DIREKT Project Status¶
Updated: 2026-07-28 (Asia/Tokyo)
Stable branch: main
VC1–VC8 promotion: PR #270 merged at c7f5985bc20372b4761e063dc3a66ecc736556e2
Visual Completion issue: #259 — CLOSED/COMPLETED
Runtime integration tracker: #261
Active repository write lane: none; the Phase 11 controlled-pilot tracker is closed not planned before entry and any restart requires a new authorization lane
1. Programme state¶
DIREKT’s current repository state is:
- Phases 0–10 — complete;
- Phase 11 internal/synthetic readiness — complete;
- Phase 11 11C–11J execution-readiness package — CLOSED AND PRESERVED — EXECUTION READY / REAL ENTRY BLOCKED / NO PRIMARY-PILOT EVIDENCE;
- Phase 11 Wave 0 finishing-line controls — CLOSED AND PRESERVED / TECHNICAL PREFLIGHT PASSED / ENTRY_BLOCKED_EXTERNAL;
- Phase 11 controlled Zambia pilot — NOT RUN / STOPPED BEFORE ENTRY / TRACKER CLOSED NOT PLANNED;
- repository-clearable Phase 12 preauthorization engineering — complete;
- formal Phase 12 production release — not authorized;
- functional customer/provider web/PWA W0–W8 — closed;
- VC0 preparation/control — closed;
- VC1–VC8 world-class product/AI modernization — complete and merged;
- UIA current-main owner-review access — CLOSED AND PRESERVED / SYNTHETIC BROWSER + INTERNAL ANDROID + IAM-PRIVATE OPERATIONS PROVEN;
- runtime integration closure — RC0–RC11 are closed. The final managed evidence index, combined regressions and truthful blocked/provider-state reconciliation are preserved; the repository write lane is released.
Administrative closure of Issue #112 does not mean Phase 11 completed. The real controlled pilot did not run, no primary evidence exists, and all privacy/legal/provider/participant/payment/production gates remain mandatory for any future re-entry.
2. Current product truth¶
DIREKT now has:
- native Android customer/provider implementation using Jetpack Compose/Material 3;
- functional responsive customer/provider web/PWA companion;
- privileged internal operations portal;
- canonical NestJS REST/OpenAPI backend;
- PostgreSQL/PostGIS/private-storage foundation;
- check-specific verification/trust engine;
- enquiries, reviews, complaints and commercial foundations;
- active managed development/staging infrastructure within documented boundaries;
- canonical browser application at
https://app.direkt.forum; - preserved synthetic historical preview at
https://direkt.forum/preview/; - completed VC1–VC8 modernization using the approved Structured Trust + Neighbourhood Marketplace + Field Utility hybrid;
- bounded AI assistance behind DIREKT-controlled backend/BFF boundaries with deterministic/manual fallback and fail-closed use-case switches;
- permanent synthetic-safe responsive/native visual-evidence generation in normal CI.
Android remains the primary native Version 1 client. Web/PWA remains additive and shares product semantics through canonical backend contracts, not shared UI binaries or privileged browser credentials.
3. W0–W8 functional parity¶
W0–W8 are closed.
DIREKT PRODUCT
│
┌──────────────┴──────────────┐
│ │
Android Client Web/PWA Client
Jetpack Compose Next.js / React
│ │
└──────────────┬──────────────┘
│
Canonical OpenAPI
│
DIREKT NestJS API
│
PostgreSQL / PostGIS / Private Storage
│
Identity / Trust / Enquiries / Reviews / Commercial / Audit
Stable W8 managed evidence remains:
- functional managed runtime source:
c1262ce2bfb76e06d2296d793f1acd6cf5cc3ca2; - managed run:
29721199177; - canonical-domain verification run:
29802524466; - canonical host:
https://app.direkt.forum.
4. VC1–VC8 completion¶
VC1–VC6¶
Promoted through PR #268 at c5eb25b2e579d7f148b67130baf307a45f11e7a0:
- cross-surface Design DNA and visual-system reconciliation;
- customer marketplace/discovery and provider-profile modernization;
- provider professional workspace and evidence presentation;
- operations mission-control / queue → case/evidence → checklist/decision composition;
- Android visual/product modernization;
- historical W4/W7 ownership corrections so legitimate later evolution remains regression-tested.
