Feature status
Honest inventory against the v2.4 spec. Working = runs end to end with no keys. Wired = built but needs a credential or external service. Not built = absent.
Part 3 — Creator Studio
| Feature | Status |
|---|---|
| Text-to-image / video, style DNA, post-pass | Working (mock adapter; real models on keys) |
| Style Library — 64 styles, 18 modifiers, incompatibility rules | Working |
| Try It — 3s draft preview of your own subject | Working |
| Apply at project / scene / shot scope | Working |
| Asset library, provenance recall, dedupe | Working |
| Pre-generation cost estimate everywhere | Working |
| Side-by-side model comparison (arena) | Working |
| Image editing suite (inpaint, outpaint, erase, background replace, face swap, style transfer, upscale) | Working — 12 tools at /studio/tools |
| Performance transfer (Act 2) | Wired — capability + Runway payload path; needs a key |
| Custom style training (LoRA) | Partial — schema, StyleTrainingJob model and injection path exist; the training job is not built |
| Worlds / 3D | Not built (Phase 4+ in the spec) |
Part 4 — Film Studio
| Feature | Status |
|---|---|
| Character Bible + Identity Package injection | Working |
| Character State Machine + cascades | Working |
| World / Prop / Story Bibles, Brand DNA | Working |
| Script Creation Studio — Fountain, structures, annotations | Working |
| Tone map, derived + reshapeable | Working |
| Per-scene cost estimator across quality modes | Working |
| Table Read cue sheet | Working (cue sheet + transport; audio generation not wired to playback) |
| Fountain / FDX export | Working |
| Shot Engine + coverage grammar | Working |
| Storyboard gate | Working — enforced in the pipeline, not just the UI |
| Media Graph cascades, Change Actor, apply style | Working |
| Timeline, assembly, graph-aware re-point | Working |
| AI edit decision lists (accept/reject per change) | Working |
| Continuity Engine + 11-category Film Audit + Fix All | Working (structural; perceptual checks flagged, not faked) |
| Budget Engine + Optimize Cost | Working |
| Vibe Directing | Working (deterministic grammar; LLM on ANTHROPIC_API_KEY) |
| Crew agents | Partial — routed and named; each has the Director's toolset, not bespoke behaviour |
| Version control on script + assets | Working |
| Branching films | Working — fork from the Team tab; branches share rendered assets |
| Master render to a video file | Wired — EDL/CMX3600/SRT complete; needs FFmpeg |
| AI test screening / A-B | Working — 5 personas, drop-off curve, A/B with a confidence gate |
Part 5 — The Theater
| Feature | Status |
|---|---|
| Catalog, rows, genres, hero | Working |
| Natural-language search with visible interpretation | Working |
| Title pages, AI cast cards, licensing display | Working |
| Player + progress + Continue Watching | Working |
| Creator channels, follows, ratings, comments | Working |
| Kids profile (G/PG, curated-only genre) | Working |
| Stage 0 / 1 / 2 moderation, strikes, two-reviewer rule | Working |
| Film Festival + voting | Working |
| Adaptive HLS/DASH | Not built — needs transcoding |
| Remix licensing terms | Working (display + storage). Marketplace transactions Not built. Payouts computed and approvable; payment rails Not built. |
Part 6 — Publishing Hub
| Feature | Status |
|---|---|
| Export formats, EDL, CMX3600, SRT | Working |
| C2PA manifests on every asset | Working — unsigned without a certificate, and says so |
| OAuth vault (AES-256-GCM) | Working |
| Platform adapters with honest readiness | Working (declarations) / Wired (uploads) |
| Auto-format engine (crop, trim, safe zones, captions, disclosure) | Working (planning) |
| Campaign planner | Working |
| Actual uploads | Wired — needs app credentials + platform review/audit |
| Cross-platform analytics ingestion | Not built — needs live platform APIs |
Part 7 — Supporting systems
| Feature | Status |
|---|---|
| Credit ledger, reserve/settle/refund | Working |
| Plans and entitlements | Working — versioned pricing, coupons, rollover, rate limits. Stripe checkout Not built. |
| Project stage tracking | Working |
| Unit-economics guardrails (dedupe, draft:final, cost tracing) | Working |
| Team collaboration + per-scene assignment | Working — add by handle, 9 roles, per-scene assignment |
Part 9 — Legal & safety
| Item | Status |
|---|---|
| Kids/COPPA posture | Working — enforced in filtering |
| Provider compliance notes surfaced | Working |
| MiniMax H3 hosted-only | Working — hard-blocked in the Router |
| Voice/likeness consent | Working — unverified consent is a Stage 0 block |
| C2PA + AI disclosure | Working (unsigned without a cert) |
| CSAM hash-matching | Blocking gate — refuses to fake a clean result |
| Social API compliance | Working — stated per platform before use |
| Generalized style attributes only | Working — all 64 reviewed |
| Media liability insurance | Blocking gate |
/admin/readiness shows all of this live. Five blocking checks currently fail, so public launch is correctly blocked.
