Core Pilot v2.97 · Real-data Readiness Register

Real customer data starts only after evidence and approval.

This register turns the AgencyOS readiness boundary into seven visible gates. It shows evidence already present, work still required and the exact approval condition for each gate.

Approved gates0 / 7Evidence review: 2 September 2026
Current decision

Real customer data remains blocked.

Use fictional or masked, non-sensitive planning information only.

How to read gate status

In progress is not approval.

These definitions explain the fixed public labels. A gate changes only through an accountable evidence review; this guide does not approve one.

Back to approval sequence 4 approval phases · 7 gatesStarts with Define · Gates 1–2 of 7Ends with Approve · Gate 7 of 7Phase order: Define → Control → Operate → Approve
ApprovedCurrent gate count: 0
The stated pass condition has been met and accountable approval recorded.Back to readiness summary
Approval sequence

Define, control, operate, then approve.

Approval phase
Where a phase sits in the four-phase approval sequence.
Register position
Where a destination or phase range sits in the seven-gate readiness register.
Phase gate
Where a destination sits in its full phase.
Remaining gate
The order of later destinations listed for that phase.
Status
Current evidence and approval state, defined in the status guide above. Review status guide
Position meaning
Register order only, not completion or approval.
  1. DefinePhase 1 of 4Gates 1–2 of 7Scope and governanceStatus: In progress
  2. ControlPhase 2 of 4Gates 3–5 of 7Lifecycle, access and securityStatus: Open
  3. OperatePhase 3 of 4Gate 6 of 7Response and recoveryStatus: Open
  4. ApprovePhase 4 of 4Gate 7 of 7Named real-data tierStatus: Open
Gate 1 of 7
Phase: DefinePhase 1 of 4Phase gate 1 of 2Status: In progress

Data scope and classification

The pilot now explains its current input fields and prohibited data, clearly distinguishes all 17 owner download ready-action, ready-card, preparing-card, confirmed-success-card, failed-error-card, hovered-card, pressed-action, pressed-card, busy, non-busy disabled, keyboard-focus and focused-card states through action, pointer, full-card and dedicated focus feedback, gives their errors a full-width local failure panel, gives owners complete fixed guidance for those existing card states, makes the visible overall and per-group shown-of-total badges plus existing group-shortcut counts self-contained, gives the existing count labels exact singular and plural grammar, names the exact fixed Purpose and File format behind empty scoped-search and filter-only results, gives purpose and format clear actions visible fixed-selection context, aligns all Quick Find clear labels and their effective-query state, gives empty recovery exact active-filter counts and fixed-label guidance and associates its recovery controls with that visible guidance while retaining the established polite shown-of-total and empty-result statuses, but the comprehensive data scope has not been approved.

Evidence already present

  • v0.57 keeps an always-available Pilot Data Entry Guide above every signed-in workspace section.
  • v0.58 maps all 26 current user-facing input groups to purpose, minimum pilot entry, prohibited data and handling.

Still required

  • Confirm every planned customer-data category for the intended first real-data tier, including fields not yet built.
  • Name the accountable reviewers and record approval of one controlled, versioned scope.
  • Reconcile the approved scope with product copy, onboarding instructions and the legal-governance package.
Gate passes only when

An accountable review approves one comprehensive versioned data scope and every public and onboarding boundary matches it.

Gate 3 of 7
Phase: ControlPhase 2 of 4Phase gate 1 of 3Status: Open

Lifecycle controls

The owner can now download a bounded Pipeline summary, a bounded agency-wide register of complete saved enquiry briefs, one selected enquiry case file covering its saved quote and Operations family, separate selected-enquiry and agency-wide activity ledgers, bounded Team access and Agency settings ledgers, bounded agency-wide Operations and Quote registers, bounded agency-wide registers of complete saved quote revisions, quote rate snapshots, priced quote line items, quote itinerary days, Operations tasks and Operations manual payment records, bounded current Work Responsibility, Work Responsibility History and Work Status History registers, plus a content-minimized 14-family Data Retention inventory, a zero-inclusive 25-state Record State inventory and a zero-inclusive 25-action Event Action inventory. The 17 agency-wide downloads are grouped in one Owner Export Centre with a named region and focused controls destination both associated with complete fixed orientation guidance, the visible self-contained shown-of-total result count and, when filtered, the visible fixed active-scope summary, a transient local Quick Find and complete fixed interaction guidance, four fixed count-aware Quick Picks with complete fixed interaction guidance, three fixed visible-group focus shortcuts with fixed visible navigation guidance and destinations plus result regions associated with their existing visible group labels, shown-of-total counts, summaries and, when filtered, the visible fixed active-scope summary, one exact group-named return-to-controls action after each visible group with its fixed destination associated to the existing visible centre guidance, the visible self-contained shown-of-total result count and, when filtered, the visible fixed active-scope summary, a visible count-aware summary with complete fixed card-label guidance and a state-aware availability status that names the current result region, visible shown-of-total labels for each non-empty group, four local purpose views and three local file-format controls with visible fixed guidance, one local active-scope summary with three individual filter adjustments and reset-all recovery plus the same tailored recovery beside an empty result, and 17 programmatically named card groups described by their visible CSV/JSON and fixed data-coverage labels, with those labels also explicitly included in every download action's description before its existing detailed help and live status, the exact fixed contract filename shown inside that help region and repeated in a visually distinct existing live success state after browser file handoff, when the same action explicitly offers that download again, while an existing error alert changes that same action to an exact retry cue, plus one static pilot-data and complete downloaded-file handling notice, but these controls are not a complete retention, export, archive, deletion or closure programme.

