Muqira ยท The Bible
// Core. AI. Workflow Engine. Integrations. Analytics. One platform, many workflows.
All saved โœ“
๐Ÿงญ How to use this tracker
This file is self-contained โ€” no login, no cloud dependency. Everything lives in your browser, with backup/restore to keep it safe across devices.
1
Navigate with the sidebar โ€” grouped by layer: Core, AI, Workflow Engine, Integrations, Analytics, then Workflow Modules, Security/QA, Growth Timeline, and Marketing/Business.
2
Click any task to mark it done (turns green โœ“). Click again to unmark.
3
Growth Timeline has horizon tabs โ€” 1 Week, 1 Month, 3/6/12 Months, 2โ€“5 Years โ€” each with its own focus and checklist.
4
Press "๐Ÿ’พ Save Progress" (or Ctrl+S) โ€” saves to browser localStorage. Progress persists between sessions.
5
Use "โฌ‡ Backup / Restore" to download a .json file regularly. Re-import on any device to sync progress โ€” treat this like a save file.
Tasks Done
0
of 0 total tracked tasks
Overall Progress
0%
Across every layer
Current Phase
Phase 0
Repo & Environment Setup
Products & Modules
6 live + 6 planned
AI Studio ยท Flow ยท Social ยท SEOventra ยท AlShorty ยท Documateo + more
Loadingโ€ฆ0%
๐ŸŽฏ Today's Mission
Loadingโ€ฆ
๐Ÿ’ธ AI Spend (month)$0
โค๏ธ Platform Healthโ€”
๐Ÿšฆ Release Ready0 / 4
๐Ÿ” Critical Security Closed0 / 0
๐Ÿ•“ Recent Activity
  • No activity yet โ€” tick a task to get started.
๐Ÿ”ฅ Phase 0 โ€” Repo & Environment Setup โœ“ Done
Monorepo structure confirmed โ€” apps/api + apps/web on muqira-web / muqira-live
CRITICALGitHub: ataurCODEX/muqira-web
CI/CD pipeline โ€” lint, test, build, deploy on every merge to main
CRITICAL
Staging + production Cloudflare environments separated
HIGH
Secrets management baseline โ€” Wrangler secrets, never committed
CRITICAL
Resolve production Worker naming conflict (if still open)
MEDIUMVerify against current production โ€” platform is live and deployed elsewhere in this tracker
Exit criteria: blank "hello world" Worker deploys automatically on merge to main
HIGH
๐Ÿ“ The Core Question
๐Ÿ“
Before building any feature: Can another workflow module use this in the next 12 months? YES โ†’ build in Core/Layer. NO โ†’ build in the module folder. This single test keeps "build once, reuse forever" real.
Muqira โ”‚ โ”œโ”€โ”€ Core Layer (identity, orgs, projects, billing, storage, settings โ€” DONE) โ”œโ”€โ”€ AI Layer (Muqira AI โ€” router, 27-model registry, prompts, cost engine โ€” DONE) โ”œโ”€โ”€ Workflow Engine Layer (trigger โ†’ step โ†’ step โ†’ validation โ†’ output โ€” DONE, 9 step types) โ”œโ”€โ”€ Muqira Connect (25 live connectors, one registry, one SDK โ€” DONE) โ”œโ”€โ”€ Analytics Layer (events, performance, engagement โ€” NOT STARTED) โ”œโ”€โ”€ Admin Console (12 pages, platform operator control plane โ€” DONE) โ”œโ”€โ”€ Marketing Site (blog, docs, changelog, status, tools, labs โ€” DONE) โ”‚ โ””โ”€โ”€ Products (the things users actually buy) โ”œโ”€โ”€ AI Studio โ† Purpose-First v2, live โ”œโ”€โ”€ Muqira Flow โ† workflow automation, live โ”œโ”€โ”€ Social Media Automation โ† Workflow #1, in progress โ”œโ”€โ”€ SEOventra โ† live sub-product โ”œโ”€โ”€ AlShorty โ† live sub-product โ”œโ”€โ”€ Documateo โ† live sub-product โ”œโ”€โ”€ SEO Automation (planned) โ”œโ”€โ”€ Content Marketing Automation (planned) โ”œโ”€โ”€ Research Automation (planned) โ”œโ”€โ”€ Product Launch Automation (planned) โ””โ”€โ”€ Directory Submission Automation (planned)
๐Ÿงญ The Strategic Shift
The unit of value is a Workflow Module running inside Muqira โ€” not a separately branded app.
Social Media Automation ships first, then SEO, Content, Research, Product Launch, and Directory Submission. SEOventra, AlShorty, and Documateo continue as real products consuming the same Core, AI, Workflow Engine, Integration, and Analytics layers โ€” the platform-layer work already done isn't thrown away, it gets a sharper first customer-facing target.
โš ๏ธ One Open Question โ€” Confirm Before Phase 4 Locks In
โ“
This blueprint assumes Workflow Modules ship as features inside Muqira rather than as separately branded standalone products. If the separately-branded product line (SEOventra, AlShorty, Documateo) is meant to run in parallel rather than be superseded by this structure, it's worth confirming how the two fit together โ€” easy to adjust now, expensive to unwind after customers are already using named products.
