Command Document
True Roadmap
Rendered as a real command-center page. Source notes remain in the repo for agents, but navigation uses pages and real files.
NyrA True Roadmap
Audited: 2026-07-15 America/New_York
This is the no-spin state of NyrA Swarm Little Buddy. The app is not sellable yet. The version number moved faster than the actual product. From here, a new alpha only counts if it removes a user-visible blocker and has proof from desktop, Android emulator, hosted alpha, or the physical phone.
What Is Going On
- Current package version:
0.1.0-alpha.83. - Android versionCode:
83. - Hosted alpha URL:
https://bridge.porterlabz.com. - Current hosted APK:
release/current/android/NyrA.apk. - Current hosted APK SHA256:
b92bbedcc86066f17edc620a105b04a6cdbd284b6d767abdb1b88ecfb07791b0. - Current local APK SHA256:
b92bbedcc86066f17edc620a105b04a6cdbd284b6d767abdb1b88ecfb07791b0. - Hosted/local status: the stable Worker deployment and durable R2 proof match the current local alpha83 APK byte-for-byte.
- Current production Worker version:
0c2d7713-8ac5-44cc-b90a-3922f17d3634. - Hosted update manifest proof: usable by phone, public APK route, checksum matched when last checked.
- Hosted support-log proof: passed when last checked.
- Desktop provider proof: 4/4 live provider catalogs and 131 compatible model entries; all eight benchmark categories route independently, task-scoped outcomes adapt the route, and the actual handling model is recorded per response.
- Hosted swarm proof: all eight task categories route independently; authenticated production smoke returned a clean answer, NyrA-only identity, 4/4 provider readiness, update metadata, support-log roundtrip, and durable D1 routing outcomes.
- Stable cloud bridge:
https://bridge.porterlabz.com; public sanitized routing policy is live and cacheable. - Release gate:
INTERNAL_ALPHA_ONLY. - Money/deploy gate:
NO_GO_LIVE_MONEY. - Command-center readiness: live-money deployability is 13%.
- Deployability blockers: 6 P0 and 1 P1.
- Physical phone proof:
PHONE_SELF_TEST_NEEDS_REVIEW; a passing physical-phone result is still missing. - Android emulator proof: 11/11 in-app self-test checks passed with 4/4 swarm routes, Phone Control ready, screen capture, and uploaded support evidence. A separate live control smoke passed text entry/clear, tap-by-text, Settings, Back, Home, Recents, and app recovery.
- Current bridge boundary: alpha83 records the stable
bridge.porterlabz.comWorker and downloads from R2 through the authenticated Worker route. - Current auth boundary: the APK is token-free and stores signed device credentials in Android Keystore; real customer checkout and second-device restore still need acceptance proof.
- Current hosted-learning boundary: production D1 retains seven days of tenant-scoped provider/model outcome metrics. Live proof persisted 11 outcomes across two isolated tenants without exposing tenant hashes or storing prompts, answers, email addresses, files, or secrets.
The blunt answer: the local desktop app has trustworthy proof for four-provider startup, adaptive model routing, answer-only presentation, voice playback, and multi-step visual mouse/keyboard control. Android control, token-free device activation, and the in-app self-test work in the emulator, but the physical-phone experience and real customer checkout/device restore are not proven, and the app is not sellable. The remaining product gap is carrying that proven baseline through physical-phone acceptance and a trusted customer release.
Why Version Churn Happened
Recent builds spent too much effort on delivery and evidence plumbing:
- APK packaging and hosted download routes.
- Update manifest checks.
- Support-log upload and readback.
- Command-center pages, CSVs, and workbook generation.
- Provider summary checks.
- Android build/rebuild scripts.
- Roadmap and launch docs.
Those are useful only after the core app works. They do not satisfy the product standard. Until NyrA behaves correctly on the phone and desktop, version numbers are noise.
What Actually Improved
- Android can build a signed internal alpha APK.
- Hosted alpha can serve an APK from a public route instead of a localhost-only link.
- Hosted update checks and support-log checks exist.
- The hosted bridge has seen all four providers configured.
- Typed chat can reach the hosted bridge when the bridge and token are valid.
- The UI has a Captain/Crew provider status surface.
- Android self-test/reporting code exists.
- Phone-control code paths exist for Android actions such as open app, back/home, and tap/type experiments.
- Alpha75 adds a native hidden-buddy recovery path so Hide Bot can have a real Show Bot path instead of depending on generic close behavior.
