Decisions locked 2 August 2026. Revised after round-1 QA (Fable + Sol). This is the change spec: what changes, in which of the four layers, and in what order. Nothing is built until it appears here. Every change lists its edit in each layer it touches, so the layers never drift apart. Source of truth is the product spec; the developer doc and the UX cite its section numbers; the change log records each shipped change.
Round-1 QA outcome: Sol NO-GO 3/10, Fable GO-WITH-FIXES 6/10. They found 3 criticals, ~8 highs, ~8 mediums. Every finding is adopted below (nothing overruled). The target is both critics at 10/10. Round-1 fixes are marked
[QA-fix]where they change a prior version.
spec 3.1, spec 15, build §15 D2.)spec 15, build §5b.)spec 4.1/4.3, build §2.3.)Marko's four calls (2 Aug): (1) points register +5 / close +15 (the evidenced-withdrawal point source stays 25 — this is the +25 points, distinct from the +$2 loyalty "evidence bonus" payment in build §3.4f2) [QA-fix r2: name collision]; (2) casino H1 contains "review"; (3) founding records shown in the header total, labelled (with the measurement guardrail below); (4) public standing = popover on the member chip, no member page.
[QA-fix]Both critics caught it: pre-publication human approval is a REJECTED design (spec 3878: "pre-publication human approval was considered and rejected"; build §15 D5: publish immediately, gate the statistics, the rejected option is the approval queue; spec 3.9/5.5: publication is immediate, automated screening holds only a small flagged group for a person). So the review layer must NOT have a CM approval queue, a "pending / in review" default state, or an "old version stays public until the new one is approved" flow.
Corrected model, used everywhere below: a written account publishes immediately after automated screening. Only an auto-flagged item is held for a moderator (spec 5.5/740/1942). Moderation is flagged-item review and takedown, never gate-before-publish. Appended updates (never edits [QA-fix r3, spec 5.4]) are auto-screened first (spec 5.5), then a clear update publishes within seconds while a flagged one is held independently [QA-fix r4: screen-before-publish, not publish-then-screen]. Never a human approval gate.
Order: decisions (done) -> P0 schema/API + spec/build edits (Part C) -> UX -> changelog. Evidence/state changes (D6, D7) land before reward copy (D1, D5), which depends on the reward-event schema (P0-1). Framing (D2, D3, D4-UX) depends on nothing and lands last. Every row touching a LOCKED marker names its spec-appendix entry + build §15 decision-log row (Part D tripwire). [QA-fix: tripwire rows added to D1/D5/D6/D3.]
| # | Change | Product spec | Developer doc | Design / UX | Change log |
|---|---|---|---|---|---|
| D6 | request_proof opening-evidence tier: casino_email (strong) > pending_screenshot (soft) > typed. A third, separate evidence dimension, never merged into the LOCKED 4.7 bad-ending ladder and never into arrival-proof. Email is accepted only as a screenshot or PDF artifact (14.10), player-supplied, never a parsing dependency. |
rewrite 2.7; reconcile 2.1 step-2 + 2.3 (email is an alternative artifact, screenshot-first ordering preserved); reconcile 13.1 (a single player-supplied artifact is not "depending on parsing casino emails"; add a comparability note so no-email casinos are not shown weaker); display rule in 3.1; note 14.10; spec appendix entry + build §15 DIM-6 row (edits LOCKED 3.1) |
§3.1 new field request_proof; §4 new enum with its OWN tokens (not .t1/.t2/.t3); §13 assignment row; 4.7 ladder untouched |
casino.html .rq chip on .rl; log.html #s1 alt artifact path + #s2 "Opens as"; app.html capture screens; verification-rules.html |
"Request evidence tiers" |
| D7 | "Answered = verifiable only." Player confirmation or on-chain clears a claim. An operator payment reference is an annotation, never a state; unverifiable answers show as "answered, disputed". | add a line to 4.4 / 4.9 (refusal-artifact + answer rules); strike the phantom edit (14.13 has no such open question) [QA-fix] |
