# ReplyTower Customer Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **91/100**. Build trust through visible system truth, connector preflight, and real verification before expanding features. This is an executive judgment score, separate from fingerprint priority.

Decision rule v1.0, 2026-07-31: this plan's registry is ReplyTower's sole priority ledger. Every outcome has one accountable owner, named responsible contributors, a privacy-safe source receipt, a real-surface acceptance test, and an explicit stop condition.

## Executive verdict

ReplyTower has meaningful implementation coverage. Its remaining problem is not a blanket 2MB backend limit and not a shortage of features. The gap is inconsistent truth across connector, plugin, proxy, PHP, ticket, widget, and portal surfaces.

```text
TODAY    hidden constraint -> generic failure -> customer report -> manual forensics
TARGET   preflight truth -> exact capability -> guided recovery -> verification receipt
```

## Evidence capsule

- **MEASURED:** 19 ReplyTower fingerprints, including the current seed: `○ 1 | △ 14 | ☐ 4 | X 0`.
- **MEASURED:** 1,408 genuine VPNCheap conversations, 8,920 messages, 1,047 users; 5,543 synthetic canaries excluded.
- **MEASURED:** 103 genuine conversations used 178 widget attachment messages. Across 937 ticket conversations, ticket attachment count was zero.
- **MEASURED:** structured satisfaction rating populated on zero conversations; 12 explicit feedback events across 10 conversations, 11 negative.
- **MEASURED:** current VPNCheap ReplyTower limit is 10MB, app ingress is 12MB, production Nginx is 12MB, and retained logs contain no upload-related 413.
- **OBSERVED:** the current request identifies an effective 2MB experience as a complaint.
- **INFERRED:** the Xboard/PHP/plugin minimum-limit chain is the leading source. Disconfirm by reading every live limit layer on the authorized panel target.

## Current state

`○ △△△△△△△△△△△△△△ ☐☐☐☐ | 1/14/4/0`

| State | Feedback IDs | Meaning |
|---|---|---|
| `○` | RT-13 | Implementation plus the named real production acceptance receipt exists. |
| `△` | RT-01, RT-02, RT-04, RT-05, RT-06, RT-08, RT-09, RT-10, RT-11, RT-12, RT-15, RT-16, RT-17, RT-18 | Implemented or focused-tested, but current browser, live connector, customer journey, money-flow, or measured performance proof is missing. Tests prove implementation, not real-surface closure. |
| `☐` | RT-03, RT-07, RT-14, RT-SEED-01 | Outcome absent, incomplete, or root layer not reconciled. |
| `X` | none | No recalled ReplyTower item is intentionally cut. |

Historical fixes remain archived. A failed verification creates a linked regression fingerprint rather than rewriting history.

## Fingerprint priority registry

This is the single canonical customer-harm score for each ReplyTower fingerprint. Scores describe the current residual action, so historically closed implementations awaiting a live replay can remain low-score monitor cards without being marked verified. Aggregate program-value scores below do not create duplicate customer priority.

