M1-01 Requirements Validation & Sign-off¶
Milestone: M1 — Detailed Planning and Team Onboarding SOW Reference: SOW §1.4, Appendix 1; Deliverable D1 Requirement Clarity: ⚠️ Blocking — several open items below must be answered before this task can close Dev Status: ⚪ Not a build item — documentation/sign-off task
Overview¶
Produce the Requirements Validation Output (D1): a reviewed, internally-consistent version of the SOW's Appendix 1 Requirements Specification, with all clarifications and delivery assumptions recorded in writing. This is the formal gate before design work starts on M2/M3.
Tasks¶
- Walk through SOW Appendix 1 (FR1–FR8, NFR1–NFR6, OR1–OR3, INT1–INT8) line by line with Curo
- Resolve and record answers to the open items list (see below)
- Produce the marked-up requirements document + approval note (Word/PDF, per Appendix 2 Deliverable format)
- Get Curo's Technical and Acceptance Lead (Annie Andrews per Appendix 4) to review and approve
Open items to resolve as part of this task¶
- Reclaim Protocol (FR4) scope & pricing — new requirement vs. the original v3 doc; confirm client sign-off status (see ../M7/M7-01-reclaim-protocol-scope-confirmation.md).
- FR2 disclosure-policy configuration depth — full config vs. default-only for MVP (see ../M5/M5-02-disclosure-policy-configuration.md).
- Credits/vouchers mechanism (NFR5) — the original credit-pool/treasury/voucher mechanism isn't respecified in the SOW (see ../M5/M5-11-credits-vouchers-mechanism.md).
- General payment/invoicing capability (NFR5) — distinct from item 3; confirm whether manual invoicing is acceptable for MVP or in-platform payment processing is expected now (see ../M5/M5-14-general-payment-invoicing-capability.md).
- M10 go-live vs. Final Acceptance definition (see ../M10/M10-01-production-deployment-go-live-readiness.md).
- AWS hosting target for the deploy pipeline (see ../M4/M4-01-v01-beta-release-package-deployment.md).
- Minor dropped specifics — passkey support, SMS gateway, Zendesk-specific help tooling, backup retention/geo-distribution detail, standalone DDoS status: confirm each is deliberately descoped or still required.
- KYB MVP-vs-Beta phasing — SOW text implies the in-platform KYB web form may only be required by "full Beta release," not MVP (see ../M2/M2-01-organisation-kyb-onboarding-flow.md).
- Regulatory compliance scope — UKDIATF, CCPA, SOC2, and UK staffing data-retention rules are each named once in NFR3 with no further specification of expected activity (see ../M9/M9-13-regulatory-industry-compliance.md).
- SAML 2.0 requirement — listed as a supported standard in Appendix 6 but not otherwise referenced; confirm it's actually needed for MVP (see ../M9/M9-12-saml2-tls13-protocol-support.md).
- D5e (M9) release packaging — unlike M4/M6/M8, M9 has no defined beta version number for its own deployment package; confirm whether it ships inside M10 or needs its own release step.
- SOW-internal D7/D8 numbering inconsistency — Appendix 3 references a "D8" deliverable that Appendix 2's Deliverables table never defines (see ../M10/M10-04-source-code-repository-handover.md).
Dependencies¶
- Curo/Annie Andrews availability for review (Appendix 4 — Technical and Acceptance Lead).
- Appendix 5 assumptions A1–A12 being reasonably stable at sign-off time.
Acceptance Criteria¶
- Requirements clarified, agreed and internally consistent (per Appendix 3 "D1" row)
- Marked-up requirements + approval note delivered
- All 12 open items above have a written answer, not just verbal agreement
Existing Reference Material¶
- ../../requirements/index.md, ../../requirements/functional.md
- ../CONSOLIDATED-SUMMARY.md — full open-items rationale
Blockers & Risks¶
- Risk: if this task is rushed or treated as a formality, the ambiguities carry silently into M5/M7/M10 where they cost far more to unwind.