needs storage [QA-fix]: annotation entity (operator ref, source, timestamp) in the P0-5 event log + P1-7 timeline; .st2 state unchanged |
casino.html .opsays/.opsays.disp chip; backoffice #p-operators resolution actions |
"Answered means verifiable" |
| D1 | Points for a registered cashout with a casino-email artifact attached (a fact, paid regardless of outcome). Gated on the D6 email tier. Value +5 (locked). | 7.1 points-table row (email-tier only, +5); guards 14.2/14.4; spec appendix + build §15 DIM-1 row (edits LOCKED 7.1) |
§12 point-source row (+5) as a reward-event (P0-1), not a ledger tweak [QA-fix] |
log.html s2/s4 "+5"; verification-rules.html; account.html "Points activity" card | "Register reward" |
| D5 | Points for confirming the ending, so fast payouts get recorded. Value +15, eligible = the player-confirmable terminals only: Paid, Refused, Account closed, Closed short, Method changed [QA-fix r2: excl. Cancelled (free-to-repeat attack, spec 5.2); excl. Unconfirmed + Abandoned-unpaid — those are reached by 21d silence and have no confirmation event to pay for], once per member/casino/window, capped. |
7.1 row (+15, one reward-event, eligible = the 5 confirmable terminals above; per-member/casino/window cap); 4.3 prompt; 10.3 email buttons; spec appendix + build §15 DIM-5 row |
§12 reward-event row (+15); §12b reminder job carries the bonus line | account.html confirm CTA; app.html ending screen; email template | "Close bonus" |
| D2 | "Tracking, not fighting" framing. On register the player sees the median + the alert promise. | one rule in 2.1 (post-upload benchmark screen) | none | index.html hero + how-it-works; log.html s4 done | "Framing pass" |
| D3 | Founding clocks visible at launch, labelled, separate bucket. Header display total may include them with an inline "(N organic + M founding)" label (Marko call 3); they still never enter any measurement (median, overdue benchmark, deposit-again range, paid-rate, ranking). Every founding record keeps a record-level "Founding member · incentivized" label (7.2) [QA-fix]. |
clarify 7.2; appendix + build §15 DIM-3 row authorizing the labelled display-total change (7.2/7.3 otherwise prohibit organic-counter entry) [QA-fix] |
§3.4f3; keep founding out of every scoring read path | casino.html live rows .prov.founding + record-level disclosure; .chead total shows "(N organic + M founding)" |
"Founding clocks labelled" |
| D4 | Reconfirm nudge + last-confirmed date (UX). Not doctrine-neutral for the backend [QA-fix]: the one-tap "still unpaid" is a write. |
none to the count doctrine; note in 4.1 | §3.1/§12b: the tap writes last_player_reply and latches said_outstanding; it is a reminder_answer and earns the existing 2 pts (7.1), not zero and not the close bonus [QA-fix]; timer semantics unchanged (21d silence still applies to true silence) |
account.html .cbtn.pulse + "last confirmed unpaid N days ago"; casino.html still-waiting rows |
"Pulse UX" |
| D8 | Auto-close: keep chain-close in MVP (specced, cheap). No email parsing at all, ever [QA-fix r2: prior "player-forwarded artifact" reintroduced forbidden parsing — spec 13.1/15]; a payment email only ever enters as a member-uploaded JPEG/PNG/HEIC/PDF artifact (14.10), same as D6, never a parsed forward. Dimitar suggested deferring chain-watch too; not a locked-3 item, so kept but recorded here. |
2.1 keep chain-close; add nothing to remove (no forward-parsing text exists); state upload-only [QA-fix r3: phantom edit] |
§13 roadmap note (no mail-parsing path) | none at MVP | when shipped |
| D9 | Discovery via page shape, not score. H1 = "Nordvale Casino review" (Marko call 2) + per-method ranking + indexable one-record pages. Zero rating number anywhere. | 8.1 + 12 SEO note; 3.1/15 LOCKED | §14 GET /ranking exists; add SEO + one-record read routes (see Part C new-page contracts) | casino.html H1/title/meta/.crumb/.revline (NEW element); index ranking tabs |
"Review-shaped discovery" |
[QA-fix: reshaped]Reviews return as a first-class non-scoring layer that publishes immediately (screening, not approval).