๐Ÿ“Š Wrong Metric vs Correct Metric
Track outcomes, not activity. A completed workflow is the actual unit of value delivered โ€” not a prompt sent or a message generated.
Instead of trackingTrack thisWhy it matters
Prompts sentWorkflows completedA completed workflow is the actual unit of value delivered
Messages generatedCampaigns publishedOutput that reaches the real world, not just generated text
โ€”Products launchedDirect measure of the Product Launch workflow's success
โ€”Content generated AND publishedGeneration alone isn't the goal โ€” publication is
โ€”Rankings improvedThe SEO workflow's actual promise to the customer
โ€”Traffic / leads generatedThe downstream business outcome every workflow ultimately serves
โ€”Time-to-completion per run, falling over timeProves the engine is actually getting better, not just busier
๐Ÿท๏ธ Revenue Model
Gate by workflow runs/month and AI tier, not by feature lockout within a workflow โ€” keeps the product feeling complete at every tier, which matters more for trust than upsell pressure does.
TierWorkflow AccessAI TierLimits
Free1 workflow module, limited runs/monthFree-tier models (Groq/OpenRouter free)Capped runs, single project, no scheduling
StarterAll shipped workflow modulesPaid tier (GPT/Claude/Gemini Pro)Higher run cap, scheduling enabled, single project
ProfessionalAll workflow modulesPremium tier availableMultiple projects, full analytics, priority support
AgencyAll workflow modulesPremium tierTeams/orgs, unlimited projects, white-label option, seat-based pricing
๐Ÿ“
Standing rule for every decision: if a feature could be reused by more than one Workflow Module, it belongs in a Layer (Core/AI/Workflow Engine/Integration/Analytics). If it's specific to one workflow's logic, it belongs in that module. This is the single test that keeps the platform from turning into disconnected products.
1
Build once, reuse forever
Auth, billing, AI routing, storage, notifications โ€” built once in a Layer, consumed by every Workflow Module. If you're writing similar code in two places, stop and extract it.
2
No workflow module ever calls an AI provider directly
Every AI call passes through Muqira.AI.generate() โ€” the single front door. Zero exceptions, even for "just a quick test."
3
AI providers are replaceable implementation details
7 providers behind one interface. A new model becomes a config-registry change, not a code change in any workflow.
4
Every Core table is scoped by org_id, with zero exceptions
A single missing filter is a cross-customer data leak. This is the #1 item on the risk register โ€” treat it that way.
5
Keep Core generic โ€” no module-specific tables
No social_posts or seo_audits table in Core. Workflow-specific data lives in workflow_runs.state_json / workflows.definition_json, or in a module-owned table outside Core if genuinely needed.
6
Workflow definitions are data, not code
JSON-schema validated, no proprietary DSL. The execution engine has zero workflow-module-specific logic inside it.
7
Adding a connector should never touch the workflow engine
The Connector contract in registry.ts is the only interface. If adding WordPress or Ghost had required engine changes, the SDK abstraction would be leaking โ€” proven correct by shipping 25 connectors without touching the engine.
8
Cost visibility before scale, not after the surprising bill
The Cost Engine must exist before Workflow #1 has real paying users. Budget-aware model selection is not optional.
9
Track completed workflows, not generated text
A completed, published, real-world outcome is the unit of value โ€” not a prompt sent or a message drafted.
10
If a module needs a feature that doesn't fit an existing Layer, redesign the module
Don't bolt on a one-off. Scope creep across workflow modules is named explicitly as a top platform risk.
Exposes: getCurrentUser(), requireAuth(), getCurrentOrg(), requireOrgMember(), requireRole(role), getProject(), can(user, action, resource), uploadAsset(), getSetting(scope, key) โ€” middleware and helpers every other layer depends on.
๐Ÿ” Identity & Authentication
Email OTP (Resend), Google OAuth, GitHub OAuth, JWT sessions all working locally
CRITICAL
RBAC middleware confirmed on every mutating route
CRITICAL
Production Cloudflare deployment of auth confirmed end-to-end
CRITICAL
๐Ÿข Organizations & Teams
Create/rename/delete org, personal org auto-created on signup
HIGH
Invite by email, accept/decline, remove member, org switcher UI
HIGH
Admin-driven org suspension with a reason shown to the org, enforced at the auth middleware
HIGH
๐Ÿ“ Projects & ๐Ÿ›ก๏ธ Permissions
Project CRUD, settings_json, brand voice / tone / audience context
HIGH
Four fixed roles (Owner/Admin/Member/Viewer) โ€” no custom permission engine yet
MEDIUM
๐Ÿ—„๏ธ Asset Storage & โš™๏ธ Settings
R2 direct upload, signed URLs, per-org storage quota
HIGH
Settings UI shared across all workflow modules
MEDIUM
Sane defaults so nothing requires configuration before first use
MEDIUM
D1 schema (23 migrations applied) confirmed matches Drizzle definitions in production
HIGH
Exposes: checkUsageLimit(org, metric), getPlan(org), getCreditBalance(org), applyDiscount(org, code), webhook handler for razorpay events.
