# PURE — Master Merger Plan (the record)

> **This is the record of a retired page.** `/master-plan.html` — "PURE Master Merger Plan,
> DRAFT v1" — was the 193 KB narrative that described what PURE would be: the vision, the PD
> economy, the organization spine, who wins, the pillars, the cross-cutting services, the data
> and security model, the deal journeys, the calendar engine, compliance, and the dev pipeline.
> Mike retired the page on 9/4/26. The plan is not history in the sense of being wrong — most of
> it shipped — but it is a *description* of a system that now exists and can be read directly.
> Where the plan and the live system disagree, **the live system wins** (CLAUDE.md: build to the
> live canon, not stale specs).
>
> - **The narrative** is preserved verbatim below, converted from the page (98 headings, 57
>   tables, 98% of the page's visible text). Nothing was summarized away.
> - **The live equivalents** — what the plan describes, as it actually runs today:
>   | The plan describes | Read it live at |
>   |---|---|
>   | Version history, what shipped when | `/poppy-pure-versions` |
>   | Pillars and every working surface | `/site-directory.html`, `/pure-plans` |
>   | Data & security model | `/pure-security-map.html`, `/security-posture` |
>   | Store products & the PD economy | `pure_store_products` (live table) |
>   | Organization spine & roles | `/org-admin`, `pure_org_members` |
>   | Dev pipeline & ticket intake | `/ticket-intake`, `pure_board` |
>   | What was retired and why | `/boneyard` |
>
> Routes `/master-plan`, `/pure-master-plan-v3`, `/merger-v2-lane-a`, `/lane-b/master-plan` and
> the space-named "PURE Master Plan v3.html" now land on `/poppy-pure-versions`, the timeline
> that carries this record forward.

---


### 1 · The vision

One site. One URL. One shell that composes itself from the viewer's **hats** and ** — org level**. A stranger gets public MLS search + lead capture; on sign-in the same shell reveals exactly the surfaces their permissions unlock — buyer, seller, agent, broker, vendor, association/MLS staff, PURE staff, super-admin. Multi-tenant SaaS: many MLSs, associations and brokerages subscribe to one platform; PURE is merchant-of-record and shares revenue down. Staging at acquisto.biz reflash to acquistorealestate.com puremls.com. Built to carry 50k daily users, desktop and mobile.

**The core problem we're solving:** we keep building new products when we already have them. This plan ** — indexes everything**, folds duplicates into one canonical surface per pillar, and enforces it with permissions — so it's "all things to all users" by ** — composition**, not by sprawl.

**1** — login · many hats

**51+** — working surfaces

**10** — store products

**136** — live DB tables

**59** — server RPCs

**22** — connected services

**6** — billing tiers

**50K** — users · design target

### 2 · Principles (the rules everything obeys)

### + The PD economy — how the money works

**PD is PURE's pricing unit** — small per-use amounts that follow real activity instead of flat subscriptions. The association and MLS run the platform; the store routes a share of every product back to them, so the system funds the industry it serves.

**Who pays** — Whoever benefits. Agent, buyer, or seller can hold a product — the deal doesn't care who pays, only that the work gets documented.

**How much** — 5 PD / listing · 25 PD / transaction · 100 PD / user / mo for professional workbenches. Small numbers that follow real activity.

**Who earns** — The industry. Store revenue shares to the association / MLS; vendors paid through the platform — no invoicing chaos.

**What it replaces** — Forms + e-sign + showing tool + CRM glue + inspection app + status calls — collapsed into one record.

| Product | Price | Who | What it does |
|---|---|---|---|
| Pure Seller Disclosure Assist | 5 PD / listing | Agent pushes to seller | Guided disclosure: serials, warranties, conditions, photos — agent approves into the deal |
| Pure Verified Capture | 5 PD / record | Whoever requests proof | Random identity checks while working a record — audit trail in the live DB |
| Pure Move-In Inspection | 25 PD / transaction | Either side · once each | Room-by-room condition proof at move-in AND move-out, three depths up to insurance-grade |
| Pure Appraiser | 100 PD / user / mo | Appraisers | USPAP/TALCB-compliant appraisal in-system: comp grid, time adjustments, signed report |
| Pure Home Inspector + Field Mode | 100 PD / user / mo | TREC inspectors | State REI 7-6 report, phone walk-through, dictation, photos, gated delivery |
| Pure Order | 50 PD / assoc / yr | Associations | Robert's Rules meetings: motions, votes, auto-minutes, parliamentarian guidance |

### 3 · The organization spine

Tenancy flows down this chain; permissions and data scope inherit along it. The REALTOR® association is itself **three rolled-up levels** — Local State National — and businesses (vendors, lenders, title, appraisers) join each deal as ** — parties**.

PUREPlatform MLS1 · regional Association3 levels · roll upLocal ×14StateNational Brokerageone organization · 1 1000sBroker·Team·Agent·ISA Client & Partiesbuyer · seller · vendors · lenders · title · appraisers

**The brokerage is one organization.** Broker, Team, Agent, and Inside Sales Agent (ISA) all live ** — inside a single brokerage** — ISAs may sit under a team or directly at the brokerage level. Every role is ** — optional**: a brokerage can be a single agent who is their own broker, or a large firm with many locations and thousands of agents, teams, and ISAs. Hats and data scope inherit down whatever structure each brokerage actually uses.

**The association is three rolled-up levels.Local** (e.g. MetroTex, one of 14) ** — State** (Texas REALTORS®) ** — National** (NAR). A ** — REALTOR® must be a member of all three**, and the Code of Ethics + forms/licensing standards flow down from NAR State Local. Associations now also accept ** — non-REALTOR® members** who join the ** — local association only** — they don't belong to the state or national bodies and aren't bound by the REALTOR® Code of Ethics, but still get local MLS/member services. The data model carries a per-person membership at each level + a REALTOR®-vs-non-REALTOR® flag.

**Businesses are parties too.** Vendors, lenders, title companies, and appraisers are set up like any other party — each is its own small organization that gets ** — linked into the transaction** with permissioned, role-scoped access to just its part of the deal. ** — Cross-tenant:** a co-op deal is shared between two brokerages with per-document approval — the transaction is owned by no single tenant.

### + Organizations — live roster & roles

Pulled from each body's public record and **saved to the live database** (pure_organizations · pure_org_members). ** — Tab each card** between ** — Staff**, ** — Volunteer leaders** (+ committees & RVPs) and ** — Membership** (dues, how to join, rules, forms); each links to its own site and feeds PURE onboarding below.

