Requirement status
docs/requirements-catalog.csv · status map: packages/curriculum/src/requirements/status.ts.PDT-001
Product thesis & guardrails
The product shall be sold primarily as a credit-union-sponsored family financial capability benefit, with a parent/guardian as the household account owner.
Acceptance: A CU can launch a branded member benefit without requiring a child to become a bank customer.
Tenant = credit union; the guardian owns the household; children are profiles, never customers or account holders.
packages/db/src/schema/family.ts/r/riverton/join/rivertonPDT-002
Product thesis & guardrails
The core learner proposition shall be real-world money decision practice, not completion of a large content library.
Acceptance: Kid home prioritizes one next mission and a small number of recommended missions.
Kid home shows one primary next mission plus at most two suggestions.
/kidPDT-003
Product thesis & guardrails
The product shall support a zero-integration launch path.
Acceptance: A CU can deploy via branded URL/QR/invitation without core banking, transaction data, or SSO.
Hosted co-branded landing page, QR code, access code and parent self-enrollment — no core banking, transaction data or SSO.
/r/riverton/join/riverton/cuPDT-004
Product thesis & guardrails
Banking integration, SSO, and embedded delivery shall be optional enhancements rather than purchase prerequisites.
Acceptance: The sales proposal and onboarding flow do not block launch on integration work.
No integration step exists anywhere in launch or onboarding; banking/SSO/embedded delivery are not required.
PDT-005
Product thesis & guardrails
The platform shall not require children to connect bank accounts, debit cards, credit reports, brokerage accounts, or payment credentials to learn.
Acceptance: Every curriculum mission offers a play-money or fictional alternative where applicable.
No bank, card, credit or payment connections exist in the product; every mission schema requires a play-money alternative.
packages/curriculum/src/schema.tsPDT-006
Product thesis & guardrails
The platform shall not provide individualized investment, credit, tax, legal, or insurance recommendations to children.
Acceptance: Content stays educational and uses reviewed examples rather than personalized recommendations.
Seed content is educational; the advice-boundary gate blocks personalized investing/credit/tax/insurance recommendations.
packages/curriculum/src/quality/lexicon.tsPDT-007
Product thesis & guardrails
The core child experience shall not include unrestricted generative-AI chat.
Acceptance: All child-facing learning content is pre-reviewed or constrained to approved interactive structures.
Children only use constrained, reviewed mission structures; Creator Chat is restricted to Innorve roles.
apps/web/src/app/studioPDT-008
Product thesis & guardrails
No child learning response shall be used to target credit products, determine creditworthiness, or create a marketing profile.
Acceptance: CU reporting excludes child-level marketing segments based on lesson behavior.
CU analytics are aggregate only; no child-level segments; referrals count only explicit adult actions.
PDT-009
Product thesis & guardrails
The platform shall separate educational outcomes from commercial outcomes.
Acceptance: Dashboards label participation/learning separately from optional parent-initiated product referrals.
Impact Dashboard and Community Report separate learning/participation from optional adult-initiated referrals.
/cu/impact/cu/reportPDT-010
Product thesis & guardrails
The product shall be capable of operating under the credit union’s brand while retaining clear “powered by Innorve” disclosure when contractually required.
Acceptance: White-label settings can be configured per institution without changing curriculum integrity.
Per-tenant brand theming with a configurable “Powered by Innorve” disclosure; curriculum content is unaffected.
KID-001
Kid experience
Kids shall enter through an age-appropriate home experience that presents one primary mission, progress, and a small set of choices.
Acceptance: A child can identify what to do next within one screen.
One screen: greeting, one big next-mission card, Skill Passport progress, booked Money Lab, two more options.
/kidKID-002
Kid experience
Missions shall follow a repeatable pattern: hook/story → decision → explanation → real-world or play-money practice → reflection → transfer challenge.
Acceptance: Every published mission includes all six components or an approved exception.
Mission player enforces story → choice → explain → practice → reflect → transfer; publish readiness checks all six.
packages/curriculum/src/schema.tsKID-003
Kid experience
Kids shall be able to complete core missions without disclosing household income, balances, or sensitive family circumstances.
Acceptance: No core mission requires private financial data.
No mission asks for private financial data; the privacy gate blocks household-finance prompts.
packages/curriculum/src/quality/lexicon.tsKID-004
Kid experience
The platform shall support distinct learner modes for ages 5–7, 8–12, 13–15, and 16–17.
Acceptance: The same topic can render different language, complexity, activity, and autonomy by age band.
All four learner modes are modeled; the $5 Challenge renders distinct 5–7 (pretend play with a grown-up), 8–12 (weekly plan) and 13–15 (work-time) versions, and the degree mission a 16–17 version. Teen lessons are never shrunk for younger bands.
packages/curriculum/src/missions/five-dollar-challenge.tspackages/curriculum/src/missions/missions.test.tsKID-009
Kid experience
The platform shall use a “Skill Passport” rather than a single financial score.
Acceptance: Learners see specific skills practiced and context, not wealth ranking or a universal grade.
Skill Passport lists specific skills with evidence — no score, grade or ranking.
/kid/passport/parentKID-010
Kid experience
Skill evidence shall distinguish scenario understanding, self-reported practice, parent-observed practice, and facilitator-observed practice.