Evidence already present

  • Pipeline, activity, quote, payment and access-history reads are bounded, and several record families have explicit capacity limits.
  • v0.80 lets the current owner download up to 500 minimized Pipeline summaries through a same-statement owner-and-tenant check, fixed private CSV contract and spreadsheet-formula neutralisation.
  • v0.81 lets the current owner download one selected enquiry's saved details, all bounded quote revisions, Operations tasks and manual payment records through owner-scoped bounded reads and a fixed private JSON contract; it excludes activity history and account, Team and internal record identifiers.
  • v0.82 lets the current owner download up to 500 newest-first saved activity entries for one selected enquiry through one indexed owner-and-tenant-scoped read and a fixed private JSON contract; it includes agency staff actor email and reviewed event summaries while excluding raw event details and internal record or membership identifiers.
  • v0.83 lets the current owner download up to 2,000 saved activity entries across the agency's enquiry ledger through one indexed owner-and-tenant-scoped read and a fixed private JSON contract; it groups reviewed entries by enquiry title, fails complete-or-none above capacity, and excludes raw event details and internal record or membership identifiers.
  • v0.84 lets the current owner download the agency's current Team access, live invitations and up to 500 reviewed access-history events through indexed owner-and-tenant-scoped reads and a fixed private JSON contract; it fails complete-or-none above capacity and excludes raw event details plus internal account, membership and event identifiers.
  • v0.85 lets the current owner download the agency's current identity and saved new-record defaults plus up to 500 reviewed settings-history events through one indexed owner-and-tenant-scoped read and a fixed private JSON contract; it fails complete-or-none above capacity, includes changed field names rather than historical values the audit model does not store, and excludes internal agency, account, membership and event identifiers.
  • v0.86 lets the current owner download up to 500 current agency-wide Operations summaries through one owner-and-tenant-scoped read using the existing Operations, task and payment indexes and a fixed private JSON contract; it includes accepted quote totals, task-status counts and non-void manual payment and refund totals, fails complete-or-none above capacity, and excludes task and payment details, staff identities and internal identifiers.
  • v0.87 lets the current owner download up to 500 current agency-wide quote summaries through one owner-and-tenant-scoped read using the existing quote-status/update and current-revision indexes and a fixed private JSON contract; it includes overall quote and current-revision state, validity, currency and manual grand total, fails complete-or-none above capacity, and excludes detailed quote content, staff identities and internal identifiers.
  • v0.88 lets the current owner download up to 500 complete saved enquiry briefs across the agency through one owner-and-tenant-scoped read using the existing newest-first enquiry index and a fixed private JSON contract; it includes planning dates, budgets, next actions and saved notes, fails complete-or-none above record or file capacity, and excludes staff and account identities, responsibility, activity, quotes, Operations, payments and internal identifiers.
  • v0.89 lets the current owner download up to 500 quotes and 500 complete saved quote revisions across the agency through one owner-and-tenant-scoped read using the existing quote, enquiry and revision indexes and a fixed private JSON contract; it includes client summaries, pricing settings and totals, inclusions, exclusions and notes, fails complete-or-none above record or file capacity, and excludes line items, rate snapshots, itinerary days, staff identities and internal identifiers.
  • v0.90 lets the current owner download up to 500 quotes, 500 revisions and 3,500 complete saved rate snapshots across the agency through one owner-and-tenant-scoped read using the existing quote, enquiry, revision and rate indexes and a fixed private JSON contract; it includes exact stored ratios, readable rates, source labels and capture times, fails complete-or-none above record or file capacity, and excludes priced line items, itinerary days, staff identities and internal identifiers.
  • v0.91 lets the current owner download up to 500 quotes, 500 revisions and 12,500 complete saved priced line items across the agency through one owner-and-tenant-scoped read using the existing quote, enquiry, revision, item and rate indexes and a fixed private JSON contract; it includes category, descriptions, quantities, source and converted amounts and saved converted subtotals, verifies every saved conversion and subtotal, fails complete-or-none above record or file capacity, and excludes rate-snapshot details, itinerary days, staff identities and internal identifiers.
  • v0.92 lets the current owner download up to 500 quotes, 500 revisions and 15,000 complete saved itinerary days across the agency through one owner-and-tenant-scoped read using the existing quote, enquiry, revision and itinerary indexes and a fixed private JSON contract; it includes position, optional date, title, optional location and optional details, preserves revisions with no itinerary days, fails complete-or-none above record or file capacity, and excludes priced line items, rate snapshots, pricing, staff identities and internal identifiers.
  • v0.93 lets the current owner download up to 500 Operations records and 25,000 complete saved tasks across the agency through one owner-and-tenant-scoped read using the existing Operations, enquiry, quote and task indexes and a fixed private JSON contract; it includes task title, category, status, optional due date and notes, assigned-or-unassigned state and timestamps, preserves Operations records with no tasks, fails complete-or-none above record or file capacity, and excludes staff identities, manual payment details, activity history and internal identifiers.
  • v0.94 lets the current owner download up to 500 Operations records and 50,000 complete saved manual payment and refund records across the agency through one owner-and-tenant-scoped read using the existing Operations, enquiry, quote and payment-record indexes and a fixed private JSON contract; it includes kind, amount, currency, occurrence date, method, optional reference and notes, recorded-or-voided state, timestamps and optional void reason, preserves Operations records with no manual records, fails complete-or-none above record or file capacity, and excludes staff identities, Operations tasks, activity history and internal identifiers.
  • v0.95 lets the current owner download the complete current responsibility state for up to 500 enquiries, 500 Operations records and 25,000 Operations tasks through batched owner-and-tenant-scoped reads using the existing enquiry, Operations, quote and task indexes and a fixed private JSON contract; it maps assigned work to the stored approved pilot staff email and available-or-needs-reassignment state, preserves unassigned work and Operations records with no tasks, fails complete-or-none above record or file capacity, and excludes notes, budgets, pricing, payments, creator identities, activity history and internal identifiers.
  • v0.96 lets the current owner download the complete saved initial responsibility state and responsibility-change history for up to 500 enquiries, 25,000 Operations tasks and 50,000 events through one owner-and-tenant-scoped read using the existing activity, enquiry and task indexes and a fixed private JSON contract; it maps prior and next saved responsibility references to approved pilot staff email, includes the agency staff actor email and current minimized work titles, proves one initial state per current record, fails complete-or-none above record, event or file capacity, and excludes notes, budgets, pricing, payments, non-responsibility activity and internal identifiers.
  • v0.97 lets the current owner download the complete saved initial status state and status-change history for up to 500 enquiries, 25,000 Operations tasks and 50,000 events through one owner-and-tenant-scoped read using the existing activity, enquiry and task indexes and a fixed private JSON contract; it includes exact prior and next saved status, agency staff actor email and current minimized work titles, proves one initial state and a continuous lifecycle through each current saved status, fails complete-or-none above record, event or file capacity, and excludes notes, budgets, pricing, payments, responsibility identities, non-status activity and internal identifiers.
  • v0.98 lets the current owner download one content-minimized inventory covering all 14 current saved AgencyOS record families through one owner-and-tenant-scoped read and a fixed private JSON contract; it reports each family's exact count, explicit retention-anchor basis and coherent oldest and newest anchor times, keeps empty families explicit, repeats the owner-role check before release, and excludes customer, trip, quote, payment, task and activity content, staff and customer identities, internal identifiers, retention periods and every archive, deletion, legal-hold or closure action.
  • v0.99 lets the current owner download one content-minimized inventory covering all 25 valid current states across six stateful AgencyOS record families through one owner-and-tenant-scoped read and a fixed private JSON contract; it reports exact zero-inclusive state counts, creation-age anchors and reconciled family totals, fails closed on unknown or incoherent states, repeats the owner-role check before release, and excludes business-record content, identities, internal identifiers, state history, retention periods and every archive, deletion, legal-hold or closure action.
  • v1.00 lets the current owner download one content-minimized inventory covering all 25 valid saved actions across three append-only AgencyOS history families through one owner-and-tenant-scoped read and a fixed private JSON contract; it reports exact zero-inclusive action counts, event-time anchors and reconciled family totals, fails closed on unknown or incoherent actions, repeats the owner-role check before release, and excludes event details, summaries, changed fields, identities, business-record content, internal identifiers, retention periods and every archive, deletion, legal-hold or closure action.
  • v1.01 groups the 17 existing agency-wide owner downloads behind one collapsed, keyboard-operable centre with three purpose labels; opening it runs nothing and changes no export scope, capacity, access check, storage or lifecycle decision.
  • v1.02 adds a local Quick Find across the fixed 17-item owner export catalogue; normalized literal tokens preserve catalogue order, empty results have explicit clear recovery, hidden controls remain mounted, typing sends no request and writes no query to database or browser persistence, and no export contract or lifecycle decision changes.
  • v1.03 adds four local purpose views to the fixed owner export catalogue; All, Records, Accountability and Lifecycle evidence expose honest fixed counts, compose with Quick Find, keep hidden controls mounted, write no preference and change no export contract or lifecycle decision.
  • v1.04 adds three local file-format controls to the fixed owner export catalogue; All formats, CSV and JSON expose exact counts within the selected purpose, compose with purpose and Quick Find, keep hidden controls mounted, write no preference and change no export contract or lifecycle decision.
  • v1.05 adds one local active-scope summary to the fixed owner export catalogue; it names the selected purpose and format plus whether Quick Find is active without echoing query text, provides one reset action, writes no preference and changes no export contract or lifecycle decision.
  • v1.06 adds one visible file-format label to each fixed owner export card; all 17 labels derive from the existing catalogue, contain only CSV or JSON, remain non-interactive and change no export contract or lifecycle decision.
  • v1.07 adds one informational handling notice before the fixed owner export catalogue; it states the fictional-or-masked data boundary and the owner's downloaded-file responsibilities, contains no record content, starts no action and changes no export contract or lifecycle decision.
  • v1.08 adds one visible fixed coverage label to each owner export card; labels derive from the existing catalogue, extend only local Quick Find matching, contain no record content and change no export contract or lifecycle decision.
  • v1.09 adds four fixed local Quick Picks to the owner export catalogue; Quotes, Tasks, History and Inventory expose counts within the selected purpose and format, toggle only the existing local query, write no preference and change no export contract or lifecycle decision.
  • v1.10 adds one visible shown-of-total label to each owner export group; all three labels derive from the same filtered catalogue, contain no record content and change no export contract or lifecycle decision.
  • v1.11 adds three fixed local shortcuts to visible owner export groups; each exposes the existing visible count, focuses only its matching heading, writes no URL or preference and changes no export contract or lifecycle decision.
  • v1.12 adds one fixed local return-to-controls action after each visible owner export group; every action focuses the same visible catalogue heading, changes no filter or URL state and changes no export contract or lifecycle decision.
  • v1.13 adds three local active-filter adjustments to the owner export scope summary; each appears only for its active purpose, format or Quick Find dimension, clears only that dimension, preserves the other filters, writes no URL or preference and changes no export contract or lifecycle decision.
  • v1.14 adds tailored local recovery beside an empty owner export catalogue; active purpose, format and Quick Find dimensions expose only their existing clear actions, reset-all remains available, no query text is repeated, no URL or preference is written and no export contract or lifecycle decision changes.
  • v1.15 adds fixed visible titles and help for the owner export Purpose and File format groups; each is associated with its existing local controls, contains no record content, writes no URL or preference and changes no export contract or lifecycle decision.
  • v1.16 adds one visible owner export results summary and names the existing result region; the shown count derives from the fixed catalogue, no second live announcement is added, no record content or preference is stored and no export contract or lifecycle decision changes.
  • v1.17 adds fixed visible guidance around the existing owner export group shortcuts; the guidance is associated with the same local controls, contains no record content, writes no URL or preference and changes no shortcut, export contract or lifecycle decision.
  • v1.18 expands the fixed visible guidance for the existing owner export Quick Picks; it explains their existing fill, toggle-clear and scoped-count behavior, is associated with the same local controls, contains no record content, writes no URL or preference and changes no Quick Pick, export contract or lifecycle decision.
  • v1.19 expands the fixed visible guidance for the existing owner export Quick Find; it explains its existing live matching, selected-scope, safe-term and clear behavior, remains associated with the same local input and result region, repeats no entered query, writes no URL or preference and changes no search, export contract or lifecycle decision.
  • v1.20 expands the fixed visible orientation for the existing Owner Export Centre; it explains that local controls only narrow the catalogue, filtering never starts a download and one matching card action remains deliberate, is associated with the same local centre, contains no record content, writes no URL or preference and changes no filter, export contract or lifecycle decision.
  • v1.21 expands the fixed visible guidance in the existing owner export handling notice; it adds a pre-download authorised-use check, retains secure, share and delete responsibilities, states that AgencyOS does not manage the downloaded copy, is associated with the same local note, contains no record content, records no download and changes no export contract or lifecycle decision.
  • v1.22 expands the fixed visible guidance for the existing owner export result cards; it explains their existing file-format and data-coverage labels before the deliberate download action, remains associated with the same local result region, contains no record content, writes no URL or preference and changes no card, export contract or lifecycle decision.
  • v1.23 adds one visible state-aware status to the existing owner export results summary; it distinguishes all-download save pauses, some-download unsaved-work pauses and the clear state from existing local workspace flags, remains associated with the same result region, contains no record content, sends no request and changes no disabled state, export contract or lifecycle decision.
  • v1.24 programmatically groups each of the 17 existing owner export cards; every group name derives from the fixed catalogue and its description points to the card's existing visible file-format and data-coverage labels, while hidden state, card order, controls, requests and lifecycle decisions remain unchanged.
  • v1.25 extends each of the 17 existing owner export download buttons' accessible description with its card's visible file-format and data-coverage labels before the control's existing detailed help and live status, while requests, disabled states, visual layout and lifecycle decisions remain unchanged.
  • v1.26 shows the exact fixed filename already enforced by each of the 17 existing owner export contracts inside that action's existing help region; every preview uses the same imported constant, wraps on narrow cards and changes no file, request, permission or lifecycle decision.
  • v1.27 appends that same exact fixed contract filename to each of the 17 existing owner export live success messages after the existing validated browser file handoff; every current count summary, error path, file, request, permission and lifecycle decision remains unchanged.
