Software Requirements¶
- Status: released — baseline
requirements-v2.1, reviewed by Nicolas Burri, 2026-08-16 (the tag defines the exact v2.1 content). Changes require change control per the configuration management plan.
Baseline history¶
| Baseline | Date | Reviewer | Contents / changes |
|---|---|---|---|
requirements-v1.0 |
2026-06-04 | Nicolas Burri | Initial set: 14 STR + 59 software requirements (8 groups). |
requirements-v1.1 |
2026-06-17 | Nicolas Burri | Tier-1 gap resolutions (GAP-23/01/03/02/04/05/06, ADR-0010..0016): added STR-015..021; new groups REQ-AUTH, REQ-ADM, REQ-USR, REQ-SIG, REQ-EFF, REQ-DPR plus REQ-SEP-008/009 and REQ-REP-004; refined REQ-LC-010 and REQ-SIG-004. |
requirements-v1.2 |
2026-06-18 | Nicolas Burri | Tier-2 & Tier-3 gap resolutions (GAP-07..22, ADR-0017..0023): added STR-022..026; new groups REQ-NFR, REQ-NOT, REQ-I18N, REQ-REL, REQ-TRN, REQ-MIG, plus REQ-DOC-014/015/016, REQ-SEP-010, REQ-LC-012/013/014, REQ-SRCH-010, REQ-UI-005/006, REQ-REP-005/006; refined REQ-DOC-005, REQ-SEP-005, REQ-SIG-001, REQ-REP-001; adopted the MoSCoW priority convention. GAP-22 closed (all gaps resolved). |
requirements-v1.3 |
2026-06-18 | Nicolas Burri | Spec-hardening round from the 2026-06-18 spec review (Tier-B, ADR-0024..0026): CANCELLED state (REQ-LC-001/002/015); disposal/erasure mechanics — storage delete, index purge, bounded backups, manifest-as-blob (REQ-DOC-015/018, REQ-SRCH-011, REQ-DPR-011); RLS connection-pool isolation (REQ-SEP-011); field-level audit + inspection copy (REQ-AUD-001/005/006); change description on versions (REQ-DOC-017); doc-ID uniqueness/LLM-ordering/re-auth clarifications (REQ-DOC-002, REQ-SRCH-007, REQ-SIG-006); dev-plan §2 safety-classification decision. |
requirements-v1.4 |
2026-06-30 | Nicolas Burri | Implementation-round changes (ADR-0027/0028/0029, Phase 2–3): REQ-SEP-012 (RLS guards content-bearing tables; scope/mandator & catalogs/identity/authz are control-plane, permission-governed); REQ-AUTH-004/006 reworked for the stateless encrypted token-state cookie (no server-side session store; revocation by per-request re-evaluation + bounded access-token lifetime/silent refresh + key rotation; compromised-cookie residual risk accepted, RISK-003); REQ-USR-004 invite-binding requires a verified email; REQ-SIG-006 deactivation denial at next signing/step-up via per-request re-evaluation. |
requirements-v1.5 |
2026-07-05 | Nicolas Burri | Demo-feedback-round changes (ADR-0044..0047): REQ-LC-005 superseded by REQ-LC-016 (four-eyes exclusion moves from the version's creator to the round's submitter — attester ≠ approver; accepted residual recorded); REQ-UI-007 added (version diff: added/removed/changed); REQ-DOC-005 annotated + ADR-0045 trace (Markdown + image attachment parts), REQ-DOC-014 ADR-0045 trace; realized REQ-SRCH-001/004/009/011 trace ADR-0044. First generated traceability snapshot accompanies the baseline (docs/traceability/matrix.md). |
requirements-v1.6 |
2026-07-07 | Nicolas Burri | Feature-wave changes (ADR-0048..0051): REQ-DOC-019..025 (folder tree, type categories, template variables + instantiation, in-text doc: links); REQ-REL-005/006 (relation CRUD vocabulary, freeze-time fromText sync; REL-001/002 refined by annotation); REQ-REP-007/008 (declarative coverage rules, released-evidence completeness); REQ-UI-008..014 (tree navigation, category tabs, References section, traceability page, CM6 editor, [[ authoring, live-refresh/presence UI); REQ-NOT-010/011 (post-commit scope-filtered SSE push, ephemeral presence with no-clobber); REQ-SRCH-012 (label-fragment lookup); REQ-EFF-003 annotated for categories. All 21 new rows landed traceability-verified at baseline. |