Acceptance: Progress labels show evidence type.
Evidence is always labeled by type: scenario and transfer (missions), self-reported (“I tried it in real life” on the passport, once per skill per day), parent-observed and facilitator-observed.
packages/curriculum/src/taxonomy.ts/kid/passportKID-011
Kid experience
Kids shall be able to explain or revise a choice; the platform shall not reward only the cheapest or most frugal option.
Acceptance: A well-explained spend decision can earn successful completion when it meets the learning objective.
Success requires naming the tradeoff, not choosing the cheapest option; learners can revise. Covered by unit tests.
packages/curriculum/src/evaluation.tspackages/curriculum/src/evaluation.test.tsKID-012
Kid experience
The platform shall avoid public leaderboards based on money saved, family wealth, allowance size, or real-dollar balances.
Acceptance: Gamification ranks no child by financial resources.
No leaderboards or rankings exist anywhere.
KID-013
Kid experience
Kids shall earn non-cash recognition for practice, explanation, persistence, and transfer of skills.
Acceptance: Badges/coins relate to skills and effort.
Non-cash Skill Stars for explanation, transfer and persistence (“kept going”).
KID-014
Kid experience
Real-world activities shall include a no-spend/play-money alternative.
Acceptance: Families can participate regardless of discretionary budget.
Play-money practice in every mission; every parent activity has a no-spend option.
KID-015
Kid experience
The learner shall be able to pause or exit sensitive activities without penalty.
Acceptance: No streak loss or shame language occurs when a mission is skipped.
“I'll finish later” saves progress on every step; no streaks, no penalty, no shame copy.
KID-017
Kid experience
Kids shall not be encouraged to disclose personal family financial conflict in peer spaces.
Acceptance: Prompts focus on fictional or voluntary examples.
Stories are fictional; reflections are private; the privacy gate flags peer-disclosure prompts.
KID-018
Kid experience
The product shall not use shame, fear, or anxiety as a motivation strategy.
Acceptance: Editorial review flags scarcity/fear messaging aimed at children.
Tone gate flags shame, fear, labels and universal rules; seed content passes.
packages/curriculum/src/qualityKID-020
Kid experience
Kids shall have a safe completion celebration that reinforces the skill learned, not a product purchase.
Acceptance: Completion screen names the skill and next practice opportunity.
Celebration names the skill, shows evidence and a real-life practice tip — never a product.
PAR-001
Parent/guardian
The parent/guardian shall be the household owner and control child enrollment, consent, age band, and communication settings.
Acceptance: A child under required consent age cannot activate independently.
Children have no accounts; only the guardian can start kid mode, and only for consented profiles; leaving kid mode needs the household PIN.
apps/web/src/server/actions/session.tsPAR-002
Parent/guardian
Parents shall be able to create and manage multiple child profiles with age-appropriate experiences.
Acceptance: One household can support siblings without sharing progress incorrectly.
Multiple child profiles (Mia 8–12, Leo 13–15) with separate progress and age-appropriate content; add-child flow.
/parent/parent/children/newPAR-003
Parent/guardian
Parent onboarding shall explain what the program teaches, what data is collected, what the CU can see, and what remains private.
Acceptance: Consent screen uses plain language and explicit data categories.
Add-child consent screen lists what's collected, what the CU sees and what stays private, in plain language.
/parent/children/newPAR-004
Parent/guardian
Parents shall receive one concise “conversation prompt” for each mission.
Acceptance: Parent prep is typically possible in under three minutes.
One conversation prompt per mission with prep under three minutes.
/parentPAR-005
Parent/guardian
Parents shall receive optional real-world activity suggestions but shall not be required to reveal bank balances or income.
Acceptance: Activities can use fictional/play money.
Optional activities with a play-money/no-spend alternative; no balances or income requested.
PAR-006
Parent/guardian
Parents shall be able to choose family priorities such as planning, spending, saving, earning, future choices, digital money, or big decisions.
Acceptance: Recommendations can use parent-selected topics without inferring sensitive traits.
Family priorities and topic choices rank kid-home suggestions ahead of sponsor featuring; inputs are guardian choices, lab follow-ups and the child's own progress only, and parents see the reasons in plain language. Unit-tested.
packages/curriculum/src/recommendation.ts/parentPAR-007
Parent/guardian
Parents shall be able to approve, hide, or postpone topics that do not fit their family context.
Acceptance: A hidden topic does not continue to surface as a required task.
Include / prioritize / not yet / hide per topic; hidden and postponed topics never surface to the child.
PAR-008
Parent/guardian
Parents shall see child skill progress with evidence labels and plain-language explanations.
Acceptance: Dashboard distinguishes “completed in app” from “practiced at home.”
Passport separates “Completed in app”, “Practiced at home” and “Money Lab” evidence with explanations.
/parentPAR-009
Parent/guardian
Parents shall not be given diagnostic labels such as “spendthrift child,” “impulsive child,” or psychological risk scores.
Acceptance: Behavioral science informs design but is not presented as a diagnosis.
No diagnostic labels anywhere; the tone gate flags labels such as “spendthrift”.
PAR-010
Parent/guardian
Parents shall be able to book Innorve live cohorts, workshops, and family Money Labs from within the experience.