VC7 — bounded AI intelligence¶
The provider-neutral AI foundation was promoted through PR #265. VC7 adds:
- optional natural-language customer discovery/category assistance;
- grounded public Help with source identifiers;
- provider onboarding/readiness guidance;
- provider public-profile drafting requiring provider confirmation.
Controls include use-case registry/data classification, prompt/version control, input limits, canonical taxonomy validation, evaluations/security tests, authorization, deterministic/manual fallback and fail-closed switches.
AI cannot approve verification, strengthen trust/publication/ranking, authorize payments, decide serious disputes/appeals, widen permissions or make legal/regulatory conclusions.
Restricted evidence OCR/extraction and restricted operations AI remain disabled until separately approved privacy/security/data-processing/provider requirements and dedicated runtime evidence exist.
VC8 — quality, regression and visual evidence¶
Permanent quality verification covers:
- responsive/adaptive presentation;
- accessibility/focus/target/reflow expectations;
- AI disclosure/fallback/privacy;
- credential and client-privilege boundaries;
- no blanket
Verifiedregression; - restricted-data AI gating;
- exact-head visual evidence.
Permanent evidence ownership:
functional-pwa-ci.yml— responsive customer/provider/public Help/operations evidence;android-ci.yml— native Android build/emulator/customer/provider/evidence captures.
The redundant standalone VC8 visual workflow was removed after both permanent lanes proved successful.
5. Final VC closure evidence¶
Exact reviewed closure head:
cc7cdb5760c01498f27ca1daba738e02296320cb
Merged through PR #270 at:
c7f5985bc20372b4761e063dc3a66ecc736556e2
All required permanent exact-head workflows passed, including Backend CI/Container, Android CI/performance, both PWA suites, W4/W7/W8, integration audit, controlled staging, recovery, supply-chain security, Phase 11 synthetic, Play readiness, Phase12A/final preauthorization and documentation quality.
Web and operations visual evidence¶
- workflow run:
29830637290; - artifact ID:
8495136163; - digest:
sha256:87e995d951efdb5d1282bbd7ad32bd08b4826a858a9c32570b0ed99f3541dd6d.
Visually inspected representative states: responsive customer discovery, deterministic AI fallback, grounded Help, provider check-specific trust, operations mission control and evidence review.
Native Android visual evidence¶
- workflow run:
29830637218; - artifact ID:
8495234528; - digest:
sha256:ec089058f023ae279325e7e89df63d33b61308ca664dad7cb64e547b6b5fe326.
Visually inspected states:
- Customer Discover;
- Provider Overview;
- Provider Evidence/recovery.
All evidence is synthetic/public-safe as applicable. No private evidence, exact private coordinates, raw contacts, credentials, developer/test-harness presentation or blanket provider verification is exposed.
6. Integration/runtime truth¶
Detailed authority remains:
docs/integrations/CURRENT_INTEGRATION_STATUS.md;docs/integrations/LIVE_INTEGRATION_LEDGER.md;docs/integrations/RUNTIME_INTEGRATION_CLOSURE_PLAN.md;WORKSTREAM_LOCK.md.
Important distinctions:
- Supabase/Postgres/PostGIS/private Storage, canonical backend, Cloud Run, Secret Manager, Workload Identity Federation, Logging and core CI/runtime infrastructure are active within documented environment boundaries;
- RC1 Resend, RC4 FCM and RC6 WhatsApp have managed synthetic outbox → provider/device or authentic provider-receipt proof, while real-participant/continuous production communications remain separately gated;
- the provider-neutral AI contract and bounded VC7 use cases are implemented, but external model runtime activation remains per-use-case/fail-closed and restricted-data AI remains disabled;
- RC5 Firebase Test Lab is CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED MATRIX: isolated project
direkt-testlab-502701-20260726, exact sourcec3744430a7beb1cd47246d858df9ac1379a068ac, run30183466799, API 26/33/36 and zero flaky retries; - RC7 Google Maps is CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY at source
47285575862cbf08845eaeabe093afea1ea79bd1, run30234521983/1, artifact8641270327(sha256:24da53c0bd6fa885fa4a6814f70af090096192e6c5b7a03c89fba51416877fde); participant/production Maps and private-coordinate publication remain disabled; other integrations still require their own runtime evidence before being represented as active; - RC8 sandbox payments are CLOSED — ACTIVE SYNTHETIC-ONLY MANAGED CANARY at source
ccc4e9463d810ddf554182b1607c22d3a7c8c8d3, run30241092949/1, artifact8643323319(sha256:bbb4600eb5a062552947e91c878dd09c6d1e4dc307ae4783c7fa1fb4cf6e4935): MTN success, Stripe unpaid Checkout, PayPal unapproved order, immutable reconciliation and cleanup passed; application provider registration, DPO/Airtel/Flutterwave runtime binding, participant use and real money remain disabled; - RC9 generated clients are CLOSED — DETERMINISTIC / BOUNDED RUNTIME ADOPTION at implementation merge
70de95c73128e921cd4d7c667de0e5a442a9e0c0: Kotlin and TypeScript generation are checksum-pinned and byte-drift enforced; Android uses the generated Firebase-session exchange behind a DIREKT-owned safe wrapper; the web uses generated auth types only behind the server-side BFF; direct browser/private API, privileged credentials, participant activation and production authority remain false; - payment rails may be sandbox-proven while real money remains disabled;
- an account, API key, secret or provider dashboard entry alone is never
ACTIVEruntime evidence.