| requirements-v1.7 | 2026-07-20 | Nicolas Burri | Three prepared waves folded into one baseline: (1) ADR-0064..0070 arcs — REQ-LC-017..026 (per-document workflow role bindings; withdraw-from-review; review comments incl. the resolution release gate), REQ-DOC-026..030 (FILE attachments; diagram content-part pair), REQ-UI-015..017, REQ-TRN-007/008 (questionnaires), REQ-MIG-004/005 (importer as developer tooling) + annotations. (2) ADR-0071..0075 arcs — REQ-TRN-009..011 (training plans, due-window compliance), REQ-DOC-031..033 (change reason/impact; source-history continuity; PDF export), REQ-EFF-009, REQ-UI-018..021, REQ-MIG-006; draw.io as annotations (engine swap, requirements unchanged). (3) ADR-0077..0083 + ADR-0062 — REQ-DOC-034..037 (requirement/trace items; PDF navigation; scope audit pack), REQ-REL-007/008 (item links; server-enforced draft-only), REQ-REP-009 (registry + verifies-OR-satisfies coverage), new group REQ-RISK-001..003 (ISO 14971 items, recorded-not-computed scores), REQ-UI-022..024, REQ-ADM-010 (per-view traceability permissions), REQ-MIG-007, new group REQ-SBOM-001..005 (ADR-0062 D-5), STR-027 (machine-verifiable traceability); ADR-0060/0063 annotation pass (ADR-0061 checked, not applicable to REQ-REP). 53 new software requirements + STR-027 + two new groups; product rows enter the matrix GAP-flagged pending the citation backfill (worklists below), no-code-carrier rows curated accepted-gap/future with reasons. |
| requirements-v1.8 | 2026-07-24 | Nicolas Burri | Delta for the post-v1.7 ADR-first arcs (ADR-0087..0094): new group REQ-OBL-001..004 (recurring obligations: config object, released-record completion + sweep-derivation parity, VIEW_OBLIGATIONS oversight, calendar schedules with the clamp rule), REQ-LC-027 (DIRECT release flow with the structural RECORD-only floor), REQ-DOC-038 (two-phase quarantine-bin GC, one-place reference inventory), REQ-UI-025 (one scope context), REQ-REP-010 (derived traceability report), REQ-API-006 (product version on wire + UI); annotations on REQ-LC-003, REQ-DOC-013, REQ-UI-018, REQ-REP-009 (ADR-0088 evidence classes). All 9 new rows landed traceability-VERIFIED at baseline (the arcs shipped with cited tests — no backfill worklist needed); group naming (REQ-OBL vs folding into TRN) reviewed and confirmed. |
| requirements-v1.9 | 2026-07-26 | Nicolas Burri | Stage C — the Validation & Regulatory axes (ADR-0084, five waves): new group REQ-VAL-001..005 (user-need / validation-case / design-element trace-item types, the validates edge, the strict per-scope designKind set, the derived validation matrix + CSV); new group REQ-GSP-001..002 (regulatory-ref type, the complies-with edge, the GSPR conformity view with NA_WITHOUT_JUSTIFICATION a HARD gap); REQ-UI-026 (GSPR authoring grid); annotations on REQ-REL-007, REQ-REP-010, REQ-UI-018/022/025. 276→284 rows, every new row traceability-VERIFIED at preparation (0 GAP). Delta detail + verified-by-test mapping below. |
| requirements-v2.0 | 2026-08-08 | Nicolas Burri | The five function families that shipped after v1.9 with no requirement representation, minted from the 2026-08-08 spec review (S5/S7) and its draft: new group REQ-MEM-001..006 (membership as a first-class recorded state; acceptance-gated entry carrying pre-assigned responsibilities; membership ≠ access with non-membership answered as nonexistence; anti-enumeration invitation with IdP-only credential minting; single-use, digest-stored, expiring links; membership end that never touches the person — ADR-0108); new group REQ-TD-001..003 (pinned assembly, issue-once-and-persist with hash identity, the partial copy marked as not the record, forward-only correction — ADR-0083, ADR-0104); REQ-UI-027 (the in-app manual shipped and versioned with the release, surface↔topic bidirectionality build-enforced — ADR-0099); REQ-CAT-008 (catalog bootstrap out of a guided setup as an explicit audited catalog act); REQ-ADM-011 (a fresh installation fully operable from its bootstrap administrator — ADR-0106, ADR-0107). STR-028..030 added (27 → 30 stakeholder requirements); 284 → 296 software-requirement rows. Unlike the v1.8/v1.9 rows, these enter with coverage GAPS expected: the five families ship verified by tests and the PQ walk, but their new ids are not yet cited in tests or journey station declarations, so the matrix GAP count goes 0 → 12 at this baseline. The citation/journey adoption is the registered follow-up, not a claim made here. Delta detail below. |