  • v1.28 gives each of those 17 existing live regions one local idle, success or error presentation state; the unchanged count-and-filename confirmation receives a readable success panel, the existing error alert retains precedence, the empty idle region remains hidden and no message, request, file, permission or lifecycle decision changes.
  • v1.29 changes each of those 17 existing action labels to the same download name followed by ‘again’ only while its existing local success string remains set after a validated browser file handoff; preparing, idle and error labels, every request, file, permission and lifecycle decision remain unchanged.
  • v1.30 changes each of those 17 existing action labels to the same exact download name prefixed by Retry only while its existing local error alert is present; the complete error stays visible, preparing, idle and successful-repeat labels retain precedence as designed, and no handler, request, file, permission or lifecycle decision changes.
  • v1.31 gives each of those 17 existing owner export error states one calm, readable full-width failure panel; the unchanged complete alert retains its alert role, live semantics and precedence, the exact Retry cue stays beside it, and no message, handler, request, file, permission or lifecycle decision changes.
  • v1.32 gives each of those 17 existing owner export busy wrappers one clear warm preparing treatment; the unchanged disabled action keeps its exact Preparing CSV or Preparing JSON label and aria-busy state, ordinary disabled controls remain muted, and no message, handler, request, file, permission or lifecycle decision changes.
  • v1.33 distinguishes each of those 17 existing owner export disabled controls through its existing busy attribute; an actively preparing action retains the wait cursor and warm treatment, a non-busy disabled action uses a not-allowed cursor while remaining muted, visible availability guidance remains the non-pointer explanation, and no disabled rule, message, handler, request, file, permission or lifecycle decision changes.
  • v1.34 gives each of those 17 existing owner export cards one restrained non-busy disabled treatment through its already-rendered wrapper and button relationship; the neutral card surface, inset marker and matching fixed labels remain distinct from the warm preparing treatment, visible availability guidance remains the explanation, and no disabled rule, message, handler, request, file, permission or lifecycle decision changes.
  • v1.35 gives each of those 17 existing owner export download buttons one dedicated solid teal focus ring through its existing class and visible keyboard-focus state; ready, retry and repeat labels share the same unobscured treatment, native disabled actions remain unfocusable, and no disabled rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.36 gives each of those 17 existing owner export download buttons one restrained teal non-busy enabled treatment through its already-rendered wrapper and native button state; ready, retry and repeat labels share the same pointer and hover feedback, warm preparing, muted paused and visible keyboard-focus states remain distinct, and no disabled rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.37 gives each of those 17 existing owner export download buttons one restrained pressed treatment through its already-rendered wrapper, native button state and browser active state; ready, retry and repeat labels share the same deeper teal surface and inset cue during activation, warm preparing, muted paused and visible keyboard-focus states remain distinct, and no disabled rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.38 gives each of those 17 existing owner export cards one restrained focused treatment through its already-rendered programmatic group, fixed labels, download-button class and browser visible-focus state; the complete download surface, file-format label and data-coverage label share one soft teal context while the solid button ring remains primary, ready, retry and repeat labels receive the same treatment, and no focus rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.39 gives each of those 17 existing owner export cards one restrained hovered treatment through its already-rendered programmatic group, fixed labels, download-button class and browser hover state; the complete download surface, file-format label and data-coverage label share one soft teal context while focused-card feedback remains stronger, ready, retry and repeat labels receive the same treatment, and no action rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.40 gives each of those 17 existing owner export cards one restrained pressed treatment through its already-rendered programmatic group, fixed labels, download-button class and browser active state; the complete download surface, file-format label and data-coverage label share one deeper teal context while the established button feedback remains immediate and focused-card feedback remains primary, ready, retry and repeat labels receive the same treatment, and no action rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.41 gives each of those 17 existing owner export cards one restrained confirmed-success treatment through its already-rendered programmatic group, fixed labels and existing local live-region success state; the complete download surface, file-format label and data-coverage label share one calm green-teal context after the validated browser file handoff, while hover, pressed and focused-card feedback remain primary, and no confirmation text, action rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.42 gives each of those 17 existing owner export cards one restrained failed-error treatment through its already-rendered programmatic group, fixed labels and existing local live-region error state; the complete download surface, file-format label and data-coverage label share one calm red-tinted context beside the unchanged complete alert and exact retry action, while hover, pressed and focused-card feedback remain primary, and no error text, alert semantic, action rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.43 gives each of those 17 existing owner export cards one restrained preparing treatment through its already-rendered programmatic group, fixed labels and existing busy wrapper state; the complete download surface, file-format label and data-coverage label share one warm context while the unchanged disabled action keeps its exact Preparing CSV or Preparing JSON label, wait cursor and solid focus ring, and no state rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.44 gives each of those 17 existing owner export cards one restrained ready treatment through its already-rendered programmatic group, fixed labels, existing non-busy wrapper and enabled action state; the complete download surface, file-format label and data-coverage label share one subtle ready context while confirmed success, failed error, hover, press, visible focus, paused and preparing treatments retain priority, and no state rule, label, message, handler, request, file, permission or lifecycle decision changes.
  • v1.45 expands the existing fixed visible owner export results help with complete card-state guidance; it explains ready, paused, preparing, confirmed-success, failed-error, hover, press and keyboard-focus meanings beside the unchanged live availability status, contains no entered or record content, adds no live region or control and changes no state, request, file, permission or lifecycle decision.
  • v1.46 expands the existing visible owner export shown-of-total badge from a count fragment to the self-contained wording ‘x of 17 owner downloads shown’; it continues to derive only from the unchanged local catalogue and describe the named result region, the existing Quick Find status remains the established polite shown-of-total announcement, the separate availability and empty-result statuses retain their exact meanings, and no state, live region, handler, request, file, permission or lifecycle decision changes.
  • v1.47 gives the existing owner export count labels exact singular and plural grammar; Purpose and File format buttons use download or downloads, Quick Picks use match or matches, and the established polite Quick Find scope status uses download or downloads from the unchanged local counts, including the real one-item CSV and Tasks paths, while no state, live region, handler, request, file, permission or lifecycle decision changes.
  • v1.48 makes each existing owner export group-shortcut description self-contained by naming the counted item as download or downloads; the fixed Records, Accountability and Lifecycle evidence shortcuts continue to appear only for groups with matches, keep the same visible number and focus action, and derive the noun only from the unchanged local visible-group count, including real one-item CSV, Tasks and Event action paths, while no state, live region, control, handler, request, file, permission or lifecycle decision changes.
  • v1.49 expands each existing visible owner export group shown-of-total badge from ‘x of y shown’ to ‘x of y downloads shown’; the Records, Accountability and Lifecycle evidence badges continue to derive from the same unchanged local visible and fixed catalogue totals, retain their more specific accessible descriptions and compact layout, and change no group visibility, state, live region, control, handler, request, file, permission or lifecycle decision.
  • v1.50 gives the existing empty owner export result heading exact scope context; a Quick Find with no Purpose or File format constraint keeps ‘No owner downloads match that search’, a Quick Find combined with either existing scope control says ‘No owner downloads match that search within the selected scope’, and a filter-only empty result keeps its established wording, without echoing entered text or changing any query, filter, recovery action, state, live region, request, file, permission or lifecycle decision.
  • v1.51 gives both existing owner export purpose and format clear actions visible fixed-selection context in the active scope summary and zero-result recovery; the visible and programmatic labels now say ‘Clear purpose: [fixed purpose]’ or ‘Clear format: [fixed format]’, while Quick Find keeps its fixed non-echoing label and every existing condition, handler, focus return, result target, state, live region, request, file, permission and lifecycle decision remains unchanged.
  • v1.52 aligns all three existing owner export Quick Find clear buttons on the exact name ‘Clear Quick Find’; the inline search clear now uses the same capitalization, the active scope and empty recovery programmatic names no longer add ‘filter’, and no entered query, condition, handler, focus return, result target, state, live region, request, file, permission or lifecycle decision changes.
  • v1.53 aligns the inline owner export Quick Find clear action with the existing effective normalized query state; whitespace-only input no longer shows that action while the unchanged 17-item catalogue, counts and scope summary remain unfiltered, meaningful queries keep their applicable existing clear actions, and no normalization, matching, handler, focus return, result target, state, live region, request, file, permission or lifecycle decision changes.
  • v1.54 gives the empty owner export recovery guidance exact active-filter count grammar; one effective Purpose, File format or Quick Find filter receives singular wording, combined scope names two or three active filters from the existing fixed selections and normalized-query boolean, whitespace-only input is not counted, entered text is never repeated, and no filter, matching, heading, recovery action, state, live region, request, file, permission or lifecycle decision changes.
  • v1.55 associates the existing empty owner export recovery group with both its visible result heading and count-aware instruction; the instruction receives one stable identifier, the group references both identifiers in reading order, the existing polite status remains the sole announcement, entered text is never repeated, and no visible copy, filter, matching, recovery action, state, live region, request, file, permission or lifecycle decision changes.
  • v1.56 associates the existing active owner export adjustment group with both its visible scope title and fixed selection summary; the summary receives one stable identifier, the group references both identifiers in reading order, Quick Find remains only Active or Not used and entered text is never repeated, and no visible copy, filter, handler, focus return, state, live region, request, file, permission or lifecycle decision changes.
  • v1.57 extends the existing empty owner export recovery group's description from its result heading and count-aware instruction to the visible active-scope title and fixed selection summary; the group references all four identifiers in reading order, Quick Find remains only Active or Not used and entered text is never repeated, and no visible copy, filter, handler, focus return, recovery action, state, live region, request, file, permission or lifecycle decision changes.
  • v1.58 aligns the active owner export scope summary's visible term from ‘Format’ to the established ‘File format’ heading; both adjustment and empty-recovery groups continue to reference that fixed selection summary, active format values and every clear/reset handler stay unchanged, Quick Find remains only Active or Not used and entered text is never repeated, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.59 aligns both existing owner export format clear actions from ‘Clear format: [fixed format]’ to ‘Clear file format: [fixed format]’; the active-scope adjustment and empty-recovery groups keep the same fixed selected value, condition, clear handler, all-format focus return and result target, Purpose and Quick Find labels stay unchanged, entered text is never repeated, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.60 replaces the generic ‘in selected purpose’ suffix in every owner export file-format choice's accessible count with the exact fixed active purpose label; all-downloads, Records, Accountability and Lifecycle evidence contexts derive only from the existing fixed selection, every visible label, count, pressed state and handler stays unchanged, Quick Pick and entered-query handling remain unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.61 replaces the generic ‘in selected purpose and file format’ suffix in every owner export Quick Pick's accessible match count with the exact fixed active Purpose and File format labels; all four Purpose labels and all three File format labels derive only from the existing fixed selections, every visible label, count, pressed state, disabled state and handler stays unchanged, entered-query handling remains unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.62 makes every owner export Purpose choice's visible and accessible download count derive from the existing fixed active File format and names that exact format in the accessible label; All formats retains 17, 7, 7 and 3, CSV yields 1, 1, 0 and 0, JSON yields 16, 6, 7 and 3, fixed group totals and every choice, pressed state and handler remain unchanged, and no result filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.63 extends the existing visible owner export Purpose help to state that its counts reflect the selected File format and the existing File format help to state that its counts reflect the selected Purpose; both control groups keep the same visible titles and aria-describedby associations, every count, choice, pressed state, handler and result stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.64 replaces the generic selected-scope wording in the visible owner export Purpose and File format help with the exact fixed active reciprocal labels; Purpose help names All formats, CSV or JSON, File format help names All downloads, Records, Accountability or Lifecycle evidence, both groups keep the same titles and aria-describedby associations, every count, choice, pressed state, handler and result stays unchanged, entered Quick Find text and record content remain excluded, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.65 extends both visible owner export reciprocal filter-help lines to explain that choices showing 0 remain available for adjusting the other fixed filter; genuine zero-count Purpose and File format choices keep the same enabled state, pressed state, handler and exact active reciprocal context, the established empty-result guidance and every recovery action stay unchanged, entered Quick Find text and record content remain excluded, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.66 extends the existing visible owner export Quick Picks help to explain that an unselected pick showing 0 is unavailable in the selected Purpose and File format scope while an active zero-count pick remains available for clearing; all four fixed Quick Picks keep the same count, pressed state, disabled condition, handler and exact fixed scope label, Quick Find focus and results remain unchanged, entered query and record content remain excluded, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.67 replaces the generic selected-scope sentence in the visible owner export Quick Picks help with the exact fixed active Purpose and File format labels; the help names one of four established Purpose values and one of three established File format values while preserving its v1.66 zero-count explanation, all four Quick Picks keep the same count, pressed state, disabled condition, handler and exact accessible scope label, Quick Find focus and results remain unchanged, entered query and record content remain excluded, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.68 replaces the generic selected-scope wording in the visible owner export Quick Find help with the exact fixed active Purpose and File format labels and states that clearing Quick Find restores that exact scope; the help names one of four established Purpose values and one of three established File format values, the entered query and record content remain excluded, every query limit, normalisation rule, match, count, input, handler, focus return, result and recovery action stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.69 replaces the generic current-choice wording in the visible owner export results help with the exact fixed active Purpose and File format labels plus the fixed Active or Not used Quick