# Project export: Time Sovereignty

This document was generated by HackStack to give an AI agent context about a hackathon project. Sections are labeled with their provenance; content marked as truncated was cut to keep this document small.

## Project metadata

- Hackathon: OpenAI Build Week
- Tagline: An AI Chief of Staff that helps one meaningful goal survive real life.
- Devpost: https://devpost.com/software/chief-of-staff-sm5evr
- GitHub: https://github.com/rainingsnow0914tw-ship-it/time-sovereignty-2026
- Demo: https://live-mobile---time-sovereignty-defqnamrrq-de.a.run.app/demo
- Video: https://www.youtube.com/embed/d0cX1V4R7h4?enablejsapi=1&hl=en_US&rel=0&start=&version=3&wmode=transparent
- Team: 1 GitHub contributor(s) — Chloe (46 commits)

## Devpost submission (written by the team)

### Overview

An AI Chief of Staff that helps one meaningful goal survive contact with real life.

### Inspiration

Most productivity tools are excellent at the first moment: they create a plan, divide it into tasks, and schedule reminders. The harder moment comes later. What happens when the action is delayed, the method is blocked, the user’s energy changes, or the original commitment no longer fits reality? A static planner usually repeats the same instruction. A general chatbot can discuss the problem, but it may not remember the commitment, notice a pattern, preserve the exact resume point, or return at the agreed time. Time Sovereignty was built for that gap. Its clearest acceptance was unexpectedly small. A user had bought drawing supplies but had not started drawing. She accepted a twenty-minute cup-sketch commitment. A real scheduled check-in returned on her phone, accepted a temporary photo and self-assessment, and GPT-5.6 recognized visible cup structure and the continuous-line approach without pretending to judge more than the evidence showed. She finished a drawing. That small change in real behavior became the product’s reason to exist: not another system that produces plans, but an AI Chief of Staff that stays with the goal when reality changes.