| requirements-v2.1 | 2026-08-16 | Nicolas Burri | The ADR-0116 maintenance-surface delta (shipped in v0.9.12): REQ-BAK-006 (the in-app EXPORT_BACKUP-gated backup act — asynchronous single-flight with a named refusal on concurrency, audited at both ends with failed runs recorded never silent, archive byte-compatible with the deploy-side producer so one restore drill covers both, attachment-hardened download; restore stays exclusively deploy-level), REQ-BAK-007 (backup evidence on the admin System surface incl. the 7-day no-verified-backup installation finding in the setup-finding grammar), REQ-ADM-012 (the admin System page: per-gate sections, the audited search-reindex act, honest read-only job heartbeats). 296 → 299 software-requirement rows; all three entered the matrix VERIFIED at minting (the v1.8 discipline — no backfill worklist). Sign-off given by Nicolas in-session 2026-08-16 and recorded on his behalf. |
The v2.0 delta (detail)¶
BASELINED 2026-08-08 — review record: Nicolas's sign-off on the draft and this review pair
("I read both files and agree with all your points"). The rows are PROMOTED verbatim from
docs/planning/requirements-v2.0-draft.md (now marked
historical); the trigger is finding S7 of the membership spec review —
the validation report's coverage derived from v1.9 while five function families were already in
the product. 12 new software requirements in two new groups plus three appended rows, and
three new stakeholder requirements:
- Memberships (ADR-0108; new group REQ-MEM): REQ-MEM-001 (invited → accepted / declined / removed as recorded state, each act audited at the mandator's own scope — the invitation is a record), REQ-MEM-002 (acceptance is what starts membership; pre-assigned responsibilities are an offer applied at acceptance, degrading to a visible gap rather than failing), REQ-MEM-003 (membership grants no content access, and a non-member sees nonexistence, not refusal — the ADR-0012 admin ≠ content line held at the tenant boundary), REQ-MEM-004 (no enumeration oracle to the inviter; credentials only via the IdP, never through LQMS — ADR-0063), REQ-MEM-005 (link hygiene: single-use, unguessable, digest-only at rest, expiring, indistinguishable failure answers), REQ-MEM-006 (ending a membership is a tenant act; existence elsewhere is untouched — only installation administration deactivates a person). A NEW group because belonging to a mandator is a distinct concern from REQ-ADM's permission/assignment machinery and REQ-USR's person lifecycle: both of those already existed while membership had no representation at all.
- Technical dossiers (ADR-0083, ADR-0104; new group REQ-TD): REQ-TD-001 (frozen pins in, one render at issue, stored bytes out under a recorded hash — the artifact of record), REQ-TD-002 (a reader missing pinned elements gets a freshly rendered partial copy visibly marked as not the record; unmarked ⇒ record), REQ-TD-003 (issued dossiers are undeletable, correction is forward-only, draft exports watermarked). A NEW group because the dossier is a deliverable assembled over documents, not a document behaviour: REQ-DOC's rows govern the versions it pins.
- In-app manual (ADR-0099): REQ-UI-027 — the manual ships inside the application and is
versioned with it, help affordances open the topic documenting their surface, and the build fails
on a missing topic, scene capture or surface link (bidirectionality enforced, not aspired to).
