π MVP Features List¶
What's In MVP¶
Core Features (Must Have)¶
- User Login - Kinde Auth integration
- Essential Eight Tracking - Quarterly assessments
- Director Dashboard - Compliance at a glance
- Board Reports - One-click PDF generation (Rule-Driven Templating)
- Policy Management - Upload, version, track + Policy Archive for legacy documents
- Risk Register - Simple risk tracking
- Task Management - Compliance task assignment (explicitly linked to policies)
- Domain Discovery - 20-second onboarding with intelligent defaults
- Existing Policy Workflow - Upload and archive legacy documents
Supporting Features¶
- Email Notifications - Task reminders, updates, urgent alerts
- Basic Approvals - Policies and risks
- Evidence Upload - Attach compliance proof with human attestation
- Multi-tenant - Directors on multiple boards
- Policy Archive - Simple storage for legacy policy documents
What's NOT in MVP¶
AI/Agent Features (Post-MVP Enhancement Stage)¶
- Single AI agent architecture (LangGraph)
- Claude 3 Opus/Sonnet integration
- AI-powered insurance form completion
- AI-written board report narratives
- AI compliance gap analysis
- AI policy document parsing/extraction
- Conversational AI guidance interface
- Complex prompt management system
- Agent monitoring/observability
- AI recommendations engine
- Automated evidence validation (AI-based)
- Real-time AI monitoring
Rationale for AI Deferral:
- Prove governance value with simpler, more reliable approach first
- Reduce development timeline to 8-12 weeks
- Lower operational costs (no LLM API usage)
- AI can enhance proven workflows after validation
- Focus on structured data foundation that AI will leverage later
Other Post-MVP Features¶
- WhatsApp/SMS notifications - Conversational interface (Month 3-6)
- API integrations (third-party tools)
- Custom frameworks (beyond core 4: E8, ACSC, S180, Privacy)
- Advanced analytics dashboards
- Native mobile apps
- Vendor management module
- Board transcript parsing (AI-based)
MVP Success Criteria¶
- Director can review compliance in 5 minutes
- Management can track all Essential Eight requirements
- Board reports generated automatically
- All decisions have audit trail
- Works on mobile browsers
Development Priority¶
- Get authentication working
- Build Essential Eight assessment
- Create director dashboard
- Add board reporting
- Everything else follows
Keep it simple. Ship it fast. Learn from users.