razorpay Checkout + Billing Portal + Webhooks integrated
CRITICAL
Plan limits enforced at the API layer (runs/month, AI usage/month, seats) โ€” not just UI-hidden
CRITICAL
Usage dashboard, failed-payment handling, proration on upgrade
HIGH
Credit-based usage system live across all four plans (Free/Starter/Professional/Agency)
HIGH
GST-aware discount system โ€” USD-priced, INR-converted at checkout, discounts apply correctly either way
HIGH
๐Ÿชœ The Spine
๐Ÿ”ง Support Modules (parallel, non-blocking)
Exposes: Muqira.AI.generate({ prompt, context, tier }) โ€” the only function any workflow step is allowed to call. Also: selectModel(tier, taskType), renderPrompt(templateKey, variables), buildContext(projectId).
โšก AI Router v2 โ€” 7 Providers
7 providers (Groq, OpenAI, Anthropic, Gemini, Mistral, DeepSeek, OpenRouter) behind one OpenAI-compatible caller
CRITICAL
BYOK org-level encrypted provider keys, mk_live_ external API token generation
HIGH
๐ŸŽš๏ธ Model Routing & Tiering
27-model registry, Free/Starter/Professional/Agency tier mapping, pricing_tier + constraints field on every model
HIGH
requireApiKeyOrAuth middleware confirmed on external API routes
HIGH
Model registry audit system โ€” weekly cron, snapshot diffing, live provider checks, admin email alerts via Resend
HIGH
Manual audit trigger endpoint exposed in Admin Console โ€” Model Registry page
MEDIUM
๐Ÿ“ Prompt Template Engine & ๐Ÿงฉ Project Context
DB-backed, versioned prompt templates with category field
HIGH
POST /api/ai/render-template endpoint live, sessionStorage handoff confirmed
MEDIUM
Brand voice / audience / prior-output context auto-injected into every prompt
MEDIUM
๐Ÿ” Model Switching & Fallback
KV-backed circuit breaker per provider (3 failures/5min opens, 2-min cooldown), configurable fallback chain
HIGH
Fallback tested with a simulated provider outage โ€” not just configured
HIGH
Silent model substitution bug fixed โ€” GenerateResult carries a substitution field, orange warning banner shown in the UI whenever it fires
CRITICAL
Root cause fixed at source โ€” resolveKey() no longer silently returns null and falls through to Groq
CRITICAL
Per-request cost ceilings by plan tier, org-level override
CRITICAL
Heuristic complexity estimation, budget-aware model selection inside generate()
HIGH
Applies automatically to Console, workflows, and external API callers โ€” verified, not assumed
HIGH
๐Ÿ’ก
Key learning: per-request ceilings beat period pools for budget control โ€” more predictable, easier to reason about per-call cost exposure. Money safety must be enforced at multiple independent layers โ€” never rely on a single gate. The Agency plan previously had no real monthly dollar cap, only a credit-count proxy; this has since been fixed.
Replaces a blank-prompt-box flow with a guided three-step experience: pick a Purpose โ†’ get model/feature recommendations โ†’ generate. Files: purpose-registry.ts, PurposeSelector.tsx, classifyPrompt().
Uses These Platform Modules
๐ŸŽฏ Purpose-First Flow
Purpose Registry โ€” 11 intents mapped to model/feature recommendations
HIGH
Three-step PurposeSelector.tsx UI โ€” pick purpose, see recommendation, generate
HIGH
Smart Prompt Analysis โ€” classifyPrompt() auto-detects intent from free-text input
MEDIUM
Multi-lens model recommendation engine wired to the Purpose Registry
HIGH
Model substitution made visible to the user โ€” orange warning banner when a selected model is silently swapped
CRITICAL
๐Ÿงฐ Supporting Surfaces
Scripting tools + library โ€” reusable prompt/script assets
MEDIUM
History, stats, and templates views inside AI Studio
MEDIUM
Settings โ€” BYOK keys, defaults, feedback + attachment support
MEDIUM
Streaming responses (SSE) โ€” Anthropic live, extend to remaining 6 providers
HIGHKnown limitation โ€” Anthropic-only today
Mobile layout verified โ€” three-step flow usable one-handed, no horizontal scroll
MEDIUM
๐Ÿ’ก
Key learning: silent failures are the most dangerous bug class here โ€” silent model substitution was found and fixed by making it loud (visible banner) rather than by trying to eliminate every future edge case that could cause it.
Exposes: WorkflowDefinition schema, executeWorkflow(workflowId, triggerPayload), getRunStatus(runId), scheduleWorkflow(), triggerWebhook(workflowId, payload), validateStepOutput(step, output), cloneTemplate(templateId, projectId), dispatchWorkflowRun().
