Roadmap¶
This roadmap describes the order of work. Release dates require separate decisions, and physical-device evidence remains mandatory after software or CI gates pass.
Now: complete the appliance release path¶
Deterministic runtime and release inputs¶
The digest-required runtime, reproducible manifest, signed deterministic bundle, pre-privilege verifier, and installation receipt are in place. The first public preview now attaches digest-pinned images, image signatures, an SPDX inventory, provenance, source correspondence, checksums, release notes, support status, and vulnerability evidence to one immutable candidate. The release pipeline verifies the published assets again from their public location.
Next, the project must qualify that exact candidate on physical hardware, complete the remaining product journeys and release procedures, and make an explicit human promotion decision before describing any channel as supported.
Installer and first run¶
Preflight, signed bootstrap verification, exact system-change preview, receipt reconciliation, and filesystem transaction simulations are in place. Remaining work includes local owner enrollment, recovery material, privacy choices, audio/model selection, backup setup, accessible onboarding, export, and complete repair/removal integration.
Signed updates and rollback¶
Threshold-signed metadata, independently verified staging authorization, checkpointed complete-target staging, atomic activation, bounded health promotion, safe resume, and automatic or explicit rollback simulations are in place. Remaining work connects these controls to real promoted downloads, physical reboot cycles, release notes, offline updates, revocation, and end-of-support procedures.
Hardware qualification¶
The project will name at least two reference x86-64 systems and publish support tiers: reference, compatible, community-tested, and unsupported. Installer enforcement and public guidance will derive from the same versioned matrix. Seventeen physical checks are waiting for compatible hardware.
The model lifecycle now has signed manifests, deterministic task routing, untrusted proposal validation, golden shadow evaluation, bounded canaries, content-free health gates, and automatic rollback in software. Its synthetic qualification matrix intentionally lists no supported model. Physical model and runtime measurements will populate that matrix alongside the appliance qualification work.
Release candidate and pilot¶
The candidate must pass clean install, first run, supported journeys, update, rollback, backup, replacement restore, support-bundle generation, uninstall, factory reset, accessibility review, security review, and a reliability pilot. Only an explicit human decision can promote it.
In progress: adaptive maintenance qualification¶
The adaptive-maintenance software slices are implemented:
- versioned contracts and deterministic adversarial simulation;
- private device inventory and content-free system health observations;
- exact installed-component matching against authoritative security evidence; and
- locally relevant recommendations, capacity forecasts, hardware compatibility checks, and the System wellbeing experience;
- exact revocable grants, maintenance windows, budgets, signed staging, checkpoints, canaries, health gates, receipts, circuit breakers, and rollback for reversible action classes;
- sandboxed community claim collection, corroboration, conflict detection, and local test proposals with no execution authority; and
- full-stack eligibility, calibration metrics, support runbooks, and pilot promotion gates.
Integration hardening is also complete. Persistent owner grants now connect to the existing checkpointed update and rollback transaction, safety budgets survive restart, System wellbeing supports authenticated grant, revoke, and defer decisions, and the preview bundle carries a hardened maintenance timer plus a release-signed read-only source registry.
The remaining gates require physical qualification on the named reference systems, a real opt-in pilot, and explicit human promotion of each automatic action class. Firmware remains blocked until vendor recovery passes on the exact hardware.
In progress: private life operations and easy data onboarding¶
The next product program is designed to make Unison feel worthwhile from the first small piece of context you choose to provide.
The first shared foundation is implemented in software:
- conversational document and image intake;
- camera and multi-page scan capture;
- private encrypted quarantine, local OCR, extraction, duplicate detection, preview, correction, and reversible admission;
- account connection through minimum-scope OAuth, SMART health authorization, provider exports, bounded MCP, and carefully constrained browser fallback;
- progressive setup that asks only what is needed for your current goal; and
- direct Connections, Imports, Sources, Privacy, Disconnect, and Delete controls alongside conversation.
This foundation includes canonical source and connection contracts, encrypted quarantine, deterministic local extraction and an OCR adapter, provenance, correction, rollback, deletion, PKCE, sandbox SMART and financial profiles, bounded local and MCP grants, incremental sync receipts, deduplication, cross-person denial, and revocation. Production provider certification and physical camera quality evidence remain open and are not implied by this software gate.
The next three capability areas are now implemented in software:
- private household operations for inventory, receipts, manuals, warranties, maintenance, renewals, returns, recalls, and procedures;
- a private health timeline and visit-preparation experience that preserves provenance and does not diagnose or change treatment; and
- read-only personal and family financial attention for obligations, exceptions, forecasts, refunds, subscriptions, and weekly briefs without autonomous money movement.
Every later domain will use the same source, connection, provenance, policy, tool, MCP, skill, computer-use, verification, and recovery architecture.
Purpose-bound cross-domain links, benefit and claim packets, care and continuity records, transition templates, credential expirations, and a unified private attention review are also implemented. All external artifacts remain drafts, and joining domains never widens disclosure implicitly.
The synthetic calibration baseline meets the configured time-to-value, precision, usefulness, burden, privacy, deletion, and time-returned targets. The remaining Phase 11 gate is human: a genuinely opted-in pilot, representative accessibility feedback, and explicit support decisions for each package and live provider.
Broaden a proven base¶
- Additional communication channels and provider integrations with the same identity, disclosure, confirmation, replay, and revocation boundaries.
- Physically qualified local and remote model profiles using the implemented data, cost, risk, hardware, lifecycle, and rollback policies.
- More capabilities and daily workflows with recoverable external execution.
- Representative assistive-technology research and hardware qualification.
- ARM64 and additional appliance forms only after the x86-64 lifecycle passes.
Later exploration¶
- Multi-device and multi-writer synchronization.
- Federation between independently governed homes.
- Richer spatial, haptic, sign, Braille, switch, and AAC interaction.
- Carefully bounded smart-home and physical actuation.