# V1 Product Review — Oshun (Unified Contemplative / Knowledge / Learning Product)

Status: independent product review — revised and expanded in a second
meticulous pass on 2026-07-07 (§9, Additional considerations) and a third
pass on 2026-07-07 covering monorepo integration, shared functionality,
and TODOS/ roadmap alignment (§10)
Reviewer: Claude (product-perspective deep review)
Date: 2026-07-06 (first pass) · 2026-07-07 (second and third passes)
Scope: `V1/features.md` + all `V1/features/*` pages, `V1/TODOS.md` completion
state, `V1/AUDIT_2026-06-24.md`, `V1/REMEDIATION_2026-06-12.md`,
`V1/planning/*`, app surfaces on disk (`apps/oshun/*`, `apps/metis/*`)
Method: full deep-read of the V1 docs corpus, then critique against the shipped
competitive set (Calm, Headspace, Insight Timer, Waking Up, Finch, Fabulous,
Ground News, NewsGuard, Sky Guide/SkySafari/Stellarium, Sefaria, Logos,
Khanmigo, Duolingo, Brilliant, NotebookLM, ChatGPT/Pi voice assistants) and
current industry SOTA. Market facts reflect knowledge through early 2026.

---

## 1. Executive summary

Oshun V1 is a single-shell consumer product spanning six domains — Tara
(contemplative practice, the spine), Arete (humane goals/habits), Veritas
(grounded news), Nyx (sky and awe), Nisaba (scholarly study), Metis
(education) — plus a cross-domain voice-first assistant, on six substrates
(grounding, memory, real-time runtime, contemplative safety, governed
generation, non-custodial payments). The engineering substance is unusually
deep and unusually honest: real taxonomies and state machines, a no-bypass
crisis-safety architecture, deterministic source-quality scoring, real
psychometrics (IRT/BKT/FSRS), and fail-loud seams wherever a provider or
credential is absent.

**Three things here are genuinely ahead of the industry**: (1) the Lilith
crisis-safety and recovery architecture — no consumer wellness app ships
anything close to a structurally non-bypassable crisis frame with a designed
re-entry journey; (2) Veritas's retraction cascade and named-attestation
sourcing — beyond Ground News/NewsGuard, which stop at bias/reliability
badges; (3) the anti-streak "humane structure" stance in Arete, which is a
real differentiator in a market trained on Duolingo-style punishment loops.

**Three things put the product at risk**: (1) **positioning diffusion** — six
domains, an agentic studio, an ancient-philology engine, and a 32-rail crypto
checkout do not answer "what do I open this app for each morning?"; (2)
**crypto-first monetization** is a conversion and *distribution* hazard — the
wellness demographic pays with Apple Pay, and app-store IAP rules make
crypto-only checkout for digital entitlements a rejection risk on iOS/Android;
(3) the **launch story vs. code-tier honesty gap** — "six co-equal domains" is
really five launching (two beta, one shell-disconnected) and one `planned`,
and the residual-audit trail (12 P0-SEC, ~250 findings) is the operative truth
behind a 99%-checked backlog.

Verdict: **a category-defining safety/trust core wrapped in too many
storefronts.** Lead with one daily ritual that threads the domains, make fiat
the default rail, ship the sleep vertical, and let the depth (Nisaba, Metis)
be discovered rather than marketed.

---

## 2. What V1 is (product identity)

- One shell, one identity, one memory, one trust signal across web (Next.js,
  ~684 routes), mobile (Expo, incl. admin-mobile), desktop companion, watch
  companions (watchOS/WearOS), Telegram bot + mini-apps, offline substrate,
  and a single BFF.
- Six customer domains; Tara is `OSHUN_SHELL_PRIMARY_DOMAIN` in code.
- Cross-domain assistant with typed invocation surfaces, persona handoffs
  (teacher/coach/scholar/moderator…), three always-on disclosure chips
  (memory-state, grounding-state, persona-identity), and four interaction
  modes up to premium avatar-embodiment.
- Generation is governed end-to-end ("Isis is the only path"): workflow
  classes, model registries, release gates (safety floor 0.9 hard block),
  watermarking, provenance bundles, human-review triggers.
- Monetization: 6 entitlement classes → 3 tiers; premium gates on voices,
  avatars, cloning, generated video, institutional gradebook. Payments are
  non-custodial crypto-first (32 rails, tier/trust disclosures, signed
  receipts); Stripe/Apple/Google fiat added 2026-07-04 as "V1.x-optional."

