FIFreeIdeaStore
SI
Contributor profile

Serge Ivy

100 strength
@serge-ivy

This profile records idea creation, critique, evidence, pivots, support signals, and visible product judgment.

Public work

2ideas created
27contributions
0support/trash/pivot signals

Ideas created

Recent contributions

refinement on RequirementsBase — MCP-native regulatory gap-analysis agentPOSITIONING / DIFFERENTIATION PLAYS. (1) Lead GTM with the FULL chain, never a single piece — raw-law translation -> MCP-native live-systems connection -> unified scorecard across software AND policy/procedure controls -> prioritised build backlog. Each link exists somewhere; nobody has all four. (2) Own the two blind spots common to ALL incumbents: (a) template/library-driven content that cannot ingest arbitrary/newly-issued statute (long tail: APRA CPS 230, novel jurisdictional/contractual obligations, fast-moving DORA RTS); (b) weakness on policy/procedure controls (universally manual attestation) — score both from live Confluence+Jira reads. (3) Target SEC/FINRA markets-conduct as content white space — even FS-strong tools (AuditBoard/Optro, Hyperproof, Archer) skew to security/resilience-flavoured regs (DORA/GLBA/FFIEC/SOX ITGC); explicit conduct-rule coverage is thin everywhere. (4) Exploit deployment/price/mid-market — every FS-capable incumbent is quote-only $40K-$500K+/yr, platform-heavy, months-long implementations expecting data to live in their workbench; an MCP-native connect-to-existing-systems agent that skips the six-figure rollout is a structural advantage. (5) Must prove: evidence-automation maturity (where Vanta/Drata have 300-400+ integrations and 1,000+ tests) and FS-regime content credibility.risk on RequirementsBase — MCP-native regulatory gap-analysis agentCOMPETITIVE THREATS (ranked). 1) Archer Evolv — the only incumbent already attempting raw-law->requirements at scale WITH deep FS content; closest single competitor to the core edge (mitigant: heavyweight $55K-$300K+/yr, self-attestation-leaning assurance, not the engineering system-of-record, no MCP/live-systems agent). 2) Norm Ai — best-funded "law-as-code" ($48M); dangerous IF it pivots from document/artifact review to live-systems verification. 3) AuditBoard/Optro + Hyperproof — both shipped agentic AI gap-discovery in 2025-2026, so the AI-automation edge is a TIMING advantage, not durable; the durable moat is specifically raw-law->buildable-requirements feeding a live-systems scorecard. 4) CUBE — consolidating the entire reg-intel content layer (bought TR Reg Intelligence + 4CRisk); most likely to reach toward live-system integration. NOTE: AuditBoard rebranded to "Optro" on 2026-03-09 (auditboard.com -> optro.ai) — update all competitive materials.evidence on RequirementsBase — MCP-native regulatory gap-analysis agentRAW-LAW-TRANSLATION EVIDENCE (the real fight). Obligation extraction from raw regulatory text is already crowded, concentrated in FS RegTech: Ascent (ascentregtech.com — patented per-obligation extraction, MiFID II in 2.5 min); CUBE (cube.global — 750 jurisdictions, acquired Thomson Reuters Regulatory Intelligence closed early 2026 + 4CRisk); Corlytics/Clausematch (corlytics.com — ONLY incumbent explicitly doing obligation->control gap + LLM remediation, but vs policy docs); Regology (regology.com — closest to "generate obligations/risks/controls/policies from raw law", 135+ countries); Norm Ai (norm.ai — $48M, law-as-executable-code); Archer Evolv (archerirm.com/evolv-compliance — 526 compliance-trained AI models, ~95% extraction accuracy, DORA/Basel/SEC/FINRA). Incumbent backbones = UCF (unifiedcompliance.com, patented NLP decomposing regulation into atomic mandates = PRIOR ART) and SCF (securecontrolsframework.com). CRITICAL DISTINCTION: every one of these stops at the policy/document layer — "done" = a policy PDF, attestation, or control-library entry. NONE connects a regulation-derived requirement to a LIVE dev/business system (Jira/Confluence/codebase) to verify actual implementation state. That full chain is the unoccupied white space.evidence on RequirementsBase — MCP-native regulatory gap-analysis agentCATEGORY-CROWDING EVIDENCE. The "done-vs-gap coverage scorecard + Jira remediation" pattern is offered by at least 9 vendors; several already AUTO-CREATE Jira tickets from failing/not-ready controls: Vanta (native, auto-ticket on failing test), Drata (auto-open on Not Ready/Failed), LogicGate (native bidirectional), ServiceNow (own ITSM engine + Jira via Integration Hub). Secureframe explicitly does NOT yet auto-create Jira tickets (manual/bulk); OneTrust's task->Jira is still Public Preview in 2026. So competing on the scorecard+backlog loop alone means fighting incumbents with 300-400+ integrations (Vanta 400+/1,200+ tests; Drata/Secureframe 