Skip to content

Latest commit

 

History

History
871 lines (761 loc) · 46.7 KB

File metadata and controls

871 lines (761 loc) · 46.7 KB

TODO.md — Current Work Queue

Current Phase

Post-W34 runtime-smoke follow-up has been merged to master through PR #12, the UI sweep proof has been merged through PR #14, the Wave 29 subreddit-isolation runtime reconciliation has been merged through PR #16, the full-access visibility gate has been merged through PR #24, and the manual runtime event recorder has been merged through PR #25. The latest Devvit playtest observed while continuing runtime proof work is v0.0.2.8. The current master dependency-hardening build passed npm run deploy, uploaded Devvit app version 0.0.2, and then reached authenticated Devvit WebView playtest readiness as v0.0.2.2 after the latest UI merge; the dev watcher later reached v0.0.2.4 after documentation/proof updates, and Wave 23 read-only source proof later continued on v0.0.2.6 and v0.0.2.8. Submission/listing docs now reflect this proof level, and the local package metadata has the upload-safe description Find enforcement drift before your users do. App details page terms/privacy links still need to be reviewed, hosted, and set outside the local CLI flow before any public publish request. Draft copy exists in docs/PRIVACY_POLICY_DRAFT.md and docs/TERMS_DRAFT.md.

The operational overhaul remains build-only/type-verified for several runtime paths unless a wave report explicitly says playtest was run. Post/comment Apply Policy menu target capture, log-only receipt persistence, receipt-backed content snapshots, receipt-backed Case Packet generation, Evidence Board create/list/status persistence, portable config export/import, privacy retention inventory/dry-run controls, Incident Mode receipt tagging/reporting, response template preview receipt persistence, community health aggregate review, policy impact summaries, policy ratification propose/review/blocking, attribution correction persistence, stored-scan replay, and manual/skipped Case Packet delivery receipt persistence are now runtime-verified on desktop Reddit playtest. Wave 29 context-derived subreddit isolation is now runtime-verified on Devvit playtest v0.0.1.122. A follow-up W17 attempt on Devvit playtest v0.0.1.123 reached the same-subreddit Operational Queue refresh path but still returned the labeled type-supported/no-items fallback, so live modqueue item reads remain open. Live Reddit moderation execution, actual retention deletion against real operational records, Mod Discussion delivery, scheduler, native Mod Notes, live modqueue reads, external AI, non-mod runtime account proof, reviewed adoption with multiple distinct moderators, and native Reddit mobile app behavior remain unverified or disabled. Server-side protected API moderator access checks are now locally verified, and the guarded build reached Devvit playtest ready on v0.0.1.126, but still needs a true non-mod account playtest. A protected current-user permission diagnostic route is locally and runtime verified for the current moderator account: the Devvit WebView Settings check on r/modmirror_dev returned Access check passed: 1 permission(s): all. A conservative full-access-only visibility gate now keeps future per-mod surfaces aggregate-only unless that runtime-probed all permission is present. The next runtime-proof wave should target one of those remaining gaps with the same safety constraints used by the post-W34 probes. A synthetic retention cleanup smoke route is now locally tested and runtime-verified through Settings on Devvit playtest v0.0.1.138; actual cleanup against real operational records still needs a separate controlled destructive cleanup test before being claimed runtime-verified. Settings now includes a manual runtime capability event recorder for safe proof bookkeeping; those manual events do not replace runtime proof for destructive or platform-dependent capabilities. The expanded Redis sorted-set diagnostic passed on Devvit playtest v0.0.1.136. The Redis storage-envelope diagnostic passed on Devvit playtest v0.0.1.137 for the current bounded storage caps: 10 scan metadata rows, 500 action rows, 500 override rows, one scan-like record, and smoke-key cleanup. The synthetic retention cleanup diagnostic passed on Devvit playtest v0.0.1.138: scans 1/1, receipts 1/1, boards 1/1, delivery 1/1, detail keys 0, and index refs 0. V4 Wave 21 reran the same safe smoke checks from the authenticated Reddit WebView on Devvit playtest v0.0.2.2 after taking over port 5678: Redis write/read matched, Redis ZSET order was newest, middle, oldest, Redis storage returned scan 10/10, actions 500/500, overrides 500/500, cleanup 0, synthetic retention cleanup returned scans 1/1, receipts 1/1, boards 1/1, delivery 1/1, detail keys 0, index refs 0, Reddit read-only returned 0 rule(s), 0 removal reason(s), 5 mod log action(s), and the current account access diagnostic returned 1 permission(s): all.

V4 Wave 21 safe route-level smoke planning now exists under docs/master-plan/v4-production-grade/waves/wave-21-safe-route-smoke/ with an operational runtime plan at docs/operational-overhaul/SAFE_ROUTE_SMOKE_RUNTIME_PLAN.md. The earlier 2026-05-21 rehearsal remains useful blocker evidence because bare curl probes to /api/health, /api/runtime-capabilities, and /api/demo/manifest returned HTTP/1.1 426 Upgrade Required; authenticated WebView proof is now captured separately and should be used for runtime labels.

V4 Wave 06 is complete: the Command Center now has a one-click Judge Demo path that builds the labeled ExampleLearning Rule 2 story through scan, adopted policy, stricter Apply Policy override receipt, Case Packet, Evidence Board, evidence graph, and digest-ready proof. This is static/demo proof, not live Devvit runtime proof.

