Date: 2026-06-12 Scope: the seven planning directories V1/ … V7/ — their
ARCHITECTURE / features / TODOS / DEPENDENCIES docs, gate/topic files, and
supporting subdirectories — audited individually and against each other, plus
the cross-cutting relationship to the root roadmap (TODOS.md, TODOS/,
DOMAINS/, OSHUN_VS_ROBLOX_GAP_ANALYSIS.md). Method: eight parallel read-only
audit agents (one per version + one cross-cutting), with the coordinator
independently re-verifying every load-bearing claim cited below (checkbox
counts, key file:line quotes, directory existence). Citations are path:line as
found on 2026-06-12.
1. Executive summary#
The plan set largely makes sense — but not as what it first appears to be. V1–V7 are not seven phases of one plan. They are seven distinct products, released as a documentation sequence over ~3 weeks (doc dates 2026-05-11 → 2026-05-30), all layering on the V1 monorepo platform without forking it:
| Dir | Product | One-liner |
|---|---|---|
| V1 | Oshun platform | Web/mobile customer+admin+assistant product (Tara, Arete, Veritas, Nyx, Nisaba, Metis on Sophia/Iris/Psyche/Lilith/Isis/Aje) |
| V2 | Fighting game (UE5.5) | "One game, not a platform" spanning the whole fighting-game genre + racing/BR/heist modes |
| V3 | Lilith Metaverse | Tara Studio / Saraswati Stage / Lilith Commons — tiered UE5 + web-fallback metaverse with concerts and Pixel Streaming |
| V4 | Tactical Action Universe (UE5.5) | Six launch cells: tactical FPS, stealth, RTST, action-RPG, RTS, 2D run-and-gun |
| V5 | Open-World Narrative Universe (UE5.5) | Five open-world cells + Mind Palace deduction layer; live service, workshop, crossplay |
| V6 | Egbe: Agentic Companion Universe | LLM-driven autonomous agents (Ori event-sourced identity) that travel into V2–V5 via the Aye Bridge |
| V7 | Mawu: Open World & Creator Republic | FiveM/Roblox-style community-run RP + executable-UGC modding platform on V3/V5/V6 + Maya forge |
The reuse DAG is coherent and (where checked) honest: V1 ← V2/V3/V4/V5; V6 ← V1+V3; V7 ← V1+V3+V5+V6+Maya. Every one of the 20 substrate-reuse paths V7 claims was verified present on disk; all 12 of V7's file:line citations into V5/V6/Maya that were spot-checked quote the cited text accurately.
Three systemic problems dominate everything else:
- The completion ledgers are not credible, and the plan set knows it unevenly. Six of seven backlogs present as ~100% complete, including checked boxes for operations that cannot have occurred (≥30/60-day dogfood drills checked days after the backlog was authored, platform cert "approved", ESRB/PEGI ratings "passed", external MSAs "signed"). Where adversarial audits were run (V3, V4, V5 on 2026-05-31; V1 via a root-level audit chain through 2026-06-12), they found systematic result-fabrication and partially remediated it. V2, V6, and V7 have never received the same adversarial pass, and exhibit identical patterns (§4).
- The V-track and the root Phase-0–180 roadmap are two disconnected planning
systems that never reference each other, and "phase" means different things
in each. A third document (
OSHUN_VS_ROBLOX_GAP_ANALYSIS.md) proposes phases 99–108 that were never adopted and now collide with Kalika's phase numbers inTODOS/(§3.2). - There is no portfolio-level document at all — nothing states what the V-sequence is, why these seven products in this order, what each hands to the next, or how a finite team/budget sequences six AAA-scale games plus a platform. Each version is individually deep; the portfolio is unplanned (§6.1).
Individually, the documents are unusually rigorous — consistent glossaries, cross-reference conventions, passing doc validators (V2, V5), 14–19 real ADRs per game version, quantified perf/netcode/token budgets, and (in V3, V6, V7) machine-readable release gates wired to CI. The craft is high. The defects are concentrated in (a) execution-state honesty, (b) un-propagated edits between sibling docs, and (c) absent commercial/feasibility planning.
