> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_06/phase06_requirement_routing_matrix.md).

# Phase 06 Requirement Routing Matrix

**Phase**: 06 - Collaboration, Isolation, and Mobile **Session**: 01 - Collaboration Requirements and Safety Baseline **Status**: Routing source for Sessions 02-07 **Created**: 2026-05-30

***

## Routing Rules

* Route each requirement to the smallest owning session that can implement and validate it.
* Do not route hosted auth, hosted storage, analytics, public replay hosting, production-hosted validation, trusted erasure, release cleanup, or legacy decommission into Phase 06 unless the phase PRD is updated first.
* Protocol-owned contracts start in `packages/protocol` before Worker, web, server, CLI, or hook consumers.
* Documentation-only conclusions from Session 01 are current contract language, not implementation of later sessions.

## Matrix

| ID       | Requirement                                                                                                                                                                                                                                                                          | Owner             | Package/surface                                      | Acceptance evidence                                                                                         |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------- | ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| P06-R001 | Keep Phase 06 baseline artifacts linked from PRD, UX PRD, Phase 06 PRD, docs, and README files.                                                                                                                                                                                      | S0601             | Spec system, docs                                    | Baseline, matrix, checklist, and docs links resolve.                                                        |
| P06-R002 | Preserve local-first operation when Worker URL, Cloudflare credentials, hosted services, analytics, public replay hosting, provider keys, Docker, and remote runners are absent.                                                                                                     | S0607             | Cross-cutting                                        | Validation sweep confirms local-only wording and no required hosted variables.                              |
| P06-R003 | Keep the local server `/warroom` route as compatibility/status metadata only.                                                                                                                                                                                                        | S0605             | `apps/server`, docs                                  | Unsupported Worker route tests and API docs keep `separate-surface` behavior.                               |
| P06-R004 | Define deterministic room, leader, participant, requester, approver, role, and decision contract shapes.                                                                                                                                                                             | S0602             | `packages/protocol`                                  | Protocol tests cover valid, invalid, duplicate, stale, and role cases.                                      |
| P06-R005 | Replace or strengthen hint-only participant authority without requiring hosted accounts.                                                                                                                                                                                             | S0602             | `packages/protocol`, `apps/warroom`, `apps/web`      | Authority model documents proof limits and tests spoofing and stale metadata.                               |
| P06-R006 | Keep leader-only approval and rejection behavior deterministic.                                                                                                                                                                                                                      | S0602             | `apps/warroom`, `apps/web`                           | Non-leader, duplicate, stale, rejected, and approved flows return compact outcomes.                         |
| P06-R007 | Guard create, join, approve, reject, connect, retry, disconnect, leave, reset, and federation sends against duplicate triggers.                                                                                                                                                      | S0602, S0604      | `apps/web`, `apps/warroom`                           | Store and UI tests verify in-flight guards and idempotent outcomes.                                         |
| P06-R008 | Revalidate room snapshot on reconnect, join decisions, Worker URL changes, storage hydration, and stale local context.                                                                                                                                                               | S0602, S0604      | `apps/web`                                           | Store tests prove stale state is cleared or revalidated.                                                    |
| P06-R009 | Keep leader, member, observer, pending, online, offline, and local participant state visible and accessible.                                                                                                                                                                         | S0604, S0606      | `apps/web`                                           | Component and browser evidence include text and accessible labels.                                          |
| P06-R010 | Extend shared safe collaboration event contracts without allowing raw local data transfer.                                                                                                                                                                                           | S0603             | `packages/protocol`                                  | Protocol validators reject unknown fields, invalid enums, bad ids, and blocked keys.                        |
| P06-R011 | Keep current safe frame families explicit: presence, cursor, focus, hero state, mission state, and room notice.                                                                                                                                                                      | S0603             | `packages/protocol`, `apps/warroom`, `apps/web`      | Worker and web tests cover accepted frame families and dropped invalid frames.                              |
| P06-R012 | Keep sender-excluded broadcast behavior for remote events.                                                                                                                                                                                                                           | S0603             | `apps/warroom`                                       | Worker socket tests prove sender does not receive its own remote event.                                     |
| P06-R013 | Keep catch-up bounded and revalidated before browser consumption.                                                                                                                                                                                                                    | S0603             | `apps/warroom`, `apps/web`                           | Tests cover cap, filtered legacy unsafe events, family summaries, and remote merge.                         |
| P06-R014 | Block prompts, provider prompts, assistant text, command bodies, terminal output, transcripts, file contents, diffs, patches, paths, secrets, tokens, exports, replay buffers, scans, media drafts, diagnostics, logs, backups, and quarantined content from collaboration payloads. | S0603, S0607      | Cross-cutting                                        | Blocked-field tests, consistency scan, docs review, and secret scan where applicable.                       |
| P06-R015 | Keep remote context separate from local hero, mission, queue, guarded-action, replay, export, notification, settings, adapter, scan, archive, memory, and media source-of-truth state.                                                                                               | S0604             | `apps/web`                                           | Store and component tests prove remote context remains dedicated overlay/panel state.                       |
| P06-R016 | Present local-only, disabled, invalid URL, unavailable, timeout, rate-limited, malformed, healthy, connected, reconnecting, caught-up, disconnected, left, pending, approved, and rejected states without blank panels.                                                              | S0604, S0606      | `apps/web`                                           | Browser evidence covers desktop and mobile states.                                                          |
| P06-R017 | Provide visible bounded feedback for room not found, room full, failed socket upgrade, stale decision, duplicate decision, non-leader decision, rejected join, reconnect failure, and catch-up failure.                                                                              | S0604             | `apps/web`                                           | UI and store tests cover failure mapping and visible copy.                                                  |
