# Build phases and remaining deployment work

| Phase | Implemented | Required environment / external setup | Run / verify | Next boundary |
|---|---|---|---|---|
| 1 Architecture + database + routes | Executable relational schema, configurable stops/weekday/cutoff | Python 3.11+; optional DATABASE_PATH | `python manage.py init`; Routes & Areas | Customer/product masters |
| 2 Customer + product + orders | CRUD, history, prices, manual orders/edits/cancellation, CSV import | Actual business catalogue, area/customer data | Dashboard masters; `import_customers.py` | Signed incoming transport |
| 3 WhatsApp webhook | Exact-byte signature, GET challenge, durable raw journal, per-number inbox, dedupe | Meta app secret/verify token, phone-number IDs, HTTPS | Signed-webhook tests; Meta test webhook | Understanding |
| 4 Intent/extraction | Conservative Hinglish parser, optional Ollama JSON schema, uncertainty review, media retention | Optional OLLAMA_URL / OLLAMA_MODEL; model installed | Simulator; mocked AI failure/low-confidence tests | Calendar assignment |
| 5 Route/day/date | India calendar, cutoff, departure, holiday and disabled route rules | Real configured schedule | Deterministic boundary tests | Confirmation |
| 6 Confirmation | Persistent follow-up draft, area/address reuse, explicit YES, repeat proposal, duplicates, API outbox | Live token and supported Graph version for real sends | Simulator order → YES; outbox status | Dashboard/sheets |
| 7 Dashboard + sheets | Responsive dashboard, daily/week filters, route sheets, CSV, browser print/PDF | Browser; no API keys | UI walkthrough; print preview; CSV download | Driver/report workflow |
| 8 Driver + reports | Date/run assignments, driver RBAC, outcomes/reschedule/payment pending, customer history, summaries | Driver profiles/accounts; optional approved owner summary template | Assigned driver login; HTTP role tests | Deployment hardening |
| 9 Tests/security/deployment | Workflow and HTTP tests, scrypt auth, CSRF, role guards, local rate limits, logging, audit, consistent backup | Protected host / HTTPS / backup destination | `python -m unittest discover -s tests -v` | Real provider acceptance and production infrastructure |

Earlier functionality is retained across phases in this project. Phase 9 does **not** mean production certification: live Meta delivery and local model accuracy cannot be tested without your setup.

Remaining production scope: hardened HTTP server/service deployment, PostgreSQL migrations, multi-instance leases/idempotency, shared sessions/rate limiting, monitoring, encrypted offsite backup/restore drills, volume/load tests, full business/branch tenant authorization, automated OCR/transcription/geocoding, native Excel/server-PDF output if required, and real-language acceptance tests on representative retailer messages. The existing V1 code can be run now; these boundaries are explicit rather than represented as finished work.