Find state; the labels come from the four established Purpose values and three established File format values, the state reveals only whether an effective query exists, entered query text and record content remain excluded, every query limit, normalisation rule, match, count, input, handler, result filter, catalogue order, card, recovery action and download stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.70 replaces the generic selected-scope wording in the empty owner export search-result heading with the exact fixed active Purpose and File format labels; the heading names one of four established Purpose values and one of three established File format values only when an effective query and a Purpose or File format filter produce no result, search-only and filter-only headings remain unchanged, entered query text and record content remain excluded, every query limit, normalisation rule, match, count, input, handler, result filter, catalogue order, card, recovery action and download stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.71 replaces the generic filter-only empty owner export heading with the exact fixed active Purpose and File format labels; the heading names one of four established Purpose values and one of three established File format values when fixed filters without an effective query produce no result, search-only and scoped-search headings remain unchanged, entered query text and record content remain excluded, every query limit, normalisation rule, match, count, input, handler, result filter, catalogue order, card, recovery action and download stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.72 extends the existing count-aware empty owner export recovery guidance with the exact fixed active filter labels; one active dimension names its established Purpose value, File format value or Quick Find label, two or three active dimensions retain the exact count and list those same labels in control order, whitespace-only input stays inactive, entered query text and record content remain excluded, every heading, query limit, normalisation rule, match, count, input, handler, result filter, catalogue order, card, recovery action and download stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.73 replaces the compressed live owner export shown-of-scope wording with the exact fixed Purpose and File format labels plus the fixed Active or Not used Quick Find state; the denominator continues to derive only from the selected Purpose and File format while the shown count continues to reflect the effective Quick Find result, singular and plural owner-download grammar remains exact, entered query text and record content remain excluded, every query limit, normalisation rule, match, count, input, handler, result filter, catalogue order, card and download stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.74 replaces the generic currently-shown wording in the visible owner export group-navigation help with the exact fixed active Purpose and File format labels plus the fixed Active or Not used Quick Find state; the associated shortcut group keeps that help as its description, entered query text and record content remain excluded, all three shortcuts retain the same visible-result condition, exact singular or plural count, result target and focus action, every card and download stays unchanged, and no filter, state, live region, request, file, permission or lifecycle decision changes.
  • v1.75 aligns each of the three existing visible owner export return-to-controls labels with its exact established accessible name by adding the fixed originating Records, Accountability or Lifecycle evidence group; every action remains inside the same visible group, scrolls to and focuses the same fixed catalogue heading, preserves Purpose, File format and Quick Find state, changes no result, card or download, and adds no filter, state, live region, request, file, permission or lifecycle decision.
  • v1.76 associates the existing owner export controls heading focused by all three return actions with the two existing visible fixed guidance paragraphs; the focused destination now carries the established catalogue-orientation and file-boundary descriptions while the centre region retains them, no new copy or live announcement is added, every exact return label, focus action, filter, result, card and download stays unchanged, and no state, live region, request, file, permission or lifecycle decision changes.
  • v1.77 extends the existing focused owner export controls destination with the visible active catalogue scope title and fixed selection summary only when the catalogue is filtered; the association names the established fixed Purpose and File format values plus Quick Find as Active or Not used without repeating entered text, the unfiltered destination retains only its two established guidance descriptions, every exact return label, focus action, filter, result, card and download stays unchanged, and no copy, state, live region, request, file, permission or lifecycle decision changes.
  • v1.78 extends the existing focused owner export controls destination with the visible shown-of-total owner download count in every catalogue scope; the association reuses the existing static x-of-17 badge after fixed orientation and, when filtered, active-scope context, derives only from the unchanged local visible result and fixed catalogue, contains no entered query or record content, adds no live announcement, leaves every exact return label, focus action, filter, result, card and download unchanged, and adds no copy, state, live region, request, file, permission or lifecycle decision.
  • v1.79 associates each of the three existing focused owner export group headings with its visible fixed group label, shown-of-total count and summary; every shortcut keeps the same fixed label, result condition, target, scroll and focus action, each association derives only from unchanged visible catalogue results and fixed group totals, entered query and record content remain excluded, no new copy or live announcement is added, every filter, result, card and download stays unchanged, and no state, live region, request, file, permission or lifecycle decision changes.
  • v1.80 extends each of the three existing focused owner export group destinations with the visible active catalogue scope title and fixed selection summary only when the catalogue is filtered; the association names the established fixed Purpose and File format values plus Quick Find as Active or Not used after the existing group label, shown-of-total count and summary without repeating entered text, every shortcut, target, focus action, filter, result, card and download stays unchanged, and no copy, state, live region, request, file, permission or lifecycle decision changes.
  • v1.81 associates each of the three existing owner export result regions with its visible fixed group label, shown-of-total count and summary plus, when filtered, the visible active catalogue scope title and fixed selection summary; each region keeps its existing heading name and visibility, the association reuses static visible context without entered query or record content, every shortcut, target, focus action, filter, result, card and download stays unchanged, and no copy, state, live region, request, file, permission or lifecycle decision changes.
  • v1.82 extends the existing owner export centre region with the visible shown-of-total owner download count in every catalogue scope plus, when filtered, the visible active catalogue scope title and fixed selection summary; the association follows the two established visible orientation and file-boundary descriptions, keeps the existing region name, disclosure, controls, results, cards and all 17 downloads unchanged, excludes entered query and record content, and adds no copy, state, live region, request, file, permission or lifecycle decision.
  • v1.83 associates each of the three existing exact owner export return actions with the same fixed controls-heading destination it already scrolls to and focuses; Records, Accountability and Lifecycle evidence keep their exact labels, group visibility and one shared target, the destination retains its established guidance, conditional scope and result-count context, every filter, result, card and download stays unchanged, and no copy, state, live region, request, file, permission or lifecycle decision changes.
  • v2.41 compares one selected historical quote revision with the current revision from already-loaded bounded summaries, marks Quote title, Status, Quote total, Valid until and Validity as changed or unchanged, gives honest not-loaded guidance when the current summary is absent and reuses the existing exact current-revision open path; the comparison adds no automatic request, write, storage, schema, permission, customer-facing publication or real-data approval.
  • v2.42 lets an operational user search and filter only quote revision summaries already loaded in the browser with one bounded transient literal query plus fixed status and validity choices, reports exact matches from the loaded count, shows at most eight results and reuses the existing guarded exact-detail path; it adds no automatic page read, endpoint, write, storage, schema, permission or real-data approval.
  • v2.43 derives selected-to-current quote-total, valid-until and status movement only from two already-loaded quote revision summaries, uses exact same-currency minor-unit and UTC calendar-day arithmetic, refuses cross-currency subtraction and treats expiry only as a loaded point-in-time state; it adds no automatic read, endpoint, write, storage, schema, permission or real-data approval.
  • v2.44 lets an operational user deliberately load exactly one earlier quote-revision summary page from the missing-current comparison state through the existing guarded cursor path, preserves the selected historical detail, transient Find state and loaded summaries, restores focus according to whether the current summary arrived, another page remains or history is exhausted, and keeps the exact cursor and comparison origin through existing retry handling; it adds no automatic scan, new endpoint, write, storage, schema, permission or real-data approval.
  • v2.45 lets an operational user deliberately load exactly one earlier quote-revision summary page from an active loaded-only Find with fewer than eight matches through the existing guarded cursor path, preserves the transient query and filters, selected quote detail, comparison and loaded summaries, keeps focus on the continuation action while another eligible page remains and otherwise restores focus to the recalculated loaded-scope status, and keeps the exact cursor and Find origin through existing retry handling; it adds no automatic scan, new endpoint, write, storage, schema, permission or real-data approval.
  • v2.46 gives a failed exact quote-revision open one named retry for the same revision, reuses exactly one existing guarded detail request, preserves loaded history, Find filters and the previously open quote, moves focus to a named progress status while the retry runs, restores the alert after repeated failure or the revision selector only after a successful same-viewer and same-enquiry result, and adds no automatic retry, history refresh, endpoint, write, storage, schema, permission or real-data approval.
  • v2.47 lets an operational user step between adjacent shown matches in an active loaded-only quote Find, derives the position and exact newer or earlier targets only from the first eight shown results without wrapping, preserves filters, loaded history and preview mode, and updates the open revision only after one existing guarded detail request succeeds; direct Find opens and exact retries retain a transient origin and restore the confirmed review position or Find status, while ordinary history returns remain unchanged. It adds no automatic request, history scan, endpoint, write, storage, schema, permission or real-data approval.
  • v2.48 lets an operational user browse every already-loaded quote Find match in explicit result pages of at most eight summaries, shows exact loaded-scope ranges and page positions, and preserves the open quote, filters, preview, cursor and retry targets without requesting or opening anything. Input and identity changes and successful history replacement return to page one; earlier append and ordinary failed refresh preserve the page. Adjacent review stays page-local, and separate history continuation still uses the total loaded match count. It adds no request, endpoint, write, storage, schema, permission or real-data approval.
  • v2.49 lets an operational user return to the exact loaded Find result for the open quote revision, derives its position and destination from the existing filtered summaries, and distinguishes matching, filtered-out and not-loaded states. A deliberate return changes only the local result page when needed and focuses the exact selected row, with guarded Find-status and heading fallbacks. Search, filters, selected detail, preview, comparison, cursor and retry target and origin remain unchanged. It adds no request, automatic lookup, endpoint, write, storage, schema, permission or real-data approval.
  • v2.50 lets an operational user move directly between an active loaded quote Find and the already-open quote preview through synchronous focus-only navigation. The exact selected full revision must be rendered, independent of whether its summary matches or is on the shown page, and loading, error, editor, busy, recovery and identity boundaries remain enforced. Return focuses the unchanged Find status or the panel heading, preserving filters, result page, preview mode, cursor and retry context. It adds no state, timer, request, endpoint, write, storage, schema, permission or real-data approval.
  • v2.51 lets an operational user open the newer or earlier shown Find match directly beside the quote preview. Named neighbours and position come from the same current result page, with no wrapping, hidden-result opening or automatic history loading. Each deliberate action reuses one guarded exact-revision request; success and exact retry focus only the requested verified preview, with Find status and panel-heading fallbacks. Search, filters, result page, preview mode, loaded history and cursor remain unchanged, and busy, recovery, identity and mounted-revision boundaries remain enforced. It adds no endpoint, write, storage, schema, permission or real-data approval.
  • v2.52 lets an operational user choose any already-loaded quote revision as a fixed comparison reference. Automatic current remains the default; a numbered reference stays fixed while reviewing other quotes. The same five summary fields and exact selected-to-reference deltas support earlier-to-earlier and current-to-earlier comparison without currency conversion. Identical or missing references have explicit states, with no silent substitution or automatic lookup. Selection is transient and viewer-and-enquiry-scoped, leaving Find, detail, preview mode, history and retry context unchanged. Existing busy and recovery guards remain, and missing-current continuation is automatic-current-only. It adds no request, endpoint, write, storage, schema, permission or real-data approval.
  • v2.53 lets an operational user open a loaded fixed reference and compare back to the previously open revision. One existing guarded exact-detail read opens the reference; only verified success makes the previous revision the new fixed reference and reverses the same summary deltas. Failed opens preserve the pair, and exact retry retains its scoped source and target. Ordinary opens, latest loads and access/context changes invalidate swap intent; live request, recovery and exact mounted-pair checks guard completion and focus. Find, result page, preview mode, loaded history and cursor remain unchanged, with no automatic scan or retry. It adds no endpoint, write, storage, schema, permission or real-data approval.
  • v2.54 compares six proposal-content sections from the two verified revisions opened by a successful comparison swap. One immutable source projection is retained in the existing scoped intent, excluding internal pricing, quantities, service/itinerary identifiers and revision notes. Ordered sections preserve duplicates without inferring item identity, and null or empty optional copy both mean absent. Exact retry uses the original source; viewer, enquiry, quote and fixed revision-pair checks gate display. Other opens, latest reads, reference/context changes and mutation/recovery applications invalidate the pair. Find, result page, history and preview mode remain unchanged. It adds no extra request, endpoint, write, storage, schema, collection, permission or real-data approval.
  • v2.55 adds a local changed-sections filter to the verified proposal-content comparison. All six sections show by default. Native hidden sections retain their keyed disclosures; exact visible and hidden counts and scoped zero-result guidance avoid claiming whole-quote equality. One local boolean resets with a new comparison pair or invalidation, without changing snapshots, Find, history, preview mode or reference. The labelled checkbox remains available at zero results and announces counts without transferring focus. It adds no request, endpoint, write, storage, schema, collection, permission, publication or real-data approval.
  • v2.56 adds explicit open and close controls for the currently shown proposal sections. A connected container reference limits each action to its direct native section disclosures, leaving hidden unchanged sections and the outer comparison untouched. Individual toggles remain native; no duplicated open-state model is introduced. The buttons name the shown count, disable at zero and retain normal focus. Existing pair-key reset and invalidation remain in force. Snapshots, Find, history, preview mode and reference do not change. It adds no request, endpoint, record write, storage, schema, collection, permission, publication or real-data approval.
  • v2.57 adds local text search across the six sections of the verified proposal pair. A query of at most 160 characters matches case-insensitive literal text within individual displayed fields, including category labels and dates but excluding identifiers, pricing, internal notes and other history. Matching sections retain both complete revisions and identify which matched. Search intersects changed-only filtering with disjoint hidden counts and distinct no-match versus hidden-match guidance. Clearing search preserves the filter and native disclosures; shown-section actions respect both filters. Pair reset and invalidation clear the query. It adds no request, endpoint, record write, storage, schema, collection, permission, publication or real-data approval.