๐Ÿ“ Definition Schema & โš™๏ธ Execution Engine
JSON-schema validated workflow definitions โ€” no proprietary DSL
CRITICAL
workflow-engine.ts, routes/workflows.ts, routes/workflow-runs.ts mounted in index.ts
CRITICAL
Trivial test workflow ("generate โ†’ validate โ†’ output") runs end-to-end
CRITICALPhase 3 exit criteria
โฑ๏ธ Trigger System & ๐Ÿงฉ Step Type Library
Manual / webhook-per-workflow triggers working
HIGH
Recurring Cron trigger โ€” workflow-scheduler.ts, next_run_at, runs pass through the same quota gate as manual runs
HIGH
9 live step types: ai_task, validation, transform, delay, integration_action, branching, human_approval, browser_automation, local_file_access, image_generation
HIGH
โœ… Validation Layer & ๐Ÿ“ฌ Queue Processing
JSON schema validation (exists/min_length/max_length/contains) + transform step (trim/case/parse_json)
MEDIUM
dispatchWorkflowRun() โ€” queue_attempts tracking with backoff between retries
HIGH
Dead-letter flag once MAX_QUEUE_ATTEMPTS is exceeded โ€” run stops retrying forever
HIGH
Dead-letter runs surfaced in Admin Console (Workflows page)
HIGHNo push alert yet โ€” see Technical Debt
๐Ÿ“‹ Workflow Templates Phase 7
Template gallery UI
LOW
One-click clone into a project (copy-on-create)
LOW
Templates owned by a system org, is_template flag on workflows
LOW
Template versioning independent of user customizations
LOW
โš ๏ธ
Open gap: dead-letter workflow runs are visible in Admin but there's no email/Slack push alert. A stuck cron workflow could sit dead-lettered for days before anyone looks.
Exposes: getConnector(id), listConnectors(), runConnectorAction(orgId, connectorId, action, params) โ€” the entire SDK contract. Adding a new connector is one file implementing the contract + one line in registry.ts. Zero engine changes required.
๐Ÿ”Œ Connector SDK & ๐Ÿ”‘ Credential Management
Single Connector contract โ€” authenticate, list actions, execute, handle webhook
CRITICALlib/connectors/registry.ts
Encrypted credential storage, decrypted per-call only, revoke-on-disconnect
CRITICAL
Per-(org, provider) rate limiting โ€” 20 actions/min, protects the org's standing with the third-party platform
CRITICALSeparate from the AI burst limiter
๐Ÿ’ฌ Communication โœ“ Live
Webhook โ€” generic inbound/outbound actions
HIGH
Slack โ€” post message, channel actions
HIGH
Discord โ€” post message, channel actions
MEDIUM
Telegram โ€” send message via bot API
MEDIUM
Email โ€” transactional send via Resend
HIGH
WhatsApp โ€” send message via Business API
MEDIUM
๐Ÿ“ฑ Social โœ“ Live โ€” Phase 4 dependency
X/Twitter โ€” post, thread, engagement pull
HIGH
Meta โ€” Facebook Pages + Instagram via Graph API
CRITICAL
LinkedIn โ€” post, company page, engagement pull
CRITICAL
YouTube โ€” upload, metadata, channel actions
MEDIUM
Reddit, Threads remain future candidates โ€” Phase 7+.
๐Ÿ“ฐ Publishing & Commerce โœ“ Live
WordPress โ€” posts, categories/tags, featured images
HIGH
Ghost โ€” posts, tags, publishing
HIGH
Shopify โ€” products, orders, storefront actions
MEDIUM
๐Ÿ—‚๏ธ Productivity & Data โœ“ Live
Notion โ€” page/database read-write
MEDIUM
Airtable โ€” record read-write
MEDIUM
Trello โ€” card/board actions
LOW
Google Sheets โ€” read-write rows
MEDIUM
Google Docs โ€” create/update documents
MEDIUM
๐Ÿงฐ Marketing & Dev-Tools โœ“ Live
Mailchimp โ€” audience + campaign actions
MEDIUM
Brevo โ€” email/SMS campaign actions
LOW
GitHub โ€” issues, PRs, repo actions
MEDIUM
Jira โ€” issue create/update
LOW
Asana โ€” task create/update
LOW
๐Ÿ“Š Analytics & SEO โœ“ Live โ€” was Phase 6
Google Search Console โ€” search performance data
HIGH
Google Analytics (GA4) โ€” traffic/conversion data
HIGH
GA4 data wired into a dedicated Analytics dashboard
MEDIUMPhase 6 โ€” connector done, dashboard not started
Search Console data wired into a dedicated Analytics dashboard
MEDIUMPhase 6 โ€” connector done, dashboard not started
๐Ÿ›ฐ๏ธ Future Connector Candidates
Build opportunistically, none required for current products: Gmail, Google Calendar, Reddit, Threads, Web Search/browser automation, Semrush, Ahrefs, Zapier-style generic HTTP action builder.
Exposes: track(eventType, payload) โ€” callable from anywhere in the stack.