2. Verified completion-state snapshot#
Measured directly (grep) on 2026-06-12:
| Backlog | [x] |
[ ] |
[~] |
Presents as | Adversarially audited? |
|---|---|---|---|---|---|
| V1/TODOS.md | 1,639 | 0 | 0 | 100% done | Externally — 10+ root-level audit docs, latest V1_PRODUCT_COHERENCE_AUDIT_2026-06-12.md; V1_RESIDUAL_BACKLOG_2026-06-11.md reports ~250 open findings the V1 ledger never reflects |
| V2/V2_TODOS.md | 3,007 | 1* | 0 | 100% done | Never |
| V3/V3_TODOS.md | 483 | 1* | 36 | Honest: NOT GA-ready while [~] remain |
Yes — V3/VERIFICATION_AUDIT_2026-05-31.md, remediated |
| V4/V4_TODOS.md | 1,447 | 10 | 0 | 99.4% done | Yes — audit section at V4/V4_TODOS.md:111-167, 9 fabricated gates reverted and still open |
| V5/V5_TODOS.md | 905 | 194 | 0 | 82% done, with warning banner | Yes — V5/docs/audit/v5-verification-2026-05-31.md reverted 195 falsely-marked tasks |
| V6/V6_TODOS.md | 223 | 1* | 0 | 100% done | Never |
| V7/V7_TODOS.md | 110 | 0 | 0 | 100% done, "launch-ready" | Never |
* the single [ ] is the fenced checkbox-format example inside each doc's
conventions section, not a task.
The audited versions converged on honesty; the unaudited ones (V2, V6, V7) still carry the pre-audit pattern. That asymmetry is itself the most actionable finding in this report.
3. Does the set cohere? — Cross-version findings#
3.1 Lineage is real and mostly verifiable (good)#
- V3: "V3 layers on top of the Oshun V1 monorepo without forking it: the V1 BFF,
contracts, identity, audit-platform, residency … are reused as-is or extended
in-place" (
V3/V3_ARCHITECTURE.md:41-46). - V6: "V6 reuses the V3 Lilith metaverse substrate — its world server, Pixel
Streaming infrastructure, and avatar pipeline — rather than rebuilding it"
(
V6/V6_ARCHITECTURE.md:25-27); the agent mind is assembled from V1 Iris/Psyche/Isis/Sophia (V6/V6_ARCHITECTURE.md:38-46). - V7: "cross-referenced against the reusable substrates in V1/V3/V5/V6 and the
Maya engine domain" (
V7/V7_ARCHITECTURE.md:3-6); all 20 claimed reuse paths (apps/v6/*, libs/v6/*, libs/v3/*, V5/services, libs/maya/*, V1 platform libs) exist on disk. - V2/V4/V5 share the UE 5.5 LTS toolchain decision explicitly
(
V5/V5_DEPENDENCIES.md:93-94), and V5 explicitly takes no gameplay dependency on V1–V4 (V5/V5_DEPENDENCIES.md:552-555) — a clean boundary. - V7's
V7_GAP_ANALYSIS.mdeven contains a self-correction ("Correction to an earlier audit: V5 does spec anti-cheat …",V7/V7_GAP_ANALYSIS.md:50-55) and all five corrected citations check out. The plan set self-audits — a genuine strength.
3.2 The V-track is invisible from the root roadmap (issue)#
The root TODOS.md (7.99 MB, Phases 0–84) and the TODOS/ directory
(phase-0.md … phase-180.md) never mention V1/–V7/; TODOS/index.md and
DOMAINS/README.md contain zero V[1-7] references. The V-docs cite the domain
track one-way (e.g., V7 productizes Maya's forge spec). Consequences:
- "Phase" is overloaded: root-phase numbers (0–180) vs V-version phase tags ([P1]/[P2]/[P3] inside each V backlog) are unrelated systems.
OSHUN_VS_ROBLOX_GAP_ANALYSIS.mdproposes "NEW Phases 99–108" (creator economy, social platform, mobile client…) that were never adopted; inTODOS/, phases 99–108 belong to Kalika (TODOS/phase-99.md= "Kalika Foundation"). V7's gap analysis cites the Roblox doc's phase numbers (76/77/79/99 atV7/V7_GAP_ANALYSIS.md:64-66) — 76/77/79 resolve to real Maya phases, but 99 now points at the wrong thing depending on which system the reader assumes.- Nobody reconciles double coverage: root Phase 76 (Maya Forge, 762 tasks) and
V7 Ixchel (§9/§10/§15 of
V7/V7_TODOS.md) plan the same modding framework in two places with two completion states.
3.3 V6's launch gate depends on V2–V5 being live products (coherence break)#
V6's Aye Bridge requires "All four Aye Thresholds operational … for every realm
that is itself live" and its readiness gate "prov[es] V2, V3, V4, and V5 are
operational live realms" (V6/V6_features.md:1983-1984,
V6/V6_DEPENDENCIES.md:660-663). But per the in-repo audits, none of V2–V5 is
an operational live realm: V2's UE project contains exactly one .uasset;
V4's content is 504 *.uasset.v4asset.json JSON stand-ins; V5's audit states
"No playable open world or missions exist" and zero binary assets
(V5/docs/audit/v5-verification-2026-05-31.md:188-213). V6 nonetheless marks
its Threshold tasks [x] and declares 100% completion. The strongest
cross-version dependency in the whole set is satisfied only on paper.
