# Open decisions and conflicts

Decisions are ranked by roadmap impact, not urgency alone. “Latest point” is a
sequencing boundary, not a delivery date.

| Rank / ID | Decision required and why it matters | Options found in repository | Affected milestones/dependencies | Evidence available / missing | Supported owner or decision-maker | Latest point / consequence of deferral |
|---|---|---|---|---|---|---|
| 1 / D-001 | Accept or hold exact retry3 for the named internal runtime/vector-source scope; release identity cannot be inferred. | Accept exact hash; hold exact hash and keep research-only use | M-001, M-004, M-006 onward | Complete technical evidence; missing owner record | Exact owner named by authorization process | Before full shippable vector/release work; deferral blocks release but not bounded development |
| 2 / D-002 | Decide whether and how the completed full schema-v6.1-r2 evidence changes the production runtime contract; technical completion does not decide adoption. | Keep evidence-only and use schema v5 for the current runtime path; define a separate r2 install/promotion/migration contract; revise or reject r2 with rationale | M-003–M-006; M-002 is already achieved evidence | Full A/B technical PASS, ADR-0032 and strict consumer receipt available; missing runtime migration/update/product-compatibility decision and proof | Architecture/product owner required; exact accountable owner not established here | Before production vectors bind schema-specific units/spans or product/user-data migrations freeze; deferral preserves runtime-schema ambiguity |
| 3 / D-003 | Define rights by surface: local corpus/app/vector distribution, controlled/public population, hosted retrieval, model processing, exports, collaboration and narration. | Separate scopes; limited/private; public/commercial; hold | M-006, M-007, M-010, M-012, M-016 | Legal posture and policy boundaries; no broad authorization | Rights holders/product owners; exact names not established here | Before each external distribution/processing action; deferral narrows release scope |
| 4 / D-004 | Define the first coherent macOS controlled-release population, primary job, feature set and success evidence. | Reader/search/citations; add minimum Projects; include/exclude semantic/Atma by declared gate | M-005, M-006 | Product compass, journeys, prototypes, shell ADR; missing validated segment/tasks | Product owner; release owner must be assigned | Before M-005 scope freeze; deferral risks endless feature integration or incoherent testing |
| 5 / D-005 | Adopt retrieval metadata, semantic-unit, reviewer, metric and threshold contract. | Passage-direct; structure-aware; multi-view; relation-aware comparators; revised provenance-first architecture | M-003, M-004, M-008, M-010 | Bounded research and candidate results; missing independent full judgments and thresholds | Retrieval/product owner plus competent reviewers; names open | Before production model/engine tuning; deferral makes quality claims non-comparable |
| 6 / D-006 | Choose supported Atma runtime profile and product boundary. | Local; BYOK; managed Agent Cloud; mixed; no agent in first release | M-007–M-009, M-016 | Local/BYOK specs and managed-cloud draft conflict; no adopted ADR/economics | Product owner; privacy/security/commercial owners needed | Before provider/account/credit/runtime implementation; deferral risks incompatible architecture |
| 7 / D-007 | Establish Atma source-authority, persona, status, qualified-review and correction governance. | Proposed Constitution/registry; keep formal classifications in Paramatma; narrower corpus librarian | M-008, M-009, M-013 | Detailed proposal and accepted invariants; missing approved anchors/reviewers/process | Product owner plus qualified reviewers; names/mandates open | Before M-008 controlled use; deferral limits agent to safer exact retrieval/explanation |
| 8 / D-008 | Decide commercial offer and public-release evidence. | One-time local purchase; optional subscriptions; limited/private release; no commercial launch yet | M-007, M-010, M-012, M-016 | Draft prices/tiers; no rights, WTP, costs, entitlements, payments, support evidence | Product/commercial leadership; specific owner open | Before price publication or paid launch; deferral keeps controlled/noncommercial scope |
| 9 / D-009 | Choose identity, entitlement, account recovery, deletion and service-boundary architecture. | Local license only; shared identity for services; separate MCP/Agent/sync entitlements | M-007, M-010, M-012 | MCP requirements and draft offers; no implemented system | Product/security/service owner; open | Before hosted or paid pilot; deferral blocks authenticated services |
| 10 / D-010 | Decide Project Writing/Board scope in the replacement shell. | Basic snippet Projects; Writing-first; Writing + Board; phased Board later | M-005, M-006, M-009 | Storage v2, ADR-0021, V3 prototype; no routed/user-validation proof | Product owner | Before M-005 acceptance plan; deferral risks building superseded breadth |
| 11 / D-011 | Define opt-in analytics and controlled-release measurement under no-telemetry default. | Local-only research; explicit opt-in analytics/crash reports; no product telemetry | M-006, M-007 | ADR-0012 and proposed agent receipts; missing privacy/metric design | Product/privacy owner; open | Before controlled release if behavioral metrics are needed; deferral limits evidence to interviews/manual receipts |
| 12 / D-012 | Define Windows activation, parity and support scope after macOS. | Full declared parity; narrower reader/search parity; defer | M-011 | Accepted sequence; no Windows CI/package/hardware evidence | Product/platform owner; open | After M-006 and before Windows investment; deferral keeps Windows planned but unscheduled |
| 13 / D-013 | Decide hosted MCP pilot population, rights, limits, service owner and relation to commercial plans. | Independent paid/included service; invite-only research pilot; defer | M-010 | Detailed accepted service boundary; no deployed service/entitlement/economics | Product/service/security owners; open | Before deployment; deferral has no effect on local app |
| 14 / D-014 | Decide whether cloud backup alone or shared collaboration is the first continuity hypothesis. | Backup/restore only; sync across owned devices; shared projects/roles; defer | M-012 | ADR-0015 seam; draft premium collaboration | Product owner; privacy/security/commercial owners | Before sync architecture; deferral preserves local-only authority |
| 15 / D-015 | Decide Paramatma first adapter workflow, external repo/package contract, statuses and reviewer governance. | Selected-text writing assistant; project claim report; no near-term integration | M-013 | Separate-engine direction and proposed reports; dependency/review evidence missing | Product owners for both systems plus qualified review owner | Before adapter implementation; deferral keeps products separate without loss to base release |
| 16 / D-016 | Decide whether and when mobile research may begin. | Remain deferred; iOS-first decision study; Android-first; one bounded multi-option spike | M-014 | ADR-0025 and superseded historical alternatives; no current demand/device/pack evidence | Product owner; new ADR required | After macOS learning unless exceptional funded evidence appears; deferral is current policy |
| 17 / D-017 | Name the first additional language/edition and its rights, partner, reviewers and maintenance owner—or explicitly defer. | No expansion; one partner-funded edition; demand-ranked research | M-015 | General invariants and existing scripts; no named program | Leadership/product/rights/source owners; open | Before placing any edition in roadmap; deferral leaves only current-corpus language QA |
| 18 / D-018 | Reconcile narration/TTS with the current delivery non-goal. | Keep outside program; research only; later managed add-on; local OS read-aloud only | M-016 | Detailed proposed contract/tiers versus overview non-goal | Product owner; rights/privacy/commercial/qualified language reviewers | Before provider or quota implementation; deferral keeps local accessibility read-aloud distinct |