- Alpha76 replaces the one-shot automatic phone proof upload with an in-session retry loop so a cold bridge or temporary upload failure should not permanently prevent support-log evidence for that installed version.
- Desktop startup now refreshes a sanitized live benchmark policy from
bridge.porterlabz.com, validates every route, caches the newest valid evidence, and rejects failed or stale policies. - Normal desktop responses show only the answer with a compact model label. Routing rationale remains available on request or in diagnostics.
- Desktop adaptive routing no longer lets unrelated fast/chat history bias coding, research, creative, vision, agentic, or safety work. Live proof selected every current category winner, including Grok 4.5 for a real computer-use planning turn.
- A model-driven live control test used a screenshot, native mouse/keyboard actions, exact text entry, Submit, visible PASS verification, and a final completion response.
- Live desktop voice playback and response-presentation checks pass without overlapping route narration.
- Desktop, local bridge, and production Worker now share the same answer boundary: normal replies contain only the answer, routing detail remains available on request, and underlying providers speak only as NyrA.
- Hosted routing now uses the same eight task categories as desktop and prevents unrelated task outcomes from distorting the current task route.
- Production hosted routing now persists tenant-scoped outcome evidence in D1 across Worker isolates. Live checks proved one tester tenant could learn without changing another tenant's outcome count, and public status exposes no tenant hash or user content.
- Android now classifies emulator versus physical-device evidence explicitly, and evidence ingestion fails closed so an emulator cannot satisfy the physical-phone gate.
- Android Accessibility text entry now searches every interactive window, retains focused Chromium virtual-node events, marshals mutations to the main thread, and preserves the clipboard while using paste fallback when direct insertion is rejected.
- A fresh Android emulator install completed admin-tester setup without billing, reached all four swarm providers, passed 11/11 in-app phone checks, uploaded its support log, and passed direct control of text, tap, screen capture, Settings, Back, Home, and Recents.
What Is Still Broken Or Not Proven
- Phone support logs now reach the bridge. The latest evidence is a clean emulator result and is deliberately blocked from clearing physical-device acceptance.
- The app still appears as a black/blank foreground plane in cases where it should be a transparent floating buddy over the current phone screen.
- The user has seen duplicate bots. That means the foreground WebView and native overlay lifecycle are still not clean enough.
- Hide Bot, Close, Show Bot, reopen, and chat-panel state are not proven reliable on the physical phone.
- Mic/listening is not production quality. Trigger words, pause mode, wake behavior, and permission recovery need real validation.
- Phone control is proven end to end in the emulator for tap-by-text, type/clear, Settings, Back, Home, Recents, screen look, and app recovery. The same path still needs physical-phone evidence, including scroll and real app targets.
- Android alpha83 proves the same answer-first behavior in the emulator: one final answer with a compact top-left model label, with routing details only when requested.
- The APK points at the stable Worker without a bundled bridge token and uses device-bound credentials, but a real checkout and clean second-device restore are still unproven.
- Hosted adaptive routing now has durable tenant-scoped D1 evidence. Paid-customer identity continuity still depends on the unproven real checkout and second-device restore flow.
- The app cannot be sold while deployability is
NO_GO_LIVE_MONEY.
Hard Stop Rules
- No marketing, billing, legal, Stripe, or launch-site polish until core app behavior passes.
- No new version bump for docs-only changes.
- No new version bump unless the build fixes a user-visible app blocker.
- No claim that phone control works until physical phone evidence exists.
- No claim that swarm mind works unless runtime tests prove provider state, selected provider, fallback behavior, and current benchmark policy. Normal answers must not expose internal routing narration unless asked.
- No paid beta until test-mode checkout, Customer Portal, and clean second-device restore are proven end to end.
- No live-money launch while any P0 deployability blocker remains.
Product Definition
NyrA is supposed to be:
- A little buddy first, not a chat window first.
- One visible character, not duplicate overlays.
- Transparent around the character, not a black/white app plane.
- Always available, but not always interrupting.
- Trigger-word/listening aware, with pause and wake behavior.
- Able to act on the current device through approved OS permissions.
- Honest when Android/Windows blocks a capability.
- A Captain/Crew swarm mind that uses multiple AI providers, not just a single OpenAI-style chat box.
If a build does not move one of those bullets forward with proof, it should not be called progress.