Verification
See the v2.4 section below — 214 assertions across three suites, run with npm run verify.
v2.4 additions
| Feature | Status |
|---|---|
| Luma Ray3.x adapter (16-bit HDR, scene planning) | Wired — registry + adapter; needs LUMA_API_KEY |
| Moonvalley Marey adapter (Cleared Content engine) | Wired — registry + adapter; needs MOONVALLEY_API_KEY |
| Runway Aleph (conversational footage editing) | Wired — payload path built; needs RUNWAY_API_KEY |
| Cleared Content mode + provenance certificates | Working — absolute routing gate, certificates audit real provenance |
| 8K upscale tier | Working (tool + capability gate); real output needs a provider |
| 16-bit HDR mastering | Working (tool + capability gate); real output needs Ray3 |
| Pitch Package generator | Working — 8 sections from the graph, with a readiness score |
| Presenter Mode | Working — consent-gated, multi-language, 5 formats |
| Ideation Boards | Working — canvas, multi-model riff, promote-into-Bible |
| Localization Engine | Working (pipeline); translation refused without a language model |
| Admin Console — users | Working — search, moderate, credits, plan, roles, impersonation |
| Admin Console — moderation | Working — queue, decisions, policy checklist, reports |
| Admin Console — pricing | Working — versioned with effective dates, coupons |
| Admin Console — API key vault | Working — encrypted, per-adapter test, vault beats .env |
| Admin Console — model config | Working — enable, routing weight, rate limit, price override |
| Admin Console — feature flags | Working — env/plan/percentage with stable buckets |
| Admin Console — catalog ops | Working — takedowns, editorial rows, DMCA, festival, policy |
| Admin Console — finance | Working (computation + approval); Not built (payment rails) |
| Admin Console — analytics | Working — KPIs, cohorts, provider health, moderation SLA |
| Admin Console — audit log | Working — immutable, survives account deletion |
| Accounts — email/password + verification + reset | Working; mail delivery Not built |
| Accounts — Google + X OAuth | Wired — full PKCE flow and linking; needs client credentials |
| Accounts — TOTP 2FA | Working — dependency-free RFC 6238 |
| Accounts — sessions and remote sign-out | Working |
| Accounts — settings pages | Working — profile, security, billing, preferences, notifications, privacy |
| Accounts — Stripe Elements card entry | Wired — renders no card field at all without Stripe, by design |
| Accounts — data export and deletion | Working — hard-delete personal data, retain-anonymized audit records |
| Demo TEST/ADMIN accounts | Working — blocked at login in production |
| Public Features comparison page | Working — 60 rows, data-driven from the admin console |
| Credits roll over (2× cap) | Working — forfeiture above the cap is stated, not hidden |
| Rate-limited free draft tier | Working — N per hour; final generations never limited |
| Cinematic Preset & VFX Library | Working — 24 camera + 25 VFX, capability-gated |
| Creator tool surface (image/video/audio) | Working — 34 tools, honest per-tool availability |
| Playlists + My List | Working |
| Kids profile PIN gate | Working — lock is on the user record, not the URL |
| Team collaboration + per-scene assignment | Working; live multi-user editing Not built |
| Branching films | Working — forks share rendered assets |
| AI test screening | Working — structural heuristic, labelled as such |
Verification
214 assertions across three suites — npm run verify.