300+). Sources: vanta.com/integrations, help.vanta.com/en/articles/11345790, help.drata.com/en/articles/6953569, support.secureframe.com JIRA article, onetrust.com/integrations/Atlassian-JIRA.comment on RequirementsBase — MCP-native regulatory gap-analysis agentRESEARCH METHODOLOGY (2026-07-01). Fan-out competitive research via 5 parallel research agents, each using live web search + site fetches. Coverage: - Agent 1: Vanta, Drata, Secureframe (SOC2/ISO automation crowd). - Agent 2: Archer/RSA Archer IRM, LogicGate Risk Cloud, ServiceNow GRC/IRM (enterprise incumbents). - Agent 3: OneTrust, Hyperproof, AuditBoard/Optro (trust/audit GRC). - Agent 4: MetricStream, Sprinto, Thoropass (mixed enterprise + startup). - Agent 5: RegTech "raw law -> requirements" category — Ascent, CUBE, Corlytics/Clausematch, Norm Ai, Regology, 6clicks Hailey, UCF, SCF, plus Wolters Kluwer OneSumX, Compliance.ai, Thomson Reuters Regulatory Intelligence, Diligent. Each vendor was scored on 7 axes: (1) name+URL, (2) one-sentence core function, (3) financial-services regulation depth vs security-framework-only, (4) evidence model (automated collection vs self-attestation), (5) Jira/dev connectivity + auto-generated remediation backlog, (6) pricing + target buyer, (7) overlap with RequirementsBase + exploitable weakness. Then synthesised into a white-space verdict. MetricStream note: deepest FS/banking content (Basel/OFAC/SEC/OCC/FINRA/FFIEC/APRA/EBA/FCA/PRA feeds) but heavyweight ($75K-$1M/yr), consultant-driven, not MCP-native.evidence on Requirements BaseCompetitive research part 2/2 — wedge, threats, enabling stack. Defensible wedge = the connective spine: one clause ID carried unbroken clause→EARS story→acceptance criterion→runnable Gherkin→live-system check, sold to the change-the-bank engineering team. Plus a MANDATORY human-review gate — the arXiv study 'From Law to Gherkin' (2025) found LLM requirement omissions and hallucinations, so review is a built-in compliance requirement, not a nicety. This turns the earlier 'completeness trap' risk from a weakness into a mandated, differentiating feature. Threats to watch: Archer Evolv (only incumbent already attempting law→requirements at scale with deep FS content — closest competitor); Norm Ai ($48M 'law-as-code', dangerous if it pivots from document-review to live-systems verification); CUBE (consolidating the entire reg-intel content layer — bought Thomson Reuters Regulatory Intelligence + 4CRisk); pincer risk from Ketryx (regulated-ALM adding executable BDD) or Gherkinizer/RequireKit/Specmatic Genie (bottom-up, adding regulatory ingestion + clause trace). Enabling stack is production-ready NOW: frontier LLM (Claude) for clause extraction, grounded via clause-aware RAG + Anthropic Citations API for provenance; EARS notation as the intermediate representation; strict structured output (clause ID a required field at every hop); emit onto two rails — Gherkin (Cucumber/Reqnroll/Serenity) and OpenAPI (Specmatic); push to backlogs via the official Atlassian and Azure DevOps MCP servers; hand structured specs to Kiro (spec-driven) or Claude Code. Note: SpecFlow is EOL (Dec 2024) — target Reqnroll.evidence on Requirements BaseCompetitive research part 1/2 — landscape (4 parallel searches, ~40 vendors + academic lit). Headline: NO vendor spans the full chain regulation → clause-traceable → buildable stories → EXECUTABLE BDD → AI-coding handoff. The market splits into two non-touching worlds: (A) RegTech/GRC (CUBE, Ascent, Corlytics, Regology, 4CRisk, Archer Evolv, Norm Ai) maps regulation→obligations→controls/policies for the COMPLIANCE officer, terminating at a policy PDF/attestation; (B) BDD/AI-gen tools (Gherkinizer, RequireKit, Specmatic Genie) turn stories into runnable tests but have zero regulatory ingestion or clause trace. RequirementsBase sits in the empty bridge. Corrections forced by evidence: (1) Traceability = table stakes (Corlytics/Regology/Archer all market it) — don't lead with it. (2) Done-vs-gap + Jira scorecard = SATURATED (Vanta/Drata/LogicGate/ServiceNow already auto-create tickets) — don't lead with it. (3) Obligation extraction = solved (Ascent did MiFID II in 2.5min; Archer Evolv ~95% accuracy) — table stakes. (4) BIAN mapping = ZERO competitors do it, and BIAN is free — novel positioning. (5) Executable step-definitions = almost nobody ships runnable tests — sharpest messaging wedge. (6) Buyer flank: every incumbent sells to Compliance/Risk; the unserved buyer is Product/Engineering/Delivery, who today hand-write specs from obligation exports.refinement on Requirements BaseSection: signal Proposal: Market evidence supports timing and white space. Competitive research across ~40 vendors confirms NO product spans regulation → clause-traceable → buildable