[QA-fix: prior claim corrected] — it already covers both writer types, tiers, and takedowns; the real gap is build §3.6 + the UX. State the hard invariant beside the ch15 rule: "no review, vote, or comment feeds any median, count, trend, or ranking."[QA-fix, critical]: deposit_again is asked only at a record ending and lives only on the terminal withdrawal record (spec 5.2), where it feeds the published range. A review never carries it as its own field; if shown near a review it is mirrored read-only from that member's own terminal record. The composer never asks it.[Marko call 2 Aug: transaction-proof, NOT mandatory Sumsub identity KYC — that is Dimitar's "central USP" and we deliberately differ]. Tiers by spec 5.1 casino standing: Deposited -> writes into the main standalone bucket; Withdrew-here -> attached premium; account-page-only (no transaction) -> can read and take part but CANNOT post a review until a deposit or cashout is proven [Marko call: raises the 5.1 floor — account-page alone no longer writes a review]. This edits LOCKED-adjacent 5.1, so it carries a spec appendix + build §15 DIM-7 row. Placement (buried vs standalone vs premium) is gated by evidence; the write gate is one proven transaction.[QA-fix r2, spec 5.4 / build §3.6]: the author cannot rewrite or delete published text. A correction is a dated child-row update appended to the thread; the whole thread shows in order. Each update is auto-screened first (spec 5.5); if clear it publishes within seconds, if flagged it is held independently [QA-fix r4] (no human approval gate). There is no edit/version-rewrite flow.[QA-fix: fork resolved]) with the build §3.6 enum verbatim: screening state = published | flagged_held | redacted | removed, evidence badges, and append-only child-row updates. Each child-row update carries its OWN screening state + removal/redaction metadata [QA-fix r3, spec 5.4-5.5 / §3.6], so a flagged update can be held or redacted independently while the rest of the published thread stays visible. Keep the whole thing out of every scoring read path (same guard as §5b).[QA-fix: four-layer rows added; reprioritized]Priority is cannot-retrofit-first. Every item now names its four layers (the round-1 gap). [QA-fix]
P0 — schema-level, cannot retrofit (build these before any UX in Part F consumes them):
| # | P0 item | Spec | Build doc | UX surface | Changelog |
|---|---|---|---|---|---|
| 0 | Cross-casino privacy-safe reputation computation — MOVED UP from P2 [QA-fix] (spec 14.13 "design before the member schema is final", Sol gap-review "urgent"; it gates the distinct-casino point source + member schema) |
14.13 design | §5 (account linking) + §12 (distinct_casino_deposit OFF until this ships) [QA-fix r3] |
none (internal) | "Privacy-safe reputation design" |
| 1 | Reward-event schema (idempotent, replayable: register +5, close +15, evidenced-withdrawal +25 points, review-screened). D1/D5 depend on it. [QA-fix r2: "evidenced-withdrawal points", not "evidence bonus" = the +$2 payment] |
7.1 | §12 | account "Points activity" | "Reward-event schema" |
| 2 | Evidence-facts + provenance (artifact, extractor, OCR confidence, profile-match, human override). D6 needs it. | 14.10/13 | §4/§13 | log/app upload | "Evidence provenance model" |
| 3 | Appeals entity in front of every penalty, removal, payout denial, evidence rejection. | net-new appeals section (+5.5 screening context) [QA-fix r4: 5.5/6 don't define appeals]; must specify scope, transitions, permissions |
new Appeal entity + API contract (states: open/upheld/overturned; one per decision; second-moderator assignment) |
account modal + backoffice #p-appeals |
"Appeals entity" |
| 4 | Operator claim lifecycle — claim via primary-domain email magic link (spec 6.6/build §11, "and nothing else"); NO DNS/file [QA-fix]; scoped creds, transfer, expiry, entitlement, billing, disclosure, all out of calculation queries. |
6/11 | §11 | operator console | "Operator lifecycle" |
| 5 | Immutable business-event log (append-only) covering reward/evidence/state/moderation/operator-annotation (D7) events. | 12.5 (audit log from day one) + 11.10 (nothing quietly deleted) [QA-fix r2: 15 = never-build, wrong home] |
§6 audit row | backoffice | "Business-event log" |