| ID | State | Current outcome | Breakdown `H+R+E+L+U+V` | Score | Band | Accountable / Responsible | Mapped action and dominant factor |
|---|---|---|---:|---:|---|---|---|
| RT-01 | `△` | Portal density fix lacks production viewport replay. | `8+3+12+5+0+4` | 32 | monitor | A: ReplyTower; R: Portal | Real-surface verification; only low residual harm/debt remains. |
| RT-02 | `△` | Mobile tab and KB hierarchy fixes lack mobile production replay. | `8+3+12+5+0+4` | 32 | monitor | A: ReplyTower; R: Portal | Mobile browser verification; bounded check, not redesign. |
| RT-03 | `☐` | VPNCheap has no explicit onboarding policy preset. | `24+3+12+10+5+7` | 61 | P2 | A: ReplyTower; R: vendor-config/portal | Onboarding policy; silent vendor-policy drift dominates. |
| RT-04 | `△` | KB and announcement import lacks live completeness/freshness receipt. | `16+3+12+10+5+7` | 53 | P3 | A: ReplyTower; R: indexing + Xboard connector | KB acceptance; shared path exists, live receipt does not. |
| RT-05 | `△` | String user-ID connector fix is focused-tested but lacks a current live connector replay. | `0+0+20+10+0+0` | 30 | monitor | A: ReplyTower; R: identity + xboard-replytower | Live connector replay; tests are implementation evidence, not closure. |
| RT-06 | `△` | Widget onboarding hardening lacks connector-to-widget E2E. | `24+3+12+10+5+10` | 64 | P2 | A: xboard-replytower; R: ReplyTower connector | Connector preflight; blocker harm and maximum verification debt. |
| RT-07 | `☐` | No vendor-facing full connector preflight exists. | `24+3+12+15+5+10` | 69 | P2 | A: ReplyTower; R: xboard-replytower | Connector preflight; portfolio-wide diagnostic leverage. |
| RT-08 | `△` | Conversation navigation is focused-tested but lacks a current embedded-widget replay. | `0+0+20+10+0+0` | 30 | monitor | A: xboard-replytower; R: ReplyTower widget API | Embedded-widget replay; tests are implementation evidence, not closure. |
| RT-09 | `△` | USDT top-up flow lacks controlled create/pay/credit receipt. | `30+3+12+10+5+10` | 70 | P2 | A: ReplyTower; R: billing API + watcher | Authorized billing verification; money correctness dominates. |
| RT-10 | `△` | Manual KB preservation passes focused tests but lacks a live import/reindex receipt. | `0+0+20+10+0+0` | 30 | monitor | A: ReplyTower; R: indexing | Live import/reindex replay; tests are implementation evidence, not closure. |
| RT-11 | `△` | KB editor focus fix lacks production typing replay. | `8+3+12+5+0+4` | 32 | monitor | A: ReplyTower; R: Portal | Browser verification; low-cost residual acceptance. |
| RT-12 | `△` | Bounded broader reasoning policy is focused-tested but lacks a live quality replay. | `0+0+20+10+0+0` | 30 | monitor | A: ReplyTower; R: chat engine | Live quality replay; tests are implementation evidence, not closure. |
| RT-13 | `○` | Briefing redesign has production verification. | `0+0+20+10+0+0` | 30 | monitor | A: ReplyTower; R: analysis + Portal | Archive plus outcome monitoring. |
| RT-14 | `☐` | Widget images work, ticket path remains text-only. | `16+15+20+10+5+7` | 73 | P2 | A: ReplyTower; R: Xboard ticket connector | Ticket attachment parity; systemic channel gap is measured. |
| RT-15 | `△` | Mobile language race fix lacks current mobile replay. | `8+3+12+5+0+4` | 32 | monitor | A: ReplyTower; R: Portal | Mobile locale verification; low residual debt. |
| RT-16 | `△` | Image-only history flags are focused-tested but lack a current real-panel replay. | `0+0+20+10+0+0` | 30 | monitor | A: xboard-replytower; R: ReplyTower widget API | Real-panel replay; tests are implementation evidence, not closure. |
| RT-17 | `△` | Persistent oversize error and effective-limit display pass tests but lack a current live limit replay. | `0+0+20+10+0+0` | 30 | monitor | A: xboard-replytower; R: ReplyTower capability + hosting | Live attachment replay; the unmeasured limit chain remains a separate seed. |
| RT-18 | `△` | Portal speed fixes are deployed without p50/p95 proof. | `16+3+12+10+5+10` | 56 | P2 | A: ReplyTower; R: API + Portal | Performance SLO; deployed code still has maximum verification debt. |
| RT-SEED-01 | `☐` | Effective 2MB report conflicts with measured 10MB backend. | `16+3+12+10+5+10` | 56 | P2 | A: ReplyTower; R: xboard-replytower + panel hosting/PHP/Nginx | Surface-neutral limit reconciliation; layer-by-layer measurement must first identify the journey, then locate the gate. |

Registry check: `19/19`; `○1 / △14 / ☐4 / X0`; all factor values, sums, and bands validated.