### What it does

Time Sovereignty begins with three natural questions: What do you want? When do you want it? Why does it matter? A real GPT-5.6 Goal Architect turns those answers into a specific proposal: the North Star, target window, first milestone, best next action, minimum version for a difficult day, completion criteria, and an appropriate rhythm such as a short sprint, finite project, or ongoing habit. The proposal is not a permanent command. The user reviews it and approves a support agreement covering: check-in rhythm and quiet hours; preferred tone and intervention style; text, photo, and voice progress formats; conditions that should pause support; when firmer follow-up is allowed; what kind of feedback is actually useful. When the action period begins, Cloud Tasks schedules a real follow-up. The private mobile lane can bring that follow-up back through the PWA and, in the final-day V2 branch, through a paired Android channel with FCM escalation and a full-screen incoming check-in. The user can report progress with text, voice transcription, or an ephemeral photo. The system then routes only the Agents the situation requires: Chief of Staff classifies the evidence and chooses the smallest useful response. Goal Architect creates or meaningfully revises the plan. Commitment Recovery joins when the user is blocked, repeatedly delayed, or facing a genuine change in direction. Memory Curator runs after the visible response so memory processing does not add unnecessary mobile latency. Possible outcomes include continuing, reducing the action, rescheduling, recalibrating, retiring a completed goal, or pausing with mercy when the user is sick or handling an emergency. The user sees the structured decision before it is persisted. After confirmation, the system saves an immutable Episode, safe Agent traces, the operational resume point, an appropriately limited memory proposal, and any justified next follow-up. It is a loop, not a one-time answer The core workflow is: goal and consent → scheduled action → real-world evidence → structured judgment → user confirmation → Episode and memory → next intervention Memory is deliberately layered instead of becoming an uncontrolled chat transcript. Immutable Episodes record what happened. Derived summaries are separated into user-level and goal-level memory so one goal cannot contaminate another. Temporary physical or emotional conditions require expiry or later rechecking. One success can create only a tentative Strategy Card; it does not become a permanent claim about the user. In the real two-check-in memory acceptance, a later Chief of Staff call retrieved exactly one relevant Strategy Card, received an explicit LIMITED_EVIDENCE instruction, changed its intervention accordingly, and updated confidence from 0.35 to 0.47 after a later success while preserving tentative status. This is also a Progress Witness and Self-Belief Loop. Recognition is evidence-specific: the assistant explains what visibly worked, asks an optional reflection question when useful, and records the result without manufacturing confidence or generic praise. One product, two proof surfaces Time Sovereignty separates the public evaluator experience from the owner’s private live lane. The original under-three-minute V1 submission video remains the main competition video and truthfully shows the original submission state. The final-day V2 supplemental video documents the protected Android follow-up work completed afterward. Its incoming-call screen is explicitly shown as a native UI replay. That replay demonstrates the interface, choices, stop path, and ring limit; it is not presented as proof that the particular displayed frame was delivered by the cloud. The real cloud-to-phone path is supported separately by redacted server timestamps, physical-device acceptance notes, and protected persistence evidence in the V2 branch. The public Demo Lab is safe for judges to open without an account, credential, API key, or rebuild. The private lane remains owner-only by design. The final day: closing the loop with a real person The final-day V2 work focused on defects found by using the product on a physical phone instead of continuing to polish a script. Voice became an action layer The voice experience previously transcribed the user and read text back. It now supports interruption, retains the relevant conversation context, and merges revisions by meaning. For example, “make it once instead of five” changes the amount, while “do it in ten minutes” changes the timing. Those are two dimensions of one commitment, not two separate commitments. Amount and timing replace prior values; changed circumstances accumulate. When the meaning is genuinely ambiguous, the model must ask instead of guessing. The voice layer is intentionally decisive. An earlier conversational version kept offering alternatives and asking how each one felt. Physical testing showed that this could turn the assistant into another comfortable place to keep deliberating. Time Sovereignty therefore optimizes ordinary intervention calls for a short concrete close: one viable action, a clear confirmation, then go do it. Explanations can still be complete when the user asks for them. It can address a real knowledge gap When a spoken question depends on external or current facts, the voice layer can invoke a bounded look_up tool. The result names sources and describes weak or conflicting evidence honestly. Search is opt-in and capped at two calls per spoken session. It is not used to search for the user’s own goal, history, or personal memory; the product already owns that state. Research results also remain separate from personal memory. It knows the limits of its hands Earlier plans sometimes told the user to set several phone alarms or maintain a repetition counter, even though those interfaces did not exist. The planning boundary now states both what the product can do and what it must not promise. The app can schedule and return its own check-in, escalate through the private Android channel, and process a response. It must not claim that it created phone alarms, calendar entries, or unsupported counters. The “next action” must be the physical action the user performs, not administrative work the assistant should have handled. Failures now explain themselves A goal whose end date had passed could not create another follow-up. The backend rejected the request correctly, but the mobile button appeared to do nothing. That reason now reaches the user in plain language instead of becoming a silent failure. Redacted, test-accelerated physical acceptance On 2026-07-21, Chloe completed a controlled physical acceptance with a real phone and a real glass of water. To finish the full escalation path within the judging window, the private Cloud Run revision used CATCH_V2_TEST_ESCALATION_SECONDS=15. This was an explicit test acceleration, not the intended production cadence. The design cadence is measured in minutes; the fifteen-second override must be removed before ordinary post-competition use. The redacted server timeline was: The final persisted state was CONFIRMED, with memory disposition DEFER, completed curation, no recorded error, and two safe Agent traces. The user drank the water. The assistant recognized the completed action, stored limited evidence, and moved on instead of continuing to nag. This acceptance was physical and end to end, but the public evidence is intentionally redacted. It does not expose the device credential, FCM token, API key, raw private reply, prompt, photo, or private reasoning. How GPT-5.6 is used GPT-5.6 is the structured decision brain of the live product. The backend requests gpt-5.6 through the OpenAI Responses API with strict Zod schemas, store: false, and zero automatic SDK retries. Recorded live calls returned gpt-5.6-sol. GPT-5.6 creates goal plans, classifies progress evidence, determines when Recovery is necessary, proposes adapted commitments, produces bounded memory observations, and returns decisions the application can validate before persistence. gpt-realtime-2.1 has a narrower role. It is activated only when the user starts the live voice experience. It provides the interruptible spoken conversation and transcription layer. It is not invoked for every application request, and it does not replace GPT-5.6 as the structured decision boundary. Developer mode exposes safe operational evidence such as provider, returned model, schema status, token usage, trace identifiers, record identifiers, and deployment revision. It excludes raw prompts, private reasoning, secrets, media, and raw user replies.

