Dental Platform · Internal Docs
Product

Requirements Traceability Matrix

Owner: Product + QALast reviewed:

Status values: implemented · implemented-blocked-on-vendor · partial · planned

#Requirement (prompt §)WhereStatus
R1Monorepo structure (§4)repo rootimplemented
R2Design system, tokens, radii, typography (§6)packages/design-tokens, packages/uiimplemented
R3Hugeicons semantic registry (§6)packages/ui/src/iconsimplemented
R4Floating-label field suite (§6)packages/ui/src/fieldsimplemented
R5ContextIsland state machine + states (§7)packages/ui/src/context-islandimplemented
R6Recorder: permissions, devices, pause/resume, timer, consent (§8)apps/clinic-web/features/recordingimplemented
R7Real waveform (AudioWorklet, RMS, reduced motion) (§8)packages/ui/src/waveformimplemented
R8Chunked, resumable, checksummed, idempotent upload (§8)core-api recordings + web uploaderimplemented
R9Diarized final transcription + live interim (§9)ai-gateway + worker + realtimeimplemented (OpenAI credentials gated)
R10Transcript editor: speakers, merge/split, redact, versions (§9)clinic-web + core-api transcriptsimplemented
R11Prompt-injection defense (§9, §26)ai-gateway prompts + evalsimplemented
R12Clinical note templates + sections + evidence (§10)packages/template-definitions, core-api clinicalnotesimplemented
R13Patient-friendly summary EN/FR (§11)ai-gateway purpose patient_summaryimplemented
R14Versioned procedure-code catalog + licensed import (§12)core-api procedurecodes + import toolimplemented
R15Treatment plans, options, stages, estimates, statuses (§13)core-api treatmentplansimplemented
R16Option comparison from approved content (§14)core-api + clinic-web compareimplemented
R17Consent templates, versions, signing evidence (§15)core-api consentsimplemented
R18Pre/post-op instruction templates + delivery tracking (§16)core-api instructionsimplemented
R19Review workspace: section approve/reject/regenerate, hashes, step-up (§17)core-api approvals, clinic-web reviewimplemented
R20Patient communication package + secure delivery (§18)core-api communications, workerimplemented
R21Patient portal incl. acceptance capture (§19)apps/patient-portal + portal APIsimplemented
R22Insurance estimates (manual + adapter, versioned) (§20)core-api insuranceimplemented (live adapters vendor-blocked)
R23Referrals, prescriptions, clearance, lab prescriptions (§21)core-api clinicaldocsimplemented
R24Role-limited reporting (§22)core-api reportingimplemented
R25Integration framework + ABELDent boundary (§23)services/integration-serviceimplemented-blocked-on-vendor
R26Full schema, RLS, UUIDv7, audit partitions (§24)database/migrationsimplemented
R27REST API + OpenAPI 3.1 + problem details + idempotency (§25)api/openapi, core-apiimplemented
R28Realtime channels + AsyncAPI (§25)realtime-gateway, api/asyncapiimplemented
R29AI gateway, AI_PHI_MODE, routing, structured outputs, evals (§26)services/ai-gatewayimplemented (PHI mode gated on contract)
R30Keycloak OIDC, passkeys, MFA, sessions, step-up (§27)infra keycloak + core-api authimplemented
R31RBAC + contextual authorization + matrix (§27)packages/permissions, core-apiimplemented
R32Privacy artifacts: PIA, classification, retention, IR (§28)security/implemented (docs)
R33Field-level envelope encryption (§28)core-api cryptoimplemented
R34Hash-chained audit (§28)core-api auditimplemented
R35Canadian infra: RKE2, CNPG, MinIO, backups, DR (§29)infrastructure/implemented (manifests; hardware client-side)
R36Observability: metrics/logs/traces/dashboards/alerts (§30)packages/observability, infraimplemented
R37Test strategy incl. cross-tenant + resilience (§31)tests/, service testsimplemented
R38CI/CD + GitOps + supply chain (§32).github/workflows, infrastructure/argocdimplemented
R39Documentation suite + docs app (§33)docs/, apps/docsimplemented
R40Compliance language + legal-review register (§34)docs/security/legal-review-required.mdimplemented