Current Scorecard
| Area | Current state | Verdict |
|---|---|---|
| Android install | Builds an installable internal APK | Partial |
| Hosted download | Stable Worker/R2 route exists; installed alpha still needs customer-safe rebuild | Partial |
| Transparent buddy | Not proven; black plane still seen | Broken |
| Single buddy lifecycle | Alpha75 patch exists; physical phone not proven | Not proven |
| Typed chat | Works when bridge reachable | Partial |
| Voice/mic | Permission and realtime failures still seen | Broken |
| Phone control | Live emulator control and 11/11 in-app self-test pass; physical phone pending | Proven in emulator |
| Desktop control | Live model-driven screenshot, click, type, submit, and visible verification passed | Proven locally |
| Swarm mind | 4/4 live catalogs, desktop and hosted eight-category routing, tenant-scoped D1 outcomes, NyrA-only identity, clean answer boundary, live agentic winner probe | Proven for desktop/hosted internal alpha; Android parity pending |
| Logs/debugging | Emulator self-test log uploads and ingests honestly; no physical phone self-test log | Partial |
| Paid launch | 7 P0 deployability blockers | Blocked |
P0 Recovery Gates
1. Buddy-First Launch
Required behavior:
- Android starts with one visible NyrA buddy.
- Chat panel is hidden by default unless setup is needed.
- No duplicate bot appears.
- Tapping/right-clicking opens the panel.
- Hide Bot hides the buddy.
- Show Bot restores the buddy.
- Close closes the panel without killing the buddy unless hidden mode is active.
Evidence required:
- Emulator screenshot.
- Physical phone screenshot or uploaded phone self-test log.
test:surface-parity.test:android-buddy-overlay.
2. Real Transparent Buddy Mode
Required behavior:
- NyrA appears over the current phone screen.
- Background behind the buddy is transparent/system-overlay based, not a black or white app plane.
- Foreground setup screens are only used when setup is actually needed.
Evidence required:
- Physical phone proof showing another app behind NyrA.
- Android overlay lifecycle check.
- Visual proof attached to the command center.
3. Reliable Chat And Listening
Required behavior:
- Typed chat works even if voice is unavailable.
- Mic permission denial does not break the app.
- Listening uses trigger/wake behavior instead of responding to everything.
- "Pause listening" enters log/context mode until timer expiry,
NyrA wake, or user action. - Voice state is visible and honest.
Evidence required:
- Voice/manual smoke logs.
- Support log entries from the installed phone build.
test:mobile-runtime-bridge-status.
4. Phone Control That Actually Acts
Required behavior:
- NyrA can open apps, tap, type, Back, Home, Recents, scroll, and report screen context where Android allows it.
- If Android blocks restricted Accessibility permissions, NyrA explains the exact manual path and records the blocker.
- Controls are exposed in a tester panel until the model can call them reliably.
Evidence required:
- Physical phone self-test log.
- At least five successful phone actions from the physical phone.
test:android-phone-control.test:android-control:emulator-live.test:mobile-phone-self-test.
5. Real Captain/Crew Swarm Surface
Required behavior:
- Normal chat shows one final answer and the handling model as a compact top-left label.
- OpenAI, Anthropic, Gemini, and Grok readiness remains available in Settings/diagnostics.
- Internal Captain/Crew and route detail is shown only when the user asks for it.
- Provider failure degrades gracefully instead of
Failed to fetch. - The app can explain why it picked a model.
Evidence required:
test:nyra-swarm-council.- Hosted smoke proving a clean answer and NyrA identity, with handling-model attribution kept in response metadata rather than answer text.
- Main UI screenshot showing the clean answer and compact model label.
test:startup-intelligence:live,test:routing-policy:fallback:live, andtest:response-presentation:live.test:task-aware-routingandtest:task-aware-routing:live.
6. Desktop Parity
Required behavior:
- Desktop NyrA can see screen context, click, type, and continue tasks through the approved local automation path.
- Desktop and phone use the same action language.
- Desktop diagnostics are exportable.
Evidence required:
test:computer-use.test:computer-use:screen.test:computer-use:actions.- Desktop smoke screenshot.
7. Stable Cloud, Update, And Logs
Required behavior:
- Stable bridge domain, preferably
bridge.porterlabz.com. - R2 or equivalent durable APK hosting.
- No bundled shared alpha token for customer builds.
- Update button checks a stable manifest and verifies checksum.
- Phone logs upload to a place Codex can inspect.
Evidence required:
cloud:mobile-bridge:check.- Stable Worker URL saved in command center.