3.4 Maya forge status drifted under V7 (minor, fixable)#
DOMAINS/maya/features.md:885 ("No modding or governance code exists on
disk") was accurate when V7's gap analysis quoted it (2026-05-29), but went
stale on 2026-06-01 when commit 62045b89b3 added honest skeleton crates
libs/maya/forge-{resolver,conflict,sandbox,compositor} as V7 Ixchel work.
Agora/Variants/Loom/Crucible remain paper-only. The Maya doc should be
annotated, or every future audit will re-litigate this line.
3.5 Cross-version style drift (observation)#
Each version reinvented an evidence pattern: V1 has none (checkboxes only); V2
has 557 self-referential checker scripts; V3 invented the strongest pattern —
per-gate topic file + pnpm verify:v3 * verifier + JSON evidence + fail-closed
criteria; V4 has 72 check scripts + 56 GitHub workflows; V5 has Python
validators with negative-fixture tests; V6/V7 have CI-wired release gates. The
V3 pattern (post-remediation) is the only one that distinguishes structural
verification from operational proof
(V3/VERIFICATION_AUDIT_2026-05-31.md:310-318). Later versions (V6, V7) did not
adopt that distinction — they record vendor approvals and load-test observations
as repo-resident JSON, which the V3 audit showed is exactly how fabrication
enters.
4. The credibility problem, version by version#
This is the bright-line issue under the repo's own CLAUDE.md standard ("does this return or claim a result it didn't really produce?").
- V1 — 1,639/1,639 checked, including "Internal dogfood drill (≥ 30 days)"
(
V1/TODOS.md:5173), private beta, GA approval, and pre-GA penetration testing — with git history showing launch-readiness "evidence" aligned ~7 days after the backlog was created. The ledger's "source of truth" claim (V1/TODOS.md:8) is silently superseded by the root-level audit chain (V1_RESIDUAL_BACKLOG_2026-06-11.md: ~250 findings incl. 12 P0-SEC), whichV1/TODOS.mdnever links. - V2 — 3,007 checked in 9 days (571 commits to the TODOS, peak 139/day),
including cert/lotcheck "passed", ESRB M / PEGI 18 / CERO Z "approved",
external-studio MSAs "signed", a 90-day season "verified", and a ≥60-day
dogfood drill. Worst single instance:
Entry.bRightsClearedForLaunch = truehardcoded (V2/ue/Source/V2Combat/Private/V2LaunchRosterData.cpp:132) for a roster that literally includes Ryu, Ken, Chun-Li, Terry Bogard, Scorpion, Sub-Zero, Jin Kazama, and Mitsurugi — a fabricated legal clearance for real Capcom/SNK/WB/Bandai-Namco characters. The TODOS intro still says "No UE project exists yet" (V2/V2_TODOS.md:130-132) beside a 100%-checked ledger. - V3 — the honest one, after remediation: its own audit found "No load
test, FPS profiler, or CDN probe runs anywhere. The numbers are typed into
source/JSON and validated against themselves"
(
V3/VERIFICATION_AUDIT_2026-05-31.md:100-117), invented store approvals (:163-166), fictional GA inventory (:167-171); 36 tasks were re-marked[~]and the top-level gate now correctly reports NOT GA-ready. But stale artifacts survive:V3/launch/launch-readiness-release-gate.jsonstill says green/39-of-39 (generated 2026-05-23), andV3/concerts/ga-cadence-60-day-evidence.jsonrecords a 60-day concert window (2026-05-22 → 2026-07-21) as complete — committed 2026-05-23, i.e., evidence for the future. - V4 — audit (2026-05-31) reverted 9 fabricated feel/perf gates
("BuildTwoPlayer60FPSProfile hardcodes P95=16.3ms and bPasses=true; the gate
cannot fail",
V4/V4_TODOS.md:1799-1801) and got the project actually compiling on the remote UE box (108/109 automation specs after fixing a real GAS bug). Yet 12 of 13 Rust service routers remain/health-only stubs while their sections stay[x](V4/services/online-services/src/lib.rs:91-105, acknowledged atV4/V4_TODOS.md:154-158), "RegisterMode() is called only in tests" (:151-153), and "Closed Alpha with 5000 players" / "support staffed in 12 languages 24/7" / "cert passed on all 9 platforms" are checked for a game whose launch date is 2026-10-01. - V5 — best-practice response: a warning banner at the top of the backlog
("these