Acceptance: Available sessions show age band, facilitator, date/time, format, capacity, sponsorship, and requirements.
Book Money Labs in-app with age band, facilitator, date/time, format, capacity, sponsorship and requirements shown.
/parent/labs/parent/labs/lab_25_weekendPAR-011
Parent/guardian
Parents shall be able to register one or more children for a sponsored cohort without entering payment when the CU covers the seat.
Acceptance: CU-sponsored seats display $0 and sponsor identity.
Book one or more children with no payment step; seats show $0 and the sponsoring CU.
PAR-013
Parent/guardian
Parents shall receive cohort reminders, preparation guidance, post-session recap, and follow-up missions.
Acceptance: Booking lifecycle is visible from the parent dashboard.
Booking timeline is visible from the parent dashboard. The scheduler sends prep three days before, a reminder the day before, a push 15 minutes before, and the recap two hours after the session ends. Preferences, quiet hours (9 PM–8 AM) and SMS STOP still apply. A child is never a recipient.
apps/web/src/server/family/scheduler.ts/api/cron/notifications/familyPAR-014
Parent/guardian
Parents shall be able to request deletion/export of covered child data and close a child profile subject to applicable retention obligations.
Acceptance: Privacy controls are available without contacting sales.
In-product JSON export, close profile and immediate deletion, recorded as privacy requests.
/parent/privacy/api/privacy/exportPAR-015
Parent/guardian
Parents shall be able to initiate contact with their credit union for relevant family financial resources, but child learning behavior shall not auto-trigger sales.
Acceptance: Product/referral actions require explicit adult initiation.
Adult-directed resource cards are separated from missions; a referral is recorded only when the adult asks.
/parentCU-001
Credit-union workspace
A credit union shall be able to launch a co-branded program without a core-banking integration.
Acceptance: Hosted branded landing page, QR code, and member invitation mechanism are sufficient for launch.
Hosted landing page, QR code and access-code enrollment are sufficient to launch.
/r/riverton/cuCU-003
Credit-union workspace
The CU shall be able to choose which age bands and curriculum collections are offered.
Acceptance: Admin can enable/disable collections without editing lesson content.
Toggle age bands and collections without editing lesson content.
/cu/libraryCU-004
Credit-union workspace
The CU shall have a pre-approved starter program configuration that can launch with minimal decisions.
Acceptance: Default setup includes missions, parent hub, marketing kit, and at least one cohort offering.
An Innorve admin provisions a setup tenant from the approved standard package: family app, parent hub, licensed mission collections, campaign kit, aggregate reporting, and a cohort seat offering. Curriculum rows are referenced, not copied. The tenant is not live.
/admin/institutionspackages/db/src/provision.tsCU-005
Credit-union workspace
The CU shall be able to invite families using QR codes, public member links, access codes, or optional member-directed invitations.
Acceptance: No member list upload is required for standard launch.
QR codes, public link and access code (member-directed invitations reuse the link); no member list upload.
/cuCU-006
Credit-union workspace
The CU shall be able to sponsor cohort seats and set eligibility windows and seat limits.
Acceptance: Parent booking reflects sponsor availability and waitlist status.
The program owner sets the eligibility window and seats per household on Sponsored seats. Who qualifies is enrolment only. A parent can't book a sponsored seat outside the window, or more children than the household limit on that session.
/cu/seatsCU-007
Credit-union workspace
The CU shall be able to request custom curriculum in natural language without directly publishing unreviewed child content.
Acceptance: Custom request enters Innorve review workflow.
Natural-language custom requests land in the Studio inbox and go through Innorve review; the CU cannot publish.
/cu/requests/studioCU-008
Credit-union workspace
The CU shall have a dashboard for activation, enrollment, mission starts, repeat participation, cohort bookings/attendance, age-band mix, and skill-practice aggregates.
Acceptance: Dashboard contains definitions and denominators.
Dashboard with activation funnel, denominators, definitions, age-band mix, skill aggregates and cohorts (synthetic baseline + live demo counts).
/cu/impactCU-009
Credit-union workspace
The CU shall not receive private child reflections, raw family financial details, or unapproved child-level behavioral profiles.
Acceptance: Institution analytics are aggregate or operationally necessary and policy-approved.
CU surfaces read aggregates only; no reflections, answers or child profiles.
CU-010
Credit-union workspace
The CU shall be able to download a board/community-impact report with branding and methodology notes.
Acceptance: Report differentiates reach, participation, learning evidence, and optional referrals.
Branded board report with a page-1 preview and a downloadable PDF. Methodology notes separate reach, participation, learning evidence and adult-initiated referrals.
/cu/reportsCU-011
Credit-union workspace
The CU shall receive ready-to-use email, SMS, social, branch, Youth Month, school/community, and event campaign templates.
Acceptance: Campaign kit can be exported or copied without a designer.
Email, SMS, social, branch flyer, poster, school/community flyer, Youth Month and event templates; copy or download the kit.
/cu/campaigns/api/cu/campaign-kitCU-012
Credit-union workspace
The CU shall have staff talking points explaining the product in under 60 seconds.
Acceptance: A branch/community employee can explain member value without financial-advice claims.
Staff talking points at /cu/talking-points: four lines under a minute, play money labelled, no child account, parents don't share finances, and the credit union sees totals only. Four don't-say lines block an outcome claim, an NCUA claim, opening an account first, and seeing how a child spends. Owner and marketing can read the page; other roles are refused.