### How we built it

The mobile-first application uses Next.js, React, TypeScript, Zod, and Vitest. The live backend runs on Google Cloud Run in asia-east1. Cloud Tasks signs callbacks with Google OIDC. Firestore transactions store sessions, check-ins, leases, immutable Episodes, derived memory, and safe traces. Secret Manager supplies the OpenAI key only to the dedicated runtime identity. The Android V2 channel uses protected one-time pairing, Android Keystore storage, FCM data messages, bounded notification escalation, and a visible permanent stop control. Incoming sound and vibration have a hard thirty-second limit, and reopening or leaving the native app stops app-owned alerts. Idempotency is enforced through deterministic task names, one queue attempt, transactional leases, reply identities, completed receipts, and a separate memory-curation lease. Cloud Run is capped during judging, and the OpenAI SDK performs no automatic retries. How the development tools were used Codex was the primary engineering environment from the clean repository through the core agent architecture, state machines, provider contracts, PWA, Cloud Run and Cloud Tasks path, Firestore schemas, protected Android channel, deployments, tests, and evidence chain. Chloe supplied the product intent, performed physical acceptance, and repeatedly challenged assumptions when the interface or AI behavior did not make human sense. When the primary Codex quota was exhausted on the final day, Claude Code continued from a documented handoff rather than recreating the project from conversation memory. It repaired defects found during live use, added the conversation-summary and bounded lookup paths, tightened capability and voice boundaries, and recorded the final physical acceptance. The handoff and resulting commits are preserved in the repository. This distinction is deliberate and documented: Codex was the primary build environment; Claude Code performed a bounded final-day continuation; GPT-5.6 and, only when voice was invoked, gpt-realtime-2.1 are the product’s runtime models. Challenges A polished mock can hide a broken loop. Physical testing found stale installed-PWA code, ignored replies, an expired-goal silent failure, a return-to-PWA navigation defect, and a client schema that allowed fewer safe traces than the server could validly return. Cloud acceptance is not phone acceptance. An FCM provider receipt was never treated as proof of visible ringing or full-screen Android behavior. Device UI outcomes were checked separately. Memory can overgeneralize. Episodes, user memory, goal memory, confidence, effectiveness, expiry, and user confirmation had to remain separate. A persuasive assistant can become manipulative. Quiet hours, pause conditions, bounded escalation, a permanent stop path, and explicit consent are part of the product contract. Voice can become another form of procrastination. The interaction was shortened around a concrete commitment instead of optimized for engagement. Retries can multiply both cost and side effects. Queue and SDK retries, Firestore leases, task naming, and read-after-write recovery had to be designed together. Accomplishments A real phone journey turned unused drawing supplies into a completed cup sketch. A later real check-in retrieved limited memory and updated its effectiveness without promoting it to permanent truth. A protected Android lane reached a physical phone with bounded sound, vibration, full-screen choices, and an always-visible stop path. A redacted final-day run connected Cloud Tasks, Realtime voice, Android response, GPT-5.6 decision, user confirmation, Episode persistence, memory, and follow-up state. Four strict structured Agent contracts maintain mock/live parity. The original V1 submission checkpoint passed 125 routine tests with 9 deliberate live-only tests skipped. The final-day V2 branch passed 215 tests with 10 deliberate live-only tests skipped, plus TypeScript, ESLint, production build, Android build, and targeted physical acceptance. The public Demo Lab provides a one-click evaluator story while making zero OpenAI API calls and reading no private state.

### What we learned

Longitudinal AI is a systems problem before it is a prompting problem. The useful unit is not one impressive answer. It is a trustworthy loop across consent, state, time, evidence, recovery, memory, cost, and the next real action. We also learned that recognition is functional. Specific, truthful feedback can help the user believe the next action is possible. But memory must earn confidence through repeated outcomes, not convert one success into a permanent personality claim. Finally, “finding the user” is valuable only when the assistant also knows when to stop. Reachability without consent is surveillance; persistence without an exit is coercion. The product needs both hands: enough presence to protect the commitment, and enough restraint to return control immediately. Try it Open the public Demo Lab: Read the explicit scripted and zero-API boundary. Run the full thirty-day story. Open Journey to inspect delay, recovery, progress, memory, and recalibration. Open Developer to inspect the schema-validated mock traces. Then watch: Original V1 submission video Final-day V2 supplemental video Public MIT repository Final-day V2 source branch The owner-only live lane is intentionally not exposed as a public guest account. Judges do not need a credential or API key to inspect the public proof.

### What's next

The immediate post-submission release task is to remove the fifteen-second escalation override and restore a humane production cadence. After the judging snapshot is preserved, the original public branch and private V2 branch can be integrated carefully into one later product line. Longer real-world pilots can then measure which interventions genuinely help different users continue, which memories remain useful, and when an assistant should reduce, recalibrate, pause, or disappear. Future adapters may include wearables, smart speakers, calendars, and richer research support—but only behind the same consent, trace, memory, and stop boundaries.

## README (from the GitHub repository)

# Time Sovereignty

**An AI Chief of Staff that protects a meaningful goal when real life interrupts.**

Built with Codex for OpenAI Build Week 2026. GPT-5.6 is the product's
structured decision brain—not a decorative chat box.

- **Public 30-day Demo Lab:**
  https://live-mobile---time-sovereignty-defqnamrrq-de.a.run.app/demo
- **Under-three-minute submission video:**
  https://youtu.be/d0cX1V4R7h4
- **Final-day V2 supplemental video (56 seconds):**
  https://youtu.be/XPdfnJ6klu0
- **Final-day V2 source and evidence snapshot:**
  https://github.com/rainingsnow0914tw-ship-it/time-sovereignty-2026/tree/codex/v2-private
- **Stable app:** https://time-sovereignty-defqnamrrq-de.a.run.app
- **Source:** https://github.com/rainingsnow0914tw-ship-it/time-sovereignty-2026
- **License:** [MIT](LICENSE)
- **Primary Codex `/feedback` Session ID:**
  `019f6085-1e4d-7e23-a0b8-371e6e47bbfa`

> `main` preserves the original V1 submission shown in the primary video. The
> labelled `codex/v2-private` branch documents the protected Android follow-up
> completed on the final day without replacing the accepted V1 baseline.

## Why this exists

Most productivity tools are good at making the first plan. They are much less
useful when the action is delayed, the method is blocked, the user's energy
changes, or the original goal no longer fits reality.

Time Sovereignty treats those moments as information instead of failure. It
keeps the North Star, current commitment, consent boundaries, progress
evidence, learned strategies, and exact resume point connected over time.