#### Staff & volunteer roles — Local Association & MLS

**Acquisto Real Estate is the live anchor tenant.** Shana & Mike's brokerage is already in the database with its agent roster (12 people) under NTREIS MetroTex. Everything we build proves itself on Shana's brokerage first — her listings, her deals, her people — then the same shell rolls out to every tenant above and beside her.

### + Who wins — every party, the client first

Everything below is a built surface today. Each person has one login; the hat decides what renders — their deal, their scope, nothing more.

#### THE CLIENT — buyer, seller, or leaseholder
- **One clear picture:** the Deal Room Spine shows exactly where their deal stands — questions contract signatures tasks money — no calling around.
- **The details they deserve:** Seller Disclosure Assist walks a seller room-by-room; buyers get a documented home with serials, warranties, and honest answers.
- **Protection on both sides:** Move-In Inspection timestamps the property's condition; Verified Capture proves who documented it.
- **Sign anywhere:** Pure Signature routes documents in order, on a phone, with identity assist.

#### THE AGENT
- Deal room runs the file: smartforms write the DB once, tasks auto-complete from real data
- SearchPro + saved-search handoffs; leads flow in from every source with action plans attached
- Push tools to clients (disclosure assist, move-in) for dollars, not subscriptions
- Mobile field mode for everything — dictate, shoot, done

#### THE BROKER
- Every file complete and auditable — compliance gates block bad submissions before they happen
- CDA/commission rails, money view per deal, office BI
- Brokerage-exclusive modes (gated until authorized) and grant-based access control

#### THE ASSOCIATION
- Dues, billing, statements, committee governance with Robert's Rules built in (Pure Order)
- Member tiers including affiliate members (inspectors, vendors)
- Store revenue share on every product; the platform pays for itself

#### THE MLS
- RESO-aligned listing entry with status-aware completeness gates — clean data at the source
- Feeds & analytics, syndication control, fine schedules, media-day photo compliance
- NOALN address-withheld handling end-to-end

#### VENDORS & PROS
- Photographers: media-day pipeline with booking, prep, delivery, compliance
- Inspectors: full TREC REI 7-6 workbench + phone field mode (licensed, affiliate members)
- Appraisers: USPAP/TALCB-compliant appraisal completed in-system
- All paid through the store — no invoicing chaos

### + Pure Social & persona — identity, brand, and reputation

Every person in PURE has a **persona** — their public-facing identity composed from their hat, org, designations, and deal history. ** — Pure Social** is the layer that projects that identity outward: agent profile pages, AI-generated social content, automated review collection, reputation aggregation, and market-update publishing. One system; every channel; no extra logins.

#### The persona — who you are inside PURE

A persona is the **public record** that others see when they look you up — within PURE (hat-scoped) and outside it (public profile page). It is claimed at onboarding, verified once, and self-maintained from that point forward.

| Hat | Persona fields | Public URL |
|---|---|---|
| Agent | Headshot · bio · license # · designations (CRS, ABR, GRI…) · brokerage affiliation · service areas · languages · active listings · sold stats · reviews + average rating · contact + social handles · video intro · team | /agent/{slug} |
| Broker | Everything an agent has + office address + roster count + brokerage brand (logo, colors) + market specialties + brokerage stats (volume, units) | /office/{slug} |
| Team | Team name + headshots + shared stats + specialties + team listings | /team/{slug} |
| Association / MLS staff | Title · committee roles · tenure · contact · governance responsibilities — claimed via the org roster | /assoc/{org}/{slug} |
| Client / consumer | Private within PURE — preferences, deal history, co-owned saved searches; never public | No public page |
| Vendor / inspector / appraiser | Credentials + license + E&O + service area + completed jobs (count only) + booking link | /vendor/{slug} |

**Profile data lives in pure_org_members.** Every persona field maps to a column: page_slug · bio · photo · years · license · phone · designations · social_handles. Verify-to-claim ties the row to a login so the member maintains their own bio from that point on. Modeled on acquistorealestate.com’s agent pages (Shana’s is the live reference).

#### Pure Social — features

| Feature | What it does | Status |
|---|---|---|
| AI listing post generator | Takes the listing photos, price, beds/baths, headline features — outputs ready-to-post captions for Instagram, Facebook, Twitter/X, and LinkedIn. Agent edits one time, publishes everywhere, or schedules ahead. | Build |
| AI market update | Monthly: pulls the agent’s market stats from the MLS, generates a subscriber-friendly market report email + social graphic. Sent to sphere on a cadence. | Build |
| Review request automation | Triggers post-close: auto-sends a personalized review request (email + SMS) to the buyer and seller 48 hours after CDA clears. Links to Google, Zillow, Realtor.com, and the PURE profile page. | Build |
| Reputation aggregator | Pulls star ratings + review text from Google Business, Zillow Agent, Realtor.com, and Facebook. Surfaces aggregate score on the agent’s PURE profile. Flags new reviews for the agent to respond. | Build |
| Agent profile page | Public SEO page at /agent/{slug} with bio, listings, sales count, designations, reviews, contact CTA, and lead capture form wired to the CRM. Schema.org markup for search engines. | Planned |
| Listing syndication posts | When a listing goes Active in PURE, auto-generates a social-ready graphic (photo + price + address) and queues it for one-tap publish or scheduled auto-post to connected channels. | Build |
| Open house social promotion | Auto-generates an open house event post and Facebook Event from the PURE open house record. Includes address, time, agent photo, and registration link. | Build |
| Personal brand kit | Agent sets brand color + secondary, uploads logo/headshot; PURE applies these to all generated graphics + profile page so everything looks on-brand without a designer. | Build |
| Social channel connections | OAuth connect to: Facebook Page · Instagram Business · Twitter/X · LinkedIn Personal/Company. Managed in the Integrations Hub with on/off kill-switches. | Build |
| Video intro + reel | Agent records or uploads a 60-second intro video; surfaces on their profile page and in the client portal when a new buyer/seller is paired with them. | Planned |

#### How it connects to the rest of PURE

| Connection | Detail |
|---|---|
| CRM / lead loop | Every profile page CTA and market update has a built-in lead-capture form that routes directly into the CRM with source tagging (“PURE Profile”, “Market Update”, “Open House”). |
| Listings spine | Listing posts and open house promotions pull from the listing record — same data, no re-entry. Status change fires the social queue automatically. |
| Deals / CDA | Review request fires from the CDA cleared event — the deal-room close is the trigger, not a manual task. |
| Goals & Performance | Review count + aggregate rating feed into the agent’s production dashboard. Social impressions and profile views are BI metrics. |
| Contact 360 | Reviews and interactions are logged to the contact’s timeline — “Left a 5-star review 2026-06-15” is a relationship touchpoint. |
| Brokerage / team brand | Brokerage sets the parent brand tokens (logo, colors, fonts); agent posts auto-include the brokerage watermark unless the agent has a whitelabel upgrade. |
| Association store | Premium social features (unlimited posts, video reel, market update automation) are marketplace upgrades — PD-priced, revenue-share back to the association. |

**Shana Acquisto (ARE) is the reference implementation.** acquistorealestate.com already has agent profile pages with photos, bio, designations, and listings. Pure Social imports that design language and extends it with reviews, social posting, and lead capture — built on top of the same pure_org_members schema the onboarding section populates. Her page is the live design target; every other agent gets the same at the same level of polish.

