# WAURE External Dependencies

This document tracks non-engineering dependencies required before WAURE can launch. It is the launch-readiness source of truth for external accounts, credentials, budgets, and Founder decisions.

## Status Key

- `Blocked`: required before public launch or full production validation.
- `Pending Founder`: Founder-owned decision or account action is required.
- `Ready To Verify`: credentials or access exist and CTO can validate.
- `Verified`: dependency has passed the documented verification method.
- `Complete`: dependency has been verified, operationalized, and removed from the active blocker list.

## Dependencies

| Dependency | Owner | Current Status | Blocking Severity | Required Action | Verification Method |
| --- | --- | --- | --- | --- | --- |
| Production Redis | CTO | Complete | Removed From Active Blockers / Required In Production Env | Existing Upstash Redis has been connected to local WAURE through `WAURE_KV_REST_API_URL` and `WAURE_KV_REST_API_TOKEN`. Configure the same verified WAURE-scoped variables in Vercel production when deploying. | Verified Upstash `PING`, production readiness `production_redis: PASS`, `/api/events`, `/api/search`, `/api/story-production?action=status`, `/api/topics`, `/sitemap-dynamic.xml`, and all applicable operational department modules reading live Redis-backed state locally. See `WAURE_REDIS_INTEGRATION_MATRIX.md`. Verified. Operational. Removed. |
| Production Admin Credentials | Founder + CTO | Complete | Removed From Active Blockers | Founder provided `WAURE_ADMIN_KEY`; it is configured locally and in Vercel Production. Production was redeployed and protected admin APIs now accept `x-waure-admin-key`. Production-authorized Launch Inventory population must continue through official production APIs only; no direct Redis injection or temporary write path is allowed. | Verified `/api/launch-control`, `/api/launch-inventory?action=plan&market=US`, and `/api/production-env-readiness` return `200` with valid admin authorization. Launch Inventory returned live category planning data; production readiness returned live blocker state. Verified. Operational. Removed. |
| Clerk Configuration | CTO | Complete | Removed From Active Blockers / Required In Production Env | Existing Clerk keys have been connected locally through `CLERK_SECRET_KEY` and `NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY`. Configure the same verified variable names, with the intended live Clerk instance values, in Vercel production when deploying. Google sign-in uses Clerk shared development credentials for local verification. Apple Sign-In is recorded as a future production enhancement, not a current blocker. | Verified `/api/auth/config` returns `available: true`; Clerk backend can create verified email users and active sessions; profile page initializes Clerk; email sign-in issues a real session token; Google sign-in is exposed in the Clerk runtime UI for development; sign-out returns to the signed-out account state; `/api/retention?action=snapshot` rejects unauthenticated and invalid-token requests and accepts a real Clerk bearer token; saved discussions, followed discussions, voting activity, and notifications persist for the correct Clerk user; session revoke reports `revoked`. Verified. Operational. Removed. |
| Google OAuth WAURE Branding | CTO / Founder | Pending Pre-Launch Polish | Medium / Trust Polish | Configure a custom Google OAuth app through Google Cloud and Clerk so the Google account chooser says users are continuing to `WAURE`, not `Clerk`. This does not block the technical login path because Founder verified Google login works, but it should be corrected before public launch for user trust. | Retest Google sign-in on production and confirm the account chooser / consent surface uses WAURE branding instead of Clerk branding. |
| Vercel Production Environment | CTO | Complete | Removed From Active Blockers | Repository reconciliation was promoted to `main` at `bee394e151ace7e4785481449d9bd6e1997a973f`; Vercel Git integration created production deployment `dpl_DNYfUsp7gyt1VMooAkjLKui9JBxj` from `main` and aliased it to `www.waure.com`, `waure.com`, `waure.vercel.app`, and the main branch aliases. | Verified deployment state `READY`, target `production`, GitHub ref `main`, GitHub SHA `bee394e151ace7e4785481449d9bd6e1997a973f`, and live production routes. Verified. Operational. Removed. |
| Vercel Preview Authentication | Founder | Pending Founder | High | Provide local or CI-safe Vercel authentication so CTO can create and inspect preview deployments. Local tooling reaches the Vercel auth gate through the linked project `team_PjpsJXuUBpB6GCeOhXcfmJNG` / `prj_Ld7cOesrcpvUowTPjkSfc44o3dgd`; the remaining failure is `No existing credentials found. Please run vercel login or pass "--token"`. | Run `vercel dev` or preview deployment workflow against linked project `prj_Ld7cOesrcpvUowTPjkSfc44o3dgd`; verify preview URL boots. |
| Search Console | Founder + CTO | Complete | Removed From Active Blockers | Founder verified the `https://www.waure.com` Search Console property and configured production service-account credentials in Vercel. The production runtime now uses `GOOGLE_SEARCH_CONSOLE_SITE_URL=https://www.waure.com`, service-account JWT authentication, and Redis-backed storage. Freshly verified properties may return zero rows until Google has collected search data; that is not a credential or ingestion failure. | Verified `/api/google-search-console?action=status` reports `configured:true`, `siteUrl:https://www.waure.com`, `authMethod:service_account_jwt`, `store.mode:redis`, and `store.available:true`. Verified production ingestion succeeds through the official admin-authenticated path and persists run `dc634152-b8b7-4a4a-88b1-462e815b0a7e` into Redis with zero rows. Verified Launch Control no longer lists `search_console`; Executive Dashboard and Company KPI Dashboard report Search Console available. Verified. Operational. Removed. |
