Epics
Larger asks that are analysed, designed and split into subtasks before anything is built.
Multi-stage builds
Support GitLab, Bitbucket and Azure DevOps alongside GitHub
Implement GitLab, Bitbucket and Azure DevOps as fully functional alternatives to GitHub. Different projects in the organization may be hosted on any of them, and each user may have access to any of them as well.
Definition of done: zero functional gap between them in AppName.
Size: EpicStart to finish: 10 h 5 minAgent work: 8 h 22 minQuestions asked: 18Tokens: 336.3MCost, list price: $248.98Lines added / deleted: +12,515 −1,529Pull requests: 10
Customer support subsystem
Do deep web research and build a subsystem to support our users. We need the following:
- A user asks a question in real time. Usually a chat with an agent can solve it, but if not, the agent can create a ticket
- The chat agent should have access to the documentation (RAG) and be able to answer any question on how to use the platform
- In the future (out of scope for now) the agent will be able to access the DB to explain things to the user, or recognize a bug and submit a ticket
- The chat agent needs heavy guardrails so it doesn't give the user anything they aren't authorized for
- Users can see their tickets and comments, respond and follow up
- An org admin can see all tickets for their company/tenant
- A platform operator can see all tickets, respond to the user, and easily create a task linked to a ticket. When the task is completed, the operator is notified and sees it in the ticket list
- What other functionality would be useful for our platform?
Must have: reuse any functionality we already have; don't reinvent the wheel. We may upgrade that functionality later and want everything to benefit.
Out of scope: email support - we'll handle that separately.
Size: EpicStart to finish: 8 h 52 minAgent work: 16 h 14 minQuestions asked: 14Tokens: 369.0MCost, list price: $247.26Lines added / deleted: +10,568 −559Pull requests: 8
Self-service organization onboarding
Currently users are invite-only, organizations are created by the operator, and the website ends at a waitlist. There is no trial, no organization created from an enquiry, and no first-run wizard.
Implement self-service onboarding for organizations. State of the art, super easy to start.
Out of scope: website links to log in and sign up.
Size: EpicStart to finish: 7 h 49 minAgent work: 13 h 15 minQuestions asked: 20Tokens: 521.8MCost, list price: $337.97Lines added / deleted: +13,089 −1,109Pull requests: 8
Tasks list features and views improvements
Improvements to Tasks:
- Rename "No feature" to "Other"; hide it if a project has no active features
- Users should be able to create tasks directly in the project (not in "No feature") (see attached screenshot)
- Return the Focus icon to the filter
- Reduce user badges on the filter to 3 + collapsed others
- Collapse the Flat / Hierarchy (Tree is a better word) buttons into one on/off button, no words
- Activity View and Table define style, look and feel - not the hierarchy
- Flat/Tree defines ONLY whether tasks are a flat list or grouped by project/feature; same style otherwise. Use the same nesting controls as for epics. Both views must support it.
- Activity View must show epic phases
- Remove the breadcrumb from the Tasks list page, and the word "Tasks" from the breadcrumb on Task details
- Remove the total count from All projects; show it on a collapsed project, and on features when expanded (see screenshot)
- Show "(1)" instead of "?1" - the yellow color implies a question
- Project in the sidebar: add Edit to the ellipsis menu
- Remove the "Filing into ... Change" line
- Clicking the pencil (see screenshot) opens a Feature edit page: name, description, optional icon (tiny colored dots, squares, triangles) shown before the feature and its tasks; clicking the icon opens a palette
- Remove Owner and Created from the task list; show them on the Feature edit page
Size: EpicStart to finish: 3 h 46 minAgent work: 8 h 39 minQuestions asked: 19Tokens: 292.4MCost, list price: $196.80Lines added / deleted: +4,165 −2,490Pull requests: 9
Close the SOC 2 compliance gaps
Make AppName fully SOC 2 compliant, so an auditor can be engaged and a Type I passed quickly, with the controls operating so a Type II window can open right after.
Input: the gap register from the previous task (40 itemized gaps with file:line evidence, grouped by Trust Services Criteria, each with what closing it looks like). Treat it as the backlog: every work item cites its gap IDs.
Scope: the Security, Availability and Confidentiality criteria, for the production environment and the machines it runs on; development is out of the boundary and must be stated as such.
Work items, in order:
- Independent review and approval on every change and deploy: required checks, a required reviewer before infrastructure is applied and code owners.
- MFA and account lifecycle: MFA for every human, a disabled user state, session idle timeout, quarterly access review, read-only database access for operators with logged break-glass.
- Close the open findings of the last security assessment, fixing or formally accepting each with an owner and date.
- Vulnerability and secret management: dependency updates and audits in CI, image scanning, patching policy, secret scanning, a key rotation table, an annual penetration test.
- Logging, monitoring and incident response: failed-login alerting and lockout, a baseline alarm set routed to a paged channel, an uptime probe, append-only security logs, an incident response policy and one tabletop exercise.
- Data classification, retention and erasure, with a scripted tenant offboarding.
- Availability and disaster recovery: RTO/RPO, Multi-AZ database, a recorded restore test, an SLO and a status channel.
- The policy set (information security, access control, risk, vendors, encryption, logging, HR, assets, BC/DR, incident response), a risk register and a named security owner.
- A vendor register, a published subprocessor list, terms of service, a privacy notice and a security page.
- Audit readiness: a system description, an evidence-collection mechanism, a readiness checklist mapping every criterion to its control and evidence, and an auditor selected with a Type I date.
Out of scope: the Processing Integrity and Privacy criteria, ISO 27001, HIPAA, and changing the product's features.
Done means: every gap is closed with cited evidence or formally accepted in the risk register; review and MFA are enforced by the servers, not just written down; a restore test has run; every criterion maps to an operating control.
Size: EpicStart to finish: 16 h 28 minAgent work: 42 h 10 minQuestions asked: 8Tokens: 1.2BCost, list price: $835.88Lines added / deleted: +30,598 −1,794Pull requests: 30
Email signup with admin approval
Allow login and signup with email/password on the main public site.
Signup flow:
- Email signup => verify email (as professional as possible), then create a password. Google, Microsoft, GitHub need no verification.
- Offer a choice: Individual or Organization (column in org table)
- Individual: ask for first name, last name, occupation, and what they plan to use AppName for
- Organization: ask for first name, last name, organization name, job title, and what they plan to use AppName for
- Save to DB as an org and a user in that org (for individuals, org name is the full name). State: Disabled - users can't log in and no tasks from org users get dispatched.
- Show a professional, exciting screen: "{First name}, thank you for your application. We review each new account. Once your account is confirmed you'll receive a welcome email with sign-in instructions. Meanwhile, watch some tutorials" (link to the website's tutorials).
- Send an email with the same information (template managed by admin with the other templates).
- When an admin enables the tenant, users can log in; admin can choose to send a welcome email with a sign-in link.
Login:
- First login: user sets up 2FA (unless the org has it off), then sets up the org as usual
Think of what else I didn't mention that's part of professional onboarding.
Size: EpicStart to finish: 8 h 12 minAgent work: 15 h 35 minQuestions asked: 19Tokens: 365.1MCost, list price: $253.49Lines added / deleted: +9,263 −867Pull requests: 9