The clearest real-world acceptance was unexpectedly simple: a user who had
bought art supplies but had not started drawing accepted a 20-minute cup-sketch
commitment. The physical Android PWA brought the check-in back, accepted a real
photo and self-assessment, and GPT-5.6 recognized the visible cup structure and
the user's continuous-line approach. The user finished a drawing. The photo was
an ephemeral model input and was not stored.

## What works

- Three-question onboarding with a real GPT-5.6 Goal Architect.
- Goal-led cadence: short sprint, finite project, or ongoing habit—never a
  forced thirty-day plan.
- Editable support agreement covering quiet hours, tone, channels, pause
  conditions, progress formats, and consent for firmer follow-up.
- Real Cloud Tasks check-ins with Google OIDC, open-PWA polling, text, photo,
  voice transcription, standard TTS, and user-started Realtime voice.
- Need-based Agent routing: Chief of Staff, Goal Architect, Commitment
  Recovery, and post-response Memory Curator.
- Immutable Episodes plus user-scoped and goal-scoped derived memory.
- A Progress Witness and Self-Belief Loop that gives evidence-specific
  recognition without turning one success into a permanent claim about the
  user.
- Safe Developer traces with provider, returned model, schema, token usage,
  record IDs, and revision—never raw prompts, media, secrets, or private
  reasoning.
- A separate, public `/demo` that compresses a clearly scripted thirty-day
  illustration story without calling any API or reading the private session.

## Real product vs. scripted proof

| Surface | Purpose | Provider and data boundary |
| --- | --- | --- |
| Private Android journey | Real onboarding, scheduled check-in, photo/voice/text reply, GPT-5.6 decision, confirmation, memory, and follow-up | Real Cloud Run, Cloud Tasks, Firestore, GPT-5.6; one paired device; server-side key |
| Public `/demo` | Show the longitudinal Day 1→30 story in under two minutes | Browser-only scripted fixtures; every trace says `mock`; no `/api/*`, Firestore, key, or private data |
| Routine tests | Fast, deterministic contract development | Mock provider behind the same strict Zod schemas |
| Recorded evidence | Prove finalized live contracts and cloud behavior | A small number of deliberate real calls, zero SDK retries |

This separation is deliberate. The competition story is fast to inspect, while
the real user path remains private and cannot expose Chloe's phone session or
the project API key.

## Architecture

```mermaid
flowchart LR
    USER["One paired phone"] --> PWA["Next.js PWA\nGoal · Check-in · Progress · Developer"]
    PWA --> RUN["Cloud Run · asia-east1\nmin/max 1 · concurrency 1"]
    RUN --> TASKS["Cloud Tasks\nOIDC · 1/sec · 1 concurrent · 1 attempt"]
    TASKS --> RUN
    RUN <--> DB["Firestore\ncheck-ins · Episodes · layered memory · safe traces"]
    RUN --> SECRETS["Secret Manager\nOpenAI key · pairing · session signing"]
    RUN <--> GPT["Responses API · GPT-5.6\nstrict Zod · store false · retries 0"]
    PWA <--> VOICE["gpt-realtime-2.1\nuser-started ears and voice"]
    DEMO["Public Demo Lab\nscripted · browser-only · no API"] -. "same local schemas" .-> PWA
```

The action state machine and intervention state machine remain independent.
Idempotency is enforced at task name, reply ID, transactional lease, completed
receipt, and curation lease boundaries.

## How GPT-5.6 is used

The application requests `gpt-5.6` through the official Responses API. The
provider returned `gpt-5.6-sol` in the recorded live runs.

1. **Goal Architect** turns three natural answers into a specific goal plan and
   defensible cadence.
2. **Chief of Staff** reads current evidence and relevant limited memory, then
   selects the smallest useful Agent path and returns one structured decision.
3. **Commitment Recovery** joins only when a report is blocked, repeatedly
   delayed, or directionally changed.
4. **Memory Curator** runs after the user-facing decision so curation does not
   add mobile latency. It may create a tentative Strategy Card; durable user
   conclusions still require an explicit user choice.

The required two-check-in memory acceptance used two Chief calls and two
post-response Curator calls, 5,447 tokens total, with zero SDK retries. The
second check-in retrieved exactly one relevant Strategy Card, treated it as
limited evidence, and updated confidence from 0.35 to 0.47 after one later
success while preserving `TENTATIVE` status.

`gpt-realtime-2.1` is a separate, user-started ears/mouth layer. It transcribes
and speaks; GPT-5.6 remains the structured decision brain.

## How Codex built it

Codex was the primary engineering environment from clean repository to real
phone acceptance. Chloe supplied the product intent and challenged assumptions;
Codex implemented, deployed, tested, and maintained the evidence chain.