Typed event schema, org/project scoping on every event
HIGH
Write to Cloudflare Queue first, batch-insert into Postgres โ€” avoid write amplification
MEDIUM
Content Performance Tracking โ€” per-post dashboard, trend-over-time, best-performing surfacing
MEDIUM
Join published content to engagement metrics pulled via Analytics Connectors
MEDIUM
Click & Engagement Tracking โ€” link shortening/tracking on outbound URLs
MEDIUMAlShorty doubles here
Engagement event capture wired to Event Pipeline
MEDIUM
Trigger: Manual ("create a post about X") or scheduled (e.g. "3 posts/week"). Steps: Topic Research โ†’ Content Generation โ†’ Image Generation โ†’ Validation โ†’ Scheduling โ†’ Publishing. Success metric: posts published per org/month, scheduled-vs-published ratio, engagement lift vs. manual posting baseline.
Uses These Platform Modules
Build Checklist
Topic Research step โ€” pulls context, optionally calls Research Automation sub-step
HIGH
Content Generation step โ€” AI Generation node via prompt templates
CRITICAL
Image Generation step
HIGH
Validation step before anything publishes
CRITICAL
Scheduling step โ€” Delay/Schedule node, calendar-aware
HIGH
Publishing step โ€” Integration Action node to LinkedIn/Facebook/Instagram
CRITICAL
Calendar view + post preview + approval queue UI
HIGH
Exit criteria: a real post goes live with zero manual editing required
CRITICALPhase 4 exit criteria
Uses These Platform Modules
Build Checklist
Branded as the workflow-automation product surface, not just an internal engine
MEDIUM
Workflow list + detail/run views polished for a real customer-facing product
HIGH
Workflow templates browsable and cloneable from the Flow UI
MEDIUM
Run history, dead-letter, and retry visibility in the Flow UI
HIGH
Cron/scheduled trigger configuration exposed in the Flow UI
MEDIUM
Flow pricing/positioning finalized as a named plan feature, not implicit
MEDIUM
Uses These Platform Modules
Build Checklist
Keyword research tool โ€” calls AI Router internally, domain logic only
CRITICAL
SERP analysis
HIGH
Site audit โ€” Browser Automation node, crawl + checks
HIGH
Search Console connector wired
MEDIUM
Rank tracking over time
MEDIUM
GA4 connector wired for traffic correlation
MEDIUM
Production deployment confirmed on Cloudflare Pages
HIGH
MuqiraBar footer (theme-aware) confirmed live
MEDIUM
Uses These Platform Modules
Build Checklist
Link creation โ€” custom slug, expiry, max-clicks (Pro)
CRITICAL
Redirect engine โ€” KV lookup, sub-10ms response
CRITICAL
Click analytics โ€” track clicks, countries, devices, referrers
HIGH
Bio pages โ€” link-in-bio with multiple links
MEDIUM
QR code generation โ€” per-link QR codes
MEDIUM
Uses These Platform Modules
Build Checklist
PDF merge/split/rotate core operations
CRITICAL
jsPDF text-primitive export confirmed โ€” no html2canvas, no 16,384px failure mode
HIGH
AI-assisted PDF summarization / Q&A via AI Router
MEDIUM
R2-backed storage for uploaded/generated PDFs, signed URLs
HIGH
Production deployment confirmed
HIGH
Admin account: chatmatterji@gmail.com. Two independent gates protect this surface โ€” a compromised session alone is not enough to reach org-suspension, payment, or model-registry controls.
๐Ÿ› ๏ธ 12 Admin Pages
Sub-nav sidebar โ€” all admin pages reachable, none orphaned
HIGH
Organizations โ€” view/search/suspend any org with reason shown to the org
HIGH
Users โ€” view/search users across orgs
MEDIUM
Subscriptions โ€” view/manage plan assignments
HIGH
Payments โ€” razorpay transaction visibility
HIGH
AI Requests โ€” inspect logged AI calls, cost, model used
HIGH
Model Registry โ€” live model list, pricing tiers, constraints, manual audit trigger
HIGH
Usage โ€” cross-org usage dashboard
MEDIUM
Discounts โ€” GST-aware discount management
MEDIUM
Integrations โ€” connector health/status overview
MEDIUM
Workflows โ€” cross-org workflow run visibility, dead-letter surfacing
HIGH
Assets โ€” R2 storage overview
LOW
๐Ÿ’ก
Key learning: nine admin pages sat unreachable until a proper sub-nav sidebar was built โ€” dead code and drift accumulate silently; regular navigation audits catch what a feature list alone won't.
๐ŸŒ Public Pages
Blog โ€” list + dynamic post pages, SEO-structured
HIGH
Changelog โ€” public-facing shipped-features log
MEDIUM
Docs โ€” guide index + dynamic guide pages
HIGH
Tools โ€” free top-of-funnel tools directory page
MEDIUM
Labs โ€” experimental/early-access features page
LOW
Status page โ€” public service status + incident history/timeline
HIGH
About, Careers, Press, Contact โ€” company/trust pages
MEDIUM
Legal โ€” Terms, Privacy, and related policy pages
HIGH
Products โ€” marketing pages per sub-product (SEOventra, AlShorty, Documateo, AI Studio)
HIGH
llms.txt served for AI-crawler discoverability
LOW
๐ŸŽฏ
SEO note: Status, Changelog, and Docs are underused SEO surfaces most SaaS competitors skip โ€” each incident write-up, changelog entry, and doc page is a long-tail indexable page that also builds trust. Keep publishing to these even when there's no "content marketing" campaign running.