## Durable evidence index

Audit envelope:

- Audit date: **2026-07-31 JST**.
- Recall evidence window: **[2026-07-02 15:00 UTC, 2026-07-31 15:00 UTC)**.
- Production cohort: **1,408 genuine conversations / 1,047 users**. The **5,543 synthetic conversations** were excluded before prioritization.
- Privacy boundary: only aggregate counts, repository paths, commit receipts, and verification gaps are retained here. No raw customer text, conversation/user IDs, credentials, private payloads, customer-specific network topology, or protocol payloads are included.
- Reach factor `R`: `0` for low-residual historical work that is merged or focused-tested and now tracked as a bounded monitor, whether its strict state is `○` or `△`; `3` for one observed vendor/report or a bounded sample without cross-tenant proof; `15` only for a complete measured channel-wide gap. `R=0` does not close an item. One observation maps to one fingerprint only, so aggregate evidence is not multiplied across rows.
- Reference rule: changed behavior is pinned to a commit receipt; a current path is used when it identifies the still-present behavior or missing contract; production facts are dated aggregate read-only snapshots. Passing code tests can verify implementation, but only the named live/browser/money/performance receipt can promote `△` to `○`.

| ID | Stable source reference | Receipt / remaining gap |
|---|---|---|
| RT-01 | ReplyTower `af26391`; `portal/src/app/(vendor)/vendor/conversations/page.tsx`; `portal/src/components/conversations/ConversationDetailView.tsx` | Density and master/detail implementation exists; current production viewport replay is missing. |
| RT-02 | ReplyTower `efbf749`, `b43e827`; `portal/src/app/(vendor)/vendor/knowledge/page.tsx`; `portal/src/components/landing/PipelineDemo.tsx` | Tab, hierarchy, scroll, and accessibility fixes exist; current mobile-browser replay is missing. |
| RT-03 | `app/core/vendor_context.py`; `app/api/v1/vendors.py`; `portal/src/app/(vendor)/vendor/tools/page.tsx` | Policy primitives exist, but registration still has no explicit, versioned VPNCheap onboarding preset or acceptance receipt. |
| RT-04 | ReplyTower `8f023c8`; xboard-replytower `2b8e41e`; `app/services/connector_client.py`; `app/core/indexing/knowledge_indexer.py` | Import and announcement paths exist; no live complete-count, checksum, or newest-announcement-age receipt. |
| RT-05 | ReplyTower `9138219`; xboard-replytower `b2aba3e`; `app/core/identity.py`; `app/core/chat/context.py` | Both identity-owning layers were fixed and focused tests passed; a current live connector replay is still required for closure. |
| RT-06 | ReplyTower `28f0f8e`; xboard-replytower `070536f`; `resources/widget/src/components/ChatPanel.js` | Session, send, history, idempotency, and handoff hardening exist; connector-to-widget E2E receipt is missing. |
| RT-07 | `app/services/connector_client.py`; `xboard-replytower/routes/api.php` | Low-level server-status and admin test route exist; no vendor-facing DNS/TLS/HMAC/path/permission/version/widget preflight contract exists. |
| RT-08 | ReplyTower `de90780`; xboard-replytower `2a8f9ec`; `app/api/v1/widget.py` | Conversation switcher/API implementation exists and focused tests passed; a current embedded-widget replay is still required for closure. |
| RT-09 | ReplyTower `8fe346a`, `c3991c3`, `6c8fbbe`; `app/api/v1/billing.py`; `portal/src/app/(vendor)/vendor/billing/page.tsx` | Flow and financial tests exist and the production watcher was healthy at audit; authorized create/pay/credit receipt is missing. |
| RT-10 | ReplyTower `721420e`; `app/core/indexing/knowledge_indexer.py` | Manual-document preservation behavior exists and focused tests passed; a live import/reindex preservation receipt is still required for closure. |
| RT-11 | ReplyTower `3d723d5`; `portal/src/components/ui/Modal.tsx` | Focus-on-open was separated from rerenders; current production typing replay is missing. |
| RT-12 | ReplyTower `2cbc70b`, `e74045c`; `app/core/chat/prompts.py` | Bounded product-neutral reasoning and KB-state behavior exist and focused tests passed; a live quality replay is still required for closure. |
| RT-13 | ReplyTower `cda3834`, `3417823` | Briefing redesign has focused tests plus a recorded production verification receipt. |
| RT-14 | ReplyTower `4c0163a`; `app/services/connector_client.py`; aggregate production census `2026-07-31` | Widget side: 178 attachment messages across 103 genuine conversations. Ticket side: zero attachments across all 937 ticket conversations; ticket normalization remains text-only. |
| RT-15 | ReplyTower `778ee18`; `portal/src/components/layout/LanguageMenu.tsx` | Blur-before-click race fix exists; current mobile Safari/Chrome replay is missing. |
| RT-16 | ReplyTower `fd779cc`; `app/api/v1/widget.py` | Additive image-only history flags exist and focused normalization tests passed; a current real-panel replay is still required for closure. |
| RT-17 | xboard-replytower `0a15427`; `Support/ImageUploadLimits.php`; `portal/src/components/public/ReplyTowerSelfWidget.tsx` | Persistent oversize error and minimum-limit display exist and standalone tests passed; a current live attachment replay is still required. Limit-chain truth remains RT-SEED-01. |
| RT-18 | ReplyTower `41c08a4`, `2253cdb`; production aggregate deployment `86be1f0` at audit | Backend performance changes were deployed; before/after route and browser p50/p95 receipts are missing. |
| RT-SEED-01 | `Support/ImageUploadLimits.php`; aggregate production configuration/log census `2026-07-31` | Measured backend cap was 10MB behind 12MB app/Nginx ingress, with no upload 413 in bounded retained logs. Exact plugin, PHP, and panel-Nginx limits were not measured, so the effective 2MB report remains open. |