  • v2.58 highlights matching text inside the six searchable proposal sections. Search and marks share the existing bounded case-insensitive literal query; lowercase match offsets map back to intact original Unicode code points and overlapping mapped ranges merge without duplicating copy. All displayed searchable fields retain complete original text and React escaping; generated placeholders remain unmarked. Guidance separates search matches from revision changes. Clearing search removes marks while counts, filters, snapshots and disclosure state remain unchanged. It adds no state, request, endpoint, record write, storage, schema, collection, permission, publication or real-data approval.
  • v2.59 adds a local index of currently shown proposal sections. Each named jump opens only its shown native disclosure and focuses its summary; return controls after each proposal side focus that section's current index entry and identify their exact revision and section. Mounted references and current hidden flags prevent stale navigation across filters or pairs. Other open states, snapshots, query, filters, counts and existing pair resets remain unchanged. Zero results omit the index while preserving recovery controls. Wrapped controls and responsive focus-scroll clearance support narrow layouts. It adds no state model, request, endpoint, record write, URL change, storage, schema, collection, permission, publication or real-data approval.
  • v2.60 adds an optional wording-change review for client summary and client notes. Exact memoized word-and-whitespace alignment marks removals from the fixed reference and additions in the open revision, without implying chronology, editing history or approval. Original text, case, punctuation and Unicode stay intact. Explicit legends, screen-reader boundaries and whitespace labels separate changes from yellow search marks. A bounded typed matrix handles inputs up to 2,000 characters each; larger loaded fields use complete labelled whole-field replacement without truncation. Equal fields add no disclosure; lists keep their existing whole-section comparison. Original sides, filters, counts, navigation, disclosures and pair invalidation remain unchanged. It adds no state model, request, endpoint, record write, storage, schema, collection, permission, publication or real-data approval.
  • v2.61 adds optional inclusion and exclusion list-change review. Exact whole-entry alignment preserves saved order, duplicate occurrences and all original text, with explicit match, removal and addition labels and one-based positions in each revision. Reference-to-open direction does not imply chronology or item identity; reordering can appear as removal and addition. Empty lists and blank legacy entries remain perceivable. Memoized alignment is bounded to 20 entries and 240 characters per entry; larger loaded lists retain complete source-labelled entries without alignment or a claim that all entries changed. Original sides, search, filters, counts, navigation, wording review and pair invalidation stay unchanged; services and itinerary remain whole-section comparisons. It adds no state model, request, endpoint, record write, storage, schema, collection, permission, publication or real-data approval.
  • v2.62 adds optional service and itinerary entry-content review. Exact projected tuples align in saved order with both one-based positions for matches and separate unaligned source-labelled rows. Services include category, title and description; itinerary includes date, title, location and details. IDs, prices, quantities, rates and internal notes are excluded. Titles and positions do not infer identity; moved or changed content can appear separately, and exact projected matches do not establish that a complete quote is unchanged. Duplicate occurrences, null dates and blank fields remain perceivable. Memoized alignment follows the current 25-service and 30-itinerary entry limits and field bounds; larger loaded content remains complete and source-labelled without alignment or an all-changed claim. Original sides, search, filters, navigation, existing reviews and pair invalidation remain intact. It adds no request, record write, storage, collection, permission, publication or real-data approval.
  • v2.63 adds independent local exact-match filters to service, itinerary, inclusion and exclusion entry reviews. All rows are shown by default, and unchecking restores original alignment order and source positions. Polite counts describe shown, total, exact-match and hidden alignment rows, never unique items or approval; an exact-match row represents entries from both revisions. No-match controls are disabled. Larger unaligned lists and fields always show every complete source-labelled row without filtering or inferred match counts. Choices survive native disclosure closing and temporary section hiding, then reset with existing comparison invalidation or keyed pair replacement. Original proposals, search, section counts and navigation are unchanged; toggles reuse memoized alignment. The release adds only ephemeral component-local booleans and no request, record write, storage, collection, permission, publication or real-data approval.
  • v2.64 adds local source-entry navigation from service, itinerary, inclusion and exclusion review rows to their exact already-loaded original entries. Both sources are offered for matched rows and only the applicable source for one-sided rows, using saved positions rather than inferred identity. Original entries in changed sections return to their currently visible review row, or the review heading when an exact match is hidden, without clearing filters. Scoped handlers recheck connected comparisons and shown sections; missing targets and unmounted pairs do nothing. Complete originals, duplicate and reordered positions, larger unaligned content, search marks, counts and other disclosure choices remain intact. Native buttons and programmatic targets have visible focus and responsive header clearance. No state, request, record write, storage, URL navigation, collection, permission, publication or real-data approval is added.
  • v2.65 adds previous and next navigation through highlighted passages in shown original proposal sections, open revision before reference. Counts match rendered highlight groups, including adjacent and Unicode-overlapping matches, rather than individual occurrences or review-copy duplicates. Next starts first, Previous starts last, and both stop at their endpoints. The destination section opens and its contextual mark receives focus; a polite last-visited status identifies position, section and revision. Both original sides return to the local navigation heading. Search and changed-only changes reset navigation alone, while disclosures and entry-review filters remain mounted; existing pair invalidation resets everything. Connected scoped targets and current rendered totals are rechecked before focus changes. Temporary local navigation state adds no request, record write, storage, URL change, collection, permission, publication, external action or real-data approval.
  • v2.66 adds a local search-scope choice for both loaded proposals, only the open revision or only the reference revision. Both is the default, with actual revision numbers in the native selector. Excluded sides contribute no match flags, passage counts or navigation targets; both complete originals remain mounted and only the searched side is highlighted. Live counts identify the scope and empty results suggest Both revisions. Scope changes preserve raw query, changed-only, disclosures and entry-review identities while resetting navigation even for equal-count side switches. Clearing search retains scope, blank search keeps every otherwise eligible section, and existing pair invalidation resets the choice. One temporary local state adds no request, record write, storage, URL change, collection, permission, publication, external action or real-data approval.
  • v2.67 adds section-and-revision shortcuts within an optional closed-by-default search-match list. Only shown matching sides appear, with their existing highlighted-passage counts rather than occurrence or unique-entry totals. A shortcut reuses the guarded current-original navigation to focus the first actual matching passage for that section and side, updating the global last-visited position so Previous and Next continue from there. It opens only the target section and preserves complete originals, saved positions, filters and other disclosures. The shortcut list resets with the existing navigation key on search, scope or changed-only changes. Native controls retain touch-size, wrapping and visible focus styling. It adds no application state, request, record write, storage, URL change, collection, permission, publication, external action or real-data approval.
  • v2.68 adds an explicit local proposal-review reset. It clears the search phrase, restores Both revisions, shows all six sections and restores every entry-review alignment row, including previously hidden sections. Only the inner section subtree is recreated, closing section and wording, list and entry-review disclosures; clearing the phrase also discards highlight navigation and its shortcut list. The outer comparison, reset control, two loaded originals, revision direction and history choices stay intact. Reset remains available at default parent choices and zero results, uses a connected comparison guard and a functional local counter, and does not intentionally move focus. Ordinary query clearing and filter changes retain their narrower behavior. It adds no request, record write, storage, URL change, collection, permission, publication, external action or real-data approval.
  • v2.69 adds bulk open and close controls for shown proposal change reviews. Counts derive from shown changed sections and describe available wording, list or entry-review panels, not individual changes, open panels or approvals. Opening also opens each eligible outer section; closing changes only its inner review. The connected container, current hidden flags and actual direct review presence determine each action. Hidden panels, entry filters, search and scope choices, highlight navigation, loaded originals, saved positions and records remain unchanged. Existing reset and outer-section controls keep their distinct behavior. It reuses native disclosures and touch-sized wrapping focus styles, adding no state, remount, focus transfer, request, record write, storage, URL change, collection, permission, publication, external action or real-data approval.
  • v2.70 groups reset and bulk proposal panel controls inside one closed-by-default native Review tools and reset disclosure. Its summary names reset and reports shown sections and available change reviews, including zero results, without implying open panels or approval. Primary search, scope, changed-only, live counts, recovery, section navigation and highlight navigation remain outside with unchanged focus destinations. The wrapper and buttons stay mounted through filtering and Reset; only the existing reset-keyed section subtree is recreated, while pair invalidation starts closed tools. Opening or closing the tools changes no review choices, inner panels, highlight position, loaded originals or records. Established native summary, button and panel styles are reused. It adds no application state, ref, handler, request, record write, storage, URL change, collection, permission, publication, external action or real-data approval.
  • v2.71 adds Move up and Move down controls for price items and itinerary entries in an unsaved quote draft. Adjacent swaps preserve stable row keys, exact contents, dates, source costs and unrelated draft fields. Focus follows the moved entry to its updated numbered heading with responsive sticky-header clearance. Boundaries and saving or recovery locks prevent unavailable moves. Existing dirty-draft and discard-confirmation behavior applies; only explicit saving submits the chosen order through the existing revision path. Server calculation assigns consecutive positions without changing totals for an order-only edit, and recovery retains the exact frozen submission and checks saved order. Existing saved revisions stay unchanged. Moving adds no request, storage, collection, sharing, schema, permission, publication, message, booking, payment or real-data approval.
  • v2.72 adds Duplicate controls for unsaved price items and itinerary entries. Each copy receives a fresh draft key and is inserted immediately after its keyed source, preserving all raw field values and leaving original rows and unrelated fields intact. Copies can be edited, moved and removed independently. Dates are not advanced; copied price lines count again in server-calculated totals on explicit Save. Visible guidance explains both consequences. Existing item limits and saving or recovery locks block copying when unavailable, while moves remain possible at capacity. Both actions share one pending-edit guard, and exact accepted-draft identity plus connected scoped key lookup protects focus on the new numbered heading. Existing dirty-draft, discard confirmation, revision saving and frozen-receipt validation preserve independent copied rows without deduplicating their content. Moving and copying add no request, browser storage, collection, sharing, schema, permission, publication, message, booking, payment or real-data approval.
  • v2.73 adds one-step Undo removal for unsaved price items and itinerary entries. It restores the latest removed entry's exact raw contents, stable key and original position using a fresh draft, preserving unrelated fields. Only the exact accepted post-removal draft remains eligible, until the next edit or Save attempt; a second removal replaces the opportunity and there is no multi-step history. Save clears Undo even when validation prevents submission, while declining Cancel keeps it available. Existing saving and recovery locks, the shared pending-edit guard and the one-price-item minimum apply; an empty itinerary retains its Undo control. Connected, accepted-draft focus moves to Undo after removal and the restored keyed heading after Undo, with responsive sticky-header clearance. The temporary editor-memory opportunity ends on unmount. Existing dirty-draft, discard confirmation, explicit revision saving and frozen-receipt checks remain in force, including saves with the last itinerary entry removed. Undo adds no request, persistent storage, collection, sharing, schema, permission, publication, message, booking, payment or real-data approval.
  • v2.74 adds five draft section shortcuts for Quote details, Internal pricing rules, Price items, Itinerary and Client-facing notes. Counts derive from current unsaved rates, price items and itinerary entries, including zero and capacity limits, and do not indicate validation or approval. A shortcut focuses the existing outer legend; each section's return button focuses the visible Draft sections heading. Native buttons use connected form-scoped targets, current draft identity and existing saving, recovery and pending-row-edit guards. All fields remain mounted and visible, with wrapping touch controls and responsive focus clearance rather than another sticky layer. Navigation preserves exact raw input, dirty state, removal Undo eligibility, validation guidance, explicit Save and Cancel, title-on-open and error-summary focus. It adds no application state, request, storage, URL change, schema, collection, sharing, permission, publication, message, booking, payment or real-data approval.
  • v2.75 adds exact-field shortcuts to the existing first client-validation error. The current validator attaches typed targets without changing rules, messages, validation order or normalized save payloads. Repeated inputs use stable draft keys; the later duplicate rate targets its currency, while list limits and missing rates target persistent section legends. The error summary keeps initial focus, and an explicit Go to field or Go to section button focuses only its connected current-editor target. Exact inputs receive an invalid marker and the existing message as a description, preserving prior help. The temporary issue is tied to the rejected draft and error message; accepted edits clear the shortcut and marker while the existing summary text remains until Save. Opening, cancellation, Save and access-change cleanup release the issue. Section navigation and declined Cancel preserve it. Saving, recovery and pending row edits retain focus priority. Server, baseline and recovery errors are never inferred from message text. No autofill, autosave, extra validation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.76 adds an explicit Check draft action that reuses existing local input validation without preparing or sending a save request. A separate result states that nothing is saved and that Save still verifies the current quote, checks server rules and calculates totals. Typed failures keep exact-field or section guidance; prior server and baseline save errors remain visible. Checking preserves raw inputs, dirty state and removal Undo. Results are tied to the exact draft, editor mode and loaded base revision, and clear after edits, Save, editor exits or access cleanup. Section navigation and declined Cancel preserve them. Only an accepted explicit check focuses its result, with current-context and connected-form guards, recovery locks and responsive clearance. No rule, normalized payload, API, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval changes.
  • v2.77 adds Find draft entry for the current unsaved quote. Bounded literal search matches price-item titles and descriptions and itinerary titles, locations, details and dates, with case and whitespace normalization. Results count entries, retain draft order and identify type, current position and title; stable keys distinguish duplicate titles. Explicit opening focuses the connected current row heading without hiding fields. Queries remain only in editor memory, survive ordinary edits while results recompute, and reset on editor unmount. Searching, clearing and opening preserve raw inputs, dirty state, Undo, validation guidance and Check draft results. Enter cannot submit from the search input, Clear returns focus there, and current-context, recovery and pending-action guards preserve focus priority. No request, payload, schema, persistent storage, URL, collection, sharing, permission, publication, external action or real-data approval changes.