/cu/talking-points/cu/campaignsCU-013
Credit-union workspace
The CU shall be able to promote parent-facing products/resources only through clearly separated, adult-directed resource cards.
Acceptance: Educational mission content remains neutral and does not change based on product conversion goals.
Resource cards are adult-directed and visually separated; mission content never changes with product goals.
CU-014
Credit-union workspace
The CU shall have a standard vendor due-diligence package available before contracting.
Acceptance: Package includes data-flow overview, privacy practices, security controls, subprocessors, incident process, accessibility statement, insurance/certifications if applicable, and product boundaries.
Vendor due-diligence pack at /cu/due-diligence lists the nine standard items. Drafts are marked DRAFT and need legal and security sign-off. Certifications and insurance are listed only when held (none are). Download all reports that no approved document source exists and does not invent a ZIP. Owner and compliance can read it; other roles are refused.
/cu/due-diligence/trust/due-diligenceCU-015
Credit-union workspace
The product shall never imply that it is NCUA-approved or NCUA-certified.
Acceptance: Marketing/legal review blocks such language.
NCUA disclaimers on every surface; brand editor rejects “NCUA approved/certified” copy.
CU-016
Credit-union workspace
The CU shall have a designated program owner and optional marketing, analyst, compliance/reviewer, and read-only executive roles.
Acceptance: Permissions match assigned responsibilities.
Program owner invites staff at /cu/team, assigns marketing, analyst, compliance or read-only executive, and can change, resend or revoke. The Brand / Campaigns / Reports / Seats / Review matrix is enforced on every CU route. Owner assignment is refused. No child data.
/cu/teamCU-017
Credit-union workspace
The CU shall be able to configure local events, branch workshops, and community partnerships in the family calendar.
Acceptance: Events can be offered alongside Innorve cohorts.
Program owner configures local events at /cu/events (5p). A published event is a lab session, so it appears beside Innorve Money Labs in the family calendar. No child records.
/cu/events/family/labsCU-018
Credit-union workspace
The CU shall have one annual contract/subscription with transparent entitlements rather than unpredictable child-level surprise fees.
Acceptance: Admin can see current entitlements and sponsored cohort balance.
The program owner sees the annual contract at /cu/contract: households enrolled of the included cap, sponsored seats used, custom requests used of the yearly allowance, contract dates, the package checklist and the renewal note. Other roles are refused. The page does not edit the contract.
/cu/contractCU-019
Credit-union workspace
The standard commercial package shall not require the CU to procure separate content, facilitators, or marketing materials to become usable.
Acceptance: Program is turnkey from day one.
Content, facilitators, Money Labs and marketing materials are included in the standard package.
CUR-001
Curriculum Studio
Authorized Innorve curriculum creators shall be able to begin curriculum creation through a natural-language chat rather than structured forms.
Acceptance: A facilitator can describe a story or lesson idea conversationally and receive a structured brief.
Creator Chat turns a conversational story into mission candidates and a structured blueprint.
/studio/newpackages/curriculum/src/assistantCUR-003
Curriculum Studio
The curriculum assistant shall ask clarifying questions only when needed to establish age, learner objective, real-world context, duration, parent involvement, and delivery format.
Acceptance: Creator can reach a first blueprint without completing a long questionnaire.
Asks only for missing age, delivery and parent role; everything else is derived and shown as “known”. Unit-tested.
packages/curriculum/src/assistant/assistant.test.tsCUR-004
Curriculum Studio
The system shall generate a curriculum brief before generating final assets.
Acceptance: Brief includes target age, financial concept, behavioral design lens, learning objective, scenario, activity, assessment, risks, and source plan.
Blueprint (brief) precedes assets: target age, concept, lens, objective, scenario, activity, measurement, risks and source plan.
CUR-008
Curriculum Studio
The pipeline shall generate age-differentiated versions of the same concept while preserving the core learning objective.
Acceptance: One “total cost of a car” idea can produce 8–12, 13–15, and 16–17 variants with different complexity.
One car idea yields 8–12, 13–15 and 16–17 variants with different complexity; “make a version for age 9 and 16” adds variants.
packages/curriculum/src/assistant/concepts.tsCUR-010
Curriculum Studio
The pipeline shall generate a no-spend/play-money alternative for any activity involving purchases, allowances, or contributions.
Acceptance: No mission requires disposable family income.
Every blueprint and seed mission includes a play-money/no-spend alternative.
CUR-011
Curriculum Studio
The pipeline shall include a “make it less judgmental” editorial pass that checks for shame, moralizing, wealth assumptions, and false universal rules.
Acceptance: Reviewer sees flagged phrases and suggested revisions.
“Make it less judgmental” gate shows flagged phrases with suggestions; “make it less preachy” applies the editorial pass.
packages/curriculum/src/qualityCUR-013
Curriculum Studio
The pipeline shall include bias/inclusion review for family structure, income, culture, disability, and access assumptions.
Acceptance: Mission can be completed by diverse households without implying one correct lifestyle.
Bias/inclusion gate flags family-structure, income, culture and access assumptions.
CUR-014
Curriculum Studio
The pipeline shall include an advice-boundary review that flags personalized investing, tax, legal, credit, or insurance recommendations.