Evidence index check: `19/19` unique IDs; the state ledger remains `○1 / △14 / ☐4 / X0`.

### Privacy-safe historical source receipts

These receipts are derived from the deduplicated Recall ledger, not from copied transcript text. Most fingerprints represent one source incident; in the current ledger all 19 have a deduplicated count of one. RT-06 is the only grouped time range and combines adjacent observations from the same onboarding incident. If recurrence is later proven, the first/last dates and incident count widen instead of creating a duplicate fingerprint.

| ID | First JST | Last JST | Evidence class | Surface / version receipt | Customer journey | Deduplicated incidents / source class |
|---|---|---|---|---|---|---|
| RT-01 | 2026-07-09 10:09 | 2026-07-09 10:09 | Direct owner observation | Web Portal; version unknown | Conversation search and transcript workspace | 1 / owner observation |
| RT-02 | 2026-07-09 15:00 | 2026-07-09 15:00 | Direct owner observation | Mobile web Portal; browser and build unknown | Scenario tabs, knowledge, Ask, and Brief layout | 1 / grouped owner UI review |
| RT-03 | 2026-07-10 16:39 | 2026-07-10 16:39 | Direct owner requirement | Portal, vendor context, connector; versions unknown | Vendor onboarding policy | 1 / owner requirement |
| RT-04 | 2026-07-11 01:10 | 2026-07-11 01:10 | Direct owner requirement | Xboard connector and ReplyTower indexing; versions unknown at report | Knowledge import and announcement freshness | 1 / owner requirement |
| RT-05 | 2026-07-11 12:14 | 2026-07-11 12:14 | Direct owner observation | Official connector API; versions unknown | User identity to AI brief | 1 / owner incident |
| RT-06 | 2026-07-11 15:18 | 2026-07-11 15:19 | Direct owner observation | Xboard embedded widget; versions unknown | Vendor onboarding, connection, and send | 1 / grouped owner onboarding incident |
| RT-07 | 2026-07-11 18:29 | 2026-07-11 18:29 | Direct owner requirement | Portal and connector health API; versions unknown | Connector setup and preflight | 1 / owner requirement grounded in setup failures |
| RT-08 | 2026-07-11 17:49 | 2026-07-11 17:49 | Direct owner requirement | Xboard embedded widget; versions unknown | Past-conversation discovery and navigation | 1 / owner feature request |
| RT-09 | 2026-07-11 23:51 | 2026-07-11 23:51 | Direct owner observation | Web Portal and billing backend; versions unknown | USDT top-up creation | 1 / owner incident |
| RT-10 | 2026-07-12 23:41 | 2026-07-12 23:41 | Quoted customer feedback | Web Portal and indexer; versions unknown | Manual knowledge reindex | 1 / relayed customer incident |
| RT-11 | 2026-07-13 13:50 | 2026-07-13 13:50 | Direct owner observation | Web Portal; browser and build unknown | Knowledge editing | 1 / owner reproducible UI incident |
| RT-12 | 2026-07-14 15:08 | 2026-07-14 15:08 | Quoted customer feedback | ReplyTower chat and RAG; model and build unknown | AI answer quality | 1 / relayed vendor feedback incident |
| RT-13 | 2026-07-15 22:28 | 2026-07-15 22:28 | Direct owner observation | Portal and analysis worker; build unknown at report | Support Health Briefing | 1 / owner product-quality incident |
| RT-14 | 2026-07-15 22:50 | 2026-07-15 22:50 | Quoted customer feedback | Xboard widget and ticket flow; versions unknown | Screenshot-assisted support | 1 / relayed vendor feedback incident |
| RT-15 | 2026-07-17 09:56 | 2026-07-17 09:56 | Direct owner observation | Mobile web Portal; browser and build unknown | Language selection | 1 / owner UI incident |
| RT-16 | 2026-07-16 00:55 | 2026-07-16 00:55 | Internal real-panel QA | Xboard embedded widget; versions unknown | Image-only history and switcher | 1 / internal QA incident |
| RT-17 | 2026-07-16 00:55 | 2026-07-16 00:55 | Internal real-panel QA | Xboard embedded widget; software version unknown, negotiated limit observed as 2.0MB | Oversize attachment recovery | 1 / internal QA incident |
| RT-18 | 2026-07-22 17:13 | 2026-07-22 17:13 | Direct owner observation | Web Portal; browser and build unknown | Vendor control-panel performance | 1 / owner performance incident |
| RT-SEED-01 | 2026-07-31, time unknown | 2026-07-31, time unknown | Current-request seed | Attachment surface unspecified; version unknown | Attachment-limit policy | 1 / current request, excluded from historical count |