stories → EXECUTABLE BDD → AI-coding handoff. The field splits into two non-overlapping worlds — RegTech/GRC (stops at policy/control artefacts for compliance officers) and BDD/AI-gen tools (start after the hard part, no regulatory input) — leaving the bridge empty. The concept is being published in 2025-26 academic papers ('From Law to Gherkin'), a recognized-but-unsolved signal. The enabling stack is production-ready today (frontier LLM extraction, clause-aware RAG + Anthropic Citations API, EARS→Gherkin, strict structured output, official Atlassian/Azure DevOps MCP servers, Kiro/Claude Code handoff). The defensible wedge is the unbroken clause→story→AC→runnable-test spine plus a mandatory human-review gate, sold to the underserved Product/Engineering/Delivery buyer rather than Compliance. Traceability, obligation extraction, and the done-vs-gap+Jira scorecard are all table stakes or saturated — the differentiation is executable output + BIAN alignment + the engineering buyer, not any single piece. Rationale: Fills the empty Current Signal field with the strongest evidence-backed reason to pay attention now: a validated white space, academic corroboration that it's unsolved, and a fully production-ready enabling stack — while correcting the pitch away from the saturated/table-stakes pieces.refinement on Auto Tax Return (Australia)Section: research Proposal: REGULATORY & SOURCE LINKS — all clickable (markdown). These are the bars that force even AI-first players to keep a registered human on lodgement. - [TPB — tax agent registration](https://www.tpb.gov.au/tax-agent-registration) — preparing/lodging returns for a fee generally requires being a registered tax agent. - [ATO — Digital Service Provider requirements](https://softwaredevelopers.ato.gov.au/RequirementsforDSPs) — DSP operational-security framework for software that touches ATO services. - [ATO — Practitioner Lodgment Service (SBR)](https://www.ato.gov.au/tax-and-super-professionals/digital-services/practitioner-lodgment-service) — the lodgement channel, gated to registered agents/DSPs. - [CDR — become an accredited data recipient](https://www.cdr.gov.au/for-providers/become-accredited-data-recipient) — open-banking bank-data ingestion needs accreditation (a high bar). Implication (unchanged): safe v1 = a preparation assistant that outputs figures for the user to self-lodge in [myTax](https://www.ato.gov.au/individuals-and-families/your-tax-return/how-to-lodge-your-tax-return/lodge-your-tax-return-online-with-mytax) — avoids TPB/DSP/SBR. Full auto-lodgement needs registration or an agent partnership (the [LodgePro](https://lodgepro.com.au/) / [Hnry](https://hnry.com.au/) model). [CDR](https://www.cdr.gov.au/for-providers/become-accredited-data-recipient) is the trustworthy long-term ingest path but not table stakes for a PDF/CSV v1. Rationale: Makes all regulatory and source references clickable markdown links, keeping the full knowledge in the ideastore record rather than in memory.refinement on Auto Tax Return (Australia)Section: research Proposal: COMPETITOR DIRECTORY — all links clickable (replaces earlier bare-URL lists). Personal-only scope. Direct / AI-first (the real competitive set): - [LodgePro](https://lodgepro.com.au/) — key rival: open-banking → auto-classify → accountant-reviewed lodgement. - [AITaxReturns](https://aitaxreturns.com.au/) — AI individual prep (its "self-lodge via SBR" claim was refuted). - [TaxFox](https://www.taxfox.com.au/) — deduction finder (its "CDR ingest" claim was refuted). - [Snapclaim](https://www.snapclaim.com.au/) — AI deduction capture. Online DIY / registered agents: - [Etax](https://www.etax.com.au/) ([fees](https://www.etax.com.au/etax-fees/)) - [H&R Block Online](https://www.hrblock.com.au/tax-return/online/lodge-online) ([pricing](https://www.hrblock.com.au/tax-return-fees-and-pricing)) - [POP Tax](https://www.poptax.com.au/) (ex-Airtax consumer heir) Free baseline: - [ATO myTax](https://www.ato.gov.au/individuals-and-families/your-tax-return/how-to-lodge-your-tax-return/lodge-your-tax-return-online-with-mytax) Sole-trader / business — OUT OF SCOPE (reference only, not competitors): - [Hnry](https://hnry.com.au/) · [Thriday](https://www.thriday.com.au/) · [Rounded](https://rounded.com.au/) · [Airtax](https://www.airtax.com.au/) · [QuickBooks Self-Employed](https://quickbooks.intuit.com/au/) · [Xero](https://www.xero.com/au/) PFM / categorisation (no return output): - [TaxTank](https://taxtank.com.au/) · [Frollo](https://frollo.com.au/) · [WeMoney](https://www.wemoney.com.au/) · [PocketSmith](https://www.pocketsmith.com/) Rationale: User wants every competitor link clickable; consolidates the earlier bare-URL/bare-domain lists into proper markdown links.refinement on Auto Tax Return (Australia)Section: