Command Document
Product Roadmap
Rendered as a real command-center page. Source notes remain in the repo for agents, but navigation uses pages and real files.
NyrA Product Roadmap Truth
Generated: 2026-07-18T13:47:13.172Z
This is the blunt roadmap for NyrA Swarm Little Buddy. It intentionally separates "testable internal alpha" from "sellable product." Version numbers do not count as progress unless the build removes a user-visible blocker and the evidence proves it.
Current Verdict
- Product verdict: Internal alpha prototype. Not ready to sell.
- Current version: 0.1.0-alpha.83
- Release channel: INTERNAL_ALPHA_ONLY
- Release candidate gate: INTERNAL_ALPHA_ONLY, 58% ready
- Money/deploy gate: NO_GO_LIVE_MONEY, 20% ready
- Deployability blockers: 3 P0, 1 P1
- Handoffs: 3 user, 0 secret-store, 0 ready for Codex review
- Hosted alpha: HOSTED_ALPHA_READY at https://bridge.porterlabz.com
- Hosted alpha boundary: stable URL recorded; token bundled: no
- Hosted swarm providers: 4/4 ready (OpenAI: gpt-5.6-sol; Anthropic: claude-fable-5; Gemini: gemini-3.5-flash; Grok/xAI: grok-4.5)
- Latest concrete app fix: Alpha83 now proves the desktop swarm and autonomous control path: all eight task lanes have at least two live-qualified providers, and a real eight-lane runtime matrix executed fast, analysis, coding, grounded research, creative, screen-image, agentic, and safety requests through their current adaptive routes. Caller cancellation is now neutral instead of a provider failure; after removing that false penalty, vision returned to its live benchmark winner with zero fallback. A destructive request carrying a screenshot stayed in the safety lane on desktop, local hosted, and Cloudflare routes, closing a high-impact vision-priority gap. Normal replies keep only the answer plus model label, voice interruption has one playback owner, and Run Autopilot completes a changing two-stage visible mission. That mission entered an exact unique marker, re-observed a newly generated challenge, entered its code, clicked Verify, observed PASS, and stored a strictly verified run with 10 successful computer actions. Public checkout remains fail-closed until launch gates clear.
- Physical phone proof: PHONE_SELF_TEST_NEEDS_REVIEW
- Cloud deploy preflight: READY_FOR_CLOUDFLARE_DEPLOY
- Current model benchmark winner: gemini
- Desktop runtime: PROVEN_ON_LOCAL_DESKTOP; answer plus compact model label; routing details only on request or in diagnostics
- Autonomous desktop proof: Run Autopilot completed a changing two-stage visible task in 47 seconds; 10 successful computer actions; newly revealed challenge re-observed; visible PASS; mission ledger strictly verified
- Live task-aware routing: TASK_AWARE_ROUTING_LIVE_PASSED; 8/8 live lanes; 4/4 providers; 0 fallbacks; safety-with-image passed
- Cancellation-neutral routing: CANCELLATION_ROUTING_LIVE_PASSED; cancellation recorded as provider failure: no
- Routing policy: MODEL_BENCHMARK_COMPLETE, 4/4 providers, 8/8 tasks have qualified fallbacks, 1 weak provider-task attempts remain visible
Hard No-Go Rules
- Do not sell while deployability status is NO_GO_LIVE_MONEY.
- Do not call it paid beta while release status is INTERNAL_ALPHA_ONLY.
- Do not ship Android to customers while the APK points at a trycloudflare tunnel or bundles a shared alpha token.
- Do not market phone control as working until physical phone self-test evidence exists.
- Do not open paid beta until a real test-mode checkout, Customer Portal, and second-device restore roundtrip are recorded.
- Do not build more payment/marketing surface until the app usability recovery checklist is green.
- Do not treat provider availability as swarm success unless runtime tests prove routing and fallback behavior; do not dump internal routing narration into normal answers.
Next Build Must Be Engineering Only
No more marketing, legal polish, Stripe polish, or version churn until these app-level issues are green:
- No version bump unless it removes a user-visible app blocker.
- Android first launch reaches the buddy/chat experience without black blank screens.
- Only one bot is visible at a time unless the user intentionally opens foreground chat from the floating buddy.
- Foreground Activity and WebView remain transparent behind the NyrA figure.
- Hide Bot, Show Bot, Close, Settings, Voice, typed chat, and update controls work on phone.
- Mic permission denial leaves typed chat online and shows a clear fix path.
- Accessibility/Phone Control setup explains restricted settings and verifies connection.
- Normal replies show only the answer and a compact model label; provider routing detail appears only when requested or in Settings/diagnostics.
- OpenAI, Claude, Gemini, and Grok readiness is represented honestly; missing providers are not faked.
- Physical phone self-test can upload a redacted support log that Codex can ingest.