V4 Wave 09 is complete: Scenario Lab now exposes acceptable alternatives, client-side required-field validation, in-flight save/archive state, stricter server expected-action validation, and active-pack archive correctness for stored calibration scenarios.

V4 Wave 17 is complete: receipt rows now lead to Case Packets and Evidence Boards, board rows can navigate back to receipt/packet context, and evidence items show explicit provenance labels instead of raw source enum values.

V4 Wave 18 is complete: Incident Mode now has a Settings control center with safe start presets, visible time-left and receipt-tag context, active safeguards, and the existing end/report flow remains explicit and confirmation-preserving.

V4 Wave 19 is complete: Configuration Portability now shows an export safety summary, server-backed dry-run policy diffs, per-policy draft/proposal dispositions, and clear confirmation that imports do not silently adopt enforcement.

V4 Wave 20 is complete: Privacy Retention now gates real deletion behind an explicit confirmation checkbox and API flag, shows selected/retained dry-run totals clearly, and separates synthetic cleanup proof from operational deletion claims in the Settings console.

V4 Wave 22 is blocked: the active Devvit identity is still the already verified full moderator account u/BrightyBrainiac; no true non-mod or limited-mod account session is available to execute ACCESS_RUNTIME_TEST_PLAN.md.

V4 Wave 23 is partially complete: the authenticated Devvit WebView session on v0.0.2.8 proved the read-only deep live scan path on r/modmirror_dev with source Live data, depth Deep, 121 actions scanned, 1 attributed, 120 unmatched, requested limit 250, page size 100, and 2 observed moderation-log page fetches. The earlier v0.0.2.6 pass repeated Act Operational Queue Refresh, but it returned the labeled type-supported/no-items fallback, so live reddit_modqueue item reads remain open. Do not claim source: "reddit_modqueue" until MODQUEUE_RUNTIME_TEST_PLAN.md returns a safe live item or captures an exact Devvit adapter/runtime failure.

V4 Wave 25 is complete as a preparation-only harness wave: docs/operational-overhaul/CONTROLLED_PROOF_HARNESS_AUDIT.md now ties the retention destructive cleanup and live Reddit moderation execution runbooks to the implementation gates. Real operational-record deletion and live remove/approve/ignore-reports execution remain unrun and require explicit approval of the exact proof plan before execution.

V4 Wave 26 is complete as a preparation-only harness wave: docs/operational-overhaul/DELIVERY_SCHEDULER_PROOF_HARNESS_AUDIT.md now ties public comment, private/modmail, Mod Discussion, native Mod Notes, and scheduler runbooks to their implementation guards. Live send/write/scheduled behavior remains unrun and requires explicit approval of the exact proof plan before execution.

V4 Wave 28 is complete: static built browser checks verified keyboard focus through the primary Act controls, accessible names for enabled interactive controls, and no 390px horizontal overflow; the client bundle and main entry sizes were measured; and a global reduced-motion CSS guard was added. Native Reddit mobile app behavior remains unverified because no native app/device session was available. A current static mobile submission screenshot now exists at docs/screenshots/submission/mobile-command-center-static.png; Playwright measured innerWidth: 390, scrollWidth: 390, and no horizontal overflow.

V4 Wave 29 is complete for assurance review scope: docs/operational-overhaul/MULTI_MODERATOR_RATIFICATION_TEST_PLAN.md now defines the distinct-moderator runtime proof. Focused tests still cover ratification threshold logic, config exports excluding private history, and Evidence Board privacy preservation. A repo secrets-pattern scan found no matches outside ignored/generated/dependency paths. Distinct-moderator runtime proof remains blocked by account availability. The dependency-hardening follow-up upgraded direct Devvit/Hono/Vite packages and removed the direct Hono/Vite audit findings. The audit-overrides follow-up also overrides Devvit-transitive tmp and ws to patched versions. A safe dev-tool bump follow-up upgraded and validated exact-pinned globals@17.6.0, prettier@3.8.3, typescript-eslint@8.59.4, and vitest@4.1.7; major Dependabot proposals remain unmerged until separately proven against Devvit. npm audit --omit=dev still fails on the remaining Devvit-transitive protobufjs chain; force fixes would downgrade or otherwise break the Devvit package chain.

V4 Wave 30 is blocked: the final completion audit cannot close the active goal while Waves 22 and 23 remain blocked by account/source proof constraints and while the broader production-readiness audit is still open. Stale merged Codex worktrees were cleaned; Gemini/Antigravity worktrees were left untouched. A dependency-hardening follow-up is documented in docs/operational-overhaul/DEPENDENCY_HARDENING.md, but the goal remains open until the remaining runtime blockers are cleared and the user gives the final green light.

docs/operational-overhaul/RUNTIME_PROOF_BACKLOG.md is the current single-page index for remaining proof gaps and proof-plan readiness. docs/master-plan/goal-completion-audit.md maps the active broad user goal to current artifacts and marks the remaining runtime-proof gaps that prevent closing the overall goal.