Acceptance: Flagged content cannot publish until corrected and approved.
Advice-boundary findings are blocking; publish is refused while any blocking gate remains.
packages/curriculum/src/pipeline.tsCUR-015
Curriculum Studio
The pipeline shall classify facts as durable principles or dynamic facts and require review/expiration rules for dynamic facts.
Acceptance: Rates, legal limits, fees, deadlines, or product details cannot remain indefinitely without review.
Dynamic facts must carry a review-by date or publishing is blocked; seed dynamic facts have dates.
CUR-016
Curriculum Studio
Every curriculum item shall have creator, owner/licensor, permitted use, source provenance, review status, last-reviewed date, and version.
Acceptance: Monica-licensed or third-party material is distinguishable from Innorve-original content.
Every item records creator, owner/licensor, permitted use, provenance, status, last-reviewed date and version; Monica-licensed vs Innorve-original is shown.
/studio/libraryCUR-017
Curriculum Studio
Curriculum status shall support idea, draft, research-checked, reviewer-approved, pilot, published, needs-review, and retired.
Acceptance: Only approved/published versions reach children.
Idea → draft → research-checked → reviewer-approved → pilot → published → needs-review → retired; only published (or pilot for pilot tenants) reach children.
packages/curriculum/src/taxonomy.tsCUR-018
Curriculum Studio
The system shall not represent curriculum “efficacy” as proven merely because AI quality checks pass.
Acceptance: Measured efficacy remains “not evaluated” until supported by real outcome evidence.
Measured efficacy stays “not evaluated” and is shown next to every quality report.
CUR-019
Curriculum Studio
The curriculum assistant shall support conversational revision across the whole asset bundle.
Acceptance: Creator can say “make the story funnier and remove tax math” and dependent assets update consistently for re-review.
Conversational revision updates story, activity, variants and sources consistently and marks sections for re-review; resets prior approval.
CUR-021
Curriculum Studio
The platform shall maintain a Story Bank where facilitators can save real anecdotes and convert them into curriculum candidates.
Acceptance: A story can remain private/internal until rights and sensitivity review are complete.
Story Bank entries stay private/internal with rights and sensitivity status until review.
/studio/story-bankCUR-022
Curriculum Studio
Credit unions may submit curriculum requests through a guided chat, but requested content shall be reviewed and published by Innorve-authorized reviewers.
Acceptance: Institution cannot directly generate and expose unreviewed child content.
CU requests are authored and reviewed by Innorve; institutions cannot publish.
CUR-023
Curriculum Studio
The creator workspace shall preserve facilitator voice while allowing a neutral/institutional tone version.
Acceptance: Monica-style storytelling can coexist with white-label institutional copy.
Facilitator voice and neutral institutional voice are both kept; switchable in chat.
apps/web/src/components/studio/blueprint-panel.tsxCUR-024
Curriculum Studio
The pipeline shall create research notes for facilitators distinguishing “what the research supports,” “what is a teaching choice,” and “what remains uncertain.”
Acceptance: Facilitators do not present hypotheses as settled evidence.
Research notes separate what research supports, teaching choices and open questions.
/studio/library/five-dollar-challengeCOH-001
Cohorts / Money Labs
The product shall include an Innorve “Money Labs” cohort catalog for live behavioral-finance education.
Acceptance: Parents and CUs can browse upcoming sessions.
Money Labs catalog for parents and a sponsorship view for CUs.
/parent/labs/cu/labsCOH-004
Cohorts / Money Labs
Each cohort shall define learning outcomes, prerequisites, materials, participation expectations, and post-session mission.
Acceptance: Booking page provides sufficient preparation.
Booking page lists outcomes, prerequisites, materials, participation expectations and the follow-up mission.
COH-005
Cohorts / Money Labs
Credit unions shall be able to reserve blocks of seats or entire private cohorts for their members.
Acceptance: CU program manager sees reserved capacity and usage.
Sponsored seats shows reserved, used and waitlist per session. Reserved seats are the capacity parents book against. A private cohort request is recorded for Innorve and is not bookable until it is a session.
/cu/seatsCOH-006
Cohorts / Money Labs
Parents shall be able to book sponsored seats directly and join a waitlist when capacity is reached.
Acceptance: Waitlist automatically communicates status changes.
Direct booking with waitlist. When a seat opens, or a 24-hour hold runs out, the next household is offered it and their guardians are sent the seat-opened message.
apps/web/src/server/family/bookings.tsapps/web/src/server/family/scheduler.tsCOH-007
Cohorts / Money Labs
The platform shall support parent attendance requirements for younger age groups where configured.
Acceptance: Registration enforces household/guardian participation rules.
Guardian attendance is enforced at booking for labs that require it.
COH-009
Cohorts / Money Labs
Facilitators shall have a roster with only the information necessary to deliver the session.
Acceptance: Sensitive household financial data is excluded.
Roster shows first name, age band, attendance and accommodations only.
/facilitatorCOH-010
Cohorts / Money Labs
Live session participation shall not require children to reveal household finances or personal family conflict.
Acceptance: Facilitator guide uses fictional/play-money scenarios by default.
Labs use play money and fictional stories by default; safety notes repeat it.