  • v2.78 makes the existing Add controls hand focus to the exact new entry after its draft update is accepted. The targets are rate source currency, price-item title and itinerary title. Existing defaults and raw data are preserved; additions retain six-rate, 25-price-item and 30-itinerary-entry limits. Fresh keys avoid existing-row collisions, and connected field-plus-key lookup reuses existing responsive focus styling. Add remains an unsaved edit through the current parent update path, preserving search text while ending old Undo and local-check or validation guidance; prior save-error text remains. Current-context, capacity, saving, recovery and pending-action guards reject competing additions before allocating a key or changing Undo. Replacement drafts, changed editor mode and missing, disabled, detached or foreign targets cannot receive deferred focus. No extra request, validation, save, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.79 extends the existing one-step removal Undo to manual exchange rates. The same global opportunity restores the exact raw rate, stable key and original position in a fresh unsaved draft, including incomplete or duplicate rates. A currency-pair notice remains available after the last rate is removed; accepted removal and restoration focus Undo and the restored rate heading using existing responsive styling. Another removal replaces the opportunity, and editing or Save ends it; search, navigation, local Check and declined Cancel preserve it. Price items, six-rate capacity, missing-rate validation, explicit Save and recovery rules remain unchanged. Saving, recovery, stale context and pending row or check actions block conflicting operations. No rate lookup, calculation, normalization, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.80 adds a direct Check and save destination beside the five existing draft-section shortcuts. Local-check results and save errors offer the same route to a named action-area heading; a return leads back to Draft sections. Navigation never focuses or activates Save itself and keeps one existing Check, Save and Cancel control. Raw draft content, search, removal Undo, current check results and validation guidance remain unchanged. Current editor-context, saving, recovery and pending row or check guards preserve focus priority, while the existing theme supplies wrapping touch controls and responsive heading clearance. No state, validation rule, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.81 adds an optional unsaved wording review at Check and save. A default-closed native disclosure renders only current title, summary, validity, service category/title/description, itinerary date/title/location/details and client-facing notes. Quantities, source pricing and currencies, rate evidence, pricing rules, totals and internal revision notes are excluded; free text is not redacted. Raw whitespace, ordering, duplicate lines and dates remain unchanged with neutral blank placeholders. This is not an exact saved client preview or shareable quote. Four Edit links reuse guarded section navigation; fields and the sole Check, Save and Cancel controls remain outside the review. Reviewing preserves search, removal Undo and existing check/error guidance. Existing validation and Save normalization remain authoritative. No application state, stored snapshot, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.82 adds exact-entry navigation between the unsaved wording review and existing service or itinerary inputs. Each review entry can focus its input heading; each editor card can open the native disclosure and focus its wording heading. Current kind and stable key identify targets independently of titles or positions, including after accepted row edits and Undo. Four section Edit links remain. Context, saving, recovery, pending-action and connected same-form target guards apply before focus or disclosure changes. Search, removal Undo, current checks, validation and save-error guidance remain intact. Focus headings reuse existing responsive clearance and outlines. Pricing exclusions, raw wording, validation and explicit Save rules remain unchanged. No application state, stored return point, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.83 adds current raw-text length guidance beside bounded quote-editor fields, extending the former summary-only counter. The summary input allowance is corrected from 1,200 to the existing server limit of 1,000; all other native input allowances stay unchanged. Counters use raw UTF-16 length, include whitespace and show textual at-or-above allowance guidance without clipping restored values or adding validation. Saved normalized content follows existing separate rules, including 20 distinct inclusion or exclusion lines of 240 characters each. Field names remain separate from their associated counters, current validation descriptions are preserved and repeated-field associations follow accepted row edits. Counters stay outside wording review and add no live announcements or focus changes. Search, review navigation, Undo, Check, Save normalization, recovery and Cancel remain unchanged. No application state, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.84 checks inclusion and exclusion line limits through the existing shared local Check and Save preparation. Prepared lists may contain at most 20 distinct non-empty lines of 240 normalized characters each, matching existing server limits. Raw draft text and valid payload arrays are preserved; trimming, blank removal and exact-string deduplication remain unchanged, with NFC used only for length comparison. Count checks precede line checks, inclusions precede exclusions and earlier validation and pricing order stays intact. Overlong-line messages identify the original source line. Typed note-field targets reuse existing error styling, counter descriptions and explicit Go to field navigation. Failure stops before save evidence or requests; valid restored lists above the total editor allowance remain accepted when saved-line rules fit. Editing, search, review, Undo, recovery and Cancel follow their existing paths. No new server rule, application state, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.85 checks scalar quote-text limits through existing local Check and Save preparation. NFC-normalized, trimmed UTF-16 length matches current server limits without rewriting draft text or valid payloads. Earlier required-field, row, currency, pricing and note-list validation retains priority; new checks follow field and current row order. Typed targets identify exact fields and stable row keys without echoing text, preserving field names and counter descriptions. Service descriptions retain the 500-character input allowance while restored values through the separate 600-character saved limit remain accepted. Initial quotes still ignore unused raw revision explanations. Failures stop before evidence or save requests, and local success does not replace server verification. Editing, search, wording review, navigation, Undo, recovery and Cancel keep their existing paths. No new server rule, application state, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.86 checks real calendar dates through existing local Check and Save preparation, using the server-compatible four-digit ISO date and UTC-midnight round trip without reading the current clock. Earlier expiry-format and all existing validation retain priority; new calendar checks inspect expiry then itinerary rows. Empty optional dates remain null, padded valid itinerary dates remain unchanged and whitespace-only dates fail. Past, repeated, out-of-order and post-expiry itinerary dates stay allowed. Typed stable-row targets and helper descriptions support exact-field navigation without changing native date controls, raw wording review or valid payloads. Failures stop before evidence or save requests; the server still checks expiry and rate-observation time against its own clock. Existing editing, search, navigation, Undo, recovery and Cancel paths remain unchanged. No new server rule, application state, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.87 shows manual-rate reference counts derived from current price-item source currencies, not quantities, totals or rate approval. Counts include incomplete and duplicated rows and update after accepted draft edits without separate state, automatic validation or live announcements. Existing local Check and Save preparation reject the first unused rate in current order, matching the existing server rule while preserving all earlier validation priority. Stable-key From currency targets compose usage and error descriptions without changing field names. Rates are never removed or converted automatically; failure stops before evidence or requests and valid payloads and server calculations stay unchanged. Guidance remains outside the wording review. Editing, search, navigation, Undo, recovery and Cancel keep their existing paths. No new server rule, quote calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.88 checks existing per-rate lexical bounds, per-item source-cost and service-fee ceilings, and supported rounding values through local Check and Save preparation before evidence or requests. Earlier format, zero, precision, unsafe-number and row-order validation retains priority. Typed exact-field and stable-row targets compose with visible guidance without changing names or controls. Invalid raw values remain available for manual correction; equivalent supported rounding inputs keep the same numeric payload and every valid payload remains unchanged. That release adds no aggregate-range preflight or displayed total, and final request verification and quote calculation stay server-owned. Editing, search, wording review, navigation, Undo, recovery and Cancel keep their existing paths. No new server rule, application state, quote calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.89 samples the browser's current time only after all existing static Check and Save-preparation validation passes. It requires Valid until to be the current UTC date or later and each manual-rate observation to be no later than the sampled instant plus the existing exact five-minute clock-skew allowance, checking expiry before rates in current row order. Typed exact-field and stable-row targets preserve raw draft values for manual correction and stop before evidence or requests. The transient clock sample is not stored, shared, persisted, placed in a URL or sent to analytics or telemetry; the server independently applies its authoritative current time. Valid payloads and all existing editing, search, wording review, navigation, Undo, recovery and Cancel paths remain unchanged. No new server rule, application state, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.90 deterministically mirrors the existing server calculation-range checks after static draft validation and before the browser clock is sampled. BigInt rational half-up conversion checks each price line and the running subtotal in current row order, then checks subtotal plus markup, service fee and supported rounding without displaying or approving a total. Typed exact-field and stable-row targets preserve raw values and valid payloads; failures stop before clock reads, save evidence or requests while the server remains authoritative for final verification and calculation. Existing editing, search, wording review, navigation, Undo, recovery and Cancel paths remain unchanged. No new server rule, application state, displayed total, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.91 aligns visible asterisks and native required semantics with the quote draft inputs that existing Check and Save validation already requires. One visible key explains the convention; manual-rate value, source and Observed at plus price-item Quantity join the previously marked quote title, validity date, client summary, price-item title and cost, itinerary title and conditional revision note. Decorative symbols remain hidden from assistive technology while controls expose their required state. Optional fields and always-populated choices stay unmarked, and the form keeps noValidate so existing validation order, messages, typed targets and server verification remain authoritative. No raw value, valid payload, calculation, request, application state, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval changes.
  • v2.92 derives one transient current-draft required-input count from the nonblank values of exactly the controls already marked required: three quote details, three fields per manual rate, three fields per price item, each itinerary title and the conditional revision note. Repeated rows count separately; accepted add, duplicate, remove and Undo edits change the current total while reordering does not. Whitespace-only values remain unfilled, but present invalid values still count, so the visible copy explicitly keeps format, relationship, date, calculation-range, current-time and server verification with Check and Save. The passive numeric summary echoes no entered wording, adds no live announcement and is derived without state, effects, requests or persistence. The form gains an accessible name and visible descriptions, and required guidance uses a higher-contrast established colour. No raw value, valid payload, validation rule, calculation, request, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval changes.
  • v2.93 adds one explicit current-draft shortcut from the passive required-value summary to the first currently missing rendered required input in current draft order. The count and target derive from the same ordered descriptors, including stable row keys and the conditional revision note, so accepted add, duplicate, reorder, remove, Undo and mode changes stay aligned. Whitespace-only values are missing while present invalid values remain for Check and Save; the shortcut is omitted when no rendered required value is missing and disabled while locked or saving. Current-context, pending-action, connected same-form and enabled-target guards preserve existing focus priority. It adds no automatic focus, live announcement, invalid marker, value change, Check, save, request, state, effect, payload field, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval.
  • v2.94 groups the existing ordered required-input descriptors by their five persistent draft sections and adds a passive current filled-of-total presence summary to each existing section shortcut; existing manual-rate, price-item and itinerary row counts remain unchanged. Quote details covers title, validity and client summary; pricing covers three required values per rendered manual rate; price items covers title, quantity and source cost per row; itinerary covers each title; notes includes the revision explanation only while revising. The summaries stay aligned with the v2.92 overall count and v2.93 first-missing target across accepted add, duplicate, reorder, remove, Undo and mode changes. Whitespace-only values are missing while present invalid values still count, so Check, Save and server verification remain authoritative. Existing destinations, explicit focus, validation, saving, raw values and valid payloads remain unchanged. No live announcement, automatic navigation, application state, effect, calculation, request, payload field, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.
  • v2.95 visibly names the exact current destination of the existing first-missing required-input shortcut using fixed section and field labels plus the current row position for repeated entries. The label and focus target derive from the same first ordered descriptor and stable row key across accepted add, duplicate, reorder, remove, Undo and revision-mode changes, include no entered value, selected currency or internal row key, and retain all existing explicit-focus guards. Whitespace-only values remain missing while present invalid values remain for Check and Save. It adds no action, automatic focus, live announcement, invalid marker, application state, effect, validation, value change, request, payload field, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval.
  • v2.96 lets each existing draft-section shortcut name and focus its first whitespace-only required input using fixed within-section field wording, the current row position and the same ordered descriptor and stable target that power the overall count, global first-missing shortcut and section summary. Accepted add, duplicate, reorder, remove, Undo and revision-mode changes keep the visible label and target aligned without exposing entered values, selected currencies or internal row keys. Sections with no missing or rendered required input and every other section entry path keep their existing heading destination. Current-context, pending-action, connected same-form and enabled-target guards preserve focus priority; present invalid values remain for Check and Save. It adds no new control, automatic focus, live announcement, invalid marker, application state, effect, validation, value change, request, payload field, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval.
  • v2.97 gives all five field sections and the Check and save area one exact visible return to their matching existing Draft sections shortcut. The six fixed section-metadata mappings move focus only after explicit selection and do not activate a shortcut, re-enter a section, validate, check or save. Accepted edits expose the matching shortcut's current row count, required-value progress and first-missing wording; no entered value, selected currency or internal row key supplies a return target. Current-draft, editor-mode, callback, pending-action, connected same-form and enabled-target guards preserve focus priority, while stale, unavailable, detached, disabled, wrong-form or foreign targets receive no fallback. Existing section navigation, raw values, valid payloads, validation, Check, Save and Cancel remain unchanged. No application state, effect, automatic focus, live announcement, value change, request, payload field, schema, persistent storage, collection, sharing, permission, publication, external action or real-data approval is added.

