# Gift Graph Feature Backlog > Gift Graph - what v0.1 left out on purpose, what the live demo surfaced, and the order I would build it in > Last Updated: 2026-10-01 · Mirrors `docs/feature-backlog.md` in the repo, with priorities added here ## Legend - **Status:** `[ ]` Not Started | `[~]` In Progress | `[x]` Complete - **Priority:** P0 (Critical) | P1 (High) | P2 (Medium) | P3 (Nice-to-have) - **Links:** [[Gift Graph Technical Decisions]], [[Gift Graph Bug Tracker]], [[Gift Graph Product Plan]] ## P0 - Critical (Proves the Privacy Model) - [x] **Consent handshake** - 2026-09-30 - *Goal:* A requester asks, an owner approves once with a default tier, and either side can see where the connection stands - *Shipped:* `request_connection` · `approve_connection` · `set_default_tier` · `revoke_connection` · `list_connections` - [x] **Tier-limited drop and pull** - 2026-09-30 - *Goal:* A pull returns only the text the tier allows; silent drops never surface; matching never touches withheld text - *Shipped:* `drop` and `pull` over Streamable HTTP, filter in the query, 12 integration tests - [ ] **Semantic matching built from disclosed text only** - P0 - *Goal:* Natural prompts match ("gift ideas about fonts" finds "type and lettering") without reopening the leak literal matching closes - *Constraint:* Embeddings computed from category and vibe text only; verbatim text never enters the index - *See:* [[Gift Graph Bug Tracker#BUG-003]] - [ ] **Drop scope decision** - P0 - *Goal:* Decide whether a drop belongs to one connection (Agent's reading, `requesterId` on `drop`) or to the owner across all approved connections (the concept page) - *See:* [[Gift Graph Technical Decisions#TDR-006]] - [ ] **Revocation semantics** - P0 - *Goal:* Decide whether renewed approval restores old drops or starts fresh; PSI-based tombstones follow from the answer - *See:* [[Gift Graph Bug Tracker#BUG-006]] ## P1 - High (From Prototype to Product) - [ ] **Registration ladder** - P1 - *v0.2:* Sign-up and login through Clerk (Google or email); first login creates the user row; a settings page issues that user's MCP token; connection invites by email or handle - *v0.3:* OAuth for MCP clients in place of static tokens, the way Replit's own MCP server works, with the user approving access in a browser - *Enterprise:* SSO and SCIM through the customer's identity provider; a SCIM removal also revokes that user's connections and drops - [ ] **Owner review screen** - P1 - *Goal:* The owner sees and edits their own drops by tier, marks surprise-safe, and reviews connection state. v0.1 is tools-only with no UI - [ ] **Enterprise SSO through Clerk with Microsoft Entra ID** - P1 - *Goal:* The customer-infra story in one evening; Entra or Okta over OIDC or SAML - *Note:* Replit's free SSO window through Clerk closed October 1, 2026 - [ ] **Anti-inference engine** - P1 - *Goal:* 48-hour release delay, a three-drop minimum per category before anything at category or vibe tier is served, jitter on top, which keeps "something design-related" from being triangulated back to "he mentioned a font on Tuesday" - [ ] **Re-run tests in the multi-artifact layout, then republish** - P1 - *See:* [[Gift Graph Bug Tracker#BUG-009]] ## P2 - Medium (Field Assets and Reach) - [ ] **Replit Skill packaging the SSO setup** - P2 - *Goal:* The "turn field patterns into templates and playbooks" line from the posting, built in Replit's own format and shareable from the repo - [ ] **Per-drop editing and tier changes** - P2 - *Goal:* Edit a drop's category or vibe text after the fact; decide what a default-tier change does to existing drops (v0.1 snapshots the tier at creation) - [ ] **Notifications, the owner's dial** - P2 - *Goal:* Push (rare, opt in), passive (the requester's agent simply knows more when asked), or seasonal (a nudge before a birthday, only if enabled) - [ ] **Black-box pen test against the live URL** - P2 - *Goal:* The outside-in result from Replit's Security Center to sit beside the clean static scan - [ ] **Review deck in a separate project** - P2 - *Goal:* The five-slide engineer-review deck from the three docs, built where it cannot touch the live server ## P3 - Nice-to-have - [ ] **Feedback widget, once a human-facing page exists** - P3 - *Why:* Feedback capture, data, and sentiment analysis are areas I have worked in deeply as a partner to product teams, and the widget is a ready surface for it - [ ] **PSI-based tombstones for purchases** - P3 - *Goal:* Mark a hint as bought without either side revealing purchase history - [ ] **The business pilot** - P3 - *Goal:* One vendor and one customer support team who already share context badly over email; measure whether tier-reduced context resolves a real ticket faster than the wall did ([[Gift Graph Product Plan]])