Immediate Queue
| Owner | Task | Evidence |
|---|---|---|
| Codex | Keep verified desktop and current Android runtime regressions green while customer and physical-phone proof is collected. | Focused desktop and Android regressions stay green without replacing the current hosted APK absent a new product blocker. |
| User + Codex | Prove customer checkout and device restore on 0.1.0-alpha.83 | Complete a Stripe test-mode checkout from a clean install, confirm webhook activation, open the Customer Portal, pair a second install, record restore evidence, and pass billing:live-rehearsal plus test:customer-device-activation. |
| User + Codex | Get one physical phone self-test support log uploaded and ingested. | mobile-phone-self-test-evidence.json status PHONE_SELF_TEST_PASSED. |
| User | Support inbox roundtrip and legal/accountant review. | supportInboxConfirmed=Yes and attorneyReviewStatus=Approved. |
Milestone Roadmap
| Phase | Name | Priority | Owner | Status | Deliverable | AcceptanceEvidence | Blocks |
|---|---|---|---|---|---|---|---|
| 0 | Truth reset | P0 | Codex | In progress | Stop version-only churn. Keep this roadmap, deployability, and release gates as the source of truth. | NYRA_PRODUCT_ROADMAP.md, nyra-product-roadmap.json, deployability-snapshot.json, release-candidate-preflight.json. | All future paid launch work. |
| 1 | App usability recovery build | P0 | Codex | Desktop proven; Android still P0 | Desktop stays a clean answer-first swarm workspace with restart-persistent, consent-gated memory; Android still needs transparent single-buddy lifecycle, reliable hide/show, honest mic flow, and typed chat proof. | test:response-presentation:live, test:startup-intelligence:live, test:task-aware-routing:live, test:adaptive-memory:runtime, test:privacy-consent-runtime, test:voice-playback:live, test:computer-action:multistep:live, test:autonomous-mission:live, emulator smoke, physical phone self-test. | Physical phone proof and paid beta readiness. |
| 2 | Phone control reliability | P0 | Codex + user phone evidence | Emulator proven; physical phone next | NyrA can open apps, tap text, type, Back/Home/Recents, screen-look, and report when Android restricted settings block Accessibility. | test:android-phone-control, test:android-control:emulator-live, test:mobile-phone-self-test, emulator support log, physical phone self-test support log, and phone control screenshots. | The core promise that NyrA can actually do things on the phone. |
| 3 | Stable mobile bridge | P0 | User + Codex | Durable bridge and token-free current-version APK proven | bridge.porterlabz.com Worker with R2 APK hosting, support-log storage, provider secrets, update manifest, ticketed APK download, and no bundled shared alpha token. | bridge.porterlabz.com health/policy checks, cloud:mobile-bridge:check, R2 object key saved, Android rebuilt against the stable bridge with tokenBundled=false. | Paid beta remains blocked by customer checkout/device-restore proof, physical-phone proof, and signed/trusted distribution. |
| 4 | Desktop parity | P0 | Codex | Local desktop capability proven; phone parity blocked | Desktop app can see screen, click, type, re-observe changed state, continue and verify multi-stage missions, remember stable preferences across restarts, export/delete its durable local data, expose swarm state, send diagnostics, and behave consistently with phone. | test:autonomous-mission:live, test:computer-action:multistep:live, test:startup-intelligence:live, test:task-aware-routing:live, test:adaptive-memory:runtime, test:privacy-consent-runtime, test:response-presentation:live, test:voice-playback:live, rendered desktop smoke screenshot. | Claiming same capability on phone and desktop. |
| 5 | Release trust and support | P0 | User + Codex | Blocked on signing/support/legal handoffs | Signed or store-trusted installer, support inbox roundtrip, legal review, privacy/terms/eula, support diagnostics with redaction review. | release:candidate:preflight has no P0 release blockers, support roundtrip confirmed, policy readiness approved, signing evidence captured. | Any paid beta install. |
| 6 | Money path | P0 | User + Codex | Blocked until product works | Stripe products/prices, hosted billing Worker, webhook, Customer Portal, license entitlement checks, test-mode rehearsal, then live-money preflight. | billing live rehearsal passed, payment launch pack cleared, deployability P0 blockers = 0. | Taking payments. |
| 7 | Marketing and launch assets | P1 | Codex | Hold until app UX is real | Screenshots, demo video, launch site, email/social/ad assets that match the shipping app. | Visuals final approved, demo video recorded against the shipping build, launch site connected to live checkout only after gates clear. | Public launch. |
What This Means
The durable bridge and current token-free Android package are proven. The next release work is real customer checkout/device-restore and physical-phone acceptance proof, not another deployment or rebuild.
Paid launch starts only after the app works, the current token-free APK is served by the stable bridge, customer checkout/device restore and phone proof exist, release trust is solved, support/legal are confirmed, and deployability has no P0 blockers.