Receipt coverage: `19/19`; first/last JST, evidence class, known-or-unknown platform/version, journey, deduplicated incident count, and source class are present for every fingerprint. No session ID, filesystem path, raw quote, user ID, or direct customer identifier is retained.

## Reproducible privacy-safe production aggregate appendix

Snapshot: **2026-07-31 04:06 JST**. The read-only MySQL 8 census used the requested half-open message window **[2026-07-03 00:00 JST, 2026-08-01 00:00 JST)**; rows existed only through snapshot time, and production had no rows for July 3-10. Query families used `START TRANSACTION READ ONLY`, `SELECT`, aggregate CTEs, `COUNT`, `COUNT DISTINCT`, `GROUP BY`, and runtime/config reads. Log work was a bounded read-only pattern census. No write statement, upload probe, raw body export, direct identifier, media locator, credential, network address, or customer text entered this plan.

| Public metric | Tool or query family | Cohort, exclusion, denominator, and exact formula |
|---|---|---|
| 6,952 conversations; 20,008 messages | MySQL 8 active-conversation coverage census | `6,952 = COUNT DISTINCT conversation` with at least one message in the window. `20,008 = COUNT message` across those complete threads. Unsampled total is `5,543 synthetic + 1,408 genuine + 1 test = 6,952`. |
| 1,408 genuine conversations; 8,920 genuine messages; 1,047 users | MySQL 8 vendor/cohort census plus distinct-user grouping | VPNCheap vendor cohort after removing platform-canary and the one test conversation. Outputs are aggregate counts only: `1,408` distinct conversations, `8,920` messages, `1,047` distinct user keys. |
| 5,543 synthetic; 79.7% | MySQL 8 vendor/panel/shape classification | Platform-canary vendor, custom panel, and exact one-user plus one-assistant probe shape. `5,543 / 6,952 × 100 = 79.7339%`, displayed as `79.7%`. The other funnel widths are `1,408 / 6,952 = 20.2524%`, displayed as `20.3%`, and `1 / 6,952 = 0.0144%`, displayed as `0.014%`. Synthetic rows are excluded from demand, feedback, attachment, repeat-user, and theme denominators. |
| 226 repeat users; 21.6% | MySQL 8 genuine-user conversation grouping | Count users with at least two distinct genuine conversations. `226 / 1,047 × 100 = 21.5855%`, displayed as `21.6%`. |
| 12 feedback events in 10 conversations; 0.71% capture | MySQL 8 summary-marker and satisfaction census | `12` structured summary events occur in `10` distinct genuine conversations. Capture uses conversations, not event count: `10 / 1,408 × 100 = 0.7102%`, displayed as `0.71%`. Satisfaction has `0` populated rows, so this is not a satisfaction rate. |
| Theme users 692, 144, 122, 102, 80, 32, 26, 12 | MySQL 8 deterministic multi-label theme census | Genuine user messages only; URL-like and encoded payloads removed before bilingual keyword-family matching; count distinct users per theme. Order: human support, connectivity, device/platform, install/update, attachment vocabulary, protocol/import, service access, billing/refund. Themes may overlap. HTML bar widths use each count divided by the maximum `692`, giving `100%, 20.8%, 17.6%, 14.7%, 11.6%, 4.6%, 3.8%, 1.7%`. |
| 102 attachment users; 103 conversations; 178 messages; maximum 0.484MB | MySQL 8 message-attachment/media join | Genuine VPNCheap cohort only. Counts use distinct user, distinct conversation, and messages with structured or legacy attachment evidence. Maximum is `ROUND(MAX(normalized byte_size) / 1,048,576, 3) = 0.484MB`; it is post-normalization size, not original upload size. The separate theme count `80` is users whose text matched attachment vocabulary, so it need not equal actual attachment users. |