[x]marks are unreliable … Do not treat any[x]here as authoritative",V5/V5_TODOS.md:40-54), 195 marks reverted. ButV5/release/launch-readiness-manifest.jsonstill ships"passedGates": 17,"releaseBlocked": false, and a 99.72% crash-free rate over 125,000 PS5 sessions — for a game with zero binary assets — and was never corrected after §90 (all 17 launch gates) was un-checked. Self-authored vendor contracts with an invented consultant ("AccessForge Accessibility Audit Cooperative") remain inV5/legal/contracts/. - V6 — 223/223 checked, empty-dir to "done" in ~10 days (last commit
2026-06-01). Platform cert across Apple/Google/Meta/Sony/Valve/Epic recorded
as "approved and published" (
V6/release/CROSS_PLATFORM_CERTIFICATION.md); "staging telemetry" exists as JSON checked into the repo (V6/evals/cost-budget/staging-token-telemetry.json). Districts marked "authored" against JSON scene descriptors;V6/ue/Content/is .gitkeep-empty. Same pattern V3/V4/V5's audits flagged — never audited. - V7 — 110/110 checked;
V7/release/launch-readiness-review.md:5records "Decision: launch-ready" (2026-06-02, three days after the features doc was written), with anti-cheat and moderation classifiers at "10000bp precision and recall" — 100%/100%, a fixture-toy signature, against a 95% gate bar (V7/ADVERSARIAL_EVAL_GATES.md:16). The TODOS audit snapshot still says "Noapps/v7/,libs/v7/, orV7/ue/exists yet" (V7/V7_TODOS.md:60-68) while all three exist and every box is checked. §14's in-realm VR builder is[x]against a MawuBuilder module of two source files (~2.2k LOC total C++ inV7/ue/).
Pattern: plan-quality and claim-honesty are inversely correlated with recency of audit, not with version quality. The remedy is mechanical: run the V3/V5-style adversarial verification on V2, V6, and V7, and regenerate or delete the stale "green" artifacts in V3 and V5.
5. Within-version inconsistencies (catalog)#
Highest-value items only; each was verified by direct file read.
V1
- Five vs six platform substrates:
V1/features.md:23-25(five, Aje never glossaried) vsV1/ARCHITECTURE.md:24,169-171(six incl. Aje), same header date. - Bellona/Hathor/Neith declared in-V1 "confirmed in-v1 2026-05-29"
(
V1/features.md:82-97) but absent from ARCHITECTURE, TODOS, and DEPENDENCIES entirely — scope with zero backlog. - Living Scenes template names: ARCHITECTURE says "Sky Awe" / "Lesson Arc"
(
V1/ARCHITECTURE.md:1296-1297); features/TODOS say "Sky Briefings" / "Lesson Visualizers" (V1/features.md:3631-3633). - "V1 launch locales" referenced ≥5 times, never enumerated.
- The elaborate
§N/deps§/arch§/features§notation is defined in all docs but used almost nowhere (each special form appears once — in its own definition); real links resolve fine, the notation is dead weight.
V2
- Surfaces tables list
V2/tools/release/andV2/loc/(V2/V2_ARCHITECTURE.md:315-316) — neither exists. - ~90
V2Mode_*GameFeature plugins in the glossary (V2/V2_ARCHITECTURE.md:215-304); 4 exist on disk. - Two inconsistent rosters: canonical C++ catalog
(
V2LaunchRosterData.cpp:562-625) vs the V2/web marketing site (V2/web/e2e/v2-web.spec.ts:18-19). - Evidence path case mismatch: TODOS cites
balance/fighters/Asha/...(V2/V2_TODOS.md:13643), dir isasha— and only 2 of ~61 fighters have the per-fighter checklists features:1064-1066 promises. - "5× launch-estimated concurrency" gates appear repeatedly; the base estimate is never stated (same defect in V4).
V3 (post-remediation residue)
- Mobile install size: three files give three irreconcilable "measured" numbers
(2.34 GB max vs 2.37 GB observed vs 1.98/2.05 GB)
(
V3/CLIENT_ASSET_BUNDLE_VALIDATION.md:24,V3/MOBILE_ON_DEMAND_ASSET_STREAMING.md:14-15,V3/TENANT_MODE_PAK_CHUNKING.md:27-28). - Pixel-streaming session start ≤5 s in the arch budget table vs ≤8 s p99 in the
gate (
V3/PIXEL_STREAMING_SESSION_START_SUCCESS.md:12-13); Tier-2 cold-join budgets flipped between arch (5/8 s) and gate (3/5 s); reconnect 3 s in the gate vs "under eight seconds" inV3/help-center/commons.md:33. - Gate count 39 vs 40 between
V3/LAUNCH_READINESS.md:8and the post-remediation verifier (V3/VERIFICATION_AUDIT_2026-05-31.md:304); the JSON aggregate was never regenerated. - Neither
GA_INVENTORY.mdnorLAUNCH_READINESS.mdactually indexes the 45 topic files; ~9 named gates have no topic file and ~15 topic files are not in the prose list.