Renumbered from the draft's
REQ-UI-0xx. - Catalog bootstrap: REQ-CAT-008 — a guided setup that needs an absent catalog entry offers
its one-click creation to a catalog administrator as an explicit audited catalog act (types
complete with their definition, roles with the standard permission sets), and hands off honestly
to callers without the permission instead of misaddressing them. Renumbered from
REQ-CAT-0xx. - Fresh-install completion (ADR-0106, ADR-0107, ADR-0108): REQ-ADM-011 — the property the
0106/0107 arcs were built for, previously only partially implied by existing REQ-ADM rows: a
fresh installation is fully operable from its bootstrap administrator with no out-of-band data
manipulation, and every guided path is walkable to its end. Renumbered from
REQ-ADM-0xx. - Stakeholder level: STR-028 (invitation-and-acceptance membership, separate from access, with no cross-organization effect — ADR-0108), STR-029 (an issued dossier is a persisted, byte-stable, hash-identified record; a non-record copy says so — ADR-0083, ADR-0104), STR-030 (the system carries its own versioned user documentation — ADR-0099). The house STR table carries no trace column, so those ADR references live here rather than in the row.
Coverage honesty at this baseline (the difference from v1.8/v1.9): those two deltas backfilled citations in the same pass and landed at GAP zero. This one does not — the twelve new ids enter the matrix as GAPs because no test or journey station cites them yet, while the behaviour itself is covered (the ADR-0108 arc, the dossier arc, the manual lint, the 0106/0107 arcs all shipped with tests, and the PQ walk's station 14 exercises the membership half). What is missing is the citation, not the verification. Registered follow-up, in order: cite the new ids in the tests that already exercise them, adopt them in the journey station declarations (the dossier station and station 14, per the draft's own note), and bring the validation report's §4 intended-use narrative current with dossiers and membership.
The v1.9 delta (detail)¶
BASELINED 2026-07-26 — sign-off given by Nicolas in-session and recorded on his behalf at his
explicit request (the tag annotation carries the same provenance). Delta for Stage C — the Validation
& Regulatory axes (ADR-0084, all five waves merged 2026-07-24), which closes the two remaining trace
axes of the traceability model and brings the trace web to all five axes at item level (requirements,
risk, design, validation, regulatory). 8 new software requirements in two new groups plus one
new REQ-UI row and five annotations. Like the v1.8 preparation (and unlike v1.7), the citations were
backfilled in the SAME pass, so every new row lands verified at preparation — the matrix GAP count
stays ZERO and no new override was needed (every arc shipped with dedicated tests):
- Validation axis (ADR-0084 Waves 2-3): new group REQ-VAL — REQ-VAL-001 (the
user-needtrace-item type, attrsource, thevalidatestarget), REQ-VAL-002 (thevalidation-casetype, attrintendedUseRef, - the new
validatesedge, item- AND document-level), REQ-VAL-003 (thedesign-elementtype, attrdesignKind, + design-element as a newsatisfiesSOURCE), REQ-VAL-004 (the STRICT per-scopedesignKindvalue set — shipped defaultarchitecture|interface|component|unit, per-scope override, server 422 on an unknown value, RLS — the OQ-3 decision), REQ-VAL-005 (the derived validation-matrix view + flat CSV + the three gap flags + the design-realization leg, reusing the ADR-0088 evidence classing). - Regulatory axis (ADR-0084 Waves 4-5): new group REQ-GSP — REQ-GSP-001 (the
regulatory-reftype with the hash-frozen attrssource | clause | applicability | justification, GSPR-as-content per ADR-0061 D-5, + the newcomplies-withedge from a requirement AND a design-element), REQ-GSP-002 (the derived GSPR conformity view + flat CSV + the four gap verdicts, with NA_WITHOUT_JUSTIFICATION a HARD gap per OQ-8). Two groups (not one) mirror the RISK-is-its-own-domain-group precedent and ADR-0084's explicit two-axis framing: design validation (ISO 13485 §7.3) and regulatory conformity (MDR Annex I / GSPR) are distinct regulatory bases, and the regulatory axis will grow (the Annex II §4 dossier consumes the conformity view later, ADR-0083 note).design-elementsits in REQ-VAL (its Wave-2 home) though it sources both axes. - GSPR authoring grid (OQ-7 — Nicolas's deliberate override of the defer lean): REQ-UI-026, the
table-shaped authoring/reading surface over regulatory-ref items, each row IS a
:::regulatory-refblock (mirrors the risk grid REQ-UI-023). - Annotations (no new row): REQ-REL-007 (the trace-link vocabulary gains
validates+complies-with, andsatisfiesgains the design-element source); REQ-REP-010 (the derived traceability report now composes a validation-matrix and a GSPR-conformity section with matching digest lines — the two axes ride the one report and its single audit-pack entry, so no separate audit-pack artifact/row); REQ-UI-022 (the reserved validation / GSPR hub tiles are now live); REQ-UI-018 (the per-scope design-kind vocabulary editor landed as an ACTIVATE_CATALOG_ENTRIES field on the Document-types tab per the "new knobs land as fields" rule); REQ-UI-025 (the validation-matrix and GSPR-conformity pages join the one-scope-context list).
