Development history
PublicVoiceShield evolved through product research, problem definition, rapid implementation and iterative refinement. The milestones below are grouped by month rather than presented as a commit-by-commit timeline.
Pre-development concept phase
- Identified the impact of hostility and trolling on public participation
- Defined the need to distinguish criticism, disagreement, abuse and genuine questions
- Established the principle: “AI advises. Humans decide.”
- Developed the idea of serving public figures, organisations, supporters and members of the public
- Outlined the responsibilities of handling public commentary safely and lawfully
- Set out the expectation that every stored record would be tenant-isolated from the outset
June 2026
- Early product research and decision-framework development
- Exploration of public-figure communication, audience risk and responsible reply support
- Definition of human oversight, escalation and audit requirements
- Data modelling work: deciding what needed to be stored, for how long, and who should be able to see it
- Design of the multi-tenant database structure around organisations and their members
- Planning of the append-only audit approach so decisions could be evidenced rather than overwritten
July 2026
- PublicVoiceShield MVP implementation
- Database installation and configuration on managed PostgreSQL
- Creation of the core schema: profiles, organisations, organisation members and invitations
- Creation of the analysis schema: social posts, thread analyses, analysed comments and comment decisions
- Creation of the research and evidence schema: research sessions, queries, sources, cache and evidence approvals
- Creation of the governance schema: privacy requests, policy versions, policy acceptances, cookie preferences and retention settings
- Row-level security policies, explicit table grants and security-definer membership checks
- Database indexing and performance review for higher comment and thread volumes
- Authentication and organisation accounts
- Analyse Thread workflow
- Secure server-side AI analysis
- Reply identity modes
- Human approval and audit trail
- Comment Review workspace
- Optional public-source research
- UK-law-assisted replies
- Privacy, legal and compliance pages
- Retention wording corrections
- Security and scalability review
- Tenant-isolation verification across organisations
- Tutorial video
- Private source-control integration
- Published controlled MVP
July 2026 — Professional Email, Support and Privacy Communications
- Introduced a branded email and case-communication system across authentication, support, privacy and security workflows
- Added fixed server-side sender identities for automated account emails, customer support, privacy rights requests and security correspondence
- Sender selection controlled by the server, so browsers and users cannot supply arbitrary sender addresses, reply-to addresses or recipients
- Branded acknowledgements for support cases, with customer-visible replies and closure messages remaining subject to authorised human action
- Internal investigation notes kept separate and never included in customer emails
- Structured PublicVoiceShield reference numbers for privacy rights requests
- Controlled acknowledgement, progress-update and outcome workflows for privacy correspondence
- Restricted delivery audit log recording sender identity, request reference, delivery status, approver and provider message information
- Professional PublicVoiceShield mailboxes configured for support, privacy and security correspondence on the organisation's own domain
July 2026 — Platform Assurance and Workspace Refinements
- Independent security review of database access controls, with least-privilege permissions applied to restricted administrative records
- Review of third-party software advisories, with findings assessed, documented and recorded as part of ongoing maintenance
- Further hardening of assistant and support records so access remains limited to the owning account or authorised platform staff
- Cost and performance review of the AI processing pipeline, with usage recorded against each analysis for internal oversight
- Added the ability to attach later comments to an existing analysed post, with a preview and confirmation step before anything is saved
- Refinements to comment separation and delivery confirmation within the comment-addition workflow
- Tidied the global footer and relocated contact details into the relevant support, privacy and security areas
July 2026 — Mobile Readiness and Brand Consistency
- Readiness assessment for a mobile application build, covering layout, navigation and account journeys on smaller screens
- Mobile presentation hardening, including safe-area handling and touch-friendly controls throughout the workspace
- Added an authenticated account closure journey to meet mobile app store expectations
- Prepared the supporting configuration and documentation required for a future store submission
- Real-device testing on mobile browsers, covering sign-in, analysis, review and account journeys
- Consistent PublicVoiceShield branding across browser tabs, home-screen icons and empty-state artwork
- Upgraded the published plan so no third-party editing badge appears, giving users a fully PublicVoiceShield-branded experience
July 2026 — Controlled Beta Access and Cost Governance
- Introduced approved-access controls so the service runs as a controlled beta rather than an open sign-up
- Server-side usage allowances for AI-assisted work, applied per account and enforced before any request is processed
- Usage recorded only against successful results, with allowances returned automatically when a request does not complete
- A protected primary owner role, with account roles and status shown in an administration view
- Administration dashboard for reviewing accounts, approving access and monitoring activity and cost
- Configurable warning levels and an overall processing limit, with a global pause control for AI-assisted features
- Owner notifications for new sign-ups and threshold events, using the branded email identities
- Introduced an optional voluntary contribution towards development, presented in the Help Centre with no effect on access or features
- Registered interest recorded securely and relayed to the support mailbox for a human response
August 2026 — Controlled Beta Test Planning
- Prepared a structured controlled-beta test plan covering eight assessment areas
- Account access: sign-up, verification, sign-in and password recovery journeys
- Organisations: creation, onboarding, member invitation and member removal
- Analysis quality: separating disagreement, criticism, abuse and genuine questions
- Reply support: identity and tone handling across the available response options
- Ongoing threads: adding later comments to an existing analysed post
- Evidence features: optional public-source research and UK-law-assisted replies
- Governance: usage allowances, cost controls and audit records
- Communications: support, privacy and security email journeys
- Mobile: repeat testing of the full workflow on phone-sized screens
- Researched and compared options for participant recruitment, feedback capture and issue triage
- Recorded the preferred options, assessed against cost, privacy exposure and administrative effort
August 2026 — Assisted Decision Quality and Cost Discipline
- Structured review of how assisted work is routed, so routine high-volume steps and more sensitive judgement steps are handled proportionately
