# 18-month candidate roadmap

**Status:** Recommended rolling-wave sequence for planning review. It is not an
approved delivery commitment and does not change the ordered program or any
authorization boundary in `docs/CURRENT.md`.

## Sequencing thesis

The recommendation protects the existing dependency spine while introducing a
user-value wedge:

1. resolve the corpus promotion and runtime-schema decisions, using the already
   completed full r2 evidence, and freeze the retrieval contract;
2. integrate a coherent offline reading-to-Project macOS experience in
   parallel;
3. prove that experience with a controlled population;
4. add one narrow grounded Atma capability;
5. use observed evidence—not aspiration—to decide commercial release, Windows,
   hosted MCP, governed continuity, and conditional expansion.

This sequence is preferred because the local product can create value without
cloud, mobile, collaboration, or long-term agent memory, while every later
intelligence/service capability depends on trusted corpus and retrieval
contracts.

## Horizon 1 — months 0–3: decisions and executable foundations

**Intended outcome:** Downstream work converts the completed r2 evidence into an
explicit runtime-direction decision, gains an unambiguous corpus basis, develops
an evaluation contract, and advances the product shell against honestly labeled
artifacts.

| Milestones | Major deliverables | Dependencies/evidence | Decision points | Confidence and unresolved scope |
|---|---|---|---|---|
| M-001 Corpus release basis decided | Exact retry3 accept/hold record and downstream policy receipt | Exact immutable identity; named owner | Freeze internal/vector source or revise assumptions | High on need; timing depends on owner |
| M-002 Full-corpus schema evidence completed — achieved starting state | Sealed r2 A/B shadow, strict full-shadow wrapper, full-scale consumer/reconciliation receipts | Consumed exact authorization; ADR-0032; immutable artifact | Keep evidence-only, specify a separate r2 runtime-adoption contract, or revise | High for achieved evidence; runtime-direction decision open |
| M-003 Retrieval/eval contract adopted — begin and close as evidence allows | Structural metadata rules, reviewer protocol, judgments, lexical baseline, threshold/ADR draft | Competent reviewers and authentic pack | Approve production comparison contract | Medium; reviewer capacity/thresholds unknown |
| M-005 Offline research UX — implementation slice | Generic navigation/direct reader contracts, selected end-to-end thin journey, critical states | Candidate-bound core, design system, user-data v2 | Confirm minimum coherent release journey | Medium; Project Writing/Board scope open |

Parallel continuous work: user task research, source/rights mapping, product
segment interviews, accessibility planning, security/threat modeling, release
hardware definition, and documentation truth checks.

Verification evidence: M-002 exact authorization/build/strict-bundle receipts;
M-001 decision receipt when recorded; reviewer-provenance eval artifacts;
generic hierarchy/direct-leaf and user-data round trips; no claim of release
readiness.

## Horizon 2 — months 3–6: trustworthy retrieval and coherent local value

**Intended outcome:** A named retrieval release is certifiable and the routed
macOS product supports a coherent offline reading-to-research journey.

| Milestones | Major deliverables | Dependencies/evidence | Decision points | Confidence and unresolved scope |
|---|---|---|---|---|
| M-003 close | Frozen eval/metadata/unit contract and human judgments | Horizon 1 evidence | Permit production candidate comparison | Medium |
| M-004 Retrieval release certified | Deterministic sidecar, selected model/engine/runtime, truthful modes/fallbacks, release eval | M-001–M-003 | Permit semantic mode in declared releases | Medium; outcome depends on measured gains |
| M-005 Offline research experience integrated | ADR-0028 shell, reader/search/citations, notes/highlights, minimum Projects, accessibility/critical-state proof | Schema/core and product-scope decisions | Define controlled-release feature set; retire proven compatibility branches | Medium |

Parallel continuous work: controlled-release recruitment/design, macOS
packaging/update experiments, rights review, support/correction workflow,
Atma runtime/governance decision, and commercial discovery. Windows may receive
portable compile/static preparation only if it does not delay macOS; no support
claim.

Verification evidence: named corpus/vector identities; A/B deterministic
builds; per-stratum evals; exact citations; real routed app journeys; keyboard,
screen-reader, loading/empty/error/offline and restart behavior.

## Horizon 3 — months 6–12: controlled macOS product and bounded intelligence

**Intended outcome:** Real users can safely use a declared macOS product, and
one narrow Atma capability can be evaluated without requiring long-term memory
or cloud collaboration.

| Milestones | Major deliverables | Dependencies/evidence | Decision points | Confidence and unresolved scope |
|---|---|---|---|---|
| M-006 macOS controlled release ready | Signed/notarized package; corpus/vector install; onboarding; update/recovery; support path | M-004/M-005; scoped rights; release audience | Expand, narrow, iterate, or hold | Medium; release population and thresholds TBD |
| M-008 Narrow grounded Atma ready | Neutral tools; bounded loop; policy/citation gate; trust UI; eval/red team; problem report | M-004/M-005 and runtime-profile decision | Broaden controlled workflows or hold | Medium/Low; governance/provider choice open |
| M-007 Commercial release decision supported — conditional | Rights/offer/entitlement/channel/support/measurement evidence | M-006 learning; commercial/legal decisions | Public/limited release, revised offer, or defer | Low/Medium; not automatically achieved by month 12 |

Parallel workstreams: M-009 schema/policy design without broad memory launch;
M-010 hosted-MCP implementation planning after the macOS milestone; Windows CI
and packaging planning after M-006; user/corpus research and AI evaluation.

Verification evidence: direct install/update/recovery and task success;
accessibility/performance on declared Macs; controlled user observations;
supported-claim/citation/abstention/privacy tests; operating/support receipts.