Deliberately NOT given rows (checked this pass; judgment rule 3): the Wave-1 schema-driven attribute UI
(the dialog collapse onto TraceItemDialog, −316 lines) is a behavior-frozen frontend refactor (projection
byte-identical, engines zero-diff) with no new user-visible behavior — it is the mechanism the new type rows
author through, covered by REQ-DOC-035's additive-registration principle, not a requirement of its own; the
may-define extension to the six/seven types rides REQ-DOC-034's existing per-(scope, type) flag mechanism
(each new type row states its gate, exactly as REQ-RISK-002 does), so no new row; the report-section +
audit-pack integration rides the REQ-REP-010 annotation above (the sections are part of the one derived
report). No new schema content COLUMN ships (trace-item attributes live inside the tree, ADR-0057; the only
DB touch is the trace_link CHECK + the design_kind_vocabulary config table, V067), so the
schema-extension lifecycle audit fires only for RLS-separation-per-new-type — covered by
DesignKindVocabularyRlsSeparationTest and RegulatoryLinkRlsSeparationTest.
Verified-by-test mapping for the v1.9 delta (each id cited at the most specific carrier):
| Requirement | Verifying test(s) |
|---|---|
| REQ-VAL-001 | ValidationAxisRegistryTest (user-need registration + fence + content-hash contract); ValidationAxisSaveTest (per-(scope,type) may-define gate); PdfExportServiceTest (the user-need fence renders formatted, not a raw literal); validation-axis.spec.ts (slash-gating + dialog authoring) |
| REQ-VAL-002 | ValidationAxisRegistryTest; ValidationAxisSaveTest (the validates edge — item-level AND document-level); PdfExportServiceTest (validation-case fence); validation-axis.spec.ts |
| REQ-VAL-003 | ValidationAxisRegistryTest; ValidationAxisSaveTest (design-element saves; satisfies gains the design-element source); PdfExportServiceTest (design-element fence); validation-axis.spec.ts |
| REQ-VAL-004 | DesignKindVocabularyRlsSeparationTest (cross-scope isolation of the value set at the DB level); ValidationAxisSaveTest (default OK / unset OK / unknown → 422 / override changes the set / clear reverts); validation-axis.spec.ts (designKind enum resolved from the scope's set) |
| REQ-VAL-005 | ValidationMatrixLogicTest (derivation, the three gap flags, ADR-0088 classing, RLS degradation); ValidationMatrixResourceTest (JSON + CSV matrix + VIEW_TRACEABILITY 403 + cross-scope separation); validation-matrix.spec.ts (sub-page + hub tile + one-scope-context) |
| REQ-GSP-001 | RegulatoryAxisRegistryTest (regulatory-ref registration + hash-frozen attr order); RegulatoryAxisSaveTest (may-define gate; empty-justification N/A saves; complies-with from a requirement AND a design-element); RegulatoryLinkRlsSeparationTest (the complies-with edge RLS separation); PdfExportServiceTest (regulatory-ref fence); regulatory-axis.spec.ts (slash-gating + dialog) |
| REQ-GSP-002 | GsprConformityLogicTest (the four gap verdicts incl. NA_WITHOUT_JUSTIFICATION as a HARD gap, ADR-0088 classing, clause ordering, RLS degradation); GsprConformityResourceTest (JSON + gap verdicts + CSV + VIEW_TRACEABILITY 403); gspr-conformity.spec.ts (sub-page + hub tile + the unjustified-N/A hard-gap chip) |
| REQ-UI-026 | regulatory-axis.spec.ts (the GSPR grid authors a row and a cell edit round-trips to the prose block) |
Still without rows at this preparation (checked, deferred): the ADR-0086 requirement trace chains +
CSV path export and the ADR-0085 relation-layer consolidation — Stage C's two views COMPOSE the chains read
model (RequirementChainLogic) but add no rows for it; those pre-Stage-C arcs remain the "known
later-increment candidates" below for a dedicated coverage audit, out of this Stage-C-scoped delta.