### + Member onboarding & data cleanup

Every org above arrives with messy legacy rosters. PURE **ingests, dedupes, verifies, and lets each member claim a profile** — so the directory is clean and self-maintaining.

Importcsv · api · mcp Dedupe & cleangolden record Verifytext + email Claim profilebio + login Live directoryself-maintaining

#### Import & cleanup tools — per organization

| Tool | What it does | Where |
|---|---|---|
| Roster CSV / Excel | Drag a membership export; columns mapped to pure_org_members, source-tagged | pure_import_staging |
| Association / MLS API | Read legacy data directly — NTREIS RESO, AMS exports, Follow Up Boss | connectors |
| MCP read-&-clean | Jobs normalize names, titles, emails, licenses; flag conflicts for review | mcp_run_next |
| Dedup engine | Match by email / phone / license; merge duplicates into one golden record | — |
| Confirm by text + email | Each member gets a verify link (SMS + email) to correct their data & set a password | pure-comms |

#### Claim your profile

Modeled on the **acquistorealestate.com** agent / broker pages (e.g. Shana Acquisto's) — ** — every position & role gets one**: agents, brokers, office staff, committee & MLS / association leaders.

**Photo & headshot**

**Bio & story**

**Designations & licenses**

**Listings & sales**

**Reviews & testimonials**

**Contact & social**

**Video & media**

**Service areas**

**Team & office**

**The profile schema already exists** in pure_org_members (page_slug · bio · photo · years · license · phone). Verify-to-claim ties the row to a login, so members maintain their own bio going forward.

### + Brand standards — per organization

PURE rides on top; each org keeps its own brand & colors for its people (the white-label theme store). Confirmed tokens come from our build canon (pure-design-tokens / CLAUDE.md). NTREIS & MetroTex are **approximate** — send their official brand kits and I'll lock exact hex + logos into each tenant theme.

### + Voice — basic to advanced

One voice across the whole site, flexing by who's holding it. Same brand, same room — the words get simpler or denser with the user's level. Progressive disclosure, not a different product.

#### Core voice (always on)

#### How it flexes by user level

The everyday agent sits in the middle — guided where stakes are high (legal, money), efficient everywhere else. The hat sets the default density; the user can lean either way.

#### Same moment, two voices

### 4 · Pillars & where every asset goes

Each pillar has **one canonical surface**; everything else becomes a view/mode inside it (Merge) or is archived + redirected (Archive) — nothing deleted. Canon = the keeper · New = to build. "Min hat" = lowest role that sees the pillar at all (scope still applies).

### 5 · Cross-cutting services (every pillar calls these)

### 6 · Data & security model

### + Infrastructure, database & APIs

The real live stack — read straight from the database today (**136 tables · 59 server functions**). This is what the unified site already runs on; the merger stamps tenancy onto it, it isn't a rebuild.

#### Database — 136 tables by domain

#### Structured · semi-structured · unstructured

#### Server, APIs & MCP

### + Referrals — broker broker, agent agent

A referral sends a client to another agent or brokerage for a fee. PURE runs the whole lifecycle on **one pipeline** (pure_referrals) and settles the fee through ** — Pure Clearing** — no more “any news?” calls.

Receivedpartner sends Acceptedagent claims Activein a deal Closeddeal done Paidfee cleared

#### Types & commission

| Type | Who | Fee |
|---|---|---|
| Agent Agent | Within the brokerage | % of side GCI or flat |
| Broker Broker | Cross-company | Negotiated — commonly 25% of side GCI |
| Network / portal partner | SetSchedule · Fello · referral networks | Partner terms |
| Past-client / sphere | Your database | Flat or % |

#### What it links to

| CDA | Referral fee posts as a line on the Commission Disbursement Authorization — taken off the top before the agent / broker split. |
|---|---|
| Income · Pure Clearing | Settles as kind: referral-fee — in = received, out = paid; reconciled in Pure Books. |
| Reports & projected income | Goals & Performance reads cleared + pending; the referral pipeline feeds projected GCI. |
| Notes & messaging | Every stage change mirrors to the contact timeline, Pure Messaging & Notifications. |
| Transaction hub | When the referred lead opens a deal, the referral links into that transaction room; the fee rides to closing. |
| Agreements & assets | Sign the referral agreement in-system (Pure Signature); send the client packet & docs with permissioned access. |
| Protection period | Tracks how long your claim to that client's deal holds. |

**One pipeline, settled automatically.** Advancing a stage auto-posts the update to the partner + a weekly digest, so the “any news?” calls stop. The fee is agreed up front, the agreement is signed in PURE, and it flows straight to the CDA and Pure Clearing — every dollar traces.

### + Partners & vendors — in the same system

Lenders, title, insurance and trades all work **inside PURE on the shared spine** — one uploader, one e-signature, one transaction hub, one audit trail. No emailing PDFs around; every party sees only their slice.