Codex accelerated the project by:

- translating the PRD and architecture into strict domain schemas, two state
  machines, four Agent contracts, and mock/live provider parity;
- creating dated decision records before large scope changes and a lightweight
  `AGENTS.md` + `docs/PROJECT_STATE.md` handoff system for long-session safety;
- provisioning and inspecting Cloud Run, Firestore, Cloud Tasks, IAM/OIDC,
  Secret Manager, budgets, and tag-only preview revisions through GCP CLI;
- driving physical Android acceptance through ADB while keeping human judgment
  for audio quality, photo meaning, and product experience;
- finding production-only defects that local happy paths missed: Firestore REST
  serialization, swallowed PowerShell JSON, missing standalone task protos,
  a three-trace client bound, Realtime token cutoff, stale installed-PWA code,
  completed-journey dead-end, and server/phone hydration timezone mismatch;
- recording every real model call, token count, revision, test result, failure,
  and repair instead of presenting the final code as a one-prompt artifact.

The chronological proof is in [the Codex build log](docs/CODEX_BUILD_LOG.md),
[decisions](docs/decisions/), and [evidence](docs/evidence/).

## Safety, privacy, and cost controls

- The OpenAI key exists only in ignored local configuration and Cloud Secret
  Manager. It never reaches JavaScript, the PWA, a URL, or the repository.
- Private access uses a signed HttpOnly/Secure/SameSite=Strict cookie, exact
  origin allowlist, single-device 

[README truncated for size]

## Detected evidence (automated analysis)

Indexed codebase: 165 recognized source files, 840 KB.
- CSS (language) — detected in the code
- Next.js (technology) — detected in the code
- OpenAI (technology) — detected in the code
- React (technology) — detected in the code
- Tailwind CSS (technology) — detected in the code
- TypeScript (language) — detected in the code
- AI coding agent: Codex — evidence: config files committed to the repository

## Codebase structure (from repository index)

### Files (120 of 189)

```
.dockerignore
.env.example
.gcloudignore
.gitignore
AGENTS.md
Dockerfile
docs/CODEX_BUILD_LOG.md
docs/codex-handoffs.md
docs/decisions/0001-repository-foundation.md
docs/decisions/0002-approved-architecture-and-phase-order.md
docs/decisions/0003-time-pressure-feature-cut-order.md
docs/decisions/0004-reference-assets-cost-and-deployment-guardrails.md
docs/decisions/0005-gcp-project-and-region.md
docs/decisions/0006-phase-3-runtime-identities-and-callback-idempotency.md
docs/decisions/0007-live-contract-validation-perimeter.md
docs/decisions/0008-time-pressure-integrated-build-and-ui-cuts.md
docs/decisions/0009-cloud-live-activation-and-cost-profile.md
docs/decisions/0010-judging-readiness-min-instance-and-accessibility.md
docs/decisions/0011-single-device-live-check-in-preview.md
docs/decisions/0012-goal-led-cadence-and-real-journey-boundary.md
docs/decisions/0013-private-session-lifetime-and-public-tryout-boundary.md
docs/decisions/0014-real-focus-loop-and-ephemeral-photo-boundary.md
docs/decisions/0015-memory-progress-witness-and-self-belief-loop.md
docs/decisions/0016-real-memory-acceptance-and-core-freeze.md
docs/DEMO_SCRIPT.md
docs/deployment/phase-3-gcp-bootstrap.md
docs/DEVPOST_SUBMISSION.md
docs/evidence/2026-07-19-live-memory-curator-contract.md
docs/evidence/demo-lab-browser-acceptance-2026-07-19.json
docs/evidence/demo-lab-browser-acceptance-2026-07-19.md
docs/evidence/gcp-walking-skeleton-2026-07-16.md
docs/evidence/live-goal-architect-contract-2026-07-18.md
docs/evidence/live-goal-cadence-contract-2026-07-18.md
docs/evidence/live-mobile-vertical-path-2026-07-17.json
docs/evidence/live-mobile-vertical-path-2026-07-17.md
docs/evidence/live-multimodal-android-acceptance-2026-07-18.md
docs/evidence/live-multimodal-check-in-contract-2026-07-18.md
docs/evidence/openai-gpt-5.6-smoke-2026-07-16.json
docs/evidence/openai-gpt-5.6-smoke-2026-07-16.md
docs/evidence/openai-gpt-5.6-smoke-success-2026-07-16.json
docs/evidence/openai-gpt-5.6-smoke-success-2026-07-16.md
docs/evidence/phase-1-verification-2026-07-16.md
docs/evidence/phase-2-local-vertical-slice-2026-07-16.md
docs/evidence/phase-3-real-cloud-task-2026-07-16.md
docs/evidence/phase-4-four-agent-orchestration-2026-07-16.md
docs/evidence/phase-4-live-contracts-2026-07-16.json
docs/evidence/phase-4-live-contracts-2026-07-16.md
docs/evidence/phase-5-8-integrated-build-2026-07-17.md
docs/evidence/phase-7-8-cloud-live-and-deployment-2026-07-17.md
docs/evidence/phase-8-submission-readiness-2026-07-17.md
docs/evidence/phase-8-youtube-publication-2026-07-19.md
docs/evidence/private-session-recovery-and-real-focus-loop-2026-07-18.json
docs/evidence/private-session-recovery-and-real-focus-loop-2026-07-18.md
docs/evidence/real-memory-learning-loop-2026-07-19.json
docs/evidence/real-memory-learning-loop-2026-07-19.md
docs/evidence/realtime-android-production-acceptance-2026-07-18.md
docs/evidence/realtime-preview-deployment-2026-07-18.md
docs/NOTION_LIVE_MOBILE_CHECKPOINT_2026-07-17.md
docs/NOTION_PHASE_5_8_CHECKPOINT_2026-07-17.md
docs/PROJECT_STATE.md
docs/source/01_Time_Sovereignty_PRD_v0.6.md
docs/source/02_Time_Sovereignty_Architecture_v2.md
docs/source/03_Codex_Kickoff_Prompt.md
docs/SUBMISSION_CHECKLIST.md
docs/submission/time-sovereignty-architecture.mmd
eslint.config.mjs
LICENSE
next-env.d.ts
next.config.ts
package.json
postcss.config.mjs
README.md
scripts/run-live-check-in.mjs
scripts/run-live-goal-architect.mjs
scripts/run-live-memory-curator.mjs
scripts/run-phase4-contract-live.mjs
scripts/run-phase4-live.mjs
scripts/smoke-openai.mjs
src/app/api/health/route.ts
src/app/api/live/check-ins/[checkInId]/confirm/route.ts
src/app/api/live/check-ins/[checkInId]/reply/route.ts
src/app/api/live/check-ins/current/route.ts
src/app/api/live/check-ins/schedule/route.ts
src/app/api/live/goals/plan/route.test.ts
src/app/api/live/goals/plan/route.ts
src/app/api/live/pair/route.ts
src/app/api/live/realtime/session/route.test.ts
src/app/api/live/realtime/session/route.ts
src/app/api/live/session/route.ts
src/app/api/tasks/interventions/[interventionId]/route.ts
src/app/api/tasks/live-checkins/[checkInId]/route.ts
src/app/api/tasks/orchestration/[requestId]/route.ts
src/app/demo/page.tsx
src/app/globals.css
src/app/layout.tsx
src/app/manifest.ts
src/app/page.tsx
src/app/pair/page.tsx
src/domain/agents/schemas.ts
src/domain/goals/schemas.ts
src/domain/index.ts
src/domain/interventions/schemas.ts
src/domain/memories/schemas.ts
src/domain/schemas.test.ts
src/domain/shared.ts
src/domain/state-machines/action-machine.ts
src/domain/state-machines/errors.ts
src/domain/state-machines/intervention-machine.ts
src/domain/state-machines/state-machines.test.ts
src/features/demo-lab/demo-lab.tsx
src/features/demo-lab/story.test.ts
src/features/demo-lab/story.ts
src/features/journey/journey-workspace.tsx
src/features/journey/live-check-in-panel.tsx
src/features/journey/live-check-in-summary.test.ts
src/features/journey/live-check-in-summary.ts
src/features/journey/live-focus-schedule.test.ts
src/features/journey/live-focus-schedule.ts
src/features/journey/model.ts
src/features/journey/photo-evidence.ts
[69 more files omitted for size]
```