V2 Master Plan Development Audit

  • Implement Command Center, Drift Radar, Policy Workbench, Apply Policy Cockpit wiring, Team Calibration Studio, Scenario Lab, Policy Simulator, Case Evidence Graph, Review Room, Community Health Radar integration, Trust/Safety Labels, Demo Orchestration Engine, Onboarding Paths, golden tests, and V2 UI surfaces.
  • Update every docs/master-plan/v2/waves/*/execution-log.md.
  • Add docs/master-plan/v2/final-audit.md.
  • Run final gates: npm run type-check, npm run lint, npm test, and npm run build.
  • Verify Devvit CLI session and playtest upload readiness for r/modmirror_dev on version v0.0.1.167; the local playtest command reached ready, but also reported a local EADDRINUSE warning for port 5678.
  • Rerun safe route-level Devvit smoke checks for the new V2 endpoints after opening the playtest WebView. V4 Wave 21 authenticated WebView proof on Devvit playtest v0.0.2.2 passed Redis, Redis ZSET, Redis storage, synthetic retention cleanup, Reddit read-only, and current-account access diagnostics. Direct localhost curl still returns 426 Upgrade Required and should remain documented as a Devvit transport boundary, not route JSON proof.
  • Rerun live WebView visual QA for API-backed V2 states; the completed static smoke only verifies nonblank fallback rendering.

UI consistency pass is now part of this batch: align dashboard cards, forms, metric boxes, and embedded launch/fullscreen layouts so spacing, borders, column rhythm, and responsive wrapping are uniform across Act, Scan, Agree, Review, Prove, and Settings.

PR #12 merge cleanup removed the merged local worktrees and local branches. Only the root master worktree remains. The untracked spec-pack directories in the repo root are intentionally left untouched.

Post-W34 Access Hardening

  • Add a full-access-only visibility helper for future per-mod/manage-level surfaces.
  • Include the visibility level in protected access diagnostics.
  • Add a non-mod and lower-permission moderator runtime test plan.
  • Add a consolidated runtime proof backlog covering remaining open gaps.
  • Verify lower-permission moderator role strings needed for expanding per-mod/manage-level visibility beyond the current all gate.
  • Runtime-verify protected API blocking with a true non-moderator account.

Post-W34 UI Uniformity Pass

  • Audit the fullscreen Devvit WebView and embedded launch card with Computer Use, plus screenshot evidence for the affected UI surfaces.
  • Normalize shared card, form, metric, and button alignment in src/client/styles.css.
  • Verify the reported Agree and Settings alignment issues in desktop fullscreen/static-rendered layouts.
  • Verify Act, Scan, Review, Prove, and the embedded launch card in both fullscreen and narrow/mobile Devvit host modes after this CSS pass.
  • Add screenshot evidence and update the post-W34 build report.

Expansion Wave 29 Checklist

  • Add central subreddit scope resolver for current context, demo exception, and live-only requests.
  • Reject cross-subreddit API requests instead of silently falling back to the current subreddit.
  • Route policy creation, drift-policy creation, attribution correction, and Apply Policy normalization through the shared subreddit guard.
  • Add API isolation error response handling.
  • Add Redis key guard for unsafe subreddit namespace segments.
  • Confirm starter template reuse remains non-sensitive through W28 portable config tests.
  • Add key/subreddit isolation tests.
  • Runtime-verify context-derived subreddit behavior in Devvit Web playtest.

Expansion Wave 28 Checklist

  • Add portable config schema for versioned packages, policies, response templates, digest settings, starter templates, and import results.
  • Add export service that excludes private history by default.
  • Add import validation and migration path for legacy v0 packages.
  • Import policies as drafts/proposed updates instead of silently adopting live enforcement.
  • Add /api/config/export, /api/config/import, and /api/config/templates routes.
  • Add Settings UI for export JSON, import dry runs/imports, and starter templates.
  • Add tests for export privacy, safe dry run, bad import failure, v0 migration, and starter labels.
  • Runtime-verify config export/import persistence through Devvit Web/Redis playtest.

Expansion Wave 27 Checklist

  • Add explicit temporary Incident Mode schema for reason, status, duration, preset suggestions, triage groups, and post-incident report.
  • Add Redis-backed Incident Mode service and namespaced keys.
  • Add /api/incidents, /api/incidents/start, and /api/incidents/:id/end routes.
  • Tag Apply Policy receipts with the active incident ID without changing execution mode or confirmation requirements.
  • Add Settings workflow to start/end incidents and view preset suggestions, triage groups, recent incidents, and the last incident report.
  • Add active Incident Mode banner and receipt-ledger incident tags.
  • Add tests for start/end/expiry behavior and receipt tagging.
  • Runtime-verify Incident Mode route persistence and active receipt tagging through Devvit Web/Redis playtest.

Expansion Wave 26 Checklist

  • Add Evidence Board schema for review-thread status, source references, evidence summaries, privacy metadata, and status history.
  • Add Redis-backed Evidence Board service and namespaced keys.
  • Add /api/evidence-boards list/create and status-update routes.
  • Collect evidence summaries from receipts, content snapshots, overrides, Case Packets, comparable cases, and policy changes.
  • Add Prove-page Evidence Board thread list and status update forms.
  • Add receipt-ledger and Case Packet entrypoints for opening boards.
  • Add lifecycle and privacy-preservation tests.
  • Runtime-verify Evidence Board route persistence through Devvit Web/Redis playtest.