---

## 3. What is genuinely strong (keep and market these)

1. **The Lilith crisis architecture is world-class.** A 13-rule crisis catalog
   bound on-by-default; merge logic that always takes the more severe signal
   (an integrator *cannot* stub it out); fail-closed crisis frame that breaks
   persona, halts synthesis, suspends memory writes, and opens an incident;
   then a designed **recovery journey** (stillness window, single re-entry
   ask, reframe protection, opt-in check-ins). Industry SOTA is a disclaimer
   and a 988 link. This is a defensible trust brand — and it should be
   independently audited and then *published*, the way security teams publish
   SOC 2. Nobody else can say this.
2. **Humane streaks in Arete.** `done|partial|skip|decline|miss` →
   `engaged/grace/no-count`, recovery that archives momentum instead of
   zeroing it, 11 friction signals, 9 interventions. Finch is the only
   competitor emotionally near this, and it's a pet metaphor, not a coaching
   system. "The habit app that never shames you" is a marketable one-liner
   backed by real code.
3. **Veritas's epistemics.** Deterministic 9-factor source scoring with
   domain-specific weights, named (never anonymous) expert attestation, a
   false-balance brake, and a **retraction cascade that re-grounds every
   dependent surface a reader saw** — including downstream Metis lessons.
   Ground News shows you bias distribution; Veritas models *evidence*. The
   cascade is beyond anything shipped in consumer news.
4. **Real computational cores where competitors fake it.** Nyx's Meeus
   ephemeris with known-answer tests; Metis's 1PL/2PL/3PL IRT + BKT + FSRS-5
   + DIF monitoring (consumer learning apps run much cruder models); Nisaba's
   30+ script handlers and CBGM collation (this is Logos/Accordance-grade
   tooling).
5. **Governed generation with provenance.** Release gates, watermark floors,
   likeness/cloned-voice human-review triggers, ed25519 provenance bundles,
   generation-tier allowlists that deny-by-default (a contemplative user
   physically cannot reach the graph editor). With C2PA SDK wiring finished,
   this is a "verified synthetic media" story regulators and press will like.
6. **The honesty culture.** Fail-loud seams, `planned`-gating over
   fake-shipping, self-auditing docs (79 inaccuracies found and logged).
   As with V2, this makes the plan auditable — rare and valuable.

---

## 4. Product gaps

### 4.1 The coherence gap: six domains, no daily thread

The "one coherent product" promise is delivered *architecturally* (one
registry, one shell, one memory) but not *experientially*. Nothing in the docs
composes the domains into a single daily habit. Calm owns "before sleep,"
Headspace owns "morning reset," Duolingo owns "the daily streak." Oshun's
answer should be **the Thread**: one composed daily ritual — wake → today's
sky moment (Nyx, one line) → a sit matched to stated mood (Tara) → one
intention (Arete) → a 90-second grounded briefing (Veritas) → an optional
2-minute learning beat (Metis). One screen, one notification, five domains
quietly doing their jobs. The assistant narrates it; the shell already has
every primitive (mood taxonomy → recommendation slate, observation windows,
check-ins, topic hubs, tutor loop). This single feature converts the
portfolio from "a directory of disconnected domain apps" — the exact thing
the promise disclaims — into a product with a reason to open it at 7am.

### 4.2 Domain-by-domain gaps vs. shipped competitors

**Tara vs. Calm/Headspace/Insight Timer/Waking Up:**
- **No sleep vertical.** Sleep stories/soundscapes are the #1 revenue surface
  in consumer mindfulness (Calm built a nine-figure business on them). Tara
  has sounds and rest modalities but no named sleep product, no wind-down
  program, no sleep-tracking integration (HealthKit/Health Connect). This is
  the largest single commercial gap in V1.
- **Human teacher catalog depth.** Competitors ship thousands of hours of
  licensed human-taught content and celebrity narrators. Tara's taxonomies
  and lineage gates are superior *infrastructure*, but the docs are thin on
  the licensed-content acquisition plan. AI-generated guidance without
  beloved human voices reads as a cold start in this category.
- **No live/community layer.** Insight Timer's live rooms and groups drive
  its retention. Mentor Presence (embodied AI mentors) is novel and shipped,
  but *human* sangha — opt-in groups, teacher-led live sits — is absent.