research Proposal: Add a competitor positioning map + feature matrix to the Competitors section (personal-only scope). ### The map — nobody's in the top-left ★ ``` FULL DRAFTED RETURN ▲ ★ THE GAP (YOU) │ ● LodgePro auto draft, │ ● Etax ● H&R Block no human needed │ (it works — but a human │ accountant + $$ in the loop) ── myTax ──────────────┼──────────────────────────► free, self-lodge, │ HUMAN + $$ NEEDED no deduction help 🥱 │ ○ TaxFox ○ Snapclaim │ ○ TaxTank ○ Frollo ○ WeMoney find / categorise, │ no full return ▼ JUST CATEGORISE ``` ### Who actually does what | App | Reads statements | Auto-finds deductions | Drafts return | No human | Free | |---|:--:|:--:|:--:|:--:|:--:| | **YOUR IDEA** ★ | ✅ | ✅ | ✅ | ✅ | 🆓* | | LodgePro | ✅ | ✅ | ✅ | ❌ | ❌ | | myTax | ❌ | ❌ | ✅ | ✅ | ✅ | | Etax / H&R Block | ❌ | ⚠️ | ✅ | ❌ | ❌ | | TaxFox / Snapclaim | ⚠️ | ⚠️ | ❌ | ✅ | ⚠️ | | TaxTank / Frollo | ✅ | ⚠️ | ❌ | ✅ | ⚠️ | *draft free, pay to export/premium. The empty top-left corner is the whole pitch. Rationale: A 2x2 positioning map + feature matrix make the market gap visually undeniable — the empty top-left quadrant is the pitch.refinement on Auto Tax Return (Australia)Section: body Proposal: Add these visual explainers to the body (markdown; mermaid + ASCII fallback so it renders anywhere). ### How it works (the 60-second version) ```mermaid flowchart LR A["📄 Shoebox of<br/>bank statements"] --> B["🔍 Parse"] B --> C["🧠 Auto-classify<br/>income · deduction · personal"] C --> D["🏷️ Map to ATO labels"] D --> E["📊 Draft return<br/>+ why each line"] E --> F["👀 You review"] F --> G["✅ Copy into myTax"] ``` ASCII fallback: `📄 Statements → 🔍 Parse → 🧠 Classify → 🏷️ ATO labels → 📊 Draft → 👀 Review → ✅ myTax` *From shoebox to submitted in one coffee. ☕* ### What Aussies pay for one simple return ``` Tax agent ████████████████████ $150–$400 😩 H&R / Etax ████████ ~$50–$99 😐 YOUR APP ██ $0–$29 😎 (draft free) myTax ▏ $0 🥱 (…you do all the work) ``` *Same result. Wildly different amount of your Sunday afternoon.* Rationale: Visual pipeline + cost bar make the value obvious at a glance and add personality to the idea page.refinement on Auto Tax Return (Australia)Section: research Proposal: Re-triage competitor set for the PERSONAL-only scope. Move sole-trader/business tools to an "Out of scope (different segment)" note rather than competitors: Hnry (hnry.com.au), Thriday (thriday.com.au), Rounded (rounded.com.au), Airtax, QuickBooks Self-Employed, Xero — these target business/ABN income, not the salaried individual, so they are NOT the competitive set (kept only as reference for how auto-categorisation is done). IN-SCOPE competitors for a personal salaried return remain: - LodgePro (https://lodgepro.com.au/) — key rival: open-banking ingest -> auto-classify -> accountant-reviewed lodgement. - AITaxReturns (https://aitaxreturns.com.au/), TaxFox (https://www.taxfox.com.au/), Snapclaim (https://www.snapclaim.com.au/) — AI deduction/return prep for individuals. - ATO myTax (free baseline, prefills income, no deduction classification). - Etax (https://www.etax.com.au/), H&R Block Online (https://www.hrblock.com.au/tax-return/online/lodge-online) — registered online individual agents. - PFM with tax angle relevant to individuals: TaxTank (taxtank.com.au), Frollo (frollo.com.au), WeMoney (wemoney.com.au) — categorisation only, no return. Also drop Sherlok entirely (mortgage refinancing, not tax). Rationale: With personal-only scope, sole-trader tools are a different segment and should not be counted as competitors; the individual-focused set is what matters.refinement on Auto Tax Return (Australia)Section: snapshot Proposal: Tighten scope: this product is for PERSONAL / individual Australian taxpayers only — primarily salaried employees (and mixed salary + simple investment income) who self-lodge via myTax. EXPLICITLY OUT OF SCOPE: - sole traders, freelancers, gig/contractor business income (ABN business schedules); - companies, trusts, partnerships, SMSFs; - GST / BAS / payroll; - anything requiring business bookkeeping. Rationale: sole traders are already well served by dedicated tools (Hnry, Thriday, Rounded, Airtax, QuickBooks Self-Employed, Xero). The underserved segment is the ordinary salaried person who uses myTax, hates categorising deductions from bank statements, and has no tool that auto-classifies them. Narrowing to personal returns keeps the classification rules simpler, the liability lower, and the wedge sharp. Remove the earlier "gig / sole-trader individuals" line from the Who It's For section — that segment is now out of scope. Rationale: User has decided the target is personal individual returns only; sole-trader/business is out of scope and already served by incumbents. Scope needs to say this explicitly.refinement