### Dependencies

- package.json: @google-cloud/firestore@^8.6.0, @google-cloud/tasks@^6.2.3, @tailwindcss/postcss@^4, @types/node@^20, @types/react@^19, @types/react-dom@^19, eslint@^9, eslint-config-next@16.2.10, google-auth-library@^10.9.0, next@16.2.10, openai@^6.47.0, postcss@^8.5.10, react@19.2.4, react-dom@19.2.4, tailwindcss@^4, typescript@^5, vitest@4.1.10, zod@4.4.3

### Recent commits (newest first)

- docs: point V1 landing page to final V2 evidence
- docs: publish submission video evidence
- docs: align final submission package
- checkpoint: accept cloud demo lab
- fix: make demo hydration deterministic
- checkpoint: add isolated 30-day demo lab
- checkpoint: accept real memory learning loop
- fix: continue real journey after completion
- checkpoint: add real memory learning loop
- checkpoint: complete real focus loop
- checkpoint: add goal-led cadence
- checkpoint: accept real multimodal android loop
- checkpoint: connect real multimodal check-ins
- checkpoint: connect live goal architect
- checkpoint: accept realtime android production path
- docs: record realtime preview deployment
- checkpoint: complete bilingual realtime voice foundation
- docs: record protected live mobile acceptance
- fix: accept safe client and task identities
- fix: include Cloud Tasks runtime descriptor

