conductor/docs/MVP_TRACEABILITY.md

62 lines
7.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Conductor v0.1.0 Requirements Traceability
## Purpose
This matrix maps every release-critical requirement area in `docs/REQUIREMENTS.md` and every approved workflow in `MVP_SCOPE.md` to an owning slice and acceptance evidence. It is the governance bridge between product requirements, implementation plans, and validation. Detailed field-level behavior remains authoritative in the linked schema and topic documents.
## Release-critical requirements
| ID | v0.1.0 requirement area | Owning slice | Validation criterion and evidence | Status |
|---|---|---|---|---|
| R1 | Browser-based application, React frontend, backend API, SQLite persistence, and Docker Compose deployment | Slices 1, 6, 8 | Production builds, Compose startup/health/restart/persistence, backup/restore in `docs/RELEASE_VALIDATION.md` and `TESTING.md` | Accepted |
| R2 | Canonical JSON project definition shared by Visual Editor, JSON Editor, Preview, persistence, and validation | Slices 2, 5, 6 | Schema matrix, canonical round trips, cross-view synchronization, save/reload/restart tests | Accepted |
| R3 | Single-page visual canvas with the eleven schema-supported components, selection, movement, resizing, deletion, properties, and basic styling | Slices 1, 2 | Slice 1/2 component tests and accepted canvas/property/Preview manual workflows | Accepted |
| R4 | REST actions with supported methods, URL, headers, query/path parameters, body template, description, and fixed proxy-policy timeout | Slices 2, 4 | Action-editor tests, proxy integration/security suites, `docs/SCHEMA.md`, `docs/PROXY_SECURITY.md` | Accepted |
| R5 | Button `onClick` and page `onLoad` execution; component/variable request templates; Table selection runtime binding | Slices 2, 6 | Frontend event/template/runtime tests and deterministic launcher/dashboard E2E | Accepted |
| R6 | Top-level response/component bindings to supported component properties or typed runtime variables | Slices 2, 5, 6 | Binding diagnostics/runtime tests, compatibility validation, dependent-data/dashboard workflows | Accepted |
| R7 | Anonymous, Basic, Bearer, API-key header, and API-key query authentication with opaque canonical references | Slices 3, 6 | All-mode backend integration and manual authenticated-request acceptance | Accepted |
| R8 | Encrypted server-side secret lifecycle, compatible selection, missing-reference behavior, and no browser/project exposure | Slices 3, 6 | `docs/SECRETS.md`, lifecycle tests, restart checks, manual redaction gate | Accepted |
| R9 | Default-deny server-side proxy with URL/header validation, SSRF/redirect/DNS controls, limits, safe errors, and explicit internal exceptions | Slices 4, 6 | `docs/PROXY_SECURITY.md`, proxy security/integration tests, Docker manual gate | Accepted |
| R10 | Sanitized bounded execution history with filtering, persistence, clear behavior, and no credential leakage | Slices 4, 6 | Backend history/redaction tests, frontend history checks, exact marker scans | Accepted |
| R11 | Central schema/semantic validation, atomic persistence, actionable cross-view diagnostics, and unsaved-edit preservation | Slices 5, 6 | Backend rollback/version/semantic tests and Slice 5 manual failure/recovery acceptance | Accepted |
| R12 | Preview runtime with loading, empty, success, upstream failure, mapping failure, retry/recovery, and ephemeral state | Slices 2, 5, 6 | Preview suites and all six deterministic manual workflows | Accepted |
| R13 | Save/load, portable JSON definition, backend/full-stack restart persistence, runtime reset, and SQLite backup/recovery | Slices 2, 5, 6 | Canonical round-trip tests, E2E save/reload, restart and offline backup/restore evidence | Accepted |
| R14 | Accessible, scannable Actions & Bindings authoring with progressive disclosure and preserved local drafts | Slice 6a | 25 frontend suites / 520 tests and `SLICE6a_MANUAL_TEST.md` acceptance | Accepted |
| R15 | Local authentication, secure sessions, global admin/user RBAC, admin-only authoring, and user lifecycle management | Slice 7a | Backend integration security matrix, frontend regression suite, and accepted manual admin/user workflows | Accepted |
| R16 | Immutable standalone published applications with public/authenticated visibility and server-owned published action execution | Slice 7a | Server-snapshot integration coverage and accepted public/restricted publishing workflows | Accepted |
| R17 | A fresh installation creates its initial administrator through a secure browser first-run flow without requiring Docker commands | Slice 7b | Atomic setup/security tests, fresh-install browser E2E, recovery verification, and manual acceptance | Planned |
## Approved acceptance workflows
| Workflow | Primary requirements | Owning validation slice | Evidence |
|---|---|---|---|
| Workflow Launcher | R2R6, R11R13 | Slice 6 | `SLICE6_MANUAL_TEST.md` Test 1 and deterministic E2E |
| Dependent Data | R5, R6, R11, R12 | Slice 6 | `SLICE6_MANUAL_TEST.md` Test 2 and runtime tests |
| Read-Only Dashboard | R3, R5, R6, R12 | Slice 6 | `SLICE6_MANUAL_TEST.md` Test 3 and deterministic E2E |
| Authenticated Request | R4, R7R10 | Slice 6 | `SLICE6_MANUAL_TEST.md` Test 5 and backend integration |
| JSON Editing and Persistence | R1, R2, R11, R13 | Slice 6 | `SLICE6_MANUAL_TEST.md` Tests 4 and 6 |
| Failure Handling | R9R12 | Slice 6 | `SLICE6_MANUAL_TEST.md` Test 4 and Slice 5 recovery evidence |
## Explicit post-MVP classifications
The following capabilities are not release requirements. Their presence in future-oriented requirements or architecture text does not block v0.1.0:
- Provider-neutral AI assistance, including chat, generation, explanation, documentation, and refactoring
- IBM Bob, watsonx, or any provider-specific AI dependency
- OIDC/enterprise SSO, external identity provisioning, and claim/group mapping (Slice 9)
- Multi-page authoring and advanced page management
- Direct Dropdown-triggered REST execution and general action chaining/orchestration
- Conditions, branches, loops, parallelism, retries, workflow graphs, and long-running task orchestration
- OAuth 2.0, IBM Cloud IAM, mTLS, and custom authentication scripts
- OpenAPI import and generated React/static/deployment-package output
- Per-action timeout and expected-response-format controls
- Binding transforms, expression languages, and configurable per-binding error policies
- Canvas zoom/pan, undo/redo, advanced JSON-editor tooling, themes, and reusable component libraries
- Tabs, modals, date pickers, file uploads, charts, progress indicators, and advanced Table capabilities
- RBAC, team collaboration, approval workflows, enterprise audit retention, and SIEM integration
- PostgreSQL/high-availability/centralized multi-user deployment
## Governance rule
`MVP_SCOPE.md` controls the release boundary. A new capability becomes release-blocking only through an explicit product-owner scope decision followed by updates to this matrix, `ROADMAP.md`, the owning slice, and its validation criteria. Aspirational or compatibility-only schema text does not silently expand v0.1.0.