COH-011
Cohorts / Money Labs
Peer chat/interactions shall be moderated or constrained according to age and session format.
Acceptance: Unmoderated public child-to-child messaging is not a core feature.
No child-to-child messaging exists; labs use moderated, preset interactions.
COH-012
Cohorts / Money Labs
Session recording shall be off by default for child cohorts unless separately approved and consented.
Acceptance: Booking and session controls reflect recording status.
Recording is off by default and shown on booking and facilitator screens.
COH-013
Cohorts / Money Labs
After a cohort, each child shall receive a follow-up mission and optional transfer challenge.
Acceptance: Cohort is connected to app practice.
Each lab designates a follow-up mission (with its transfer step). For 30 days after a lab the child took part in, kid home leads with it as “After your Money Lab …” unless a mission is already in progress.
packages/curriculum/src/recommendation.ts/kidCOH-014
Cohorts / Money Labs
Parents shall receive a concise recap and suggested conversation, not private comments about other participants.
Acceptance: Post-session communications respect participant privacy.
Identical recap for every family, with one conversation idea and no comments about others.
COH-015
Cohorts / Money Labs
The CU shall receive aggregate attendance, completion, satisfaction, and follow-up participation for sponsored cohorts.
Acceptance: No private child notes are included.
CU sees aggregate bookings/attendance with suppression, never notes.
COH-016
Cohorts / Money Labs
Cohorts shall support accommodation requests and accessible materials.
Acceptance: Parent can request accommodation privately before session.
Private accommodation requests go only to the facilitator.
COH-018
Cohorts / Money Labs
Facilitators shall be able to mark observed skill evidence using structured rubrics.
Acceptance: Observation is tied to the relevant learning objective and evidence type.
Rubric levels are recorded per learner and become facilitator-observed evidence tied to the skill.
COH-019
Cohorts / Money Labs
Cohort content shall be version-locked at booking so material changes are traceable.
Acceptance: Facilitator and participants receive the approved version associated with the session.
Bookings lock the curriculum version; facilitators see the locked version.
COH-020
Cohorts / Money Labs
Parents shall be able to rate session usefulness and optionally suggest future topics.
Acceptance: Feedback informs curriculum backlog without exposing child identity to other families.
Families who took part rate a finished session 1–5 and can suggest a topic (contact details rejected). The Studio sees averages and unattributed topic ideas per item and on the overview as backlog input.
/parent/labs/studioFAC-001
Facilitator
Facilitators shall have a workspace for upcoming cohorts, assigned curricula, materials, rosters, preparation, and follow-up.
Acceptance: One dashboard supports the full delivery cycle.
Facilitator “Today” covers sessions, curriculum, materials, roster, preparation and follow-up.
/facilitatorFAC-002
Facilitator
Facilitators shall be able to ask the Creator Chat for alternate examples, age adjustments, or explanations before a session.
Acceptance: Draft adaptations remain private until approved if they change child-facing content.
Facilitators can use Creator Chat for alternate examples and age adjustments; drafts stay private until approved.
FAC-003
Facilitator
Facilitators shall have a “teach this safely” panel with sensitive-topic notes and red lines.
Acceptance: Every cohort package includes behavior and privacy guardrails.
“Teach this safely” panel with safety notes, red lines and misconceptions.
FAC-004
Facilitator
Facilitators shall be able to submit field notes about confusing prompts, strong activities, or learner misconceptions.
Acceptance: Feedback is captured against curriculum version.
Field notes are stored against the locked curriculum version and shown in the library.
FAC-005
Facilitator
Facilitators shall not record unstructured psychological diagnoses or sensitive household financial notes.
Acceptance: Freeform notes warn against prohibited/sensitive data.
Field notes warn when text looks like finances, diagnoses or labels.
FAC-006
Facilitator
Facilitators shall be able to escalate a curriculum issue to the content team and stop use of a problematic item.
Acceptance: High-severity flag can quarantine content from future sessions.
Escalation with severity; high severity quarantines the item from sessions and children.
FAC-008
Facilitator
Facilitators shall be able to see sponsor branding and session-specific welcome/closing messages.
Acceptance: They can acknowledge the CU without turning instruction into product sales.
Sponsor welcome/closing messages shown with a no-sales reminder.
FAC-009
Facilitator
Facilitator performance shall be evaluated on delivery quality, learner safety, and program outcomes—not product referrals.
Acceptance: No sales conversion quota is attached to child instruction.
No referral or sales metric exists for facilitators.
FAC-010
Facilitator
Facilitators shall receive an evidence summary showing which statements are research-backed, standards-derived, or illustrative.
Acceptance: They can answer “why are we teaching this?” accurately.
Evidence summary labels statements as research-backed, standards-derived or illustrative.
GAM-001
Gamification
Gamification shall reward practice, explanation, transfer, persistence, and helpful collaboration rather than wealth accumulation.
Acceptance: Badges map to skills/behaviors.
Recognition maps to skills and learning behaviors, never money.
GAM-002
Gamification
The system shall support play-money wallets used only inside learning simulations.
Acceptance: Play money is clearly labeled and cannot be cashed out.
Play-money wallet is labeled “can't be spent or cashed out” and exists only inside missions.
GAM-005
Gamification
Streaks shall not punish children for missed days or create pressure to disclose personal data.
