1inow should grow as a controlled system: clear permissions, clean environment handling, safe AI boundaries, and explicit integration approvals.
01
No secrets in code
Production credentials must stay outside the repository and inside controlled environments.
02
Role-based access
Founder, admin, manager, member, and viewer permissions should be explicit and auditable.
03
AI boundaries
AI routes remain stubbed until provider, permissions, audit, and cost rules are approved.
04
Audit trail
Important user, admin, AI, and integration actions should be recorded for review.
05
Integration approval
External services require a scoped task, build validation, and production decision.
Current state
OpenAI, Gemini, Anthropic, Resend, Stripe, analytics, and monitoring are intentionally not connected yet.
Data ownership
User-created content should remain owned by the user or organization that created it.
Production rule
Every major phase must build successfully and be committed separately before moving forward.
Nova + Vera
Nova and Vera stay with you as two living senses of the system.
Nova listens for movement. Vera watches for meaning, risk, and missing context. Together they make 1inow feel less like software and more like a daily operating partner.