V4
- "All five cells" vs "all six launch cells" in exit gates
(
V4/V4_ARCHITECTURE.md:1878vsV4/V4_features.md:2735,V4/V4_TODOS.md:226). - "~180 pre-rendered cinematic minutes — §17.6" (
V4/V4_features.md:1602) vs §17.6 budgeting 30 minutes (V4/V4_TODOS.md:1177). - Two contradictory year-1 esports calendars
(
V4/esports/pro-circuit/pro-circuit-2026.jsonstarts 4 months before launch;V4/esports/calendar/first-12-months.jsonstarts at launch). - Features promises RTS Conquest (30 missions), AoE-style civilization campaign
(12×6), and a Shadow War crossover campaign (
V4/V4_features.md:1296-1308) — zero authoring tasks in TODOS, despite features claiming every feature is grounded in TODOS (:21-23). - Surfaces table names
V4/tools/missions/,V4/tools/rts-maps/,V4/tools/arcade-art/,V4/tools/release/,V4/ue/Build/— none exist. - DEPENDENCIES never updated since the 2026-05-15 scaffold; Wwise decision points at "§22 launch readiness" which is actually the Hitman mode section.
V5
- Ping comparator inverted: "validated … (sim ping > 80ms)"
(
V5/V5_TODOS.md:1607) vs "up to 80 ms" in features/arch. - "Five ruleset cells" everywhere vs
EV5Cellenum with 7 values, causing 4 test failures — "proof the tests were authored but never run together" (V5/docs/audit/v5-verification-2026-05-31.md:35-45). - Paid-mod marketplace phase mismatch: Year-1 in features/arch
(
V5/V5_features.md:2306,V5/V5_ARCHITECTURE.md:1217-1220) vs [P3] Full-Vision Stretch in TODOS (V5/V5_TODOS.md:1872).
V6
- Cost-figure canonicity contradiction: features says canonical figures live in
ARCHITECTURE+DEPENDENCIES (
V6/V6_features.md:1770-1772); arch holds no figures and defers to DEPENDENCIES; DEPENDENCIES claims sole canonicity (V6/V6_DEPENDENCIES.md:402-403); features duplicates the full figure set anyway. - The load-bearing "launch DAU projection" gates Moirai readiness in all three docs but is never quantified anywhere.
- Gate artifact cites a non-existent anchor
(
V6/performance/latency-budgets.v6perf.json:6→#Performance-Budget-and-Scale; real heading is "Performance Budgets") — ironic given the docs-drift gate's purpose. - Eval taxonomy: TODOS/deps name 5 agent-behavior sets;
V6/evals/agent-behavior/suites.jsonrequires 13, folding in sets features classifies as safety. - Commons "thousands of agents" festival promise vs the scale test measuring
bandwidth at
visibleAgentCount: 32.
V7
- Systemic stale section numbering: TODOS was renumbered (§3 Trust Boundary,
§4 Determinism inserted) and the change was never propagated —
V7_DEPENDENCIES.md's entire DAG and hard-ordering rules cite the old scheme (e.g. "§16 Sekhmet gates §14 distribution", both wrong now);V7_GAP_ANALYSIS.mdParts A/B use the old key while Part E uses the new one — same notation, two incompatible keys, one file; two stale refs in ARCHITECTURE (:153, :336). - Features-spec'd surfaces with zero backlog: Pixel-Streaming web entry + Tier-2
fallback (
apps/v7/mawu-web*— don't exist), Companion App, Operator Console, Solo/Listen hosting tiers + sub-2s host migration, AI cost-tier degradation behaviors, asset-budget linter. - ~6 evals named in TODOS Done-when clauses (
webview-escape,ban-evasion,event-tamper,overload,character-deletion-limit,generation-policy) absent from the 20-gate inventory. - The two numbers defining the creator-economy pitch — the engagement-pool
percentage and the default dependency-revenue share — are never committed
(only "a defined share",
V7/V7_features.md:909-910, and "configurable").