Released 2026-07-24 (was: prepared). Delta for the arcs that landed ADR-first after the
v1.7 baseline (ADR-0087..0094); 9 new software requirements in one new group plus
annotations, bringing the baseline back to covering the shipped system. Unlike the v1.7
preparation, the citations were backfilled in the SAME pass, so every new row lands verified
(matrix GAP unchanged at zero) — no new override was needed, all arcs shipped with dedicated tests:
- Recurring obligations (ADR-0089; calendar schedules ADR-0094): new group REQ-OBL —
REQ-OBL-001 (per-scope obligation config, RECORD completion type, CONFIGURE_REVIEW_POLICY CRUD,
RLS), REQ-OBL-002 (completion-by-released-record; derived-never-stored status; the self-contained
sweep raises/reconciles the non-manually-resolvable
OBLIGATION_DUEtask; sweep–derivation parity), REQ-OBL-003 (VIEW_OBLIGATIONSoversight roll-up), REQ-OBL-004 (INTERVAL/MONTHLY/YEARLY kinds, the never-too-late clamp, occurrence-after-anchor next-due, calendar parity). A NEW group because recurring QMS-operations duties (ISO 13485 §6.3) are a distinct concern from REQ-TRN's person-and-document read-acknowledgement. - DIRECT release flow (ADR-0091): REQ-LC-027 (STANDARD/DIRECT release flow — single-person DRAFT→RELEASED for RECORD-category types only, releaser-gated, guardrails preserved); REQ-LC-003 annotated (the release-flow axis, orthogonal to REQ-LC-007's release mode); REQ-UI-018 annotated (the knob landed as a Review-policies field per its own rule).
- Orphan-blob quarantine bin (ADR-0092): REQ-DOC-038 (two-phase quarantine→purge, 30-day bin,
registry-not-file-move, the column-inventory architecture test, self-healing), refining REQ-DOC-013
(annotated; the base GC row itself flipped GAP→
verifiedin the same wave). - One scope context (ADR-0093): REQ-UI-025 (the toolbar switcher is the only scope filter; neutral picker on ALL for per-scope views; display-filter-only — the server still authorizes).
- Scope traceability report (ADR-0087): REQ-REP-010 (the derived per-scope gap-digest PDF,
VIEW_TRACEABILITY-gated, hub download + permission-conditional audit-pack entry). - Product version (ADR-0090 §3): REQ-API-006 (
productVersionvia/api/version+ the UI build/version display;EXPORTED-event tool version). - Verification evidence classes (ADR-0088): no new row — a refinement annotated on REQ-REP-009
(verified vs planned
verifiesclasses, reported as separate counts; the fully-verified roll-up).
Already covered (checked this pass, no row needed): OpenAPI generation (REQ-API-004 — verified
via OpenApiSpecTest); USER_BOUND invite-binding audit (REQ-USR-010 — verified via
UserProvisioningTest). Deliberately NOT given rows: the ADR-0089 §5 optional trace-tie and the
ADR-0088 §5 freshness-as-a-rule (optional / not built).
Verified-by-test mapping for the v1.8 delta (each id cited at the most specific carrier):
| Requirement | Verifying test(s) |
|---|---|
| REQ-OBL-001 | RecurringObligationTest (RLS separation; CONFIGURE_REVIEW_POLICY CRUD gate); RecurringObligationResourceTest; obligations.spec.ts (scope-config Obligations tab) |
| REQ-OBL-002 | RecurringObligationTest (derived status: no-execution/fresh/due-soon/overdue, completion-anchored); RecurringObligationSweepTest (raise/idempotent/auto-resolve) |
| REQ-OBL-003 | RecurringObligationTest (VIEW_OBLIGATIONS oversight gate); RecurringObligationResourceTest (oversight 403); obligations.spec.ts (oversight page + route guard) |
| REQ-OBL-004 | ObligationScheduleTest (kinds, clamp, next-due parity, per-kind validation) |
| REQ-LC-027 | DirectReleaseTest (happy path, non-releaser 403, comments gate, STANDARD refuses direct, action reflection); direct-release.spec.ts; obligations.spec.ts (release-flow control, RECORD-only) |
| REQ-DOC-038 | BlobGcSweepServiceTest (quarantine→purge round trip, never-delete-referenced, rescue, purge-time re-verify); BlobHashColumnInventoryTest (column-inventory architecture test) |
| REQ-UI-025 | scope-context.spec.ts (one context; neutral picker; deep link) |
| REQ-REP-010 | TraceabilityReportResourceTest (PDF + hardening headers + VIEW_TRACEABILITY/cross-scope 403); traceability-hub.spec.ts (hub download delivery) |
| REQ-API-006 | build-info.spec.ts (product version leads the build stamps; pre-release "unreleased") |
v1.7 citation-backfill worklist — COMPLETE. The 27 rows below (prepared GAP at v1.7) were
promoted to verified by citing their ids in the named tests; the matrix now reports GAP ZERO.
