0 open prototype placeholders3 built · 7 awaiting a real-world dependency
No prototype placeholder is left open. Every row below has been built out as far as the prototype can take it; the rows marked "awaiting a real-world dependency" wait on a contract, a provider or a legal opinion rather than on more build work.
PH-1
Simulated login, KYC and MFA labels
Label onlyD-16
Awaiting a real-world dependency
Today: Persona selection with the label "Simulated demo sign-in". No credential is entered, stored or verified.
Built in the prototype: The Security & PDPA posture screen is built — retention schedule, processor register, MFA policy matrix, KYC document sets and a working data-subject request register. Real sign-in still needs an identity provider.
Information needed
Chosen identity provider and session model (hosted auth vs self-managed).
MFA policy: which roles are forced, which factors are accepted.
KYC/KYB provider, the document set per stakeholder type, and who reviews a failed check.
Approve the identity and KYC workstream, then replace the persona gate with real sign-in and per-role MFA enforcement.
PH-2
Mock trustee banking rails
Mock valueD-4
Awaiting a real-world dependency
Today: The trustee is a real persona with its own portal, pooled account reference and settlement confirmations — but the account number, payment references and settlement timing are mock values.
Built in the prototype: The trustee is a full persona: its own portal, pooled account, per-project sub-ledgers and settlement confirmations that appear on the project ledger and escrow position. Real account details need the executed mandate.
Information needed
Executed trustee agreement, including the named trust account and sub-ledger reporting format.
Payment rail and file format for release instructions, plus the settlement cut-off actually offered.
Reconciliation channel: statement feed or API, and the break-handling procedure.
Action that fills it
Sign the trustee mandate, then swap mock account references and settlement timing for the trustee's real reporting feed.
Today: Refund and reversal are built and post to the ledger. Freeze, dispute and cancellation panels remain greyed and tagged as reserved.
Built in the prototype: Refund and reversal post to the ledger today. Freeze, dispute and cancellation stay reserved pending the exception policy.
Information needed
Who may freeze a project sub-ledger, and on what documented trigger.
What a frozen sub-ledger blocks: deposits, releases, retention release, or all three.
Cancellation settlement rule: how work certified but unreleased is treated.
Escalation owner for a contested amount, given no adjudication workflow exists in scope.
Action that fills it
Confirm the exception policy, then activate the greyed panels using the existing refund/reversal ledger types.
PH-4
Native app and offline capture
Form-factor noteD-15
Built in prototype
Today: Responsive web only, with a note that offline evidence capture is relevant but undecided.
Built in the prototype: Offline evidence capture is built: a queued capture path with a simulated connection toggle, visible sync state and same-milestone conflict flagging.
Information needed
Whether site evidence must be captured with no connectivity at all.
Device mix on site, and whether camera metadata must be trusted.
Sync-conflict rule when two people capture against the same milestone offline.
Action that fills it
Decide web-plus-offline-cache versus a native shell, then add a queued capture path with visible sync state.
PH-5
Seeded facility figures are read-only
Greyed controlFD-10FD-1
Awaiting a real-world dependency
Today: Facility limits, drawdown schedules and disbursement status are seeded mock values in RM. Edits to seeded rows are disabled; only simulated drawdowns can be added.
Built in the prototype: Facility limits, drawdown schedules and the facility portal are built with seeded values; edits stay closed until the data source is agreed.
Information needed
Source of facility data: manual entry by the desk, or a file/feed from the financier.
Which facility fields the desk may edit after origination, and who approves a change.
Whether drawdown approval sits with the desk in this product or outside it.
Action that fills it
Agree the facility data source, then open the edit path for the fields the desk owns and keep the rest as reported values.
PH-6
Mock documents, certificates and receipts
Mock valueD-16
Built in prototype
Today: Every document is generated in-app with a mock audit hash and a "Simulated" watermark. No e-signature exists.
Built in the prototype: Typed acknowledgement signing is built: signature blocks, a per-document-class retention register and audit-hash verification with match / mismatch / not-registered results.
Information needed
Signing model: typed acknowledgement, drawn signature, or a certified e-signature provider.
Document retention location and period, and who may re-issue a document.
Whether the audit hash must be independently verifiable, and against what register.
Action that fills it
Choose the signing and storage model, then replace generated documents with signed, retained originals.
PH-7
Regulatory posture statement
Label onlyFD-1
Awaiting a real-world dependency
Today: "No regulatory or licensing claims — FD-1 pending" appears wherever money is shown.
Built in the prototype: Every money surface carries the no-claims wording. Only a legal opinion can replace it.
Information needed
Legal opinion on the activity performed: payment agent, escrow agent, or neither.
Whether funds sit with a licensed trustee only, and the resulting obligations.
Disclosure wording each stakeholder must see before funding.
Action that fills it
Obtain the legal opinion, then replace the pending label with the approved disclosure wording.
PH-8
Notification delivery outside the app
Mock valueSM-2
Awaiting a real-world dependency
Today: Email, SMS, WhatsApp and push channels are configurable per user and per event class, but nothing is dispatched — external messages are content-free by rule.
Built in the prototype: The escalation ladder is built: four tiers, wait intervals, money-critical override, content-free channel previews and an acknowledgement that stops the ladder. Delivery still needs providers.
Information needed
Chosen delivery providers per channel, and the sender identities.
Content rule confirmation: what may leave the platform without exposing amounts.
Quiet-hour override for money-critical events, if any.
Action that fills it
Connect delivery providers, then dispatch the already-modelled event classes using the stored preferences.
PH-9
Support escalation approver is a mock role
Mock valueSM-5
Built in prototype
Today: Support is read-only, escalation is time-boxed, and every action is logged with actor, target record and reason — but the approver is a mock named role.
Built in the prototype: A named approving function with out-of-hours cover is built, with a time-boxed escalation window, auto-expiry and never-escalatable record types.
Information needed
Named approving function and its out-of-hours cover.
Maximum escalation window, and which record types can never be escalated.
Retention period for the support action log.
Action that fills it
Assign the approving function, then bind escalation approval to that account instead of a mock name.
PH-10
Supplier profile display choice
Greyed controlD-18
Awaiting a real-world dependency
Today: Materials use one generic naming convention. Whether a supplier profile is shown is a toggle, and no listing is ever presented as a platform recommendation or endorsement.
Built in the prototype: Neutral generic material naming and a supplier profile toggle are built. Display needs supplier consent.
Information needed
Supplier consent wording for profile display.
Which profile fields may be shown, and by whom they are verified.
Neutral ordering rule for any list of suppliers.
Action that fills it
Collect supplier consent, then enable profile display with the neutral ordering rule stated on the surface.