on Requirements BaseSection: next_step Proposal: Single cheapest test that exercises every load-bearing assumption at once: take ONE regulation (APRA CPS 230), translate it into a typed requirement pack — each item tagged software vs policy/procedure — WITH clause→story traceability. For at least one policy-type item, define concretely how implementation would be PROVEN beyond self-attestation (evidence, not a ticked box). Put the pack in front of one real compliance lead and pre-sell a fixed-fee gap sprint against it. Success = they trust the traceability, believe the coverage is honest (not falsely green), and pay. This tests all three at once: is the translation faithful and complete enough to trust, is done-vs-gap credible, and will a firm pay — before building any pack library or platform. Rationale: Consolidated next step that supersedes the earlier "pre-sell a gap sprint" proposal: adds clause traceability, software/policy typing, and a concrete proof-of-implementation check so the single test covers the completeness, verification, and willingness-to-pay risks together.refinement on Requirements BaseSection: risk Proposal: Four surviving risks after the translation-layer reframe: (1) Completeness trap — traceability proves each generated requirement maps to a clause, but not that every obligation was captured; a missed rule never shows as a gap, so a firm can see 100% green over an invisible hole. Proving completeness needs an expert to read the whole regulation — the exact cost the AI was meant to remove. (2) Verification-of-done honesty — the done-vs-gap scorecard is only as honest as its ticks; software is verifiable, but policy/procedure controls rely on self-attestation and a written-but-unfollowed policy still reads green. (3) Interpretation liability — principles-based regs (esp. APRA) require opinionated interpretation; clause→story→test traceability is the mitigation and the moat. (4) Crowded GRC market — Vanta/Drata/Archer/LogicGate/ServiceNow already map obligations and track coverage; the edge must be automatic raw-law→buildable-requirements translation, not the scorecard. Unresolved decision: position as "sign-off-grade, complete, expert-gated" (premium, competes with law firms) or "fast first draft, human-completed" (cheap, tool-shaped) — the pitch currently implies both, which are different companies. Rationale: Consolidated risk field capturing the risks that survived successive reframes, plus the still-open positioning decision. Supersedes the earlier standalone risk contributions as the canonical summary.refinement on Requirements BaseSection: snapshot Proposal: RequirementsBase is a translation layer that turns government/regulator source text (e.g. APRA CPS 230, AML obligations) into buildable requirements — user stories, use-cases, acceptance criteria, and executable BDD tests — with every artefact traceable back to the exact clause it came from ("pseudo-code for something that could be built"). Each requirement is typed as a SOFTWARE control (built in code, verifiable via tests) or a NON-SOFTWARE control (policy, procedure, guideline). Because regulation is shared across all firms in a jurisdiction, the translation is reusable, and keeping it current is a subscription (always-current regulation-as-requirements) rather than a maintenance cost. AI drafts the translation at scale; domain experts validate and sign off; clause→story→test traceability lets compliance teams audit faithfulness. An MCP-native gap-analysis agent connects to a client's Jira/Confluence/live systems and produces a single coverage scorecard — done vs gap across both software and policy controls — plus a prioritised remediation list, a sprint-ready Jira backlog, and a matched test pack that feed AI coding tools (Claude Code, Kiro). The product delivers the shared regulatory layer; the firm-specific "buildable in this bank" last mile stays with the client and its integrators. Revenue: platform licences (free → A$55k–190k/yr firm licences for consultancies and SIs), fixed-fee productised services (gap sprints, pack customisation, onboarding), and subscription updates. Rationale: Consolidated canonical snapshot that supersedes earlier piecemeal snapshot proposals: folds in the translation-layer reframe, clause traceability, the software-vs-policy control typing, and the done-vs-gap coverage scorecard. Represents the idea's current, internally consistent state.risk on Requirements BaseVerification-of-done honesty (the scorecard's weak point). The gap tracker labels each requirement done vs gap, but a scorecard is only as honest as its ticks. Software controls are verifiable (inspect code / run tests). Non-software controls (policy, procedure, guideline) usually rely on self-attestation — someone saying "we did