

Phase 1 readiness
This workbook defines the minimum information and people required to turn Phase 1 into a decision-ready architecture and implementation plan within ten business days.
Named decision owners with authority to resolve product, technical, security, and commercial questions.
Relevant code, AWS topology, APIs, current agents, checkout SDK, data, and operational controls.
One representative customer journey, real failure examples, and measurable acceptance criteria.


Name the owners
| Role | Responsibility | Name | Availability |
|---|---|---|---|
| Executive sponsor | Outcome, budget, scope, escalation, final acceptance | Yash Daftary | ____________ |
| Product owner | Customer journeys, admin experience, roadmap, priorities | Alisha Mody | ____________ |
| Technical owner | Codebase, APIs, identity, integration, implementation constraints | Bhavin or delegate | ____________ |
| AWS/security owner | Cloud boundary, IAM, network, logs, compliance, access approval | ____________ | ____________ |
| Checkout SDK owner | Third-party embed flow, keys, publishing, supported patterns | ____________ | ____________ |
| AI/agent owner | Current agents, prompts, tools, evaluations, failure cases | ____________ | ____________ |


Minimum viable access


Open the working lane
GitHub: @robertohluna
Email: roberto@miosa.ai
Open a shared Slack channel or equivalent thread that includes the Commas product owner, technical owner, relevant development leads, and Roberto.
A Commas engineer should walk MIOSA through the relevant repository or repositories, the local development path, and the production boundary.
Begin with source access and nonproduction documentation. Expand access only when a discovery finding requires it and the responsible Commas owner approves it.


One flow end to end
| User | Who performs the work? What do they know? What can they approve? |
|---|---|
| Trigger | What event or intent starts the journey? |
| Inputs | What facts, files, answers, APIs, and business context are required? |
| Process | What does the agent plan, create, verify, and hand off? |
| Output | What exactly becomes reviewable and publishable? |
| Official state | What is written back into Commas after approval? |
| Policy gates | What is prohibited, flagged, rate-limited, or escalated? |
| Evidence | What proves what happened and why? |
| Outcome | What business result is observed later? |
| Success | What completion, quality, cost, safety, and performance thresholds matter? |


90-minute working session
Confirm Phase 1 decision, first use case, non-goals, commercial concerns, and immovable product or compliance rules.
Walk the new-creator and embedded-checkout flows. Select the proof and name its success measures.
Review Commas services, identity, org/workspace model, AWS, current agents, APIs, and official state.
Define allowed data, secrets, approvals, hard prohibitions, cross-tenant learning, and incident expectations.
Confirm owners, access, working sessions, midpoint checkpoint, Miami review, blockers, and next action.
Named use case, owner map, access register, decision log, known risks, and the Phase 1 execution calendar.