worklists.app the frontline app

What ships today,
and what does not.

This page exists so the rest of this site can be read as a description rather than as marketing. Everywhere else is written in the release tense; the delta lives here, dated, and this page is authoritative over any sentence on the site that disagrees with it.

Ledger date: 2026-08-20. The app lives at apps/worklists.app and ships through an operator's own developer account; nothing is hosted on this origin. The product document is served byte-identically at /product.md, and it opens with the sentence this ledger is built to keep true: nothing on this door is built and nothing is hosted. No price is published (P0-A3).

Shipped

  • The compile-time regime binding: a deployment manifest (*.deployment.json, 2 in the tree) binds one operator, one tenant and one regime into the build, and discretionary is refused at compile time.
  • 3 build gates in the app's own tree — regime-binding-gate, views-gate, white-label-gate — each run in the estate's install-free gate chain.
  • The six-View, twelve-Role registry with measured per-face token budgets; the white-label gate fails a build that carries a hard-coded product name.
  • The app ships through the operator's own developer account; over-the-air updates are disabled by design, so what is in the hand is what was signed.
  • This door: the page, its markdown and JSON twins by content negotiation, the blog, the dated ledger, llms.txt, the sitemap, and /product.md — the product document served byte-identically.
  • POST /waitlist — the access list, stored in this door's own D1 database, the row exactly what the form says it is.
  • Request telemetry to the estate's shared store, disclosed in full at /what-we-log in three faces.

Open in the launch ledger

  • A screen. The app's root component renders nothing yet — phases 1 and 2 of the surface spec (the regime binding and the registry) are in the tree, and the first View is not (P0-A1; dot-do/vis#337–#347). Read from apps/worklists.app/src/App.tsx during this build.
  • The free evaluation deployment against the demo tenant, self-serve, no card (P0-A2; dot-do/vis#424).
  • The price per production deployment. The model is ruled — one price per deployment, annual, unlimited performers — and the number is $TBD; nothing publishes until it is a number we are willing to change (P0-A3; dot-do/vis#422).
  • The store listing under an operator's account, end to end, proven once (P0-A4).
  • Signup notification on the access list; today the row is written and nobody is paged (P0-A5).

How to read the two columns.

The left column is checkable: the app's gates run with npm run gate at the repository root, and this origin's faces answer over HTTP — curl https://worklists.app/product.md returns the product document byte for byte.

The right column is the open half of the launch ledger. Each entry names its launch-blocker number in docs/P0-LAUNCH-BLOCKERS.md, closes by shipping the mechanism, and is dated when it closes. Opening an entry records a gap; it does not license a present-tense sentence somewhere else on the site.

The standard.

A closing event is an EPCIS 2.0 event and validates against the pinned official schema at the family's event layer. GS1 is the standards body and has not reviewed, certified or endorsed this project.

← The door