**Arete vs. Finch/Fabulous/Habitica:**
- Widget-first UX (home-screen check-ins) and wearable one-tap logging are
  table stakes; watch companions exist, but the habit-widget story isn't
  explicit.
- No social accountability option (partner/duo mode). Optional and quiet —
  but its absence caps retention for a large cohort.

**Veritas vs. Ground News/Particle/NewsGuard:**
- **Coverage breadth and freshness.** The scoring/attestation machinery is
  superior, but a news product lives or dies on ingestion scale, latency, and
  editorial staffing for the attestation pipeline. Named-expert attestation
  at news speed is an operations problem the docs don't cost out. Risk:
  a beautiful trust model over a thin trickle of stories.
- No push-alert/personalized-digest posture is described (quiet-hours are
  aspirational) — the retention surface of every news product.

**Nyx vs. Sky Guide/SkySafari/Stellarium:**
- **No AR point-at-the-sky overlay** — the single feature that made Sky Guide
  and Star Walk mass-market. Nyx's ephemeris core makes this cheap relative
  to its impact; without it, Nyx is a beautiful almanac competing against
  magic.
- No telescope control (SkySafari's enthusiast moat) and no astrophotography
  community loop. Acceptable to skip; AR is not.

**Nisaba vs. Sefaria/Logos/Accordance:**
- Corpus licensing is the moat and the cost center (critical editions,
  lexicons, and translations are mostly *licensed*, not open). The docs model
  citation/credential invariants beautifully but say little about the
  acquisition strategy or which corpora ship at launch. Sefaria wins by
  being free + community; Logos wins by owning licensed depth. Nisaba needs
  a stated corpus strategy or it launches as an empty cathedral
  (currently: shell-disconnected, stub workspace API).

**Metis vs. Khanmigo/Duolingo/Brilliant/Canvas-ecosystem:**
- The psychometrics and standards layer (LTI 1.3, SCORM, OneRoster, QTI3,
  Caliper, Open Badges) exceed consumer competitors and match institutional
  incumbents on paper. What's missing is the **adoption motion**: no teacher
  onboarding funnel, no content marketplace, no consumer motivation loop to
  replace the punishing streaks V1 rightly rejects (what *is* the humane
  Duolingo loop? Arete's grace-streak mechanics should be reused here — a
  cross-domain synergy the docs don't draw).

### 4.3 Assistant gap

The routing/memory/disclosure scaffolding is ahead of the field (persona
handoffs with memory boundaries; invocation guards; degradation with
disclosed reasons). But the **LLM itself is provider-gated and the
voice-first experience is unproven** — and in 2026 the bar is ChatGPT
Advanced Voice / Gemini Live: sub-second, interruptible, emotionally
attuned. A contemplative product's assistant must be *calmer and more
present* than the general-purpose giants, not merely well-governed. Latency
budgets, barge-in behavior, and voice persona quality need the same
engineering rigor the safety layer got. Until a provider is wired, V1's
most-marketed surface is a beautifully specified silence.

### 4.4 Monetization and distribution gaps

- **Crypto-first is backwards for this audience.** The non-custodial rail is
  technically excellent (signed receipts verifiable against-chain is genuinely
  novel) — but meditation/news/learning customers convert via Apple Pay,
  Google Pay, and cards. Fiat (added 2026-07-04, "V1.x-optional") must be the
  **default** presented rail; crypto becomes the privacy-preserving option
  for the minority who want it.
- **App-store compliance risk (undocumented).** Digital entitlements
  purchased in-app on iOS/Android must use platform IAP (or fall under the
  post-anti-steering external-link entitlements, which are jurisdiction- and
  policy-fragile). A crypto checkout for premium tiers inside the mobile app
  is a rejection/removal risk. The docs' regulatory review covers securities/
  sanctions/regional gates but not *store policy* — this needs a decided
  posture (IAP in-app; crypto/fiat on web with reader-app-style flows).
- **No customer-facing pricing narrative.** Tiers/feature keys are modeled;
  dollar prices live in an external catalog; there is no pricing *page*
  strategy, trial design, or intro-offer narrative in the corpus. For a
  product this broad, the packaging story (what does `plus` mean to a human?)
  is a launch blocker, not a detail.