- R2 APK object saved.
- Phone self-test evidence ingested.
- Hosted update proof with stable domain.
Execution Roadmap
Phase 0: Truth Reset
Status: now.
Deliverable:
- This roadmap is the source of truth.
- Version bumps are frozen unless tied to app behavior proof.
- Hosted alpha proof must be refreshed when local APK hash changes.
Acceptance:
test:true-roadmap.test:product-roadmap.test:deployability-preflight.
Phase 1: Usability Recovery Build
Status: highest priority.
Deliverable:
- One-buddy Android and desktop app with reliable hide/show/close, transparent overlay, typed chat, and honest mic state.
Acceptance:
- Emulator proof.
- Desktop proof.
- Physical phone proof or phone self-test log.
- No duplicate-buddy state in support logs.
Phase 2: Physical Phone Evidence Loop
Status: next.
Deliverable:
- Installed phone can send redacted self-test logs automatically or from a button.
- Codex can read those logs without relying on screenshots.
Acceptance:
mobile-phone-self-test-evidence.jsonchanges fromNO_PHONE_SELF_TEST_LOGto a real physical-phone result.- The command center lists exact failed checks and next actions.
Phase 3: Phone Action Build
Status: after Phase 2.
Deliverable:
- NyrA can perform allowed phone actions and records exact action results.
Acceptance:
- Physical phone self-test shows at least five successful actions.
- Android restricted permission failures are reported clearly.
Phase 4: Real Swarm Build
Status: proven on local desktop and the hosted internal-alpha bridge; Android user-facing parity remains.
Deliverable:
- Adaptive Captain/Crew routing with one clean final answer, compact model attribution, and detail on request.
Acceptance:
- Each configured provider can be tested.
- UI shows available providers and chosen provider.
- Provider failure does not kill chat.
- Unrelated task history cannot distort another benchmark category.
- Normal answers contain no model, provider, scorecard, or route narration unless the user asks.
- Every provider presents one NyrA identity rather than its own assistant identity.
Phase 5: Stable Hosted Build
Status: stable Worker, durable R2 hosting, and tenant-scoped D1 routing evidence verified; paid-customer authentication continuity and physical-phone proof remain blocked.
Deliverable:
- Stable mobile bridge, durable APK hosting, stable update manifest, cloud support logs, customer-safe auth, and durable tenant-scoped routing evidence.
Acceptance:
- APK no longer points at a temporary tunnel.
- Shared alpha token is removed from customer builds.
- Phone logs arrive in the command center without screenshots.
- Adaptive routing state is tenant-scoped in Durable Objects/D1, or the hosted runtime makes no persistence claim.
Phase 6: Paid Beta Readiness
Status: hold.
Deliverable:
- Signed/store-trusted release, support/legal/privacy, Stripe, billing backend, customer portal, and final current screenshots.
Acceptance:
- Release candidate preflight has zero P0 blockers.
- Deployability is no longer
NO_GO_LIVE_MONEY. - A non-developer tester can install, launch, use, update, and export diagnostics.
Immediate Engineering Work
- Run the alpha81 physical-phone self-test and ingest the uploaded log; emulator evidence is already green but cannot clear this gate.
- Fix the first physical-phone failure, prioritizing transparent overlay and single-buddy hide/show/close lifecycle.
- Prove mic permission recovery, trigger-word listening, timed pause/log mode, and wake behavior on the physical phone.
- Prove at least five real phone-control actions and honest Android restriction handling.
- Replace the bundled shared mobile token with customer-safe account/device authentication.
- Produce a signed or store-trusted Windows build and rerun non-developer install/update/diagnostics acceptance.
Owner Split
Codex owns:
- Code fixes.
- Test scripts.
- Emulator verification.
- Desktop verification.
- Hosted alpha checks.
- Command-center evidence ingestion.
- APK and desktop builds.
- Turning phone logs into actionable bug fixes.
User owns:
- Installing the APK on the physical phone.
- Granting Android permissions that the OS requires manually.
- Providing screenshots only when the app cannot upload logs.
- Supplying stable cloud/account secrets when cloud deployment is ready.
Bottom Line
NyrA is an internal alpha with a proven desktop path and a now-working Android emulator control path, but it is not yet a dependable physical-phone or customer release. The path forward is not another version bump. It is physical-device proof of the buddy, transparency, listening, chat, logs, and actions, followed by customer-safe authentication and trusted release packaging.