| Automated Story Rendering / AI Gateway Budget | Founder | Deferred Future Capability | Deferred / Future Scaling | Do not treat automated narration as a launch blocker. Current production publishing is satisfied by Writer Organization (Temporary Human-Guided Workflow). Configure a production AI credential later by enabling one of `VERCEL_OIDC_TOKEN`, `AI_GATEWAY_API_KEY`, or `OPENAI_API_KEY` when automation becomes the scaling bottleneck or Founder approves a future Editorial Rendering Engine. | Run `/api/production-env-readiness` with admin auth and verify `automated_story_rendering: PASS` only when future automation is being activated. Until then, verify Launch Control lists it as deferred rather than blocked. |
| Candidate Incident Audition A/B Validation | Founder + CTO | Deferred By AI Gateway Budget | Deferred / Future Quality Evidence | Resume the frozen A/B validation only after budget preflight passes; do not regenerate completed stories. This is not a current launch blocker because Writer Organization (Temporary Human-Guided Workflow) satisfies the current publishing business objective. | Complete Dataset A and Dataset B, create blind review set, collect Founder scores, then reveal and analyze results when Founder reactivates the validation. |
| Founder Blind Review Capacity | Founder | Pending Founder | Medium | Reserve review time for Candidate Incident Audition validation and live product review sessions. | Founder completes blind review records with publish/reject, score, and comments for the prepared validation set. |
| Monetization Configuration | Founder + CEO + CTO | External Pending / Not Launch Blocking | Post-Launch Activation | AdSense ownership verification and `ads.txt` passed. AdSense site review is pending Google. Real ads remain OFF until Google approval and explicit Founder activation. Provider-neutral WAURE Ad Layer remains locked. | When Google approves: CEO reports approval -> Founder authorizes activation -> enable real serving -> verify desktop/mobile placements -> rerun production verification -> monitor RPM/viewability/UX. |
| Final Launch Criteria | Founder | Complete | Removed From Active Blockers | Founder approved WAURE V1 launch on 2026-09-17 using the current verified production candidate. Do not add new pre-launch features. | Canonical GO record: `docs/FOUNDER_LAUNCH_GO_DECISION_2026-09-17.md`. Latest production verification after Admin Command Center fix: `44 PASS / 0 FAIL / 0 BLOCKED`. |
| Production Domain And Canonicals | CTO + Founder | Complete | Removed From Active Blockers | Founder verified `https://waure.com` in browser with valid HTTPS, secure connection, valid certificate, and no browser warnings. Repository reconciliation promoted the canonical fixes to production through `main`. Production deployment `dpl_DNYfUsp7gyt1VMooAkjLKui9JBxj` is `READY` from commit `bee394e151ace7e4785481449d9bd6e1997a973f`. | Verified `http://waure.com/` redirects to `https://waure.com/`, `https://waure.com/` redirects to `https://www.waure.com/`, `http://www.waure.com/` redirects to `https://www.waure.com/`, and `https://www.waure.com/` serves 200. Verified homepage canonical, Open Graph URL, and JSON-LD use `https://www.waure.com`. Verified a sitemap-discovered story page canonical, Open Graph URL, and JSON-LD use `https://www.waure.com`. Verified `robots.txt` advertises `https://www.waure.com/sitemap.xml` and `https://www.waure.com/sitemap-dynamic.xml`. Verified static and dynamic sitemap `<loc>` values use `https://www.waure.com`. No production-facing metadata sample contained `waure.vercel.app` or non-www canonical URLs. Verified. Operational. Removed. |
| Production Public URL Runtime Config | Founder + CTO | Complete | Removed From Active Blockers | `WAURE_PUBLIC_URL=https://www.waure.com` and `NEXT_PUBLIC_SITE_URL=https://www.waure.com` are configured in Vercel Production. Domain, HTTPS, redirects, canonicals, robots, and sitemaps were already verified; this completes the runtime environment requirement used by readiness checks, webhooks, sitemaps, canonicals, and production smoke logic. | Verified `/api/production-env-readiness` with admin auth reports `public_url: PASS` with both `WAURE_PUBLIC_URL` and `NEXT_PUBLIC_SITE_URL` configured. Verified Launch Control no longer lists `public_url`; it now reports 2 remaining blockers. Verified Executive Dashboard and Company KPI Dashboard load in production. Verified. Operational. Removed. |
| Scout Source Credentials | Founder | Pending Founder | Medium | Provide approved source/API credentials for live Scout discovery where required. | Run Scout source health checks and verify opportunities enter the Google Brain → Scout → Work Generation loop. |

## Current Launch Blockers

As of 2026-09-17, Founder decision is GO. No external dependency in this file remains a WAURE V1 product-launch blocker.

Post-launch / external pending items:

- AdSense site review is pending Google. This is not a product-launch blocker.
- Real ad serving remains OFF until Google approval and explicit Founder activation.
- Google OAuth WAURE branding remains trust polish and should be corrected, but Founder already verified Google login works.
- Vercel Preview Authentication remains useful for preview workflows but production launch is verified through GitHub `main` and Vercel production.
- Scout source credentials remain useful for stronger current-content coverage but do not block WAURE V1 launch.
- Candidate Incident Audition A/B validation remains deferred future evidence, not a launch blocker.

## Operating Rule

Do not simulate, fake, or bypass these dependencies. Continue improving credential-independent product quality while these remain pending. When a dependency becomes ready, verify it using the method above and update this registry.