Expansion Wave 25 Checklist

  • Re-check Devvit ModMail / Mod Discussion support in installed typings and official docs.
  • Add case_packet as a team delivery subject type.
  • Add a shared Case Packet delivery draft model.
  • Add Prove-page controls to copy Markdown and store manual delivery receipts.
  • Add Prove-page control to store a Mod Discussion draft receipt without sending a Reddit message.
  • Add tests for case packet delivery draft generation and delivery receipt subject storage.
  • Add an internal Mod Discussion delivery runtime test plan before enabling any real send path.
  • Runtime-verify internal Mod Discussion delivery on a safe test subreddit before enabling any real send path.
  • Runtime-verify delivery receipt persistence through Devvit Web/Redis playtest.

Expansion Wave 24 Checklist

  • Re-check native Mod Notes support in installed Devvit typings and official docs.
  • Add native Mod Note attempt schema and receipt status.
  • Add gated native Mod Notes service.
  • Add Apply Policy opt-in mode for native/log-only/no Mod Note.
  • Record skipped, sent, and failed Mod Note attempts on receipts.
  • Add fallback, success, and failure tests.
  • Add a native Mod Notes runtime test plan before enabling native mode.
  • Runtime-verify reddit.addModNote in Devvit playtest on safe test content before enabling native mode.

Expansion Wave 23 Checklist

  • Add response template schema tied to policy steps.
  • Add safe template rendering with explicit missing-variable placeholders.
  • Add policy editor fields for warning, removal explanation, mod note, modmail, and private-message drafts.
  • Add Apply Policy preview integration.
  • Store gated response previews on receipts.
  • Add escaping, fallback, and Apply preview tests.
  • Runtime-verify response preview persistence through Devvit Web/Redis playtest.

Expansion Wave 22 Checklist

  • Add policy impact measurement schema.
  • Add before/after policy impact service.
  • Add policy impact API route.
  • Add policy-detail before/after UI.
  • Add demo-labeled impact fallback.
  • Add tests for thresholds, insufficient data, and demo labeling.
  • Runtime-verify policy impact route through Devvit Web/Redis playtest.

Expansion Wave 21 Checklist

  • Add aggregate community health schema.
  • Add aggregate-only community health service.
  • Include repeat-author buckets without exposing usernames.
  • Include unresolved overrides, policy churn, drift stability, and receipt-backed case packet readiness.
  • Add /api/community-health.
  • Surface community health on the Review page.
  • Add empty/small-community tests.
  • Runtime-verify community health route through Devvit Web/Redis playtest.

Expansion Wave 20 Checklist

  • Add read-only replay contracts.
  • Add replay service for stored or synthetic attributed actions.
  • Add replay API route under policy records.
  • Add policy replay UI on the Agree page.
  • Add replay fixtures and edge-case tests.
  • Keep replay from mutating action receipts or live Reddit state.
  • Runtime-verify replay route against a stored scan in Devvit Web/Redis playtest.

Expansion Wave 19 Checklist

  • Add explicit ratification settings and summary schema.
  • Add a pure policy ratification helper service.
  • Store proposal notes with proposed versions.
  • Enforce approval thresholds before reviewed adoption.
  • Keep quick adoption explicit and block it when policy settings disable it.
  • Show approval thresholds and proposal notes in the Agree UI.
  • Add threshold and invalid-transition tests.
  • Runtime-verify policy lifecycle API writes through Devvit Web/Redis playtest.

Expansion Wave 18 Checklist

  • Add attribution correction schema.
  • Add Redis-backed attribution correction persistence.
  • Apply moderator corrections during future scan attribution.
  • Preserve inferred/corrected distinction and original evidence.
  • Add correction API endpoints.
  • Add scan-page calibration UI for stored scan actions.
  • Add synthetic tests for correction persistence and future attribution.
  • Runtime-verify correction persistence through Devvit Web/Redis playtest.

Expansion Wave 17 Checklist

  • Research current Devvit modqueue/report API support from official docs and installed typings.
  • Record modqueue capability as type-only until playtest proves it.
  • Add shared triage contracts for capability, queue item, policy hint, history summary, and response.
  • Add read-only triage service that normalizes Reddit queue items.
  • Add /api/modqueue/triage without demo/fake queue fallback.
  • Surface Operational Queue triage on the Act page.
  • Link triage items into Apply Policy target fields.
  • Add targeted service tests for capability, normalization, adapter failure, and missing subreddit context.
  • Add a safe runtime test plan for live modqueue item proof.
  • Runtime-verify /api/modqueue/triage in Devvit playtest with safe queue content. Post-W34 playtests refreshed the panel on v0.0.1.94 and v0.0.1.123, and V4 Wave 23 refreshed it again on v0.0.2.6, but all runs still returned the type-supported/no-items fallback instead of verified Reddit modqueue items.

Expansion Wave 16 Checklist

  • Create docs/expansion-waves/REPO_CONTEXT_RELOAD.md before production coding.
  • Add content snapshot schema/types.
  • Add content snapshot server service.
  • Capture target snapshots in Apply Policy previews.
  • Persist snapshots on action receipts.
  • Surface receipt-backed snapshots in Case Packets.
  • Add content snapshot tests for post, comment, failed fetch, and missing target.
  • Add Wave 16 implementation report.
  • Run full W16 validation gate.
  • Runtime-verify snapshots through real post/comment menu entrypoints in Devvit playtest.

Wave 9/10 — Digest, Delivery Status, Launch Hardening.

Status: Wave 7/8 and the redesign rescue branch are merged to master and pushed to origin through PR #11. Wave 9/10 implementation and runtime QA are merged to master and pushed to origin.

