Product · Features

Feature catalogue

One engine for many institutions. Integrity rules (device-only cast, no self-role, append-only log) are never pack-disabled. Tags show honest delivery maturity.

Pilot — usable in pilot / production-minded deploys Partial — core path works; UX or coverage incomplete Planned — design intent; not required for pilot

Always-on integrity engine

FeatureDescriptionStatus
Multi-tenant voting systemsEach institution is a system (slug, pack, branding, settings)Pilot
Multi-system device wallet modelPartitioned credentials per system on one devicePartial
Decisions: motions + electionsBinary, option-selection, election kindsPilot
Append-only public logHash chain; public verify; audit packsPilot
Mobile-only ballot castDevice signature required; portal cannot castPilot
Mode B sealingEncrypt choice; tracker inclusion; tallier thresholdPilot
Mode A public ballotsOptional low-stakes clear ballotsPartial
Roll commitmentEligible set frozen at openPilot
Roles + freeze + no self-roleDecision-scoped parties; integrity invariantsPilot
Community notesNotes with moderation hide + logPilot
Per-system brandingThemes light/dark, logosPilot
Open-source verifierCLI + public pagesPilot

Cast & ballot UX

FeatureDescriptionStatus
Idempotent castSafe retry does not double-countPilot
Content-hash bindingVote bound to frozen decision contentPilot
Binary / option / ranked pathsChoice shapes per kind/methodPilot
Inclusion-first receiptTracker + deep links; no choice revealPilot
Tracker re-fetchList trackers after re-authPilot
Device bind / rotate / recoverRotation preferred; cooling-off on recoverPilot
Fingerprint anti-phishingStable system fingerprintPilot
Review-and-confirm UIFull summary before signPartial
Flutter multi-system app UIConsumer wallet screensPlanned
Verify wizard (in-app)3-step inclusion UXPlanned

Governance rules

FeatureDescriptionStatus
Pass rulesMajority, absolute, supermajority, unanimous, …Pilot
Quorum rules% or absolute; separate from passPilot
Tie-breakShared, rerun, lot, chair_castPilot
Outcome mode metadataBinding / advisory / ratificationPilot
Min argue / min vote hoursWindow gates; emergency loggedPilot
Empty opposition policyBanner or block openPilot
Param freezeRules immutable after freeze/openPilot

Decision lifecycle & clerk workflow

FeatureDescriptionStatus
Draft → open → close → tally / voidState machine + log eventsPilot
Extend windowLogged extensionPilot
Emergency openPack-gated audit trailPilot
Option withdrawLogged; no silent erasePilot
Clerk export CSVMembership / decisions / outcomesPilot
Evidence blobsHash + URI off-logPilot
Meeting / agenda entitiesChamber workflow objectsPlanned
Minutes PDF packClerk archive exportPlanned

Deliberation & elections

FeatureDescriptionStatus
For / against materialBinary motion advocatesPilot
Per-option evidenceElections / option motionsPilot
Plurality / multi-winnerSeats + tally methodsPilot
IRV / ranked supportRanked paths in stackPartial
Full STV pluginAdvanced electoral methodPlanned
Nomination workflowPropose → accept → freezePlanned

Membership, officers & access

FeatureDescriptionStatus
Officer bootstrap / appointNo self-appoint privileged rolesPilot
Sessions & logout-allBearer sessions; revokePilot
TOTP + recovery codesOptional / pack-required MFAPilot
Dual-control membershipPropose / approvePilot
Two-admin-before-live gateBlocks first open until ≥2 officersPilot
Bind token hygieneShort TTL, single usePilot
Rate limitsAuth, bind, public HTML, inclusionPilot

Transparency, ops & hosting

FeatureDescriptionStatus
Public HTML hub / results / verify / trackerObserver legitimacy pagesPilot
Prometheus metricsInstance scrapePilot
Security webhooksAlerts with optional HMACPilot
Smoke / device-cli / cast_demoIntegration toolingPilot
Docker Compose profilesPostgres, auth, observabilityPilot
Hosted lease (commercial)Operated environmentsPartial
Self-serve SaaS billingAutomated signup + payPlanned

Procedure packs

PackTierTypical useStatus
club_basicT1Clubs & societiesPilot
board_companyT2Boards, dual control, 2FAPilot
union_associationT2Large membership, quorumPilot
coop_weightedT2Weighted votingPartial
council_chamberT2Formal public bodiesPilot
high_assuranceT3Forced threshold posturePilot

Roadmap / deferred (honest)

  • Full Flutter multi-system consumer UI (crypto + CLI exist today)
  • Mode C receipt-free / re-vote
  • People’s Vote ideation backlog phase
  • Full STV and advanced electoral plugins
  • National statutory packaging / eID integration
  • Self-serve SaaS billing wizard

Quarterly review checklist: docs/SITE_CONTENT_REVIEW.md in the meta repo.