๐Ÿ“‹ Phase 7 Build Checklist
Workflow Templates system โ€” gallery, one-click clone into project
MEDIUM
SEO Automation workflow module (Analyze โ†’ Issues โ†’ Recommend โ†’ Tasks)
HIGH
Content Marketing Automation workflow module
MEDIUM
Research Automation workflow module (shared sub-step for others)
MEDIUM
Product Launch Automation workflow module
LOW
Directory Submission Automation workflow module
LOW
๐ŸŽ€ MuqiraBar โ€” Cross-App Shared UI
MuqiraBar universal footer โ€” theme-aware via useTheme(), hardcoded prop removed
MEDIUM
SiteFooter.tsx โ€” conditional full Footer vs MuqiraBar by route
MEDIUM
Propagated to all sub-product repos with their own ThemeProvider
MEDIUM
Repos without their own ThemeProvider โ€” prop pinned or ThemeProvider.tsx copied
LOW
โš ๏ธ
The platform's #1 named risk: multi-tenant data isolation. Every Core table must be scoped by org_id with zero exceptions โ€” a single missing filter is a cross-customer data leak.
๐ŸŽฏ
The bar: a feature is not "done" until it works in production, not just locally. Every fixed critical/high bug gets a regression test so it can't silently come back.
Phase 0 โ€” Repo & Environment Setup โœ“ Done
Preโ€“Month 1 ยท โ–ผ 4 deliverables
1
Monorepo structure
apps/api (Hono/Workers/D1), apps/web (Next.js 15/Pages) โ€” muqira-web / muqira-live, GitHub ataurCODEX/muqira-web
2
CI/CD pipeline
Lint, test, build, deploy on every merge to main
3
Staging + production environments
Separate Cloudflare environments, separate secrets
4
Secrets management baseline
Wrangler secrets, .dev.vars locally, never committed
๐ŸŽฏ
Exit criteria: a blank "hello world" Worker deploys automatically on merge to main.
Phase 1 โ€” Muqira Core โœ“ Done
Months 1โ€“2 ยท โ–ผ 7 deliverables
1
Identity & Authentication
Email OTP (Resend), Google OAuth, GitHub OAuth, JWT sessions, RBAC middleware
2
Organizations & Teams
Create/invite/remove members, org switcher, personal org auto-created on signup, admin-driven suspension with customer-visible reason
3
Projects
CRUD + project-level settings_json + brand context
4
Permissions (RBAC)
Owner/Admin/Member/Viewer โ€” four fixed roles
5
Billing Foundation
razorpay Checkout + webhooks, plan limits enforced at the API layer, credit system, GST-aware discounts
6
Asset Storage
R2 direct upload, signed URLs, per-org quota
7
Settings
jsonb columns on organizations/projects โ€” no new infra
๐ŸŽฏ
Exit criteria: auth + org + billing all work end-to-end with zero workflow logic yet built.
Phase 2 โ€” Muqira AI โœ“ Done
Months 2โ€“3 ยท โ–ผ 7 deliverables
1
AI Router v2
7 providers (Groq, OpenAI, Anthropic, Gemini, Mistral, DeepSeek, OpenRouter), single OpenAI-compatible caller, shared generate-pipeline module
2
Model Registry & Tiering
27-model registry, audited weekly with snapshot diffing + live provider checks, BYOK org-level encrypted keys, mk_live_ external API tokens
3
Prompt Template Engine
DB-backed, versioned prompt templates with category field, POST /api/ai/render-template
4
Project Context Management
Brand voice / audience / prior-output injection into every prompt
5
AI Usage Tracking & Cost Engine
Per-request cost ceilings by plan tier, heuristic complexity estimation, budget-aware model selection โ€” the Golden Rule enforcement layer
6
Model Fallback (hardened)
KV-backed circuit breaker per provider (3 failures/5min opens, 2-min cooldown), configurable fallback chain
7
AI Studio v2 โ€” Purpose-First
Purpose Registry (11 intents), three-step PurposeSelector UI, Smart Prompt Analysis, multi-lens recommendation engine, visible model-substitution warning banner
๐ŸŽฏ
Exit criteria: a test call through the Router correctly routes a free-tier user to a free-tier model and a premium-tier user to the best available model, with cost logged.
