Sign inStart creating

Feature status

Honest inventory against the v2.4 spec. Working = runs end to end with no keys. Wired = built but needs a credential or external service. Not built = absent.

Part 3 — Creator Studio

FeatureStatus
Text-to-image / video, style DNA, post-passWorking (mock adapter; real models on keys)
Style Library — 64 styles, 18 modifiers, incompatibility rulesWorking
Try It — 3s draft preview of your own subjectWorking
Apply at project / scene / shot scopeWorking
Asset library, provenance recall, dedupeWorking
Pre-generation cost estimate everywhereWorking
Side-by-side model comparison (arena)Working
Image editing suite (inpaint, outpaint, erase, background replace, face swap, style transfer, upscale)Working — 12 tools at /studio/tools
Performance transfer (Act 2)Wired — capability + Runway payload path; needs a key
Custom style training (LoRA)Partial — schema, StyleTrainingJob model and injection path exist; the training job is not built
Worlds / 3DNot built (Phase 4+ in the spec)

Part 4 — Film Studio

FeatureStatus
Character Bible + Identity Package injectionWorking
Character State Machine + cascadesWorking
World / Prop / Story Bibles, Brand DNAWorking
Script Creation Studio — Fountain, structures, annotationsWorking
Tone map, derived + reshapeableWorking
Per-scene cost estimator across quality modesWorking
Table Read cue sheetWorking (cue sheet + transport; audio generation not wired to playback)
Fountain / FDX exportWorking
Shot Engine + coverage grammarWorking
Storyboard gateWorking — enforced in the pipeline, not just the UI
Media Graph cascades, Change Actor, apply styleWorking
Timeline, assembly, graph-aware re-pointWorking
AI edit decision lists (accept/reject per change)Working
Continuity Engine + 11-category Film Audit + Fix AllWorking (structural; perceptual checks flagged, not faked)
Budget Engine + Optimize CostWorking
Vibe DirectingWorking (deterministic grammar; LLM on ANTHROPIC_API_KEY)
Crew agentsPartial — routed and named; each has the Director's toolset, not bespoke behaviour
Version control on script + assetsWorking
Branching filmsWorking — fork from the Team tab; branches share rendered assets
Master render to a video fileWired — EDL/CMX3600/SRT complete; needs FFmpeg
AI test screening / A-BWorking — 5 personas, drop-off curve, A/B with a confidence gate

Part 5 — The Theater

FeatureStatus
Catalog, rows, genres, heroWorking
Natural-language search with visible interpretationWorking
Title pages, AI cast cards, licensing displayWorking
Player + progress + Continue WatchingWorking
Creator channels, follows, ratings, commentsWorking
Kids profile (G/PG, curated-only genre)Working
Stage 0 / 1 / 2 moderation, strikes, two-reviewer ruleWorking
Film Festival + votingWorking
Adaptive HLS/DASHNot built — needs transcoding
Remix licensing termsWorking (display + storage). Marketplace transactions Not built. Payouts computed and approvable; payment rails Not built.

Part 6 — Publishing Hub

FeatureStatus
Export formats, EDL, CMX3600, SRTWorking
C2PA manifests on every assetWorkingunsigned without a certificate, and says so
OAuth vault (AES-256-GCM)Working
Platform adapters with honest readinessWorking (declarations) / Wired (uploads)
Auto-format engine (crop, trim, safe zones, captions, disclosure)Working (planning)
Campaign plannerWorking
Actual uploadsWired — needs app credentials + platform review/audit
Cross-platform analytics ingestionNot built — needs live platform APIs

Part 7 — Supporting systems

FeatureStatus
Credit ledger, reserve/settle/refundWorking
Plans and entitlementsWorking — versioned pricing, coupons, rollover, rate limits. Stripe checkout Not built.
Project stage trackingWorking
Unit-economics guardrails (dedupe, draft:final, cost tracing)Working
Team collaboration + per-scene assignmentWorking — add by handle, 9 roles, per-scene assignment