The adversarial suite (verify-security.ts) is the important one: every case asserts that something is refused. It caught two real bugs during development — an OAuth unique-constraint crash and a foreign-key failure in account deletion — both documented in the README.
Final sweep — completed after the v2.4 audit
Everything below was found missing in a line-by-line re-read of the spec and has since been built.
| Feature | Spec | Status |
|---|---|---|
| Three pipeline modes (Beginner / Director / Professional) | 4.7 | Working — 16 steps, per-mode exposure, live progress from real rows |
| Script version compare + restore | 4.11 | Working — LCS diff; restore APPENDS, never rewinds |
| AI writing functions (8) | 4.5 | Working — 4 structural run keyless; 4 generative refuse without a model |
| Script import (Fountain / FDX / text) | 4.5 | Working — PDF refused with a reason |
| Character model sheets (8 views) | 4.1 | Working — shared base seed, attached back as canon refs |
| Voice library + auto-ducking mixer + loudness | 3.3 | Working — real ducking from dialogue timing; LUFS reported as estimated |
| Prompt extraction, batch + seed | 3.1 | Working — contiguous seeds, reproducible by construction |
| IP / copyright pre-check on prompts and uploads | 3.1 | Working — blocks before credits are reserved; image scan honestly reported as not run |
| Viral templates, music-video mode, podcast-to-video | 3.2 | Working — 7 templates, 16:9 and 9:16 |
| Remix flow | 5.2 | Working — copies story, never footage; obligations enforced |
| Public pricing page | 7.2 | Working — reads the active pricing version |
| Face restoration | 2.2 | Working — separate capability from upscaling |
| One-click modes (influencer / product / ad remake / illustrated story) | 3.5 | Working — plan-and-price before spending |
| Watch parties | 5.2 | Working — host clock, 2s poll, drift tolerance, Kids rating still enforced |
| Moderation appeals | 5.3 | Working — 30-day window, different-reviewer rule, overturn restores and clears strikes |
| Merchandising | 5.4 | Working (records) / Not built (fulfilment, payment) |
| Creator subscriptions | 5.4 | Working (tiers, MRR) — subscriptions stay pending without rails, never "active" |
| External licensing | 5.4 | Working — enquiry → creator response → revenue event |
| Fan funding | 5.4 | Working — all-or-nothing actually refunds; uncollected total surfaced |
| Audio stems export | 6.1 | Working (plan + FFmpeg commands); rendering needs FFmpeg |
| Project archive export | 6.1 | Working — full graph and provenance; binaries by URL |
| Tax reports | 7.1 | Working — CSV with disclaimers in the header |
| Passkeys (WebAuthn) | 7.2 | Working — dependency-free; origin binding, replay and clone detection |
Still not built, and why
| Item | Reason |
|---|---|
| Adaptive HLS/DASH | Needs a transcoding pipeline and CDN. |
| Payment rails | Needs Stripe and a fulfilment provider. Every economics surface says so. |
| Cross-platform analytics ingestion | Needs live platform API access. |
| Worlds / 3D | Phase 4+ in the spec. |
| Live multi-user editing | Needs CRDT and a realtime transport. |
| LoRA training execution | Schema and injection path exist; the training job does not. |
| Archive re-import | The archive is a hand-off record, not a one-click restore. |
Verification
476 assertions across five suites, plus a design-system check — npm run verify.
| Suite | Assertions | Covers |
|---|---|---|
verify-pipeline.ts | 44 | Core generation pipeline |
verify-v24.ts | 109 | v2.4 features |
verify-security.ts | 61 | Adversarial — every case asserts a refusal |
verify-v25.ts | 126 | Pipeline modes, versions, writing room, audio, remix, IP gate |
verify-v26.ts | 136 | Community, economics, modes, exports, passkeys |
check-styles.ts | — | Every palette class and custom utility resolves |
Two further scripts run against a live server:
npm run smoke— all 59 routes render (scripts/smoke-routes.ts)npm run smoke:content— 58 assertions that pages contain what they claim (scripts/check-content.ts)
The style check caught four real bugs: bg-cine-900 and bg-cine-950 did not exist in the palette, so those backgrounds silently rendered as nothing.