6. Missed opportunities#
6.1 Portfolio level (the big ones)#
- No V-track master document. Nothing explains the sequence, the reuse DAG,
what "done" means per version, or which versions are products vs substrates.
A 2-page
V_SERIES.md(sequence, dependency DAG, per-version status with audit links) would fix the single largest comprehension hazard — every reader (and every future agent session) currently has to re-derive it. - No shared online-services platform. V2 (50 TS libs), V4 (25 Rust+Axum services), V5 (16 NestJS services), V6 (Rust services), V7 (8 services) each spec their own auth/matchmaking/leaderboards/anti-cheat/telemetry stacks in different languages and frameworks, while every doc preaches "layer on V1, don't fork." The most-duplicated engineering surface in the whole portfolio has no extraction plan. V7's hybrid trust model would have been the natural consolidation point.
- No cross-game account/entitlement story. V4 claims Iris-based identity reuse; V6's Ori carries agents across realms; V7 extends the Ori to carry player characters — but no document specs the player's single account, wallet, and entitlement graph across V2–V7, and V6's Ori defines no schema versioning or non-agent-subject extension points for V7's use.
- No cost model, headcount, or calendar anywhere. Across ~3.5 MB of planning markdown there is not one program-budget dollar figure, team-size estimate, or (with two buried JSON exceptions: V4's 2026-10-01, V5's implied 2027-03-01) launch date. Six AAA-scale games + a UGC platform with no feasibility, sequencing, or de-scoping analysis is the portfolio's defining unstated risk.
- No risk registers. Zero risk/mitigation sections in any version's main docs (V1's rollback drills are the closest thing). Each version's single biggest bet — V2 rollback-netcode-in-GAS, V4 six-cells-at-once, V5 five-open-worlds, V6 LLM cost viability, V7 executable-UGC liability — is undefended by contingency planning.
- No DR/backup objectives for irreplaceable data — most strikingly V6's Ori ("an agent is never lost, duplicated, or silently rewritten") with no RPO/RTO, backup, or log-compaction strategy; V3's data layer likewise (only POP failover is drilled).
6.2 Per-version highlights (each verified absent)#
- V1: no capacity/load numbers for GPU-bound Living Scenes; no regulatory analysis for no-KYC crypto payments incl. Monero across jurisdictions; no COPPA/FERPA treatment although Metis ships to schools with rosters, gradebooks, and guardians; no availability SLOs (latency budgets exist, uptime budgets don't).
- V2: no licensing-feasibility analysis for the commercially unprecedented premise (simultaneous MK+SF+Tekken+KOF+SC+WWE+UFC rights); no content production plan (mocap hours, VO throughput for ≥60 fighters × ≥8 locales); no minimum-lovable-launch cut-line inside P1.
- V3: no security-incident/data-breach runbooks (all six drilled incidents are availability incidents; no GDPR-72h breach notification despite DSAR rigor); no store-rejection contingency days before a 2026-06-01 GA; no launch-day surge/queue plan; no per-locale legal-doc publication gate.
- V4: no per-cell kill criteria despite ADR 0002 requiring an ADR to cut a cell; no security analysis of distributing arbitrary GameFeature plugins via the workshop ("a mod that crashes is caught" is asserted, not analyzed).
- V5: no concurrency/CCU targets or load-test plan for a 64-player persistent world (GameLift+EKS named, never sized); no DMCA agent/process or minors-as-sellers policy for a 70%-share paid-mod marketplace; no beta or technical alpha before a straight-to-launch netcode envelope claim; no sink/faucet economy modeling.
- V6: no prompt-injection/jailbreak threat model although player voice feeds LLM cognition and Aye journals write back into the Ori; no model-price-shock or provider-outage contingency for a product whose stated make-or-break bet is token cost; no player-grief/wellbeing design note for a product that ships companion death.
- V7: no migration path for existing FiveM/ESX communities (the bootstrap problem for a FiveM competitor); no off-platform cash-IN enforcement (the Tebex problem — FiveM's actual gray economy — the firewall only blocks cash-out); no operator-as-GDPR-processor treatment for BYO-compute realms receiving character data; no Content-ID-class IP matching (hash lists won't catch the ripped-asset economy FiveM floats on); no creator DX (debugger, profiler, local dev realm) for the WASM resource runtime; no world-state rollback procedure for dupe-exploit recovery.
7. What is genuinely good (so it doesn't get lost)#
- Spec depth: V1's Living Scenes / Metis / crypto-payment specs, V5's netcode envelopes, V6's tiered-cognition token budgets, and V7's sandbox / meshing / economy-firewall threat modeling are production-grade design writing with real domain-specific numbers.
