Skip to main content

The direction

This page is direction, not commitment. Nothing here has a date, and everything here is subject to the constraints at the bottom, which are the parts that will not move. For what is tracked and scheduled, read What is next. For what runs today, read What is live.
Status legend:Planned · 🔵 Future

The autonomy ratchet 🔵

GreatBook’s agents are deliberately narrow today: the Clerk files and never fixes, the Bookkeeper drafts and pauses, the Auditor reads and never writes, the Accountant proposes and never posts. The direction is to widen that by earning it, one measurable class of work at a time: The rule underneath it: starts closed and earns openness. Autonomy is granted against a measured rate on a named class of work, never assumed from a demo.
A standing grant is not a relaxed control. It moves when a human decides - from per-item to per-class, in advance and in writing - and it never removes the requirement that a posting is attributable to a person who could have refused it.

Analytics over the same book 🔵

The direction is read-only analytics and planning over the dimensioned ledger: dashboards, budget versus actual, forecasting, and the longer enterprise-performance line. The endpoints that exist today are already portable Postgres queries over the dimensioned GL rather than being tied to one cube engine, which is what keeps this an extension rather than a migration.
The constraint that will not move: analytics reads the book. It never becomes a place where a number is computed differently from how the ledger computes it. Two answers to the same question is the exact failure the single writer exists to prevent, and a reporting layer with its own arithmetic re-creates it one layer up.

Multi-org onboarding ⚪

Row-level security is org-scoped from the first migration, and a cross-org caller already sees zero rows - so multi-tenancy is a property of the schema rather than something to retrofit. What multi-org needs is the surrounding product: a per-session org context forwarded end to end rather than a single-org default, an onboarding path that seeds a chart and rails for a new book, and per-tenant policies for the authenticated database role. The chart itself is already designed for it: the IFRS core is the design standard and the Vietnamese statutory codes are carried as a mapping, so a second jurisdiction is a new projection rather than a second set of accounts.

Deeper document coverage ⚪

146 document types are declared and classifiable today; the Bookkeeper’s document lane posts one accounting effect. The direction is to widen that lane one effect at a time, each with its posting rule, its sub-ledger row, its Close checksum, and its worked eval case - in that order. A document type that can be classified but not posted is honest; a document type that posts by a rule nobody tested is not.

What will not change

These are the commitments the rest of the roadmap is written inside.