Quality Notes - SmallBiz Ops Copilot
Updated: 2026-05-30
These notes keep the repository easy to review without overstating what is production-ready.
Profile
| Field | Value |
|---|---|
| Repository | smallbiz-ops-copilot |
| Primary stack | TypeScript/JavaScript, Cloudflare |
| Review expectation | Local review should not require customer data or production credentials. |
Commands
| Purpose | Command |
|---|---|
| Full local gate | npm run verify |
| Test suite | npm test |
| Lint | npm run lint |
CI
- .github/workflows/architecture-blueprint.yml
- .github/workflows/ci.yml
- .github/workflows/dependency-review.yml
- .github/workflows/repository-health.yml
- .github/workflows/repository-surface.yml
- .github/workflows/secret-scan.yml
Boundaries
- Demo, fixture, and synthetic-data modes must stay clearly labeled.
- Provider keys, tenant credentials, warehouse secrets, medical data, financial data, or customer logs must never be committed.
- Production claims require environment-specific validation, monitoring, rollback, and human approval paths.
- Screenshots, videos, and README claims should match the current implementation and documented commands.
Before Presenting
- README explains the user, the pain, the safety boundary, and the fast proof path.
docs/service-launch-playbook.mdexplains the product, pilot, service, or proof-of-value angle when relevant.- Tests or smoke checks are documented even when optional infrastructure is unavailable.
- Failure modes and unsupported claims are visible before the project is presented externally.
Checked-in evidence inventory
The following files and commands are discovered from this repository rather than inferred from a generic template. Their presence does not prove production readiness by itself; it gives reviewers a concrete path to reproduce the maintained checks.
Verification commands
npm run verifynpm run testnpm run lint
Test files
tests/approve-send.test.mjstests/copilot-edge.test.mjstests/copilot.test.mjstests/date-edge.test.mjstests/date-range.test.mjstests/db-helpers.test.mjstests/draft-provider-config.test.mjstests/draft-runtime.test.mjstests/frontend-metadata.test.mjstests/http-helpers.test.mjstests/integration-guard-edge.test.mjstests/integration-guard.test.mjstests/integration-status.test.mjstests/korean-public-apis.test.mjstests/logger.test.mjstests/meta.test.mjstests/openai-runtime-key.test.mjstests/product-positioning.test.mjstests/ticket-status-edge.test.mjstests/ticket-status.test.mjs
Continuous integration workflows
.github/workflows/architecture-blueprint.yml.github/workflows/ci.yml.github/workflows/dependency-review.yml.github/workflows/repository-health.yml.github/workflows/repository-surface.yml.github/workflows/secret-scan.yml
How to interpret the result
A passing local or CI check supports only the behavior covered by that check. It does not establish security certification, regulatory approval, clinical validity, production availability, or a customer outcome. Review the source, fixtures, environment assumptions, and failure paths before extending the result to another deployment.