#### Lender

| Application | Borrower applies in-system; status visible to the agent on the deal. |
|---|---|
| Disclosures | Loan Estimate / Closing Disclosure delivered & e-signed (ESIGN / UETA) — via Pure Signature. |
| Pre-approval | Letter rides straight into the deal room + the offer. |
| Document upload | Pay stubs, statements, conditions — dropped to the uploader, classified & filed. |
| Payoff coordination | Receives payoff requests from title; updates the net sheet. |

#### Title & escrow

| Title order | Open title in-system; commitment + exceptions tracked on the deal. |
|---|---|
| Rate quote | Title rates / premiums quoted straight into the net sheet. |
| Net sheet | Expected seller / buyer net auto-built from price, payoffs & fees — the Net Sheet surface. |
| Payoff request | Request mortgage payoff(s) from the lender; logged & dated. |
| Title forms | Commitment, CD, T-47, owner's / lender's policy, disbursement — filed to the room. |

#### Insurance

| Quote & bind | Homeowner / hazard quote requested & bound in-system. |
|---|---|
| Declarations page | Dec page uploaded, e-signed, filed to the deal. |
| Proof to lender | Evidence of insurance shared to the lender automatically. |

#### Trades — roofers, plumbers, inspectors, contractors

| Field uploader | Upload receipts, photos, invoices & warranties from the job site. |
|---|---|
| Warranties | Warranty docs attach to the **property record** — they follow the home. |
| In-route GPS | “Follow my location” en route — the **same location-share + SOS feature built for agent showing safety**. |
| Guided walk-throughs | Step-by-step capture so the work is documented consistently. |
| Review & approve | Agent / owner reviews uploads; approved items post to the room + money. |

**One spine, reused.** The uploader, e-signature (Pure Signature), the location / safety service (lifted straight from showings), the transaction hub and the audit trail are shared services — each vendor just gets the role-scoped slice they need, and everything they add is reviewed, approved, and logged.

### + A deal, start to finish — the system carrying it

One listing, told as a story. Every step below is a built surface — this is not a roadmap, it's a tour of what's live.

#### Seller journey — 10 steps

**1 · Lead arrives** — Website / Zillow / referral categorized, action plan attached, agent claims it

**2 · Pre-listing** — Agent pushes Seller Disclosure Assist — seller documents serials, warranties, conditions from their phone

**3 · Media day** — Photographer booked through the pipeline; prep checklist; photo compliance + identity-checked on site

**4 · Listing goes live** — RESO rules gate entry — cannot syndicate incomplete; saved-search alerts fire to matching buyers

**5 · Buyers compete** — SearchPro side-by-side compare; Offer Comparison weighs terms, not just price

**6 · Contract** — TREC 20-18 smartform writes the DB once; ¶3 math can't go out of sync; tasks spawn with real deadlines

**7 · Signatures** — Pure Signature routes in order — phone-friendly, identity assist, effective-date stamps on execution

**8 · Diligence** — Inspector works REI 7-6 in Field Mode; appraiser completes a USPAP appraisal in-system; amendments negotiate from findings

**9 · Close + move in** — Money view finalizes; Move-In Inspection timestamps condition; CDA pays the right people

**10 · Forever after** — Record stays: warranties, serials, photos, post-close nurture — the client's next deal starts warm

#### Buyer journey — 8 steps

**1 · Get matched** — Saved searches the buyer co-owns with their agent fire alerts the moment a fitting home lists

**2 · Browse & tour** — SearchPro side-by-side compare; request a showing in a tap — lands in the agent's schedule

**3 · Make an offer** — Offer Comparison weighs terms, not just price; estimated costs shown before signing

**4 · Negotiate** — TREC 20-18 smartform; counters route back and forth with the math kept in sync

**5 · Sign** — Pure Signature routes in order, phone-friendly, identity assist, effective-date stamps

**6 · Diligence** — Inspector REI 7-6 Field Mode; USPAP appraisal in-system; amendments negotiate from findings

**7 · Close + move in** — Money finalizes; Move-In Inspection timestamps condition; CDA pays the right people

**8 · Settle in, forever** — Record stays — warranties, serials, photos; Contact 360 keeps the relationship warm for the next move

### + PURE Calendar — one time engine for every party

Every time-bound event across PURE in one role-scoped agenda: TREC contract deadlines, showings, media days, company meetings, task due dates, and CRM follow-up plans — auto-populated, subscribable as iCal, and remindable via email + SMS. The calendar is not a feature; it's the scheduling rail the whole transaction rides on.

#### Event sources — what feeds the calendar

| Source | Events created | Table / surface |
|---|---|---|
| TREC contract (20-18 / 39-10) | Option period expiry · financing deadline · appraisal deadline · closing date — auto-created when the contract executes; the buyer and seller both receive a deal iCal link | deals.option_expiry, financing_dl, appraisal_dl, close_date |
| TC checklist milestones | Every date milestone in the TC checklist spawns a calendar entry + a task with configurable reminders — nothing falls through the cracks | pure_tc · pure_tasks |
| Showings | Confirmed + requested showing appointments with client name, listing address, time window, and status — color-coded orange | pure_showings |
| Media day | Photographer arrival, prep-window start, and shoot completion — booked in the media-day pipeline, slots into the listing agent's calendar automatically | pure_media_day |
| Open house | Start / end time, listing address, agent host, RSVP count — published to the public listing page + the agent's calendar | Open House Manager |
| Pure Order / meetings | Board meetings, committee meetings, education events, annual conference — entered in Pure Order and pushed to every relevant member's calendar automatically | Pure Order surface |
| CRM action plans | Follow-up task due dates from lead routing, nurture sequences, and agent action plans — appear as task events with drill-through to the contact | pure_tasks · campaigns |
| Vendor jobs (inspections, appraisals, trades) | Booked job dates for licensed pros — address, contact, linked deal — only on the vendor's calendar | pure_vendors · pure_vendor_jobs |

#### Views
**Agenda Built**

Chronological day-grouped list — soonest first. Color-coded by type. "Today / tomorrow / in N days" labels. Each item deep-links to its surface.
**Week view Build**

7-column grid across the work week. Overlap detection; drag to reschedule a showing. Density control for busy brokers.
**Month view Build**

Standard month grid with event dots; click a day for the agenda. Closings in green, option expirations in orange.
**Per-deal timeline Build**

All dates for one transaction on a single timeline — shared with every party on the deal room.