| 0 exact production 2MB complaints | MySQL 8 bounded attachment-limit pattern census | Genuine VPNCheap user messages only, after removing URL-like and encoded payloads before size/failure matching. The single initial encoded-payload hit was rejected by this rule, leaving `0` exact complaint conversations in the snapshot. RT-SEED-01 therefore comes from the current request, not this message census. |
| 937 ticket; 471 widget | MySQL 8 channel/status grouping | Genuine VPNCheap conversations only. `937 + 471 = 1,408`. Ticket attachment census is `0 / 937`; widget attachment use accounts for all `103` attachment conversations and `178` attachment messages. |
| 10MB vendor, 12MB app ingress, 12MB production Nginx; checked-in Nginx 10m | Read-only vendor JSON setting, runtime setting, loaded Nginx config, and repository config reads | Backend effective cap formula is `min(10, 12, 12) = 10MB`. Checked-in Nginx `10m` differs from loaded production `12m`. Plugin, panel PHP, and panel Nginx were not measured, so this does not close the effective 2MB seed. |
| No precise upload 413 in bounded retained logs | Read-only Nginx access/error and current app-log pattern census | Nginx error logs reach production launch around July 11, access logs around July 17, and current app logs around July 22. One access-log 413 was a GET conversation endpoint, not upload; precise upload-too-large matches were zero. This bounded result cannot exclude rotated earlier events. |

### Other exact HTML metric receipts

- `19 = 18 historical ReplyTower fingerprints + 1 current-request seed`; registry states sum to `1 + 14 + 4 + 0 = 19`, leaving `14 + 4 = 18` unresolved.
- `5` ReplyTower product surfaces is the direct count of the five mutually exclusive portfolio groups in the HTML; their row states sum back to the same `○1 / △14 / ☐4 / X0` ledger.
- `7` ranked product proposals is a direct count of the seven program cards below. Their `93/91/90/86/82/79/76` values and rejected-shortcut `38/31/24` values are executive judgments, not production measurements or fingerprint scores.
- `90 days` and `80%` are approved planning horizons and exit targets, not observed production outcomes.
- Recall coverage `5,458 session files / 21,419 in-window user messages / 0 parse failures` comes from the exhaustive 29-day half-open timestamp-window parser receipt. Only the privacy-safe deduplicated fields above entered this plan.
- Every exact production number displayed in the HTML maps to one row in this appendix; percentage rounding is stated explicitly rather than reverse-inferred from chart width.

## Ranked plan

The fingerprint registry below is the only customer-harm priority ledger. The scores in this section are executive program-value judgments, kept separate so a shared intervention does not score the same customer fingerprint twice.

### 1. Vendor connector and widget preflight, program value: 93/100

**PROPOSED:** one vendor-facing preflight checks DNS/TLS, callback reachability, signed auth, required routes, permissions, plugin version, capability matrix, widget session, send/history, and escalation round trip. It returns safe reason codes and an exportable redacted receipt.

Dominant factor: a broken onboarding path blocks the product and currently becomes diagnosable only after customer impact.

### 2. Ticket attachment parity, program value: 91/100

**PROPOSED:** extend the connector ticket/event contract with image metadata and safe retrieval, then cover ingestion, storage, vision, portal transcript, and both plugin directions. Widget attachment success does not close ticket parity.

Dominant factor: production proves a systemic channel gap, not merely a UI request.