Part 9 — Legal & safety

ItemStatus
Kids/COPPA postureWorking — enforced in filtering
Provider compliance notes surfacedWorking
MiniMax H3 hosted-onlyWorking — hard-blocked in the Router
Voice/likeness consentWorking — unverified consent is a Stage 0 block
C2PA + AI disclosureWorking (unsigned without a cert)
CSAM hash-matchingBlocking gate — refuses to fake a clean result
Social API complianceWorking — stated per platform before use
Generalized style attributes onlyWorking — all 64 reviewed
Media liability insuranceBlocking gate

/admin/readiness shows all of this live. Five blocking checks currently fail, so public launch is correctly blocked.

Verification

See the v2.4 section below — 214 assertions across three suites, run with npm run verify.


v2.4 additions

FeatureStatus
Luma Ray3.x adapter (16-bit HDR, scene planning)Wired — registry + adapter; needs LUMA_API_KEY
Moonvalley Marey adapter (Cleared Content engine)Wired — registry + adapter; needs MOONVALLEY_API_KEY
Runway Aleph (conversational footage editing)Wired — payload path built; needs RUNWAY_API_KEY
Cleared Content mode + provenance certificatesWorking — absolute routing gate, certificates audit real provenance
8K upscale tierWorking (tool + capability gate); real output needs a provider
16-bit HDR masteringWorking (tool + capability gate); real output needs Ray3
Pitch Package generatorWorking — 8 sections from the graph, with a readiness score
Presenter ModeWorking — consent-gated, multi-language, 5 formats
Ideation BoardsWorking — canvas, multi-model riff, promote-into-Bible
Localization EngineWorking (pipeline); translation refused without a language model
Admin Console — usersWorking — search, moderate, credits, plan, roles, impersonation
Admin Console — moderationWorking — queue, decisions, policy checklist, reports
Admin Console — pricingWorking — versioned with effective dates, coupons
Admin Console — API key vaultWorking — encrypted, per-adapter test, vault beats .env
Admin Console — model configWorking — enable, routing weight, rate limit, price override
Admin Console — feature flagsWorking — env/plan/percentage with stable buckets
Admin Console — catalog opsWorking — takedowns, editorial rows, DMCA, festival, policy
Admin Console — financeWorking (computation + approval); Not built (payment rails)
Admin Console — analyticsWorking — KPIs, cohorts, provider health, moderation SLA
Admin Console — audit logWorking — immutable, survives account deletion
Accounts — email/password + verification + resetWorking; mail delivery Not built
Accounts — Google + X OAuthWired — full PKCE flow and linking; needs client credentials
Accounts — TOTP 2FAWorking — dependency-free RFC 6238
Accounts — sessions and remote sign-outWorking
Accounts — settings pagesWorking — profile, security, billing, preferences, notifications, privacy
Accounts — Stripe Elements card entryWired — renders no card field at all without Stripe, by design
Accounts — data export and deletionWorking — hard-delete personal data, retain-anonymized audit records
Demo TEST/ADMIN accountsWorking — blocked at login in production
Public Features comparison pageWorking — 60 rows, data-driven from the admin console
Credits roll over (2× cap)Working — forfeiture above the cap is stated, not hidden
Rate-limited free draft tierWorking — N per hour; final generations never limited
Cinematic Preset & VFX LibraryWorking — 24 camera + 25 VFX, capability-gated
Creator tool surface (image/video/audio)Working — 34 tools, honest per-tool availability
Playlists + My ListWorking
Kids profile PIN gateWorking — lock is on the user record, not the URL
Team collaboration + per-scene assignmentWorking; live multi-user editing Not built
Branching filmsWorking — forks share rendered assets
AI test screeningWorking — structural heuristic, labelled as such

Verification

214 assertions across three suites — npm run verify.