The first Wave 9 slice adds persisted digest contracts, a deterministic server digest engine, Redis-backed digest history, digest API routes, an upgraded Digest page, and digest capability status in Settings. Manual digest plus Markdown copy remains the supported launch path. Mod discussion delivery and weekly scheduling are still disabled/unverified until runtime proof exists.

Scheduler, AI/LLM judging, automatic bans, queue-dashboard scope, and external analytics remain out of scope.

Wave 9/10 Launch Checklist

  • Wave 7/8 merged to master before Wave 9/10 began.
  • Wave 9/10 prompts installed in root docs/, prompts/wave9-10/, and scripts/.
  • Integration branch created: integration/wave9-10-launch-readiness.
  • Digest contracts and constants added.
  • Deterministic digest engine added.
  • Digest history persists in Redis data model.
  • Digest API routes added.
  • Digest page upgraded with preview, recommendations, Markdown export, and history.
  • Settings shows digest delivery/scheduler capability status.
  • Mod discussion delivery remains disabled/unverified.
  • Scheduler remains disabled/unverified.
  • Static Digest/Settings visual QA captured.
  • npm audit reviewed and documented.
  • Launch readiness checklist filled with local/static/runtime evidence.
  • App listing draft complete.
  • Devpost draft complete.
  • Screenshot/video plan complete.
  • Final Wave 9/10 report complete.
  • Runtime playtest re-run for Wave 9/10.
  • Full final checks pass.
  • Integration branch merged to master after checks.
  • master pushed to origin after Wave 9/10 merge.

Wave 7/8 Productization Status

Wave 7/8 is complete and merged. The client starts as a compact inline launch card, opens into the Command Center IA, carries the ExampleLearning demo through scan -> policy -> Apply Policy -> review -> Case Packet -> digest, exposes runtime Settings, and preserves the Devvit expanded-modal viewport dropdown.

Wave 7/8 Productization Checklist

  • Compact inline launch/status card implemented.
  • New IA implemented: Command Center, Scan, Policies, Review, Case Packets, Digest, Settings.
  • Command Center is the first dashboard screen.
  • Setup wizard and ExampleLearning demo scenario are visible from Command Center.
  • Policy health, override inbox, and Case Packet UI are upgraded.
  • Manual Digest generates Markdown without adding scheduler scope.
  • Runtime Settings shows data mode, health caveats, delivery mode, demo state, and last scan context.
  • Demo/static-preview fallbacks keep the 3-minute story usable without live API access.
  • Full final checks pass.
  • Runtime playtest is re-run for Wave 7/8.
  • Integration branch is merged to master and pushed.
  • Post-merge redesign rescue branch created after user rejected visual quality.
  • Redesign branch build/type-check/lint/tests pass.
  • Redesign branch reaches Devvit playtest ready.
  • Redesign branch inline card renders in signed-in Safari Reddit playtest.
  • Redesign branch native expanded modal opens with Devvit viewport dropdown.
  • Redesign branch demo workflow works end-to-end in signed-in Safari playtest.
  • Redesign branch pushed to origin/redesign/wave7-8-command-center-ui.
  • Draft PR opened for redesign review: https://github.com/Arshgill01/ModMirror/pull/11.
  • User reviews redesigned UI and gives explicit green light.
  • Merge redesign/wave7-8-command-center-ui to master if approved.

Wave 6 Case Packet Checklist

  • Case packet shared contracts and DTOs exist.
  • Case packet generator works from demo data.
  • Generator can target stored Apply Policy action IDs.
  • Policy version/snapshot at action time is shown when recorded.
  • Policy changes after the action are caveated.
  • Override context and review status appear when present.
  • Prior same-user same-rule history appears when available.
  • Comparable cases use deterministic filters and match reasons.
  • Suggested appeal posture is deterministic and caveated.
  • Markdown export/copy UI exists.
  • Unit tests cover engine, posture, comparables, markdown, missing data, and demo generation.
  • npm run dev reaches Devvit Playtest ready.
  • Runtime browser proof of dashboard Case Packet generation from the playtest UI, including Markdown copy/export.

Wave 5 Governance Core Checklist

  • Policy edits create immutable versions.
  • Active policy version pointer is stored.
  • Old policy versions remain readable.
  • Apply Policy action logs include policy version/snapshot when available.
  • Overrides default to unresolved review status.
  • Override review updates preserve original override event fields.
  • Policy health supports stable/watch/at_risk/needs_review/insufficient_data.
  • Governance dashboard shows policy health, override review inbox, and version summaries.
  • Demo mode still works.
  • Build/typecheck/lint/tests pass after integration.
  • Runtime/playtest status is recorded honestly.

Wave 3/4 Completion Checklist

  • Policy creation API and dashboard flow.
  • Policy editing API and dashboard flow.
  • Policy list/overview dashboard.
  • Create policy from Mirror Scan drift candidate.
  • Manual policy creation.
  • Empty policy fallback copy.
  • Small-subreddit policy-first copy.
  • Apply Policy preview endpoint and dashboard simulator.
  • Apply Policy confirm endpoint in log_only mode.
  • Deviating selected actions require override reason.
  • Action events are stored in Redis sorted sets.
  • Override events are stored in Redis sorted sets.
  • Aggregate override summary service/API hides per-mod breakdowns.
  • Demo scan supports the full policy/apply loop.
  • Local build/test/typecheck/lint pass in Wave 3/4 worktree.
  • Runtime playtest reaches ready.
  • Browser UI proof that signed-in Safari opens the playtest subreddit and shows the dashboard launcher.
  • Browser UI proof that the dashboard launcher confirmation form opens without creating a post.
  • Browser UI proof that the dashboard custom post renders after approval to submit the confirmation form.