it." A policy can be written and ticked green while nobody follows it; regulators judge actual behaviour, not the document. So a green board can give false confidence, and when a regulator finds a "done" that wasn't, the tool that reported it green carries the blame. Two riders: (1) This positioning lands in a crowded GRC market — Vanta, Drata, Archer, LogicGate, ServiceNow already map obligations to controls and track done-vs-gap. The defensible edge is NOT the scorecard; it is automatically translating raw regulation into typed, buildable, clause-traceable requirements. (2) Done-vs-gap only means something if the requirement list is complete — a requirement that was never generated never appears as a gap, so a firm can read 100% green over an invisible hole (inherits the completeness trap).evidence on Auto Tax Return (Australia)COMPETITOR SCAN 3/3 — Regulatory context (verified primary sources) + the market gap. WHY EVEN AI-FIRST PLAYERS KEEP A HUMAN ON LODGEMENT — three regulatory bars, all confirmed from primary sources: - TPB tax agent registration — https://www.tpb.gov.au/tax-agent-registration — preparing/lodging returns for a fee generally requires being a registered tax agent. - ATO Digital Service Provider requirements — https://softwaredevelopers.ato.gov.au/RequirementsforDSPs — plus the Practitioner Lodgment Service / SBR path — https://www.ato.gov.au/tax-and-super-professionals/digital-services/practitioner-lodgment-service — lodging to the ATO for others is gated behind DSP operational-security + SBR. - CDR accreditation (open banking) — https://www.cdr.gov.au/for-providers/become-accredited-data-recipient — automatic bank-data ingestion needs accredited-data-recipient status (a high bar; note TaxFox's CDR claim was refuted, i.e. it likely avoids this). IMPLICATION: the safe v1 remains a PREPARATION ASSISTANT that outputs figures for the user to self-lodge in myTax — avoids TPB/DSP/SBR — while full auto-lodgement needs registration or an agent partnership (the LodgePro/Hnry model). CDR is the trustworthy long-term ingestion path but is not table stakes for a PDF/CSV v1. THE GENUINE GAP (post-research): a salaried-consumer, statements-in -> auto-classified deductions -> reviewed draft -> self-lodge-in-myTax product with NO human in the loop still does not cleanly exist. Competitors either insert an accountant (LodgePro, Hnry) or stop at deduction-finding without lodgement (TaxFox, Snapclaim). Deduction DISCOVERY for salaried DIY earners is the underserved wedge myTax cannot match. RESEARCH METHOD: 6 angles, 25 sources fetched, 114 claims extracted, 3-vote adversarial verification (23 confirmed, 2 refuted). Caveat: automated synthesis was token-limited, so some per-competitor pricing specifics beyond LodgePro remain unverified; URLs and the findings above are solid.evidence on Auto Tax Return (Australia)COMPETITOR SCAN 2/3 — Adjacent tools (online agents, the free baseline, sole-trader automation, PFM/categorisation). FREE BASELINE (biggest "why pay?" competitor): - ATO myTax via myGov — https://www.ato.gov.au/individuals-and-families/your-tax-return/how-to-lodge-your-tax-return/lodge-your-tax-return-online-with-mytax — free, prefills salary/interest/dividends/health. VERIFIED it does NOT classify deductions from bank statements. That omission is the wedge. ONLINE DIY / REGISTERED AGENTS: - Etax — https://www.etax.com.au/ (fees: https://www.etax.com.au/etax-fees/) - H&R Block Online — https://www.hrblock.com.au/tax-return/online/lodge-online (pricing: https://www.hrblock.com.au/tax-return-fees-and-pricing) - POP Tax / ex-Airtax consumer heir — Airtax alternatives referenced via https://annamoney.au/alternatives/airtax-alternative SOLE-TRADER / FREELANCER AUTOMATION (auto-categorise + often file tax; registered): - Hnry — https://hnry.com.au/sole-traders (auto-categorises income/expenses AND files tax) - Thriday — https://www.thriday.com.au/features/business-tax (AI transaction categorisation + tax) - Rounded — https://rounded.com.au/pricing PFM / TRANSACTION-CATEGORISATION WITH TAX ANGLE (no return output): - TaxTank — https://taxtank.com.au/ (bank feeds + categorisation, investors/sole traders) — nearest on the bank-statement angle - Frollo — https://frollo.com.au/open-banking/ (also a CDR accredited data provider) - WeMoney — https://www.wemoney.com.au/open-banking Also seen: PocketSmith (pocketsmith.com), QuickBooks Self-Employed (quickbooks.intuit.com/au), Xero (xero.com/au) — business/PFM categorisation, not consumer return prep. BUCKETS: (1) AI + human accountant on lodgement [LodgePro, Hnry]; (2) deduction-finding, no lodgement [TaxFox, Snapclaim]; (3) categorisation/PFM, no return [TaxTank, Frollo, WeMoney].evidence on Auto Tax Return (Australia)COMPETITOR SCAN 1/3 — Direct / near-direct