The adversarial suite (verify-security.ts) is the important one: every case asserts that something is refused. It caught two real bugs during development — an OAuth unique-constraint crash and a foreign-key failure in account deletion — both documented in the README.

Final sweep — completed after the v2.4 audit

Everything below was found missing in a line-by-line re-read of the spec and has since been built.

FeatureSpecStatus
Three pipeline modes (Beginner / Director / Professional)4.7Working — 16 steps, per-mode exposure, live progress from real rows
Script version compare + restore4.11Working — LCS diff; restore APPENDS, never rewinds
AI writing functions (8)4.5Working — 4 structural run keyless; 4 generative refuse without a model
Script import (Fountain / FDX / text)4.5Working — PDF refused with a reason
Character model sheets (8 views)4.1Working — shared base seed, attached back as canon refs
Voice library + auto-ducking mixer + loudness3.3Working — real ducking from dialogue timing; LUFS reported as estimated
Prompt extraction, batch + seed3.1Working — contiguous seeds, reproducible by construction
IP / copyright pre-check on prompts and uploads3.1Working — blocks before credits are reserved; image scan honestly reported as not run
Viral templates, music-video mode, podcast-to-video3.2Working — 7 templates, 16:9 and 9:16
Remix flow5.2Working — copies story, never footage; obligations enforced
Public pricing page7.2Working — reads the active pricing version
Face restoration2.2Working — separate capability from upscaling
One-click modes (influencer / product / ad remake / illustrated story)3.5Working — plan-and-price before spending
Watch parties5.2Working — host clock, 2s poll, drift tolerance, Kids rating still enforced
Moderation appeals5.3Working — 30-day window, different-reviewer rule, overturn restores and clears strikes
Merchandising5.4Working (records) / Not built (fulfilment, payment)
Creator subscriptions5.4Working (tiers, MRR) — subscriptions stay pending without rails, never "active"
External licensing5.4Working — enquiry → creator response → revenue event
Fan funding5.4Working — all-or-nothing actually refunds; uncollected total surfaced
Audio stems export6.1Working (plan + FFmpeg commands); rendering needs FFmpeg
Project archive export6.1Working — full graph and provenance; binaries by URL
Tax reports7.1Working — CSV with disclaimers in the header
Passkeys (WebAuthn)7.2Working — dependency-free; origin binding, replay and clone detection

Still not built, and why

ItemReason
Adaptive HLS/DASHNeeds a transcoding pipeline and CDN.
Payment railsNeeds Stripe and a fulfilment provider. Every economics surface says so.
Cross-platform analytics ingestionNeeds live platform API access.
Worlds / 3DPhase 4+ in the spec.
Live multi-user editingNeeds CRDT and a realtime transport.
LoRA training executionSchema and injection path exist; the training job does not.
Archive re-importThe archive is a hand-off record, not a one-click restore.

Verification

476 assertions across five suites, plus a design-system checknpm run verify.

SuiteAssertionsCovers
verify-pipeline.ts44Core generation pipeline
verify-v24.ts109v2.4 features
verify-security.ts61Adversarial — every case asserts a refusal
verify-v25.ts126Pipeline modes, versions, writing room, audio, remix, IP gate
verify-v26.ts136Community, economics, modes, exports, passkeys
check-styles.tsEvery palette class and custom utility resolves

Two further scripts run against a live server:

  • npm run smoke — all 59 routes render (scripts/smoke-routes.ts)
  • npm run smoke:content — 58 assertions that pages contain what they claim (scripts/check-content.ts)

The style check caught four real bugs: bg-cine-900 and bg-cine-950 did not exist in the palette, so those backgrounds silently rendered as nothing.

Second full-spec sweep

A second line-by-line pass over the outline found nine more items with no implementation. All nine are now built.