## Key source files (fetched from GitHub, selected and truncated for size)

### AGENTS.md

```markdown
# Codex Repository Instructions

This is the standalone OpenAI Build Week repository for **Time Sovereignty**.

## Product goal

Build a production-shaped AI Chief of Staff that protects one meaningful long-term goal through planning, scheduled check-ins, recovery, progress evidence, memory, and continued follow-up without taking control away from the user. The public demo must include a real user-facing path, not just evidence-only model calls.

## Required reading order

Before broad implementation work, read:

1. `docs/source/01_Time_Sovereignty_PRD_v0.6.md`
2. `docs/source/02_Time_Sovereignty_Architecture_v2.md`
3. `docs/source/03_Codex_Kickoff_Prompt.md`

Treat those files as the current product source of truth. Preserve them unchanged; record later decisions separately.

## Collaboration

- Speak to Chloe in Traditional Chinese unless she requests otherwise.
- Explain the product-facing result before internal schemas or code.
- Do not reduce the product to a generic reminder or task app.
- Do not begin a broad implementation change until the kickoff review is presented and Chloe approves it.

## Security

- Never read, print, quote, commit, or expose plaintext API keys.
- Use `.env.local` for `OPENAI_API_KEY`; keep `.env.local` ignored.
- Treat `GPTAPIKEY.txt` as secret-bearing and never add it to Git.
- Use Secret Manager for deployed credentials.

## Build Week evidence

- Use Codex as the primary implementation environment.
- Keep clear milestone commits and verify before committing.
- Use GPT-5.6 meaningfully in the live product.
- Maintain agent/tool traces and a user-visible outcome evidence chain.
- Keep the primary task available for final `/feedback` submission evidence.

## Engineering discipline

- Complete and verify the main vertical loop before optional integrations or visual polish.
- Keep mock and live providers behind the same schemas.
- Prefer structured outputs, explicit state transitions, idempotent scheduled handlers, and deterministic safety checks.
- Preserve the status distinctions `IMPLEMENTED_IN_MVP`, `INTERFACE_PREPARED`, and `FUTURE` used by the source documents.
- Never fabricate completion, deployment, test, trace, or API evidence.

## Important directories and files

- `src/app/`: Next.js UI and HTTP routes. Protected live-device and Cloud Tasks entry points live under `src/app/api/`.
- `src/features/onboarding/`: goal intake, plan review, support agreement, and bilingual onboarding UI.
- `src/features/journey/`: longitudinal command center, check-in, progress, simulation, developer trace, and live mobile UI.
- `src/domain/`: versioned goal, agent, intervention, memory, progress, and journey contracts.
- `src/orchestration/`: four-Agent routing and safe trace orchestration.
- `src/live-checkin/`: single-device pairing, Firestore state, scheduling, idempotency, quiet-hours fence, GPT-5.6 orchestration, and Realtime session boundary.
- `src/providers/ai/`: mock/live GPT-5.6 provider contract. Live Responses API 
[truncated — 3719 more characters]
```

### docs/NOTION_LIVE_MOBILE_CHECKPOINT_2026-07-17.md

```markdown
# Time Sovereignty — live mobile checkpoint

- Date: 2026-07-17
- Project: OpenAI Build Week / Time Sovereignty
- Status: Backend and 390x844 PWA accepted; physical Android remains
- Primary Codex task: `019f6085-1e4d-7e23-a0b8-371e6e47bbfa`

## What became real

The installed-PWA design now has one protected vertical path: a real Cloud
Task creates a pending check-in; the open PWA polls; Chloe can hear tap-to-play
TTS and answer with text or browser voice transcription; Commitment Recovery
and Chief of Staff use real GPT-5.6; Chloe confirms the adapted commitment;
Firestore stores the decision, safe traces, confirmed memory, and next
follow-up; Developer shows provider/model/tokens/trace ID.

## Proof

- Backend: 464 + 762 = 1,226 tokens; duplicate reply returned in 0.110 seconds
  with unchanged traces and no extra model call.
- Browser: 461 + 750 = 1,211 tokens at 390x844; real decision confirmed; Today
  updated; Developer traces visible; 0 console errors and 0 warnings.
- Combined deliberate usage: four GPT-5.6 calls, 2,437 tokens.
- Stable production remained `00012-7gn` at 100%; final private preview is
  `00017-dif` at 0% under tag `live-mobile`.

## Lessons worth keeping

1. Cloud-first acceptance exposed defects that local tests could not: missing
   Cloud Tasks runtime JSON in Next standalone, strict safe-projection behavior,
   and short-versus-full task identity headers.
2. Agent result and safe trace must land in one Firestore transaction or a
   network break can repeat a billable call.
3. A public PWA can remain safe when the API key stays server-side and access is
   a short, revocable, single-device session—not a secret embedded in Git or a
   URL.
4. Poll while open is enough for the recorded story; background push is a
   separate product decision and should not be smuggled into a hackathon build.

## Exact next move

When Chloe is awake: open the 0% preview on Android, install the PWA, retrieve
the fresh one-time pairing value without writing it to chat or a file, pair,
run one recorded live story, hear phone TTS, try voice transcription or text
fallback, show Developer trace, revoke, then rotate the pairing value again.
USB is not required.