| 6 | Automated screening + flagged-item moderation for written accounts [QA-fix: was "CM approval workflow"] — auto-screen, publish immediately, hold only flagged (3.9/5.5). |
3.9/5.5 | §3.6 | backoffice #p-reviews (flagged queue) |
"Screening + flagged moderation" |
P1 — needed for a credible full platform [QA-fix r2: four-layer rows added, was prose]:
| # | P1 item | Spec | Build doc | UX surface | Changelog |
|---|---|---|---|---|---|
| 7 | Operator counter-evidence timeline (versioned, redacted, own moderation state) | 4.9/6 | §11/§3.6 | casino .opsays -> .otl; operator console |
"Counter-evidence timeline" |
| 8 | Reputation entitlement backend (penalties, level history, Top invites, corroboration independence, inactivity/revocation) | 7.1 (level curve LOCKED) [QA-fix r3: §7.4 does not exist] |
§12 | account "standing" + popover; backoffice #p-members |
"Reputation backend" |
| 9 | Payout operations hardening (compliance, provider refs, idempotency, failures, replacement, reconciliation) | net-new (partial: tester rewards 7.2) [QA-fix r4: ch6 is Casino Profile] |
§2.5 payout machine + §3.4f/f2 + §6 payout.approve [QA-fix r3] |
backoffice #p-payouts; account redeem |
"Payout ops" |
| 10 | Universal casino ingestion (discover/identity/crawl/ownership/staff-confirm) | 6.2/6.5/6.6 (casino identity) [QA-fix r4: ch10 is Interface] |
§10 (+§11 ownership claim) | backoffice #p-ingestion; provisional page states |
"Universal ingestion" |
| 11 | Search + feed indexes (full-text search net-new; trending, decay, diversity) | 10.8 feed (privacy, evidence-tier, rate-limit, sampling, amount-band guards) + full-text net-new; 8.1 for ranking only [QA-fix r5: §8.1 is rankings, feed lives in 10.8]. Decay affects feed recency only, never a measured figure. |
§14 | #searchov grouped; index feed/trending |
"Search + feed" |
P2 — operational completeness [QA-fix r2: four-layer rows added]:
| # | P2 item | Spec | Build doc | UX surface | Changelog |
|---|---|---|---|---|---|
| 12 | Contests / campaign admin | net-new (relates to 7.2 founding-corpus paid contests) [QA-fix r3] |
§12 | backoffice campaigns | "Campaign admin" |
| 13 | Notification prefs + follows + delivery logs | net-new (10.3 covers only email-confirm buttons) [QA-fix r3] |
§12b | account settings; follow controls | "Notifications + follows" |
| 14 | Versioned consent / policy / reward-terms / jurisdiction (the reward-jurisdiction subset moved to P0/I1 [cov-fix r2]; this row keeps consent/policy/reward-terms versioning) |
11.7-11.9 (jurisdiction) [QA-fix r3] |
§11 | footer legal; consent capture | "Versioned policy" |
| 15 | Public APIs | net-new (spec side); read routes in §14 | §14 | (docs surface) | "Public APIs" |
| 16 | Member profile privacy controls | net-new (privacy promise lives in ch5/safety, not a controls section) [QA-fix r3] |
§11 | account privacy; popover scope | "Privacy controls" |
| 17 | AI-summary provenance + human correction | 5.3 + 5.6 (our summary marked as ours; themes never a number) [QA-fix r3] |
build home TBD (new) | casino summary block | "AI-summary provenance" |
Deferred against a LOCKED line — DESIGN ONLY in v1 [QA-fix]: the terms-watch archive (spec 6.1 LOCKED: "version one does not build the weekly terms archive"). v1 work is the append-only schema design on paper only — no storage deployed, no snapshots, no parser jobs, no public page. Shipping it requires a 6.1 amendment (appendix + §15 row) first.
build §15 decision-log row naming what it replaces. [QA-fix: now applied to D1, D5, D6, D3, terms-watch — round 1 had only D7.]area lists every layer touched.Keyed to the classes that exist in /Users/supersonic/Downloads/Unrigged-prototype-live/. Any chip on >1 page is one component, one copy string; every new block cites its spec section.
THREE evidence chip families that must never blur [QA-fix: round 1 had two; the live page already conflates a third]:
- Opening evidence (.rq, how the record was proven to exist when logged): .rq.email / .rq.shot / .rq.typed, with its own token set (not the ladder's .t1/.t2/.t3) [QA-fix]. Renders first in .rmeta.
- Arrival proof (NEW .arr family, split out of the current misuse) [QA-fix, critical]: live casino.html renders bank-arrival proof as .etier t1/t2 on paid rows (lines ~292/297) — that is neither opening nor bad-ending evidence. Chip-kit normalization moves it to its own .arr family (bank_or_wallet_arrival / on_chain / none).