### 4.5 Industry SOTA checklist

| Capability (2026 bar) | Bar-setter | V1 |
|---|---|---|
| Crisis safety beyond a hotline link | (nobody) | ✅✅ beyond SOTA (Lilith no-bypass + recovery journey) |
| Humane habit mechanics | Finch | ✅✅ beyond SOTA (grace/no-count streaks, recovery engine) |
| Evidence-modeled news + retraction propagation | Ground News (bias only) | ✅✅ beyond SOTA (cascade), ⚠️ ops unproven |
| AI companion w/ persistent memory + disclosure | ChatGPT memory, Ebb | ✅ modeled better (chips, scopes, consent), ❌ LLM unwired |
| Sub-second expressive voice assistant | ChatGPT AV / Gemini Live | ❌ gap (provider-gated, no latency budget stated) |
| Sleep content vertical | Calm | ❌ **gap** |
| AR sky overlay | Sky Guide | ❌ **gap** |
| Adaptive learning w/ real psychometrics | ALEKS/Duolingo | ✅ exceeds (IRT+BKT+FSRS+DIF) — unlaunched |
| LMS interop (LTI/SCORM/OneRoster) | Canvas ecosystem | ✅ modeled fully |
| Generated-media provenance (C2PA) | industry scrambling | ✅ architecture, ❌ SDK unpinned (G0 gate) |
| Cross-device continuity | table stakes | ⚠️ partial (several sync seams incomplete) |
| Watch/widget presence | table stakes | ✅ exists (watchOS/WearOS, widgets) |
| Fiat one-tap payment | table stakes | ⚠️ just added, "optional" — must be default |
| Offline practice mode | Calm/Headspace downloads | ✅ offline substrate exists (verify depth for audio) |

---

## 5. Ideas that would make the product better

1. **The Thread (§4.1)** — the composed daily ritual across domains. This is
   the flagship recommendation of this review; it is also the cheapest, since
   every primitive already exists. Ship it as the default home surface.
2. **Sleep by Tara.** Wind-down program (Tara modalities + Living Scenes
   "Contemplative Arc" dimmed variants + Nyx "tonight's sky as you drift"),
   sleep soundscapes, HealthKit/Health Connect integration, morning
   reflection into Arete. Reuses four existing systems; fills the largest
   commercial hole.
3. **Publish the safety architecture.** External audit of the Lilith crisis
   path + a public "Contemplative Safety Report" + an API-level guarantee
   statement. Trust is this product's brand; make it legible. (Pair with the
   C2PA mint/verify completion so provenance badges appear on every generated
   artifact user-facing.)
4. **AR sky mode for Nyx** — point-at-sky identification using the existing
   ephemeris core; observation windows become "walk outside now"
   notifications with a lift-your-phone moment. This is Nyx's mass-market
   unlock.
5. **Human teachers program for Tara.** A curated launch roster of 10–20
   licensed human teachers (the lineage taxonomy is *made* for this), with
   Mentor Presence positioned as practice-between-classes, not as the
   headliner. AI-first guidance in this category invites backlash; human-led
   with AI continuity is the defensible framing.
6. **Sangha, quietly.** Opt-in small groups (4–12) with shared sits, shared
   Threads, and Arete duo accountability — moderated under the existing T&S
   machinery. Retention compounding without becoming a social network.
7. **Grace-streaks as the Metis motivation loop.** Port Arete's
   `engaged/grace/no-count` mechanics into Metis learner progress — "the
   learning app that doesn't punish you for having a life" extends the brand
   coherently and answers Duolingo without copying it.
8. **Veritas daily briefing as audio.** The grounded-explainer Living-Scene
   template + TTS → a 3-minute morning briefing with confidence bands spoken
   plainly ("well-supported… contested…"). Slots into the Thread; competes
   with news podcasts on trust rather than speed.
9. **Nisaba launch = one corpus, free, deep.** Pick one open corpus (e.g.
   Hebrew Bible via open editions, or Greek NT with open apparatus) and ship
   the *full* Nisaba experience against it — reader, lexicon, morphology,
   concept graph, notebooks — free. Sefaria proved free-depth builds scholar
   communities; licensed breadth can follow demand.
10. **Unified "Why am I seeing this?"** — one tap on any recommendation
    (sit, story, lesson, sky event) opens the same explanation sheet backed
    by memory scopes + grounding chips. The disclosure infrastructure exists;
    surfacing it uniformly would be a visible trust differentiator no
    competitor matches.