## Horizon 4 — months 12–18: evidence-selected expansion

**Intended outcome:** Only the expansion tracks whose prerequisites and observed
value justify investment reach a verifiable state. Detail is intentionally
lower because product evidence, capacity, and decisions are not yet available.

| Candidate milestone | Directional outcome | Conditions to enter | Decision enabled | Confidence |
|---|---|---|---|---|
| M-009 Governed project continuity | Multi-session projects and inspectable user-owned memory pass longitudinal tests | M-008; memory/privacy/schema decisions; migration/recovery proof | Enable/limit advanced skills and proactivity | Low/Medium |
| M-010 Hosted MCP pilot | Authenticated invited clients receive bounded evidence with operational controls | M-004/M-006; rights; service owner; auth/entitlement | Expand, revise limits, or stop | Medium/Low |
| M-011 Windows supported release | Declared Windows parity passes direct package/runtime/UX proof | M-006; Windows CI/hardware/signing/support capacity | Claim Windows support or defer | Medium/Low |
| M-012 Cloud project continuity pilot | Opted-in backup/restore and possibly shared-project value is validated | M-009; adopted commercial/account model; rights/privacy/cost | Backup-only, collaboration expansion, or defer | Low |
| M-013 Paramatma selected-text workflow | Thin adapter and human-reviewed evidence report pass | M-008; external contract/repo; qualified review | Expand adapter or keep conditional | Low |
| M-014 Mobile investment decision | Evidence supports one platform/product strategy or continued deferral | M-006 learning; user demand; explicit spike authority | Fund iOS/Android/none; new ADR | Low |

M-015 additional language/edition and M-016 narration remain outside the base
18-month sequence unless a named source/partner or strong product/commercial
evidence closes their prerequisites. Keeping them visible does not reserve
capacity.

## High-level candidate sequence

```text
Months 0–3    decide corpus basis + decide how completed r2 evidence
              affects the runtime contract
              freeze retrieval/evaluation contract
              build first coherent ADR-0028 journey in parallel

Months 3–6    certify retrieval release
              integrate offline reading-to-Project macOS experience

Months 6–12   controlled macOS release
              narrow grounded Atma controlled use
              commercial release decision only if evidence is sufficient

Months 12–18  evidence-selected Windows, hosted MCP, project continuity,
              cloud continuity, and Paramatma tracks
              mobile decision only; language/narration normally outside horizon
```

## Conditional branches

### If retry3 is held

- Continue bounded schema/retrieval/product work over read-only evidence.
- Do not build a shippable vector sidecar, declare canonical runtime, or perform
  release proof.
- Reframe M-001 as a recorded hold plus a named corrective corpus path; revise
  all downstream horizon confidence.

### If schema-v6.1-r2 is not adopted as a runtime direction

- Preserve the successful full-shadow evidence as Tier B evidence-only work and
  decide whether to retain schema v5, revise r2, or evaluate another runtime
  architecture.
- Do not silently bind product spans, editions, filters, migrations, or vectors
  to a technically successful but non-runtime artifact.

### If vector quality or product economics do not justify a sidecar

- Retain verified lexical/structured retrieval and truthful capability labels.
- A reader-only or lexical-only controlled release would require explicit
  revision of the current database-then-vector program, but it is a credible
  alternative to indefinite delay.

### If controlled macOS use shows weak product value

- Narrow or revise the reading/Projects experience before expanding Atma,
  Windows, cloud, or public distribution.
- Treat task failure as product evidence, not a prompt to add more features.

### If managed Agent Cloud is not adopted

- Keep Atma local/BYOK only if that profile passes privacy, product, and
  support gates; remove managed-credit/tier assumptions from M-007.
- Hosted MCP remains separately viable because clients own generation.

## Material alternatives

### Alternative A — earlier lexical-only controlled reader

Prefer this if vector evaluation/build becomes the dominant delay while exact
reader/search/Projects value and scoped rights are already strong. It requires
an explicit product-program decision because current intent places evaluated
vectors before macOS release. Benefit: earlier user evidence. Risk: release
scope may not represent the intended semantic/Atma value proposition.

### Alternative B — research-workspace-first controlled release

Prefer this if target users validate Projects Writing/Board as the main
differentiator and exact lexical evidence is sufficient for their first tasks.
Benefit: sharp user-value wedge. Risk: V3 breadth could delay a coherent reader;
the minimum workflow must be kept narrow and inside ADR-0028.

### Alternative C — hosted-evidence-first after corpus/retrieval

Prefer this only if licensing favors remote bounded access over local
distribution and external-client demand is verified. Benefit: one controlled
service surface. Risk: does not prove the in-product VedaBase experience and
adds auth, anti-extraction, operations, and service cost.

### Alternative D — partner-funded language, institution, or mobile track

Prefer only when a named partner supplies demand, rights, funding, reviewers,
and maintenance capacity without diverting the macOS foundation. Benefit:
external evidence/capacity. Risk: bespoke scope and governance can distort the
core program.

## What would cause resequencing

- Owner accept/hold outcomes or a failed full-scale schema gate.
- Retrieval evidence that rejects the assumed semantic-unit/model/engine path.
- Rights that permit one distribution surface but not another.
- Controlled-release evidence showing a different primary job or an
  incomplete minimum experience.
- Staffing/capacity that prevents the documented parallel lanes.
- Security/privacy findings that require architecture or product changes.
- A funded partner with named rights/reviewers for an otherwise conditional
  edition or institutional workflow.
- A new accepted ADR superseding platform, agent runtime, MCP, memory, or
  product-shell direction.

The sequence should be reviewed after each milestone decision. It should not be
converted into quarter-by-quarter promises until owners, capacity, thresholds,
and release populations are explicit.
