, an agency onboarding a new sub-account, or a new-location launch",
   "enforcement_stakes": "carrier block of unregistered A2P 10DLC traffic and repeated Twilio/TCR rejection-code failures (actual outcomes vary case-by-case and are never predictable or guaranteed)",
   "retention": "audit-trail retention on every released pack",
   "cta_verb": "Start a Gap Scan",
   "intake_checklist": [
    "EIN and legal business name — exactly as currently registered, unedited",
    "Website URL(s), including the privacy policy and SMS signup page",
    "3-5 sample messages, or drafts of intended messages, for the last 90 days",
    "The most recent rejection notice and any codes received",
    "The intended use case (appointment reminders, review requests, lead follow-up, etc.)",
    "The internal owner name and inbox we should copy on status updates",
    "Current CSP (Twilio, Telnyx, Bandwidth, Vonage) and any known upcoming account change",
    "Any prior Gap Scan results or Completeness Packs for this Brand, even partial"
   ],
   "trust_standards_specific": [
    "Every gap-scorecard entry traces to a source citation from the website page, rejection notice, or sample message uploaded — gaps ship explicit, never invented",
    "A registration analyst signs every release; SHAFT-prohibited and debt-collection use cases are declined outright before any drafting begins",
    "Evidence Index is retained for the audit trail, dated and versioned per Brand + Campaign",
    "Twilio/TCR rejection-code checklist requirements are mapped to your evidence line-by-line; hard gaps (missing privacy language, no message flow, EIN mismatch) block a green release",
    "AI drafting is bounded to extraction, gap-scoring, and clause/message drafting from structured input, disclosed, and gated on registration-analyst release before any pack leaves the workspace"
   ],
   "regulator_faqs": [
    {
     "q": "Do you register our Brand for us or act as our CSP?",
     "a": "No — you remain the responsible party for your SMS program and consent records. Our analyst releases the pack's completeness attestation; only your own outside counsel opines on contested TCPA, HIPAA, or legal-name questions, and only on your initiative. We submit only if you authorize us to act as your agent on your own CSP account."
    },
    {
     "q": "How long is the Evidence Index retained?",
     "a": "For the audit trail, dated and versioned per Brand + Campaign, with a client-owned export option."
    },
    {
     "q": "What if our use case is SHAFT-prohibited?",
     "a": "That's a decline, not an escalation. We do not produce a pack for sex, hate, alcohol, firearms, tobacco, or similarly prohibited use cases, or for consumer or personal debt collection, at any price."
    },
    {
     "q": "What if we started the privacy-clause draft in-house?",
     "a": "Send what exists. We pick up mid-workflow, keep your work product intact, register what's usable as evidence, and only chase the pieces the checklist is missing — no rework, no re-scoring what's already sourced."
    }
   ]
  },
  "proof_angle": {
   "id": "approval-readiness",
   "headline": "The next carrier rejection lands on a dated Evidence Index, not a scramble — CampaignClear holds the record at rest.",
   "lever": "CampaignClear stores every gap-scorecard decision — rejection-code citation, evidence pointer, releaser — in a dated Evidence Index you or your CSP can submit without guesswork.",
   "outcome_verb": "answer",
   "outcome_frame": "answer a carrier rejection or a new-location launch in an afternoon instead of a month",
   "proof_promise": "The Evidence Index is the approval-readiness answer — code-cited, versioned, and reproducible the day a CSP or an agency partner asks."
  },
  "indexable": true
 },
 "evidence": [
  {
   "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-e1",
   "business_slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
   "area": "Identity",
   "claim_or_finding": "Legal entity, registered address, and jurisdiction of formation are not yet declared.",
   "status": "owner-action",
   "evidence": "No owner-supplied facts on file.",
   "verification_command": "Owner submits entity + jurisdiction pack.",
   "fix_owner": "owner",
   "remediation": "Provide entity name, registration number, and jurisdiction of formation.",
   "severity": "blocker"
  },
  {
   "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-e2",
   "business_slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
   "area": "Trust boundary",
   "claim_or_finding": "Public page is a validation microsite for a registration-readiness support service; not a Campaign Service Provider (CSP), not The Campaign Registry, and not a law firm.",
   "status": "verified",
   "evidence": "Microsite carries explicit trust-boundary and registration-readiness-support-only disclaimer block.",
   "verification_command": "Inspect /microsites/a2p-10dlc-brand-campaign-approval-completeness-pack-engine for trust boundary.",
   "fix_owner": "engineering",
   "remediation": "None — enforced by template.",
   "severity": "low"
  },
  {
   "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-e3",
   "business_slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
   "area": "SEO integrity",