Wave 2 Integration Checklist

  • Merge deterministic attribution engine.
  • Merge mandatory r/ExampleLearning demo seed data.
  • Merge live source adapters for mod log, rules, and removal reasons.
  • Merge Mirror Scan dashboard states.
  • Wire demo and live scan through the same scan service.
  • Verify confidence breakdown totals.
  • Verify demo Rule 2 drift candidate.
  • Complete docs/WAVE2_COMPLETION_REPORT.md.
  • Keep Policy Agreement Flow out of Wave 2.
  • Keep Apply Policy and Override Audit out of Wave 2.

Wave 1 Completed Locally

  • Create shared TypeScript data contracts in src/shared/schema.ts.
  • Create shared constants for confidence levels, enforcement actions, and override reasons.
  • Centralize Redis key construction in src/server/services/redis.ts.
  • Add getAppConfig / setAppConfig.
  • Add getDemoModeState, getDemoModeFlag, and setDemoModeFlag.
  • Add getPolicyByRule, setPolicyByRule, and listPolicies.
  • Add saveLastScanMetadata and getLastScanMetadata.
  • Add saveAuditEvent and listRecentAuditEvents.
  • Rewire /api/smoke/redis through the Wave 1 Redis service.

Wave 1 Historical Runtime Follow-up

  • Hit /api/smoke/redis in playtest and confirm modmirror:{subreddit}:smoke:redis-data-layer write/read.
  • Confirm Redis hash behavior for modmirror:{subreddit}:policies.
  • Locally test reverse sorted-set ordering for modmirror:{subreddit}:overrides.
  • Runtime-run the Redis sorted-set diagnostic in Devvit playtest v0.0.1.131 and record the failed empty observed-order result.
  • Rerun the expanded Redis sorted-set diagnostic in Devvit playtest v0.0.1.136 and confirm observedOrder matched expectedOrder.
  • Add local caps for scan metadata plus action and override audit indexes.
  • Add a safe Redis storage-envelope diagnostic route and Settings control for scan metadata, action-event, and override-event cap proof.
  • Runtime-run /api/smoke/redis-storage in Devvit playtest and verify expected counts plus smoke-key cleanup.
  • Runtime-confirm practical Redis storage limits for the current scan metadata and audit-event caps before storing larger live datasets.

Wave 0 Completed Locally

  • Create Devvit app scaffold from current official mod-tool template.
  • Confirm Node/npm versions.
  • Confirm Devvit CLI/package versions.
  • Confirm generated install/dev/build/upload/publish commands.
  • Build smallest possible Redis smoke test.
  • Build smallest possible Reddit API smoke test.
  • Build smallest possible post/comment menu action and form chaining smoke test.
  • Verify SDK/type support for moderation log, removal reasons, subreddit rules, submit comments, remove/approve/ignore reports, private messages, modmail, native Mod Notes, and moderator permission checks.
  • Replace destructive template example with non-destructive smoke-test surfaces.
  • Document Wave 0 findings in RESEARCH.md.
  • Mark Wave 0 assumptions as verified, unverified, broken, or deferred in RESEARCH.md and docs/DEVVIT_RESEARCH_QUESTIONS.md.

Wave 0 Runtime Blockers

  • Complete npm run login / npx devvit login.
  • Complete npx devvit whoami locally as u/BrightyBrainiac.
  • Create or bind the real Reddit app identity for modmirror; npx devvit view --json returns app id 5cd5fae3-9da6-4e7c-a243-7c8762badd91.
  • Run npm run dev far enough to reach Playtest ready in r/modmirror_dev.
  • Hit /api/smoke/redis in playtest and confirm Redis read/write.
  • Hit /api/smoke/reddit in playtest and capture redacted sample output.
  • Runtime-verify the replacement post/comment Apply Policy menu actions and target context handoff in Reddit.
  • Verify whether submitComment works on normal content, before removal, and after removal.
  • Verify whether a submitted removal comment can be distinguished/stickied.
  • Add a public comment delivery runtime test plan before enabling comment delivery.
  • Add a private message/modmail delivery runtime test plan before enabling private delivery.
  • Verify private message and modmail delivery behavior.
  • Verify native Mod Notes add/read/delete behavior with real moderator permissions.
  • Add a native Mod Notes runtime test plan before enabling native mode.
  • Add server-side protected API moderator access checks for live subreddit context.
  • Add route-level middleware tests proving public health stays reachable and protected API routes require moderator access.
  • Add a protected current-user permission diagnostic route for safe runtime permission-string capture.
  • Runtime-capture the current moderator account's permission string in the Devvit WebView diagnostic (all on r/modmirror_dev).
  • Classify moderator-access API failures separately in the client so blocked users see moderator-account guidance instead of generic input-fix text.
  • Add the required runtime test plan for true non-mod blocking and lower-permission moderator role strings.
  • Runtime-verify protected API blocking with a true non-moderator account.
  • Verify lower-permission moderator role strings needed for per-mod/manage-level visibility.

