Feature Truth Inventory¶
This inventory records what visible product areas can honestly do today. The goal is to keep the current Dashboard model stable: Home, Read, Watch, Listen, Collections, Search, detail pages, Review Queue, and Settings/Admin. Removed all-in-one management workflows must not return as active product behavior.
Status labels:
- Live: implemented, persisted, and user-visible.
- Partial: usable but incomplete or dependent on Engine availability.
- Placeholder: visible as a future destination, but not functionally wired.
- Simulated: local or fake behavior only; should be disabled, relabeled, or removed.
- Experimental: intentionally available, but not guaranteed as product behavior.
- Not connected: visible for context, disabled, and not persisted.
- Engine unavailable: Engine state could not be loaded; fake defaults must not be substituted.
- Read-only / requires restart / requires credentials / admin only: specific blockers before a setting can change live behavior.
- Hidden/removed: should not appear as an active product surface.
| Area | Current status | What works | What does not work | Settings persist | Engine/API support | Visible now | Recommended next phase |
|---|---|---|---|---|---|---|---|
| Home / discovery | Partial | Renders Engine display data when available and shows first-library empty states that point to Libraries and Ingestion. | Discovery quality depends on available library data and Engine availability. | Not a settings surface. | Yes, through display APIs. | Yes. | Stabilize as real libraries are configured and ingested. |
| Read lane | Partial | Browse lane shell and reading surfaces render with Engine display data. | Completeness depends on ingestion and metadata quality. | Playback/reading preferences persist through the playback settings API. | Yes, partial display and playback APIs. | Yes. | Improve data completeness after ingestion work. |
| Watch lane | Partial | Browse and persistent video playback use current display/playback contracts. Compatible sources direct-play; other sources can use prepared adaptive HLS with seeking, resume, alternate audio, and captions in native HLS clients. | Browser support still depends on its native media stack; there is no bundled JavaScript HLS compatibility layer. | Personal playback preferences and resume persist; system delivery policy persists in transcoding config. | Yes for direct play, adaptive packages, signed delivery, and progress. | Yes. | Validate additional native clients and add a browser compatibility layer only if product support requires it. |
| Listen lane | Partial | Music browse shell, quick access, playlists, and playback host render. | Advanced playlist editing and playback behavior remain limited. | Personal playback preferences persist. | Partial. | Yes. | Expand only after product truth baseline is stable. |
| Search | Partial | Cross-library search UI and result rows render. | Result quality depends on indexed library data and Engine availability. | Not a settings surface. | Yes, through search/display contracts. | Yes. | Improve with ingestion/search quality later. |
| Detail pages | Live | Detail pages render item data and launch the shared editor for inline metadata, artwork, identity, and placement corrections where Engine support exists. | Unsupported fields/actions are capability-gated by editor context and Engine availability. | Yes, through editor, preferences, display override, artwork, canonical, and membership APIs where supported. | Yes. | Yes. | Keep media correction inline without creating a management workbench. |
| Review Queue | Live | Shows uncertain or blocked items, opens the shared editor in review mode, and resolves only through the Engine review API. | Depends on Engine review data and supported review actions. | Review resolve, dismiss, and skip-universe actions persist through existing review APIs. | Yes. | Yes. | Keep as the exception workflow. |
| Ingestion | Partial | Shows ingestion operations snapshots and progress when Engine data is available. | Historical depth and action coverage are limited. | Operational actions persist only where API-backed. | Yes, partial. | Yes. | Continue ingestion operational improvements. |
| Settings > Libraries | Live | Administrators manage catalogued libraries, stable catalogue source identities, incoming locations, presentation, metadata, intake, duplicate, and organization policies, plus the one managed View storage root. | Reorganization execution remains an explicit dry-run-and-confirm operation. | Yes through Engine/config actions. | Yes. | Yes. | Add per-library operational history after beta feedback. |
| View Personal Space and scopes | Live | Each enabled profile has one automatically provisioned Personal Space beneath the managed View root, fed by multiple persisted sources/devices. Managed folder imports copy originals into stable profile/source paths; optional external links remain read-only. Mine resolves the caller's Personal Space; Shared Library queries only accepted shared membership and never aggregate private profile spaces. Eligible folders are watched and reconciled in the background. | Mobile/device producers are not implemented. | Scope, density, per-source Timeline inclusion, Shared access, submission, curator review, and Gallery sharing persist independently. | Yes, through /view/scopes, /view/preferences, policy, source administration, folder browsing, and reconciliation APIs. |
