Commit de51b6

2026-08-07 11:37:08 admin: init
/dev/null .. risks decisions, questions.md
@@ 0,0 1,79 @@
+ ---
+ title: Risks, Decisions, and Open Questions
+ aliases: [Risk Register, ADRs]
+ tags: [3netra/wiki, risks, adr]
+ product: 3netra Meta Android App
+ source_repository: 3Netra-ai/3n_meta_android
+ source_ref: origin/prod
+ source_revision: b48aada8fd5427b5db0c02945569963c4ae543c8
+ last_verified: 2026-08-06
+ up: "[[Home]]"
+ ---
+
+ # Risks, Decisions, and Open Questions
+
+ ## Risk register
+
+ | Severity | Risk | Impact | Recommended action |
+ |---|---|---|---|
+ | Critical | Random embeddings when FaceNet model load fails | False identification and unsafe trust | Fail closed; surface model error; add model integrity test |
+ | Critical | Active AI client replaces every successful Edge Function reply with fixed text | Core narration/chat/summary is non-functional or misleading | Decode and validate the response; add contract/UI tests before release |
+ | Critical | Cloud biometric storage conflicts with local/encrypted claims | Student privacy, legal, trust | Define one consented architecture; enforce encryption, RLS, deletion |
+ | Critical | Committed/app-compiled credential material and an unsafe provider boundary | Credential compromise and unauthorized provider use | Rotate/revoke; purge history where required; use managed server secrets only |
+ | Critical | SOS flow is represented but incomplete | Safety harm | Remove claim/entry point until end-to-end verified |
+ | High | Compose and Expo apps share package/build ownership | Wrong artifact, config/signing drift | Record ADR selecting canonical app and retire/rename the other |
+ | High | Glasses connection methods are partly simulated | Core product appears connected when it is not | Implement DAT connection state as single source of truth |
+ | High | No proven Supabase RLS/policy tests | Cross-user or cross-school disclosure | Add versioned schema/policies and adversarial tests |
+ | High | Student age/consent is fabricated or defaulted | FERPA/DPDPA failure | Build verified eligibility workflow |
+ | High | Sensitive debug logging | Biometric/device data leakage | Structured redacted logging and release log policy |
+ | High | Very small test suite and lint disabled | Regression and release risk | Restore quality gates incrementally |
+ | High | AWS workflow cannot demonstrate a deployable active backend | Release drift and false operations claims | Select Edge Function or SAM as canonical; fix required parameters and add deployment/contract validation |
+ | Medium | Orphaned services/routes | Misleading feature status and maintenance cost | Wire with acceptance tests or remove |
+ | Medium | In-memory chat/story | Loss on process death; unclear retention | Decide explicit ephemeral vs durable design |
+ | Medium | Legacy PDF export API | Export failures on modern Android | Use MediaStore or Storage Access Framework |
+ | Medium | Product-age conflict | Wrong copy, consent, UX and validation | Product decision with one canonical PRD |
+ | Medium | Vendor/model hidden behind backend without telemetry | Cost/quality incidents hard to diagnose | Add backend model-routing and quota observability |
+
+ ## Architecture decisions needed
+
+ | ID | Decision | Options |
+ |---|---|---|
+ | ADR-001 | Canonical Android app | Compose `src/frontend`; Expo root app; intentionally separate products/packages |
+ | ADR-002 | Biometric storage | Encrypted device-local only; encrypted cloud sync; remove recognition |
+ | ADR-003 | Primary audience | Higher Education (high school & college); separate editions |
+ | ADR-004 | Voice activation | Always-on wake word; push-to-talk; glasses gesture; phased combination |
+ | ADR-005 | AI provider boundary | Backend-selected model; user/tenant policy; deterministic fallback chain |
+ | ADR-006 | Session history | Explicitly ephemeral; encrypted local; cloud with consent and retention |
+ | ADR-007 | Hardware abstraction | Meta-only near term; formal HAL before second vendor |
+ | ADR-008 | Emergency feature | Production safety workflow; informational assistance only; remove |
+ | ADR-009 | AI execution path | Repair/retain Supabase `chat-vision`; activate/fix AWS SAM; one tested canonical boundary |
+
+ ## Open product questions
+
+ - Is the app a student tool, caregiver companion, school platform, or all three with separate role surfaces?
+ - Which features are safe to advertise today on the active build?
+ - Does a struck-through roadmap item mean delivered, cancelled, or deferred?
+ - Who is authorized to enroll another person's face, and how is their consent recorded?
+ - What is the age threshold and guardian verification mechanism by market?
+ - Are images, video frames, prompts, responses, and transcripts retained by the backend or downstream model vendor?
+ - What happens when the AI is uncertain, especially for identity, emotion, obstacles, and emergency contexts?
+ - Is seven-language output required at launch, and which vendor is authoritative for each speech function?
+
+ ## Recommended execution order
+
+ ```mermaid
+ flowchart TD
+ A[Resolve product audience and canonical app] --> X[Repair fixed AI-response client path]
+ X --> B[Fix face-model fail-closed behavior]
+ B --> C[Define consent, RLS, retention, and vendor data flow]
+ C --> D[Make glasses connection/capture production-real]
+ D --> E[Turn core flows into tested release gates]
+ E --> F[Complete AI chat latency and wake-word scope]
+ F --> G[Wire or remove orphaned features]
+ G --> H[Add offline, navigation, dashboards, and new hardware]
+ ```
+
+ ---
+
+ > [!tip] Navigation
+ > ⬅️ [[11-Security-Privacy-Compliance|Security, Privacy & Compliance]] · 🏠 [[Home]] · ➡️ [[13-Source-Map-Glossary|Source Map & Glossary]]
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9