Roadmap

This roadmap describes the order of work. Release dates require separate decisions, and physical-device evidence remains mandatory after software or CI gates pass.

Now: complete the appliance release path

Deterministic runtime and release inputs

The digest-required runtime, reproducible manifest, signed deterministic bundle, pre-privilege verifier, and installation receipt are in place. The first public preview now attaches digest-pinned images, image signatures, an SPDX inventory, provenance, source correspondence, checksums, release notes, support status, and vulnerability evidence to one immutable candidate. The release pipeline verifies the published assets again from their public location.

Next, the project must qualify that exact candidate on physical hardware, complete the remaining product journeys and release procedures, and make an explicit human promotion decision before describing any channel as supported.

Installer and first run

Preflight, signed bootstrap verification, exact system-change preview, receipt reconciliation, and filesystem transaction simulations are in place. Remaining work includes local owner enrollment, recovery material, privacy choices, audio/model selection, backup setup, accessible onboarding, export, and complete repair/removal integration.

Signed updates and rollback

Threshold-signed metadata, independently verified staging authorization, checkpointed complete-target staging, atomic activation, bounded health promotion, safe resume, and automatic or explicit rollback simulations are in place. Remaining work connects these controls to real promoted downloads, physical reboot cycles, release notes, offline updates, revocation, and end-of-support procedures.

Hardware qualification

The project will name at least two reference x86-64 systems and publish support tiers: reference, compatible, community-tested, and unsupported. Installer enforcement and public guidance will derive from the same versioned matrix. Seventeen physical checks are waiting for compatible hardware.

The model lifecycle now has signed manifests, deterministic task routing, untrusted proposal validation, golden shadow evaluation, bounded canaries, content-free health gates, and automatic rollback in software. Its synthetic qualification matrix intentionally lists no supported model. Physical model and runtime measurements will populate that matrix alongside the appliance qualification work.

Release candidate and pilot

The candidate must pass clean install, first run, supported journeys, update, rollback, backup, replacement restore, support-bundle generation, uninstall, factory reset, accessibility review, security review, and a reliability pilot. Only an explicit human decision can promote it.

In progress: adaptive maintenance qualification

The adaptive-maintenance software slices are implemented:

Integration hardening is also complete. Persistent owner grants now connect to the existing checkpointed update and rollback transaction, safety budgets survive restart, System wellbeing supports authenticated grant, revoke, and defer decisions, and the preview bundle carries a hardened maintenance timer plus a release-signed read-only source registry.

The remaining gates require physical qualification on the named reference systems, a real opt-in pilot, and explicit human promotion of each automatic action class. Firmware remains blocked until vendor recovery passes on the exact hardware.

In progress: private life operations and easy data onboarding

The next product program is designed to make Unison feel worthwhile from the first small piece of context you choose to provide.

The first shared foundation is implemented in software:

This foundation includes canonical source and connection contracts, encrypted quarantine, deterministic local extraction and an OCR adapter, provenance, correction, rollback, deletion, PKCE, sandbox SMART and financial profiles, bounded local and MCP grants, incremental sync receipts, deduplication, cross-person denial, and revocation. Production provider certification and physical camera quality evidence remain open and are not implied by this software gate.

The next three capability areas are now implemented in software:

  1. private household operations for inventory, receipts, manuals, warranties, maintenance, renewals, returns, recalls, and procedures;
  2. a private health timeline and visit-preparation experience that preserves provenance and does not diagnose or change treatment; and
  3. read-only personal and family financial attention for obligations, exceptions, forecasts, refunds, subscriptions, and weekly briefs without autonomous money movement.

Every later domain will use the same source, connection, provenance, policy, tool, MCP, skill, computer-use, verification, and recovery architecture.

Purpose-bound cross-domain links, benefit and claim packets, care and continuity records, transition templates, credential expirations, and a unified private attention review are also implemented. All external artifacts remain drafts, and joining domains never widens disclosure implicitly.

The synthetic calibration baseline meets the configured time-to-value, precision, usefulness, burden, privacy, deletion, and time-returned targets. The remaining Phase 11 gate is human: a genuinely opted-in pilot, representative accessibility feedback, and explicit support decisions for each package and live provider.

Broaden a proven base

Later exploration

Where to follow implementation