---

## 6. Criticisms and tweaks

1. **Resolve the "six co-equal domains" story.** Code says: 5 launch (2 beta,
   Nisaba shell-disconnected), Metis `planned`. Marketing that says "six" will
   be fact-checked against the app in one session. Say "five, with education
   arriving for institutions first" — or wire Nisaba/launch Metis before
   saying six. The audit already reconciled the internal wording; the
   *external* narrative needs the same honesty.
2. **Make fiat the default rail now** (§4.4). Keep the crypto rail as the
   privacy option and a genuine differentiator for the sovereignty-minded —
   but a wellness product whose checkout leads with Monero disclosures will
   bleed >90% of intenders at the paywall. Also: decide the app-store IAP
   posture before submission, not during review.
3. **Metis investment paradox.** The most-built domain (psychometrics,
   standards, BYOM harness) is unlaunchable (`planned`, no dedicated DB, 5 of
   13 cross-domain wirings missing). Either promote it into the launch wave
   for institutions (its compliance story is strong: under-13 controls,
   FERPA/COPPA posture) or explicitly park it and stop accruing depth ahead
   of wiring. Building deeper on an unlaunched domain is inventory, not
   product.
4. **The money path has real integration debt**: the payments bridge declares
   `@aje/*` but never imports it, and runs two unreconciled internal event
   vocabularies. For the subsystem that takes money, "honest self-flagged
   inconsistency" is still a P0 to reconcile before GA.
5. **Naming hygiene**: "Lilith" = safety substrate + showcase route + a
   separate meditation app; "Veritas" = domain + a 66-lib journalism
   collection; `libs/maat` is an unrelated B2B product. Internal, but it will
   leak into support docs, incident comms, and onboarding of new staff.
   Publish a canonical disambiguation page (the glossary partly does this —
   finish it).
6. **8 launch locales including two RTL** (ar, he) is admirable and
   expensive; with content-hungry domains (Tara guidance, Veritas stories),
   locale count multiplies editorial cost, not just string cost. Consider
   launching 4 locales deep rather than 8 shallow.
7. **The residual-audit truth must gate the launch narrative**: 12 P0-SEC
   findings and ~250 residuals are the operative backlog behind a 99%-checked
   TODOS. The corpus itself says checkboxes are not authoritative — hold GA
   messaging to the residual ledger, not the checkbox ratio.
8. **Quiet-hours and notification ethics** are aspirational in Veritas while
   Tara promises contemplative care — a contradiction users will *feel* (a
   breaking-news push at 11pm from the same app that guarded your wind-down).
   One cross-domain attention policy (Lilith-owned) should govern every
   notification surface; it's the kind of coherence the product promise is
   about.