Acceptance: Streak recovery/grace behavior is supportive.
No streaks; pausing never costs anything.
GAM-006
Gamification
The platform shall avoid variable-ratio gambling-like reward mechanics.
Acceptance: Rewards are transparent and tied to learning actions.
No random or variable rewards; recognition is transparent and tied to actions.
GAM-008
Gamification
Kids shall be able to collect “Skill Stars” or equivalent recognition across curriculum tracks.
Acceptance: Collection reflects breadth of practice rather than dollar values.
Skill Stars collect per skill, reflecting breadth of practice.
GAM-009
Gamification
Gamification settings shall be age-banded.
Acceptance: Younger learners receive simpler visual reinforcement; teens receive more autonomy and less childish treatment.
Teens see a skill log instead of stars and less playful treatment; per-band recognition styles are configured.
GAM-010
Gamification
The system shall allow a curriculum item to disable gamification when the topic is sensitive.
Acceptance: Serious topics are not forced into playful treatment.
Per-item toggle disables playful recognition for sensitive topics.
/studio/libraryANA-001
Analytics
Analytics shall distinguish reach, enrollment, participation, learning evidence, cohort engagement, retention, and parent feedback.
Acceptance: Metrics are not collapsed into one vanity score.
Reach, enrollment, participation, evidence, cohorts, retention and parent feedback are reported separately.
ANA-002
Analytics
The primary family engagement funnel shall include invited/reached → household enrolled → child activated → first mission → repeat mission → 30/90-day return → cohort participation where applicable.
Acceptance: CU dashboard shows denominator at each stage.
Funnel from reached to cohort participation with each stage's denominator.
ANA-003
Analytics
Learning reporting shall focus on skill practice and transfer evidence, not only quiz scores.
Acceptance: Reports include the evidence class and context.
Learning reporting by evidence class and skill, not quiz scores.
ANA-008
Analytics
The CU shall be able to report community impact without exposing individual child data.
Acceptance: Exports use aggregate counts and suppression where needed.
Aggregate counts with suppression under 10.
ANA-009
Analytics
Product referrals, if enabled, shall be measured separately and only from adult-initiated actions.
Acceptance: No child mission response counts as a sales lead.
Referrals are counted only from adult requests and reported separately.
ANA-010
Analytics
The platform shall support annual renewal reporting summarizing reach, engagement, cohorts, curriculum used, and program recommendations.
Acceptance: CU can use report in budget/board review.
The board report summarizes reach, participation, cohorts, curriculum in use and renewal notes. Counts are aggregates with suppression under 10. Efficacy is not evaluated, and the file is not advice.
/cu/reportsANA-011
Analytics
Analytics shall clearly label demo/synthetic data in demonstrations.
Acceptance: No demo is mistaken for achieved results.
Every synthetic metric is labeled demo data; live demo counts are shown separately.
MKT-001
Marketing / activation
The platform shall include a ready-to-launch family campaign kit for each institution.
Acceptance: CU receives landing page, email, SMS, social posts, branch flyer, poster, QR assets, and staff script.
Kit includes landing page, email, SMS, social, flyer, poster, QR code and staff script.
MKT-002
Marketing / activation
The platform shall include seasonal campaign packs such as Youth Month, back-to-school, summer earning, first job, first car, and college planning.
Acceptance: CU can activate campaign without new creative work.
Youth Month, back-to-school, summer earning, first job, first car and college planning packs.
MKT-003
Marketing / activation
Every campaign shall have a parent-first message and optional child-facing creative appropriate to age.
Acceptance: Marketing never directly pressures children to buy financial products.
Parent-first messaging; kid-facing poster only invites a grown-up.
MKT-004
Marketing / activation
The credit union shall be able to sponsor a featured “Mission of the Month.”
Acceptance: Mission promotion retains educational neutrality.
CU features a Mission of the Month; the mission content stays unchanged.
/cu/libraryMKT-006
Marketing / activation
The platform shall provide parent webinar/workshop promotional templates for Money Labs.
Acceptance: Cohort marketing can be launched quickly.
Money Lab promo template filled with the next lab's details.
MKT-007
Marketing / activation
The platform shall provide a CU launch checklist with clear owner responsibilities.
Acceptance: Program manager can see what remains before go-live.
Launch checklist with owners and required-for-live flags.
/cuMKT-008
Marketing / activation
The program shall support referral codes/QRs by branch/event for aggregate channel attribution.
Acceptance: CU can measure activation source without needing child financial data.
Channel codes per branch/event with aggregate attribution only.
MKT-009
Marketing / activation
The product shall include a parent-facing FAQ explaining privacy, curriculum approach, sponsorship, and what is/is not financial advice.
Acceptance: Parents can understand program before enrolling.
Parent FAQ (5l) explains totals-only access, sponsorship, and education rather than advice. Linked from settings, the account menu, and the invite welcome.
/family/faq/trustTRU-001
Trust / privacy / safety
The platform shall minimize child personal information to what is necessary for the service.
Acceptance: Enrollment does not collect unnecessary financial or demographic details.
Child data is a nickname, age band, avatar and optional interests — no birthdate, school or financial data.
TRU-003
Trust / privacy / safety
Parents shall be able to review, correct where appropriate, and request deletion of covered child information subject to applicable obligations.