## Conflict details

### Schema-v5 runtime versus schema-v6.1-r2 production architecture

- **Competing versions:** schema-v5 retry3 is the complete technically verified
  current runtime/vector-source candidate; schema-v6.1-r2 now has a successful
  full-corpus A/B shadow admitted only as non-runtime evidence by ADR-0032.
- **Consequence:** treating the r2 PASS as runtime adoption would overclaim;
  treating schema v5 as the permanent production design would ignore stronger
  full-scale r2 metadata/span/storage/reader-binding evidence.
- **Resolution:** D-001 and D-002 remain separate. The first controls exact
  retry3 internal/vector-source promotion. The second determines whether r2
  remains evidence-only or enters a separately governed runtime contract.

### Local/BYOK Atma versus managed Agent Cloud

- **Competing versions:** current agent/desktop sources preserve local/BYOK
  profiles; the managed routing draft proposes a subscription service with no
  customer API keys.
- **Consequence:** provider selection, privacy copy, project upload, accounts,
  metering, cancellation, offline behavior, cost, and support all change.
- **Resolution:** D-006 requires an ADR/product decision before implementation.

### Corpus-only MCP versus Personal/Organization MCP

- **Competing versions:** accepted MCP owns authenticated read-only corpus
  evidence and no personal state; pricing drafts propose personal/project MCP.
- **Consequence:** attaching projects or memory to the same service would cross
  an explicit architecture/privacy boundary.
- **Resolution:** keep M-010 corpus-only. Remove commercial claims or create a
  separately governed future service through a superseding ADR.

### Project workflow versus product-shell composition

- **Competing versions:** ADR-0021 preserves Projects as local, agent-independent
  writing/research state; ADR-0028 supersedes the V3 shell composition.
- **Consequence:** the workflow is accepted, the prototype layout is not.
- **Resolution:** D-010 selects the minimum workflow and proves it in the one
  routed ADR-0028 application.

### Mobile active timing versus deferral

- **Competing versions:** a historical presentation proposed mobile spikes and
  sync inside 12 months; ADR-0025 forbids active mobile app/FFI/pack work now.
- **Consequence:** historical ranges cannot appear as current dates.
- **Resolution:** M-014 is a late conditional decision milestone; actual mobile
  delivery requires new evidence and an ADR.

### Narration scope

- **Competing versions:** the current overview lists TTS/audio outside the
  delivery program; later agent/commercial drafts specify Narrate with Atma.
- **Consequence:** rich specs and quota tables can be mistaken for commitment.
- **Resolution:** M-016 remains outside-horizon decision readiness until D-018.

## Highest-impact missing evidence

1. Exact owner decision for M-001 and the separate r2 runtime-direction
   decision enabled by completed M-002 evidence.
2. Competent human retrieval judgments and thresholds.
3. First-release user research and minimum coherent product definition.
4. Surface-specific rights and distribution authority.
5. Team capacity, accountable owners, hardware, budget, and operating model.
6. Atma runtime/governance adoption.
7. Commercial validation and account/entitlement infrastructure.

Deferring a decision should narrow the claim or keep the track conditional. It
must not be converted into assumed approval.