---

## 7. Risks

1. **Positioning diffusion** (§4.1) — the defining product risk. Without the
   Thread (or equivalent), reviewers will describe Oshun as "six apps in a
   trench coat," the exact critique the promise anticipates.
2. **Cold-start content economics** — Tara guidance hours, Veritas
   attestation staffing, Nisaba corpora licensing: three domains whose
   quality bar is set by content operations the docs under-specify. The
   governance machinery multiplies content cost (every claim needs named
   attestation) — budget it or narrow launch surface area.
3. **App-store distribution** (§4.4) — crypto checkout + generated media +
   under-13 institutional flows are three separate review-team triggers;
   needs a compliance dossier per store before submission.
4. **AI-wellness backlash** — an AI mentor guiding grieving users is exactly
   the scenario journalists probe. V1's crisis architecture is the best
   defense in the industry; it only works as a defense if it is *publicly
   legible* (§5.3) and if the human-teacher story (§5.5) leads.
5. **Provider dependence at the last mile** — assistant LLM, TTS/voice,
   video generation are all env-gated externals; product quality at launch
   equals whichever providers get wired, yet no provider SLAs/latency budgets
   are stated for the assistant path (Isis release gates cover safety, not
   snappiness).
6. **Regulatory surface of the crypto rail** — the review is thorough
   (Saudi NO-GO, XMR regional gates, invoice caps), but the residual risk is
   reputational adjacency: "meditation app takes Monero" is a headline that
   writes itself. Default-fiat (§6.2) also mitigates this.

---

## 8. Prioritized recommendations

**P0 — before GA**
1. Ship the Thread as the default home experience (§5.1).
2. Fiat default / crypto optional; decide app-store IAP posture (§6.2, §4.4).
3. Reconcile the payments-bridge ↔ Aje integration and its event vocabularies
   (§6.4); clear the 12 P0-SEC residuals.
4. Wire one production LLM/voice provider with stated latency budgets; prove
   the assistant's calm-voice moment (§4.3).
5. Fix the external domain-count narrative (§6.1).
6. Pin and wire the C2PA SDK (already a G0 gate — hold it).

**P1 — the delight wave**
7. Sleep by Tara (§5.2).
8. AR sky mode (§5.4).
9. Human teachers launch roster + Mentor Presence as supporting act (§5.5).
10. Publish the safety architecture externally (§5.3).
11. Veritas audio briefing in the Thread (§5.8).
12. Cross-domain attention/notification policy under Lilith (§6.8).

**P2 — compounding depth**
13. Sangha small groups (§5.6); Arete duo mode.
14. Grace-streaks ported to Metis; institutional-first Metis launch decision
    (§6.3).
15. Nisaba one-corpus-free launch (§5.9).
16. Unified "Why am I seeing this?" sheet (§5.10).
17. Locale depth-over-breadth review (§6.6).

---

## 9. Additional considerations (second pass)

### 9.1 Pricing anchors and packaging (the missing number)

The first pass flagged the absence of a customer-facing pricing narrative;
the second pass should supply the anchor. The consumer comps are firm:
Calm and Headspace sit at ~$69.99/yr, Brilliant at ~$149/yr, Insight Timer
Plus at ~$60/yr. Oshun's breadth (practice + news + study + learning +
assistant) argues for pricing *above* single-category apps but below the
"stack of five subscriptions" it replaces: recommend **$99–129/yr
(≈$12.99/mo) for Oshun+**, annual-first paywall design, with the existing
one-time intro-offer and PPP machinery doing the regional work. The
`starter/plus/pro/scholar/institutional` class ladder should collapse to
at most **two consumer-visible names**; six classes are an internal
entitlement reality, not a paywall UI.

### 9.2 The wellness/medical claims boundary

Crisis handling, grief check-ins, and "recovery" language sit close to
regulated territory (FDA digital-therapeutics guidance, EU MDR
wellness-vs-medical boundaries, FTC health-claims enforcement). The
architecture is defensible; the *marketing* needs a claims-review gate so
no surface ever implies diagnosis or treatment. Separately, a long-term
**clinical-evidence track** (Headspace and Calm both run RCT programs) is
the credibility play that matches this product's trust posture — pursue it
as research, never as a launch claim.

### 9.3 Health-platform integration is table stakes and free trust

HealthKit/Health Connect **writes** (mindful minutes, sleep) cost little
and anchor Oshun in the user's existing health graph; **reads** (sleep,
HRV) feeding Tara's mood-to-recommendation engine are a differentiator —
but only behind an explicit Iris consent category with plain-language
disclosure. The watch companions already exist; this is the missing data
spine between them and Tara.