Second full-spec sweep
A second line-by-line pass over the outline found nine more items with no implementation. All nine are now built.
| Feature | Spec | Status |
|---|---|---|
| Multi-shot sequence builder | 3.2 | Working — labelled shots + per-character dialogue in one pass |
| Video background replace + relight | 3.2 | Working — relights the subject to match the new environment |
| Video relight | 3.2 | Working — 11 lighting states, composition untouched |
| Model-sheet action set (walk/run/fight/talk) | 4.1 | Working — 12 views total, attached as canon refs |
| Asset library semantic + visual search | 3.6 | Working — labelled terms honestly without an embedding provider |
| PDF script import | 4.5 | Working — real text extraction incl. FlateDecode; scanned PDFs refused |
| Adapt from an existing Universe | 4.5 | Working — carries end-of-film character state forward |
| Tips | 5.4 | Working (records) — stays pending without payment rails |
| Rentals & purchases | 5.4 | Working — rental window starts on first play, expiry enforced |
| Creator-editable captions | 5.1 | Working — edits override derived cues and survive re-render |
| Per-user compute caps | 7.4 | Working — concurrency + rolling 24h ceiling, distinct from credits |
Bugs this sweep found in existing code
- Head-of-line blocking in the generation queue.
runQueue(n)drained the global FIFO oldest-first, so "enqueue N then run N" silently processed someone else's backlog while the caller's work stayed queued.runQueuenow accepts the caller's own ids. - Abandoned generations were never reaped. A crash mid-render left credits reserved against a job that would never finish — charged for nothing, and unspendable.
reapStaleGenerations()now runs on every queue pass, fails them past 30 minutes and refunds the hold. - The first compute cap broke batching. A 12-view model sheet is one user action; the initial concurrency limit of 2 made a documented feature impossible. The cap now ignores a just-submitted burst (60s grace) and the floor is set by the largest legitimate action.
Verification
583 assertions across seven suites, plus the design-system check — npm run verify.
| Suite | Assertions |
|---|---|
verify-pipeline.ts | 44 |
verify-v24.ts | 109 |
verify-security.ts | 61 |
verify-v25.ts | 127 |
verify-v26.ts | 136 |
verify-v27.ts | 84 |
verify-pdf.ts | 22 |
check-styles.ts | design-system consistency |
Against a live server: npm run smoke (61 routes) and npm run smoke:content (70 assertions that pages contain what they claim).
Community forum & help desk
Three connected surfaces sharing one knowledge base.
| Feature | Status |
|---|---|
| Help centre — 75 articles across 12 categories | Working — searchable, browsable, per-article feedback |
| Help search | Working — ranked by where the match landed, with keywords covering how people actually phrase questions |
| Help assistant | Working — retrieval-grounded, cites every article used, refuses rather than inventing |
| Assistant with a model | Wired — ANTHROPIC_API_KEY synthesises the same retrieved articles; still constrained, still cites |
| Community forum | Working — 11 categories, 5 thread kinds, votes, accepted answers, subscriptions, search |
| Accepted answers | Working — asker or moderator marks it; the reply floats to the top and the thread flips to answered |
| Forum moderation | Working — pin, lock, hide, restore; a hidden post stays visible to its author with the reason |
| Assistant in a thread | Working — posts a grounded answer, clearly attributed, and refuses when it has nothing |
| Documentation gap tracking | Working — failed searches and unhelpful answers are logged and grouped |
Design decisions worth knowing
Articles live in code, not the database. They document the behaviour of specific functions and ship in the same commit as the features they describe. Documentation stored separately drifts, and a help centre that lies is worse than none.
The assistant can only cite articles that exist. That constraint is the whole design — it structurally cannot describe a button that is not there, which is the failure mode that makes most product chatbots untrustworthy. When the catalog has no answer it says so and offers the forum.
It works with no API key. In grounded mode the answer is assembled from the retrieved articles directly, which is genuinely useful because the articles are written as answers. The mode is labelled on every response.
Author labels are denormalized. A forum where every old answer says "deleted account" is a forum nobody trusts, and refusing to delete accounts is worse.