#### Hat-scoped calendar — who sees what

| Hat | Calendar scope |
|---|---|
| Client (buyer / seller) | Their deal dates only: showings they're involved in, key contract deadlines (option expiry, appraisal, financing, close), moving day |
| Agent | All their deals' deadlines + showings they run + media days + open houses + company meetings + CRM task due dates + their external calendar events (if synced) |
| ISA | Follow-up task deadlines from lead action plans + their showing schedule |
| Broker / TC | Every deal in the office + all agent showing schedules + company events + compliance deadlines; can filter by agent or deal |
| Vendor (inspector / photographer / appraiser) | Their booked jobs only — arrival time, property address, contact, linked deal; no other deal data visible |
| Association staff | Board meetings, committee meetings, dues billing cycles, education events — from Pure Order; members see the events relevant to their committees |
| Admin (PURE staff) | Full calendar across all tenants (filtered by org); incident response timelines; deploy windows |

#### Subscribe & publish — iCal feeds

Any PURE calendar is a **subscribable iCal feed** — paste the URL into Google Calendar, Outlook, or Apple Calendar and it updates live. Sent automatically at deal milestones (contract execution, closing date set).

| Feed URL pattern | Audience & trigger |
|---|---|
| /ics/deal/{deal_id} | Sent to all parties at contract execution — buyer, seller, agents, TC, lender, title; everyone's phone gets deal dates automatically |
| /ics/agent/{agent_id} | Agent subscribes once — all PURE events (deals, showings, media days, tasks, meetings) appear in their personal calendar app |
| /ics/office/{brokerage_id} | Broker / office manager — the full office calendar including all deals and showings; filterable by agent |
| /ics/association/{assoc_id} | Association members subscribe once; board + committee + education events are always current |
| /ics/vendor/{vendor_id} | Inspector / photographer / appraiser — their booked jobs as calendar events with address + contact; no other deal data |

**Two-way sync with Google Calendar / Outlook (planned).** PURE subscribes to the agent's external calendar via OAuth2 — showing requests placed externally appear in PURE; accepted PURE showings post back to Google Calendar. Token stored per-user, refreshed automatically; opt-in only.

#### Pure Order + meeting integration
- **Pure Order** creates a meeting record (date, time, location, agenda) — it immediately appears on every relevant member's PURE Calendar with no extra step.
- **Committee meetings** from Committee Governance appear for the chair, vice-chair, and all members of that committee.
- **Board of directors** meetings appear for all board members automatically.
- **RSVP / attendance** — members respond in PURE; the meeting runner sees the attendance count before the meeting starts.
- **Association iCal** — one published feed for the year; members subscribe once; education events and deadlines are always current.
- **Minutes link-back** — after the meeting, auto-generated minutes link to the original calendar entry (permanent, searchable record).

#### Reminders

| Event type | Default lead times | Channels |
|---|---|---|
| Option period expiry | 3 days before + 24 hours before | Email + SMS + in-app |
| Financing / appraisal deadline | 5 days + 48 hours + 24 hours before | Email + SMS + in-app |
| Closing date | 7 days + 3 days + 1 day before | Email + SMS + in-app |
| Showing (confirmed) | 60 min before (client + agent) | SMS + push |
| Media day | Day before + 2 hours before | Email + SMS |
| Association meeting | 1 week + 1 day before | Email + in-app |

**Delivery:** email · SMS · in-app push (PWA). Each user sets their preference per event type in Settings. All reminders are rows in pure_reminders, processed by the MCP comms server — logged, opt-outable, TCPA-compliant quiet hours enforced.

#### Build status

| Feature | Status |
|---|---|
| Agenda view — showings + closings + media days | Built · live |
| TREC contract dates auto-populate | In progress |
| Pure Order / meeting integration | Planned · next sprint |
| Per-deal iCal feed + auto-send at execution | Build |
| Agent / office / association iCal feeds | Build |
| Google Calendar / Outlook two-way sync | Build |
| Week + month view | Build |
| Configurable reminders (email + SMS) | Build — blocked on pure-comms wiring |

### + Security & access control

Hats + org IDs are JWT claims; the database enforces them with row-level security. The UI hides, the DB enforces — so a forged request can't reach another tenant's data. This is live today and tightening table-by-table.

### + Compliance & accessibility

Outreach consent, legal docs, and an accessible UI — **tracked as data, enforced in the product, documented for audit**.

#### Communications & consent

| Area | Rule | Where it lives |
|---|---|---|
| TCPA | Prior express written consent before calls / texts; quiet hours; per-channel consent recorded with a timestamp | consent log |
| Do-Not-Contact / DNC | Honor internal + national DNC; suppression checked before every send | suppression list |
| Unsubscribe / opt-out | One-click unsubscribe in every email; STOP keyword for SMS; instant suppression | pure-comms |
| CAN-SPAM | Physical address + working unsubscribe in every email; honored promptly | email footer |
| Password resets | Self-serve reset via verified email; expiring tokens; nothing stored in plaintext | Supabase Auth |

#### Legal & forms — versioned and linked

| Terms of Service · Privacy Policy | Versioned, dated, acceptance logged per user. |
|---|---|
| E-sign consent (ESIGN / UETA) | Disclosure + consent before any electronic signature. |
| IABS & Consumer Protection Notice | TREC-required disclosures surfaced at first substantive contact. |
| Wire-fraud advisory | Shown before any funds / closing instructions. |
| Data retention & deletion | Stated retention windows; export + delete on request. |

#### Accessible website — WCAG 2.2 AA
**Color-contrast study**

≥ 4.5:1 body text, ≥ 3:1 large & UI
**Color-blind safe**

Never color alone; tested deuter / protan / tritan
**Font-size study**

≥ 16px body, rem units, scales to 200%
**Keyboard & focus**

Full keyboard nav, visible focus rings
**Screen-reader labels**

Semantic HTML + ARIA, alt text
**Reduced motion**

Honor prefers-reduced-motion
**Target size**

≥ 44px touch targets

**Tracked, not just promised.** Consent, suppression, and disclosure acceptances are rows with timestamps — provable in the audit log; accessibility is checked each release.

### + What real-estate data borrows from health records

Medical-records systems solved the hard version of our problem: **many parties, one sensitive record, shared safely**. We adopt their proven patterns.

| Health-records pattern | PURE equivalent |
|---|---|
| Standard exchange format (FHIR / HL7) | RESO Web API + a shared data dictionary — every party speaks one schema. |
| Patient owns the record; consent-driven sharing | The consumer owns their data; granular, revocable consent per party (TXR 1101 model). |
| Minimum-necessary, role-based access | Hats + RLS — each party sees only the fields their role needs. |
| Audit trail of every access (HIPAA) | Hash-chained audit_log + Verified Capture — who saw / changed what, provable. |
| Break-the-glass + disclosure log | Gated overrides (PureGates) with a logged reason. |
| Enter-once, reconcile (no re-keying) | Seller / agent enter data once; parties review & approve, never retype. |
| De-identification for analytics | Address-withheld (NOALN) + aggregated reporting; PII stays scoped. |
| Record locator / interoperable IDs | Golden record + dedup — one ID per person / property across tenants. |

**The mental model:** treat a transaction like a patient chart — one trusted record, role-scoped views, consent-driven sharing, and a complete audit trail.

