> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/sessions/phase07-session01-hosted-services-requirements-and-privacy-baseline/tasks.md).

# Task Checklist

**Session ID**: `phase07-session01-hosted-services-requirements-and-privacy-baseline` **Total Tasks**: 18 **Estimated Duration**: 3-4 hours **Created**: 2026-05-30

***

## Legend

* `[x]` = Completed
* `[ ]` = Pending
* `[P]` = Parallelizable (can run with other \[P] tasks)
* `[SNNMM]` = Session reference (NN=phase number, MM=session number)
* `TNNN` = Task ID

***

## Progress Summary

| Category       | Total  | Done   | Remaining |
| -------------- | ------ | ------ | --------- |
| Setup          | 3      | 3      | 0         |
| Foundation     | 5      | 5      | 0         |
| Implementation | 7      | 7      | 0         |
| Testing        | 3      | 3      | 0         |
| **Total**      | **18** | **18** | **0**     |

***

## Setup (3 tasks)

Initial configuration and environment preparation.

### Cross-cutting

* [x] T001 \[S0701] Verify Phase 06 closeout, analyzer state, Phase 07 Session 01 prerequisites, and active current session context (`.spec_system/PRD/phase_07/session_01_hosted_services_requirements_and_privacy_baseline.md`)
* [x] T002 \[S0701] Review Phase 06 closeout, hosted-service docs, privacy docs, environment docs, deployment docs, release docs, API docs, package README files, environment examples, and current test/source inventory for the baseline (`.spec_system/PRD/phase_07/hosted_services_requirements_privacy_baseline.md`)
* [x] T003 \[S0701] Create the hosted baseline, requirement routing matrix, and hosted payload blocklist deliverable files (`.spec_system/PRD/phase_07/hosted_services_requirements_privacy_baseline.md`)

***

## Foundation (5 tasks)

Core structures and base implementations.

### Cross-cutting docs and examples

* [x] T004 \[S0701] \[P] Inventory active local, public-client, server-only secret, deploy-only secret, reserved future, and blocked variables from docs and examples (`.spec_system/PRD/phase_07/hosted_services_requirements_privacy_baseline.md`)
* [x] T005 \[S0701] \[P] Capture hosted identity, hosted storage, public replay, analytics, push, remote access, tunnel, operator diagnostic, and local-first fallback requirements from PRD and downstream session stubs (`.spec_system/PRD/phase_07/phase07_requirement_routing_matrix.md`)
* [x] T006 \[S0701] \[P] Capture Phase 06 security findings, hosted identity limits, production-hosted validation limits, trusted erasure deferral, and current GDPR posture (`.spec_system/PRD/phase_07/hosted_services_requirements_privacy_baseline.md`)
* [x] T007 \[S0701] \[P] Capture current Worker, server, web, CLI, hook, adapter, protocol, export, replay, archive, backup, and log boundaries relevant to future hosted transfer (`.spec_system/PRD/phase_07/hosted_payload_privacy_blocklist.md`)
* [x] T008 \[S0701] Define Phase 07 baseline rules for public browser config, server-only secrets, deploy-only credentials, disabled defaults, consent, minimization, redaction, authorization, unsupported states, and validation evidence (`.spec_system/PRD/phase_07/hosted_services_requirements_privacy_baseline.md`)

***

## Implementation (7 tasks)

Main feature implementation.

### Spec system

* [x] T009 \[S0701] Create the hosted services requirements and privacy baseline with source evidence, local-first constraints, variable categories, hosted surfaces, and Phase 08 deferrals (`.spec_system/PRD/phase_07/hosted_services_requirements_privacy_baseline.md`)
* [x] T010 \[S0701] Create the requirement-to-session routing matrix for Sessions 02-07 and Phase 08 ownership of trusted erasure, production-hosted validation, certification, release hardening, and decommission work (`.spec_system/PRD/phase_07/phase07_requirement_routing_matrix.md`)
* [x] T011 \[S0701] Create the hosted payload privacy blocklist and local-first fallback checklist for hosted storage, analytics, public replay, push, diagnostics, remote access, Worker, adapters, exports, archives, logs, and backups (`.spec_system/PRD/phase_07/hosted_payload_privacy_blocklist.md`)
* [x] T012 \[S0701] Update master PRD, UX PRD, and Phase 07 PRD with Session 01 links, routing ownership, local-first boundaries, hosted-service vocabulary, and Phase 08 deferrals (`.spec_system/PRD/PRD.md`, `.spec_system/PRD/PRD_UX.md`, `.spec_system/PRD/phase_07/PRD_phase_07.md`)

### Stable docs

* [x] T013 \[S0701] Update hosted-services, privacy/security, environments, deployment, release, architecture, and API docs with hosted routing, variable categories, blocked payloads, local-first fallback, disabled-default analytics, and Phase 08 deferrals (`docs/hosted-services.md`, `docs/privacy-and-security.md`, `docs/environments.md`, `docs/deployment.md`, `docs/release.md`, `docs/ARCHITECTURE.md`, `docs/api/README_api.md`)
* [x] T014 \[S0701] Update environment examples and Worker configuration comments where stale to distinguish active, reserved, public-client, server-only secret, deploy-only secret, and blocked values (`.env.local.example`, `apps/server/.env.example`, `apps/adapters/.env.example`, `apps/warroom/wrangler.toml`)

### Package docs

* [x] T015 \[S0701] Update server, web, War Room, CLI, hooks, adapters, and protocol README files with hosted-service ownership, public/secret config boundaries, analytics consent posture, payload blocklist, diagnostics, local-only fallback, and no hosted identity/storage/erasure/release claims (`apps/server/README_server.md`, `apps/web/README_web.md`, `apps/warroom/README_warroom.md`, `apps/cli/README_cli.md`, `apps/hooks/README_hooks.md`, `apps/adapters/README_adapters.md`, `packages/protocol/README_protocol.md`)

***

## Testing (3 tasks)

Verification and quality assurance.

### Cross-cutting

* [x] T016 \[S0701] Run a consistency scan for hosted-service names, variable categories, blocked payload categories, public/secret/deploy boundaries, local-first wording, disabled-default analytics wording, and Phase 08 deferrals (`.spec_system/PRD/phase_07/phase07_requirement_routing_matrix.md`)
* [x] T017 \[S0701] Run whitespace, ASCII, LF, and link/path validation for all changed session, PRD, doc, README, environment example, and config-comment files (`.spec_system/specs/phase07-session01-hosted-services-requirements-and-privacy-baseline/spec.md`)
* [x] T018 \[S0701] Record command outcomes, docs review results, changed files, residual risks, and next-session handoff for implementation and validation (`.spec_system/specs/phase07-session01-hosted-services-requirements-and-privacy-baseline/implementation-notes.md`)

***

## Completion Checklist

Before marking session complete:

* [x] All tasks marked `[x]`
* [x] All tests passing or scoped non-code deferrals documented
* [x] All files ASCII-encoded
* [x] Unix LF line endings
* [x] implementation-notes.md updated
* [x] Ready for the validate workflow step

***

## Next Steps

Run the validate workflow step for Phase 07 Session 01.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/sessions/phase07-session01-hosted-services-requirements-and-privacy-baseline/tasks.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
