One place to find every plan, spec, standard, and audit that governs PURE. HTML docs open live on the site; .md specs open as source. Type to filter.
Operator decision sheet: tick which of the 71 pure-admin widget tiles move under /pure-admin/* (Move/Copy per tile), download the decisions file.
The current north-star product plan for the whole platform.
Prior master-plan revision, kept for reference.
System blueprint — how the surfaces fit together.
Merging v4 + v5 surfaces into one shell.
Feature-by-feature merge matrix across versions.
Roadmap status and review notes.
Turn the client gate into a real boundary — per-user identity, RLS, TOTP/AAL2. Includes the MFA lock-out solution + blast-radius/rollback.
Live rollout state of the RLS + MFA checkpoints, with per-step rollback. Reads the checkpoint table.
Review-only plan for flipping verify_jwt=true on pure-mcp: grounded current state, the anon-JWT nuance, pre-flight checks, step-by-step, verification matrix, and one-toggle rollback. What the Operator does vs Code.
Grace-gated AAL2 enforcement: enrollment-paced rollout, step-up flow, per-org mfa_required. Client step-up VALIDATED live; server-side aal2 on 8 tables.
Design + exact code + deploy/rollback for aal2 checks in pure-mcp (connector.run, release.*): actor-JWT channel, fail-closed. Awaiting watched window.
Review-only plan for enforcing two-factor without locking anyone out: grounded (only 3 of 36 enrolled), the structural no-lockout guarantee, four layers, org-by-org rollout, break-glass + recovery, one-flag rollback.
Multi-hat identity, default hat, switching, act-as/act-for delegation.
The canonical hats/roles/orgs rules in force.
Live per-page login-gate coverage across the site.
Live scoreboard — RLS, MFA, and hardening status.
Contract-first SQL/endpoint spec Code builds against.
Definition of the posture registry + level-ups.
Confirmed API keys, providers, and function state.
Live pass/fail of every guardrail; self-heals nightly.
Page registry, kill-switch, visibility tiers, ownership.
Stamped, date-sortable file & batch naming.
PureTable component + data-table conventions.
Email/SMS deliverability + outbound conventions.
Analytics/marker tag rules.
MLS/RESO data-dictionary alignment.
Multi-lane operations manual — queue, claims, combine.
Live page inventory + matched/unmatched menu coverage.
Page-level quality/coverage checks.
How acquisto.biz publishes (GitHubNetlify), pitfalls.
Retire/park pages safely with successor ribbons.
Build spec for the park-a-URL system + crons.
Audit of plan vs. built.
Component registry + queue-and-cron autobuild contract.
Component authoring/studio spec.
Colors, type, logo, voice.
Extended brand guidance.
Responsive/mobile compatibility requirements.
Step-by-step reversible plan (CP1-9) to reproduce the Acquisto property-search bar, quick-filter popovers and 4-tab Advanced Filters on PURE, with the field/data gaps called out.
Data migration plan of record.
Throughput, caching, and scale targets.
Document ingestion + extraction engine spec.
Sandbox/test-drive experience spec.
Poppy agent build roadmap.
Operating Poppy on the platform.
Poppy runner/execution spec.
Live conversation + ticket-writing scope.
PURE MLS Technologies · Plans & Docs index · add a card when a new plan/spec lands