Wave 1 Tasks

  • Create src/shared/schema.ts with researched data contracts from docs/DATA_MODEL.md.
  • Create src/shared/constants.ts with confidence/action/message-delivery constants.
  • Use local derived rule keys, not assumed Devvit rule IDs, in shared policy types.
  • Set default message delivery to log_only until comment-before/removal and comment-after/removal behavior is playtest-verified.
  • Create a Redis key helper that produces modmirror:{subreddit}:{suffix} keys.
  • Split server code into src/server/services/ while preserving the current Devvit Web/Hono entrypoint shape.
  • Add a health/status endpoint that reports app name, runtime context if available, demo-mode state, and whether live playtest proof is still missing.
  • Create the initial dashboard shell/client entry deliberately; the Wave 0 template did not generate one.
  • Add focused unit tests for pure shared helpers using vitest.config.ts.
  • Keep smoke endpoints/menu actions non-destructive until playtest proof exists.
  • Update RESEARCH.md if Wave 1 discovers new SDK/runtime facts.

Wave 2 Prerequisites

  • Wave 1 shared contracts, Redis helper, health/status endpoint, and dashboard shell exist and pass typecheck/build.
  • Runtime playtest either verifies Redis/Reddit/menu/form behavior or Wave 2 explicitly stays demo/local-only until auth is unblocked.
  • Comment delivery ordering is tested or Mirror Scan/Policy work defaults all outbound messaging to log_only.
  • The rule attribution contract uses confidence labels and evidence arrays for every inferred match.
  • Demo seed data is available before judging-facing screenshots or video work.

Wave 2 Tasks After Prerequisites

  • Fetch moderation log actions through reddit.getModerationLog({ subredditName, limit, pageSize }).all().
  • Fetch removal reasons through reddit.getSubredditRemovalReasons(subredditName).
  • Fetch subreddit rules through reddit.getRules(subredditName).
  • Normalize mod actions without assuming structured rule/removal IDs.
  • Implement deterministic attribution with high/medium/low/unmatched confidence labels.
  • Store scan summary metadata in Redis while avoiding raw content storage.
  • Render Mirror Scan dashboard results with clear demo/live labeling.

Ready For Wave 3

  • Shared contracts are importable from server code through src/shared/index.ts.
  • Use ruleKey for policy and attribution references; do not assume a stable Devvit rule ID.
  • Start Policy Agreement Flow from MirrorScan.driftCandidates.
  • Keep policy message delivery defaulted to log_only until public comment behavior is playtest-verified.
  • Preflight commands passed on 2026-05-16: npm run build, npm test, npm run type-check, npm run lint, npx devvit whoami, and npm run dev to Playtest ready.

Do Not Start Until Scoped

  • Apply Policy enforcement flow.
  • public comment delivery as a default.
  • private message, modmail, or native Mod Notes delivery.
  • override audit dashboard.
  • Devpost final copy.

Operational Overhaul Moderation Execution Follow-up

  • Add a controlled destructive Reddit moderation execution test plan before any live remove/approve/ignore-reports proof.
  • Runtime-verify remove, approve, and ignore-reports only on approved throwaway content with receipt evidence and explicit cleanup notes.

Operational Overhaul W10 Follow-up

  • Add disabled-by-default AI advisory contracts and capability endpoint.
  • Add mocked-provider tests that require deterministic evidence citations.
  • Keep AI advisory unable to decide or execute enforcement.
  • Runtime-verify Devvit external fetch with a safe test provider before enabling any live AI advisory path.
  • Runtime-verify Devvit app secret retrieval for any provider key before marking AI advisory available.
  • Add Terms/Privacy readiness notes before any uploaded build uses external fetch for AI.

Operational Overhaul W11 Follow-up

  • Add team delivery capability states for manual copy, mod discussion, and scheduler.
  • Add preview-first delivery APIs for digest/policy proposal content.
  • Store manual/skipped delivery receipts without sending Reddit messages.
  • Keep product routes from injecting a live delivery adapter.
  • Add an internal Mod Discussion delivery runtime test plan before enabling any real send path.
  • Runtime-verify internal Mod Discussion delivery on a safe test subreddit before enabling any real send path.
  • Add a scheduler runtime test plan before registering any scheduler task.
  • Register and runtime-verify a scheduler task before scheduler delivery is marked anything stronger than unavailable.
  • Locally verify scheduler confirmations cannot route through the Mod Discussion adapter or create user-facing delivery.
  • Runtime-verify Mod Discussion permission failure shape before enabling real delivery.

Operational Overhaul W12 Follow-up

  • Reframe the dashboard around Act, Scan, Agree, Review, Prove, and Settings.
  • Put Apply Policy and the action receipt ledger on the Act workspace.
  • Move policy lifecycle work into Agree and proof artifacts into Prove.
  • Capture static desktop and mobile screenshots for the Act workspace.
  • Runtime-verify the new IA inside Devvit WebView on desktop Reddit.
  • Runtime-verify the new IA inside Reddit desktop host Mobile Devvit modal/narrow WebView.
  • Audit tracked docs/bookmark-like references for old W12 page IDs after integration. No tracked current docs/bookmarks require an update; legacy hash compatibility remains in client routing.
  • Update user-owned external docs/bookmarks outside this repo if any still reference old page IDs.