Yes. | Keep every View query behind the same resolver and resource authorization service. |
| View Photos | Live | The five-item View rail and /view Photos route use trusted scope resolution and same-origin media grants. Browser uploads use a readable year/month/date filename layout. The aspect-aware mixed-media timeline supports anchored cursor paging, an authorized year/month scrubber, automatic loading, search, filters, item/Shift/date-group selection, a floating action bar, favorites, archive, trash, restore, Gallery placement, purpose-sized thumbnails/previews, Live Photo motion, compound-file provenance, persisted description/tags/location, and the shared accessible media viewer. |
Semantic search, automatic AI annotations, local reverse-geocoding data, and bidirectional rolling-DOM pruning are not implemented. | Yes; browsing, renditions, and metadata overrides do not modify originals. | Yes, through /view/assets, /view/assets/timeline-index, /view/uploads, /view/items/*, and signed /view-media/* grants. |
Yes. | Add enrichment only through privacy-preserving background processors. |
| View Folders and Shared Library | Live | /view/folders exposes authorized indexed sources and nested folders without turning child directories into libraries or Galleries. Profiles can pin folders privately; source owners can override Photos inclusion at any branch and descendants inherit the nearest rule. Shared scope includes only the accepted Shared Library root. /view/contributions supports batch previews, pending submissions, cancellation, My submissions, curator review, accept/decline, destination confirmation, direct curator add, async verified transfer, restart recovery, and an activity timeline. |
Pending counts in the global activity indicator and contribution-scoped thumbnail grants are not yet surfaced. | Pending/declined work is non-mutating. Accepted managed items move only after Shared verification; linked sources retain originals. | Yes, through /view/folders and /view/shared/*. |
Yes. | Add large-queue cursor paging and live SignalR progress after beta workload measurements. |
| View Galleries | Live | Manual and Smart Galleries support create, edit, delete, covers, ordering, rule evaluation, cursor paging, duplicate-safe manual membership, drag/drop placement, and owner-selected profile sharing with view/contribute permissions. Smart Galleries reject manual membership; deleting a Gallery never deletes assets. | There is no public-link sharing. | Yes. | Yes, through /view/galleries* and /view/share-targets. |
Yes. | Keep recipient selection policy-gated and Gallery-scoped. |
| View People | Partial | The Engine and Dashboard page only named or reviewed provenance-aware people annotations from an authorized scope and truthfully report when no capable annotations exist. | Face recognition is not implemented and unnamed faces are not invented. | Not an editable settings surface. | Yes, through /view/people. |
Yes for real annotations and empty capability state. | Add recognition only with explicit privacy controls and a real producer. |
| View Places | Partial | The Engine pages/searches real authorized GPS/place aggregates. The Dashboard plots those coordinates, synchronizes selectable markers with an accessible thumbnail list, and opens the shared viewer. Personal-space item location can be saved as a manual override or reset to embedded GPS in the viewer. | No third-party basemap/tile integration, MapLibre style, local geocoder dataset, or viewport clustering is connected; the UI labels the coordinate plot as the tile-free fallback. | Yes for authorized personal-item location overrides; originals are unchanged. | Yes, through /view/places and /view/items/{id}/location. |
Yes for real coordinates, editing, reset, viewer reuse, and empty state. | Add a configured/privacy-reviewed map provider and packaged local geodata before enabling tiles or place search. |
| View in Collections | Live | An administrator-authored Collection can reference a whole Gallery or a versioned View smart rule through the editor. Stored sources never contain individual local asset IDs, remain dynamic, and are projected only after View authorization. | Public Gallery links are not implemented. | Yes. | Yes, through /collections/*/personal-media. |
Yes. | Keep projections dynamic, authorized, and count-free when inaccessible. |
| Backup and recovery | Live | System settings create consistent archives, list and download them, validate restore contents and data integrity, and stage a restart-time restore while preserving the previous data-store file. | Scheduling, remote targets, and retention automation are not yet exposed. | Yes. | Yes, through /system/backups/*. |
Yes, admin only. | Add scheduling/retention after real beta usage. |
| Settings > Providers | Live | Provider catalogue/status/health, credentials-present state, connection tests, provider config, and pipeline priority load/save through Engine APIs where available. | Adding providers is disabled when live catalogue data is unavailable; no hardcoded fallback appears as saved config. | Yes for provider config and pipelines when Engine is reachable. | Yes, partial health depth. | Yes. | Later provider management refinement. |