### + Upload engine — capture every past session

Import & consolidate all prior work

Assigned · Ana

Goal: pull every past Claude Design session’s work into **one searchable history** — so we never lose anything and can always find the best of what we’ve built. Tool: Session Registry (writes to pure_project_registry).

#### Steps
1
**Collect the URLs**

In claude.ai/design, open each project and copy its URL — the …/p/<id> link.
2
**Paste into the registry**

Bulk-paste (one per line) into Session Registry **Add all**. Give each a short name so it’s findable.
3
**Auto-save**

The registry parses each project ID and writes it to the live DB — the list persists, nothing is lost.
4
**Hand off to the agent**

Say “import the registry.” The agent reads the list (list_projects).
5
**Ingest the files**

For each project the agent reads its files cross-project and inventories them — surfaces, data models, dictionaries, decisions, assets.
6
**Dedupe & index**

Fold into a master index (pure_memory + a consolidated history doc); tag by pillar/topic; flag duplicates; keep the canonical **best** version of each.
7
**Verify & log**

Flip each row to **imported**; log the pass to qa_runs; spot-check a few.
8
**Search anytime**

The consolidated index + dictionary make every past decision and surface findable.

**Captured:** files & artifacts from any project you have access to (you own them, so all of them). ** — Not captured:** the old chat transcripts — only what those sessions produced. That’s the one limit, and the consolidated index closes most of the gap by indexing the actual outputs.

### + Live dev pipeline — ticket intake via pure-mcp

How PURE staff keep the live site updated **without hand-editing code**: a ticket rides the pure-mcp server end-to-end — intake build QA publish live — every step logged in the database for audit and rollback.

**Where PURE staff do this today:** Mission Control (type a ticket pure_board) and the Admin Console (operate the live site). Web ticket entry means anyone at their level files a request that reaches Claude through PURE — the same rail, permissioned. Gateway is gateway-proof (x-mcp-key, scoped principals); compliance-gated changes (NOALN, brokerage-exclusive) stay locked until dual admin authorize.

### + Release management — version control, test servers & controlled rollout

Nothing reaches a member untested. Every change is **versioned, promoted through environments, tested with real cohorts, then released** — with one-click rollback.

#### Environments — promote, don't hot-fix

Local / devbuild Stagingacquisto.biz Beta cohortopt-in tenants Productionacquistorealestate.com puremls.com

#### Version control & releases

| Git mirror | puremlstech/pure-deploy takes the full state at every close — diffable history, one-click revert source. |
|---|---|
| Release registry | Every publish tagged in pure_releases + pure_deploy_registry (version, actor, URL). |
| One-click rollback | mcp_deploy_rollback / release.revert to any prior version. |
| Auto-changelog | Deploys self-log (Netlify auto-build rows) — no manual release notes. |

#### Controlled tests

| Feature flags / gates | PureGates toggles a feature **per tenant** without a redeploy. |
|---|---|
| Canary / staged % | Release to one office one association all, watching metrics at each step. |
| A/B & beta | Compare variants; opt-in beta cohorts get the change first. |
| Monitors & QA | GTmetrix speed + UptimeRobot uptime; SEV banners; verifier verdicts in qa_runs — no ship without a recorded pass. |

#### User groups & focus groups

Associations love being involved — so **involvement is a feature**. Cohorts test, vote, and feed the roadmap.
**Beta cohorts**

Opt-in per tenant; early access
**Tech committee as focus group**

The association's own committee reviews previews
**Feedback ticket**

Web ticket entry the board — closes the loop
**Release previews & notes**

What's coming, shown before it ships
**Advisory votes**

Pure Order meeting runner — motions & votes

**The loop:** build stage beta cohort & focus group fix from their tickets staged production rollout monitor rollback if needed. Members feel ownership; PURE ships safely.

### + Training, learning & FAQ

Every feature ships with the help to use it — **training videos linked to a Learning library and contextual FAQ**, at every level, mostly marketplace upgrades.

Featureany surface Training videoshort, tagged Learning librarycourses by role Contextual FAQthe ? on the page Ticket if stuckto the board

| Training videos | Short clips per feature, **tagged to the surface**; completion tracked per member. |
|---|---|
| Learning library | Courses & playbooks per role / level; CE-style tracks; onboarding paths. |
| Contextual FAQ | The **?** on every surface opens the relevant answers **and the matching video**. |
| AI meeting review | Web meetings recorded, summarized, action items logged & linked. |
| “Still stuck?” | Opens web ticket entry the board — the same loop the dev pipeline runs on. |
| Marketplace | Most education is an upgrade (Pure.ai plans, pro tracks) — non-dues revenue for the tenant. |

**Linked, not siloed.** A video, its Learning course, and the on-page FAQ all point at the same feature — and exist at ** — every level** (NAR · state · MLS · association · brokerage · agent · consumer), each with its own scoped content.

### + PURE App — native mobile

Some jobs the browser can't do — they need a real app (iOS/Android, one codebase). The web shell stays the backbone; the app adds device powers and works in the field with no signal.

| Capability | What it does |
|---|---|
| MFA / authenticator | Built-in PURE authenticator — push-approve sign-in + rotating codes, so the org isn't dependent on a third-party app; ties to the same Supabase Auth + MFA already live. |
| Location services | Geofenced showings & check-ins, nearby-listings, agent-safety live location sharing + panic, route/territory tools — background location the web can't access. |
| Offline data entry | Inspections, disclosures, CMAs, open-house sign-ins, photos captured with no signal; queued locally and synced on reconnect (enter-once still holds). |
| NFC lockbox / showings | Tap to open a credentialed lockbox; access is permissioned to the showing + logged to the transaction (who, when, where) for the audit chain. |
| Camera & documents | Scan/photograph docs & property AI data entry straight into MLS/deal fields; media-day uploads from the phone. |
| Push notifications | Offers, signatures, showing requests, lead alerts, tasks — native push, per hat. |

**Build approach:** one cross-platform codebase (React Native / Expo or Capacitor) that ** — reuses the same Supabase backend, auth, hats & data spine** as the web — not a separate product. PWA first for reach; native app for NFC, background location, true offline & the authenticator. The app is ** — PURE-branded with the same per-tenant theming** as the web.