FeatureSpecStatus
Multi-shot sequence builder3.2Working — labelled shots + per-character dialogue in one pass
Video background replace + relight3.2Working — relights the subject to match the new environment
Video relight3.2Working — 11 lighting states, composition untouched
Model-sheet action set (walk/run/fight/talk)4.1Working — 12 views total, attached as canon refs
Asset library semantic + visual search3.6Working — labelled terms honestly without an embedding provider
PDF script import4.5Working — real text extraction incl. FlateDecode; scanned PDFs refused
Adapt from an existing Universe4.5Working — carries end-of-film character state forward
Tips5.4Working (records) — stays pending without payment rails
Rentals & purchases5.4Working — rental window starts on first play, expiry enforced
Creator-editable captions5.1Working — edits override derived cues and survive re-render
Per-user compute caps7.4Working — concurrency + rolling 24h ceiling, distinct from credits

Bugs this sweep found in existing code

  • Head-of-line blocking in the generation queue. runQueue(n) drained the global FIFO oldest-first, so "enqueue N then run N" silently processed someone else's backlog while the caller's work stayed queued. runQueue now accepts the caller's own ids.
  • Abandoned generations were never reaped. A crash mid-render left credits reserved against a job that would never finish — charged for nothing, and unspendable. reapStaleGenerations() now runs on every queue pass, fails them past 30 minutes and refunds the hold.
  • The first compute cap broke batching. A 12-view model sheet is one user action; the initial concurrency limit of 2 made a documented feature impossible. The cap now ignores a just-submitted burst (60s grace) and the floor is set by the largest legitimate action.

Verification

583 assertions across seven suites, plus the design-system check — npm run verify.

SuiteAssertions
verify-pipeline.ts44
verify-v24.ts109
verify-security.ts61
verify-v25.ts127
verify-v26.ts136
verify-v27.ts84
verify-pdf.ts22
check-styles.tsdesign-system consistency

Against a live server: npm run smoke (61 routes) and npm run smoke:content (70 assertions that pages contain what they claim).

Community forum & help desk

Three connected surfaces sharing one knowledge base.

FeatureStatus
Help centre — 75 articles across 12 categoriesWorking — searchable, browsable, per-article feedback
Help searchWorking — ranked by where the match landed, with keywords covering how people actually phrase questions
Help assistantWorking — retrieval-grounded, cites every article used, refuses rather than inventing
Assistant with a modelWiredANTHROPIC_API_KEY synthesises the same retrieved articles; still constrained, still cites
Community forumWorking — 11 categories, 5 thread kinds, votes, accepted answers, subscriptions, search
Accepted answersWorking — asker or moderator marks it; the reply floats to the top and the thread flips to answered
Forum moderationWorking — pin, lock, hide, restore; a hidden post stays visible to its author with the reason
Assistant in a threadWorking — posts a grounded answer, clearly attributed, and refuses when it has nothing
Documentation gap trackingWorking — failed searches and unhelpful answers are logged and grouped

Design decisions worth knowing

Articles live in code, not the database. They document the behaviour of specific functions and ship in the same commit as the features they describe. Documentation stored separately drifts, and a help centre that lies is worse than none.

The assistant can only cite articles that exist. That constraint is the whole design — it structurally cannot describe a button that is not there, which is the failure mode that makes most product chatbots untrustworthy. When the catalog has no answer it says so and offers the forum.

It works with no API key. In grounded mode the answer is assembled from the retrieved articles directly, which is genuinely useful because the articles are written as answers. The mode is labelled on every response.

Author labels are denormalized. A forum where every old answer says "deleted account" is a forum nobody trusts, and refusing to delete accounts is worse.

Bugs this work found

  • Two broken cross-references in the help catalog pointed at slugs that did not exist. Now asserted — every related link must resolve.
  • Short keywords matched gibberish. Plain substring matching meant a two-character keyword like x matched inside zzzqqxx, so nonsense scored against real articles. Search now matches on word boundaries.
  • A single keyword counted as a full phrase match. "The render farm" inside a seventy-character nonsense question scored as a phrase hit on the export article. A phrase match now requires the keyword to cover half the query.

