# Release roadmap

> What works today, what comes next, and how we know it is ready.

## Milestone 01 · Connect an agent

**Local foundation implemented.** Workspaces, per-agent bearer credentials, authenticated MCP, and contact creation, retrieval, and search are available. Access control, duplicate candidates, retry protection, and audit attribution are covered by PostgreSQL feature tests.

**Still to verify:** the actual Hermes agent must create a contact through the deployed Forge endpoint, disconnect, reconnect, and retrieve it. An unauthorised caller must not be able to access it.

## Milestone 02 · A useful personal CRM

**Contact-management slice implemented locally:**

- Revision-aware contact updates and archive/restore, with idempotent retries and audit attribution.
- Name/email/phone search, reusable workspace tags, and tag discovery.
- CLI-managed typed custom-field definitions, discovery, explicit value patches, and scalar equality filters.

**Wider CRM implemented locally:**

- Organisations, projects, affiliations, and project participants.
- Append-only activity entries with source references and multiple record links.
- Tasks, active-contributor assignment, linked records, due-date filtering, and the complete claim-based lifecycle.
- Direct relationship filters and paginated contact/project briefs with source references and outstanding tasks.

PostgreSQL MCP feature tests cover the capture-and-project workflow and isolation boundaries. **Still to verify:** the same journey through the deployed service in a fresh real-agent session.

## Milestone 03 · Reliable shared use

**Implemented locally:**

- Atomic claims, renewal, release, expiry, reclaiming interrupted work, and outcome-backed completion.
- Paginated attempt history, claimable/unassigned searches, and allowlisted record sorting.
- Idempotency, revision conflicts, workspace isolation and audited archive/restore behaviour.
- A real two-process PostgreSQL race test demonstrating one claim winner.
- Consistent, credential-free administrator export with concurrent-write snapshot verification.
- Administrator activity redaction, including stored retry copies.

**Still to verify operationally:** a second real agent connection and handoff, deployed acceptance journeys, sustained shared-use load, automated production backups, monitoring and an isolated recovery rehearsal. These checks need the actual deployment and clients.

The first release is complete when the full acceptance checklist in `SCOPE.md` passes. A local foundation is not a claim of production readiness.

## Owner onboarding and agent access

**Implemented:** guided trusted-server installation with owner creation and an initial browser checklist, session sign-in and sign-out, a workspace overview, token creation/replacement/revocation with password confirmation, Hermes and generic MCP connection instructions, and the last accepted request for each current token. Existing CLI administration remains available. Account and workspace isolation, installation cancellation/validation and rejection of retired public setup, and credential lifecycle are covered by tests.

**Not implemented:** OAuth, MFA, email recovery/verification, additional workspace members and workspace switching. The live Hermes acceptance checks above still apply.

## Intentionally outside the release

Orbit will not add a CRM dashboard, embedded LLM, workflow engine, public signup, billing, or native email/calendar integrations in this release. A due task will not wake an agent or authorise an external action.

Documentation and the small owner interface support an agent-operated CRM; there is no contact/project management dashboard.