Phase 3 โ€” Workflow Engine โœ“ Done
Months 3โ€“4 ยท โ–ผ 6 deliverables
1
Workflow Definition Schema
JSON-schema validated definitions, no proprietary DSL
2
Workflow Execution Engine
workflow-engine.ts, routes/workflows.ts, routes/workflow-runs.ts โ€” sequencing, state, retry
3
Trigger System
Manual / recurring Cron (workflow-scheduler.ts, quota-gated like manual runs) / webhook-per-workflow
4
Step Type Library
9 live step types: ai_task, validation, transform, delay (pause/resume via scheduled_jobs), integration_action, branching, human_approval, browser_automation, local_file_access, image_generation
5
Validation Layer
JSON schema (exists/min_length/max_length/contains) + transform (trim/case/parse_json)
6
Task/Queue Processing
dispatchWorkflowRun() โ€” retry with backoff + dead-letter after MAX_QUEUE_ATTEMPTS, surfaced to Admin instead of retrying forever
๐ŸŽฏ
Exit criteria: a trivial test workflow ("generate text โ†’ validate โ†’ output") runs end-to-end through Trigger โ†’ Step โ†’ Validation โ†’ Output with zero workflow-module-specific code in the engine.
Phase 4 โ€” Workflow #1: Social Media Automation In Progress
Months 4โ€“6 ยท โ–ผ 3 deliverables
1
LinkedIn, Meta (Facebook + Instagram), X, YouTube connectors
Auth, post, fetch engagement metrics โ€” all four live in the connector registry
2
Social Media Automation workflow
Topic Research โ†’ Content Generation โ†’ Image Generation โ†’ Validation โ†’ Scheduling โ†’ Publishing
3
Workflow-specific UI
Calendar view, post preview, approval queue
๐ŸŽฏ
Exit criteria: a real post, generated end-to-end by the workflow, goes live on a connected LinkedIn/Facebook/Instagram account with no manual editing required.
Phase 4.5 โ€” Muqira Connect: Full Connector Build-Out โœ“ Done
Parallel to Phase 4 ยท โ–ผ 8 deliverables
1
Communication
Webhook, Slack, Discord, Telegram, Email, WhatsApp
2
Social
X/Twitter, Meta, LinkedIn, YouTube
3
Publishing & Commerce
WordPress, Ghost, Shopify
4
Productivity & Data
Notion, Airtable, Trello, Google Sheets, Google Docs
5
Marketing
Mailchimp, Brevo
6
Dev & Project Management
GitHub, Jira, Asana
7
Analytics & SEO
Google Search Console, Google Analytics (GA4)
8
Per-connector rate limiting
20 actions/min per (org, provider) โ€” protects the org's standing with the third-party platform, separate from the AI burst limiter
๐ŸŽฏ
Exit criteria: adding a new connector requires only implementing the Connector contract and one registry line โ€” proven by shipping 25 connectors across 6 categories on the same registry.
Phase 4.6 โ€” Admin Console & Marketing Site โœ“ Done
Parallel to Phase 4 ยท โ–ผ 2 deliverables
1
Admin Console
12 pages behind is_platform_admin + ADMIN_SECRET: Organizations, Users, Subscriptions, Payments, AI Requests, Model Registry, Usage, Discounts, Integrations, Workflows, Assets โ€” reachable via a proper sub-nav sidebar
2
Marketing site
Blog, Changelog, Docs, Tools, Labs, Status (with incident history), About/Careers/Press/Contact, Legal, per-product marketing pages, llms.txt
๐ŸŽฏ
Exit criteria: a platform operator can see and act on every org, subscription, payment, AI request, and workflow run from one console.
Phase 5 โ€” Publishing Infrastructure Hardening In Progress
Months 6โ€“8 ยท โ–ผ 2 deliverables
1
OAuth/credential hardening at scale
Encryption at rest, strict access scoping, refresh rotation, revoke-on-disconnect verified for every live connector
2
Scheduler + queue hardening
Higher volume, dead-letter alerting (email/Slack) โ€” currently surfaced in Admin only, no push alert yet
๐ŸŽฏ
Exit criteria: connector build-out already proves the SDK works (Phase 4.5) โ€” this phase hardens what exists under real volume.
Phase 6 โ€” Analytics Layer Not Started
Months 8โ€“10 ยท โ–ผ 4 deliverables
1
Event Pipeline
Cloudflare Queue โ†’ batch-insert Postgres, typed event schema
2
GA4 + Search Console connectors
Already live in Muqira Connect (Phase 4.5) โ€” this phase is wiring them into a dedicated Analytics dashboard, not building the connectors themselves
3
Content Performance Tracking
Per-post dashboard, trend-over-time, best-performing surfacing
4
Click & Engagement Tracking
Link shortening/tracking layer โ€” AlShorty doubles here
๐ŸŽฏ
Exit criteria: a user can see real engagement numbers (not just "published" status) on content the Social Media workflow generated.
Phase 7 โ€” Workflow Marketplace & New Modules Multi-Workflow
Months 10โ€“12 ยท โ–ผ 6 deliverables
1
Workflow Templates system
Gallery, one-click clone, system-org-owned templates
2
SEO Automation
Analyze Website โ†’ Find Issues โ†’ Recommendations โ†’ Tasks
3
Content Marketing Automation
Brief Intake โ†’ Research โ†’ Draft โ†’ Validate/Edit โ†’ Publish
4
Research Automation
Define Question โ†’ Web Research โ†’ Synthesize โ†’ Structured Output
5
Product Launch Automation
Analyze Product โ†’ Generate Assets โ†’ Launch Plan โ†’ Publish
6
Directory Submission Automation
Gather Info โ†’ Match Directories โ†’ Generate Copy โ†’ Submit โ†’ Track
๐ŸŽฏ
Exit criteria: a second workflow module ships in materially less time than Workflow #1 did, because the platform layers already exist.