- Bad-ending ladder (.etier.t1..t4, LOCKED spec 4.7): reserved for bad endings ONLY after the split. Normalize the label inconsistency ("Tier 1 · casino email" vs "Proof · casino email") to "Proof · ..." on ending chips only.
Per-change surfaces: D6 .rq chips on .rl rows + log #s1 alternative screenshot/PDF email path (no raw .eml) + #s2 "Opens as"; app data-u="2" + rewrite the "No pending row" .warn; the email path is an alternative input, never a 5th step (.steps i unchanged). D7 .opsays/.opsays.disp amber annotation chip, .st2 state UNCHANGED, off the index .tk feed. D1/D5 .pts pill (mint, own tokens); the account card is "Points activity" not "ledger" (spec 10.7) [QA-fix], rows reuse .hxrow; D5 "+15" on .cbtn.dark + app #upush; .pts never on public casino rows. D2 copy-only (sweep out militant vocabulary). D3 .prov.founding on live rows and a record-level "Founding member · incentivized" disclosure; .chead total shows "(N organic + M founding)". D4 .cbtn.pulse (amber, first in .crow, one-tap = a reminder_answer write earning 2 pts) + "last confirmed unpaid N days ago" (one shared string on account + casino). D9 H1 "Nordvale Casino review" + .crumb + .revline (NEW element [QA-fix]) + index .dcard per-method tabs.
Review layer, element-level [QA-fix: screening not approval; no sentiment field; append-only]: casino.html #reviews (NEW section) after .oreply, before #community. .rev card (NEW) from .thread DNA, no .votes column, left accent only when evidence-backed, header chips (.mstand + "Deposit proven"/"Withdrew here" .pchip — .pchip exists in community.html, port it) [QA-fix r2: named source]. No deposit_again field on the card — if shown, mirrored read-only from the member's terminal record. Optional slimmed .oreply. Invariant .evnote (port from community.html) under the h2: "Written accounts never touch the numbers." Composer gated by casino standing (5.1): registered/account-screenshot -> buried .rl.low; deposited -> standalone; withdrew -> premium [QA-fix r2]. Append-only: authors post dated child-row updates, never edit; each update is auto-screened first, then a clear one publishes in seconds while a flagged one holds [QA-fix r4]. Screening states use the build §3.6 enum verbatim: published (default) / flagged_held / redacted / removed [QA-fix r2] + skeleton. No "pending approval" state.
NEW hooks (net-new, tag so a dev does not hunt for them) [QA-fix r2]: .rq (+.email/.shot/.typed), .arr, .opsays (+.disp), .pts, .rev, .cbtn.pulse (variant of existing .cbtn), .prov.founding (variant of existing .prov, today an inline-styled .prov span), .revline, #reviews. Everything else the plan cites (.etier .thread .rmeta .rl .rl.low .oreply .chead .mstand .crumb .st2 .hxrow .crow #community #p-reviews #p-operators #p-members #searchov .evnote #upush #s1 #s2 .steps .tk .dcard .lb .measure .votes) exists in the live pages.
[QA-fix: P0 schemas precede all UX]Step 0 (was missing): land the P0 schema + API decisions and the spec/build edits they require (Part C P0-0..6 + the LOCKED-marker appendix/§15 rows) BEFORE any component. Part A/D order (spec -> build -> UX) is violated if chips ship before their contracts.
Then: 1. Chip kit (one source): .rq (own tokens), .arr (NEW), .opsays(+.disp), .prov.founding, .pts, "last confirmed unpaid" string, "Provisional page" chip (cite spec 6.5) [QA-fix], the .mstand popover definition (moved here so .rev can consume it) [QA-fix]; + .etier/.arr split + label normalization. 2. Reason-required modal (CM flag-takedown, appeal decisions, payout denials). 3. Review card .rev + .evnote + composer (screening states). 4. .cbtn.pulse. 5. "Points activity" card. 6. Member-standing popover consumers. 7. verification-rules.html copy. 8-16. Pages in dependency order (log -> app -> casino -> account -> index -> rankings -> backoffice -> operator console -> community), then a byte-identical chip diff + spec-citation pass.
