Roadmap
Planned, not-yet-built work — derived from the live issue tracker.
Everything here is planned or in-flight — not shipped. It's derived directly from the open
issue tracker. For what's actually built, see Status.
Some of these are partially delivered. A few issues stay open to track remaining scope
even though their first slice shipped (e.g. #19,
#21,
#29 below). The
Status board is the source of truth for "done".
- Security hardening — the authentication surface is being hardened. See the trust model.
- Diarization robustness — #114 engine non-determinism run-to-run · #115 dedup / stale-span handling across an engine change · #113 identity latency ~2.5–5 min on long meetings · #127 mid-recording refresh drops to a finals-only fallback.
The in-person live experience is the active feature front. All in-flight, none shipped:
| Issue | Summary |
|---|
| #117 | No pause button while a recording is in progress |
| #118 | Live running summary during a recording |
| #119 | Live AI chat, grounded in the live transcript |
| #120 | Anchored comments / human notes on transcripts |
| #121 | Attach images (sealed, timestamp-anchored) |
| #122 | Share a live recording — Otter-style external link |
| #26 | Cross-device live-recording presence + red LIVE indicator + audio handoff |
| #30 | Live ASR-first streaming, then speaker catch-up (in-person + mobile) |
| Issue | Summary |
|---|
| #91 | Shared-with-me meetings discoverable on the recipient's dashboard (not link-only) |
| #92 | Revoke a recipient's access to a shared meeting |
| #93 | When a person withdraws voice consent — what happens to their name on past transcripts |
| #94 | Locking a meeting owner_only after sharing — revoke existing shares? |
| #108 | "Make private" available at recording start, not only after a meeting exists |
| #83 | Corrections from a non-owner — dispute + single source of truth |
| #97–#101 | Consent-notify hardening: expired magic links, approve/flip fan-out, single-worker idempotency, email-case asymmetry |
| #86 · #139 | FPM recognition-notice email is dark; tag-consent email omits the accept/reject CTA |
| #85 | Conclave owns meeting context, VFTEE owns the consent screen — context never crosses the wire |
| Issue | Summary |
|---|
| #136 | Summary → distilled story: chapters, callbacks, streaming |
| #137 | Feed prior obligations into the model for insight derivation |
| #130 | Chat with your meetings / memory — multi-turn on top of the unified retriever |
| #18 | Unified retrieval service (one retrieval path) |
| #90 · #36 · #39 | Refine backlog: vocab suggestions (partly in #124), OOV highlighting, vocab-management UI |
| #107 · #138 | Unify editor/viewer rendering; Studio refine post-merge bug bucket (from #124) |
| #40 · #17 · #15 | Workspace entity canon; meeting-type tagging/clustering; personal memory (RLHF loop) |
| Issue | Summary |
|---|
| #19 | Conclave MCP server + scoped agent tokens — PATs + OAuth "Connect" shipped; MCP server proper pending |
| #21 | Attestation & trust-receipt surface — seal signing shipped (records carry enclave-origin proof); remaining scope = a client-side attestation viewer |
| #29 | Standalone analytics app — analytics.conclavehq.org is live; remaining scope = retire the in-app cockpit |
| #134 | Regulated-data redaction — v1 live (structured detect/strip + signed receipt); v2 free-form PHI/PII + v3 verifiable-redaction proof planned |
| #25 | Signup access gate — closed-beta invite codes |
| #16 | When is Conclave-web "done"? (mobile gate + product-boundary decision) |
| #11 · #10 | Live co-pilot overlay → native Mac app; meeting templates |
| Issue | Summary |
|---|
| #31 · #32 | Post-processing ETA/progress; fire-and-forget upload with a status card |
| #34 | Audio waveform render is slow for long recordings |
| #102 · #103 | Freshness: hidden-tab polling; forever-403 sessions stuck on "Finalizing…" |
| #84 · #69 | Newsletter signup wiring; test-suite settings-singleton corruption |
| Issue | Summary |
|---|
| Capture#2 | Bot-path acoustic identity (voiceprint + which-mic over Meet) |
| Capture#3 | Multi-phone capture (0.2) |
| Capture#4 | Voice recreation from fingerprints (experiment) |
| Capture#5 | Per-workspace bot allocation / no duplicate bot |
| Issue | Summary |
|---|
| VFTEE#9 | Consent before capture — defer voiceprint creation until the subject approves |
| VFTEE#4 | "Hear the clip before consent" broken end to end (clip_ref / capability handshake) |
| VFTEE#6 · #7 | Withdrawn-consent guard is per-voiceprint not per-person; notify failure creates a silent pending proposal |
| VFTEE#2 | Robust voiceprint enrollment + poisoned-enrollment eval |
| Issue | Summary |
|---|
| Mobile#3 | Inbox: wire Shared-with-you / Invitations / Recognitions to real data (backend-gated) |