### 9.4 Assistant-first as a first-class front door

Post-ChatGPT, a large cohort starts every interaction with a question, not
a tile grid. The invocation registry and context-handoff machinery already
support the assistant as a full front door (deep-linking into domain
surfaces); instrument **assistant-first vs. tile-first cohort retention**
from day one and let the data decide the default home layout. This also
future-proofs against the OS-level assistant platforms (Siri/Gemini
intents) that will increasingly disintermediate app home screens.

### 9.5 Telegram as a growth channel — with a payments firewall

The bot + mini-app surfaces are a genuinely differentiated acquisition
channel (low CAC, strong ex-US reach, viral share mechanics native to the
platform). Two cautions: keep **all payments out of Telegram surfaces**
(the crypto rail inside Telegram invites both store-policy and regulatory
scrutiny), and treat Telegram identity as a lower-trust tier in Iris
(no crisis-sensitive memory on that surface).

### 9.6 Voice and content rights operations

Persona voices, TTS narration, and any cloned-voice features need
documented consent chains contract-side, not just registry-side — V3's
voice-cloning consent registry is the model; V1 personas should inherit it
wholesale before any voice marketing. Similarly, Veritas quoting/excerpt
policy and Nisaba corpus rights are **licensing budget lines**, not
engineering tasks; the first pass under-priced them.

### 9.7 Support and safety staffing as launch gates

The 5-minute crisis-queue first-response SLA is a payroll commitment
(24/7 coverage, crisis-trained staff, multiple languages at 8 locales).
Convert the SLA into a staffing plan with named coverage before GA — an
unstaffed crisis SLA is worse than none, because the architecture
*promises* the response.

### 9.8 Data portability as a visible feature

DSAR machinery exists; surface it as a one-tap "download your practice
history / journal / learning record" in settings. For a trust-branded
product, self-serve export is marketing, and it pre-empts the "walled
garden" critique the multi-domain breadth will otherwise attract.

### 9.9 Cross-portfolio brand architecture

One account spans nine products, which means one **reputational blast
radius**: an incident in a game property (V2 gore controversy, V7
moderation failure) lands on the wellness brand that handles users in
crisis. Consider a two-brand architecture — Oshun (wellness/knowledge:
V1, V3, V9) and a publisher label for the game line (V2, V4, V5, V7) —
sharing the account substrate but not the consumer-facing name. Also note
the synergy direction: V9 Metis is the natural premium driver *inside*
Oshun+ (its "Netflix for your mind" subscription and V1's tiers should be
one SKU, not two), and V3 is Tara's embodiment, not a separate purchase
decision.

## 10. Monorepo integration & shared functionality (third pass)

This pass audits V1 against the wider monorepo — the DOMAINS registry, the
185-phase TODOS/ roadmap, `V_SERIES.md`, and the (proposed, unstarted)
`V_SERIES_PLATFORM_CONSOLIDATION.md` — plus actual package-dependency
evidence.

### 10.1 V1 is the substrate hub in fact, not just in doctrine

Dependency evidence confirms the architecture: `apps/oshun/bff` is the
broadest substrate consumer in the repo (Sophia research/citations, Psyche
voice/dialogue, Themis disputes, ~18 `@yemaya/*` packages, and the
canonical `@oshun/*` adapters), and it is the **only** consumer of
`@oshun/generation-control-isis` and `@oshun/c2pa-export`. The "Isis is
the only path" promise is real precisely because the BFF is the only door.
This is the strongest layering story in the portfolio and should be
defended as such — every later product that bypasses the adapters weakens
V1's central guarantee.

### 10.2 The adapter family is forking — V1 should own the convergence

The canonical one-adapter-per-substrate intent (`libs/oshun/`:
evidence-sophia, memory-iris, embodiment-psyche, persona-policy-lilith,
generation-control-isis, payments-bridge) is already bypassed by the
younger products: V6 routes through parallel packages
(`@iris/agents-core`, `@oshun/psyche-agent`, `@oshun/isis-behavior-policy`,
`@oshun/isis-agent-gen`), and V8/V9 use their own gate/judge stacks. Only
V3 reuses the canonical adapters (memory-iris, persona-policy-lilith).
Two families for one substrate means two behaviors for one policy — the
exact drift the adapters exist to prevent. As substrate owner, V1 should
convene the reconciliation (one Isis entry point, one Psyche entry point)
before V6/V8/V9 ship against the forks.