[QA-fix: contracts + magic-link + design-only terms].lb + .measure.6.6/§11, no DNS/file), profile editor with live casino preview, one free reply, counter-evidence authoring, billing/entitlement; every editable element a permanent "Presentation only" pill; reuses the backoffice shell.#p-reviews = flagged-item queue (not an approval gate) [QA-fix], new #p-appeals, #p-payouts, #p-ingestion, D7 #p-operators actions.[QA-fix]: spec + build §14 read routes, canonical ownership, redaction, provisional visibility (noindex until staff-confirmed, spec 6.5), and the publish-without-dates mitigation for the spec 3.1 identification risk (dated event lists must not map to a support ticket).review.html single-review page. No global reviews.html index.#p-appeals; a full appeal.html history page is deferred unless a later round argues for it.6.1 LOCKED), no page shipped.Marko's 4 calls (locked): register +5 / close +15; H1 contains "review"; founding in the labelled header total (measurements organic-only); popover not member page.
Defaults (corrected [QA-fix], override any):
- Review section after .oreply, before #community. Adopt.
- Reviews get zero vote/helpful counters; order = evidence-then-recency. Adopt.
- "Casino email" = a screenshot or PDF artifact only (14.10); no raw .eml/forwarded-message parsing (13.1: nothing may depend on parsing casino emails) [QA-fix]. Adopt.
- request_proof: typed chip publicly shown (transparency). Adopt.
- .opsays amber, OFF the index feed. Adopt.
- Pulse "still unpaid" tap is a reminder_answer → earns the existing 2 pts, writes last_player_reply, latches said_outstanding [QA-fix: was "earns nothing"]. Adopt.
- Close bonus (+15): the 5 player-confirmable terminals only — Paid, Refused, Account closed, Closed short, Method changed — once per member/casino/window, capped [QA-fix r2: excl. Cancelled (farm attack) AND Unconfirmed/Abandoned-unpaid (silence states, no confirm event)]. Adopt.
- Written accounts publish immediately after automated screening; only flagged items are held [QA-fix: no pre-publication approval]. Adopt.
- Reviews are append-only: authors cannot edit or delete; a correction is a dated child-row update that is auto-screened first, then publishes in seconds if clear / holds if flagged (spec 5.4/5.5, build §3.6) [QA-fix r2: was "edit republishes"; edits violate 5.4]. Adopt.
- Overturned penalties: keep the original public event, append the overturn. Adopt.
- Provisional casino pages: noindex until identity + ownership staff-confirmed (spec 6.5). Adopt.
- Operator counter-evidence: public shows "counter-evidence submitted" until redaction + moderation complete. Adopt.
- Terms-watch: design the schema on paper only in v1, no store/page shipped (6.1 LOCKED) [QA-fix]. Adopt.
Rounds 1-6 QA'd our plan against Dimitar's 9 Slack proposals only. On 2 Aug we then diffed against his full 19k-word CasinoPilot spec + backend + strategy (Fable 7/10, Sol 6/10). Core architecture and doctrine are carried or deliberately inverted (his 5-database model, permission units, immutable audit log, magic-link claim, dispute throttles at the same constants, attachment visibility, provisional-brand pipeline, payout machine all map onto ours, often ours stronger). But the proposal-only QA silently dropped a band of operational + compliance depth. Every item below is adopted; none conflicts with a locked decision; each lands in an existing Part C item or one new spec subsection. [Coverage-fix 2 Aug]
P0 - schema-level or launch-legal (cannot retrofit; land before the matching P0 build freezes):
| # | Gap (Dimitar ref) | Our spec | Our build | UX | Changelog |
|---|---|---|---|---|---|