Backend/integration readiness does not authorize real participant data, private evidence processing, production communications, real money or production release.
7. Trust, privacy and commercial boundaries¶
The following remain non-negotiable:
- no blanket
Verifiedbadge; - public trust remains check-specific, scoped, dated/currentness-aware and limitation-aware;
- payment/commercial state cannot create or strengthen verification, publication or ranking authority;
- exact private provider coordinates, private evidence, raw contact data, credentials and reviewer-private notes remain protected;
- browser/Android clients do not receive privileged provider/database/payment/AI credentials;
- provider scope and consequential authorization remain backend-authoritative;
- synthetic fixtures cannot replace canonical state while claiming production functionality.
8. Phase 11/12 boundaries remain unchanged¶
VC1–VC8 completion does not clear:
- actual 11C–11H Zambia pilot evidence;
- evidence-backed 11J
PROCEED; - required Zambia legal/privacy/regulatory approvals and final live policy versions;
- production evidence/private-data readiness;
- end-to-end account deletion where required;
- production environment and backup restore;
- operational staffing/exercises;
- active production monitoring/escalation;
- real Play account/current-policy/signed-release controls;
- formal go/no-go/staged rollout;
- any production AI capability without provider/data/evaluation/security/monitoring/fallback/human-accountability approval.
9. Next execution rule¶
VC1–VC8 and RC1–RC9 are closed at their documented boundaries. RC8 closed on exact source ccc4e9463d810ddf554182b1607c22d3a7c8c8d3 through run 30241092949/1 and artifact 8643323319 (sha256:bbb4600eb5a062552947e91c878dd09c6d1e4dc307ae4783c7fa1fb4cf6e4935). RC9 implementation PR #497 passed its complete exact-head matrix on 04ef57f31414ec5165e353abba74afb8dfdcc901 and squash-merged to main@70de95c73128e921cd4d7c667de0e5a442a9e0c0.
RC10 is closed on implementation PR #502 exact head cdab6622e0cc06e35cddca2bb5bc8ea70c027b38, squash-merged at 620a99ba5465ad38ce012df0a8fa15e458de6505. RC11 closed through PR #505 exact head 66626d315a8d132dbf8f34749a2679e42c609d7c, squash-merged at 87f567fccfa92244c7951432436c7163c71d5fc7. Phase 11C–11J execution readiness implemented through PR #508 exact head ae4fcb0350be4023f82e2be8df88c18cca583695, squash-merged at 2bf58c2c5df40aa76742730ec4a49644c2506a89, and closed through PR #509 exact head 311937bc08770c3ab664f15b1896fc4d5ec2f40a, squash-merged at 1c32171ddc46c8f5c0e8176b2be14c4d4f4d355c. Wave 0 finishing-line controls implemented through PR #512 exact head 1befa902def70d2c997aaba260e0d8e2a5d4b12d, squash-merged at f561658d140aaf214fa6eaca99c80bcc98ee284f, and closed through PR #513 exact head 1e4291ef669ca01eb4f639b2f1734a85d8448a63, squash-merged at 632dd0bdbb2a3b8c24bd285918deff3e54bd3ba9. Technical preflight passed and P11-G14 is closed for the implementation source. The lane is released; P11-G01–P11-G13, real entry and all PRIMARY-PILOT evidence remain externally blocked.
This project status records repository/product completion truth only and does not imply production authorization beyond the explicitly evidenced integration and release boundaries.