Bugs this work found
- Two broken cross-references in the help catalog pointed at slugs that did not exist. Now asserted — every
relatedlink must resolve. - Short keywords matched gibberish. Plain substring matching meant a two-character keyword like
xmatched insidezzzqqxx, so nonsense scored against real articles. Search now matches on word boundaries. - A single keyword counted as a full phrase match. "The render farm" inside a seventy-character nonsense question scored as a phrase hit on the export article. A phrase match now requires the keyword to cover half the query.
Verification
693 assertions across eight suites, plus the design-system check — npm run verify.
| Suite | Assertions |
|---|---|
verify-pipeline.ts | 44 |
verify-v24.ts | 109 |
verify-security.ts | 61 |
verify-v25.ts | 127 |
verify-v26.ts | 136 |
verify-v27.ts | 84 |
verify-pdf.ts | 22 |
verify-community.ts | 110 |
Against a live server: npm run smoke (71 routes) and npm run smoke:content (86 assertions).
Graphics Model Test
Compare engines side by side before committing a whole film to one.
| Feature | Status |
|---|---|
| Engine picker with live availability | Working — unavailable engines are listed with the exact key each needs |
| Identical prompt / seed / refs across every entry | Working — enforced in the service |
| Cost preview before running | Working |
| Model pinning (no failover during a test) | Working — pinning an unavailable engine fails rather than substituting |
| Result grid with latency, credits and score | Working |
| 1–5 star rating per result | Working |
| Winner sets the project's preferred engine | Working — injected into every later generation |
| Preference falls back when it cannot serve a request | Working — and explains why |
Models added this pass
grok-imagine, grok-imagine-image, nano-banana-pro, ideogram-3, recraft-v3, firefly-image-4, pika-2.5, mochi-1, flux-schnell, sd-3.5-large.
35 models registered, of which 8 are self-hostable. Adobe Firefly is a second licensed engine, so Cleared Content mode is no longer one model deep — previously a single point of failure for the whole premium SKU.
Bugs this work found
- The UI and the service disagreed on the run threshold. The service allowed
≥2 selected / ≥1 runnable; the button required 2 runnable. With no provider keys that meant a permanently disabled button and no explanation.
- A preferred model from a different modality produced no explanation. Asking
for video on a project whose chosen stills engine was set silently routed elsewhere. It now says the preferred engine is not a model of that kind.
Verification
774 assertions across nine suites — npm run verify. Live: 73 routes, 86 content assertions.
Activation inventory, reachability and mobile
Admin → Activation
A live inventory of every feature and whether it is switched on, at /admin/activation. Three states:
- active — working now.
- needs-key — built and tested, waiting on a credential. Configuration, not development.
- not-built — genuinely absent, with what building it involves.
Computed from the environment, the credential vault and the model registry on every load — never a hand-kept list. A verification assertion flips FFMPEG_PATH and asserts the state follows, which is what stops it silently rotting into a page that says "active" for something broken a month ago.
Every pending item states what unlocks it and what happens today instead. Nothing fails silently.
Reachability
npm run check:reach walks every App Router page and every href in the codebase, and fails if any page has no inbound link. A route nothing links to is a feature nobody will find — indistinguishable, from the user's side, from not building it. 65 pages, all reachable.
Mobile
| Layer | Status |
|---|---|
| Responsive web | Working — 38 routes audited for overflow and safe areas |
| Bottom tab navigation below 768px | Working |
| PWA (installable, standalone, shortcuts) | Working |
/api/v1 REST API for native apps | Working — 13 endpoints, Bearer auth, one envelope |
| Capability discovery for shipped clients | Working |
| Native iOS / Android apps | Not built — see docs/MOBILE.md §4 |
Bugs found and fixed this pass
- No navigation at all below 768px. The desktop nav is
hidden md:flex; nothing
replaced it. A phone user could reach the Create/Watch toggle and nothing else.
- Horizontal overflow on the Graphics Model Test. A grid whose only column
definition sat behind lg: fell back to an implicit auto column, which will not shrink below min-content — so GOOGLE_AI_API_KEY is not configured widened the page to 526px on a 375px screen. check:mobile now fails on any grid without an unprefixed base column.
undefined !== falsecorrupted the activation sort.notBuilt()left
blocksLaunch undefined while f() set it to false, so every needs-key item sorted below the not-built ones — exactly backwards from the order an operator works through.
