Version 1 coverage matrix

September 2, 2026 · View on GitHub

Use this matrix to find the governed route and approval state for a recurring work area. The bounded version 1 baseline covers product, engineering, services, data, web, interfaces, lifecycle marketing, AI, and operations. “Authored” means that rules and routes exist; it does not mean that independent or qualified approval is complete.

Work areaRequired standards and profilesVendor or platform playbookV1 state
Agentic systemsAI-AGENTS, ENGINEERING-QUALITY, agentic profile; ENGINEERING-JS-QUALITY for JavaScript and TypeScriptTrellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScriptAuthored; qualified review pending
Programmatic interfaces and servicesAPI-CONTRACTS, ENGINEERING-QUALITY, ENGINEERING-JS-QUALITY for JavaScript and TypeScript, OPERATIONS-LOGGING for TypeScript logging, OPERATIONS-RELIABILITY, programmatic-interface/service profileTrellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScriptAuthored; qualified review pending
Database and dataDATA-DATABASE, DATA-QUALITY, DATA-REDIS, database-change and Redis-change profiles; ENGINEERING-JS-QUALITY for JavaScript and TypeScript toolingTrellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScript; GA4 when an analytics implementationAuthored; Redis draft and qualified review pending
Product deliveryPRODUCT-DELIVERY, product-feature profile; ENGINEERING-JS-QUALITY for JavaScript and TypeScriptTrellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScriptAuthored; qualified review pending
Ordinary software changes and test strategyENGINEERING-QUALITY, ENGINEERING-TESTING, software-change profile; ENGINEERING-JS-QUALITY for JavaScript and TypeScriptTesting field guide, recipes, records, and test-strategy playbook; Trellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScriptPost-v1 draft; representative-reader and independent engineering, quality, and operations review pending
Universal UI and contentDESIGN-INTERACTION, FND-ACCESSIBILITY, CONTENT-INTERFACE, UI-feature profile; ENGINEERING-JS-QUALITY for JavaScript and TypeScriptTrellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScriptAuthored; accessibility review pending
Apple interfacesAPPLE-PLATFORM-INTERACTION, universal UI corpus, and Apple-interface profileApple HIG auditPost-v1 platform draft; independent Apple-platform and accessibility review pending
Public web and searchWEB-QUALITY, SEO-FOUNDATIONS, public-web profile; ENGINEERING-JS-QUALITY for JavaScript and TypeScriptTrellis for JavaScript and TypeScript; vendored anti-slop through Oxlint for TypeScript; Search ConsoleAuthored; source and accessibility review pending
Analytics and experimentsANALYTICS-MEASUREMENT, GROWTH-EXPERIMENTS, growth-experiment profileGA4Authored; analytics and privacy review pending
Core lifecycle marketingMARKETING-LIFECYCLE, marketing-lifecycle profileGA4 and Search Console when applicableAuthored; marketing, privacy, and legal review pending
Public project showcaseMARKETING-PROJECT-SHOWCASE, WRITING-FUNCTIONAL, WEB-QUALITY, public-web profileSearch Console when applicableDraft; independent writing and accessibility review pending
Functional writing and errorsWRITING-FUNCTIONAL, CONTENT-ERRORS, functional-writing profileNoneExisting stable corpus; independent verification pending
Commercial evidence reviewsCommercial-evidence-review profile, FND-EVIDENCE, WRITING-FUNCTIONAL, conditional sales, marketing, privacy, and security routesNonePost-v1 draft; research, sales, and qualified domain review pending
Public legal documentsLEGAL-PUBLISHED-TERMS, legal-document profile, PRIVACY-DATA, FND-TRUST, WRITING-FUNCTIONALNonePost-v1 draft; qualified legal and privacy review pending
Organizational knowledge systemsKNOWLEDGE-SYSTEMS, company-brain profile, federated-knowledge patternStandards conformance auditPost-v1 draft; knowledge, AI, data, security, privacy, product, and engineering review pending
Code and dependency removalENGINEERING-CODE-REMOVAL, code-removal profile, FND-CHANGE, AGENT-VERIFICATIONKnip plus Biome/Trellis for TypeScript/JavaScript; Ruff, deptry, and contextual Vulture for PythonPost-v1 draft; engineering review pending
Reliability and incidentsOPERATIONS-RELIABILITY, FND-CHANGE, reliability/incident profileNoneAuthored; operations and security review pending
Privacy and application securityPRIVACY-DATA, SECURITY-APPLICATIONNoneExisting drafts; qualified review pending
Secrets and credentialsSECURITY-SECRETS, secrets/Infisical profileNone; Infisical is required by the standardAuthored; qualified security and operations review pending
External platformsINTEGRATIONS-VENDOR plus the closest task profileSeparate Stripe, Plaid, Vercel, Resend, Neon, and Cloudflare playbooks with manifest-backed review bundlesPost-v1 drafts; provider-domain review pending

Cross-cutting foundations

Every active profile routes directly or conditionally to evidence, trust, safe change, accessibility, privacy, security, and agent verification according to the task's behavior and risk.

Outside the v1 boundary

The former specialist queue is now authored as governed drafts: MARKETING-PAID-MEDIA, MARKETING-DIRECT-OUTREACH, MARKETING-PUBLIC-ENGAGEMENT, MARKETING-DISTRIBUTION, SALES-REVENUE-OPERATIONS, DISCOVERY-APP-STORES, and MEDIA-PRODUCTION-RIGHTS, routed by PROFILE-SPECIALIST-MARKETING. LEGAL-PUBLISHED-TERMS and PROFILE-LEGAL-DOCUMENT add a post-v1 route for public terms, notices, policies, and addenda. These documents remain outside the bounded v1 release and need independent, domain-qualified review before activation. The marketing coverage map records each external Marketing Skills task and its exact route.