Still required

  • Define and approve a retention schedule for every data category.
  • Complete and test the approved agency-wide export scope beyond the current partial Pipeline, Enquiry-brief, selected-case, activity, Team access, Agency settings, Operations-summary, Quote-summary, Quote-revision, Quote-rate-snapshot, Quote-line-item, Quote-itinerary-day, Operations-task, Operations-payment-record, current Work Responsibility, Work Responsibility History and Work Status History families and the content-minimized Data Retention, Record State and Event Action inventories, including every other required full-detail record family, plus archive, verified deletion and complete agency closure.
  • Document any legal-hold exceptions and prove they do not silently prevent ordinary deletion.
Gate passes only when

The documented lifecycle completes end-to-end tests for retention, export, archive, deletion, closure and approved hold exceptions.

Gate 4 of 7
Phase: ControlPhase 2 of 4Phase gate 2 of 3Status: In progress

Access lifecycle

Controlled team access now includes a fixed read-only summary-viewer role with an enforced 30-day deadline after acceptance, records invited, newly accepted, newly declined and removed access levels plus viewer deadlines, completed-review counts, post-transfer role outcomes and fixed self-service exit outcomes in owner history, distinguishes active-access removal from pending-invitation cancellation when those exact facts were stored, rechecks authority when an open workspace reaches that deadline, returns to view, reconnects, restores, receives a same-origin change signal or completes a visible-online five-minute cadence, and enforces the assignment-pause sequence for routine operational-member removal; broader recovery, exceptional succession and governed least privilege remain incomplete.

Evidence already present

  • Owner and member access, invitations, revocation, self-leave and safe ownership transfer have accountable history.
  • The owner can record exact-roster access reviews and see a fixed 90-day review cadence.
  • Shared reads and writes recheck active agency access at the decisive data boundary.
  • v0.60 shows the owner current open enquiry and task assignments before active-member removal and rechecks the snapshot immediately before the existing versioned removal request.
  • v0.61 lets the current owner deliberately reassign up to 20 exact-version open work items per request to one exact active teammate, records every successful change in existing activity history and refreshes authoritative remaining counts.
  • v0.62 requires the exact reviewed assigned-work counts to match again inside the decisive active-member removal statement; count drift changes neither membership nor Team history, and uncertain-retry review rechecks both Team state and impact.
  • v0.63 requires one fixed operational reason for active-member removal, freezes it with the reviewed counts through uncertain recovery and shows the resulting reason-and-count receipt only in owner access history.
  • v0.64 lets the current owner persistently and reversibly pause new assignments to one exact active member after reviewing assigned-work counts; the member retains access to existing work for deliberate handoff, and start or cancellation writes an accountable Team event.
  • v0.65 links a confirmed active-member removal receipt to the exact stored assignment-pause start time when planned offboarding was already active, while preserving direct and historical receipts without inventing a timestamp.
  • v0.66 requires routine active-member removal to have the matching stored assignment pause at the decisive write, while security or policy response remains available for immediate reviewed revocation.
  • v0.67 rechecks the authoritative signed-in identity and active agency role when an already-open workspace becomes visible or focused; confirmed access loss clears cached private views and local drafts, while an unverified check preserves the view behind an explicit retry.
  • v0.68 reuses the same bounded access check when a visible browser reconnects or a workspace is restored from back-forward cache; ordinary initial loads are excluded and overlapping resume signals still coalesce into one request.
  • v0.69 sends one fixed non-identifying same-origin browser signal after a tab confirms an access change; another open tab reuses the authoritative access check before clearing, and signal-started checks do not announce again.
  • v0.70 schedules the existing authoritative access check five minutes after the prior attempt settles while a workspace remains visible and online; hidden, offline or confirmed-changed workspaces stop the cadence, and every check still coalesces through one request.
  • v0.71 lets an owner invite one fixed summary-viewer access level whose separate workspace receives minimized Command Centre and Pipeline summaries, cannot open record detail or use operational endpoints, is excluded from every assignment path and retains the existing return, reconnect, restore, cross-tab and visible-online access rechecks.
  • v0.72 gives every accepted summary viewer one server-enforced deadline exactly 30 days after acceptance, shows that deadline to owners, schedules an exact open-workspace recheck, blocks expired viewers before new summaries and lets an expired viewer remove only their own retained Team record.
  • v0.73 records the exact operational-member or summary-viewer level for every newly accepted invitation in owner history, includes the exact fixed deadline for a viewer and leaves older acceptance events unaltered when those facts were not originally recorded.
  • v0.74 projects the exact operational-member or summary-viewer level already stored with an invitation-created event beside its acceptance deadline, while leaving older creation events without a recorded role unaltered.
  • v0.75 projects the exact operational-member or summary-viewer level and active-or-pending prior state already stored with a member-revoked event, while leaving older removal events without a recorded role unaltered.
  • v0.76 records and projects the exact operational-member or summary-viewer level for every newly declined invitation, requires receipt parity with the winning decline and leaves older decline events without a recorded role unaltered.
  • v0.77 projects only the exact 1-to-11 current-access-record count stored with a completed review after its winning complete-roster check, while withholding stored membership identifiers and versions and leaving older review events without a recorded count unaltered.
  • v0.78 records and projects the successor-owner and former-owner-operational-member outcomes from the exact winning ownership-transfer post-state, while leaving older transfer events without both originally recorded roles unaltered.
  • v0.79 projects only the already-recorded operational-member-left, active-viewer-left or expired-viewer-retained-record-removed outcome for a self-service access exit, while leaving owner removals, invitation cancellations and older events without an initiator receipt unaltered.

Still required

  • Complete ownership recovery and exceptional succession without weakening tenant boundaries.
  • Complete broader offboarding beyond the enforced routine sequence, bounded reassignment and linked closure receipts, including governed granular permissions beyond the fixed summary-viewer role and prompt-revocation operating procedures beyond the bounded event, cross-tab and visible-cadence checks.
  • Approve recurring review ownership, escalation, enforcement and an independent evidence programme.
Gate passes only when

A tested access-lifecycle procedure covers join, change, review, revocation, offboarding, lost-owner recovery and exceptional succession with accountable evidence.

Gate 5 of 7
Phase: ControlPhase 2 of 4Phase gate 3 of 3Status: In progress

Production security

The pilot has application-level access and response protections, but no completed production security assurance programme.

Evidence already present

  • Same-origin write checks, strict request validation, immutable tenant scope and commit-time access guards protect current pilot actions.
  • A baseline response-security policy covers public pages, workspace pages, APIs and worker responses.

Still required

  • Complete a threat model and verify transport and storage protection, security headers, WAF and rate limits.
  • Operate secret rotation, dependency scanning and redacted-log controls.
  • Remediate an independent penetration test and record closure of every blocking finding.
Gate passes only when

A production security review accepts the tested controls and an independent penetration-test report has no unresolved blocking finding.

Gate 6 of 7
Phase: OperatePhase 3 of 4Phase gate 1 of 1Status: Open

Operations and resilience

Review-safe user recovery exists for uncertain pilot actions, but production monitoring, response and recovery operations are not established.

Evidence already present

  • Critical pilot writes freeze uncertain outcomes, support a deliberate check-latest path and avoid blind retry.

Still required

  • Operate tested monitoring and alerts with named responders.
  • Approve an incident and breach-response playbook with communication and escalation paths.
  • Prove recoverable backups through a successful restore drill and document recovery and support targets.
Gate passes only when

Monitoring, incident response and backup restoration complete witnessed exercises against documented recovery and support targets.

Gate 7 of 7
Phase: ApprovePhase 4 of 4Phase gate 1 of 1Status: Open

Controlled go-live

The product remains a fictional-or-masked pilot; no accountable approval has named a permitted real-data tier.

