Skip to content

Gate 0.5 decisions

C8 — VA API matrix in onboarding

Decision (2026-07-11): Removed from veteran onboarding.

  • Onboarding verification step shows capabilityStatusCard only (identity, service history, verification — three rows).
  • Full 17-API catalog lives in Profile → VA API Matrix (Dev) via VAAPIMatrixDevView, visible when Configuration.showsVADiagnostics (sandbox / staging API builds only).
  • ProviderInvitePlaceholderView was already deleted; ROI share step covers provider handoff.

Decision (2026-07-09): Deferred post–Gate 0.5.

  • Production path today: email OTP via SendGrid on POST /api/secure-access/open.
  • iOS: SMS deep-link share remains visible but disabled (Configuration.secureLinkSmsEnabled = false).
  • Rationale: Email OTP satisfies Gate 0 DoD (designated-recipient verify before artifact view). Server-side SMS provider integration is not required to earn Gate 0 or exit Gate 0.5.
  • Revisit when: mobile-first provider handoff in the field requires SMS OTP, or SendGrid deliverability is insufficient.

Decision (2026-07-09, updated 2026-07-15 for AWS): Temporary harness-only env var on ECS prod. Torn down 2026-07-16 after inbox OTP proof.

  • Was: When SECURE_LINK_E2E_LOG_OTP=true, API logged OTP to CloudWatch for e2e-roi-gate0-full.sh.
  • Now: Inbox-only harness (E2E_OTP_IMAP_*e2e-harness@last1.enterprises). Key removed from SM + Terraform; logging branch deleted from API. Prod invariant: OTPs are never logged.
  • Override: OTP_CODE env for one-off manual runs.

D10 — Hogan Lovells Part 2 copy

Item Status
10-5345 / Part 2 form copy in app Parameterized in ROIFormCopy / Part2ConsentViewnot counsel-locked
Blocks Gate 0 earn: no · Real veteran pilot: yes · Sandbox Gate 1 build: no
Owner Hogan Lovells engagement (conflicts clearing)
Gate 0.5 status (2026-07-11) Documented; awaiting HL review. Does not block declaring Gate 0 earned or starting Gate 1 sandbox.
Next action Ryan: HL review ticket / target date when conflicts clear