| I1 | Payout geo-eligibility (his 2.8, backend 3.6): NO reward record minted for blocked regions (not mint-then-block), disclosed at contribution + at payout, blocklist-worded Terms, pre-launch legal review, config.geo guard. The reward-jurisdiction policy is effective-dated/versioned (source, owner, review date) at P0 [cov-fix r2: pulled from P2-14, must version before reward minting] |
new ch11 subsection + ch14 row | 3.4f2 reward guard + 12b | notice at contribution + cash-out | "Payout geo-eligibility" |
| I2 | Reward-void lifecycle on removal (backend 3.6): void still-payable only, NEVER claw back paid, no reward for flagged-held, identical on every removal path | new 7.4 (or fold into 7.1) [cov-fix: 7.6 does not exist] |
2.4 side-effects + 3.4f + P0-1 event | Points activity reflects voids | "Reward void semantics" |
| I3 | Per-brand paid entitlement (his 5.6): move paid_profile off the Operator entity onto the claim/brand relationship; every gated render checks the current brand |
11.1b one line | 3.4b/3.4c BrandEntitlement + P0-4 | operator multi-brand switcher | "Per-brand entitlement" |
| I4 | GDPR deletion/anonymization state machine (his 9): player double-confirm + 24h grace + profile 410 + PII purge + unpaid-ledger forfeiture (records already stay anonymized); operator delete -> casino reverts to unclaimed, replies remain | new ch11 transitions | deletion states + purge jobs + backup deadline + audit | double-confirm + grace countdown + cancel | "Deletion and anonymization" |
| I5 | Public handle privacy (his 6.4): NEVER prefill handle from OAuth real name; blank-start; uniqueness; rate-limited changes (real names on gambling records = our threat model) | 10.7 Interface Rules [cov-fix: pinned] |
member schema 3.4a | signup handle step | "Public handle rule" |
| I6 | Written-account caps + independent update moderation (his 1.7/1.8, backend 3.2/3.8): one standalone account per member per casino; corrections = appends (cadence 7d then 30d, max updates); appends earn 0 points; each child-row carries its OWN moderation_state/redaction/removal + attachment links |
5.4-5.5 explicit | 3.6 child state+reason+actor+ts + 12 zero-append rule | held/redacted/removed per update | "Account caps + update moderation" |
| I7 | Canonical entity/licence graph (his 1.4a, strategy 16): LegalEntity, LicenceRecord, Domain, permitted-domain history as first-class tables (not a passport json blob), each with effective dates + source owner + next-review date |
extend 6.2-6.4 | replace 3.4b passport with first-class tables | source drawer + dated licence/ownership history | "Canonical entity + licence graph" |
| I8 | Written-account + update attachments (his 1.6.8, backend 2.3/3.8): stable child table, default non-public, malware/redaction status, author receipt indicator; operators still never see raw evidence | add to ch5 + viewer policy 12.8 | stable child table + audit | uploader + private/processing indicator | "Written-account attachments" |
| I9 | Serious-allegation publication rule (strategy 22-23, our 12.15/14.13 OPEN): decide which serious allegations need an evidence threshold before publish; deterministic legal-risk hold + appeal + immutable decision record | resolve the 12.15/14.13 open question | legal-risk hold reason + appeal + decision record | precise held-item copy (no implied operator approval) | "Serious-allegation rule" |
| I10 | Explicit dispute scoping (his 7.2): API rejects a dispute from an operator against a casino it has not claimed (state the guard, not an assumption) | 6.6 | 2.5 dispute guard + 14 | - | "Dispute scoping guard" |
| I11 | Signup hygiene layer (his 6.2, strategy integrity): device fingerprint, per-IP/email/device account limits, signup rate limits, feed anomaly.review | ch9 note | member fields + anomaly feed | - | "Signup hygiene" |
P1 - product completeness / trust surface (four-layer rows, per Part D) [cov-fix r3]. I21 is P0 (with P0-1); I22/I23 are P1.