AI-first AU competitors (deep web research, 25 sources, adversarially verified). KEY RIVAL — LodgePro (https://lodgepro.com.au/): AI-first AU platform; ingests bank data via open banking, auto-classifies into ATO categories, produces a return, and lodges AFTER a registered accountant reviews it. Claims "prepare and lodge in under 15 minutes." VERIFIED (high confidence). This is the closest thing to this idea already shipping — but it keeps a human accountant on the lodgement step. AITaxReturns (https://aitaxreturns.com.au/): AI-guided individual tax return prep. NOTE: its claim to lodge directly to the ATO via SBR was REFUTED 0-3 in verification — it likely routes lodgement through a registered agent rather than self-serve SBR. TaxFox (https://www.taxfox.com.au/): deduction-finder / tax estimate app. NOTE: its claim to ingest bank data via CDR open banking was REFUTED 0-3 — appears to rely on manual / receipt entry, not automatic bank linking. Snapclaim (https://www.snapclaim.com.au/): AI tax deduction capture app. Fetched as a primary source; specifics unverified. PATTERN: every end-to-end player keeps a registered human accountant on the actual lodgement (LodgePro, Hnry). Pure no-human auto-lodgement for salaried consumers still does not cleanly exist — but the green field is closing. LodgePro is now the competitor to beat. (Sherlok, listed in the original idea, is CONFIRMED miscategorised — it is mortgage refinancing, not tax. Drop it.)refinement on Requirements BaseClarification (resolves the "not everything is a test" objection): each translated requirement is typed as either a SOFTWARE control (built in code, verifiable via tests) or a NON-SOFTWARE control (internal guideline, policy, or procedure). The system doesn't force everything into executable tests — instead it tracks IMPLEMENTATION STATUS across both types: for every requirement derived from a regulation, the company can see what has been implemented and what is still a gap. The output is a single coverage scorecard (done vs gap) spanning code and policy, not just a test pack. This positions the gap-analysis agent as a regulation-to-implementation coverage tracker.refinement on Requirements BaseSection: snapshot Proposal: RequirementsBase is a translation layer that turns government and regulator source text into buildable requirements. It ingests regulation (e.g. APRA CPS 230, AML obligations) and outputs structured, testable assets — user stories, use-cases, acceptance criteria, and executable BDD tests — effectively "pseudo-code for something that could be built," with each artefact traceable back to the exact regulatory clause it came from. Because regulation is shared across every firm in a jurisdiction, the translation is reusable, and keeping it current becomes a subscription (always-current regulation-as-requirements) rather than a maintenance cost. AI drafts the translation at scale; domain experts validate and sign off, and clause→story→test traceability lets compliance teams audit faithfulness. An MCP-native gap-analysis agent connects to a client's Jira/Confluence/live systems, scores current coverage against the reference packs, and outputs a prioritised remediation list, a sprint-ready Jira backlog, and a matched test pack — feeding directly into AI coding tools like Claude Code or Kiro. The product delivers the shared regulatory layer; the firm-specific "buildable in this bank" last mile stays with the client and their integrators. Revenue: platform licences (free → A$55k–190k/yr firm licences for consulting firms and SIs), fixed-fee productised services (gap sprints, pack customisation, onboarding), and subscription updates. Rationale: Repositions from a static "requirements library" (which triggered the reusability-paradox objection) to a regulation-to-requirements translation layer, where the shared regulatory source makes the output genuinely reusable and turns the maintenance treadmill into a subscription. Adds clause traceability as the core trust/moat mechanism.pivot on Requirements BaseReframe (strengthens the idea): the core value is a TRANSLATION LAYER, not a requirements library. The system ingests government/regulator source text (e.g. APRA CPS 230, AML obligations) and translates it into structured, buildable requirements — user stories, use-cases, acceptance criteria, BDD tests — i.e. "pseudo-code for something that could be built." Firms no longer re-derive requirements from dense legal prose themselves. Why this is stronger: regulation is SHARED across every firm in a jurisdiction, so the translation is genuinely reusable — this defuses the earlier reusability-paradox objection for the regulatory-derived layer. It also flips the maintenance treadmill from a cost into the business model: an always-current