- Two wrong assertions in my own mobile checker, both fixed rather than muted:
it matched max-w-[1800px] as a fixed width, and flagged grid-cols-3 as rigid when Tailwind compiles it to minmax(0,1fr), which shrinks fine.
Refactor
verifyCredentials() was extracted from signIn() so the mobile API can issue a Bearer token instead of a cookie while sharing one implementation of every gate — demo-account blocking, ban, suspension, 2FA. Two copies would drift, and the copy that drifted would be the one letting a banned user in.
A mobile token is a Session row: one device list, one revoke path, and a password reset or ban kills it. Asserted directly in verify-platform.ts.
Verification
827 assertions across ten suites, plus design-system, reachability and mobile checks — npm run verify. Live: 79 routes, 93 content assertions, 45 mobile checks.
Addendum A1 — ArcReel & ecosystem review
Full detail, including the design rationale and the bugs this pass uncovered, is in addendum-a1.md.
| Feature | Status |
|---|---|
| A1.1 Book-to-Film adaptation (TXT/MD/EPUB/PDF/DOCX) | Working — structural extraction runs with no keys; a model enriches it |
| A1.2 Grid storyboard generation + deterministic split | Working — panel files need FFMPEG_PATH; geometry and display do not |
| A1.3 Narration Mode (TTS-first pipeline) | Working |
| A1.3 Product-Ad Mode (strict-fidelity products) | Working — lighting normalization reported as not performed without a backend |
| A1.4 Reference-to-video "Quick Shot" | Working — demonstrable on the mock adapter |
| A1.5 Narrative clue tracking (Chekhov flags) | Working — 12th Film Audit category |
| A1.6 NLE export — OTIO, CapCut, Premiere, FCP, Resolve, EDL | Working |
| A1.7 Multi-key provider pools with rotation | Working — needs TOKEN_VAULT_KEY to store keys |
| A1.7 User BYOK + custom OpenAI/Google-compatible endpoints | Working — needs TOKEN_VAULT_KEY |
| A1.8 Resumable pipelines (lease-based, graph-diff resume) | Working |
| A1.9 Agent Platform API — scoped keys, MCP manifest, agent endpoint | Working |
| A1.10 Sandboxed agent runtime | Partial — application policy enforced; OS-level isolation is infrastructure, and the console says so |
| A1.11 Candidate adapters (Vidu Q3, Kling v3 Omni, Hailuo 2.3, Video O1) | Wired — registry rows + adapters; need keys |
| A1.12 Pose library (24 blocking references) + plan export | Working |
Corrections to earlier entries in this document
- Provider adapters. Nine adapter names in the registry had no implementation
behind them and silently resolved to the mock adapter. All nine are now implemented, and isModelLive() requires a registered adapter as well as a key so the state cannot recur. Any earlier row implying xai, pika, ideogram, recraft, adobe, google, vidu, selfhost or utility models worked on a key alone was wrong.
- Post-processing utilities (upscale, HDR master, interpolation, face
restore, lip-sync post) now refuse with a stated reason when no processing backend is configured, rather than resolving to a mock that returned the input.
Captions, dubbing, voices and the product page
Full detail in captions-dubbing-voices.md.
| Feature | Status |
|---|---|
| Closed captions in 30 languages, viewer-chosen colour/size/background | Working |
| Right-to-left caption rendering (Arabic, Urdu, Persian) with correct fonts | Working |
| Caption readability checking (cues too fast to read) | Working |
| Caption preferences synced to the account and to localStorage | Working |
| Re-render the whole film in another language with matching lip-sync | Working — translation needs ANTHROPIC_API_KEY; runs on the mock adapter end to end |
| Audio-only dub, with the mode recorded and shown so the two are never conflated | Working |
| Per-line duration budgets given to the translator, and timing risks flagged before the render | Working |
| Resumable dubs across many languages | Working |
| Voice library, describe-a-voice, upload, in-browser recording | Working |
| Voice audition with emotion, language and a refresh that re-seeds | Working — real timbre needs TTS_API_KEY |
| Consent gating on cloned voices, re-checked at use rather than at assignment | Working |
| Voice references sent to native-audio video models as performance refs | Working |
| Product page — 94 features, links verified to resolve | Working |