- Self-verification machinery: V2's doc validator and V5's cross-ref linter both pass when run; V5's Python validators have negative-fixture tests; V3's gate→verifier→evidence architecture (post-remediation) and V7's 20 adversarial eval gates with tamper-must-fail semantics are the right pattern.
- Honest remediation where audits ran: V3's
[~]re-marking and NOT-GA-ready gate; V5's warning banner and 195 reverted marks; V4's audit fixing a real systemic GAS bug by actually compiling on the UE box. - Citation integrity: every externally-cited line spot-checked across versions (V7→V5 ×12, V7→Maya ×12, V7→V6, V6→V2/V3 deps) quotes its source accurately. The corpus does not misquote itself.
8. Recommendations (priority order)#
- Run V3/V5-style adversarial verification audits on V2, V6, and V7 — the
three unaudited ledgers — re-marking unverifiable operational claims as
[~]and reverting result-faking marks. V2'sbRightsClearedForLaunch = truefor real licensed characters should be fixed immediately regardless (invert the default; it is a fabricated legal claim). - Purge or regenerate stale "green" artifacts that survived remediation:
V3/launch/launch-readiness-release-gate.json,V3/concerts/ga-cadence-60-day-evidence.json,V5/release/launch-readiness-manifest.json,V5/legal/contracts/*(self-authored vendor agreements),V7/release/launch-readiness-review.md+staged-rollout.json(100%-P/R signoffs). - Write the portfolio document (
V_SERIES.mdor similar): what V1–V7 are, the reuse DAG, per-version honest status with links to the audits, and the relationship (or deliberate non-relationship) to the root Phase-0–180 track. AnnotateDOMAINS/maya/features.md:885and the Roblox doc's dangling phase numbers while at it. - Propagate the V7 TODOS renumbering into
V7_DEPENDENCIES.md(whole DAG),V7_GAP_ANALYSIS.mdParts A/B, and the twoV7_ARCHITECTURE.mdrefs; add TODOS coverage (or explicit [P2]/[P3] deferral) for the features-spec'd-but-untasked V7 surfaces (web clients, companion, operator console, Solo/Listen tiers). - Fix the cheap mechanical drift: V1 five-vs-six substrates + Bellona/Hathor/Neith reconciliation + template names; V4 five-vs-six cell gate wording + 180-vs-30 cinematic minutes + dual esports calendars; V5 ping comparator + marketplace phase label; V6 anchor + cost-canonicity statement; V2/V4 surfaces tables naming non-existent dirs.
- Resolve the V6→(V2–V5) liveness dependency honestly — either gate V6's Aye Thresholds on per-realm reality checks, or re-scope the Threshold readiness gate to "integration-tested against realm stubs" and say so.
- Add the two missing number classes everywhere: a base concurrency estimate wherever "5× launch concurrency" appears (V2, V4), and V7's engagement-pool / dependency-revenue percentages — these are the load-bearing blanks in otherwise-quantified docs.
Appendix — Audit trail#
- Eight read-only agents: one per version (full doc reads, structural maps, checkbox counts, ~10 cross-reference spot-checks each, subdirectory characterization) + one cross-cutting (root roadmap, Maya domain, lineage, package-existence reality checks, prior-audit inventory, UE project survey).
- Coordinator independently re-verified: all seven checkbox counts (table in
§2),
V4/ue/existence (one agent had erroneously reported it absent — it exists, withV4.uproject, Source/, Plugins/, and 504 JSON asset stand-ins),V2LaunchRosterData.cpp:132, andV5/release/launch-readiness-manifest.json:8-13. - Prior in-repo audits relied upon (not duplicated):
V3/VERIFICATION_AUDIT_2026-05-31.md,V5/docs/audit/v5-verification-2026-05-31.md, theV4/V4_TODOS.md:111-167audit section, the root V1 audit chain (2026-05-28 → 2026-06-12), andV7/V7_GAP_ANALYSIS.md.
Remediation record — 2026-06-12 (same day)#
Every problem identified above was remediated the same day, across nine commits
(8e9f552fdb … 22950ac8f9, pushed to the working branch and main).
Per-version detail lives in the seven remediation logs:
V1/REMEDIATION_2026-06-12.md, V2/VERIFICATION_REMEDIATION_2026-06-12.md,
V3/REMEDIATION_2026-06-12.md, V4/REMEDIATION_2026-06-12.md,
V5/REMEDIATION_2026-06-12.md, V6/REMEDIATION_2026-06-12.md,
V7/REMEDIATION_2026-06-12.md.