โœ… Marketing Action Checklist
โœ… SEO Action Checklist
โœ… Business Action Checklist
๐Ÿ“
The core question: Can another workflow module use this in the next 12 months? YES โ†’ Build in a Layer (packages/ or platform API). NO โ†’ Build in the workflow module's folder.
Feature Ownership
FeatureOwnerLocationNotes
AuthenticationCore Layerapps/api/auth/All workflow modules import this
AI RoutingAI Layerpackages/ai/router.tsOnly entry point for AI calls
Workflow ExecutionWorkflow Enginepackages/workflow-engine/Every module's steps run through this
Cost TrackingAI Layerpackages/ai/cost-engine.tsAuto-logged per request
Billing / razorpayCore Layerapps/api/billing/One razorpay account
File StorageCore Layerapps/api/storage/R2 via platform service
Connector SDKMuqira Connectlib/connectors/registry.tsSingle Connector contract, 25 connectors registered
Topic Research / Content GenSocial Automationworkflow definitionCalls AI Router internally
Keyword Research / SERP AnalysisSEOventraapps/seoventra/Domain logic only
PDF ProcessingDocumateoapps/documateo/Storage via platform R2
Link Shortening / Click TrackingAlShortyapps/alshorty/Also serves as platform click layer
โš ๏ธ
If you find yourself about to build one of these: stop, re-read the Guiding Principles, and ask if there's a simpler path. Every item on this list has killed bootstrapped companies.
โœ•
Kubernetes or container orchestration โ€” Cloudflare Workers scale globally for free.
โœ•
Microservices split of apps/api โ€” modular monolith on Workers until proven independent scaling needs.
โœ•
Event mesh / message broker (Kafka, RabbitMQ) โ€” Cloudflare Queues is enough until serious scale.
โœ•
Multi-region deployment logic โ€” Workers are already globally distributed by default.
โœ•
Custom AI model training or fine-tuning โ€” route across 7 existing providers instead.
โœ•
Real-time collaborative editing (Google-Docs style) โ€” massive complexity, uncertain return at this stage.
โœ•
Enterprise SSO โ€” not before real revenue and an actual enterprise customer asking.
โœ•
Granular custom-permission engine โ€” Owner/Admin/Member/Viewer is enough for years.
โœ•
Plugin marketplace โ€” not before 3+ workflow modules are live with real usage.
โœ•
Native mobile apps โ€” responsive web is sufficient; native adds huge maintenance overhead.
โœ•
On-premise / self-hosted offering โ€” cloud SaaS only until an enterprise customer pays for it.
โœ•
Custom analytics infrastructure โ€” lightweight pipeline first, not a Snowflake-style stack.
โœ•
White-label reseller system โ€” after PMF only.
โœ•
Affiliate / referral program infrastructure โ€” after PMF only.
โœ•
Rebuilding billing/auth/storage per sub-product โ€” everything reusable goes in Muqira Core, no exceptions.
Frontend
Next.js 15ReactTailwindCSSshadcn/uiCloudflare Pages
Backend
Cloudflare WorkersHonoTypeScript
Database
D1 (Cloudflare SQLite)Drizzle ORM23 migrations applied
Queue & Storage
Cloudflare QueuesCloudflare R2Cloudflare KV
Auth
Resend (Email OTP)Google OAuthGitHub OAuthJWT Sessions
AI Providers (7)
GroqOpenAIAnthropicGeminiMistralDeepSeekOpenRouter
Payments
razorpayCheckoutBilling PortalWebhooks
PDF Generation
jsPDF text primitives
Never html2canvas โ€” non-selectable output, 16,384px page-height failure mode.
Monitoring & VCS
SentryPostHog / CF AnalyticsGitHub
RiskMitigation
AI Router as a single point of failureEvery workflow module depends on it โ€” build Model Fallback early, not as an afterthought.
OAuth token securityA leaked LinkedIn/Facebook token is a real liability โ€” encryption at rest + strict access scoping on the token store from day one.
Multi-tenant data isolationEvery Core table scoped by org_id with zero exceptions โ€” one missing filter is a cross-customer data leak.
Cost overruns from AI usageThe Cost Engine must exist before Workflow #1 has real paying users, not after the first surprising bill.
Scope creep across workflow modules"Build once, reuse forever" is the safeguard โ€” if a Phase 7 module needs a feature that doesn't fit an existing Layer, redesign the module, don't bolt on a one-off.
Connector maintenance burdenEvery third-party API changes over time โ€” budget ongoing maintenance capacity per connector, not just initial build time.
Title
Severity
Est. hours
Decision
Reason
Alternatives considered
Current Focus
Blockers
Next 3 Actions
Decisions Made (free-form)
Open Questions
Abandoned / Deprioritized
Ideas Backlog