Retained as the provenance of that promotion:
| Requirement | Verifying test(s) |
|---|---|
| REQ-TRN-009 | TrainingPlanServiceTest (self-record/four-eyes-confirm/supersede/evidence/renewal-sweep) |
| REQ-TRN-010 | TrainingPlanServiceTest (derived obligations); my-training.spec.ts |
| REQ-TRN-011 | TrainingComplianceServiceTest (roll-up, overdue boundary, neutral-release anchor); EndpointBodyBindingTest (due-window) |
| REQ-DOC-031 | DocumentServiceTest (reason+impact ride the revision; setChangeInfo freeze/409/v1); LifecycleServiceTest (SUBMIT pins reason+impact); EndpointBodyBindingTest |
| REQ-DOC-032 | DocumentServiceTest (startAtVersion continuity; source-history claims record; red-line audit actors); DisposalServiceTest (source_history severed) |
| REQ-DOC-033 | PdfExportServiceTest (stamped/audited PDF; DRAFT/IN_REVIEW 409; REVOKED + cross-scope 404; mermaid label; alt placeholder); pdf-export.spec.ts |
| REQ-EFF-009 | DocumentServiceTest (effectiveStanding / listVersions over backdated effective_from) — backfill target |
| REQ-UI-018 | ScopeConfigReadResourceTest (type catalog); scope-config.spec.ts (tab gating, redirect) |
| REQ-UI-019 | my-training.spec.ts (plan render, record, dashboard, compliance/aging) |
| REQ-UI-020 | pdf-export.spec.ts (Download PDF on RELEASED/REVOKED; absent on DRAFT/IN_REVIEW) |
| REQ-UI-021 | change-reason.spec.ts (revise requires reason; IN_REVIEW prominence; v1 empty; editor edit) |
| REQ-DOC-034 | RequirementLogicTest, RequirementRegistryServiceTest; requirement.spec.ts |
| REQ-DOC-035 | TraceItemGeneralizationTest (synthetic second type — registry/links/suspect/coverage, zero engine change) |
| REQ-DOC-036 | PdfExportServiceTest (bookmarks/anchors, context-dependent doc: links, merged ToC/chapters); pdf-export.spec.ts |
| REQ-DOC-037 | PdfExportServiceTest (streamed zip, sha256 manifest, citation closure, completeness marker); audit-pack.spec.ts |
| REQ-REL-007 | RequirementLinkServiceTest (edge vocabulary, suspect, dedupe/self-edge); requirement-links.spec.ts |
| REQ-REL-008 | RequirementLinkServiceTest + RelationServiceTest (source-must-have-DRAFT 409; clearSuspect exempt) |
| REQ-REP-009 | RequirementRegistryServiceTest, TraceMatrixTest (verifies-OR-satisfies separate counts, uncovered list); traceability.spec.ts |
| REQ-RISK-001 | RiskTraceItemTest (attribute set, recorded tokens); risk.spec.ts |
| REQ-RISK-002 | RiskTraceItemTest (controlKind; mitigates/implemented-by/verifies edges) |
| REQ-RISK-003 | RiskTraceItemTest (gap flags, accepted-without-reduction, document implemented-by clears); risk.spec.ts |
| REQ-UI-022 | traceability-hub.spec.ts, traceability.spec.ts, traceability-training.spec.ts |
| REQ-UI-023 | risk-grid.spec.ts |
| REQ-UI-024 | audit-pack.spec.ts |
| REQ-ADM-010 | TraceabilityPermissionSeparationTest; CoverageResourceTest, RelationResourceTest (per-view server gate) |
Known later-increment row candidates (arcs still without rows): periodic-review status visibility (ADR-0076/V054 — deferred at v1.7 preparation); the ADR-0083 dossier proper (SectionPin, regulatory skeletons, DRAFT→ISSUED) when built; the requirement trace chains + CSV path export (ADR-0086) and the relation-layer consolidation (ADR-0085) — their shipped slices need a coverage audit at the next preparation to decide whether they warrant their own rows or ride existing ones. (Single-person record release is now built — REQ-LC-027, this delta.)