### 7 · acquistorealestate.com — the public IDX site

**What it is today:** a fast Next.js public IDX/MLS search front end — login (email + Google), Purchase/Lease · Active/Sold · Residential/Commercial/Land, location + radius search, saved searches, rich listing cards (beds/baths/sqft/$ per sqft/year), browse by county/city/zip/neighborhood/open house, consultation capture, light/dark, MLS-fed with image CDN. It ranks on a very broad keyword footprint — that traffic is an asset we must not lose.

#### How it pulls in
- **It becomes the public face of the unified shell** — the "Visitor" layer of the Search & Listings pillar. Same listings spine feeds both the consumer search and the agent tools (CMA, deal room) — no duplicate listing data.
- **Lead loop:** every public search, saved search, and consultation flows straight into the CRM/Office pillar and routes to the right agent (agent-invited association or brokerage round-robin).
- **Rebuild better for ranking:** server-render listing + city/county/zip/neighborhood pages, full schema.org (RealEstateListing, Breadcrumb, FAQ), clean canonicals, sitemaps, top-tier Core Web Vitals. ** — 301 every existing URL** so we gain ranking, never lose it.
- **Feed:** the live Google Cloud feed lands in the single normalized listings store (powers search index + listing pages + agent tools). NOALN/exclusive gates control address visibility.

**Decision pending:** keep the public search as fast static/CDN modules behind the shell (fastest, lowest risk) or move it to SSR/ISR for maximum SEO (more work, better ranking). My recommendation: ** — SSR/ISR for the public pages only**, app-shell for everything behind login.

**Handover needed:** (1) the acquistorealestate.com code, (2) the Google Cloud feed credentials/spec. Then I scrape + rebuild the public front cleaner than the original and wire it to the spine.

### + Data feeds & MLS syndication

A listing is entered once in PURE, then fans out to every channel through a **RESO-standard feed** — the research is already built into syndication.js / feedops.js. Inbound, the MLS feed populates PURE; outbound, PURE pushes each portal, gated by exposure mode + seller opt-outs, on a watched, SLA'd loop.

MLS RESO Web APIinbound feed PURE listings spinenormalized · tenant-stamped Portals & sitesoutbound syndication

#### Syndication channels

#### RESO feed payload & exposure modes

**Compliance loop.NAR Clear Cooperation:** once a listing is publicly marketed, the agent has ** — 1 business day** to submit it to the MLS — PURE runs the clock (idle running overdue) from the public-marketing date. ** — Feed ops** (feedops.js) watch list price, status, photo count, exposure mode & opt-outs; changes debounce 2s and re-push on a 24h SLA. ** — Seller opt-outs** (internet display, address, AVM, comments) and the ** — NOALN** / ** — brokerage-exclusive** modes stay LOCKED until PURE admin + MLS admin dual-authorize. ** — Premium placement resale:** the MLS bulk-buys portal exposure keys and resells (agent pays 100 vs 300 retail).

#### Inbound enrichment, safety & efficiency feeds

Beyond syndication, PURE pulls feeds in to enrich every listing & contact, keep agents safe in the field, and cut busywork — the data lands once and powers search, the deal room, and the CRM.

### + Private listing networks & exposure control

A listing doesn't have to go everywhere. PURE governs exposure on a ladder from **fully public** to ** — fully private** — the same exposureMode that drives syndication. Private tiers (broker-exclusive, NOALN) are ** — built but compliance-gated**; the PURE Private Listing Network is the cross-brokerage quiet-market layer.

**Compliance gates (locked by default).NOALN** and ** — broker-exclusive** are coded but ** — LOCKED** until ** — dual authorization — PURE admin AND MLS admin**, per tenant, fully audited (the PureGates registry holds every not-yet-legal capability). ** — Clear Cooperation guardrail:** any public marketing of an exclusive/private listing voids it — PURE surfaces a risk warning and starts the 1-business-day MLS clock. ** — Seller consent** (TXR 1101 portal consents) drives what each listing may do; the PURE & broker private networks are opt-in and membership-scoped — only network members see them, with one-click “promote to MLS.”

### + Lead intake — from any source to the right person

Built on the **live Follow Up Boss probe** (30,550 events; Shana's book). The machinery exists — the **#1 gap was that leads arrive but plans don't attach**. PURE pulls the trigger: every channel lands in one inbox, deduped, intent-scored, then auto-routed with a follow-up plan.

Sourcesapi · email · zapier · csv Inboxpure_leads · source filed AI normalize + scoreintent: high/mid/low Dedupmatch person RouteISA · agent · broker Plan + saved searchauto-attach

#### Inbound sources — file it, track it

#### Routing logic

**Unique inbound email + AI data dump.** Every source/agent gets a ** — unique inbound address** (the …@followupboss.me pattern, generalized) — forward or BCC ** — anything** (a portal email, a screenshot, a CSV, free text, dictation) and it's ** — logged, source-attributed, and AI-parsed** into {source, type, person, contact, intent, criteria}. ** — Mass import:** CSV / API / webhook bulk load with source tagging. ** — Dedup & recurring:** inbound is matched to existing people by email/phone — a returning lead never spawns a duplicate or a new owner; it ** — re-routes to whoever already has them**, bumps the intent score, and logs the new touch (speed-to-lead clock). ** — Partner loop:** referral sources write to pure_referrals (partner, stage, fee), auto-post stage updates back, and tie fees to Pure Clearing.

### + Reference — what looks & functions best

Real surfaces already built, shown as the visual + functional bar for the unified product. Everything ships **Pure-branded** — Pure Books, Pure Payroll, Pure CDA, Pure Signature, Pure MLS, Pure Clearing, Pure Store, Pure Title — one consistent name, look & behavior.
**Contracts — TREC 20-18**

Smart promulgated form: write the deal once flows to MLS, disclosures, signing.
**Signing — Pure Signature**

In-order signing ceremony with identity assist, on the transaction.
**Legals — Compliance Center**

Deal compliance + NOALN / brokerage-exclusive gates, attorney review.
**Database — PURE Data Atlas**

Every live table & column — the schema we stamp with tenant IDs for RLS.
**Transaction hub — Deal Room Spine**

Questions contract signatures tasks money; every party in one room.
**Navigation — PURE Directory**

Search + favorites over every surface; the index that becomes the role-aware nav.

### + Market size — every org is a tenant

The whole plan scales because each org level is a sellable PURE tenant. Starting point: **Acquisto Real Estate** (1 brokerage) its ** — NTREIS** MLS & ** — Collin County AoR** then replicate the same multi-tenant engine outward.