Verification

693 assertions across eight suites, plus the design-system check — npm run verify.

SuiteAssertions
verify-pipeline.ts44
verify-v24.ts109
verify-security.ts61
verify-v25.ts127
verify-v26.ts136
verify-v27.ts84
verify-pdf.ts22
verify-community.ts110

Against a live server: npm run smoke (71 routes) and npm run smoke:content (86 assertions).

Graphics Model Test

Compare engines side by side before committing a whole film to one.

FeatureStatus
Engine picker with live availabilityWorking — unavailable engines are listed with the exact key each needs
Identical prompt / seed / refs across every entryWorking — enforced in the service
Cost preview before runningWorking
Model pinning (no failover during a test)Working — pinning an unavailable engine fails rather than substituting
Result grid with latency, credits and scoreWorking
1–5 star rating per resultWorking
Winner sets the project's preferred engineWorking — injected into every later generation
Preference falls back when it cannot serve a requestWorking — and explains why

Models added this pass

grok-imagine, grok-imagine-image, nano-banana-pro, ideogram-3, recraft-v3, firefly-image-4, pika-2.5, mochi-1, flux-schnell, sd-3.5-large.

35 models registered, of which 8 are self-hostable. Adobe Firefly is a second licensed engine, so Cleared Content mode is no longer one model deep — previously a single point of failure for the whole premium SKU.

Bugs this work found

  • The UI and the service disagreed on the run threshold. The service allowed

≥2 selected / ≥1 runnable; the button required 2 runnable. With no provider keys that meant a permanently disabled button and no explanation.

  • A preferred model from a different modality produced no explanation. Asking

for video on a project whose chosen stills engine was set silently routed elsewhere. It now says the preferred engine is not a model of that kind.

Verification

774 assertions across nine suitesnpm run verify. Live: 73 routes, 86 content assertions.

Activation inventory, reachability and mobile

Admin → Activation

A live inventory of every feature and whether it is switched on, at /admin/activation. Three states:

  • active — working now.
  • needs-key — built and tested, waiting on a credential. Configuration, not development.
  • not-built — genuinely absent, with what building it involves.

Computed from the environment, the credential vault and the model registry on every load — never a hand-kept list. A verification assertion flips FFMPEG_PATH and asserts the state follows, which is what stops it silently rotting into a page that says "active" for something broken a month ago.

Every pending item states what unlocks it and what happens today instead. Nothing fails silently.

Reachability

npm run check:reach walks every App Router page and every href in the codebase, and fails if any page has no inbound link. A route nothing links to is a feature nobody will find — indistinguishable, from the user's side, from not building it. 65 pages, all reachable.

Mobile

LayerStatus
Responsive webWorking — 38 routes audited for overflow and safe areas
Bottom tab navigation below 768pxWorking
PWA (installable, standalone, shortcuts)Working
/api/v1 REST API for native appsWorking — 13 endpoints, Bearer auth, one envelope
Capability discovery for shipped clientsWorking
Native iOS / Android appsNot built — see docs/MOBILE.md §4

Bugs found and fixed this pass

  • No navigation at all below 768px. The desktop nav is hidden md:flex; nothing

replaced it. A phone user could reach the Create/Watch toggle and nothing else.

  • Horizontal overflow on the Graphics Model Test. A grid whose only column

definition sat behind lg: fell back to an implicit auto column, which will not shrink below min-content — so GOOGLE_AI_API_KEY is not configured widened the page to 526px on a 375px screen. check:mobile now fails on any grid without an unprefixed base column.

  • undefined !== false corrupted the activation sort. notBuilt() left

blocksLaunch undefined while f() set it to false, so every needs-key item sorted below the not-built ones — exactly backwards from the order an operator works through.

  • Two wrong assertions in my own mobile checker, both fixed rather than muted:

it matched max-w-[1800px] as a fixed width, and flagged grid-cols-3 as rigid when Tailwind compiles it to minmax(0,1fr), which shrinks fine.