Requirements specification for LQMS, in two levels:
- Stakeholder requirements (
STR-NNN) — the intended use; what CSV validation validates against. One file: stakeholder_requirements.md. - Software requirements (
REQ-<GROUP>-NNN) — testable system behavior; what verification tests against. Every software requirement traces to at least one STR and, where applicable, the deciding ADR.
LQMS is a pure software product, so no separate "system requirements" level exists — the software level is the system level. (Requirement documents of user projects managed inside LQMS are QMS content and out of scope.)
Known coverage gaps and ambiguities in the current baseline are tracked in gap-analysis.md (a working document, not part of the baseline); they feed change-control rounds.
Structure¶
| File | Group | Prefix |
|---|---|---|
| stakeholder_requirements.md | Intended use | STR |
| req_documents.md | Documents, versions & storage | REQ-DOC |
| req_lifecycle.md | Life cycle & reviews | REQ-LC |
| req_separation.md | Scopes, mandators & separation | REQ-SEP |
| req_auth.md | Authentication & session | REQ-AUTH |
| req_admin.md | Administration, permissions & onboarding | REQ-ADM |
| req_users.md | User identity & lifecycle | REQ-USR |
| req_signatures.md | Electronic signatures | REQ-SIG |
| req_effectivity.md | Effectivity, periodic review & validity | REQ-EFF |
| req_data_protection.md | Data protection, retention & disposal | REQ-DPR |
| req_catalogs.md | Catalogs, roles & users | REQ-CAT |
| req_search.md | Search | REQ-SRCH |
| req_backup.md | Backup & restore | REQ-BAK |
| req_audit_reporting.md | Audit trail & regulatory reporting | REQ-AUD / REQ-REP |
| req_api_ui.md | API & user interface | REQ-API / REQ-UI |
| req_nfr.md | Non-functional (capacity, availability, security) | REQ-NFR |
| req_notifications.md | Notifications & tasks | REQ-NOT |
| req_i18n.md | Internationalization (content language, time zones) | REQ-I18N |
| req_relationships.md | Document relationships | REQ-REL |
| req_migration.md | Migration & import | REQ-MIG |
| req_training.md | Read-acknowledgement & questionnaires | REQ-TRN |
| req_obligations.md | Recurring obligations (periodic QMS duties) | REQ-OBL |
| req_risk.md | Risk management (ISO 14971 hazards & controls) | REQ-RISK |
| req_validation.md | Design validation & the validation traceability axis | REQ-VAL |
| req_gspr.md | Regulatory conformity (GSPR / essential principles) | REQ-GSP |
| req_sbom.md | Software bill of materials & supply-chain assurance | REQ-SBOM |
| req_memberships.md | Mandator membership & invitations | REQ-MEM |
| req_dossiers.md | Technical documentation dossiers | REQ-TD |
Conventions¶
- IDs are never reused after deletion; superseded requirements are struck through with a pointer to their successor, not removed.
- Each software requirement is individually testable; the trace column lists the satisfied STRs and deciding ADRs.
- Requirement → test traceability is maintained per the verification plan.
- Open details inside a requirement are marked
TBD:like everywhere else in the docs. - Requirements carry a MoSCoW priority (Must / Should / Could / Won't) to enable MVP sequencing (GAP-21); the initial classification is done as a dedicated pass when implementation is planned, rather than retrofitted to every requirement now.
Traceability¶
A generated requirements-traceability matrix links every requirement to its test,
implementation, and commit evidence and flags untraced gaps — see
../traceability/ (regenerate with
python3 scripts/generate-traceability.py).