Home / Admin / Comms: asks and steps

Comms: asks and steps

The state of play, kept on the site rather than in a chat message, in the manner of the sibling sites' comms pages. Numbered so a reply can refer to an item without quoting it.

Asks back to the project lead

The exact list, with who and which step waits on each, is docs/ops/needs.md; it is the source and this page points at it rather than copying it. In one line each, as of v0.1.1 (2026-10-05):

#AskBlocksStatus
N1Branch protection on dev and main with validate requiredsection 9.5; every release from here on arrives by pull requestOpen
N2Hardware-key 2FA for the organisation; sgit.ai verified as an organisation domain; the Actions policysection 9.5; the rows on /security/ say "unconfirmed"Open
N3A billing account, confirmed project ids, and the bootstrap run once the script existsstep 3Open
N4The Google OAuth client secret for sign-in, as the GitHub environment secret for devstep 3Open
N5Confirm the versioning decision: every release bumps the third digit; the second digit is reserved for a milestone you name (brief-corrections C15)nothing; recorded as decided on 2026-10-05Confirm
N6Confirm that documents are rendered at build time with the raw markdown one click away, rather than a client-side markdown viewer (C16)nothingConfirm
N0DNS, Pages with the custom domain and HTTPS, and the re-run of the v0.1.0 workflowstep 1Done, 2026-10-05

The build order, as it stands

Section 11 of the brief, one row per step, from data/steps.json. The planned version is what the brief wrote; releases bump the third digit, so the delivered version differs.

#StepPlanned asDelivered asStatusNote
T1The pipeline before the sitev0.1.0v0.1.0doneLive at secrets.sgit.ai on 2026-10-05; verify-live green.
T2Content pages, everything marked proposed; /shipped/; twins; llms.txt; sitemapv0.2.0v0.1.1doneThe documents are rendered to HTML as well; the family nav with grouped menus.
T3Bootstrap, Terraform, infra.yml, rules, environments.json with dev real; sign in against devv0.3.0openBlocked on the GCP items in needs.md (billing, project ids, bootstrap run, OAuth client secret).
T4PRF probe page; keyring v1 library with KATs; setup and unlock; recovery codev0.4.0openNot before step 3's probe pages are green on a real dev project.
T5Entries: kinds, vault list, entry page, copy and reveal, lock timers, mergev0.5.0open
T6Devices page; account export and import; meta.json; matrix pagev0.6.0open
T7Admin pages with fixes; rules.yml; new-environment.md timed on a fresh main projectv0.7.0openNot before step 6: the users page needs meta.json.
T8prod live; homepage demo real; security page final; acceptance test publishedv0.8.0open
T9Phase 2 data only: public bundle in directory/, inbox rules livev0.9.0opensgit pki import of the published bundle to verify.

Open questions carried from the brief

Listed and dated at the end of brief-corrections.md: the Playwright virtual authenticator and PRF, Google's implicit flow, the Security Rules syntax, where Identity Platform stores user records, and whether sgit pki import reads a browser-generated bundle.