Operational Overhaul W13 Follow-up

  • Add a runtime verification matrix endpoint.
  • Add a runtime verification matrix document.
  • Run Devvit playtest to readiness on r/modmirror_dev.
  • Verify the subreddit dashboard launcher appears and opens its confirmation form.
  • Verify the W12 operational IA renders inside Reddit's desktop expanded WebView.
  • Verify post Apply Policy menu entry on an ordinary safe post detail page.
  • Verify post menu target context handoff into the Act workspace.
  • Verify comment Apply Policy menu entry on an ordinary safe comment.
  • Verify comment menu target context handoff into the Act workspace.
  • Hit /api/smoke/redis in Devvit runtime and record a redacted read/write result.
  • Hit /api/smoke/reddit in Devvit runtime and record redacted read-only context.
  • Verify log-only Apply Policy creates a receipt in Devvit Redis.
  • Verify native Reddit mobile app layout and interaction behavior.

Expansion Wave 30 Follow-up

  • Add privacy retention settings for scan history, action receipts, evidence boards, team delivery receipts, case packets, and AI advisory logs.
  • Keep policy history protected by default and outside deletion controls.
  • Add inventory export and manual deletion APIs with dry-run support.
  • Add Settings UI for retention windows, privacy inventory, and deletion controls.
  • Add service tests for defaults, setting updates, inventory export, dry-run behavior, and expired cleanup.
  • Runtime-verify retention settings, privacy inventory, and dry-run deletion controls against Devvit Redis on a safe test subreddit.
  • Add a safe synthetic retention cleanup smoke route that creates old synthetic Redis records, deletes only those records through retention cleanup, and verifies detail keys plus index references are gone.
  • Runtime-verify the synthetic retention cleanup smoke route in Devvit playtest.
  • Add a controlled destructive cleanup test plan before attempting real operational-record deletion proof.
  • Runtime-verify actual expired-data cleanup only after a controlled destructive cleanup test is planned.
  • Add a scheduled cleanup task only after scheduler behavior is runtime-verified in this app shape.

Expansion Wave 31 Follow-up

  • Add client error taxonomy for static preview, timeout, network, API, and clipboard failures.
  • Add timeout-aware API fetches with actionable retry/fallback messages.
  • Add static-preview/runtime resilience notice in the dashboard shell.
  • Add clipboard failure handling for Case Packet and Digest Markdown copy.
  • Add mobile CSS/static checks for core workspace collapse and wrapped runtime data.
  • Run a 390px Playwright static-client smoke check for Act, Scan, Review, Prove, and Settings with no horizontal overflow.
  • Runtime-verify the same narrow layouts inside Reddit's Devvit WebView on desktop mobile mode.
  • Runtime-verify the same narrow layouts inside the native Reddit mobile app.
  • Replace static-client browser proof with Devvit WebView screenshots after playtest access is available for W31.

Expansion Wave 32 Follow-up

  • Add deterministic synthetic fixtures for stable, drifted, improving, small-subreddit, noisy-attribution, repeated-offender, policy-version, and incident-mode histories.
  • Add a golden synthetic evaluation manifest.
  • Add a local synthetic evaluation command.
  • Cover replay, drift, policy-impact, and safety-label expectations in tests.
  • Update the golden manifest intentionally when replay, analytics, or synthetic safeguard semantics change. Post-W34 added a foreign-subreddit action safeguard to the manifest.
  • Add future scenario coverage for multi-community comparison after W34 integration decides the cross-community contract. Coverage now reflects the W29 isolation-first contract rather than cross-community analytics.

Expansion Wave 33 Follow-up

  • Add a Settings-facing runtime capability matrix.
  • Distinguish verified runtime, verified static, type-only, demo-only, disabled, deferred, unsupported, and failed runtime states.
  • Record Redis/Reddit smoke route health events without changing smoke response shapes.
  • Prevent health events from enabling destructive live moderation operations.
  • Runtime-run /api/smoke/redis and /api/smoke/reddit in Devvit playtest so the matrix can promote safe capabilities with real proof.
  • Add operator UI for running safe Redis and Reddit read-only smoke checks from inside the authenticated WebView.
  • Runtime-verify post-menu Apply Policy target capture in Devvit playtest.
  • Add operator UI for recording manual playtest events if future runtime proof needs moderator-observed states that are not reachable by smoke routes.
  • Add a safe Redis sorted-set ordering diagnostic route and Settings control for future Devvit runtime proof.
  • Runtime-run /api/smoke/redis-zset in Devvit playtest v0.0.1.131 and record that it returned ok: false with an empty observedOrder.
  • Rerun /api/smoke/redis-zset after the diagnostic switched to the documented variadic zAdd call; Devvit playtest v0.0.1.136 reported Redis sorted-set smoke passed: observed newest, middle, oldest.
  • Add a safe Redis storage-envelope diagnostic route and Settings control for bounded scan metadata, action-event, and override-event proof.
  • Runtime-run /api/smoke/redis-storage in Devvit playtest v0.0.1.137 and verify expected counts plus smoke-key cleanup.

Expansion Wave 34 Follow-up

  • Create the W34 integration branch from the sequential expansion line.
  • Add expansion architecture notes.
  • Add the expansion build report.
  • Review and merge the W16-W34/post-W34 line through PR #12.
  • Run Devvit playtest proof for the W33 runtime capability matrix on a safe subreddit before promoting Redis/Reddit smoke beyond local/static proof.
  • Merge the expansion/post-W34 line to master and clean merged local worktrees/branches.