### 10.3 Two provenance signers is one too many

The repo carries `@oshun/content-signing` (consumed by V3, V8, and Isis's
3D asset library) **and** `@oshun/c2pa-export` (consumed only by V1's
BFF), plus domain-local C2PA code in Euterpe/Isis/Themis/Yemaya/Calliope.
For the product whose G0 launch gate is C2PA SDK wiring (§4.5 first pass),
the fix and the consolidation are the same work: fold `c2pa-export` into
`content-signing`, make it the portfolio's single signer, and V1's
provenance badges inherit multi-product test coverage for free.

### 10.4 The standalone-app twins (Tara, Nyx, Veritas)

The roadmap ships Tara (Phase 22, App-Store-safe meditation with a
deliberately separate brand/user-base), Nyx (Phase 21), and Veritas
(Phase 23) as standalone apps — all marked 100% — while V1 ships the same
names as in-shell domains on shared libs. This is intentional dual
distribution, but it doubles content governance, review queues, and
support surfaces for three brands, and it can cannibalize Oshun+
conversion (why subscribe to the bundle if the standalone is enough?).
Recommend an explicit twin-strategy doc per pair: which surface leads in
each market, one content pipeline feeding both, and upgrade paths from
standalone → Oshun+ as the funnel design.

### 10.5 The account/entitlement graph is a V1 deliverable

`V_SERIES_PLATFORM_CONSOLIDATION.md` Problem 2 — one Oshun player account
with Profile, Entitlement, and Character/being graphs (V6 Ori as the
character store) — is unstarted (all checkboxes open) and is really a V1
platform work item, since V1 owns identity and billing. Cross-product
grants (V9's lesson unlocks, V2–V5 game entitlements, V6/V7 beings) all
route through it. Prioritizing this unblocks every sibling's bundle
mechanics and prevents each game shipping its own entitlement dialect —
the entitlement-class sprawl already visible inside V1 (§9.1) becomes
portfolio-wide sprawl otherwise.

### 10.6 The ML data flywheel needs V1's consent regime

Phases 85–96 (ML sovereignty) explicitly plan passive training-data
harvest from Isis, Psyche, Iris, Sophia, Hathor, Yemaya, Veritas, and
Metis — eight systems V1 users touch, several in intimate contexts
(assistant memory, contemplative sessions, learner records). V1's Iris
consent scopes and crisis-time write-suspension must be the flywheel's
gating layer *by contract*, not by convention: a training-data consent
category, surfaced in the privacy center, checked at harvest time. Done
right this is a differentiator ("your practice never trains models
without you"); done silently it is the scandal that ends the trust brand.

### 10.7 Roadmap assets V1 under-uses

- **Phase 97 (Skills System)** — unified cross-domain skill composition
  for Iris/Nous: the assistant's natural growth path beyond intent
  routing; V1's assistant roadmap should cite it rather than reinvent.
- **Phase 139 (sovereign office/scholarly/collab suite)** — overlaps
  Nisaba notebooks and study plans; reuse rather than parallel-build.
- **Phase 146 (sovereign identity provider)** — if pursued, V1 identity
  is its first tenant; align key architecture now to avoid a migration.
- **Concordia (Phase 179, ~complete)** — mediation/bargaining substrate
  suitable for V1's support-dispute and refund-appeal flows; currently
  uncited by V1 docs.

## 11. Closing note

V1's substrates — crisis safety, evidence governance, humane behavioral
mechanics, provenance-gated generation — are the strongest trust
infrastructure I've seen specified for a consumer AI product, and most of it
is real code with honest seams. The product wrapped around it is currently a
cathedral with six entrances and no nave. Give it the Thread, a sleep
vertical, human voices, and a checkout a meditator would actually use, and
Oshun V1 stops being an impressive architecture and becomes a habit — which
is, fittingly, the thing it teaches.
