This is the canonical product roadmap. It is organized by outcomes, not implementation layers, and should be updated when an issue changes scope or a milestone is completed.
Last reviewed: 2026-07-31
Blueprints should become the smallest trustworthy path from “we plan to ship this” to a reviewed Markdown changelog:
- useful for one developer without any hosted service;
- understandable without knowing the signed-file implementation;
- safe and explicit when a small team exchanges work;
- extensible toward GitHub, GitLab, and VaultSync without making a provider the source of truth.
Goal: a new contributor can build the app, and a developer can plan and export a release without implementation knowledge.
- Restore a reproducible local build and executable helper scripts.
- Establish public-project documentation, templates, automation, and visual identity.
- Move the supported runtime to .NET 10 LTS and Avalonia 12.
- Make the primary workspace a draggable, diagram-first blueprint canvas backed by real version and item relationships.
- Persist, sign, audit, sync, validate, and restore shared node positions while keeping viewport preferences machine-local.
- Add approval-first Source Lens discovery for changelogs, roadmaps, GitHub issues, and issue-linked GitHub Projects.
- Replace icon-only navigation with a clear workflow rail and adaptive next-action guidance.
- Keep release, team, sync, trust, and integration operations in focused secondary tools.
- Add native folder pickers instead of requiring raw paths.
- Add explicit first-run identity setup and pre-project identity-invitation export.
- Add two-step recoverable archive flows for draft versions and items.
- Group release items by changelog category and improve version/item empty states.
- Preview changelogs before writing a file and expose incomplete, key, description, and compact options.
- Add view-model workflow tests for identity setup, create, edit, freeze, release, preview, and export.
- Establish lightweight milestone tags and accomplishment records without binary packaging.
Exit criteria:
- clean clone builds with one documented command;
- create, close, reopen, plan, release, and export work end to end;
- all destructive or immutable actions explain their consequences;
- the v0.2 milestone is recorded by a tag, changelog section, release-history entry, and lightweight GitHub prerelease.
Goal: two people can exchange signed changes through a shared directory and understand every blocked action.
- Add a two-workspace end-to-end collaboration test harness.
- Replace raw-first conflict previews with bounded document-aware field comparisons and retained raw evidence.
- Add guided whole-document conflict resolution and machine-local recovery copies.
- Show shared/last push/last pull manifest evidence, audit status, and actionable recovery steps.
- Replace identity-bundle copy/paste with signed identity and project invitation files.
- Define behavior for member key rotation, compromise, and lost keys.
- Test interrupted/partial shared copies, deleted files, required-file deletion, and stale or replayed manifests.
- Document backup and disaster-recovery procedures.
Exit criteria:
- user A can push and user B can pull on a supported shared-folder target;
- tampered or incomplete input is rejected without mutating trusted local state;
- conflicts explain what changed and produce a recoverable result;
- membership changes cannot remove the last active administrator.
Goal: connect release intent to source history without weakening local ownership.
- Read local Git root, branch, remote, dirty state, tag, and recent commits.
- Match item keys in commit subjects for changelog context.
- Expand canvas editing with box selection, multi-select, keyboard movement, alignment guides, and a minimap.
- Add user-created typed relationships after defining their domain and conflict semantics.
- Link a Blueprints project to one or more repositories.
- Add release-readiness diagnostics for uncommitted and unmatched changes.
- Define provider-neutral issue, pull-request, and release references.
- Add a bounded read-only GitHub issue/Project discovery adapter through the authenticated GitHub CLI.
- Route hosted discovery through a provider-neutral reader contract and add pull-request/release references.
- Replace the authenticated GitHub CLI implementation with a direct provider adapter.
- Add standalone GitHub Project draft-item discovery.
- Define and separately approve any future provider write operations.
- Add GitLab parity after the provider contract stabilizes.
Exit criteria:
- source status is useful offline;
- provider credentials and settings never enter signed project truth;
- no hosted provider is required for core release planning.
Goal: let VaultSync improve transport and recovery while each product keeps a clear responsibility.
- Finalize the exchange-root contract.
- Detect a VaultSync-managed location and report backup health.
- Register Blueprints exchange roots through an explicit opt-in adapter.
- Add a release safety gate based on verified backup state.
- Test restore of both local and exchange workspaces.
Exit criteria:
- Blueprints owns release semantics and signatures;
- VaultSync owns backup/sync transport and verification;
- either product remains usable when the other is absent.
Goal: make the application understandable on first contact while establishing the data-safety contracts required for stable releases.
- Replace the engineering-console shell with beginner-first setup, plain-language task navigation, and a modern visual system.
- Add explicit accessibility names, keyboard destination shortcuts, readable icon actions, and an accessibility qualification guide.
- Make core local signed mutations and recoverable archives atomic across project state and their audit evidence.