Evidence already present

  • The workspace warning, data-entry guide and field map repeat the pilot-only handling rule before users enter data.
  • v2.40 extends the existing Back to approval sequence description with a visible Phase order: Define → Control → Operate → Approve preview, derives the value from the established ordered approval-phase labels and preserves the v2.39 ending, v2.38 starting and v2.37 sequence-size context; the reciprocal route, all six definitions, phase and gate labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.39 completes the existing Back to approval sequence description with visible Ends with Approve · Gate 7 of 7 context, derives the ending label and range from the established final approval phase and preserves the v2.38 starting-phase and v2.37 sequence-size context; the reciprocal route, all six definitions, phase and gate labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.38 extends the existing Back to approval sequence description with visible Starts with Define · Gates 1–2 of 7 context, derives the starting label and range from the established first approval phase and preserves the v2.37 sequence-size context; the reciprocal route, all six definitions, phase and gate labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.37 gives the existing Back to approval sequence route one visible 4 approval phases · 7 gates destination context, programmatically associates that context as the link's accessible description and derives both values from the established readiness collections; the v2.36 reciprocal route, v2.35 Status guide link, all six definitions, phase and gate labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.36 adds one reciprocal native Back to approval sequence link to the existing named status guide, with a fixed visible label, exact accessible purpose, 44-pixel target, sticky-header clearance and target outline; the v2.35 Status guide link, all six definitions, four phase-start routes, three continuing routes, labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.35 turns the new Status definition into one native fragment link to the existing named status guide, with a fixed visible label, exact accessible purpose, 44-pixel target, sticky-header clearance and target outline; all four phase-start routes, three continuing routes, labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.34 adds one exact Status definition to the approval-sequence guide, explaining that it identifies a gate's current evidence and approval state in the status guide rather than its order; the existing Approval phase, Register position, Phase gate, Remaining gate and Position meaning definitions, all four phase-start routes, three continuing routes, labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.33 adds one exact Register position definition to the approval-sequence guide, explaining that it identifies where a destination or phase range sits in the fixed seven-gate readiness register; the existing Approval phase, Phase gate, Remaining gate and Position meaning definitions, all four phase-start routes, three continuing routes, labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.32 adds one exact Approval phase definition to the approval-sequence guide, explaining that it identifies where a phase sits in the fixed four-phase approval sequence; the existing Phase gate, Remaining gate and Position meaning definitions, all four phase-start routes, three continuing routes, labels, positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.31 gives every continuing approval-sequence gate destination its parent phase's exact position within the four-phase approval sequence by reusing the established mapped Phase N of 4 value for both visible and accessible wording; all three continuing routes, four phase-start routes, global positions, titles, named phases, within-phase positions, remaining positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.30 gives every previous-gate and next-gate destination its parent phase's exact position within the four-phase approval sequence by matching each adjacent gate's fixed phase to the established phase-card order and deriving Phase N of 4 from that index and shared total for both visible and accessible wording; all 12 adjacent routes, directions, global positions, titles, named phases, within-phase positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.29 gives every status-grouped Matching gates destination its parent phase's exact position within the four-phase approval sequence by matching each gate's fixed phase to the established phase-card order and deriving Phase N of 4 from that index and shared total for both visible and accessible wording; all seven status-grouped routes, global positions, titles, named phases, within-phase positions, statuses, counts, approvals and real-data permissions stay unchanged.
  • v2.28 gives every fixed Jump to gate destination its parent phase's exact position within the four-phase approval sequence by matching each gate's fixed phase to the established phase-card order and deriving Phase N of 4 from that index and shared total for both visible and accessible wording; all seven fragment routes, global positions, titles, named phases, within-phase positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.27 gives every detailed readiness gate header its parent phase's exact position within the four-phase approval sequence by matching the gate's fixed phase to the established phase-card order and deriving Phase N of 4 from that index and shared total; all seven global positions, within-phase positions, statuses, evidence, approvals and real-data permissions stay unchanged.
  • v2.26 gives every approval phase its exact position within the four-phase approval sequence by deriving Phase N of 4 from the established mapped order and phase total for both visible and accessible wording; all four phase ranges, seven gate destinations, titles, positions, statuses, approvals and real-data permissions stay unchanged.
  • v2.25 gives every approval phase its exact range within the seven-gate register by deriving the first and last gate from each fixed phase group and expanding the visible and accessible range to Gates N–N of 7 or Gate N of 7 as appropriate; all four phase-start routes, three continuing routes, gate titles, positions, statuses, approvals and real-data permissions stay unchanged.
  • v2.24 gives every approval-sequence destination its exact position within the seven-gate register by expanding all four phase-start cues and three continuing-gate labels to Gate N of 7 and deriving the same gate total in each accessible name; all seven sequence routes, titles, phase positions, remaining positions, statuses, approvals and real-data permissions stay unchanged.
  • v2.23 gives every previous-gate and next-gate destination its exact position within the seven-gate register by expanding its visible direction label to Previous gate N of 7 or Next gate N of 7 and deriving the same gate total in its accessible name; all 12 adjacent routes, titles, phase positions, statuses, approvals and real-data permissions stay unchanged.
  • v2.22 gives every status-grouped Matching gates destination its exact position within the seven-gate register by expanding its visible Gate N label to Gate N of 7 and deriving the same gate total in its accessible name; all seven status-grouped routes, titles, phase positions, statuses, counts, approvals and real-data permissions stay unchanged.
  • v2.21 gives every fixed Jump to gate destination its exact position within the seven-gate register by expanding its visible Gate N label to Gate N of 7 and deriving the same gate total in its accessible name; all seven routes, titles, phase positions, statuses, counts, approvals and real-data permissions stay unchanged.
  • v2.20 gives every previous-gate and next-gate destination its exact position within the full phase beside its established named phase and current status, deriving the adjacent gate index and phase total from the same fixed phase group for both visible and accessible wording; all 12 adjacent routes, gate records, phase names, statuses, counts, approvals and real-data permissions stay unchanged.
  • v2.19 gives every status-grouped Matching gates destination its exact position within the full phase beside its established named phase and current status, deriving the current gate index and phase total from the same fixed phase group for both visible and accessible wording; all seven status-grouped routes, gate records, phase names, statuses, counts, approvals and real-data permissions stay unchanged.
  • v2.18 gives every fixed Jump to gate destination its exact position within the full phase beside its established named phase and current status, deriving the current gate index and phase total from the same fixed phase group for both visible and accessible wording; all seven routes, gate records, phase names, statuses, counts, approvals and real-data permissions stay unchanged.
  • v2.17 gives every detailed readiness gate header its exact position within the full phase beside its established named phase, deriving the current gate index and phase total from the same fixed phase group while retaining its global Gate N of 7 label; all seven gate routes, phases, statuses, records, counts, evidence, pass conditions, approvals and real-data permissions stay unchanged.
  • v2.16 gives every continuing approval-phase gate destination its exact position within the full phase alongside its established remaining-gate position, deriving both values from the same fixed phase group index and length and broadening the Phase gate definition from starting destinations to every destination; all four start routes and three continuing routes stay unchanged and no label, gate, phase, status, count, record, approval or real-data permission changes.
  • v2.15 turns the approval sequence position guide into one semantic definition list, giving Phase gate, Remaining gate and Position meaning one exact term-and-description pair each so the same established distinction is easier to scan and remains the named description for the sequence; all four start routes and three continuing routes stay unchanged and no label, gate, phase, status, count, record, approval or real-data permission changes.
  • v2.14 adds one visible position guide to the approval sequence, explaining that Phase gate describes each start destination's position in its full phase, Remaining gate describes the order of later destinations listed for that phase and position is register order rather than completion or approval; the same named guide describes the existing sequence for assistive technology, all four start routes and three continuing routes stay unchanged and no gate, phase, status, count, record, approval or real-data permission changes.
  • v2.13 gives every approval-phase start destination one exact position within its full phase group, deriving Define's Phase gate 1 of 2, Control's 1 of 3 and Operate and Approve's 1 of 1 context from the existing remaining-gate group length plus one for both visible and accessible wording; all four start routes and three continuing routes stay unchanged and no gate, phase, status, count, record, approval or real-data permission changes.
  • v2.12 gives every continuing approval-phase gate destination one exact position within its remaining-gate group, deriving Define's 1 of 1 and Control's 1 of 2 or 2 of 2 context from the existing ordered group index and length for both visible and accessible wording; all three routes, gate records and statuses stay unchanged, single-gate phases retain no empty continuation panel and no gate, phase, count, approval or real-data permission changes.
  • v2.11 gives every multi-gate approval-phase continuation panel one exact remaining-gate count derived from the same fixed remaining-gate group that supplies its established destinations, with singular wording for Define's one remaining gate and plural wording for Control's two; Operate and Approve retain no empty continuation panel, all three continuing routes stay unchanged and no gate, route, phase, status, count, record, approval or real-data permission changes.
  • v2.10 gives every multi-gate approval-phase continuation panel one visible phase-specific label derived from the same constrained phase name as its exact accessible name; Define and Control retain their three established continuing gate routes, Operate and Approve retain no empty continuation panel, the longer headings wrap inside the existing responsive panels and no gate, route, phase, status, count or real-data permission changes.
  • v2.09 gives every approval-phase start destination one visible gate title derived from the same fixed startGate record as its established number, phase, status, fragment route and exact accessible name; the four start routes plus three continuing routes still cover all seven fixed gates exactly once, the compact title wraps inside the existing touch-sized card and no gate, route, phase, status, count or real-data permission changes.
  • v2.08 gives every approval-phase card one visible starting-gate Status field and gives the multi-gate Define and Control phases direct status-labelled links to Gates 2, 4 and 5; the four start routes plus three continuing routes cover all seven fixed gates exactly once, derive phase membership and status from the constrained register, add no empty control for a single-gate phase and change no gate, route, phase, status, count or real-data permission.
  • v2.07 gives every previous-gate and next-gate control one visible Phase field beside its existing Status field, deriving both values from the immediately adjacent fixed gate and aligning each exact accessible name to the same Phase and Status wording; all 12 controls retain their established direction, number, title, fragment route, wrapping action group and touch-sized target while changing no gate, phase, status, count or real-data permission.
  • v2.06 gives every matching-gate destination visible Phase and Status fields derived from the fixed gate record and shared labels, and aligns its exact accessible name to the same field wording; all seven links retain their established status grouping, number, title, fragment route and touch-sized target while changing no gate, phase, status, count or real-data permission.
  • v2.05 gives every previous-gate and next-gate control one visible Status field derived from the immediately adjacent fixed gate and aligns each exact accessible name to the same Status wording; all 12 controls retain their established direction, number, title, fragment route, wrapping action group and touch-sized target while changing no gate, status, count or real-data permission.
  • v2.04 prefixes every fixed readiness gate header phase and linked status value with its visible field name and aligns each exact status-definition link name to the same Status wording; all seven pairs derive from the established shared vocabularies, retain the compact wrapping header group and change no gate, route, phase, status, count or real-data permission.
  • v2.03 prefixes every fixed readiness-index phase and status value with its visible field name and aligns each exact accessible destination name to the same Phase and Status wording; all seven labels derive from the established shared vocabularies, retain the compact wrapping metadata row and change no gate, route, phase, status, count or real-data permission.
  • v2.02 adds one visible guide directly above the readiness-index destinations, explicitly distinguishing a gate's phase as its position in the approval sequence from its current status as its evidence and approval state; the named navigation references the guide through one stable description relationship, adds no state or request and changes no gate, route, phase, status, count or real-data permission.
  • v2.01 gives every fixed Jump to gate destination one visible phase label derived from the gate's existing constrained phase field and the same shared Define, Control, Operate or Approve labels used by the approval sequence and gate headers; the seven compact metadata rows pair phase with the current status, wrap within the established destination cards, add the phase to each exact accessible link name and change no gate route, phase range, status, count or real-data permission.
  • v2.00 gives every fixed readiness gate header one visible phase label derived from that gate's new constrained Define, Control, Operate or Approve phase field and the same shared phase labels used by the existing approval-sequence cards; the seven compact labels remain beside the current status route, wrap on narrow headers, add no link or script and change no phase range, gate, status, count or real-data permission.
  • v1.99 turns each of the four fixed approval-sequence cards into one native fragment link to that phase's first gate, deriving the destination from the established gate records and naming the phase, gate range, first gate number and first gate title; the visible Start at Gate cue, full-card target and existing gate destination treatment add no script, focus management or review state and change no phase, gate, count or real-data permission.
  • v1.98 gives every fixed readiness gate header one native link back to its matching status definition, derived from that gate's established status, number and title, with a visible Definition cue, an exact contextual accessible name and a 44-pixel target; all seven links reuse the three existing definition fragments and their static target treatment, add no script, focus management or review state and change no gate, count or real-data permission.
  • v1.94 turns the three existing readiness summary counts into native fragment links to their matching static status definitions, with exact accessible names derived from the same labels and counts, visible definition cues, 44-pixel targets, 100-pixel sticky-header clearance and a CSS-only target outline; the links add no script, focus management or review state and change no gate or real-data permission.
  • v1.95 adds one native return-to-summary link inside each of the three fixed readiness status definition cards, with an exact accessible name derived from the established status label, a visible Back to readiness summary cue, 44-pixel targets and the existing 100-pixel summary clearance and CSS-only target outline; the links add no script, focus management or review state and change no gate or real-data permission.
  • v1.96 gives each of the three fixed readiness status definition cards one visible Current gate count derived from the same In progress, Open and Approved aggregate used by the summary links; the compact labels remain narrow-screen safe and add no script, focus management or review state while changing no gate, count or real-data permission.
  • v1.97 gives every non-empty readiness status definition one native Matching gates list derived from the same fixed gate records and status grouping as its count, with seven exact fragment links that visibly name each gate number and title, repeat the established accessible gate name, keep 44-pixel targets and add no placeholder for the zero-count Approved status; the links add no script, focus management or review state and change no gate, count or real-data permission.
  • v1.93 adds one static status guide beside the readiness summary that defines the three fixed public labels from the same status constants: In progress means evidence is advancing while the pass condition remains unmet, Open means required work and approval remain outstanding, and Approved means the stated pass condition and accountable approval are recorded; the guide explicitly says progress is not approval, reflows from a two-column section and three definition cards to one column on narrow screens, adds no script or review state and changes no gate or real-data permission.
  • v1.92 gives every fixed readiness gate card a visible Gate N of 7 position label derived from the same mapped gate number and fixed register length, placed beneath its existing decorative two-digit marker; all seven titles, public statuses, summaries, evidence, pass rules, fragment routes, exact navigation names, 100-pixel clearance and destination highlight stay unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.91 expands the fixed seven-link readiness index from number-only circles into compact visible destination cards derived from the same gate records, showing each established gate number, title and current status; the exact accessible names and fragment routes stay unchanged, the index uses seven, four and two responsive columns with a 76-pixel minimum target, destination clearance and highlighting remain unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.90 gives all six previous-gate and six next-gate controls a visible two-line destination label derived from the same immediately adjacent fixed register record, pairing the established direction and gate number with its title; each existing exact accessible name still includes number, title and current status, routes, summary action, wrapping group, 44-pixel minimum target, destination highlight and 100-pixel sticky-header clearance stay unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.89 adds one shared CSS-only target outline to the fixed readiness summary and all seven established gate cards so native fragment navigation leaves a clear amber destination cue with a five-pixel offset; the cue changes no layout border, transform or animation, every existing fragment link, exact accessible name and 100-pixel sticky-header clearance stays unchanged, no script, focus management or review state is added and no gate or real-data permission changes.
  • v1.88 adds one native previous-gate link after Gates 2 through 7, derived from the immediately preceding fixed register record and named with that gate's established number, title and current status; Gate 1 remains the starting point with no circular previous-gate link, the existing summary and next-gate routes stay available in one wrapping action group, every destination keeps 100-pixel sticky-header clearance, gate content, counts and the blocked decision stay unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.87 adds one native next-gate link after Gates 1 through 6, derived from the immediately following fixed register record and named with that gate's established number, title and current status; Gate 7 remains the final decision point with no circular next-gate link, every destination keeps 100-pixel sticky-header clearance, gate content, counts and the blocked decision stay unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.86 adds one native return-to-summary link after every readiness gate with an exact accessible name derived from its established gate number and title; all seven links share the fixed summary destination, which keeps the same 100-pixel sticky-header clearance, while gate order, evidence, counts and the blocked decision stay unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.85 keeps every readiness gate destination below the sticky public site header by increasing the existing static anchor clearance from 24 to 100 pixels; all seven fragment links, exact accessible names, gate records, counts and the blocked decision stay unchanged, no script or review state is added and no gate or real-data permission changes.
  • v1.84 gives each of the seven existing numbered readiness jump links an exact accessible name derived from its established gate number, title and current status; visible numbers, gate order, fragment targets, counts and decision stay unchanged, no review state is stored and no gate or real-data permission changes.

Still required

  • Complete a masked-data pilot and close its documented findings.
  • Obtain privacy and security sign-off and deliver staff handling guidance.
  • Record an accountable go-live approval that names the first permitted real-data tier and its effective boundary.
Gate passes only when

All six preceding gates are approved and one accountable go-live decision explicitly names the first permitted real-data tier.

No shortcut

Partial evidence is not approval.

This register is a transparent evidence snapshot, not a certification, legal opinion, security attestation or automated compliance system. It does not change a gate by itself and stores no review state.

WhatsApp us