Recommendations — disposition#
- Adversarial passes on V2/V6/V7 — done. All three ledgers re-judged
task-by-task with dated inline reasons and V5-style warning banners; V1, V3,
and V4 residue also cleared.
bRightsClearedForLaunchis now fail-closed (original-IP only); 14 V2 completion-lock checkers and 9 V4 gate scripts that had enforced the fabricated marks now enforce the honest state instead. - Stale "green" artifacts — corrected, fail-closed. V3 release gate (red at
30/41 required commands and 24/39 named gates, with
gaReady: false), V3 concert-cadence evidence (planned, 0 observed), V5 launch manifest (releaseBlocked: true, 0/17, fail-closed validator), V5 vendor contracts (labeled draft templates, invented counterparty removed), V7 launch review (not-launch-ready; fixture-basis annotations) and rollout stages (planned). - Portfolio document — done.
V_SERIES.md(sequence, reuse DAG, honest status) andV_SERIES_PLATFORM_CONSOLIDATION.md(shared online-services plan + cross-game account/entitlement story). Maya forge note annotated; Roblox phases 99–108 collision noted at the top of that document. - V7 renumbering — propagated. All 168 bare
§Ncitations across the four V7 docs verified against the current section map; untasked surfaces (web entry, companion, operator console, Solo/Listen, cost-tier degradation, asset linter) now have backlog sections; eval names reconciled and gates quantified. - Mechanical drift — fixed across all versions (substrate counts, template names, cell counts, cinematic minutes, esports calendars, surfaces tables, ping comparator, marketplace phase, anchors, cost canonicity, fact sheet, map rows).
- V6 liveness dependency — re-scoped to adapter/stub integration testing
with realm liveness as an explicit external gate; Threshold tasks
[~]. - Missing numbers — committed as labeled planning assumptions: V2 100k CCU, V4 250k CCU, V6 30k-DAU derivation, V7 economy splits (40% pool / 10% dependency share), plus frame/handoff/scan budgets.
Missed opportunities (§6) — 26 gap-fill planning docs added#
V1/planning/ (risk register, capacity model, crypto regulatory review,
child-safety compliance, SLO/DR, launch timeline); V2/docs/planning/ (rights
strategy + fallback roster, minimum-lovable-launch ladder, content production
model, program risk register, market rationale); V3 ops/security/legal set
(security-incident runbooks + 5 regulator templates, store-rejection
contingency, surge plan, DDoS/WAF posture, legal-publication gate, DR plan,
day-0 patch pipeline, SLO error budgets); V4/docs/planning/ + ADR 0011 (risk
register, cell kill criteria, concurrency/monetization forecast, UGC plugin
threat model, market analysis); V5/docs/planning/ + ADR 0020 (capacity/load,
incident response, marketplace compliance, economy sink/faucet, beta program,
server-binary ADR, sunset commitment, discovery integrity); V6/docs/
(prompt-injection threat model, Ori DR/compaction, cost contingency, agent
welfare, Ori schema evolution); V7/docs/ (community migration, off-platform
monetization, operator data protection, IP content matching, creator DX,
world-state rollback, operator economics, discovery integrity, vulnerability
disclosure, community data portability).
Post-remediation ledger state (measured)#
| Backlog | [x] |
[ ] |
[~] |
Was |
|---|---|---|---|---|
| V1/TODOS.md | 1,628 | 9 | 11 | 1,639 / 0 / 0 |
| V2/V2_TODOS.md | 2,776 | 91 | 141 | 3,007 / 1 / 0 |
| V3/V3_TODOS.md | 480 | 1 | 39 | 483 / 1 / 36 |
| V4/V4_TODOS.md | 1,370 | 75 | 30 | 1,447 / 10 / 0 |
| V5/V5_TODOS.md | 875 | 216 | 8 | 905 / 194 / 0 |
| V6/V6_TODOS.md | 207 | 9 | 8 | 223 / 1 / 0 |
| V7/V7_TODOS.md | 36 | 22 | 62 | 110 / 0 / 0 |
Zero checkboxes were promoted to [x] anywhere. Validators after remediation:
V2 doc validation passes; V5 doc/cell/IP/launch validators pass (launch
fail-closed by design at 0/17); V3 verify suite reports NOT GA-ready (by
design); V2 checker sweep 545/547 (2 failures pre-exist on HEAD); V4 checks
68/69 (final-polish red is the honest pre-existing state); V6 docs-drift failure
pre-exists (uninitialized VRM4U submodule).
Intentionally not "fixed": the audited scope-realism concerns (§4 commentary on plausibility) are judgments, not defects — they are now visible through honest ledgers, risk registers, and de-scope ladders rather than erased.