regulation-as-requirements subscription (like a legal-update service that goes one step further, into buildable form). What still stands: (a) interpretation liability — principles-based regs require opinionated interpretation, so faithful clause→story→test traceability is the real moat and the thing compliance teams must be able to audit; (b) product delivers the shared first ~60%, with the firm-specific "buildable in THIS bank" last mile remaining (which conveniently lowers channel conflict — consultancies use it as a tool rather than fear it); (c) competes adjacent to reg-change trackers (CUBE, Ascent, LexisNexis/Thomson Reuters) — win by going all the way to executable stories/tests, not by being the only one tracking regs. Cheapest test: translate ONE regulation (CPS 230) into a story/use-case pack WITH clause traceability, put it in front of one compliance lead. Yes = "saves weeks and I trust the trace." Tests both load-bearing assumptions at once: good enough to trust, and saves enough to pay for.risk on Requirements BaseCritical assessment — five failure modes, most fatal first: 1. Reusability paradox (core flaw). Functional requirements are valuable because they're firm-specific (products, jurisdiction, risk appetite, legacy stack). A requirement generic enough to resell is either so abstract it's a truism BIAN gives away free, or so specific it doesn't fit the next buyer. The reusable middle band is thin — and it's exactly what the A$55–190k/yr licence charges for. 2. Provenance doesn't transfer. Regulated buyers pay for accountability tied to THEIR system, not a library another firm's expert blessed elsewhere. A sign-off on a generic pack carries no assurance or liability across the boundary — so the thing "buyers will pay for" is the thing that doesn't cross it. 3. Inverted margin story. "AI drafts at scale" implies cheap content, but the value is the expensive human validation, whose cost dominates and doesn't shrink with scale. Regulation churns (APRA, Basel, AML, multi-jurisdiction) → permanent re-validation treadmill; stale requirements are worse than none. This is a consultancy with an AI intake funnel, not an AI-leverage content business. 4. Channel conflict with the named buyer. Consulting firms and SIs sell requirements-gathering as billable hours. A library that commoditizes that work threatens their model — you're asking them to pay you to undercut their own margin. 5. Liability on the gap agent. An MCP agent wired into a bank's live systems declaring "you have a compliance gap" — false negatives are regulatory exposure for the client and litigation exposure for you. Without heavy assurance you can't sell it; with it you're back to a consultancy (see #3). Secondary: cold-start (no packs = no value; large upfront build before revenue) and undifferentiation vs BIAN (free), Big-4 accelerators, and Jama/DOORS. Decider: will a real FS firm pay for a validated requirement written for someone else? If reusability is thin, everything downstream collapses.refinement on Requirements BaseSection: next_step Proposal: Before building any packs, pre-sell a single fixed-fee gap sprint to one real FS firm. Concretely: pick one BIAN capability domain in one jurisdiction, hand-build one reference pack, and get a paying client to run their current-state against it. Success = they pay, and the output changes what they actually put in their next sprint. This tests the load-bearing assumption (will a firm pay for a requirement written for someone else?) for the cost of one sprint, before any platform or content investment. Rationale: The idea's viability hinges on requirement reusability across firms. That is cheap to falsify with one pre-sold engagement and expensive to discover after building a pack library. De-risk the core assumption first.refinement on Slowdown Personal ResetSection: research Proposal: Remove the stale caveat line in the Research Trail that reads: "The local Slowdown docs page at /Users/serge/dev/meetup/slowdown/docs/index.md currently contains parent-volleyball research, so it was not used as Slowdown evidence." It refers to leftover content from an unrelated project that was accidentally left in that docs file, not to anything about Slowdown itself. Keeping it in the canonical idea just confuses readers. Either delete the line entirely, or replace it with a neutral note: "The local docs/index.md was skipped as evidence because it contained unrelated leftover content at time of research." Once the local docs file is cleaned up on the source machine, drop the note altogether. Rationale: The line describes an accidental copy-paste mixup in a local file on a separate machine, not a property of the Slowdown idea. It adds no signal and reads as noise/confusion in the canonical Research Trail.