**Source note:** these are ** — public U.S. industry benchmarks (approximate, to verify)** — I couldn't find a stored research file with our own counts in this workspace. If our research lives elsewhere (a doc, sheet, or upload), send it and I'll replace these with the exact figures and date them. Demo anchors already in the build: NTREIS ≈ 18,400 users · Collin County AoR ≈ 1,240 members · Acquisto ≈ 46 agents.

### 9 · Product capabilities

The same data, many ways to see and act on it. Every list of records is viewable, filterable, visualized, reported on, and automatable — standard out of the box, customizable per user and hat.

#### Views & visualization

One dataset, switch the lens in a click. Views save per user/hat; hybrids split the screen.

**Hybrids:map + list** (pins beside results) · ** — table + detail** (grid left, record right) · ** — calendar + agenda** · ** — board + map**. Any view saves as a named preset; the hat sets the default.

#### Dashboards

#### Reports & BI

#### AI

#### CRM — built to close

#### Field entry & controls

Forms are data, not PDFs. Every field is the right input type, validated, with the action right there — enter once, reuse everywhere.

#### Tooltips & definitions

Every term is one hover/tap from a plain-language definition, sourced from the per-level dictionary. Hover a chip:

### 10 · The PURE operating framework

Four layers + one loop. Build a capability once; expose it by permission. Composition over sprawl — the model the whole plan executes against.

### 11 · Scope of work

What we commit to first, what phases in, and what we deliberately leave out of v1.

### 12 · Version control & releases

One trunk, semantic versions, every release reversible in a click. The batch is the unit of rollback; the live DB + GitHub mirror are the source of truth.

### 13 · Update timeline & cadence

Weekly timestamped batch ships; hotfix patches as needed; minor every ~2 weeks; major at phase gates. The queue, in order:

### 14 · Review & best practices

Nothing ships without a recorded pass. Quality, compliance, and coordination are gates, not afterthoughts.

### 15 · Future-proofing

Bets that keep this durable as it scales from one brokerage to many MLSs.

### The call to action

PURE already contains nearly everything an end-to-end real-estate business needs — it's just scattered across versions, lanes, and duplicate surfaces. This plan folds it into **one role-aware site** where every hat sees exactly its tools, every record is enter-once, and every org level is a billable tenant.

**To start Phase 0–1, I need three things:** (1) the acquistorealestate.com codebase, (2) the Google Cloud listing-feed credentials, (3) the official NTREIS & MetroTex brand kits. Approve the framework + v1 scope and I consolidate to the single shell.

Approve in Command Center Ecosystem Map Admin Console

### 16 · Rollout (phases to approve)

### + Glossary — the words we use

| ARE | **Acquisto Real Estate** — the brand owned by Shana and Mike Acquisto. Never the English verb. Token: --pure-are-blue: #29ABE2. |
|---|---|
| PD | PURE's pricing unit — small per-use amounts that follow real activity instead of flat subscriptions. |
| Hat | One person's active role (agent, broker, association, vendor, client). One login holds many hats; switching re-renders the shell to that role's scope. |
| The Spine | The deal-room view that links questions forms signatures tasks money on one screen. The canonical transaction hub. |
| NOALN | No-Address-On-Listing Network — address withheld from public display. Gated; requires PURE + MLS dual unlock to enable. |
| Grant | An explicit, expiring permission that lets someone see across an org/tenant boundary. Every grant is logged in the audit trail. |
| Lane | An AI work session (A, B, …). Lanes claim tickets from the live board and verify everything they ship. |
| Batch | A timestamped copy of the whole deploy — the unit of publishing and the instant rollback point. |
| SEV-1/2/3 | Incident severity: outage / degraded / minor. SEV-1 banners cannot be dismissed by users. |
| RLS | Row-Level Security — the Postgres policy layer that enforces hat + org scope at the database, not just the UI. |
| AMS | Association Management System — the association's own CRM (dues, members, committees, governance). PURE builds one AMS used by all tenants, scoped to their data. |
| MCP | The PURE MCP server — named, scoped, audited tools; replaces raw Supabase keys with a controlled gateway. Runs as a Supabase Edge Function. |
| Testin | The Testin.MikeSupabase GitHub branch — committing here auto-deploys to acquisto.biz in ~30 seconds. |

The full living dictionary is in the product — live pure_dictionary table in Supabase (135 entries and growing).

### + Quick answers

Q

**Is this live or a demo?** — The surfaces are live against a real database; client-facing money/PDF moments are clearly marked demo until their gates (forms uploads, pricing approvals) clear.

Q

**What happens if something breaks?** — The status glance goes amber/red, a banner posts everywhere, staff get messaged, and any release can be reverted to the previous batch in one action.

Q

**Who can see my data?** — Your hat decides. Cross-boundary viewing requires a logged, expiring grant. Identity checks can be required on any sensitive capture.

Q

**Can it replace our current tools?** — The deal record already carries forms, signatures, tasks, money, search, disclosure, inspection, and appraisal natively — the integrations layer covers the rest while it migrates.

Q

**How does deploy work?** — Commit to Testin.MikeSupabase branch acquisto.biz live in ~30 seconds. For major changes cut a batch folder first; drag-drop to Netlify still works as a one-off for whole-site deploys.

### + Your actions — items waiting on a person

!

**Upload TXR forms (1101 · 1406 · 1405 · 1414 · OP-H)** — Unblocks promulgated-form output across forms + disclosure (ND-1)

!

**Upload 4.8 MLS rules engine** — Local-MLS deltas for listing completeness gates (ND-2)

!

**Reconnect UptimeRobot with the main API key** — Completes the site-uptime tile on the PURE Status page (ND-6)

!

**Answer APR-1..6 in Command Center Approvals** — Verified Capture price · MCP hosting · Netlify token · spend caps · FUB registration · lead routing

!

**Get Lane A's close-out batch into the workspace** — Their cleared tickets union at the next Combine (ND-4)

!

**Lane A: flip USE_RPC=true in pure-wallet.js** — Client wallet-writes should use the signed JWT path, not the anon key — must commit to Testin to go live

**Testin auto-build live** — Commit to Testin.MikeSupabase acquisto.biz live in ~30s. Drag-drop path still available as a one-off.

**MFA + JWT auth on Admin Console** — Admin Console writes with the signed user JWT, not the anon key. Pure Signature via Supabase Auth.

**Auto-session capture live** — pure_session_log table · log_session() + list_sessions() RPCs · Session Registry at /lane-b/session-registry.html