```

### Dockerfile

```
FROM node:22-alpine AS dependencies
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci --no-audit --no-fund

FROM node:22-alpine AS builder
WORKDIR /app
ENV NEXT_TELEMETRY_DISABLED=1
COPY --from=dependencies /app/node_modules ./node_modules
COPY . .
RUN npm run build

FROM node:22-alpine AS runner
WORKDIR /app
ENV NODE_ENV=production
ENV NEXT_TELEMETRY_DISABLED=1
ENV PORT=8080
ENV HOSTNAME=0.0.0.0
RUN addgroup --system --gid 1001 nodejs \
  && adduser --system --uid 1001 nextjs
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
# @google-cloud/tasks loads this generated descriptor at runtime. Next.js
# standalone tracing omits it because the package resolves the path dynamically.
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/@google-cloud/tasks/build/protos/protos.json ./node_modules/@google-cloud/tasks/build/protos/protos.json
USER nextjs
EXPOSE 8080
CMD ["node", "server.js"]

```

### package.json

```
{
  "name": "time-sovereignty",
  "version": "0.1.0",
  "license": "MIT",
  "private": true,
  "scripts": {
    "dev": "next dev",
    "build": "next build",
    "start": "next start",
    "lint": "eslint .",
    "typecheck": "tsc --noEmit",
    "test": "vitest run",
    "test:live:phase4": "node scripts/run-phase4-live.mjs",
    "test:live:phase4-contracts": "node scripts/run-phase4-contract-live.mjs",
    "test:live:goal-architect": "node scripts/run-live-goal-architect.mjs",
    "test:live:check-in": "node scripts/run-live-check-in.mjs",
    "test:live:memory-curator": "node scripts/run-live-memory-curator.mjs",
    "test:watch": "vitest",
    "smoke:openai": "node scripts/smoke-openai.mjs"
  },
  "dependencies": {
    "@google-cloud/firestore": "^8.6.0",
    "@google-cloud/tasks": "^6.2.3",
    "google-auth-library": "^10.9.0",
    "next": "16.2.10",
    "openai": "^6.47.0",
    "react": "19.2.4",
    "react-dom": "19.2.4",
    "zod": "4.4.3"
  },
  "devDependencies": {
    "@tailwindcss/postcss": "^4",
    "@types/node": "^20",
    "@types/react": "^19",
    "@types/react-dom": "^19",
    "eslint": "^9",
    "eslint-config-next": "16.2.10",
    "postcss": "^8.5.10",
    "tailwindcss": "^4",
    "typescript": "^5",
    "vitest": "4.1.10"
  },
  "overrides": {
    "next": {
      "postcss": "8.5.10"
    }
  }
}

```

### src/domain/index.ts

```typescript
export * from "./agents/schemas";
export * from "./goals/schemas";
export * from "./interventions/schemas";
export * from "./memories/schemas";
export * from "./shared";
export * from "./state-machines/action-machine";
export * from "./state-machines/errors";
export * from "./state-machines/intervention-machine";

```

### src/app/page.tsx

```typescript
import { OnboardingFlow } from "../features/onboarding/onboarding-flow";
import { LocaleProvider } from "../i18n/locale";

export default async function Home({
  searchParams,
}: {
  searchParams: Promise<{ profile?: string | string[] }>;
}) {
  const requestedProfile = (await searchParams).profile;
  const profile = requestedProfile === "play" ? "play" : "default";
  return (
    <LocaleProvider>
      <OnboardingFlow profile={profile} />
    </LocaleProvider>
  );
}

```

### src/app/layout.tsx

```typescript
import type { Metadata } from "next";
import "./globals.css";

export const metadata: Metadata = {
  title: "Time Sovereignty — AI Chief of Staff",
  description:
    "Turn one meaningful goal into a protected plan, a clear next action, and support that adapts to real life.",
};

export default function RootLayout({
  children,
}: Readonly<{
  children: React.ReactNode;
}>) {
  return (
    <html lang="en" className="h-full antialiased" suppressHydrationWarning>
      <body className="min-h-full flex flex-col">{children}</body>
    </html>
  );
}

```

### src/app/demo/page.tsx

```typescript
import { DemoLab } from "../../features/demo-lab/demo-lab";
import { LocaleProvider } from "../../i18n/locale";

export default function DemoPage() {
  return (
    <LocaleProvider>
      <DemoLab />
    </LocaleProvider>
  );
}

```

### src/app/pair/page.tsx

```typescript
import { PairingRecoveryPage } from "../../features/onboarding/pairing-recovery-page";
import { LocaleProvider } from "../../i18n/locale";

export default function PairPage() {
  return (
    <LocaleProvider>
      <PairingRecoveryPage />
    </LocaleProvider>
  );
}

```

### src/app/api/health/route.ts

```typescript
import { NextResponse } from "next/server";

import { readAiProviderMode } from "@/providers/ai/runtime-provider";

export const runtime = "nodejs";

export async function GET() {
  return NextResponse.json(
    {
      ok: true,
      service: "time-sovereignty",
      providerMode: readAiProviderMode(),
      model: process.env.OPENAI_MODEL ?? "mock",
      revision: process.env.K_REVISION ?? "local",
      checkedAt: new Date().toISOString(),
    },
    {
      headers: {
        "Cache-Control": "no-store",
      },
    },
  );
}

```

[154 more indexed source files omitted to keep this export small. The full file list is in the Codebase structure section above.]