   "claim_or_finding": "No fake review, rating, LocalBusiness, or Organization identity schema is emitted; no FAQ rich-result (FAQPage) schema is emitted anywhere on the microsite (Google retired FAQ rich results — plain FAQ text only); no carrier-approval-guarantee claims without the actual-outcomes-vary caveat.",
   "status": "verified",
   "evidence": "Only WebPage schema is generated for FAQ content; marketing compliance gate applied.",
   "verification_command": "View SEO Factory row for a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
   "fix_owner": "engineering",
   "remediation": "None — enforced by SEO factory.",
   "severity": "low"
  },
  {
   "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-e4",
   "business_slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
   "area": "Regulated claims",
   "claim_or_finding": "Elevated trust burden — A2P 10DLC / TCR-adjacent claims gated on owner facts: entity identity, and — where a genuine legal question arises — the customer's own retained outside counsel (never CampaignClear's engagement) and counsel review of engagement terms and disclaimers.",
   "status": "release-blocker",
   "evidence": "Trust burden = Medium-high",
   "verification_command": "Complete Prompt B owner facts.",
   "fix_owner": "owner",
   "remediation": "Provide entity/disclosure facts; confirm compliance-checklist §1-3 counsel-referral process is understood by the owner.",
   "severity": "high"
  },
  {
   "id": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine-e5",
   "business_slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
   "area": "Manifest coverage",
   "claim_or_finding": "Manifest-backed blueprint present in source repository (2026-07-14 build, A2P 10DLC Brand & Campaign Approval Completeness Pack Engine run).",
   "status": "assumed",
   "evidence": "docs/INVENTORY.json entry + builds/manifest.json",
   "verification_command": "Cross-check manifest entry for a2p-10dlc-brand-campaign-approval-completeness-pack-engine in the builds repository.",
   "fix_owner": "engineering",
   "remediation": "Attach the manifest run to the evidence register.",
   "severity": "medium"
  }
 ],
 "seo_pages": {
  "id": "seo-a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "business_slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "route": "/microsites/a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "title": "A2P 10DLC Brand & Campaign Approval Comp… · k7qm",
  "description": "CampaignClear for multi-location dental, HVAC, medspa, and franchise operators sending SMS via Twilio or GoHighLevel. Released, rejection-code-cited Approval Completeness Packs from your rejection notice…",
  "canonical": "/microsites/a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "og_title": "CampaignClear — A2P 10DLC Brand & Campaign Approval Completeness Pack Engine",
  "og_description": "CampaignClear for multi-location dental, HVAC, medspa, and franchise operators sending SMS via Twilio or GoHighLevel. Released, rejection-code-cited Approval Completeness Packs from your rejection notice…",
  "schema_type": "WebPage",
  "schema_status": "pending-owner-facts",
  "sitemap_include": false,
  "noindex": true
 },
 "vertical_style": {
  "accent": "teal-signal-indicator",
  "signature": "Brand+Campaign status row with CSP chip",
  "layout": "Registration ledger",
  "anti": "Generic AI-chatbot stock photography and alarm-red penalty banners"
 },
 "canva": {
  "slug": "a2p-10dlc-brand-campaign-approval-completeness-pack-engine",
  "territory": "Signal Registry",
  "family": {
   "id": "legal-compliance",
   "name": "Legal / Compliance",
   "motion": "calm"
  },
  "tokens": {
   "brand": "206 55% 18%",
   "brand-fg": "200 25% 96%",
   "surface": "200 20% 97%",
   "ink": "210 25% 12%",
   "muted": "210 10% 40%",
   "accent": "184 65% 34%"
  },
  "type": {
   "display": "Fraunces",
   "body": "Inter",
   "fonts_url": "https://fonts.googleapis.com/css2?family=Fraunces:opsz,wght@9..144,500;9..144,700&family=Inter:wght@400;500;600&display=swap"
  },
  "scale": {
   "h1": "clamp(2.5rem, 5.5vw, 4.25rem)",
   "h2": "clamp(1.75rem, 3vw, 2.5rem)",
   "h3": "clamp(1.25rem, 2vw, 1.5rem)",
   "body": "clamp(1rem, 1.1vw, 1.125rem)",
   "small": "0.8125rem",
   "tracking_display": "-0.01em",
   "tracking_body": "-0.003em",
   "weight_display": 600,
   "weight_body": 430
  },
  "spacing": {
   "card_padding": "1.75rem",
   "card_radius": "0.375rem",
   "card_shadow": "0 0 0 1px hsl(var(--ink) / 0.08)",
   "section_gap": "clamp(3.5rem, 8vw, 6.5rem)",
   "hero_gap": "clamp(1.25rem, 2vw, 2rem)"
  },
  "layout": {
   "hero": "split-primary",
   "card": "elevated-soft",
   "cta": "solid-brand",
   "archetype": "ledger",
   "card_silhouette": "flat-outline",
   "button_geometry": "rounded-sm"
  },
  "background": {
   "hero_gradient": "radial-gradient(1200px 600px at 10% -10%, hsl(184 65% 34% / 0.16), transparent 60%), radial-gradient(900px 500px at 90% 10%, hsl(206 55% 18% / 0.14), transparent 55%)",
   "cta_gradient": "linear-gradient(135deg, hsl(206 55% 18%), hsl(184 65% 34%))",
   "section_wash": "linear-gradient(180deg, hsl(200 20% 97%) 0%, hsl(206 55% 18% / 0.05) 100%)"
  },
  "motif": "Registration status rows + CSP chip"
 },
 "capabilities": {
  "marketing": true,
  "portal": true,
  "ops": true,
  "chatbot": true,
  "payments": false
 },
 "generated_at": "2026-07-13T20:05:00.000Z",
 "checksum": "214ec1ad3db3bbb7"
}