| # | Gap (Dimitar ref) | Spec | Build | UX | Changelog |
|---|---|---|---|---|---|
| I12 | 18+ / responsible-gambling surface (his 1.13, strategy 12) | new RG subsection (ch10/11) | - | RG notice on every public page footer + self-exclusion/support links at high-risk moments (e.g. day-19); no loss-chasing copy | "Responsible-gambling surface" |
| I13 | Reply safety-scan buildable rule (his 5.3a): PII/threat pattern list, false-positive-acceptable, category-naming blocks; replies AND player text | 5.5 detail | screening subsection (pattern list, scan result/reason) | human-readable block reason | "Reply safety scan" |
| I14 | Advisory specificity coach (his 1.6.5): amber, advisory, never-blocking; substance bar for the paid tester contribution (~$8 + 20 pts, build 3.4f2) and separately the 25-pt evidenced_withdrawal source [cov-fix] |
5.3 note | screening service | composer amber hints | "Specificity coach" |
| I15 | Status-aware submit CTA + own-review pinned + composer overlay (his 1.6.6/1.8/1.11): CTA names next blocker, never dead-grey; no indexable form URL | - | - | Part E composer + CTA + pinned own-review + overlay | "Composer CTA + overlay" |
| I16 | Public written-account read APIs (his 1.12, backend 5.1/5.3) | 12.11 | §14: /casino/{id}/accounts, /member/me/accounts, true totals, cursor pagination, status visibility |
casino review controls + "Your accounts" list; hide controls that add no value at the current count | "Written-account browsing APIs" |
| I17 | Operator console contract (his 5.2-5.6): six-tab, multi-brand switcher, claim/entitlement matrix, reply ~1000-char cap, disputed-claim path, public "claimed since [date]", operator-visible dispute progress | 11.1b | P0-4 entitlement + 3.4e reply cap | Part G 6-tab console | "Operator console contract" |
| I18 | Methodology "How It Works" page (his 13): fixed trust sections - how a record is made+screened, why paid contributions don't corrupt, firewall-in-code, what operators can/can't see, known blind spots | 9.1/12.15 section list | - | new How-It-Works page | "Methodology page" |
| I19 | Operator billing (his 10): schema (Stripe customer/subscription/invoice/debt) in P0-4; console presentation P1 [cov-fix r2] |
11.1b | P0-4 schema | invoice list + debt-before-cancel warning | "Operator billing" |
| I20 | Parameters + source-freshness: review min/max length (his 1.6.2, 500-3,000); avatars curated-set-no-uploads (his 6.4a); operator-logo moderation (his 6.4b); source/owner/timestamp/next-review per factual field. Dimitar's review-count ranking tiebreak (his 4) REJECTED [cov-fix r2: LOCKED - review count must never feed a ranking]; tiebreak by measurement (distinct players, sample size, recency) only |
ch5 (lengths) / 6.2-6.4 (source-freshness) / ch7 (avatars) | §8/§14 params | avatar set + logo moderation | "Parameters + source-freshness" |
| I21 (P0, with P0-1) | Reward-history reconciliation (his 2.9-2.10): lifetime-earned and available-balance reconcile EXACTLY to the immutable reward-events (invariant, projected from the event store) | 7.1 invariant | P0-1 event projections + reconciliation check | Points activity derived from events | "Reward reconciliation invariant" |
| I22 | Signup methods (his 6.3): ADOPT social login primary + email/password; payout wallet captured at cash-out, not signup | 12.10 | member schema | signup step | "Signup methods" |
| I23 | Reusable KYC (his 11.4): if an optional-KYC provider is picked, prefer one supporting reuse (lowers friction; does NOT change the transaction-proof gate) | 2.1 note | provider-selection decision | - | "Reusable KYC" |
Adopt-his-approach where his is better (both critics agreed): 5.3a scan rule (only concrete PII/threat spec either side wrote), geo exclude-at-source design, reward-void rules, per-brand entitlement, handle/avatar privacy defaults, GDPR flow shape (grace + 410 + revert-to-unclaimed), advisory coach + status-aware CTA, operator-visible dispute progress, first-class LegalEntity/LicenceRecord over JSON, source-freshness doctrine, reusable-KYC when the provider is picked, his complete server-side browsing contract, the "documented exclusions and why" habit for the passport.
Recorded rejects (decisions, not omissions): loyalty sponsorship / operator co-branding of the rewards surface (fails our payer-neutrality test, spec 11.3); mandatory-KYC-to-post (we use transaction-proof, DIM-7); complaint mediation / Resolution Desk / resolution fund (spec 15); off-platform badge for sale (spec 7.1).
Dimitar alignment (Slack mpdm, 2 Aug 11:16): he now explicitly endorses no disputes/complaints flow in v1 - "the clock works precisely because it's narrow, it only ever asks 'was this withdrawal paid,' never 'who is right,' so it needs no judge. Ship that." This matches our locked no-mediation stance (spec 15, J16). His future complaints-service (2-3 trained managers + published rulebook, aged clock becomes the case file) matches our phase-2 deferral (spec 12.15). Note: our operator fact-check disputes (D7 / spec 6.6) are NOT a who-is-right mediation flow, so they stay. CM throughput per Dimitar: a trained CM handles 100+ reviews/day (relevant to capacity planning, not the spec).
Consolidated from both coverage passes. These are choices, not gaps - the material for explaining to Dimitar how our version differs when we hand it over.
[cov-fix r2][cov-fix r2][cov-fix r2]