| P06-R018 | Keep Worker diagnostics compact and free of account ids, zone ids, tokens, request headers, IPs, room payloads, prompts, commands, paths, exports, scans, media drafts, local diagnostics, and logs.                                                                                 | S0603, S0607      | `apps/warroom`, `apps/web`, docs                     | Health tests and docs review confirm compact metadata only.                                                 |
| P06-R019 | Define current execution posture as non-executing proposals and unavailable results.                                                                                                                                                                                                 | S0605             | `packages/protocol`, `apps/server`, `apps/web`, docs | Guarded-action tests and docs confirm approval does not execute.                                            |
| P06-R020 | Define future file, git, terminal, Docker, remote, and hosted executor threat model requirements.                                                                                                                                                                                    | S0605             | Cross-cutting                                        | Isolation diagnostics doc and tests list consent, auth, audit, rollback, redaction, and unavailable states. |
| P06-R021 | Preserve deterministic unsupported-route envelopes for file, git, terminal, remote, container, collaboration, channels, push, webhook, settings, hosted, and Worker route families.                                                                                                  | S0605             | `apps/server`, `packages/protocol`                   | Unsupported-route tests cover status, family, docs, and no sensitive echo.                                  |
| P06-R022 | Keep CLI status/doctor diagnostics compact and recovery narrow.                                                                                                                                                                                                                      | S0605             | `apps/cli`                                           | CLI tests/docs confirm no raw prompts, commands, paths, tokens, raw spool, or erasure claim.                |
| P06-R023 | Keep hook/listener diagnostics silent, timeout-bounded, sanitized, and non-executing.                                                                                                                                                                                                | S0605             | `apps/hooks`                                         | Hook docs/tests confirm no stdout/stderr raw payloads and no inbound command execution.                     |
| P06-R024 | Define supported mobile viewport checks for cockpit, War Room, local orchestration, settings, dialogs, and overlays.                                                                                                                                                                 | S0606             | `apps/web`, Playwright                               | Desktop/mobile browser evidence includes changed surfaces and screenshots.                                  |
| P06-R025 | Ensure keyboard access, visible focus, native control semantics, and focus return for changed surfaces.                                                                                                                                                                              | S0606             | `apps/web`                                           | Component tests and browser review cover keyboard paths and focus return.                                   |
| P06-R026 | Ensure pointer access, stable hit targets, no layout shift, and no incoherent overlap.                                                                                                                                                                                               | S0606             | `apps/web`                                           | Browser evidence confirms no clipped controls or overlapping text.                                          |
| P06-R027 | Ensure screen-reader labels for icon controls, diagnostics, remote context, rosters, pending joins, unavailable states, and dialogs.                                                                                                                                                 | S0606             | `apps/web`                                           | Tests check accessible names, `aria-*`, dialog relationships, and text equivalents.                         |
| P06-R028 | Ensure reduced-motion behavior preserves meaning without nonessential motion.                                                                                                                                                                                                        | S0606             | `apps/web`                                           | Reduced-motion browser or component evidence covers changed surfaces.                                       |
| P06-R029 | Keep long room codes, participant names, errors, state labels, buttons, and panel text fitting or wrapping cleanly.                                                                                                                                                                  | S0606             | `apps/web`                                           | Mobile screenshots and manual review show no clipping.                                                      |
| P06-R030 | Validate changed docs, README files, PRDs, security notes, and runbooks for consistent state names and deferrals.                                                                                                                                                                    | S0607             | Docs                                                 | Consistency scan passes.                                                                                    |
| P06-R031 | Retain local and mocked Worker evidence without calling it production-hosted validation.                                                                                                                                                                                             | S0607             | Tests, docs                                          | Validation report labels evidence scope precisely.                                                          |
| P06-R032 | Keep hosted identity as a tracked residual risk unless Session 02 ships a bounded non-hosted authority proof and documents limits.                                                                                                                                                   | S0607 or Phase 07 | Security docs                                        | Security posture keeps hosted identity risk open or explains bounded resolution.                            |
| P06-R033 | Keep hosted auth, hosted storage, Supabase, analytics, push, public replay hosting, and tunnel variables future/deferred.                                                                                                                                                            | Phase 07          | Hosted docs, environments                            | Hosted services guardrail doc updated in Phase 07.                                                          |
| P06-R034 | Keep trusted unified erasure out of Phase 06 unless Phase 08 scope changes.                                                                                                                                                                                                          | Phase 08          | Security, release                                    | Docs avoid erasure claims for Worker state, browser hints, logs, exports, replay, backups, and valid spool. |
| P06-R035 | Keep release candidate smoke, production-hosted app validation, mobile certification, and decommission gates later-phase work.                                                                                                                                                       | Phase 08          | Release docs                                         | Release guide keeps these gates explicit.                                                                   |

## Session Handoff

Session 02 should start with P06-R004 through P06-R009 and must update this matrix only if authority requirements move to another owner.

Session 03 should start with P06-R010 through P06-R018 and must preserve the blocked payload categories from the baseline.

Session 04 should start with P06-R007, P06-R008, and P06-R015 through P06-R017, then feed any mobile-specific findings into Session 06.

Session 05 should start with P06-R003 and P06-R019 through P06-R023.

Session 06 should start with P06-R024 through P06-R029 and use `mobile_accessibility_acceptance_checklist.md` as the acceptance source.

Session 07 should validate P06-R001 through P06-R035 and update stable docs, security posture, and carryforward memory with evidence-backed outcomes only.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_06/phase06_requirement_routing_matrix.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