- Add versioned workspace inspection, ordered migrations, complete pre-migration backups, rollback, and future-schema rejection.
- Add encrypted signing-identity backup and clean-profile recovery with private/public-key verification.
- Stabilize and bound the version-1 hosted-source provider contract.
- Publish an attacker-focused threat model plus planned platform, version-support, release-qualification, and vulnerability-response targets.
- Expand interruption, malicious-marker, linked-path, migration, provider-contract, and identity-recovery tests.
Exit criteria:
- a first-time user can distinguish starting, opening, and joining without understanding Blueprints internals;
- interrupted local mutation or archive promotion restores the prior workspace;
- current workspaces open without rewriting, future schemas fail clearly, and migration failures preserve the original;
- a signing identity can be encrypted, restored on a clean profile, and verified before use;
- extension and security boundaries are versioned, bounded, tested, and documented.
Goal: make large plans understandable and let ordinary users work with real repositories without leaving the application.
- Organize related work automatically by changelog category, work type, or version.
- Expose visible wide-range zoom, accurate fit, pointer-centered scaling, and clearer canvas navigation.
- Replace manual-only repository paths with native local-folder selection.
- Add explicit clone, fast-forward pull, commit-all, and push workflows.
- Remove the former 100-proposal Markdown/import ceiling while retaining resource-safety bounds.
- Suppress repository hooks, reject executable repository-local Git configuration, and retain provider-write separation.
Exit criteria:
- a first-time user can browse to or clone a repository without typing a filesystem path;
- pull cannot silently merge or overwrite dirty local work;
- repository-controlled hooks and executable local Git configuration do not run through Blueprints;
- large planning documents are no longer truncated at 100 proposals;
- related work is visibly grouped and the complete plan can be navigated from 25% through 250% zoom.
Goal: make the primary canvas readable as a release plan and expose its direct-manipulation capabilities without weakening signed project truth.
- Replace version ownership fans with movable, resizable version frames.
- Organize work by Planned, In Progress, Review, and Complete lifecycle columns while retaining changelog categories.
- Add a backward-compatible signed item lifecycle field with legacy Planned/Complete mapping and validation.
- Add Plan, Dependencies, and Release Notes projections; keep Timeline visibly deferred until target dates exist.
- Render only meaningful typed relationships in Plan, including direction arrowheads, labels, selection, and related-edge focus.
- Add direct two-endpoint connection mode backed by the existing relationship editor, validator, signing, and audit flow.
- Replace permanent instruction strips with a compact toolbar, shortcut help, search, filters, focus, zoom-to-selection, and a clickable minimap.
- Reorganize the inspector into Details, Relationships, Evidence, and History.
- Persist view mode, filters, search, minimap visibility, viewport, zoom, and collapsed frames as bounded machine-local preferences.
- Add light/dark canvas resources and projection, lifecycle, minimap, compatibility, and large-board tests.
Exit criteria:
- containment, rather than ownership lines, communicates version ownership in Plan;
- Plan and Dependencies are usable projections of the same signed documents;
- lifecycle movement uses the normal signed item command and remains blocked for immutable or unsafe workspaces;
- existing schema-1 workspaces open without rewriting and old incomplete/completed items map predictably.
Goal: supported installers and documented recovery for small teams.
- Complete retained keyboard, focus, scaling, and screen-reader qualification on every supported desktop.
- Add signed, reproducible packages and release attestations when distribution work begins.
- Retain manual qualification results for Windows, macOS, and Linux under the published support policy.
- Add automated same-user key rotation, revocation evidence, and stronger platform-keystore integration.
- Commission independent security and recovery review of the stable source tree.
- a hosted Blueprints account service;
- real-time collaborative editing;
- replacing GitHub or GitLab issue tracking;
- executing arbitrary repository hooks or scripts;
- silent automatic conflict merging;
- storing private signing keys in project or shared folders.
Security work is a release requirement across every milestone, not a one-time feature:
- maintain an attacker-focused threat model for every trust boundary;
- add adversarial tests for malformed, replayed, rolled-back, partially written, and maliciously signed input;
- define key rotation, revocation, recovery, and platform keystore integration;
- make core local signed workspace updates atomic and recoverable;
- generate an SBOM for every published package;
- generate provenance attestations when downloadable packages are introduced;
- commission an independent security review before a stable release;
- publish supported-version and vulnerability-response targets;
- never describe a release as audited unless its exact source and artifacts were reviewed.
No release can guarantee that every user is always safe. Blueprints instead aims to make its trust boundaries explicit, minimize sensitive state, fail closed when integrity cannot be established, and respond transparently when a weakness is found.
Each unchecked item should become one scoped issue with:
- a user-visible outcome;
- acceptance criteria;
- security and data-migration impact;
- automated and manual verification;
- milestone and area labels.
The roadmap is directional; GitHub milestones and issues are the execution record.