| Settings > Metadata | Partial | Catalog, media type, Wikidata, hydration, and pipeline settings are live where their tabs expose Engine-backed save actions. | Matching/review/universe controls without persistence are disabled and marked not connected/read-only. | Mixed JSON/API-backed behavior. | Partial. | Yes. | Later metadata hardening. |
| Settings > Local AI | Live | AI health, model inventory, model download/cancel/load/unload, hardware profile, benchmark, resources, enrichment progress, feature flags, runtime values, vocabulary, and schedules use Engine-backed AI APIs/config where shown as live. Unsupported/not connected feature behavior is labelled instead of faked. | Model deletion, job last/next run metadata, and Local AI job control actions are not shown because no public Engine endpoint exists. Some saved settings can require restart, scheduler reload, model reload, or later Engine wiring to take effect. | Yes for AI config values and supported lifecycle actions. | Yes, through /ai/* endpoints. |
Yes. | Continue connecting individual AI feature implementations without expanding scope beyond Local AI. |
| Settings > Delivery | Partial | Engine-backed transcoding settings persist FFmpeg, cache, hardware, and adaptive HLS policy; diagnostics expose delivery readiness. | Placeholder per-profile Direct Play and subtitle/audio preference controls remain unconnected. | Yes for system transcoding policy; no for placeholder per-profile controls. | Yes for adaptive delivery and diagnostics; partial for the broader settings surface. | Yes, with unsupported controls labelled not connected. | Add only controls backed by explicit Engine policy. |
| Settings > Access | Partial | Profiles and API keys use Engine APIs. API key plaintext is shown only once on create and list/revoke operations are real where supported. | Remote access, network rules, sessions, and rate-limit controls are read-only/not connected unless backed by Engine config. | Partial. | Partial. | Yes, labelled partial in navigation. | Later access/security work. |
| Settings > Plugins | Partial | Plugin list, enable/disable, settings JSON, dynamic manifests, health, jobs, delete actions, in-app guidance, and approved GitHub catalog lookup use Engine plugin APIs where available. | Install/update marketplace behavior is not implemented and is not shown as live. Approved catalog lookup is discovery-only, not an installer. | Partial. | Partial. | Yes, labelled partial. | Future plugin install/update phase. |
| Playback preferences | Live | Personal playback, reading, subtitle, resume, and progress preferences save through the playback settings API. | Delivery-specific settings are separate and not persisted. | Yes. | Yes. | Yes. | Maintain while expanding playback later. |
| AI model management | Live | Model list comes from Engine/config, role keys use config names, supported roles can download/cancel/load/unload, and missing/downloading/ready/loaded/error state is not faked. | Delete is hidden. Roles unsupported by lifecycle must be labelled configured-only instead of receiving action buttons. | Lifecycle state is Engine-owned; model definitions persist through AI config. | Yes. | Yes. | Add richer job/activity telemetry only when Engine exposes it. |
| AI feature toggles | Live | Toggles load/save through AI config and dependency status explains disabled, missing model, downloading model, hardware limited, not connected, and ready states. | A saved flag is not presented as active unless the dependency checks pass. Some saved flags are marked not connected until Engine behavior consumes them. | Yes. | Yes for config; per-feature behavior varies. | Yes. | Connect remaining feature implementations where product-backed. |
| Provider priority | Live | Engine pipeline configuration can load/save when available, with explicit strategy labels for waterfall, cascade, and sequential behavior. | Provider add options require live catalogue data from the Engine. | Yes when Engine APIs are reachable. | Yes, partial. | Yes. | Later provider management refinement. |
| Direct Play settings | Partial | Runtime manifests preserve direct play whenever the negotiated client supports the source. | Placeholder user-facing override controls do not persist. | System behavior is live; placeholder overrides are not. | Yes for automatic selection. | Yes, unsupported overrides disabled. | Add overrides only with a real policy contract. |
| Subtitle/audio delivery settings | Partial | Adaptive packages serve managed and embedded WebVTT captions and separate alternate-audio renditions. | Placeholder user-facing default-track controls do not persist. | System packaging policy is live; placeholder preferences are not. | Yes for track discovery and delivery. | Yes, unsupported preferences disabled. | Add profile defaults only with a real persisted contract. |
| All-in-one management workflow | Hidden/removed | Current product surfaces replace the old combined workspace. | No routes, nav labels, CSS, or current behavior should be rebuilt. | Not applicable. | Not applicable. | No. | Keep removed. |