Refactor

verifyCredentials() was extracted from signIn() so the mobile API can issue a Bearer token instead of a cookie while sharing one implementation of every gate — demo-account blocking, ban, suspension, 2FA. Two copies would drift, and the copy that drifted would be the one letting a banned user in.

A mobile token is a Session row: one device list, one revoke path, and a password reset or ban kills it. Asserted directly in verify-platform.ts.

Verification

827 assertions across ten suites, plus design-system, reachability and mobile checks — npm run verify. Live: 79 routes, 93 content assertions, 45 mobile checks.


Addendum A1 — ArcReel & ecosystem review

Full detail, including the design rationale and the bugs this pass uncovered, is in addendum-a1.md.

FeatureStatus
A1.1 Book-to-Film adaptation (TXT/MD/EPUB/PDF/DOCX)Working — structural extraction runs with no keys; a model enriches it
A1.2 Grid storyboard generation + deterministic splitWorking — panel files need FFMPEG_PATH; geometry and display do not
A1.3 Narration Mode (TTS-first pipeline)Working
A1.3 Product-Ad Mode (strict-fidelity products)Working — lighting normalization reported as not performed without a backend
A1.4 Reference-to-video "Quick Shot"Working — demonstrable on the mock adapter
A1.5 Narrative clue tracking (Chekhov flags)Working — 12th Film Audit category
A1.6 NLE export — OTIO, CapCut, Premiere, FCP, Resolve, EDLWorking
A1.7 Multi-key provider pools with rotationWorking — needs TOKEN_VAULT_KEY to store keys
A1.7 User BYOK + custom OpenAI/Google-compatible endpointsWorking — needs TOKEN_VAULT_KEY
A1.8 Resumable pipelines (lease-based, graph-diff resume)Working
A1.9 Agent Platform API — scoped keys, MCP manifest, agent endpointWorking
A1.10 Sandboxed agent runtimePartial — application policy enforced; OS-level isolation is infrastructure, and the console says so
A1.11 Candidate adapters (Vidu Q3, Kling v3 Omni, Hailuo 2.3, Video O1)Wired — registry rows + adapters; need keys
A1.12 Pose library (24 blocking references) + plan exportWorking

Corrections to earlier entries in this document

  • Provider adapters. Nine adapter names in the registry had no implementation

behind them and silently resolved to the mock adapter. All nine are now implemented, and isModelLive() requires a registered adapter as well as a key so the state cannot recur. Any earlier row implying xai, pika, ideogram, recraft, adobe, google, vidu, selfhost or utility models worked on a key alone was wrong.

  • Post-processing utilities (upscale, HDR master, interpolation, face

restore, lip-sync post) now refuse with a stated reason when no processing backend is configured, rather than resolving to a mock that returned the input.


Captions, dubbing, voices and the product page

Full detail in captions-dubbing-voices.md.

FeatureStatus
Closed captions in 30 languages, viewer-chosen colour/size/backgroundWorking
Right-to-left caption rendering (Arabic, Urdu, Persian) with correct fontsWorking
Caption readability checking (cues too fast to read)Working
Caption preferences synced to the account and to localStorageWorking
Re-render the whole film in another language with matching lip-syncWorking — translation needs ANTHROPIC_API_KEY; runs on the mock adapter end to end
Audio-only dub, with the mode recorded and shown so the two are never conflatedWorking
Per-line duration budgets given to the translator, and timing risks flagged before the renderWorking
Resumable dubs across many languagesWorking
Voice library, describe-a-voice, upload, in-browser recordingWorking
Voice audition with emotion, language and a refresh that re-seedsWorking — real timbre needs TTS_API_KEY
Consent gating on cloned voices, re-checked at use rather than at assignmentWorking
Voice references sent to native-audio video models as performance refsWorking
Product page — 94 features, links verified to resolveWorking