Current security and documentation work — September 2026
Security audit and remediation #657: public-source exposure, authorization, VPN/public access, tool transports, publication boundaries, dependencies, and secure installation.
Documentation refresh #667: reconcile the active app/, packages/, and runtime contracts against source and tests.
See deployment notes for the immediate security changes and remaining rollout work. Issue status and validation receipts establish what is complete.
Historical Narrative Group Database roadmap
The remainder is preserved historical planning. Its version numbers, dates, checkboxes, paths, and architecture claims have not been revalidated against the current platform.
This document outlines the development roadmap for the Narrative Group Database project, highlighting planned features, improvements, and strategic direction.
✅ Kids Interactive Pages: Four new/upgraded pages teaching A2A, inheritance, voting, and parallelization
The current version includes Narrative Performance features, advanced visualization, workflow management, agent communication, STC bot monitoring, and interactive educational components.
Dashboard Redesign: Create a more intuitive dashboard for key management
Mobile Responsiveness: Enhance mobile experience across all pages
Accessibility Improvements: Ensure WCAG 0.2 AA compliance
Performance Optimization: Reduce load times and improve rendering performance
API Enhancements
GraphQL API: Add GraphQL support alongside REST endpoints
Rate Limiting: Implement more sophisticated rate limiting
API Versioning: Introduce formal API versioning
Enhanced Documentation: Expand API documentation with more examples
GitHub Label Inventory: Implemented core data structure, API route extension, and query API endpoints for GitHub label lifecycle management (registry, cross-repo, usage, applications, renames). Multiverse cascade trigger for ‘actionnable’ labels is in place. Full testing is currently blocked by a JSON parsing error during Redis data retrieval.
Three-Universe Hybrid Cloud/Local Platform 🔮 ENVISIONED in Issue #171:
Context: Not just webhook infrastructure, but a ceremonial development platform where every interaction is interpreted through Engineer (Mia), Ceremony (Ava), and Story (Miette) lenses, with kinship-aware session tracking and offline resilience
Core Infrastructure:
Action Queue Infrastructure: Redis-based persistent queue for webhook actions
Local Agent Heartbeat: Track online/offline status of local processing agents (miadi-code)
Queue Polling Service: Local agent polls cloud queue for pending actions
Dual-Mode Processing: Cloud receives webhooks, local processes when available
Offline Resilience: Actions queue when local offline, process when back online
Real-Time Coordination: Priority to online local agents, cloud fallback when offline
Action Status Tracking: Monitor action processing lifecycle (pending/processing/completed/failed)
Retry Logic: Automatic retry on transient failures with exponential backoff
Fire Keeper A2A Protocol: Ceremony-aware agent coordination via Redis broker with human-in-the-loop gating
Cross-Repo Narrative View: Unified story across repositories
Documentation: See issue-171--f016dc81-605f-4fd0-8e02-4690675a6b65--2602120807/VISION_REFINED.md for full three-universe context and ceremonial purpose
QSTASH Integration: ❌ Previously attempted, never functional - considering replacement with action queue system
Vector Indexing: Semantic search and content discovery capabilities
End-to-end Testing: Complete testing with real GitHub webhook events
Performance Optimization: Optimize Redis operations and event processing
Monitoring and Alerting: Add monitoring for workflow health and performance
Security Hardening: Enhanced authentication and rate limiting for workflows
SMS/MMS Communication System
SMS Webhook Endpoint: JSON POST webhook for VoIP.ms integration (/api/workflow/smswebhook) - PREFERRED METHOD
VoIP.ms Format Support: Complete support for VoIP.ms nested JSON payload structure
SMS ETL Parser: Transform SMS data into agent-friendly format with array/string media handling
SMS Event Storage: Redis-based storage with structured keys (Workspace.Communication.sms:from.timestamp)
SMS Context Analysis: Urgency detection, sentiment analysis, and phone number classification
SMS Callback Endpoint: DID service integration for incoming SMS/MMS (/api/workflow/smscallback) - DEPRECATED DUE TO PROVIDER ISSUES
SMS Response Engine: Automated SMS reply system based on agent analysis
SMS ETL Parser: Advanced SMS data transformation system for agent-friendly processing
SMS Context Analysis: Built-in urgency detection, sentiment analysis, and phone number classification
SMS Event Storage: Redis-based storage with structured keys (Workspace.Communication.sms:from.timestamp)
SMS Tracing System: Complete tracing integration following webhook patterns
SMS TTL Management: Configurable TTL using EH_SMS_TTL environment variable (7 days default)
SMS Queue Integration: SMS events automatically added to processing queue for agents
Cross-Platform Consistency: SMS handling follows same patterns as GitHub webhook system
Version 0.2.1 (June 2025)
GitHub Webhook ETL Parser: Created comprehensive ETL transformation system for agent-friendly data
Improved Timestamp Format: Changed from 20250623T14391 to YYmmDDHHmmss format (e.g., 250623143900)
TTL Configuration Management: Implemented configurable TTL using environment variables
EH_WEBHOOK_GITHUB_TTL for webhook raw data (1 week default)
EH_STORY_TTL for agent-friendly processed data (30 days default)
Agent Data Structure: Focused extraction of essential fields for Spiral Agents:
Repository metadata, issue/PR details, reactions, comments, branch information
Dual Storage Strategy: Raw webhook data + processed agent-friendly data with different retention
Enhanced OpenAPI Documentation: Updated all specifications with new webhook response format
Structured Key Generation: Automatic creation of workspace-organized keys (Workspace.owner.repo:type.id.timestamp)
Version 2.0.0 (May 2025)
Added Narrative Performance Feature with text processing engine
Implemented performance orchestration with three modes
Added voice modulation controls
Introduced Advanced Cluster View for key relationships
Added Workflow management system with webhook integration
Implemented Agent Workflow integration
Added comprehensive API documentation with Swagger UI
Added Kids documentation section
Version 0.2.0 (December 2025)
Completed comprehensive Agent Workflow System implementation
Added GitHub webhook endpoint (/api/workflow/webhook) with proper validation
Implemented agent registration and event polling system (/api/workflow/agent-notify)
Added inter-agent communication through workflow notifications (/api/workflow/notify)
Created HOWTO documentation system (/api/workflow/howto) with setup guides
Built CLI testing utilities (scripts/workflow-cli.sh) with interactive menus
Updated OpenAPI specifications with complete workflow endpoint documentation
Enhanced documentation with practical examples and troubleshooting guides
Fixed TypeScript compilation errors across all workflow routes
Resolved Next.js dynamic server usage issues for production builds
Version 1.0.0 (August 2023)
Initial API implementation with memory, redstones, and lattices endpoints
Support for both reader and writer tokens
Dark mode theme with toggle button
Auto-refresh functionality for forge state
Memory key metadata inspection endpoint
🛠️ Technical Debt and Maintenance
Code Refactoring: Improve code organization and reduce duplication
Test Coverage: Increase unit and integration test coverage
Documentation Updates: Keep documentation in sync with features
Dependency Management: Regular updates of dependencies
Performance Optimization: Identify and resolve performance bottlenecks
📝 Feedback and Adjustments
This roadmap is a living document and will be updated based on user feedback, technological advancements, and strategic priorities. We welcome community input on feature priorities and development direction.