### 3. Repair the upload constraint contract, program value: 90/100

**PROPOSED:** reconcile checked-in Nginx `10m` with the production `12m` value through config-as-code; make public, authenticated, reference, self-widget, and Telegram paths enforce the same effective vendor cap before full-body buffering; turn Telegram degradation into an attributable failure; test cap-minus-one, cap, cap-plus-one, missing or lying length, chunked oversize, MIME, pixel-bomb, cross-tenant grants, and Redis failure.

Dominant factor: repository inspection already proves contract drift and inconsistent cap enforcement even though it does not prove the reported 2MB root cause.

### 4. Structured feedback and escalation telemetry, program value: 86/100

**PROPOSED:** persist rating, negative reason, recovery outcome, escalation acceptance, response latency, and resolution. Report by release/channel/theme with privacy-safe links, not copied transcripts.

Dominant factor: the current 0.71% explicit-feedback capture cannot support product decisions.

### 5. Performance SLO and trace, program value: 82/100

**PROPOSED:** measure portal route and browser p50/p95 after deployed fixes, set the SLO from the baseline, and trace only remaining slow paths.

Dominant factor: fixes are deployed, but outcome is still unmeasured.

### 6. Explicit VPNCheap onboarding policy and KB acceptance, program value: 79/100

**PROPOSED:** version an idempotent preset: retention off, subscription-link actions off, subscription authorization on, other approved tools on. Acceptance records complete KB counts/checksum plus latest-announcement age.

Dominant factor: implicit defaults create silent vendor-specific policy drift.

### 7. Reconcile the 2MB chain before changing policy, program value: 76/100

**PROPOSED:** read the deployed plugin version, plugin panel setting, PHP `upload_max_filesize`, PHP `post_max_size`, panel Nginx, ReplyTower Nginx, vendor setting, and app ingress. Publish the smallest byte value as the effective cap and log which layer rejected.

Dominant factor: the symptom is real to the user, but raising ReplyTower alone cannot fix an unmeasured 2MB downstream gate.

Rejected shortcuts:

- Raise only ReplyTower's cap: **38/100**. It leaves the PHP/plugin minimum chain, buffering, quota, and error mismatch untouched.
- Add more portal features before preflight and telemetry: **31/100**. It increases surface area without improving trust.

## Delivery sequence

### 0-30 days

- Verify all fourteen `△` items at their real surface.
- Run authorized read-only attachment-chain reconciliation; no production upload probe.
- Freeze preflight and ticket-attachment contracts with both repositories.
- Baseline portal p50/p95 and feedback capture.

Exit: every active item has owner, envelope, acceptance test, and stop condition.

### 31-60 days

- Implement preflight, ticket attachment parity, feedback capture, onboarding preset, and upload-constraint repair in isolated branches.
- Add cap-minus-one, cap, cap-plus-one, absent/lying length, chunked oversize, MIME, pixel-bomb, cross-tenant, wrong-user, Redis-failure, and unsigned-key tests.
- Browser-test localized upload, recovery, history, and mobile portal flows.

Exit: every scheduled P1/P2 is `○` or approved `X`; at least 80% of scheduled `△` cards become `○`.

### 61-90 days

- Canary one tenant, then widen against mismatch, 413, abandonment, latency, storage-byte, quota, vision-success, escalation, and feedback metrics.
- Close only with production receipts and zero tenant/auth/privacy regression.

Exit: two release windows with zero P1/P2 regression and no scheduled P1/P2 left at `△` or `☐`.

## Acceptance and stop conditions

- Attachment capability display equals the smallest measured layer byte-for-byte.
- Oversize rejection is localized, persistent, attributable, and observable.
- Raw upload bodies are capped before full buffering; MIME, pixel, animation, EXIF, grant, quota, and tenant protections remain intact.
- Unsigned `X-Api-Key` mutations remain `401`; signed HMAC and JWT paths pass.
- Manual knowledge survives reindex; complete panel KB plus latest announcements pass count/freshness checks.
- Billing verification uses a controlled real create/pay/credit smoke with explicit authorization before any money action.
- Stop on tenant leakage, auth weakening, silent BYOK fallback, data loss, or unreproducible synthetic exclusion.

## Ownership

- ReplyTower is accountable for ticket attachments, portal/preflight, telemetry, onboarding policy, and backend capability truth.
- `xboard-replytower` is accountable for the embedded widget surface and contributes connector/plugin capability evidence.
- Hosting/PHP/Nginx owners are responsible only for the layer they operate; they do not own customer-visible closure.