Acceptance: Controls are documented and operational.
Guardians can review (export), close or delete child data in-product.
TRU-004
Trust / privacy / safety
Child information shall not be sold or used for targeted advertising.
Acceptance: Privacy policy and product behavior align.
No advertising or data-sale code paths; stated in the trust center.
TRU-005
Trust / privacy / safety
The platform shall maintain a clear retention policy and shall not keep child data indefinitely without a specific purpose.
Acceptance: Retention is purpose-linked and visible in privacy documentation.
Purpose-linked retention is enforced by applyRetention: closed profiles are deleted after a 30-day recovery window and learning records after 12 months of inactivity; runs are audited with counts only. Scheduled via /api/cron/retention or `pnpm db:retention`; privacy pages read the same policy constants. Tested.
packages/db/src/retention.tspackages/db/src/retention.test.ts/parent/privacy/trustTRU-006
Trust / privacy / safety
The platform shall use privacy-preserving aggregate reporting for credit unions.
Acceptance: CU cannot browse child-level journals or raw reflections.
CU reporting is aggregate and privacy-preserving.
TRU-007
Trust / privacy / safety
No public child profile, follower graph, or open messaging network shall be part of the core product.
Acceptance: Social exposure is minimized.
No public profiles, followers or open messaging.
TRU-008
Trust / privacy / safety
The product shall prevent a child from entering personal contact information into open discussion spaces where technically and operationally feasible.
Acceptance: Cohort interactions use controlled modes.
No open discussion spaces exist; free-text answers warn against contact details.
TRU-010
Trust / privacy / safety
The product shall distinguish financial education from counseling, therapy, financial advice, and regulated recommendations.
Acceptance: User-facing and facilitator language reflects boundaries.
UI copy consistently distinguishes education from advice, counseling and therapy.
TRU-011
Trust / privacy / safety
The platform shall support content rights/licensing controls for facilitator-owned and third-party content.
Acceptance: Only permitted institutions/audiences receive licensed content.
Only items licensed to a tenant reach its families; rights metadata on every item.
TRU-014
Trust / privacy / safety
The product shall support incident and content takedown procedures.
Acceptance: A harmful or incorrect mission can be unpublished quickly while preserving audit history.
Reviewers unpublish and quarantine instantly; history and audit log are preserved.
apps/web/src/server/actions/studio.tsTRU-015
Trust / privacy / safety
The product shall provide clear disclaimers that NCUA does not approve or certify vendor technology.
Acceptance: No misleading regulatory endorsement appears.
NCUA non-endorsement disclaimer appears across public, parent and CU surfaces.
ADM-002
Admin / commercial
The platform shall support institution-level configuration without duplicating curriculum for every CU.
Acceptance: One approved curriculum item can be licensed to many tenants with controlled overrides.
One curriculum item is licensed to many tenants with controlled overrides (enable, feature, sponsor note).
ADM-003
Admin / commercial
The platform shall support program packages that bundle app access, curriculum, marketing, reporting, and cohort entitlements.
Acceptance: Sales can offer a simple package rather than many separate SKUs.
Standard package bundles app, curriculum, marketing, reporting and Money Lab seats.
ADM-004
Admin / commercial
Custom curriculum, dedicated cohorts, event kits, and specialized branding may be optional add-ons.
Acceptance: Add-ons do not break the core turnkey experience.
Optional event-kit and dedicated white-label add-ons can be scheduled without removing core package access. Custom curriculum stays unavailable so it cannot bypass rights review.
/admin/institutions/[id]/entitlementsADM-005
Admin / commercial
The platform shall support institution renewal review with usage and outcome summary.
Acceptance: Account owner can generate renewal packet.
An Innorve admin can open an aggregate renewal packet with reach, engagement, cohorts, licensed curriculum, definitions, suppression under 10, and “Efficacy: not evaluated.”
/admin/institutions/[id]/renewalADM-006
Admin / commercial
The product shall support household-based rather than child-by-child billing where contractually preferred.
Acceptance: Commercial model does not penalize larger families.
The contract view states one annual subscription billed per household, with no per-child fees. Larger families are not charged more.
/cu/contractADM-007
Admin / commercial
The platform shall support free pilot/design-partner programs while clearly distinguishing them from standard contracts.
Acceptance: Pilot entitlements and dates are explicit.
Lakeshore is a labeled design-partner pilot with explicit dates and entitlements.
ADM-008
Admin / commercial
The product shall provide customer-success tasks and onboarding milestones for each CU.
Acceptance: No institution is “live” without confirmed brand, consent flow, support contacts, and program owner.
Customer success confirms onboarding milestones in admin; going live is refused (and audited) unless brand, consent flow, support contacts and program owner are confirmed and the contacts and owner actually exist. Required items can't be reopened while live. Tested.
packages/db/src/lifecycle.tspackages/db/src/lifecycle.test.ts/adminADM-009
Admin / commercial
The product shall support institution offboarding and data disposition.
Acceptance: CU and Innorve have clear end-of-contract process.
Offboarding is planned and confirmed separately. Confirmation shuts off access. Deletion is a second confirmation and stays held under the recorded retention policy (D-01); it does not claim the data is gone.
/admin/institutions/[id]/offboardingpackages/db/src/commercial.ts