- Anonymised side-by-side evaluation against existing test material, measured on accuracy, relevance, tone, caution and responsiveness
- Cautious-by-default behaviour reinforced for sensitive material, with human referral preferred over an automated suggestion
- Per-request cost and usage recorded for internal oversight, with warning levels and an overall processing limit retained
- Owner-only view for reviewing routing decisions and evaluation results
August 2026 — Access Control Assurance
- Independent review of account permissions across invitations, onboarding and profile updates
- Server-side enforcement of role assignment, so no permission can be granted from the browser
- Database-level guards added alongside application checks, giving two independent layers
- Regression tests covering privilege escalation attempts, retained as part of the standard test suite
- Repeat security scan completed after the changes
August 2026 — Relevance by Organisation Type
- Introduced an organisation-type-aware catalogue so each account sees only the optional workspaces relevant to it
- Types covered include elected representatives and public offices, councils and local authorities, housing associations, retail and customer-service organisations, charities, education, healthcare, public bodies and communications agencies
- Unreleased areas are shown as planned rather than offered, and are never switchable by an account owner
- Every eligibility rule re-applied on the server, with the browser view treated as presentation only
- Automated tests covering every organisation type, to confirm the offered set changes with the selection
August 2026 — Informed Onboarding and Governance Controls
- Removed any pre-selected organisation type so the choice is always deliberate
- Each type presented as a described choice that states plainly what it changes and what it does not
- Settings mirrors the onboarding wording, so the two never disagree
- Organisations we have not yet classified are marked for review rather than granted anything automatically
- Platform-owner governance controls for correcting an organisation type or recording a documented exception, with a reason required and an audit record kept
August 2026 — Working at Scale
- Account administration reworked into a searchable, sortable and collapsible list with status filtering and organisation context
- Direct links from an account to the relevant governance controls
- Comment review toolbar for long discussions, with ordering by sequence, author, risk or undecided-first
- Filtering by category and recommended action, with progressive loading for very long threads
- Internal notification when a new support case is raised, so requests reach a person promptly
August 2026 — Audience Understanding Workspace
- First optional workspace released, grouping already-analysed comments into recurring themes
- Recurring unanswered questions surfaced, with the human decision on any clarification recorded
- No new data collected: the workspace reuses material the organisation has already submitted
- Wired into the controlled-beta controls: approved accounts only, usage allowances, cost limits and the global pause
- Existing accounts brought onto the same allowance basis as new ones
August 2026 — Privacy by Design and Records of Processing
- Diagnostic logging rewritten so personal details and access tokens are removed before anything is recorded
- Account closure extended to clear the settings and allowance records that can be safely removed, with the limited items kept for audit stated openly
- Settings and closure screens updated so people are told what is deleted and what is retained, and why
- Supplier and processing records corrected to describe the actual route taken by assisted analysis
- Formal documentation pack drafted for the operator's compliance file, with outstanding owner decisions listed rather than assumed
August 2026 — Public Site Quality and Discoverability
- Independent read-only review of the live site covering links, response codes, page titles, descriptions and mobile usability
- Confirmed findings corrected: canonical and social addresses now point to the live domain on every public page
- Search-engine instructions and the site index aligned to the same domain, with sign-in and account screens excluded from indexing
- Touch targets on shared page elements enlarged to meet accessibility guidance
- No page wording, design, access rules or product behaviour altered by the corrections
August 2026 — Assurance of Controlled Access
- Re-confirmed that every new sign-up is held for the operator's approval before any assisted feature can be used, enforced on the server rather than in the interface
- Administrative registers restricted so sensitive governance references are visible only to the operator, with a reduced view for signed-in users
- Governance trail confirmed as append-only and unreachable from the application
- Independent security review re-run, findings addressed or recorded with reasons
August 2026 — Multi-Platform Link Recognition
- Support for links from the major public discussion platforms, recognised by address only
- No account connection, no automated collection and no posting, hiding or reporting anywhere: discussion text is always supplied by the person using the service
- Analysis records reduced to structure and outcome only, with no capacity to hold submitted wording
- A clear control to clear the working session, with plain wording about what that does and does not cover
- Operator-only register recording the permitted status of each platform, with every change logged and a reason required
August 2026 — Processing Route Review
- Reviewed how assisted analysis reaches its processing provider, and prepared a simpler, more directly accountable route
- Owner-only test mode used first, so nothing changed for accounts while the option was assessed
- Anonymised side-by-side comparison against existing test material before any recommendation was made
August 2026 — Supplier Assurance and Approved Wording
- Supplier data-processing terms reviewed and formally recorded, including retention position and applicable safeguards
- Every proposed public wording change presented side by side for owner approval before publication
- Amendments applied exactly as approved, with unverified details marked as unconfirmed rather than assumed
August 2026 — Controlled Change and Verification
- Agreed a strict sequencing rule so published wording never described a route that was not yet in use
- Change carried out as a single controlled operation: readiness checks, publication, switch, verification and a prepared rollback
- No substitution behaviour: a request that cannot use its intended route is refused and referred for owner review rather than quietly handled elsewhere
- Every step recorded in an append-only governance trail
- Read-only pre-publication and post-publication verification against the live site and live settings
August 2026 — Presentation Refinement
- Design pass for a calmer, more authoritative feel, within the existing brand identity
- Clearer hierarchy, steadier spacing, refined panels, tables and empty states, and a clearer distinction between ordinary and higher-risk actions
- Improved readability on long governance pages and further mobile refinement
- No change to wording, permissions, routing or product behaviour
Created and developed by Mohammad Asif. Built from sustained product thinking, rapid implementation and iterative testing.