Always-on integrity engine
| Feature | Description | Status |
| Multi-tenant voting systems | Each institution is a system (slug, pack, branding, settings) | Pilot |
| Multi-system device wallet model | Partitioned credentials per system on one device | Partial |
| Decisions: motions + elections | Binary, option-selection, election kinds | Pilot |
| Append-only public log | Hash chain; public verify; audit packs | Pilot |
| Mobile-only ballot cast | Device signature required; portal cannot cast | Pilot |
| Mode B sealing | Encrypt choice; tracker inclusion; tallier threshold | Pilot |
| Mode A public ballots | Optional low-stakes clear ballots | Partial |
| Roll commitment | Eligible set frozen at open | Pilot |
| Roles + freeze + no self-role | Decision-scoped parties; integrity invariants | Pilot |
| Community notes | Notes with moderation hide + log | Pilot |
| Per-system branding | Themes light/dark, logos | Pilot |
| Open-source verifier | CLI + public pages | Pilot |
Cast & ballot UX
| Feature | Description | Status |
| Idempotent cast | Safe retry does not double-count | Pilot |
| Content-hash binding | Vote bound to frozen decision content | Pilot |
| Binary / option / ranked paths | Choice shapes per kind/method | Pilot |
| Inclusion-first receipt | Tracker + deep links; no choice reveal | Pilot |
| Tracker re-fetch | List trackers after re-auth | Pilot |
| Device bind / rotate / recover | Rotation preferred; cooling-off on recover | Pilot |
| Fingerprint anti-phishing | Stable system fingerprint | Pilot |
| Review-and-confirm UI | Full summary before sign | Partial |
| Flutter multi-system app UI | Consumer wallet screens | Planned |
| Verify wizard (in-app) | 3-step inclusion UX | Planned |
Governance rules
| Feature | Description | Status |
| Pass rules | Majority, absolute, supermajority, unanimous, … | Pilot |
| Quorum rules | % or absolute; separate from pass | Pilot |
| Tie-break | Shared, rerun, lot, chair_cast | Pilot |
| Outcome mode metadata | Binding / advisory / ratification | Pilot |
| Min argue / min vote hours | Window gates; emergency logged | Pilot |
| Empty opposition policy | Banner or block open | Pilot |
| Param freeze | Rules immutable after freeze/open | Pilot |
Decision lifecycle & clerk workflow
| Feature | Description | Status |
| Draft → open → close → tally / void | State machine + log events | Pilot |
| Extend window | Logged extension | Pilot |
| Emergency open | Pack-gated audit trail | Pilot |
| Option withdraw | Logged; no silent erase | Pilot |
| Clerk export CSV | Membership / decisions / outcomes | Pilot |
| Evidence blobs | Hash + URI off-log | Pilot |
| Meeting / agenda entities | Chamber workflow objects | Planned |
| Minutes PDF pack | Clerk archive export | Planned |
Deliberation & elections
| Feature | Description | Status |
| For / against material | Binary motion advocates | Pilot |
| Per-option evidence | Elections / option motions | Pilot |
| Plurality / multi-winner | Seats + tally methods | Pilot |
| IRV / ranked support | Ranked paths in stack | Partial |
| Full STV plugin | Advanced electoral method | Planned |
| Nomination workflow | Propose → accept → freeze | Planned |
Membership, officers & access
| Feature | Description | Status |
| Officer bootstrap / appoint | No self-appoint privileged roles | Pilot |
| Sessions & logout-all | Bearer sessions; revoke | Pilot |
| TOTP + recovery codes | Optional / pack-required MFA | Pilot |
| Dual-control membership | Propose / approve | Pilot |
| Two-admin-before-live gate | Blocks first open until ≥2 officers | Pilot |
| Bind token hygiene | Short TTL, single use | Pilot |
| Rate limits | Auth, bind, public HTML, inclusion | Pilot |
Transparency, ops & hosting
| Feature | Description | Status |
| Public HTML hub / results / verify / tracker | Observer legitimacy pages | Pilot |
| Prometheus metrics | Instance scrape | Pilot |
| Security webhooks | Alerts with optional HMAC | Pilot |
| Smoke / device-cli / cast_demo | Integration tooling | Pilot |
| Docker Compose profiles | Postgres, auth, observability | Pilot |
| Hosted lease (commercial) | Operated environments | Partial |
| Self-serve SaaS billing | Automated signup + pay | Planned |
Procedure packs
| Pack | Tier | Typical use | Status |
| club_basic | T1 | Clubs & societies | Pilot |
| board_company | T2 | Boards, dual control, 2FA | Pilot |
| union_association | T2 | Large membership, quorum | Pilot |
| coop_weighted | T2 | Weighted voting | Partial |
| council_chamber | T2 | Formal public bodies | Pilot |
| high_assurance | T3 | Forced threshold posture | Pilot |
Roadmap / deferred (honest)
- Full Flutter multi-system consumer UI (crypto + CLI exist today)
- Mode C receipt-free / re-vote
- People’s Vote ideation backlog phase
- Full STV and advanced electoral plugins
- National statutory packaging / eID integration
- Self-serve SaaS billing wizard
Quarterly review checklist: docs/SITE_CONTENT_REVIEW.md in the meta repo.